Vietnam Newsroom & Threat Intelligence
Clear sources · Careful assessments
NOTEDo not attribute a ransomware family from a file extension or a single ransom note.Vietnam time · UTC+7

IOC tracking

Publish indicators only with sufficiently clear sources, timestamps and context.

HashDomainIPFile artifactRegistryURLFilenameExtension
No validated IOC set is ready for release
No fabricated hashes, IPs or domains are displayed. The categories below define monitoring scope, not an automated feed.
Awaiting data

A hash needs its algorithm, sample source and observation time.

Value
—
Source / last seen
—
Status
Not released
Awaiting data

A domain needs a role, observation time and a fresh ownership assessment.

Value
—
Source / last seen
—
Status
Not released
Awaiting data

An IP address needs context; historical data must not automatically become a blocking rule.

Value
—
Source / last seen
—
Status
Not released
Awaiting data

File artifacts need a path, collection source and relationship to the event.

Value
—
Source / last seen
—
Status
Not released
Awaiting data

Registry keys and values need process and environment context.

Value
—
Source / last seen
—
Status
Not released
Awaiting data

URLs are defanged when needed. Do not automatically visit suspected malicious links.

Value
—
Source / last seen
—
Status
Not released
Awaiting data

Filenames have low specificity; corroborate behavior and hashes.

Value
—
Source / last seen
—
Status
Not released
Awaiting data

An extension is a lead, not a family conclusion.

Value
—
Source / last seen
—
Status
Not released

A released record needs type, value, source, time, confidence, observation context and update history.

IOCs assist detection and investigation but do not independently establish intrusion. Check each indicator's source, observation time, confidence and behavior before blocking or responding.

IOC types

Hashes, domains, IPs, URLs, mutexes, service names, file paths and log indicators.

Using IOCs safely

Do not execute samples or upload suspected malware to public services when it contains sensitive data.

Link context

Correlate IOCs with related ransomware families and TTPs.

Threat IntelligenceIncident response
CISA and partners — AA24-109A: Akira RansomwareInitially published 18/04/2024 · Reference documentation on Akira, IOCs and TTPs. See the update date at the source.
Palo Alto Networks Unit 42 — Mallox Ransomware2023 · Sample research and intrusion chain analysis by Unit 42.

Each source's scope and date are recorded separately when available. A citation does not independently verify every assessment.