English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

Red October - Indicators of compromise

GReAT
Kaspersky Lab Expert
Posted January 21, 10:19  GMT
Tags: Targeted Attacks
0.3
 

Since our announcement about "Red October", we've received a lot of questions on how to quickly identify compromised systems.

That's why together with our partner Alienvault we've decided to put together a small whitepaper for CERTs and system administrators which can help identify and mitigate the attack.

The small whitepaper includes summarized information about malware's known locations in infected systems, command and control domains and servers, snort rules, RC4 encryption keys, passwords and an industry standard IOC file with all these informations.

At the moment, our sinkhole is still registering traffic from 36 infected victims in several countries. We hope the information will help CERTs and admins to successfully identify and eradicate the infections.

Download the whitepaper: "Red October - Indicators of compromise"


Comments

If you would like to comment on this article you must first
login


Bookmark and Share
Share

Analysis

Blog