# VCTK security baseline

Baseline để so sánh nếu `C:\JXVCTK\JxVoCongTruyenKy` bị updater đổi file.

## Snapshot hiện tại

`2026-09-18-vctk/` — lấy lúc 2026-09-18, sau khi Defender đã cách ly:

- `_TatAntiVirut\DefenderControl\DefenderControl.exe`
- `_TatAntiVirut\DefenderControl21\dControl.exe`
- `_AutoVLBS\VLBS13\core.dll`

Những file đó **không còn trên đĩa**, nên inventory này phản ánh trạng thái *sau quarantine*.

## Cách so sánh lần sau

```bat
python security-baseline\2026-09-18-vctk\scripts\compare_to_baseline.py
```

Hoặc SQL:

```sql
SELECT relpath, size, sha256 FROM files WHERE ext IN ('.exe','.dll','.sys','.asi','.bat','.cmd');
```

File đổi SHA256 (đặc biệt `AutoUpdateVCTK.exe`, `KY_VCTK_CTCX_NEW.exe`, `game.exe`, `add.bat`) là tín hiệu updater đã đẩy bản mới — cần soi lại trước khi chạy.

---

## Snapshot 2026-09-28 (audit đầy đủ 5 giai đoạn)

Thư mục: `2026-09-28-vctk/` — audit sau đợt updater 19–25/09. Báo cáo kỹ thuật: [`2026-09-28-vctk/notes.md`](2026-09-28-vctk/notes.md) · Báo cáo tổng hợp: [`../SECURITY_AUDIT_2026-09-28.md`](../SECURITY_AUDIT_2026-09-28.md)

**Phát hiện chính:**
- `_AutoKimYen\vauth.auto` = **Trojan:MSIL/Zusy.NK!MTB** (xuất hiện 19/09, đã chạy 27/09) — bị che bởi exclusion folder game.
- `_AutoVLBS\VLBS13\core.dll` = **Trojan:Win32/tenga** (tái xuất hiện sau cách ly 18/09).
- `_TatAntiVirut\DefenderControl*.exe` = HackTool (hồi sinh trên đĩa).
- Firewall tắt cả 3 profile; Tamper Protection off; 3 exclusion (folder game + `C:\21AK22` + folder 360Auto đã xóa).
- `vietguards.driver` = blob 32 MB mã hóa, không phải PE (3 phiên bản trong 10 ngày).
- Server thật (đo live 28/09): `222.255.217.212` — kênh chính `:6673`, phụ `:6663`, gateway `:5622`.

**Cách lặp lại / công cụ** (trong `2026-09-28-vctk/scripts/`):
```powershell
python  scripts\diff_vs_baseline_fast.py        # bat file moi/doi size vs inventory 18/09
python  scripts\analyze_changed_binaries.py     # phan tich tinh + doi chieu ban zip
# (Admin) scripts\defender_elevated.ps1         # exclusion/firewall/task/threat + scan goc
# (Admin) scripts\defender_scan_copies.ps1      # AV that: staged copy ngoai exclusion
# (Admin) scripts\capture_elevated.ps1 -Seconds 300   # pktmon bat goi khi vao game
pwsh    scripts\sample_connections.ps1          # socket sampler + DNS cache
pwsh    scripts\endpoint_checks.ps1             # TLS/HTTP/RDAP thu dong
```

**Lưu ý vận hành:**
- Gói gốc `Full_JxVCTK_123456.zip` mở được bằng mật khẩu `123456` (trong tên file) → dùng làm bản đối chiếu gốc.
- Watch list mở rộng: thêm `vauth.auto`, `vietguards.driver`, hash launcher mới — xem `2026-09-28-vctk/watch_hashes.txt` và `iocs.json`.
- **Cảnh báo:** folder `C:\JXVCTK\JxVoCongTruyenKy` đang nằm trong exclusion Defender — mọi scan trực tiếp folder này vô nghĩa; bắt buộc staged-copy ra ngoài trước khi quét (đã có script).

