Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a actinium. Aliases observados: actinium, apt-c-53, armageddon, bluealpha, gammadrop, gammaload, glowsand, glowspark, hive0051, primitive bear, pterodo, shuckworm. Conteo por tipo: domain: 50455, file_path: 1130, ipv4: 28, url: 208.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | 0.elitoras.ru | APTTrail |
| Domain | 0.hustorla.ru | APTTrail |
| Domain | 001912184.retarus.ru | APTTrail |
| Domain | 02.belkort.ru | APTTrail |
| Domain | 02.bortogat.ru | APTTrail |
| Domain | 02.domasq.ru | APTTrail |
| Domain | 02.elitoras.ru | APTTrail |
| Domain | 02.timerto.ru | APTTrail |
| Domain | 02.vadilops.ru | APTTrail |
| Domain | 02.voranfi.ru | APTTrail |
| Domain | 03.bortogat.ru | APTTrail |
| Domain | 03.domasq.ru | APTTrail |
| Domain | 03.elitoras.ru | APTTrail |
| Domain | 03.protimas.ru | APTTrail |
| Domain | 03.vadilops.ru | APTTrail |
| Domain | 03.voranfi.ru | APTTrail |
| Domain | 032xwkhts.corolain.ru | APTTrail |
| Domain | 043.libellus.ru | APTTrail |
| Domain | 04djgx9h1.corolain.ru | APTTrail |
| Domain | 06ez6x.moolin.ru | APTTrail |
| Domain | 0apkhude1h8biwnd.spotifik.ru | APTTrail |
| Domain | 0e42557e7ebf4251bad6d1e53a680dfb.hopers.ru | APTTrail |
| Domain | 0ejbfnz2mkneq14e46.moolin.ru | APTTrail |
| Domain | 0enhzs.moolin.ru | APTTrail |
| Domain | 0f6vi2h1w.corolain.ru | APTTrail |
| Domain | 0gcqbjhae4qj.metanat.ru | APTTrail |
| Domain | 0gg2nmb5vnea.jolotras.ru | APTTrail |
| Domain | 0hwo4ajnr.corolain.ru | APTTrail |
| Domain | 0ievltomh.corolain.ru | APTTrail |
| Domain | 0ivrlzyk.moolin.ru | APTTrail |
Referencias
- http://lists.emergingthreats.net/pipermail/emerging-sigs/2021-November/030492.html
- http://researchcenter.paloaltonetworks.com/2017/02/unit-42-title-gamaredon-group-toolset-evolution/
- https://aaqeel01.wordpress.com/2021/01/18/docx-files-template-injection/
- https://app.any.run/tasks/008c9df0-96b2-4616-9b75-d6a95ee74457/
- https://app.any.run/tasks/17575220-f087-4baa-bc96-3d9bdb0f10ed/
- https://app.any.run/tasks/26e685f3-9a76-45fa-ad70-dd61cb64812c/
- https://app.any.run/tasks/4622fd63-97dc-433a-b859-9be099f37e20/
- https://app.any.run/tasks/5022d054-250f-41fa-93ad-b0cc1c4aba6a/
- https://app.any.run/tasks/58ad6333-96c4-4616-bba6-c0acc7c1500c/
- https://app.any.run/tasks/62e67bce-1c3f-4262-a3b4-93fc7aab8190/
- https://app.any.run/tasks/6401f328-c80f-48f7-95a9-b3b981111e94/
- https://app.any.run/tasks/6919cbfb-f193-4125-a282-f3cf7f835e66/