Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a aguilaciega. Aliases observados: aguilaciega, apt-c-36, apt-q-98, apt36, blind eagle, blotchyquasar, tag-144. Conteo por tipo: domain: 64, file_path: 1, ipv4: 20, url: 9.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | ajaxcoder.polycomusa.com | APTTrail |
| Domain | aseguradotelle.duckdns.org | APTTrail |
| Domain | autgerman.autgerman.com | APTTrail |
| Domain | autgerman.com | APTTrail |
| Domain | axu87794.polycomusa.com | APTTrail |
| Domain | ceoempresarialsas.com | APTTrail |
| Domain | ceosas.linkpc.net | APTTrail |
| Domain | ceoseguros.com | APTTrail |
| Domain | chileimportaciones.cl | APTTrail |
| Domain | cryptersandtools.minhacasa.tv | APTTrail |
| Domain | defenderav.con-ip.com | APTTrail |
| Domain | dian.server.tl | APTTrail |
| Domain | diangovcomuiscia.com | APTTrail |
| Domain | edificiobaldeares.linkpc.net | APTTrail |
| Domain | enero2022.con-ip.com | APTTrail |
| Domain | envio02-04.duckdns.org | APTTrail |
| Domain | envio14-03.duckdns.org | APTTrail |
| Domain | envio1414.duckdns.org | APTTrail |
| Domain | envio19-05.duckdns.org | APTTrail |
| Domain | envio21-05.duckdns.org | APTTrail |
| Domain | envio2333.duckdns.org | APTTrail |
| Domain | envio26-03.duckdns.org | APTTrail |
| Domain | envio28-003.duckdns.org | APTTrail |
| Domain | envio29.duckdns.org | APTTrail |
| Domain | envio31-03.duckdns.org | APTTrail |
| Domain | equipo.linkpc.net | APTTrail |
| Domain | febenvi.duckdns.org | APTTrail |
| Domain | giraffebear.polycomusa.com | APTTrail |
| Domain | hellmagers.polycomusa.com | APTTrail |
| Domain | host-rami.polycomusa.com | APTTrail |
Referencias
- https://gist.github.com/kirk-sayre-work/354d875086bb533b3095dc06b7537869
- https://mp.weixin.qq.com/s/-7U1-NTP0EdVOtptzbHUsg (Chinese)
- https://otx.alienvault.com/pulse/64419d343c9d98fc279185f7
- https://research.checkpoint.com/2023/blindeagle-targeting-ecuador-with-sharpened-tools/
- https://ti.360.net/blog/articles/apt-c-36-continuous-attacks-targeting-colombian-government-institutions-and-corporations-en/
- https://tria.ge/220314-3qe5padgh2
- https://tria.ge/230506-mbyeqagg43/behavioral1
- https://tria.ge/230506-mdhr2sgg55/behavioral2
- https://twitter.com/0xToxin/status/1654802474534830080
- https://twitter.com/1ZRR4H/status/1503572957595111427
- https://twitter.com/HONKONE_K/status/1145536069435195392
- https://twitter.com/Joseliyo_Jstnk/status/1654038642489442304