Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a APT 18. Aliases observados: APT 18. Conteo por tipo: domain: 14, ipv4: 1, url: 2.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | 128.er1620.com | APTTrail |
| Domain | 223-25-233-248.revdns.8toinfinity.com.sg | APTTrail |
| Domain | admin.er1620.com | APTTrail |
| Domain | exp0day.com | APTTrail |
| Domain | ftp.exp0day.com | APTTrail |
| Domain | gmail.bkz88.com | APTTrail |
| Domain | good.myftp.org | APTTrail |
| Domain | hello.mjw.bz | APTTrail |
| Domain | info.imly.org | APTTrail |
| Domain | login.3bz.org | APTTrail |
| Domain | logo.mjw.bz | APTTrail |
| Domain | suck.er1620.com | APTTrail |
| Domain | test.3bz.org | APTTrail |
| Domain | zip.redirectme.net | APTTrail |
| IP | 223.25.233.248:8080 | APTTrail |
| URL | http://137.175.4.132 | APTTrail |
| URL | http://223.25.233.248 | APTTrail |
Referencias
- https://github.com/fireeye/iocs/blob/master/APT18/0ae061d7-c624-4a84-8adf-00281b97797b.ioc
- https://www.fireeye.com/blog/threat-research/2015/07/demonstrating_hustle.html (# APT18's campaign)
- https://www.virustotal.com/gui/ip-address/137.175.4.132/relations
- https://www.virustotal.com/gui/ip-address/223.25.233.248/relations