Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a apt 27. Aliases observados: apt 27, apt27, bronze union, cycldek, emissary panda, emissary panda, goblin panda, group 35, iron tiger, luckymouse, temp.hippo, tg-3390. Conteo por tipo: domain: 171, ipv4: 21, url: 15.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | 24h.tinthethaoi.com | APTTrail |
| Domain | 265g.site | APTTrail |
| Domain | 36106g.com | APTTrail |
| Domain | 88tech.me | APTTrail |
| Domain | activity.maacson.com | APTTrail |
| Domain | adobesys.com | APTTrail |
| Domain | aibeichen.cn | APTTrail |
| Domain | amazonawsgarages.com | APTTrail |
| Domain | analyaze.s3amazonbucket.com | APTTrail |
| Domain | analysis.windowstearns.com | APTTrail |
| Domain | api.youkesdt.asia | APTTrail |
| Domain | atlas-sian.net | APTTrail |
| Domain | awvsf7esh.dellrescue.com | APTTrail |
| Domain | bbs.maacson.com | APTTrail |
| Domain | bbs.sonypsps.com | APTTrail |
| Domain | buy.teamviewsoft.com | APTTrail |
| Domain | cat.toonganuh.com | APTTrail |
| Domain | cdn.laokpl.com | APTTrail |
| Domain | center.veryssl.org | APTTrail |
| Domain | chatsecure.uk.to | APTTrail |
| Domain | chatsecurelite.uk.to | APTTrail |
| Domain | chatsecurelite.us.to | APTTrail |
| Domain | chinhsech.com | APTTrail |
| Domain | chototem.com | APTTrail |
| Domain | chrome-upgrade.com | APTTrail |
| Domain | ckvyk.com | APTTrail |
| Domain | ckvyk.net | APTTrail |
| Domain | cloud.cutepaty.com | APTTrail |
| Domain | cloudservicesdevc.tk | APTTrail |
| Domain | coco.sodexoa.com | APTTrail |
Referencias
- https://app.any.run/tasks/949f2624-505c-4f10-a304-1671492f9a22/
- https://blog.eclecticiq.com/chinese-state-sponsored-cyber-espionage-activity-targeting-semiconductor-industry-in-east-asia
- https://blogs.quickheal.com/apt-27-like-newcore-rat-virut-exploiting-mysql-targeted-attacks-enterprise/
- https://cofense.com/blog/open-source-gh0st-rat-still-haunting-inboxes-15-years-after-release/
- https://docs.google.com/document/d/1oYX3uN6KxIX_StzTH0s0yFNNoHDnV8VgmVqU5WoeErc (2018-06-21: EmissaryPanda waterhole in Mongolia's president and parliament websites)
- https://marcoramilli.com/2020/03/19/is-apt27-abusing-covid-19-to-attack-people/
- https://medium.com/@Sebdraven/gobelin-panda-against-the-bears-1f462d00e3a4
- https://medium.com/@Sebdraven/goblin-panda-changes-the-dropper-and-reused-the-old-infrastructure-a35915f3e37a
- https://medium.com/@Sebdraven/goblin-panda-continues-to-target-vietnam-bc2f0f56dcd6
- https://medium.com/@Sebdraven/malicious-document-targets-vietnamese-officials-acb3b9d8b80a
- https://medium.com/@Sebdraven/rtf-royal-road-drops-a-new-backdoor-mfc-and-links-with-goblin-panda-90db06f80611
- https://meltx0r.github.io/tech/2019/09/19/emissary-panda-apt.html