Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a APT 30. Aliases observados: APT 30. Conteo por tipo: domain: 15, file_path: 2, ipv4: 4, url: 1.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | appsecnic.com | APTTrail |
| Domain | aseanm.com | APTTrail |
| Domain | autoapec.com | APTTrail |
| Domain | bigfixtools.com | APTTrail |
| Domain | bluesixnine.com | APTTrail |
| Domain | cbkjdxf.com | APTTrail |
| Domain | creammemory.com | APTTrail |
| Domain | gordeneyes.com | APTTrail |
| Domain | iapfreecenter.com | APTTrail |
| Domain | kabadefender.com | APTTrail |
| Domain | km-nyc.com | APTTrail |
| Domain | km153.com | APTTrail |
| Domain | lisword.com | APTTrail |
| Domain | newpresses.com | APTTrail |
| Domain | techmicrost.com | APTTrail |
| FILE_PATH | /clntcmd.php | APTTrail |
| FILE_PATH | /clntsignin.php | APTTrail |
| IP | 103.233.10.152:3306 | APTTrail |
| IP | 103.233.10.152:4433 | APTTrail |
| IP | 103.233.10.152:8080 | APTTrail |
| IP | 172.247.197.189:443 | APTTrail |
| URL | http://103.233.10.152 | APTTrail |
Referencias
- https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2015/05/20081935/rpt-apt30.pdf
- https://twitter.com/3XS0/status/1253426730217291778 (# Lecna/BACKSPACE, NETEAGLE)
- https://twitter.com/Vishnyak0v/status/1252495730486456321
- https://www.ptsecurity.com/ww-en/analytics/pt-esc-threat-intelligence/eagle-eye-is-back-apt30/
- https://www.virustotal.com/gui/ip-address/103.233.10.152/relations