Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a apt-31. Aliases observados: apt-31, bronze vinewood, zirconium. Conteo por tipo: domain: 24, ipv4: 1.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | api.flushcdn.com | APTTrail |
| Domain | api.hostupoeui.com | APTTrail |
| Domain | api.last-key.com | APTTrail |
| Domain | be-government.com | APTTrail |
| Domain | cdn.microsoft-official.com | APTTrail |
| Domain | const.be-government.com | APTTrail |
| Domain | drmtake.tk | APTTrail |
| Domain | edgecloudc.com | APTTrail |
| Domain | flushcdn.com | APTTrail |
| Domain | gitcloudcache.com | APTTrail |
| Domain | hostupoeui.com | APTTrail |
| Domain | inst.rsnet-devel.com | APTTrail |
| Domain | intranet-rsnet.com | APTTrail |
| Domain | last-key.com | APTTrail |
| Domain | microsoft-products.com | APTTrail |
| Domain | office.microsoft-products.com | APTTrail |
| Domain | offline-microsoft.com | APTTrail |
| Domain | p1.offline-microsoft.com | APTTrail |
| Domain | portal.intranet-rsnet.com | APTTrail |
| Domain | portal.super-encrypt.com | APTTrail |
| Domain | rsnet-devel.com | APTTrail |
| Domain | super-encrypt.com | APTTrail |
| Domain | wshnews.com | APTTrail |
| Domain | yandexpro.net | APTTrail |
| IP | 20.11.11.67:443 | APTTrail |
Referencias
- https://otx.alienvault.com/pulse/610a40dee36aae4fcd35e9cf
- https://twitter.com/h2jazi/status/1519769353297747970
- https://www.cert.ssi.gouv.fr/uploads/CERTFR-2021-CTI-013.pdf
- https://www.ptsecurity.com/ww-en/analytics/pt-esc-threat-intelligence/apt31-cloud-attacks/
- https://www.ptsecurity.com/ww-en/analytics/pt-esc-threat-intelligence/apt31-new-attacks/
- https://www.secureworks.com/research/bronz-vinewood-uses-hanaloader-to-target-government-supply-chain
- https://www.virustotal.com/gui/file/33f136069d7c3a030b2e0738a5ee80d442dee1a202f6937121fa4e92a775fead/detection
- https://www.virustotal.com/gui/file/c4343d5a53495095cf0d44c308c2bb6ad1a10ccf97aef62e49ae03c27d980c5d/detection
- https://www.virustotal.com/gui/file/efdbb19fb65bcf5c4a8feb3eab784682d01f3e75f711674e4d469d4dfe4a21f3/detection
- https://www.virustotal.com/gui/ip-address/31.192.107.152/relations