Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a APT 33. Aliases observados: APT 33. Conteo por tipo: domain: 99, ipv4: 1, url: 1.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | admindirector.com | APTTrail |
| Domain | akadnsplugin.com | APTTrail |
| Domain | alsalam.ddns.net | APTTrail |
| Domain | aramcojobs.ddns.net | APTTrail |
| Domain | availsqaapi.premieredigital.net | APTTrail |
| Domain | azure-dnszones.com | APTTrail |
| Domain | backupaccount.net | APTTrail |
| Domain | backupnet.ddns.net | APTTrail |
| Domain | becomestateman.com | APTTrail |
| Domain | bistbotsproxies.ddns.net | APTTrail |
| Domain | boeing.servehttp.com | APTTrail |
| Domain | businessscards.com | APTTrail |
| Domain | cardchsk.com | APTTrail |
| Domain | cardkuys.com | APTTrail |
| Domain | ceoadminoffice.com | APTTrail |
| Domain | chromup.com | APTTrail |
| Domain | customermgmt.net | APTTrail |
| Domain | dailystudy.org | APTTrail |
| Domain | digitalcodecrafters.com | APTTrail |
| Domain | diplomatsign.com | APTTrail |
| Domain | dyn-corp.ddns.net | APTTrail |
| Domain | dyncorp.ddns.net | APTTrail |
| Domain | eventmonitoring.org | APTTrail |
| Domain | fucksaudi.ddns.net | APTTrail |
| Domain | gefurrinn.com | APTTrail |
| Domain | global-careers.org | APTTrail |
| Domain | googlechromehost.ddns.net | APTTrail |
| Domain | googlmail.net | APTTrail |
| Domain | groupchiefexecutive.com | APTTrail |
| Domain | hellocookies.ddns.net | APTTrail |
Referencias
- https://app.any.run/tasks/c761d00f-4897-4c9e-8468-9172fcce21d7/
- https://blog.telsy.com/meeting-powerband-the-apt33-net-powerton-variant/
- https://blog.trendmicro.com/trendlabs-security-intelligence/more-than-a-dozen-obfuscated-apt33-botnets-used-for-extreme-narrow-targeting/
- https://go.recordedfuture.com/hubfs/reports/cta-2019-0626.pdf
- https://hyas.com/news/hunting-apt33-campaign-infrastructure/
- https://otx.alienvault.com/pulse/5d13cf4759eec0125b9d8ffa
- https://otx.alienvault.com/pulse/5d85272acd389e89e743368c
- https://otx.alienvault.com/pulse/5dcc25f17c401b08b33d3d84
- https://otx.alienvault.com/pulse/5dcd22740cea7974f1e9927b
- https://otx.alienvault.com/pulse/5e4430d06ed4c78cf4aa7872
- https://shadowdragon.io/blog/additional-insights-into-iranian-cyber-espionage-apt33-2/
- https://thehackernews.com/2023/12/microsoft-warns-of-new-falsefont.html