Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a apt-5. Aliases observados: apt-5, apt5, pittypanda, ptiger, ptrat. Conteo por tipo: domain: 16.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | acers.com.tw | APTTrail |
| Domain | avstore.com.tw | APTTrail |
| Domain | dopodo.com.tw | APTTrail |
| Domain | foxcom.com.tw | APTTrail |
| Domain | helosaf.com.tw | APTTrail |
| Domain | killerhost.skypetm.com.tw | APTTrail |
| Domain | kimoo.com.tw | APTTrail |
| Domain | lightening.com.tw | APTTrail |
| Domain | newb02.skypetm.com.tw | APTTrail |
| Domain | paccfic.com | APTTrail |
| Domain | seed01.com.tw | APTTrail |
| Domain | skypetm.com.tw | APTTrail |
| Domain | stareastnet.com.tw | APTTrail |
| Domain | symantecs.com.tw | APTTrail |
| Domain | trendmicro.org.tw | APTTrail |
| Domain | trendmicroup.com | APTTrail |
Referencias
- https://apt.thaicert.or.th/cgi-bin/showcard.cgi?g=PittyTiger%2C%20Pitty%20Panda
- https://github.com/rsmudge/Malleable-C2-Profiles/blob/master/APT/pitty_tiger.profile
- https://paper.seebug.org/papers/APT/APT_CyberCriminal_Campagin/2014/2014.07.11.Pitty_Tiger/Pitty_Tiger_Final_Report.pdf
- https://www.virustotal.com/gui/file/388d46cd5bed2c08c2bd90fa0cec35c90f9e4728579d639cce9ace75a20990be/detection