Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a APT BAHAMUT. Aliases observados: APT BAHAMUT. Conteo por tipo: domain: 175, file_path: 6, ipv4: 14, url: 1.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | 32e6dwbbpg.de | APTTrail |
| Domain | 32player.com | APTTrail |
| Domain | 5iw68rugwfcir37uj8z3r6rfaxwd8g8cdcfcqw62.de | APTTrail |
| Domain | 96r1yh643o.de | APTTrail |
| Domain | account-googie.com | APTTrail |
| Domain | accountvalidate.com | APTTrail |
| Domain | airfitgym.com | APTTrail |
| Domain | ambicluster.com | APTTrail |
| Domain | appswonder.info | APTTrail |
| Domain | aspnet.dyndns.info | APTTrail |
| Domain | aspnet.dyndns.infoassurecom.info | APTTrail |
| Domain | assurecom.info | APTTrail |
| Domain | ay3a9j7pc3.de | APTTrail |
| Domain | bulletinalerts.com | APTTrail |
| Domain | by4mode.com | APTTrail |
| Domain | capsnit.com | APTTrail |
| Domain | cdn-icloud.co | APTTrail |
| Domain | cdn-icloud.cocelebsnightmares.com | APTTrail |
| Domain | cdw1ir0dc9g3dwl5oh1y.de | APTTrail |
| Domain | celebsnightmares.com | APTTrail |
| Domain | citrusquad.com | APTTrail |
| Domain | classmunch.com | APTTrail |
| Domain | cloud-authorize.com | APTTrail |
| Domain | cocahut.com | APTTrail |
| Domain | cocelebsnightmares.com | APTTrail |
| Domain | cocoka.info | APTTrail |
| Domain | cocoka.infocrawloofle.com | APTTrail |
| Domain | cohealthclubfun.com | APTTrail |
| Domain | crawloofle.com | APTTrail |
| Domain | cyroonline.com | APTTrail |
Referencias
- https://about.fb.com/wp-content/uploads/2023/05/Meta-Quarterly-Adversarial-Threat-Report-Q1-2023.pdf
- https://blog.talosintelligence.com/2018/07/Mobile-Malware-Campaign-uses-Malicious-MDM-Part2.html
- https://mp.weixin.qq.com/s/YAAybJBAvxqrQWYDg31BBw?_x_tr_sl=zh-CN&_x_tr_tl=en&_x_tr_hl=zh-CN
- https://otx.alienvault.com/pulse/5f7dd394005536c84adbaf56
- https://otx.alienvault.com/pulse/625591f0fdef5bd852d84afe
- https://otx.alienvault.com/pulse/63809fb03dacd453ae69d37b
- https://otx.alienvault.com/pulse/6552657c0e444a423248f10c
- https://pastebin.com/9U57CHZn
- https://threatfox.abuse.ch/browse/malware/apk.bahamut/
- https://twitter.com/0x6rsk/status/1656554067160702982
- https://twitter.com/BaoshengbinCumt/status/1656577909224796161
- https://twitter.com/Circuitous__/status/1377767299709550593