Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a APT BLACKTECH. Aliases observados: APT BLACKTECH. Conteo por tipo: domain: 45, file_path: 2, ipv4: 5, url: 3.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | activate.linkblackclover.com | APTTrail |
| Domain | adobeupdate.serveusers.com | APTTrail |
| Domain | amazon.panasocin.com | APTTrail |
| Domain | centos.onthewifi.com | APTTrail |
| Domain | centos1.chinabrands.xyz | APTTrail |
| Domain | centos2.chinabrands.xyz | APTTrail |
| Domain | centosupdate.dynamic-dns.net | APTTrail |
| Domain | centosupdates.com | APTTrail |
| Domain | centrosupdate.proxydns.com | APTTrail |
| Domain | config.zapto.org | APTTrail |
| Domain | csp.fortinetline.com | APTTrail |
| Domain | em.totalpople.info | APTTrail |
| Domain | evergo.dnset.com | APTTrail |
| Domain | fibtec.jkub.com | APTTrail |
| Domain | fortinetline.com | APTTrail |
| Domain | gstrap.jkub.com | APTTrail |
| Domain | harb.bbsindex.com | APTTrail |
| Domain | herace.https443.org | APTTrail |
| Domain | idonotknow.lflinkup.com | APTTrail |
| Domain | idonotknow.lflinkup.net | APTTrail |
| Domain | idonotknow.serveusers.com | APTTrail |
| Domain | inkeslive.com | APTTrail |
| Domain | linuxhome.jkub.com | APTTrail |
| Domain | macfee-update.serveftp.com | APTTrail |
| Domain | microsoftonline.com.authorizeddns.net | APTTrail |
| Domain | microsoftvm.net | APTTrail |
| Domain | ns1001.centosupdates.com | APTTrail |
| Domain | office.panasocin.com | APTTrail |
| Domain | okinawas.ssl443.org | APTTrail |
| Domain | org.misecure.com | APTTrail |
Referencias
- https://app.validin.com/detail?find=212.115.54.194&type=ip4&ref_id=fd9bbd3c264#tab=resolutions (# 2025-03-01)
- https://blog.jpcert.or.jp/2018/06/plead-downloader-used-by-blacktech.html
- https://dmpdump.github.io/posts/Kivars/
- https://insight-jp.nttsecurity.com/post/102h7vx/blacktechflagpro (Japanese)
- https://otx.alienvault.com/pulse/5db0438c08e53c4d7931e3f4
- https://twitter.com/8th_grey_owl/status/1262047338006065155
- https://twitter.com/BushidoToken/status/1446602218170376199
- https://twitter.com/nahamike01/status/1467499135171710977
- https://twitter.com/nao_sec/status/1446277006690119681
- https://unit42.paloaltonetworks.com/bendybear-shellcode-blacktech/
- https://www.virustotal.com/gui/file/0931feef56951022c1559db77e5f01191a208ffb06f0a6f77597ba17b722de03/detection
- https://www.virustotal.com/gui/file/1286aa5c73cf2c8058c52271869a5727d71ca5bd4dd0854be970d2a25cb52bf8/detection