Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a apt-c-01. Aliases observados: apt-c-01, poison ivy. Conteo por tipo: domain: 183, ipv4: 4, url: 2.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | 126mailserver.serveftp.com | APTTrail |
| Domain | 143-244-183-240.cprapid.com | APTTrail |
| Domain | 360urlscan.com | APTTrail |
| Domain | 64-176-165-42.cprapid.com | APTTrail |
| Domain | 6c99b2c4cf5a.expolebanon.com | APTTrail |
| Domain | access.webplurk.com | APTTrail |
| Domain | accounts126.com | APTTrail |
| Domain | afte856422126.com | APTTrail |
| Domain | aliago.dyndns.dk | APTTrail |
| Domain | annie165.zyns.com | APTTrail |
| Domain | app.newfacebk.com | APTTrail |
| Domain | as1688.webhop.org | APTTrail |
| Domain | atrew56877.com | APTTrail |
| Domain | avdsart.com | APTTrail |
| Domain | babana.wikaba.com | APTTrail |
| Domain | backaaa.beijingdasihei.com | APTTrail |
| Domain | bearingonly.rebatesrule.net | APTTrail |
| Domain | bribieislandhistory.com | APTTrail |
| Domain | bt0116.servebbs.net | APTTrail |
| Domain | buendnis-fuer-kinder.com | APTTrail |
| Domain | caac-cn.com | APTTrail |
| Domain | caac-cn.org | APTTrail |
| Domain | canberk.gecekodu.com | APTTrail |
| Domain | ceepitbj.servepics.com | APTTrail |
| Domain | censor.site | APTTrail |
| Domain | center-gai.com | APTTrail |
| Domain | certifications.services | APTTrail |
| Domain | chamber.icu | APTTrail |
| Domain | check.blogdns.com | APTTrail |
| Domain | china.serveblog.net | APTTrail |
Referencias
- https://hunt.io/blog/greenspot-apt-targets-163com-fake-downloads-spoofing
- https://mp.weixin.qq.com/s/6wVfE9SE3wVuazxVppe3tA
- https://threatbook.io/domain/download163ease.com
- https://ti.360.net/uploads/2018/09/20/6f8ad451646c9eda1f75c5d31f39f668.pdf (Chinese)
- https://twitter.com/RedDrip7/status/1118009381679878144
- https://twitter.com/ThreatBookLabs/status/1613735997363359745
- https://twitter.com/ThreatBookLabs/status/1641631696742391808
- https://twitter.com/ThreatBookLabs/status/1645986803592347648
- https://twitter.com/ThreatBookLabs/status/1651978128439517185
- https://twitter.com/blackorbird/status/1293732897405378560
- https://www.virustotal.com/gui/domain/webplurk.com/relations
- https://www.virustotal.com/gui/file/534522b87f1158f28587f82b4df590546a004f17a648cfcff2bdcc5fc2cc3355/detection