Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a apt-c-06. Aliases observados: apt-c-06, apt06, thinmon. Conteo por tipo: domain: 314, file_path: 7, ipv4: 3, url: 2.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | 100100011100.com | APTTrail |
| Domain | 163pics.net | APTTrail |
| Domain | 163services.com | APTTrail |
| Domain | 42world.net | APTTrail |
| Domain | 779999977.com | APTTrail |
| Domain | 88dafa.biz | APTTrail |
| Domain | academyhouse.us | APTTrail |
| Domain | account163-mail.com | APTTrail |
| Domain | ackr.myvnc.com | APTTrail |
| Domain | acrobatup.com | APTTrail |
| Domain | adobearm.com | APTTrail |
| Domain | adobeplugs.net | APTTrail |
| Domain | adoberegister.flashserv.net | APTTrail |
| Domain | adobeupdates.com | APTTrail |
| Domain | albasrostga.com | APTTrail |
| Domain | alexa97.com | APTTrail |
| Domain | alphacranes.com | APTTrail |
| Domain | alphastros.com | APTTrail |
| Domain | amanity50.biz | APTTrail |
| Domain | anti-wars.org | APTTrail |
| Domain | appfreetools.com | APTTrail |
| Domain | apple-onlineservice.com | APTTrail |
| Domain | applyinfo.org | APTTrail |
| Domain | auto2115.icr38.net | APTTrail |
| Domain | auto2116.phpnet.us | APTTrail |
| Domain | auto24col.info | APTTrail |
| Domain | autobaba.net84.net | APTTrail |
| Domain | autoban.phpnet.us | APTTrail |
| Domain | autobicy.yaahosting.info | APTTrail |
| Domain | autobicycle.20x.cc | APTTrail |
Referencias
- http://blog.nsfocus.net/darkhotel-3-0908/
- http://securelist.com/blog/research/66779/the-darkhotel-apt/
- https://blogs.jpcert.or.jp/ja/2019/05/darkhotel_lnk.html (Japanese)
- https://insight-jp.nttsecurity.com/post/102ho8o/operation-restylink (Japanese)
- https://mp.weixin.qq.com/s/nyxZFXgrtm2-tBiV3-wiMg
- https://otx.alienvault.com/pulse/5cee9ffe72473a4c259773b7
- https://otx.alienvault.com/pulse/5dbc5ca2e4310e29af9612e3
- https://otx.alienvault.com/pulse/5f34088f58d80664ae9fbd1c
- https://otx.alienvault.com/pulse/627b9aa3b3842d989f57bfe6
- https://researchcenter.paloaltonetworks.com/2018/09/unit42-traps-prevents-wild-vbscript-zero-day-exploit-internet-explorer/
- https://s.tencent.com/research/report/741.html (Chinese)
- https://securelist.com/chrome-0-day-exploit-cve-2019-13720-used-in-operation-wizardopium/94866/