Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a apt-c-40. Aliases observados: apt-c-40, apt40, leviathan, mudcarp, periscope. Conteo por tipo: domain: 61, file_path: 2, url: 7.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | accountsx.bounceme.net | APTTrail |
| Domain | api.dreamsbottle.com | APTTrail |
| Domain | appexistence.com | APTTrail |
| Domain | armybar.hopto.org | APTTrail |
| Domain | australianmorningnews.com | APTTrail |
| Domain | bbranchs.com | APTTrail |
| Domain | byfleur.myftp.org | APTTrail |
| Domain | cankerscarcass.com | APTTrail |
| Domain | capitana.onthewifi.com | APTTrail |
| Domain | cdn.aexhausts.com | APTTrail |
| Domain | chemscalere.com | APTTrail |
| Domain | cm.musicandfile.com | APTTrail |
| Domain | cnnzapmeta.com | APTTrail |
| Domain | dexercisep.com | APTTrail |
| Domain | duutsxlydw.com | APTTrail |
| Domain | dynamics.ddnsking.com | APTTrail |
| Domain | eujinonline.sytes.net | APTTrail |
| Domain | goo2k88yyh2.chickenkiller.com | APTTrail |
| Domain | guardggg.com | APTTrail |
| Domain | heraldsun.me | APTTrail |
| Domain | iherlvufjknw.com | APTTrail |
| Domain | image.australianmorningnews.com | APTTrail |
| Domain | ja.iherlvufjknw.com | APTTrail |
| Domain | katy197.chickenkiller.com | APTTrail |
| Domain | kulkarni.bounceme.net | APTTrail |
| Domain | laodailylive.com | APTTrail |
| Domain | laodata.network | APTTrail |
| Domain | laodiplomat.com | APTTrail |
| Domain | laotranslations.com | APTTrail |
| Domain | mail2.ignorelist.com | APTTrail |
Referencias
- https://github.com/ti-research-io/ti/blob/main/ioc_extender/ET_Gh0st_Variant.json
- https://medium.com/@Sebdraven/apt-40-in-malaysia-61ed9c9642e9
- https://otx.alienvault.com/pulse/5ca740c67a9dbc78fe32f9b9
- https://otx.alienvault.com/pulse/5e3dbad21b45e958a0d9e5a6
- https://otx.alienvault.com/pulse/5efa1262602caffb4ac35148
- https://otx.alienvault.com/pulse/60f597533e911956a673717b
- https://otx.alienvault.com/pulse/61b2290ee7cb4628d56979d5
- https://twitter.com/ClearskySec/status/1110941178231484417
- https://twitter.com/Vishnyak0v/status/1203986670623887361
- https://us-cert.cisa.gov/ncas/alerts/aa21-200a
- https://www.accenture.com/t20190305T200954Z__w__/us-en/_acnmedia/PDF-96/Accenture-Security-MUDCARP-Full-Report.pdf
- https://www.elastic.co/fr/blog/advanced-techniques-used-in-malaysian-focused-apt-campaign