Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a apt-c-43. Aliases observados: apt-c-43, apt43. Conteo por tipo: domain: 34, ipv4: 2, url: 1.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | 6e24a5fb.ngrok.io | APTTrail |
| Domain | adtiomtardecessd.zapto.org | APTTrail |
| Domain | agaliarept.com | APTTrail |
| Domain | artyomt.com | APTTrail |
| Domain | asymmetricfile.blogspot.com | APTTrail |
| Domain | blogwhereyou.com | APTTrail |
| Domain | ceofanb18.mipropia.com | APTTrail |
| Domain | correomindefensagobvemyspace.com | APTTrail |
| Domain | djcaps.gotdns.ch | APTTrail |
| Domain | f9527d03.ngrok.io | APTTrail |
| Domain | frejabe.com | APTTrail |
| Domain | funkytothemoon.live | APTTrail |
| Domain | grannegral.com | APTTrail |
| Domain | great-jepsen.51-79-62-98.plesk.page | APTTrail |
| Domain | intelligent-archimedes.51-79-62-98.plesk.page | APTTrail |
| Domain | java.serveblog.net | APTTrail |
| Domain | koliast.com | APTTrail |
| Domain | lawyersofficial.mipropia.com | APTTrail |
| Domain | mcsi.gotdns.ch | APTTrail |
| Domain | op-icaro.site | APTTrail |
| Domain | plushbr.com | APTTrail |
| Domain | pompst.store | APTTrail |
| Domain | postinfomatico.blogspot.com | APTTrail |
| Domain | pumapomp.store | APTTrail |
| Domain | sangeet1.000webhostapp.com | APTTrail |
| Domain | skyscopeups.cfd | APTTrail |
| Domain | soldatenkovarten.com | APTTrail |
| Domain | solutionconect.online | APTTrail |
| Domain | surgutneftegazappstore.com | APTTrail |
| Domain | tobabean.expert | APTTrail |
Referencias
- https://app.validin.com/detail?find=212.224.107.244&type=ip4&ref_id=ee39f8a47e5#tab=resolutions
- https://app.validin.com/detail?find=43.240.239.76&type=ip4&ref_id=c3e81320c9c#tab=resolutions
- https://blog.360totalsecurity.com/en/apt-c-43-steals-venezuelan-military-secrets-to-provide-intelligence-support-for-the-reactionaries-hpreact-campaign/
- https://otx.alienvault.com/pulse/5d4818218a872ad45f4d4e85
- https://otx.alienvault.com/pulse/624c29baad734a210134b02c
- https://research.checkpoint.com/2022/state-sponsored-attack-groups-capitalise-on-russia-ukraine-war-for-cyber-espionage/
- https://securelist.com/el-machete/66108/
- https://twitter.com/ShadowChasing1/status/1382869518830039041
- https://twitter.com/ShadowChasing1/status/1382869522965667840
- https://www.virustotal.com/gui/file/29f8fac13d1500c521ebcd6213e3c4316bd2097a2824f967c66ec74a432ce9ee/detection
- https://www.virustotal.com/gui/file/813c8b8b43be5a928a5cd841bea08d7d5453ab8a1196e3c81abd7a144027247b/detection
- https://www.virustotal.com/gui/file/825a9c8312acaf025e3389391811d5de212db4886f9ffd9392beeeed63d1223d/detection