Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a apt-c-50. Aliases observados: apt-c-50. Conteo por tipo: domain: 23, file_path: 13, ipv4: 1, url: 5.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | androidsecurityupdate.com | APTTrail |
| Domain | androidsystemsupdate.com | APTTrail |
| Domain | androidsystemswebview.com | APTTrail |
| Domain | appsoftupdate.com | APTTrail |
| Domain | arzdigitals.com | APTTrail |
| Domain | firmwaresystemupdate.com | APTTrail |
| Domain | georgethompson.space | APTTrail |
| Domain | googleassisstants.com | APTTrail |
| Domain | googleservicesforar.com | APTTrail |
| Domain | googleupdateservicese.com | APTTrail |
| Domain | googlextabv.com | APTTrail |
| Domain | lohefeshordeh.net | APTTrail |
| Domain | newportschoolupdateserver.com | APTTrail |
| Domain | ns1.googleassisstants.com | APTTrail |
| Domain | ns2.googleassisstants.com | APTTrail |
| Domain | padre914.com | APTTrail |
| Domain | ronaldlubbers.site | APTTrail |
| Domain | sarayemaghale.hami24.net | APTTrail |
| Domain | stevenwentz.com | APTTrail |
| Domain | systemdriverupdate.com | APTTrail |
| Domain | ychatonline.net | APTTrail |
| Domain | ydownyload.net | APTTrail |
| Domain | ynewnow.net | APTTrail |
| FILE_PATH | /farahv2.apk | APTTrail |
| FILE_PATH | /hass/answer.php | APTTrail |
| FILE_PATH | /hass/get-function.php | APTTrail |
| FILE_PATH | /hass/upload-log.php | APTTrail |
| FILE_PATH | /mmh/gt-func.php | APTTrail |
| FILE_PATH | /mmh/lg-upld.php | APTTrail |
| FILE_PATH | /mmh/on-answ.php | APTTrail |
Referencias
- https://github.com/ti-research-io/ti/blob/main/ioc_extender/ET_Lazarus.json
- https://mp.weixin.qq.com/s/yaLC8gs-U92X6WnYzuuQ7w
- https://otx.alienvault.com/pulse/5d9db01cc5328d4649e0594c
- https://research.checkpoint.com/domestic-kitten-an-iranian-surveillance-operation/
- https://twitter.com/blackorbird/status/1181868468620017665 (# Cyrus Attack)
- https://twitter.com/felixaime/status/1353622368913133569
- https://twitter.com/malwrhunterteam/status/1340344596698677250
- https://twitter.com/malwrhunterteam/status/1753545424508440994
- https://www.blackberry.com/content/dam/blackberry-com/asset/enterprise/pdf/direct/mobile-malware-report.pdf
- https://www.virustotal.com/gui/file/0d09d5e46e779d796a8d295043e5bbd90ac43705fa7ff7953faa5d8370840f93/detection
- https://www.virustotal.com/gui/file/3c273166c5221614198a7bbe0ed8ed0738ca4b62321a8d44a43fa7353a9f7d70/detection
- https://www.virustotal.com/gui/file/5e87acd4f1eca03e68df275b69bd0f79d328b29318abf25ae1e8ba6f238b34af/detection