Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a APT-C-55. Aliases observados: APT-C-55, Black Banshee, HancomAgent, HttpTroy, Larva-25004, RftRAT, UAT-5394, Velvet Chollima, archipelago, blindingcan, comebacker, emerald sleet. Conteo por tipo: domain: 23699, file_path: 295, ipv4: 87, url: 71.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | 00701111.000webhostapp.com | APTTrail |
| Domain | 00a7c185.duckdns.org | APTTrail |
| Domain | 00pr43.picid1fdl6.dynv6.net | APTTrail |
| Domain | 01nservercc.cfd | APTTrail |
| Domain | 01onlinen.cfd | APTTrail |
| Domain | 022hucku25u.dns.navy | APTTrail |
| Domain | 02nservercc.cfd | APTTrail |
| Domain | 02onlinen.cfd | APTTrail |
| Domain | 03nservercc.cfd | APTTrail |
| Domain | 03onlinen.cfd | APTTrail |
| Domain | 04nservercc.cfd | APTTrail |
| Domain | 04onlinen.cfd | APTTrail |
| Domain | 059879e5-b2e8-4f58-aa46-95f69d92aa34.random.onlinenhiscomservice.store | APTTrail |
| Domain | 059879e5-b2e8-4f58-aa46-95f69d92aa34.random.voranstaks.shop | APTTrail |
| Domain | 05c0.nkfumxgqxd.v6.rocks | APTTrail |
| Domain | 05nservercc.cfd | APTTrail |
| Domain | 05onlinen.cfd | APTTrail |
| Domain | 06nservercc.cfd | APTTrail |
| Domain | 06onlinen.cfd | APTTrail |
| Domain | 0751u9n4lg.v6.rocks | APTTrail |
| Domain | 07nservercc.cfd | APTTrail |
| Domain | 07onlinen.cfd | APTTrail |
| Domain | 086k3a.93vf4b71cv.dynv6.net | APTTrail |
| Domain | 08nservercc.cfd | APTTrail |
| Domain | 08onlinen.cfd | APTTrail |
| Domain | 090.apollo-page.kro.kr | APTTrail |
| Domain | 090.gov5nikisa.kro.kr | APTTrail |
| Domain | 09nservercc.cfd | APTTrail |
| Domain | 09onlinen.cfd | APTTrail |
| Domain | 0a1fi7nsne.dynv6.net | APTTrail |
Referencias
- https://app.any.run/tasks/166bb71d-0998-46cf-844b-3cd263bef4bd
- https://app.any.run/tasks/74d55d02-7bbd-444c-a01b-30ac52a7e576/
- https://app.any.run/tasks/f4172853-90e6-49ad-be7b-bf6efa771448/
- https://app.validin.com/axon?find=141.164.50.204&type=ip
- https://app.validin.com/axon?find=141.164.52.102&type=ip
- https://app.validin.com/axon?find=158.247.227.83&type=ip
- https://app.validin.com/axon?find=27.10.16.4&type=ip
- https://app.validin.com/axon?find=27.102.106.48&type=ip
- https://app.validin.com/axon?source=DNS&limit=100&type=ip&find=141.164.60.65
- https://app.validin.com/axon?source=DNS&limit=100&type=ip&find=216.189.159.197
- https://app.validin.com/axon?source=DNS&type=ip&find=141.164.43.213
- https://app.validin.com/axon?source=DNS&type=ip&find=141.164.49.199