Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a APT CALYPSO. Aliases observados: APT CALYPSO. Conteo por tipo: domain: 30, ipv4: 3, url: 5.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | aztecoo.com | APTTrail |
| Domain | blog.globnewsline.com | APTTrail |
| Domain | clark.l8t.net | APTTrail |
| Domain | dealsgle.com | APTTrail |
| Domain | draconess.com | APTTrail |
| Domain | etheraval.com | APTTrail |
| Domain | globnewsline.com | APTTrail |
| Domain | krgod.qqm8.com | APTTrail |
| Domain | mail.globnewsline.com | APTTrail |
| Domain | mail.sultris.com | APTTrail |
| Domain | membrig.com | APTTrail |
| Domain | pop3.wordmoss.com | APTTrail |
| Domain | prowesoo.com | APTTrail |
| Domain | r01.etheraval.com | APTTrail |
| Domain | rawfuns.com | APTTrail |
| Domain | rosyfund.com | APTTrail |
| Domain | streleases.com | APTTrail |
| Domain | sultris.com | APTTrail |
| Domain | surfanny.com | APTTrail |
| Domain | tc.streleases.com | APTTrail |
| Domain | teldcomtv.com | APTTrail |
| Domain | tv.teldcomtv.com | APTTrail |
| Domain | usergetacss.com | APTTrail |
| Domain | uv.usergetacss.com | APTTrail |
| Domain | waxgon.com | APTTrail |
| Domain | webmail.surfanny.com | APTTrail |
| Domain | wordmoss.com | APTTrail |
| Domain | yolkish.com | APTTrail |
| Domain | youtubemail.club | APTTrail |
| Domain | zmail.wordmoss.com | APTTrail |
Referencias
- https://otx.alienvault.com/pulse/60638f7aff63f9956797e899
- https://otx.alienvault.com/pulse/6267dbe17cdc91a784b256d6
- https://st.drweb.com/static/new-www/news/2022/march/telecom_research_en.pdf
- https://twitter.com/TI_ESC/status/1264843775232421888
- https://www.ptsecurity.com/upload/corporate/ww-en/analytics/calypso-apt-2019-eng.pdf
- https://www.ptsecurity.com/ww-en/analytics/calypso-apt-2019/
- https://www.recordedfuture.com/chinese-group-calypso-exploiting-microsoft-exchange/
- https://www.virustotal.com/gui/file/a32b3e0f9b0daaaea6ddda9875f463ff100a28005eb66a03c0308a1820787fce/detection
- https://www.virustotal.com/gui/file/aea4d3d01ab9a564ca12af0d1a8b5eecb381a409b30b3ac8fee13f85f8e8db24/detection
- https://www.virustotal.com/gui/ip-address/46.105.227.110/relations