Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a APT COLDWASTREL. Aliases observados: APT COLDWASTREL. Conteo por tipo: domain: 105.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | account-api.cloudstorageservice.online | APTTrail |
| Domain | account-api.onlinestorageroute.space | APTTrail |
| Domain | account-api.protondrive.online | APTTrail |
| Domain | account.email-pm.me | APTTrail |
| Domain | account.onlinestorageroute.space | APTTrail |
| Domain | account.open-button.com | APTTrail |
| Domain | account.proton-drive.me | APTTrail |
| Domain | account.proton-service.services | APTTrail |
| Domain | account.proton-verify.me | APTTrail |
| Domain | account.proton.shared-urls.me | APTTrail |
| Domain | account.protondrive.cloud | APTTrail |
| Domain | account.protondrive.online | APTTrail |
| Domain | account.protondrive.onlinestorageroute.space | APTTrail |
| Domain | account.protondrive.services | APTTrail |
| Domain | account.secure-pm.me | APTTrail |
| Domain | account.service-pm.me | APTTrail |
| Domain | account.service-proton.com | APTTrail |
| Domain | account.service-proton.me | APTTrail |
| Domain | account.services-proton.me | APTTrail |
| Domain | accounts-proton.me | APTTrail |
| Domain | accounts.support-ukr.net | APTTrail |
| Domain | center-facebook.com | APTTrail |
| Domain | civic-synergy.online | APTTrail |
| Domain | cloudstorageservice.online | APTTrail |
| Domain | decryptor.me | APTTrail |
| Domain | desktop-facebook.com | APTTrail |
| Domain | document-decryption.me | APTTrail |
| Domain | drive-proton.com | APTTrail |
| Domain | drive.link-pm.me | APTTrail |
| Domain | drive.proton-verify.me | APTTrail |
Referencias
- https://app.validin.com/detail?find=38.180.18.59&type=ip4&ref_id=3160b1058e5#tab=resolutions
- https://app.validin.com/detail?type=ip&find=38.180.87.136#tab=resolutions
- https://citizenlab.ca/2024/08/sophisticated-phishing-targets-russias-perceived-enemies-around-the-globe/
- https://en.fofa.info/result?qbase64=aGVhZGVyX2hhc2g9Ii0xNjkyOTY3NzM4IiAmJiBzZXJ2ZXI9PSJuZ2lueC8xLjE4LjAiICYmIGFzbj0iMjA2ODA0Ig%3D%3D
- https://en.fofa.info/result?qbase64=aGVhZGVyX2hhc2g9IjY1ODMyNjkwMSIgJiYgamFybT0iMjdkNDBkNDBkMDAwNDBkMDAwNDJkNDNkMDAwMDAwNGFjMjRlNzdkNzY2NDY4NjdmMGY2YTBjNmQ5YjliYjAiICYmIHNlcnZlcj09Im5naW54LzEuMTguMCIgJiYgaXA9IjM4LjE4MC44Ni44Ny8xNiI%3D
- https://search.censys.io/certificates/d15350021f0ecc2faf863db6c41dbc415b4c85bf17d5d0f94785ea890fda3cc0
- https://www.pwc.com/gx/en/issues/cybersecurity/cyber-threat-intelligence/coldwastrel-space.html
- https://www.virustotal.com/gui/file/4a9a2c2926b7b8e388984d38cb9e259fb4060cccc2d291c7910be030ae5301a3/detection
- https://www.virustotal.com/gui/ip-address/38.180.18.236/relations
- https://www.virustotal.com/gui/ip-address/38.180.86.201/relations
- https://www.virustotal.com/gui/ip-address/38.180.86.87/relations
- https://www.virustotal.com/gui/ip-address/45.133.195.117/relations