Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a APT DRAGONOK. Aliases observados: APT DRAGONOK. Conteo por tipo: domain: 14.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | bbs.donkeyhaws.info | APTTrail |
| Domain | biosnews.info | APTTrail |
| Domain | busserh.mancely.com | APTTrail |
| Domain | donkeyhaws.info | APTTrail |
| Domain | ghostale.com | APTTrail |
| Domain | http.donkeyhaws.info | APTTrail |
| Domain | https.osakaintec.com | APTTrail |
| Domain | jpaols.com | APTTrail |
| Domain | moafee.com | APTTrail |
| Domain | ndbssh.com | APTTrail |
| Domain | php.marbletemps.com | APTTrail |
| Domain | pktmedia.com | APTTrail |
| Domain | skyppee.com | APTTrail |
| Domain | ycbackap.com | APTTrail |
Referencias
- http://www.morphick.com/resources/news/deep-dive-dragonok-rambo-backdoor
- https://app.any.run/tasks/ceb18346-8e01-4abe-89b9-97b44b14c9a0/
- https://app.validin.com/detail?find=153.234.67.222&type=ip4&ref_id=d4329fdcf8a#tab=resolutions
- https://researchcenter.paloaltonetworks.com/2015/04/unit-42-identifies-new-dragonok-backdoor-malware-deployed-against-japanese-targets/
- https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/wp-operation-quantum-entanglement.pdf
- https://www.lac.co.jp/english/report/2018/01/23_alert_01.html