APTTrail: APT EARTHBERBEROKA indicators and references

Fecha
18 Jun 2026
Actor
apt-earthberberoka
Tipo
Ioc
Pais
Unknown
Sector
-
Confianza
high
100
Prioridad analitica
Alta

Basado en actor, pais, IOCs, TTPs, filtracion y calidad de contexto.

30IOCs
0TTPs
apt-earthberberokaActor
UnknownPais
Executive Summary
APTTrail mantiene indicadores publicos asociados a APT EARTHBERBEROKA. Aliases observados: APT EARTHBERBEROKA. Conteo por tipo: domain: 55, ipv4: 3.

Key Points

  • https://documents.trendmicro.com/assets/txt/earth-berberoka-domains-2.txt
  • https://g-soft.info/security/2196/earth-berberoka-apt-iocs/
  • https://otx.alienvault.com/pulse/62714f1a00e250a297938915
  • https://www.trendmicro.com/en_us/research/22/d/new-apt-group-earth-berberoka-targets-gambling-websites-with-old.html
  • https://www.virustotal.com/gui/file/2c403e390f59b2c2bfafde476dc18000b0ad1bbc8ac9ee0670662c48ba5b748f/detection

Resumen APTTrail

APTTrail mantiene indicadores publicos asociados a APT EARTHBERBEROKA. Aliases observados: APT EARTHBERBEROKA. Conteo por tipo: domain: 55, ipv4: 3.

Indicadores de Compromiso (IOCs)

TipoValorContexto
Domain1.googie.phAPTTrail
Domain12371829hkdanm.fbi.amAPTTrail
Domain1qw6etagydbn2peifj8hf.fbi.amAPTTrail
Domain2.googie.phAPTTrail
Domain3.googie.phAPTTrail
Domainadobe-flash.wikiAPTTrail
Domainadobe.nameAPTTrail
Domainagph.ivi66.netAPTTrail
Domainbos.github.wikiAPTTrail
Domaincaonimade.11i.meAPTTrail
Domaind.github.wikiAPTTrail
Domaindarknet.rootkit.toolsAPTTrail
Domaindarwin.github.wikiAPTTrail
Domaindownload.mircrosoftscoulds.comAPTTrail
Domaindust.github.wikiAPTTrail
Domainexmail.googie.com.phAPTTrail
Domainfbi.fuckbc.comAPTTrail
Domainflash.wy886066.comAPTTrail
Domainfuckbc.comAPTTrail
Domainfuckeryoumm.nmb.betAPTTrail
Domainfuckyou.fbi.amAPTTrail
Domaingb.googie.phAPTTrail
Domaingithub.wikiAPTTrail
Domaingoogie.com.phAPTTrail
Domaingoogie.phAPTTrail
Domainhelloword.11i.meAPTTrail
Domainhelloword.daj8.meAPTTrail
Domainhk.whoamis.infoAPTTrail
Domainhkdust.github.wikiAPTTrail
Domainhuaidan.fbi.amAPTTrail

Referencias

Diamond Model

Adversary
apt-earthberberoka
Ver perfil →
Victim
APTTrail: APT EARTHBERBEROKA indicators and references
Capability
Ioc
Infrastructure
1.googie.ph
12371829hkdanm.fbi.am
1qw6etagydbn2peifj8hf.fbi.am
2.googie.ph

Indicadores de Compromiso (IOCs)

TipoValorContextoOSINT
Domain 1.googie.ph APTTrail VT OffSec SOCRadar
Domain 12371829hkdanm.fbi.am APTTrail VT OffSec SOCRadar
Domain 1qw6etagydbn2peifj8hf.fbi.am APTTrail VT OffSec SOCRadar
Domain 2.googie.ph APTTrail VT OffSec SOCRadar
Domain 3.googie.ph APTTrail VT OffSec SOCRadar
Domain adobe-flash.wiki APTTrail VT OffSec SOCRadar
Domain adobe.name APTTrail VT OffSec SOCRadar
Domain agph.ivi66.net APTTrail VT OffSec SOCRadar
Domain bos.github.wiki APTTrail VT OffSec SOCRadar
Domain caonimade.11i.me APTTrail VT OffSec SOCRadar
Domain d.github.wiki APTTrail VT OffSec SOCRadar
Domain darknet.rootkit.tools APTTrail VT OffSec SOCRadar
Domain darwin.github.wiki APTTrail VT OffSec SOCRadar
Domain download.mircrosoftscoulds.com APTTrail VT OffSec SOCRadar
Domain dust.github.wiki APTTrail VT OffSec SOCRadar
Domain exmail.googie.com.ph APTTrail VT OffSec SOCRadar
Domain fbi.fuckbc.com APTTrail VT OffSec SOCRadar
Domain flash.wy886066.com APTTrail VT OffSec SOCRadar
Domain fuckbc.com APTTrail VT OffSec SOCRadar
Domain fuckeryoumm.nmb.bet APTTrail VT OffSec SOCRadar
Domain fuckyou.fbi.am APTTrail VT OffSec SOCRadar
Domain gb.googie.ph APTTrail VT OffSec SOCRadar
Domain github.wiki APTTrail VT OffSec SOCRadar
Domain googie.com.ph APTTrail VT OffSec SOCRadar
Domain googie.ph APTTrail VT OffSec SOCRadar
Domain helloword.11i.me APTTrail VT OffSec SOCRadar
Domain helloword.daj8.me APTTrail VT OffSec SOCRadar
Domain hk.whoamis.info APTTrail VT OffSec SOCRadar
Domain hkdust.github.wiki APTTrail VT OffSec SOCRadar
Domain huaidan.fbi.am APTTrail VT OffSec SOCRadar

Referencias y enlaces

→ Perfil del actor apt-earthberberoka en el blog → Ver apt-earthberberoka en IntelTracker → URL IntelTracker: documents.trendmicro.com→ URL IntelTracker: g-soft.info→ URL IntelTracker: otx.alienvault.com→ URL IntelTracker: www.trendmicro.com→ URL IntelTracker: www.virustotal.com→ URL IntelTracker: www.virustotal.com → Fuente OSINT: github.com→ Fuente OSINT: raw.githubusercontent.com→ Fuente OSINT: documents.trendmicro.com→ Fuente OSINT: g-soft.info→ Fuente OSINT: otx.alienvault.com→ Fuente OSINT: www.trendmicro.com → Buscar apt-earthberberoka en APTTrail → Repositorio APTTrail → Buscar en Google News → Analizar en VirusTotal → Feed RSS del blog
← Volver al panel de inteligencia

Incidentes recientes