APTTrail: APT FINFISHER indicators and references

Fecha
18 Jun 2026
Actor
apt-finfisher
Tipo
Ioc
Pais
Egypt
Sector
-
Confianza
high
100
Prioridad analitica
Alta

Basado en actor, pais, IOCs, TTPs, filtracion y calidad de contexto.

30IOCs
0TTPs
apt-finfisherActor
EgyptPais
Executive Summary
APTTrail mantiene indicadores publicos asociados a APT FINFISHER. Aliases observados: APT FINFISHER. Conteo por tipo: domain: 11, ipv4: 10, url: 2.

Key Points

  • http://securityaffairs.co/wordpress/8085/intelligence/finfisher-the-case-of-a-cyber-espionage-found-everywhere.html
  • https://app.any.run/tasks/a717ebe4-e74f-4b0a-8233-b138906861a8/
  • https://citizenlab.ca/2015/10/mapping-finfishers-continuing-proliferation/
  • https://citizenlab.ca/2015/10/mapping-finfishers-continuing-proliferation/
  • https://community.rapid7.com/community/infosec/blog/2012/08/08/finfisher

Resumen APTTrail

APTTrail mantiene indicadores publicos asociados a APT FINFISHER. Aliases observados: APT FINFISHER. Conteo por tipo: domain: 11, ipv4: 10, url: 2.

Indicadores de Compromiso (IOCs)

TipoValorContexto
Domainbrowserupdate.downloadAPTTrail
Domainff-demo.blogdns.orgAPTTrail
Domaingoogle.wwwhost.bizAPTTrail
Domaininfo.dynamic-dns.netAPTTrail
Domainnews-youm7.comAPTTrail
Domainpal2me.netAPTTrail
Domainpal4u.netAPTTrail
Domainshop8d.netAPTTrail
Domaintiger.gamma-international.deAPTTrail
Domainworkingulf.netAPTTrail
Domainwp.piedslibres.comAPTTrail
IP108.61.190.183:443APTTrail
IP109.235.67.175:443APTTrail
IP184.82.101.234:443APTTrail
IP184.82.101.234:53APTTrail
IP185.141.24.204:443APTTrail
IP185.25.51.104:443APTTrail
IP213.252.247.105:443APTTrail
IP45.86.136.138:443APTTrail
IP45.86.163.138:443APTTrail
IP79.143.87.216:443APTTrail
URLhttp://158.69.105.207APTTrail
URLhttp://172.241.27.171APTTrail

Referencias

Diamond Model

Adversary
apt-finfisher
Ver perfil →
Victim
APTTrail: APT FINFISHER indicators and references
Egypt
Capability
Ioc
Infrastructure
browserupdate.download
ff-demo.blogdns.org
google.wwwhost.biz
info.dynamic-dns.net

Relations

Mapa de nodos relacionados por IOCs compartidos, actor, enlaces IntelTracker/OSINT, campanas y victimas observadas. Haz click en un nodo para abrir el post, filtro o fuente.

16 enlaces
Nodo actual
APTTrail: APT FINFISHER indicators and references
apt-finfisher · Egypt

Indicadores de Compromiso (IOCs)

TipoValorContextoOSINT
Domain browserupdate.download APTTrail VT OffSec SOCRadar
Domain ff-demo.blogdns.org APTTrail VT OffSec SOCRadar
Domain google.wwwhost.biz APTTrail VT OffSec SOCRadar
Domain info.dynamic-dns.net APTTrail VT OffSec SOCRadar
Domain news-youm7.com APTTrail VT OffSec SOCRadar
Domain pal2me.net APTTrail VT OffSec SOCRadar
Domain pal4u.net APTTrail VT OffSec SOCRadar
Domain shop8d.net APTTrail VT OffSec SOCRadar
Domain tiger.gamma-international.de APTTrail VT OffSec SOCRadar
Domain workingulf.net APTTrail VT OffSec SOCRadar
Domain wp.piedslibres.com APTTrail VT OffSec SOCRadar
IP 108.61.190.183:443 APTTrail VT OffSec SOCRadar
IP 109.235.67.175:443 APTTrail VT OffSec SOCRadar
IP 184.82.101.234:443 APTTrail VT OffSec SOCRadar
IP 184.82.101.234:53 APTTrail VT OffSec SOCRadar
IP 185.141.24.204:443 APTTrail VT OffSec SOCRadar
IP 185.25.51.104:443 APTTrail VT OffSec SOCRadar
IP 213.252.247.105:443 APTTrail VT OffSec SOCRadar
IP 45.86.136.138:443 APTTrail VT OffSec SOCRadar
IP 45.86.163.138:443 APTTrail VT OffSec SOCRadar
IP 79.143.87.216:443 APTTrail VT OffSec SOCRadar
URL http://158.69.105.207 APTTrail VT OffSec SOCRadar
URL http://172.241.27.171 APTTrail VT OffSec SOCRadar
Domain securityaffairs.co Extraido del contenido VT OffSec SOCRadar
Domain app.any.run Extraido del contenido VT OffSec SOCRadar
Domain citizenlab.ca Extraido del contenido VT OffSec SOCRadar
Domain community.rapid7.com Extraido del contenido VT OffSec SOCRadar
Domain otx.alienvault.com Extraido del contenido VT OffSec SOCRadar
Domain securelist.com Extraido del contenido VT OffSec SOCRadar
Domain twitter.com Extraido del contenido VT OffSec SOCRadar

Referencias y enlaces

→ Perfil del actor apt-finfisher en el blog → Ver apt-finfisher en IntelTracker → URL IntelTracker: securityaffairs.co→ URL IntelTracker: app.any.run→ URL IntelTracker: citizenlab.ca→ URL IntelTracker: citizenlab.ca→ URL IntelTracker: community.rapid7.com→ URL IntelTracker: otx.alienvault.com → Fuente OSINT: github.com→ Fuente OSINT: raw.githubusercontent.com→ Fuente OSINT: securityaffairs.co→ Fuente OSINT: app.any.run→ Fuente OSINT: citizenlab.ca→ Fuente OSINT: community.rapid7.com → Buscar apt-finfisher en APTTrail → Repositorio APTTrail → Mas incidentes en Egypt → Buscar en Google News → Analizar en VirusTotal → Feed RSS del blog
← Volver al panel de inteligencia

Incidentes recientes