Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a APT FLAXTYPHOON. Aliases observados: APT FLAXTYPHOON. Conteo por tipo: domain: 3, url: 3.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | asljkdqhkhasdq.softether.net | APTTrail |
| Domain | vpn437972693.sednc.cn | APTTrail |
| Domain | vpn472462384.softether.net | APTTrail |
| URL | http://149.28.137.179 | APTTrail |
| URL | http://158.247.193.93 | APTTrail |
| URL | http://158.247.226.80 | APTTrail |
Referencias
- https://otx.alienvault.com/pulse/64e86c65ba511d1d4c4aa590
- https://www.microsoft.com/en-us/security/blog/2023/08/24/flax-typhoon-using-legitimate-software-to-quietly-access-taiwanese-organizations/
- https://www.virustotal.com/gui/file/a596d4a1ede0d022d77f0b03c723c7071ffec0e89b35f0d30fb9ff15feeb4969/detection
- https://x.com/Cyberteam008/status/1909432341702787180
- https://x.com/skocherhan/status/1920679514096468212