Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a APT GREF. Aliases observados: APT GREF. Conteo por tipo: domain: 113, ipv4: 32.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | 6006.secpert.com | APTTrail |
| Domain | 6006.upupdate.cn | APTTrail |
| Domain | 789aa654.top | APTTrail |
| Domain | adoptewer.com | APTTrail |
| Domain | allshell.net | APTTrail |
| Domain | allwhatsapp.net | APTTrail |
| Domain | amote-366.vicp.cc | APTTrail |
| Domain | anar.gleeze.com | APTTrail |
| Domain | android.apps.us.to | APTTrail |
| Domain | androidapps.duia.in | APTTrail |
| Domain | androidapps.fvk.cc | APTTrail |
| Domain | androidapps.home.hn.org | APTTrail |
| Domain | androidapps.jetos.com | APTTrail |
| Domain | androidapps.linkpc.net | APTTrail |
| Domain | androidapps.myfirewall.org | APTTrail |
| Domain | androidapps.nerdpol.ovh | APTTrail |
| Domain | androidapps.npff.co | APTTrail |
| Domain | androidapps.nsupdate.info | APTTrail |
| Domain | androidapps.spdns.eu | APTTrail |
| Domain | androidapps.spdns.org | APTTrail |
| Domain | androidapps.tempors.com | APTTrail |
| Domain | androidsapps.ml | APTTrail |
| Domain | api--telegram.ru | APTTrail |
| Domain | api.telegram5.org | APTTrail |
| Domain | api.telegramrc.com | APTTrail |
| Domain | app.telegramrc.com | APTTrail |
| Domain | attoo1s.com | APTTrail |
| Domain | babyedu-online.com | APTTrail |
| Domain | battle.com.tw | APTTrail |
| Domain | bhvghg.com | APTTrail |
Referencias
- https://blog.lookout.com/multiyear-surveillance-campaigns-discovered-targeting-uyghurs
- https://citizenlab.ca/2025/04/uyghur-language-software-hijacked-to-deliver-malware/
- https://github.com/volexity/threat-intel/blob/main/2023/2023-09-22%20EvilBamboo/indicators/iocs.csv
- https://otx.alienvault.com/pulse/5efca5ec3da9c1ceace695fc
- https://threatfox.abuse.ch/browse/tag/BadBazaar/
- https://threatfox.abuse.ch/browse/tag/BadBazaar/
- https://tria.ge/231005-2xj7jshg69
- https://tria.ge/231103-l385vsfh7v
- https://tria.ge/231103-nfveasbe23
- https://tria.ge/240109-rhyraacacq/behavioral1
- https://twitter.com/naumovax/status/172042145649913054
- https://twitter.com/naumovax/status/1744741775661756421