Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a APT HIGAISA. Aliases observados: APT HIGAISA. Conteo por tipo: domain: 13, ipv4: 1, url: 1.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | api.s2cloud-amazon.com | APTTrail |
| Domain | app-dimensiona.s3.sa-east-1.amazonaws.com | APTTrail |
| Domain | bjj-files-production.s3.sa-east-1.amazonaws.com | APTTrail |
| Domain | comcleanner.info | APTTrail |
| Domain | footracker-statics.s3.sa-east-1.amazonaws.com | APTTrail |
| Domain | goodhk.azurewebsites.net | APTTrail |
| Domain | p-game.s3.sa-east-1.amazonaws.com | APTTrail |
| Domain | s2cloud-amazon.com | APTTrail |
| Domain | sixindent.epizy.com | APTTrail |
| Domain | speedshare.oss-cn-hongkong.aliyuncs.com | APTTrail |
| Domain | xianggang000.oss-cn-hongkong.aliyuncs.com | APTTrail |
| Domain | yitoo.oss-cn-hongkong.aliyuncs.com | APTTrail |
| Domain | zeplin.atwebpages.com | APTTrail |
| IP | 45.76.6.149:443 | APTTrail |
| URL | http://152.42.226.161 | APTTrail |
Referencias
- https://blog.malwarebytes.com/threat-analysis/2020/06/higaisa/
- https://github.com/StrikeReady-Inc/samples/blob/main/2024-08-20%20VN%20Oil%26Gas%20MSC/urls.txt
- https://otx.alienvault.com/pulse/5eda8caf8ef3aa0d8d0b8030
- https://www.tgsoft.it/news/news_archivio.asp?id=1568&lang=eng
- https://www.virustotal.com/gui/file/1e6c661d6981c0fa56c011c29536e57d21545fd11205eddf9218269ddf53d448/detection
- https://www.virustotal.com/gui/file/9b73cd0be50e457d9355b702d8b6df09b77a1c92bd70bbdcb538d87eccf6eef0/detection
- https://www.virustotal.com/gui/file/df999d24bde96decdbb65287ca0986db98f73b4ed477e18c3ef100064bceba6d/detection
- https://www.virustotal.com/gui/file/f1d519f43c36e24a89b351f00059a1bdb9afc2a339f7301117babb484e2cc555/detection
- https://x.com/StrikeReadyLabs/status/1825885062186860714
- https://x.com/TuringAlex/status/1937442563285508449
- https://x.com/VirITeXplorer/status/1835667782853140788