Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a APT LAZYSCRIPTER. Aliases observados: APT LAZYSCRIPTER. Conteo por tipo: domain: 18, ipv4: 2, url: 1.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | bsjsiq3ytpt3efsn6wnu3pukxil6q6plty6m6dcz.duckdns.org | APTTrail |
| Domain | gowaymevps.xyz | APTTrail |
| Domain | gowaymevpslink1.xyz | APTTrail |
| Domain | gowaymevpslink2.xyz | APTTrail |
| Domain | gowaymevpslink3.xyz | APTTrail |
| Domain | gowaymevpslink4.xyz | APTTrail |
| Domain | gowaymevpslink5.xyz | APTTrail |
| Domain | iatassl-telechargementsecurity.duckdns.org | APTTrail |
| Domain | internetexploraldon.sytes.net | APTTrail |
| Domain | jbizgsvhzj22evqon9ezz8bmbupp1s6cprmriam1.duckdns.org | APTTrail |
| Domain | milla.publicvm.com | APTTrail |
| Domain | saqicpcgflrlgxgoxxzkbfrjuisbkozeqrmthrzo.duckdns.org | APTTrail |
| Domain | securessl.fit | APTTrail |
| Domain | smscs.publicvm.com | APTTrail |
| Domain | stub.ignorelist.com | APTTrail |
| Domain | u1153246fov.ha004.t.justns.ru | APTTrail |
| Domain | varifsecuripass.duckdns.org | APTTrail |
| Domain | vistacp-enhance.duckdns.org | APTTrail |
| IP | 185.81.157.186:1995 | APTTrail |
| IP | 45.91.92.112:449 | APTTrail |
| URL | http://185.81.157.186 | APTTrail |
Referencias
- https://lab52.io/blog/very-very-lazy-lazyscripters-scripts-double-compromise-in-a-single-obfuscation/
- https://otx.alienvault.com/pulse/603693b42a32d06720efad59/
- https://otx.alienvault.com/pulse/6228d0ba244cc5a2d6457b25
- https://resources.malwarebytes.com/files/2021/02/LazyScripter.pdf
- https://twitter.com/h2jazi/status/1366759252757512194
- https://www.virustotal.com/gui/file/0652962c5dace16ed170a932e3ce7eb3097b34bc809343fbb96b27cf3d22a5c7/detection
- https://www.virustotal.com/gui/file/23ea10f4b1a73a4e8b13466fff8983110216779d2d3cefe1fc151c6bb65c3b42/detection
- https://www.virustotal.com/gui/ip-address/147.182.192.241/relations
- https://www.virustotal.com/gui/ip-address/185.81.157.186/relations
- https://www.virustotal.com/gui/ip-address/66.29.130.204/relations