Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a APT PKPLUG. Aliases observados: APT PKPLUG. Conteo por tipo: domain: 58.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | 3w.tcpdo.net | APTTrail |
| Domain | admin.nslookupdns.com | APTTrail |
| Domain | adminloader.com | APTTrail |
| Domain | adminsysteminfo.com | APTTrail |
| Domain | andphocen.com | APTTrail |
| Domain | app.newfacebk.com | APTTrail |
| Domain | appupdatemoremagic.com | APTTrail |
| Domain | cdncool.com | APTTrail |
| Domain | csip6.biz | APTTrail |
| Domain | dns.cdncool.com | APTTrail |
| Domain | feed-5613.coderformylife.info | APTTrail |
| Domain | gooledriveservice.com | APTTrail |
| Domain | honor2020.ga | APTTrail |
| Domain | hwmt10.w3.ezua.com | APTTrail |
| Domain | imw100pass.imwork.net | APTTrail |
| Domain | info.adminsysteminfo.com | APTTrail |
| Domain | jackhex.md5c.com | APTTrail |
| Domain | jackhex.md5c.net | APTTrail |
| Domain | lala513.gicp.net | APTTrail |
| Domain | linkdatax.com | APTTrail |
| Domain | logitechwkgame.com | APTTrail |
| Domain | lzsps.ml | APTTrail |
| Domain | mail.queryurl.com | APTTrail |
| Domain | md.sony36.com | APTTrail |
| Domain | md5c.net | APTTrail |
| Domain | microsoftdefence.com | APTTrail |
| Domain | microsoftserve.com | APTTrail |
| Domain | mxdnsv6.com | APTTrail |
| Domain | netvovo.windowsnetwork.org | APTTrail |
| Domain | newfacebk.com | APTTrail |
Referencias
- https://community.emergingthreats.net/t/ruleset-update-summary-2023-09-22-v10423/980
- https://otx.alienvault.com/pulse/6511d6fd63ecbfd938c3580f
- https://pan-unit42.github.io/playbook_viewer/?pb=pkplug
- https://unit42.paloaltonetworks.com/pkplug_chinese_cyber_espionage_group_attacking_asia/
- https://unit42.paloaltonetworks.com/stately-taurus-attacks-se-asian-government/
- https://unit42.paloaltonetworks.com/unsigned-dlls/