Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a APT Q12. Aliases observados: APT Q12. Conteo por tipo: domain: 10, file_path: 17, ipv4: 8, url: 13.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | aufreighttransport.com | APTTrail |
| Domain | controlmytraffic.com | APTTrail |
| Domain | coredashcloud.com | APTTrail |
| Domain | guesttrafficinformation.com | APTTrail |
| Domain | hoaquincloud.com | APTTrail |
| Domain | msvsseccloud.com | APTTrail |
| Domain | nyculturecloud.com | APTTrail |
| Domain | org-nk.com | APTTrail |
| Domain | tomatozcloud.com | APTTrail |
| Domain | trafficcheckdaily.com | APTTrail |
| FILE_PATH | /JxQpe5T2nCn747UP.bmp | APTTrail |
| FILE_PATH | /VYtpPTc8UE2zG4dH.bmp | APTTrail |
| FILE_PATH | /WHZAZVRYVJTN.bmp | APTTrail |
| FILE_PATH | /d7w5y/n3tb4.asp | APTTrail |
| FILE_PATH | /files/kqAjJY3v4JxtChh3.bmp | APTTrail |
| FILE_PATH | /kqAjJY3v4JxtChh3.bmp | APTTrail |
| FILE_PATH | /manager/JxQpe5T2nCn747UP.bmp | APTTrail |
| FILE_PATH | /manager/VYtpPTc8UE2zG4dH.bmp | APTTrail |
| FILE_PATH | /verify/V4/WHZAZVRYVJTN.bmp | APTTrail |
| FILE_PATH | /wkdo9/2qpmk.asp | APTTrail |
| FILE_PATH | /wkdo9/4b3ru.asp | APTTrail |
| FILE_PATH | /wkdo9/n3tb4.asp | APTTrail |
| FILE_PATH | /wkdo9/t1802.asp | APTTrail |
| FILE_PATH | /z2jb95/a3pvvu.asp | APTTrail |
| FILE_PATH | /z2jb95/fz0n15.asp | APTTrail |
| FILE_PATH | /z2jb95/hsvxr8.asp | APTTrail |
| FILE_PATH | /z2jb95/yejo9i.asp | APTTrail |
| IP | 185.181.229.110:443 | APTTrail |
| IP | 185.181.230.110:443 | APTTrail |
| IP | 185.181.230.71:443 | APTTrail |
Referencias
- https://blogs.jpcert.or.jp/ja/2025/10/APT-C-60_update.html
- https://twitter.com/malwrhunterteam/status/1541784815728459779
- https://twitter.com/unpacker/status/1541944761140948993
- https://twitter.com/unpacker/status/1541944861275828224
- https://twitter.com/unpacker/status/1541945280467111936
- https://www.secrss.com/articles/36606 (Chinese)
- https://www.virustotal.com/gui/file/1b7502a8a9e17568c1cd31629708f922822eaac86f4685261401b3b1f46de5fe/detection
- https://www.virustotal.com/gui/file/41cfac27c16272327bbe6c2251ce43432d26c4a01ff9a3042b824ba8ebcccb0d/detection
- https://www.virustotal.com/gui/file/6702d4eca0e2bd4e7cbfc3e700d241f7934b52626f66b7dacf1807dc20a66103/detection
- https://www.virustotal.com/gui/file/90b7e2c0aea51f1b51c367ee580cbacb06e71b4fb934ac9f2e4dec1bb3fdfeb0/detection
- https://www.virustotal.com/gui/file/9932be44c8916fc5750ef63866ab6b4ab3984298cdfadad2c606f3f6d36127e9/detection
- https://www.virustotal.com/gui/file/bffacbb0b54a3b1dd6f25686d2486d0a064f5e8eedefb4e572740f7b63ba4fa4/detection