Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a APT TA416. Aliases observados: APT TA416. Conteo por tipo: domain: 2, ipv4: 8, url: 4.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | upespr.com | APTTrail |
| Domain | zyber-i.com | APTTrail |
| IP | 103.107.104.19:33182 | APTTrail |
| IP | 103.107.104.19:33255 | APTTrail |
| IP | 103.107.104.19:443 | APTTrail |
| IP | 107.167.64.4:443 | APTTrail |
| IP | 45.154.14.235:443 | APTTrail |
| IP | 45.248.87.162:110 | APTTrail |
| IP | 69.90.184.125:443 | APTTrail |
| IP | 92.118.188.78:443 | APTTrail |
| URL | http://103.107.104.19 | APTTrail |
| URL | http://45.154.14.235 | APTTrail |
| URL | http://45.248.87.162 | APTTrail |
| URL | http://69.90.184.125 | APTTrail |
Referencias
- https://otx.alienvault.com/pulse/5fbc0c5ec4bfeaa7f7956ff4
- https://twitter.com/aRtAGGI/status/1498314276104200193
- https://twitter.com/felixaime/status/1501150428016357378
- https://twitter.com/fr0s7_/status/1501158252045901824
- https://twitter.com/h2jazi/status/1498308592495214592
- https://www.joesandbox.com/analysis/584888/0/html
- https://www.proofpoint.com/us/blog/threat-insight/good-bad-and-web-bug-ta416-increases-operational-tempo-against-european
- https://www.proofpoint.com/us/blog/threat-insight/ta416-goes-ground-and-returns-golang-plugx-malware-loader
- https://www.virustotal.com/gui/file/6a5b0cfdaf402e94f892f66a0f53e347d427be4105ab22c1a9f259238c272b60/detection
- https://www.virustotal.com/gui/file/effd63168fc7957baf609f7492cd82579459963f80fc6fc4d261fbc68877f5a1/detection
- https://www.virustotal.com/gui/file/effd63168fc7957baf609f7492cd82579459963f80fc6fc4d261fbc68877f5a1/detection