Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a APT TIBET. Aliases observados: APT TIBET. Conteo por tipo: domain: 48, ipv4: 3.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | 1.test.3322.org.cn | APTTrail |
| Domain | 123ewqasdcxz.xicp.net | APTTrail |
| Domain | 2.test.3322.org.cn | APTTrail |
| Domain | 3.test.3322.org.cn | APTTrail |
| Domain | 4.test.3322.org.cn | APTTrail |
| Domain | airjaldinet.ml | APTTrail |
| Domain | antmoving.online | APTTrail |
| Domain | beemail.online | APTTrail |
| Domain | bf.mk | APTTrail |
| Domain | browserservice.zzux.com | APTTrail |
| Domain | client-user-id.com | APTTrail |
| Domain | cta-tibet.com | APTTrail |
| Domain | ctmail.dns-dns.com | APTTrail |
| Domain | dalailama.online | APTTrail |
| Domain | designer.dynamic-dns.net | APTTrail |
| Domain | energy-mail.org | APTTrail |
| Domain | getadobeflashdownloader.proxydns.com | APTTrail |
| Domain | gmail.isooncloud.com | APTTrail |
| Domain | gmailapp.me | APTTrail |
| Domain | hoop-america.oicp.net | APTTrail |
| Domain | hotmal1.com | APTTrail |
| Domain | hy.micrsofts.com | APTTrail |
| Domain | in-tibet.net | APTTrail |
| Domain | install.ddns.info | APTTrail |
| Domain | ip.micrsofts.com | APTTrail |
| Domain | izelense.com | APTTrail |
| Domain | loginwebmailnic.dynssl.com | APTTrail |
| Domain | ly.micorsofts.net | APTTrail |
| Domain | mail-tibet.net | APTTrail |
| Domain | mailanalysis.services | APTTrail |
Referencias
- https://citizenlab.ca/2019/09/poison-carp-tibetan-groups-targeted-with-1-click-mobile-exploits/
- https://github.com/citizenlab/malware-indicators/blob/master/201909_MissingLink/iocs.csv
- https://otx.alienvault.com/pulse/5d89e04cea5c55ee87a6aa05
- https://otx.alienvault.com/pulse/5d9c9101d569bf434dbc9385
- https://otx.alienvault.com/pulse/5e83635bf1c0d9b195569252
- https://otx.alienvault.com/pulse/5e84c248adbbd69f8c569252
- https://otx.alienvault.com/pulse/5fca9086207f00c7222c0c87
- https://securelist.com/holy-water-ongoing-targeted-water-holing-attack-in-asia/96311/
- https://securelist.com/new-uyghur-and-tibetan-themed-attacks-using-pdf-exploits/35465/
- https://twitter.com/craiu/status/1176437943369703424
- https://www.alienvault.com/blogs/labs-research/latest-adobe-pdf-exploit-used-to-target-uyghur-and-tibetan-activists
- https://www.alienvault.com/open-threat-exchange/blog/cve-2012-0158-tibet-targeted-attacks-and-so-on