Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a APT TODDYCAT. Aliases observados: APT TODDYCAT. Conteo por tipo: domain: 29, ipv4: 1, url: 1.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | ad.fopingu.com | APTTrail |
| Domain | admit.pkigoscorp.com | APTTrail |
| Domain | backend.rtmcsync.com | APTTrail |
| Domain | cdn.pkigoscorp.com | APTTrail |
| Domain | cert.qform3d.in | APTTrail |
| Domain | certexvpn.com | APTTrail |
| Domain | cyberguard.certexvpn.com | APTTrail |
| Domain | eaq.machineaccountquota.com | APTTrail |
| Domain | eohsdnsaaojrhnqo.windowshost.us | APTTrail |
| Domain | fopingu.com | APTTrail |
| Domain | gist.gitbusercontent.com | APTTrail |
| Domain | git.gitbusercontent.com | APTTrail |
| Domain | gitbusercontent.com | APTTrail |
| Domain | githubdd.workers.dev | APTTrail |
| Domain | idp.pkigoscorp.com | APTTrail |
| Domain | imap.774b884034c450b.com | APTTrail |
| Domain | machineaccountquota.com | APTTrail |
| Domain | mfeagents.workers.dev | APTTrail |
| Domain | ns01.nayatel.orinafz.com | APTTrail |
| Domain | pic.rtmcsync.com | APTTrail |
| Domain | pkigoscorp.com | APTTrail |
| Domain | proxy.rtmcsync.com | APTTrail |
| Domain | qaq2.machineaccountquota.com | APTTrail |
| Domain | qform3d.in | APTTrail |
| Domain | raw.gitbusercontent.com | APTTrail |
| Domain | rtmcsync.com | APTTrail |
| Domain | solitary-dawn-61af.mfeagents.workers.dev | APTTrail |
| Domain | sslvpn.pkigoscorp.com | APTTrail |
| Domain | update.certexvpn.com | APTTrail |
| IP | 139.180.145.121:443 | APTTrail |
Referencias
- https://research.checkpoint.com/2023/stayin-alive-targeted-attacks-against-telecoms-and-government-ministries-in-asia/
- https://securelist.com/toddycat-keep-calm-and-check-logs/110696/
- https://securelist.com/toddycat/106799/
- https://www.virustotal.com/gui/file/877579185a72fbaf1afa78d3c50dbab187780d545d5375ba4c29147083176697/detection