Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a apt10. Aliases observados: apt10, earth kasha, gallium, noopldr, stone panda. Conteo por tipo: domain: 1486, ipv4: 11, url: 2.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | 002562066559681.r3u8.com | APTTrail |
| Domain | 031168053846049.r3u8.com | APTTrail |
| Domain | 0625.have8000.com | APTTrail |
| Domain | 1.gadskysun.com | APTTrail |
| Domain | 100fanwen.com | APTTrail |
| Domain | 11.usyahooapis.com | APTTrail |
| Domain | 19518473326.r3u8.com | APTTrail |
| Domain | 1960445709311199.r3u8.com | APTTrail |
| Domain | 1j.www1.biz | APTTrail |
| Domain | 1z.itsaol.com | APTTrail |
| Domain | 2012yearleft.com | APTTrail |
| Domain | 2014.zzux.com | APTTrail |
| Domain | 202017845.r3u8.com | APTTrail |
| Domain | 2139465544784.r3u8.com | APTTrail |
| Domain | 2789203959848958.r3u8.com | APTTrail |
| Domain | 5590428449750026.r3u8.com | APTTrail |
| Domain | 5q.niushenghuo.info | APTTrail |
| Domain | 6r.suibian2010.info | APTTrail |
| Domain | 9gowg.tech | APTTrail |
| Domain | Jepsen.r3u8.com | APTTrail |
| Domain | a.wubangtu.info | APTTrail |
| Domain | a1.suibian2010.info | APTTrail |
| Domain | ab.4pu.com | APTTrail |
| Domain | abc.wikaba.com | APTTrail |
| Domain | abcd100621.3322.org | APTTrail |
| Domain | abcd120719.6600.org | APTTrail |
| Domain | abcd120807.3322.org | APTTrail |
| Domain | acc.emailfound.info | APTTrail |
| Domain | acc.lehigtapp.com | APTTrail |
| Domain | acsocietyy.com | APTTrail |
Referencias
- http://blog.jpcert.or.jp/2017/02/chches-malware--93d6.html
- http://jsac.jpcert.or.jp/archive/2021/pdf/JSAC2021_202_niwa-yanagishita_en.pdf
- http://researchcenter.paloaltonetworks.com/2017/02/unit42-menupass-returns-new-malware-new-attacks-japanese-academics-organizations/
- https://1275.ru/ioc/8083/earth-kasha-apt10-apt-iocs/
- https://app.any.run/tasks/875fe058-ade2-4d26-86fc-411417e33dff/
- https://app.any.run/tasks/b5634afb-0d3a-4d0b-97c8-fbbd25b9aa97/
- https://blog-en.itochuci.co.jp/entry/2024/01/24/134100
- https://blog.ensilo.com/uncovering-new-activity-by-apt10
- https://brica.de/alerts/alert/public/1214983/apt10-using-cobalt-strike-confirm-new-attack-with-apt-attacker-group-menupass-apt10/
- https://community.emergingthreats.net/t/ruleset-update-summary-2024-12-02-v10781/2210
- https://documents.trendmicro.com/images/TEx/Earth-Kasha-Blog-IoCshFxTmpo.txt
- https://github.com/janhenrikdotcom/iocs/blob/master/APT10/cloud-hopper-indicators-of-compromise-v3.pdf