Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a apt19. Aliases observados: apt19, c0d0so0, codoso, codoso team, deep panda, sunshop group. Conteo por tipo: domain: 57, file_path: 1, ipv4: 2, url: 8.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | EmpireB1ue.com | APTTrail |
| Domain | ameteksen.com | APTTrail |
| Domain | asconline.we11point.com | APTTrail |
| Domain | assso.net | APTTrail |
| Domain | autodiscover.2bunny.com | APTTrail |
| Domain | b.gnisoft.com | APTTrail |
| Domain | capstoneturbine.cechire.com | APTTrail |
| Domain | caref1rst.com | APTTrail |
| Domain | careflrst.com | APTTrail |
| Domain | client.gnisoft.com | APTTrail |
| Domain | extcitrix.we11point.com | APTTrail |
| Domain | facefuture.us | APTTrail |
| Domain | gifas.blogsite.org | APTTrail |
| Domain | gifas.cechire.com | APTTrail |
| Domain | giga.gnisoft.com | APTTrail |
| Domain | gnisoft.com | APTTrail |
| Domain | google-dash.com | APTTrail |
| Domain | googlewebcache.com | APTTrail |
| Domain | healthslie.com | APTTrail |
| Domain | hrsolutions.we11point.com | APTTrail |
| Domain | icbcqsz.com | APTTrail |
| Domain | images.googlewebcache.com | APTTrail |
| Domain | jbossas.org | APTTrail |
| Domain | kaspersyk.com | APTTrail |
| Domain | lyncdiscover.2bunny.com | APTTrail |
| Domain | me.we11point.com | APTTrail |
| Domain | microsoft-cache.com | APTTrail |
| Domain | mycitrix.we11point.com | APTTrail |
| Domain | myhr.we11point.com | APTTrail |
| Domain | oa.ameteksen.com | APTTrail |
Referencias
- https://attack.mitre.org/wiki/Group/G0009
- https://cybergeeks.tech/analyzing-apt19-malware-using-a-step-by-step-method/
- https://krebsonsecurity.com/wp-content/uploads/2015/02/FBI-Flash-Warning-Deep-Panda.pdf
- https://otx.alienvault.com/pulse/6245655996f5a1a01e2b5d94
- https://otx.alienvault.com/pulse/62b5767285717d7d3a45b2b8
- https://twitter.com/unpacker/status/1343143954007482369
- https://unit42.paloaltonetworks.com/new-attacks-linked-to-c0d0s0-group/
- https://www.cisa.gov/uscert/ncas/alerts/aa22-174a
- https://www.domaintools.com/resources/blog/domaintools-101-the-art-of-tracking-threat-actors
- https://www.fireeye.com/blog/threat-research/2017/06/phished-at-the-request-of-counsel.html (Network Based Indicators (NBI))
- https://www.fortinet.com/blog/threat-research/deep-panda-log4shell-fire-chili-rootkits
- https://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/the-black-vine-cyberespionage-group.pdf