Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a apt34. Aliases observados: apt34, greenbug, helixkitten, oilrig, spearal, veaty. Conteo por tipo: domain: 217, file_path: 5, ipv4: 42, url: 3.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | 262t3my0gt.cardioteacher.com | APTTrail |
| Domain | 2fhj.asiaworldremit.com | APTTrail |
| Domain | 2u21hipg70.uber-asia.com | APTTrail |
| Domain | 2zcf.uber-asia.com | APTTrail |
| Domain | 3j3oyvsf8i.joexpediagroup.com | APTTrail |
| Domain | 5s5gp24f8x.asiaworldremit.com | APTTrail |
| Domain | 6google.com | APTTrail |
| Domain | 7a7n4j60g4.cardioteacher.com | APTTrail |
| Domain | 7w7rbgt13f.uber-asia.com | APTTrail |
| Domain | ababab.biz | APTTrail |
| Domain | acceptplan.com | APTTrail |
| Domain | acrlee.com | APTTrail |
| Domain | acrobatverify.com | APTTrail |
| Domain | admin.mofaiq.com | APTTrail |
| Domain | akamai-global.com | APTTrail |
| Domain | akastatus.com | APTTrail |
| Domain | alcirineos.com | APTTrail |
| Domain | alforatsystem.com | APTTrail |
| Domain | allsecpackupdater.com | APTTrail |
| Domain | amazon-loveyou.com | APTTrail |
| Domain | anhuisiafu.com | APTTrail |
| Domain | antivirus-update.top | APTTrail |
| Domain | anyportals.com | APTTrail |
| Domain | applicationframehost.in | APTTrail |
| Domain | apps.iqwebservice.com | APTTrail |
| Domain | asiacall.net | APTTrail |
| Domain | asiaworldremit.com | APTTrail |
| Domain | astrazencea.com | APTTrail |
| Domain | astrazeneeca.com | APTTrail |
| Domain | axoryvexity.eu | APTTrail |
Referencias
- https://app.validin.com/detail?find=151.236.17.231&type=ip4&ref_id=29bbecc74a1#tab=resolutions
- https://app.validin.com/detail?find=185.76.78.177&type=ip4&ref_id=70a5c38659b#tab=resolutions
- https://app.validin.com/detail?find=3981e30d1289ce1be9210c929a68bca0&type=hash&ref_id=f7daca57730#tab=host_pairs (# 2025-03-31)
- https://app.validin.com/detail?find=b60d5beecd0576e7c59f2195e2462822f9d096cd&type=hash&ref_id=f7daca57730#tab=host_pairs (# 2025-03-31)
- https://app.validin.com/detail?find=helllllllllllllllllllllllllo&type=raw&ref_id=ad162dcfc0e#tab=dns
- https://blog.malwarebytes.com/threat-intelligence/2022/05/apt34-targets-jordan-government-using-new-saitama-backdoor/
- https://blog.morphisec.com/microsoft-equation-editor-backdoor
- https://docs.google.com/document/d/1oYX3uN6KxIX_StzTH0s0yFNNoHDnV8VgmVqU5WoeErc (# 2018-05-13: PRB-Backdoor and its connection to Oilrig)
- https://docs.google.com/document/d/1oYX3uN6KxIX_StzTH0s0yFNNoHDnV8VgmVqU5WoeErc (2017-11-14: ALMA Communicator by Oilrig sample)
- https://docs.google.com/document/d/1oYX3uN6KxIX_StzTH0s0yFNNoHDnV8VgmVqU5WoeErc (2017-11-16: Iranian Oilrig campaign with C2 coldflys[.]com)
- https://docs.google.com/document/d/1oYX3uN6KxIX_StzTH0s0yFNNoHDnV8VgmVqU5WoeErc (2017-11-22: Oilrig - new old sample)
- https://docs.google.com/document/d/1oYX3uN6KxIX_StzTH0s0yFNNoHDnV8VgmVqU5WoeErc (2017-12-10: Oilrig-APT34)