APTTrail: bigpretzel indicators and references

Fecha
18 Jun 2026
Actor
bigpretzel
Tipo
Ioc
Pais
United Kingdom
Sector
-
Confianza
high
100
Prioridad analitica
Alta

Basado en actor, pais, IOCs, TTPs, filtracion y calidad de contexto.

30IOCs
0TTPs
bigpretzelActor
United KingdomPais
Executive Summary
APTTrail mantiene indicadores publicos asociados a bigpretzel. Aliases observados: bigpretzel, graphite spyware. Conteo por tipo: domain: 18, ipv4: 17.

Key Points

  • https://app.validin.com/detail?find=%2FO%3Dnetwork39managment%2FCN%3Dgreenad&type=raw&ref_id=92a69af4516#tab=host_pairs (# 2025-06-13)
  • https://citizenlab.ca/2025/03/a-first-look-at-paragons-proliferating-spyware-operations/
  • https://citizenlab.ca/2025/06/first-forensic-confirmation-of-paragons-ios-mercenary-spyware-finds-journalists-targeted/ (# bigpretzel)
  • https://search.censys.io/hosts/178.237.39.204
  • https://x.com/blackorbird/status/1933368441433698638

Resumen APTTrail

APTTrail mantiene indicadores publicos asociados a bigpretzel. Aliases observados: bigpretzel, graphite spyware. Conteo por tipo: domain: 18, ipv4: 17.

Indicadores de Compromiso (IOCs)

TipoValorContexto
Domainancient-thing.itAPTTrail
Domainexternal-astra.comAPTTrail
Domainexternal-cag.comAPTTrail
Domainexternal-cap.comAPTTrail
Domainexternal-drt.comAPTTrail
Domainexternal-muki.comAPTTrail
Domainexternal-shotgun3.comAPTTrail
Domainexternal-sht-prd-4.comAPTTrail
Domainexternal-sht.comAPTTrail
Domainforti.external-muki.comAPTTrail
Domainforti.external-shotgun3.comAPTTrail
Domainforti.external-sht-prd-4.comAPTTrail
Domainforti.external-sht.comAPTTrail
Domainforti.internal-stg.comAPTTrail
Domainforti.paraccess.comAPTTrail
Domaininternal-abba.comAPTTrail
Domaininternal-stg.comAPTTrail
Domainmodern-money.orgAPTTrail
IP178.237.39.204:443APTTrail
IP178.237.39.204:50801APTTrail
IP178.237.39.204:53392APTTrail
IP178.237.39.204:64823APTTrail
IP194.71.130.218:443APTTrail
IP46.183.184.91:443APTTrail
IP84.110.122.27:443APTTrail
IP84.110.47.82:4443APTTrail
IP84.110.47.83:443APTTrail
IP84.110.47.84:1443APTTrail
IP84.110.47.84:443APTTrail
IP84.110.47.84:4443APTTrail

Referencias

Diamond Model

Adversary
bigpretzel
Ver perfil →
Victim
APTTrail: bigpretzel indicators and references
United Kingdom
Capability
Ioc
Infrastructure
ancient-thing.it
external-astra.com
external-cag.com
external-cap.com

Indicadores de Compromiso (IOCs)

TipoValorContextoOSINT
Domain ancient-thing.it APTTrail VT OffSec SOCRadar
Domain external-astra.com APTTrail VT OffSec SOCRadar
Domain external-cag.com APTTrail VT OffSec SOCRadar
Domain external-cap.com APTTrail VT OffSec SOCRadar
Domain external-drt.com APTTrail VT OffSec SOCRadar
Domain external-muki.com APTTrail VT OffSec SOCRadar
Domain external-shotgun3.com APTTrail VT OffSec SOCRadar
Domain external-sht-prd-4.com APTTrail VT OffSec SOCRadar
Domain external-sht.com APTTrail VT OffSec SOCRadar
Domain forti.external-muki.com APTTrail VT OffSec SOCRadar
Domain forti.external-shotgun3.com APTTrail VT OffSec SOCRadar
Domain forti.external-sht-prd-4.com APTTrail VT OffSec SOCRadar
Domain forti.external-sht.com APTTrail VT OffSec SOCRadar
Domain forti.internal-stg.com APTTrail VT OffSec SOCRadar
Domain forti.paraccess.com APTTrail VT OffSec SOCRadar
Domain internal-abba.com APTTrail VT OffSec SOCRadar
Domain internal-stg.com APTTrail VT OffSec SOCRadar
Domain modern-money.org APTTrail VT OffSec SOCRadar
IP 178.237.39.204:443 APTTrail VT OffSec SOCRadar
IP 178.237.39.204:50801 APTTrail VT OffSec SOCRadar
IP 178.237.39.204:53392 APTTrail VT OffSec SOCRadar
IP 178.237.39.204:64823 APTTrail VT OffSec SOCRadar
IP 194.71.130.218:443 APTTrail VT OffSec SOCRadar
IP 46.183.184.91:443 APTTrail VT OffSec SOCRadar
IP 84.110.122.27:443 APTTrail VT OffSec SOCRadar
IP 84.110.47.82:4443 APTTrail VT OffSec SOCRadar
IP 84.110.47.83:443 APTTrail VT OffSec SOCRadar
IP 84.110.47.84:1443 APTTrail VT OffSec SOCRadar
IP 84.110.47.84:443 APTTrail VT OffSec SOCRadar
IP 84.110.47.84:4443 APTTrail VT OffSec SOCRadar

Referencias y enlaces

→ Perfil del actor bigpretzel en el blog → Ver bigpretzel en IntelTracker → URL IntelTracker: app.validin.com→ URL IntelTracker: citizenlab.ca→ URL IntelTracker: citizenlab.ca→ URL IntelTracker: search.censys.io→ URL IntelTracker: x.com → Fuente OSINT: github.com→ Fuente OSINT: raw.githubusercontent.com→ Fuente OSINT: app.validin.com→ Fuente OSINT: citizenlab.ca→ Fuente OSINT: citizenlab.ca→ Fuente OSINT: search.censys.io → Buscar bigpretzel en APTTrail → Repositorio APTTrail → Mas incidentes en United Kingdom → Buscar en Google News → Analizar en VirusTotal → Feed RSS del blog
← Volver al panel de inteligencia

Incidentes recientes