Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a BlackGuard. Aliases observados: BlackGuard, cherryspy, hatvibe. Conteo por tipo: domain: 10, file_path: 1, ipv4: 1, url: 7.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | background-services.net | APTTrail |
| Domain | diagnostic-resolver.com | APTTrail |
| Domain | download-resourses.info | APTTrail |
| Domain | energieecoinnov.info | APTTrail |
| Domain | energieecotech.info | APTTrail |
| Domain | enrollmentdm.com | APTTrail |
| Domain | lookup.ink | APTTrail |
| Domain | ms-webdav-miniredir.com | APTTrail |
| Domain | net-certificate.services | APTTrail |
| Domain | trust-certificate.net | APTTrail |
| FILE_PATH | /hftqlbgtg.php | APTTrail |
| IP | 38.180.207.137:45323 | APTTrail |
| URL | http://139.99.126.38 | APTTrail |
| URL | http://206.166.251.216 | APTTrail |
| URL | http://38.180.206.61 | APTTrail |
| URL | http://38.180.207.137 | APTTrail |
| URL | http://45.136.198.184 | APTTrail |
| URL | http://5.45.70.178 | APTTrail |
| URL | http://84.32.188.123 | APTTrail |
Referencias
- https://app.validin.com/detail?find=dd9aef0ce3d64a9dd4009357637617fc&type=hash&ref_id=1065472a0a3#tab=host_pairs
- https://blog.sekoia.io/double-tap-campaign-russia-nexus-apt-possibly-related-to-apt28-conducts-cyber-espionage-on-central-asia-and-kazakhstan-diplomatic-relations/
- https://cert.gov.ua/article/4697016 (Ukrainian)
- https://cert.gov.ua/article/6280129
- https://search.censys.io/hosts/38.180.206.61
- https://search.censys.io/hosts/38.180.207.137
- https://www.bitdefender.com/blog/businessinsights/deep-dive-into-downex-espionage-operation-in-central-asia/
- https://www.virustotal.com/gui/file/70d8e503fd199de816815b88e82fe70802955437cdc3785cbd0d34e0343ce5f1/detection
- https://www.virustotal.com/gui/file/75395359af2d61b2434d68fbee12ebc9947c4d113ca8363dd060caab76077474/detection
- https://www.virustotal.com/gui/file/cb9405390b4eb81beebb91ee596f77103e6ee47927c3f27d85474d06e2250e31/detection
- https://www.virustotal.com/gui/ip-address/172.104.62.59/relations
- https://www.virustotal.com/gui/ip-address/185.158.248.198/relations