Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a Bronze Highland. Aliases observados: Bronze Highland, Daggerfly. Conteo por tipo: domain: 3, ipv4: 11.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | flash.governmentmm.com | APTTrail |
| Domain | governmentmm.com | APTTrail |
| Domain | update.devicebug.com | APTTrail |
| IP | 103.96.128.44:10001 | APTTrail |
| IP | 103.96.128.44:16564 | APTTrail |
| IP | 103.96.131.150:19876 | APTTrail |
| IP | 103.96.131.150:40020 | APTTrail |
| IP | 122.10.89.170:9552 | APTTrail |
| IP | 122.10.89.172:10560 | APTTrail |
| IP | 223.165.4.175:81 | APTTrail |
| IP | 45.125.64.200:33200 | APTTrail |
| IP | 45.125.64.200:33220 | APTTrail |
| IP | 45.125.64.200:33223 | APTTrail |
| IP | 45.77.140.81:81 | APTTrail |
Referencias
- https://app.any.run/tasks/e5ad4dd0-32f7-45a6-8012-44711ed04f0e/
- https://blog.malwarebytes.com/threat-analysis/2020/07/chinese-apt-group-targets-india-and-hong-kong-using-new-variant-of-mgbot-malware/
- https://otx.alienvault.com/pulse/5f170c74a81587f5b2b6be5f
- https://symantec-enterprise-blogs.security.com/threat-intelligence/daggerfly-espionage-updated-toolset
- https://twitter.com/h2jazi/status/1296919948598673409
- https://www.bleepingcomputer.com/news/security/chinese-cyberspies-use-new-ssh-backdoor-in-network-device-hacks/
- https://www.virustotal.com/gui/domain/governmentmm.com/relations
- https://www.virustotal.com/gui/file/23acab55f533cad2471516d15f52a85d7f3a64e9589b6bfc76981dde39d1e0d4/detection
- https://www.virustotal.com/gui/file/5687b32cdd5c4d1b3e928ee0792f6ec43817883721f9b86ec8066c5ec2791595/detection
- https://www.virustotal.com/gui/file/5c52e41090cdd13e0bfa7ec11c283f5051347ba02c9868b4fddfd9c3fc452191/detection
- https://www.virustotal.com/gui/file/82a662cc06c49714efd8ed9086e20181659535718c515aa583efc70206256085/detection
- https://www.virustotal.com/gui/file/82c36fe8429b63c59d06d3741d1e4de7b60e196d1106a678fe052cc73909a997/detection