Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a cargotalon. Aliases observados: cargotalon, eaglet implant, headmare, phantomc2, phantomcore, phantomocx, phantomproxylite, phantomremote, ung0901. Conteo por tipo: domain: 633, file_path: 13, ipv4: 32, url: 27.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | 146.190.234.multiversitetet.no | APTTrail |
| Domain | 193.37.71.221.sslip.io | APTTrail |
| Domain | 1be.pro | APTTrail |
| Domain | 1to30.shop | APTTrail |
| Domain | 3hito.tech | APTTrail |
| Domain | 50forwardspodcast.co.uk | APTTrail |
| Domain | 7evenfoundation.org | APTTrail |
| Domain | 92108.sbs | APTTrail |
| Domain | aainfo.online | APTTrail |
| Domain | abhinayafoodrecipes.com | APTTrail |
| Domain | abstractcorner.com | APTTrail |
| Domain | account.win-shares.com | APTTrail |
| Domain | acquisizione.net | APTTrail |
| Domain | activehealth01.online | APTTrail |
| Domain | admirationhq.com | APTTrail |
| Domain | aegissecurity.online | APTTrail |
| Domain | affilipost.com | APTTrail |
| Domain | affordablecarsonline.com | APTTrail |
| Domain | agelessbonds.com | APTTrail |
| Domain | aifix.space | APTTrail |
| Domain | ainghain.com | APTTrail |
| Domain | aiupworkpro.com | APTTrail |
| Domain | alliedambitions.com | APTTrail |
| Domain | allin1livetv.xyz | APTTrail |
| Domain | allretail.shop | APTTrail |
| Domain | allstaramerican.com | APTTrail |
| Domain | almaxhura.com | APTTrail |
| Domain | alquilerdecuatrimotosmedellin.com | APTTrail |
| Domain | alsawsanaalsawdaa.com | APTTrail |
| Domain | alugueseusite.net | APTTrail |
Referencias
- https://bi.zone/expertise/blog/rainbow-hyena-snova-atakuet-novyy-bekdor-i-smena-taktik/
- https://securelist.com/head-mare-hacktivists/113555/
- https://securelist.ru/head-mare-phantomheart-and-phantomproxylite/114753/
- https://www.virustotal.com/gui/file/01f12bb3f4359fae1138a194237914f4fcdbf9e472804e428a765ad820f399be/detection
- https://www.virustotal.com/gui/file/063a8cad2115f6021532fa5093b33ec322b052c936659ec5cb42aa53a8207e59/detection
- https://www.virustotal.com/gui/file/0f1dcdc414afca59f97800a2d108089bf9f9a0cb3f7fbf0522dc10e8f7449046/detection
- https://www.virustotal.com/gui/file/4a65b7a0f940a55ab308595844ec2df205487d8b291162fb11d066ac3765074d/detection
- https://www.virustotal.com/gui/file/4c78d6bba282aaff0eab749cfa8a28e432f7cbf9c61dec8de8f4800fd27e0314/detection
- https://www.virustotal.com/gui/file/5d924a9ab2774120c4d45a386272287997fd7e6708be47fb93a4cad271f32a03/detection
- https://www.virustotal.com/gui/file/7e9d6a70a13c589622f47b2b984a9952c6498e8564df9e0e3fd86a7ac0088bf4/detection
- https://www.virustotal.com/gui/file/a048c920cf17b9ab4060e67dcd7d94b03aabb6636f895ede59d63b35c1145024/detection
- https://www.virustotal.com/gui/file/a464cfd80810c6f5357b4e738317e900baef9a45fbbc59f5c51475f69b053e5e/detection