Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a chrysalis. Aliases observados: chrysalis, hacked notepad++, warbird. Conteo por tipo: domain: 51, ipv4: 5, url: 3.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | 38qmk6.0to9.info | APTTrail |
| Domain | 3qyo4o7.7r7i3.info | APTTrail |
| Domain | 7g91xhp.envuy3.net | APTTrail |
| Domain | aliancesky.com | APTTrail |
| Domain | api.cloudtrafficservice.com | APTTrail |
| Domain | api.skycloudcenter.com | APTTrail |
| Domain | api.wiresguard.com | APTTrail |
| Domain | asean-star.com | APTTrail |
| Domain | aseaneco.org | APTTrail |
| Domain | aseansec.dynalias.org | APTTrail |
| Domain | babysoal.com | APTTrail |
| Domain | beckhammer.xicp.net | APTTrail |
| Domain | boshman09.com | APTTrail |
| Domain | cdncheck.it.com | APTTrail |
| Domain | chris201.net | APTTrail |
| Domain | cloudtrafficservice.com | APTTrail |
| Domain | cpcl2006.dyndns-free.com | APTTrail |
| Domain | cybertunnel.dyndns.info | APTTrail |
| Domain | dtdf5vu.nt7yq.info | APTTrail |
| Domain | harryleed.dyndns.org | APTTrail |
| Domain | iascas.net | APTTrail |
| Domain | imonju.com | APTTrail |
| Domain | imonju.net | APTTrail |
| Domain | interhero.net | APTTrail |
| Domain | j.4tc3ldw.g9ml.www0.org | APTTrail |
| Domain | jackyson.dyndns.info | APTTrail |
| Domain | kid.dyndns.org | APTTrail |
| Domain | kjd.dyndns.org | APTTrail |
| Domain | l.hovux.eln9wj7.7gpj.org | APTTrail |
| Domain | newinfo32.eicp.net | APTTrail |
Referencias
- https://notepad-plus-plus.org/news/hijacked-incident-info-update/
- https://securelist.com/notepad-supply-chain-attack/118708/
- https://www.accenture.com/t20180131T100734Z__w__/us-en/_acnmedia/PDF-46/Accenture-Security-Elise-Threat-Analysis.pdf
- https://www.paloaltonetworks.com/content/dam/paloaltonetworks-com/en_US/assets/pdf/reports/Unit_42/operation-lotus-blossom/unit42-operation-lotus-blossom.pdf
- https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit/
- https://www.validin.com/blog/exploring_notepad_plus_plus_network_indicators/
- https://www.virustotal.com/gui/file/0755d2dc99c0a44f4e5435c398d9afca0db783e51a9df9ea472ac6936384d0d8/detection
- https://www.virustotal.com/gui/file/0a9b8df968df41920b6ff07785cbfebe8bda29e6b512c94a3b2a83d10014d2fd/detection
- https://www.virustotal.com/gui/file/7f2e0f51e83d6cf9c50922f898126b139f69cc49e8768830042358c1bd336dbc/detection
- https://www.virustotal.com/gui/file/b4169a831292e245ebdffedd5820584d73b129411546e7d3eccf4663d5fc5be3/detection
- https://www.virustotal.com/gui/file/e7cd605568c38bd6e0aba31045e1633205d0598c607a855e2e1bca4cca1c6eda/detection
- https://www.virustotal.com/gui/file/f365cfbca03a28a7692308c9766f8ae92f74f6c79aaa68458b1facbc74b534f2/detection