Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a CVE-2023-41991. Aliases observados: CVE-2023-41991, CVE-2023-41992, CVE-2023-41993, Cytrox Predator. Conteo por tipo: domain: 127.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | 1domainregistry.com | APTTrail |
| Domain | almal-news.com | APTTrail |
| Domain | asistentcomercialonline.com | APTTrail |
| Domain | barbequebros.com | APTTrail |
| Domain | beinfo.net | APTTrail |
| Domain | bestshowineu.com | APTTrail |
| Domain | betly.me | APTTrail |
| Domain | blocoinformativo.com | APTTrail |
| Domain | bni-madagascar.com | APTTrail |
| Domain | boundbreeze.com | APTTrail |
| Domain | branchbreeze.com | APTTrail |
| Domain | buysalesblog.com | APTTrail |
| Domain | c.betly.me | APTTrail |
| Domain | c1tvapp.com | APTTrail |
| Domain | c3p0solutions.com | APTTrail |
| Domain | cabinet-salyk.kz | APTTrail |
| Domain | caddylane.com | APTTrail |
| Domain | canylane.com | APTTrail |
| Domain | chat-support.support | APTTrail |
| Domain | cheesyarcade.com | APTTrail |
| Domain | cibeg.online | APTTrail |
| Domain | clockpatcher.com | APTTrail |
| Domain | colabfile.com | APTTrail |
| Domain | craftilly.com | APTTrail |
| Domain | despachosnegocios.com | APTTrail |
| Domain | dollgoodies.com | APTTrail |
| Domain | drivemountain.com | APTTrail |
| Domain | e-kgd.kz | APTTrail |
| Domain | eclipsemonitor.com | APTTrail |
| Domain | eppointment.io | APTTrail |
Referencias
- https://blog.sekoia.io/the-predator-spyware-ecosystem-is-not-dead/
- https://citizenlab.ca/2023/09/predator-in-the-wires-ahmed-eltantawy-targeted-with-predator-spyware-after-announcing-presidential-ambitions/
- https://community.emergingthreats.net/t/ruleset-update-summary-2023-10-11-v10437/1028
- https://github.com/SpyGuard/SpyGuard/commit/5d2c914d55089aa67fecd1ab065d085b4051fd4c
- https://www.recordedfuture.com/research/predator-spyware-infrastructure-returns-following-exposure-sanctions
- https://www.recordedfuture.com/research/predator-still-active-new-links-identified
- https://www.virustotal.com/gui/ip-address/169.239.129.76/relations
- https://www.virustotal.com/gui/ip-address/185.123.102.40/relations
- https://www.virustotal.com/gui/ip-address/185.235.137.6/relations
- https://www.virustotal.com/gui/ip-address/185.243.113.169/relations
- https://www.virustotal.com/gui/ip-address/192.169.7.252/relations
- https://www.virustotal.com/gui/ip-address/193.29.56.252/relations