Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a exilerat. Aliases observados: exilerat, luckycat, sepulcher, shadownet, ta413. Conteo por tipo: domain: 56, ipv4: 8, url: 1.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | 89757.x.gg | APTTrail |
| Domain | airjaldi.online | APTTrail |
| Domain | applestatic.com | APTTrail |
| Domain | bailianlan.c.dwyu.com | APTTrail |
| Domain | cattree.1x.biz | APTTrail |
| Domain | charlesbrain.shop.co | APTTrail |
| Domain | clbest.greenglassint.net | APTTrail |
| Domain | dalailamatrustindia.ddns.net | APTTrail |
| Domain | duojee.info | APTTrail |
| Domain | fidk.rkntils.dnset.com | APTTrail |
| Domain | fireequipment.website.org | APTTrail |
| Domain | flex-jobs.in | APTTrail |
| Domain | footballworldcup.website.org | APTTrail |
| Domain | frankwhales.shop.co | APTTrail |
| Domain | freetibet.in | APTTrail |
| Domain | gmailcom.tw | APTTrail |
| Domain | goodwell.all.co.uk | APTTrail |
| Domain | havefuns.rkntils.10dig.net | APTTrail |
| Domain | hi21222325.x.gg | APTTrail |
| Domain | indiatrustdalailama.com | APTTrail |
| Domain | jeepvihecle.shop.co | APTTrail |
| Domain | jobflex.in | APTTrail |
| Domain | johnnees.rkntils.10dig.net | APTTrail |
| Domain | killmannets.0fees.net | APTTrail |
| Domain | kinkeechow.shop.co | APTTrail |
| Domain | kittyshop.kilu.org | APTTrail |
| Domain | lucysmith.0fees.net | APTTrail |
| Domain | maritimemaster.kilu.org | APTTrail |
| Domain | masterchoice.shop.co | APTTrail |
| Domain | mondaynews.tk | APTTrail |
Referencias
- http://www.trendmicro.com/cloud-content/us/pdfs/security-intelligence/white-papers/wp_luckycat_redux.pdf
- https://blog.talosintelligence.com/2019/02/exilerat-shares-c2-with-luckycat.html
- https://otx.alienvault.com/pulse/5f4faad08bc69edf206bf6b6
- https://otx.alienvault.com/pulse/6037c5dff774e1d70491bf0d/
- https://twitter.com/threatinsight/status/1531688214993555457
- https://www.proofpoint.com/us/blog/threat-insight/chinese-apt-ta413-resumes-targeting-tibet-following-covid-19-themed-economic
- https://www.proofpoint.com/us/blog/threat-insight/ta413-leverages-new-friarfox-browser-extension-target-gmail-accounts-global
- https://www.recordedfuture.com/chinese-state-sponsored-group-ta413-adopts-new-capabilities-in-pursuit-of-tibetan-targets
- https://www.virustotal.com/gui/ip-address/134.122.129.102/relations
- https://www.virustotal.com/gui/ip-address/172.105.35.111/relations
- https://www.virustotal.com/gui/ip-address/192.46.213.63/relations