Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a famoussparrow. Aliases observados: famoussparrow, keyboy, pirate panda, tropic trooper, usbferry. Conteo por tipo: domain: 90, ipv4: 27, url: 2.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | about.jkub.com | APTTrail |
| Domain | adobehomework.com | APTTrail |
| Domain | ak.buycheap.cn | APTTrail |
| Domain | amazoncdns.com | APTTrail |
| Domain | ap.missmichiko.com | APTTrail |
| Domain | api.cnicchina.com | APTTrail |
| Domain | athenatechlabs.com | APTTrail |
| Domain | auth.boxlibraries.com | APTTrail |
| Domain | awsdns-531.com | APTTrail |
| Domain | backus.myftp.name | APTTrail |
| Domain | blog.techmersion.com | APTTrail |
| Domain | broadmediacloud.com | APTTrail |
| Domain | buycheap.cn | APTTrail |
| Domain | c11r.awsdns-531.com | APTTrail |
| Domain | cache10.newsfreecloud.com | APTTrail |
| Domain | cachecloud.cloudflaresrv.com | APTTrail |
| Domain | cas04.awsdns-531.com | APTTrail |
| Domain | cdglobalclouds.com | APTTrail |
| Domain | cdn.kkxx888666.com | APTTrail |
| Domain | cdn101.cloudflaresrv.com | APTTrail |
| Domain | cdn181.awsdns-531.com | APTTrail |
| Domain | cloudflaresrv.com | APTTrail |
| Domain | cloudshappen.com | APTTrail |
| Domain | cloudsrv.cloudfrontsrv.com | APTTrail |
| Domain | cnicchina.com | APTTrail |
| Domain | credits.offices-analytics.com | APTTrail |
| Domain | dbacloudsupport.com | APTTrail |
| Domain | de.huseinhbz.click | APTTrail |
| Domain | dpponline.trickip.org | APTTrail |
| Domain | eleven.mypop3.org | APTTrail |
Referencias
- https://citizenlab.ca/2016/11/parliament-keyboy/
- https://documents.trendmicro.com/assets/Tech-Brief-Tropic-Trooper-s-Back-USBferry-Attack-Targets-Air-gapped-Environments.pdf
- https://github.com/ti-research-io/ti/blob/main/ioc_extender/ET_APT-FamousSparrow.json
- https://otx.alienvault.com/pulse/5ebd510bcf2617c25c082fb3
- https://otx.alienvault.com/pulse/614d9d97468b5d59e66efeec
- https://securelist.com/new-tropic-trooper-web-shell-infection/113737/
- https://twitter.com/0x680x610x6A/status/1761993166780330420
- https://twitter.com/r0ny_123/status/1410537058418888705
- https://www.trendmicro.com/content/dam/trendmicro/global/en/research/24/k/breaking-down-earth-estries-persistent-ttps-in-prolonged-cyber-operations/iocs-breaking-down-earth-estries-persistent-ttps-in-prolonged-cyber-operations.txt
- https://www.trendmicro.com/en_us/research/24/k/breaking-down-earth-estries-persistent-ttps-in-prolonged-cyber-o.html
- https://www.virustotal.com/gui/file/2f6cb063966125e0a9f2aa72e471c05657f95a3ddd9f65329071b7ee4acedce6/detection
- https://www.virustotal.com/gui/file/446a393266d27961c09217054182bb4003346cc402e62c700ac3e334f9bfa035/detection