Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a Hade ransomware. Aliases observados: Hade ransomware, TimosaraHackerTerm. Conteo por tipo: domain: 16, ipv4: 1.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | back.estonine.com | APTTrail |
| Domain | bingoshow.xyz | APTTrail |
| Domain | bk.estonine.com | APTTrail |
| Domain | does-no-exist33.estonine.com | APTTrail |
| Domain | e.estonine.com | APTTrail |
| Domain | indicate.estonine.com | APTTrail |
| Domain | inducate.estonine.com | APTTrail |
| Domain | load.estonine.com | APTTrail |
| Domain | log.estonine.com | APTTrail |
| Domain | moon.estonine.com | APTTrail |
| Domain | p.estonine.com | APTTrail |
| Domain | pslog.estonine.com | APTTrail |
| Domain | shelltools-1254394685.cos.ap-shanghai.myqcloud.com | APTTrail |
| Domain | sk.estonine.com | APTTrail |
| Domain | sploit.estonine.com | APTTrail |
| Domain | task.estonine.com | APTTrail |
| IP | 101.37.76.66:5000 | APTTrail |
Referencias
- https://twitter.com/BushidoToken/status/1369273531867992064
- https://twitter.com/Max_Mal_/status/1480284003617882121
- https://twitter.com/resecurity_com/status/1377137102094098439
- https://www.infosecurity-magazine.com/news/hades-ransomware-linked-hafnium/
- https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/
- https://www.virustotal.com/gui/file/62842cffd1c663ac2b2abe85a9fd482fcffc1c2e0683d1a536d8791b9f99cd3b/detection