Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a hydra saiga. Aliases observados: hydra saiga, shadowsilk. Conteo por tipo: domain: 251, file_path: 1, ipv4: 21, url: 9.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | accessibleneats.com | APTTrail |
| Domain | accttechllc.com | APTTrail |
| Domain | adm-govuz.com | APTTrail |
| Domain | admin.inboxsession.info | APTTrail |
| Domain | akcloud.top | APTTrail |
| Domain | akersolutoins.com | APTTrail |
| Domain | alandyh.com | APTTrail |
| Domain | albertinamachinery.com | APTTrail |
| Domain | alfhjdumnsulhuehs.com | APTTrail |
| Domain | allcloudindex.com | APTTrail |
| Domain | allocco-ar.com | APTTrail |
| Domain | alpine-hosokawa.net | APTTrail |
| Domain | altendorf-de.com | APTTrail |
| Domain | annons.info | APTTrail |
| Domain | arableaguenews.com | APTTrail |
| Domain | arpimportnl.com | APTTrail |
| Domain | asdnwakalet.net | APTTrail |
| Domain | asmtld.com | APTTrail |
| Domain | atomicenergylab.com | APTTrail |
| Domain | auth.allcloudindex.com | APTTrail |
| Domain | authmailinbox.com | APTTrail |
| Domain | ax47tui83.com | APTTrail |
| Domain | aydemirtek.com | APTTrail |
| Domain | babblnipresses.com | APTTrail |
| Domain | bencoconstructionsllc.com | APTTrail |
| Domain | bestdomblog.com | APTTrail |
| Domain | bestmartsolutions.com | APTTrail |
| Domain | bestunif.com | APTTrail |
| Domain | bluemoono.com | APTTrail |
| Domain | brainytask.tech | APTTrail |
Referencias
- https://app.validin.com/detail?find=64.7.198.66&type=ip4&ref_id=55f2c681bec#tab=resolutions
- https://app.validin.com/detail?find=Accessible%20Neats&type=raw&ref_id=ea4a621b30a#tab=host_pairs (# 2025-01-24)
- https://www.group-ib.com/blog/shadowsilk/
- https://www.seqrite.com/blog/operation-peek-a-baku-silent-lynx-apt-dushanbe-espionage/
- https://www.seqrite.com/blog/silent-lynx-apt-targeting-central-asian-entities/
- https://www.virustotal.com/gui/file/1b76931775aa4de29df27a9de764b22f17ca117d6e5ae184f4ef617c970fc007/detection
- https://www.virustotal.com/gui/file/297d1afa309cdf0c84f04994ffd59ee1e1175377c1a0a561eb25869909812c9c/detection
- https://www.virustotal.com/gui/file/3560660162f2268d52b69382c78192667a7eee5796d77418a8609b2f1709f834/detection
- https://www.virustotal.com/gui/file/66294c9925ad454d5640f4fe753da9e7d6742f60b093ed97be88fcdd47b04445/detection
- https://www.virustotal.com/gui/file/99c6017c8658faf678f1b171c8eb5d5fa7e7d08e0a0901b984a8e3e1fab565cd/detection
- https://www.virustotal.com/gui/file/a146e914560229a3389589acaee42cbcd37504731f8c7ba17676678db0547fed/detection
- https://www.virustotal.com/gui/file/c045344b23fc245f35a0ff4a6d6fa744d580cde45c8cd0849153dee7dce1d80c/detection