Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a Ke3chang. Aliases observados: Ke3chang, Mirage, Playful Dragon, Royal APT, Vixen Panda, apt15. Conteo por tipo: domain: 59, file_path: 9, ipv4: 4, url: 1.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | adobeonline.net | APTTrail |
| Domain | andspurs.com | APTTrail |
| Domain | beltsymd.org | APTTrail |
| Domain | buy.babytoy-online.com | APTTrail |
| Domain | buy.healthcare-internet.com | APTTrail |
| Domain | cavanic9.net | APTTrail |
| Domain | center.nmsvillage.com | APTTrail |
| Domain | centrozhlan.com | APTTrail |
| Domain | chart.healthcare-internet.com | APTTrail |
| Domain | compatsec.com | APTTrail |
| Domain | control.mimepanel.org | APTTrail |
| Domain | cv.livehams.com | APTTrail |
| Domain | cyclophilit.com | APTTrail |
| Domain | cyprus-villas.org | APTTrail |
| Domain | daily.huntereim.com | APTTrail |
| Domain | dnsapp.info | APTTrail |
| Domain | dream.zepotac.com | APTTrail |
| Domain | dsmanfacture.privatedns.org | APTTrail |
| Domain | dyname.europemis.com | APTTrail |
| Domain | finance.globaleducat.com | APTTrail |
| Domain | forcan.hausblow.com | APTTrail |
| Domain | goback.strangled.net | APTTrail |
| Domain | grek.freetaxbar.com | APTTrail |
| Domain | halimatoudi.com | APTTrail |
| Domain | info.audioexp.com | APTTrail |
| Domain | inicializacion.com | APTTrail |
| Domain | item.amazonout.com | APTTrail |
| Domain | items.babytoy-online.com | APTTrail |
| Domain | items.burgermap.org | APTTrail |
| Domain | log.autocount.org | APTTrail |
Referencias
- https://app.any.run/tasks/8d777de7-d51d-4c97-8e91-d0e54461fc2b/
- https://github.com/PaloAltoNetworks/Unit42-timely-threat-intel/blob/main/2024-03-25-Timeline-for-misake-by-Playful-Taurus.txt
- https://otx.alienvault.com/pulse/5d3040c20c143e436cc113d8
- https://otx.alienvault.com/pulse/5ec7f55daebc94b5857d69f1
- https://otx.alienvault.com/pulse/6492f2af01c58203dd0bcd3b
- https://pastebin.com/qdDymcuy)
- https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/flea-backdoor-microsoft-graph-apt15
- https://twitter.com/MeltX0R/status/1174069208709312512
- https://twitter.com/MeltX0R/status/1174442212412809216
- https://twitter.com/VK_Intel/status/976977927072985088
- https://twitter.com/in_threat/status/735472063247421440
- https://twitter.com/malwrhunterteam/status/1616138902938746882