Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a msupdater. Aliases observados: msupdater. Conteo por tipo: domain: 5, file_path: 4, url: 1.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | great.vssigma.com | APTTrail |
| Domain | red.vssigma.com | APTTrail |
| Domain | resell.siseau.com | APTTrail |
| Domain | siseau.com | APTTrail |
| Domain | vssigma.com | APTTrail |
| FILE_PATH | /microsoft/errorpost/default/connect.aspx | APTTrail |
| FILE_PATH | /microsoftupdate/getupdate/default.aspx | APTTrail |
| FILE_PATH | mail.hfmforum.com/microsoft/errorpost/default/connect.aspx | APTTrail |
| FILE_PATH | mail.hfmforum.com/microsoftupdate/getupdate/default.aspx | APTTrail |
| URL | http://140.112.19.195 | APTTrail |
Referencias
- https://samples.vx-underground.org/APTs/2010/2010.09.06/Paper/MSUpdater%20Trojan.pdf
- https://www.virustotal.com/gui/file/2ab81ed10aa5f5f3443714924e4d89ae3050c1a30332a55c2cfae58851ae4ac1/detection
- https://www.virustotal.com/gui/file/452b1789b5f9c6acc390148048f923f40270a3c2800ce4e1a8b9cbc90aab49e5/detection
- https://www.virustotal.com/gui/file/6a237ffe0f7d84ffd9652662a2638a9b5212636b414ce15ea2e39204d2a24e7f/detection
- https://www.virustotal.com/gui/file/75d3c3875744196cedff55d179bc62412adeba5e769fbfc85b2b891ff32b4f9f/detection
- https://www.virustotal.com/gui/file/d8a976979d4eeaf7485249c49d4a31824638a49dac308c5114c113b4a3eed9c9/detection