Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a rare werewolf. Aliases observados: rare werewolf. Conteo por tipo: domain: 249, ipv4: 1.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | 4t-niagara.com | APTTrail |
| Domain | 4tniagara.com | APTTrail |
| Domain | accouts-verification.ru | APTTrail |
| Domain | acountservices.nl | APTTrail |
| Domain | acountservices.online | APTTrail |
| Domain | aemiliuszathe.nl | APTTrail |
| Domain | aeternus.be | APTTrail |
| Domain | alcor-as.com | APTTrail |
| Domain | allroundvideomedia.nl | APTTrail |
| Domain | almaz-aero.site | APTTrail |
| Domain | amorapersoneel.nl | APTTrail |
| Domain | anyhostings.ru | APTTrail |
| Domain | anyinfos.ru | APTTrail |
| Domain | aoffices.ru | APTTrail |
| Domain | autodegroenehoek.nl | APTTrail |
| Domain | autoopkoperbenny.be | APTTrail |
| Domain | autotificate.com | APTTrail |
| Domain | barbershopwbd.nl | APTTrail |
| Domain | batwoman-fashion.nl | APTTrail |
| Domain | beeldspraakfotografie.nl | APTTrail |
| Domain | berkelgame.com | APTTrail |
| Domain | bharatsingh-logistics.nl | APTTrail |
| Domain | biesbeauty.nl | APTTrail |
| Domain | blijlekkernij.nl | APTTrail |
| Domain | bloomakay.be | APTTrail |
| Domain | bmapps.org | APTTrail |
| Domain | boefjes.nl | APTTrail |
| Domain | boelit-pvlog.be | APTTrail |
| Domain | bouwwerkennoten.be | APTTrail |
| Domain | broodjesboutique.nl | APTTrail |
Referencias
- https://app.validin.com/detail?find=89.110.65.154&type=ip4&ref_id=e41544d48ff#tab=resolutions
- https://securelist.com/librarian-ghouls-apt-wakes-up-computers-to-steal-data-and-mine-crypto/116536/
- https://www.kaspersky.ru/blog/librarian-ghouls-cad-formats/38199/
- https://www.kaspersky.ru/blog/malicious-mailout-scr-attachment/37823/
- https://www.virustotal.com/gui/file/02e49ad0d589b463a5dae39e81ff6c4151b2b9baca366ede566a5c0829a75d84/detection
- https://www.virustotal.com/gui/file/26a632f35e4382310044085b7f0e94fb5cd47f30ace588f7fceef9283a26a54a/detection
- https://www.virustotal.com/gui/file/2d4943980d751e6551ca04be73d5443359cde2e1ee142ff35ab1c9e84c105f56/detection
- https://www.virustotal.com/gui/file/96c7ba19beef1a314a3575f250872dde5b61a82674abdc3508009179292b806f/detection
- https://www.virustotal.com/gui/ip-address/109.107.176.232/relations
- https://x.com/AUZombie/status/2004528083723047319
- https://x.com/PrakkiSathwik/status/2024500406274154503