Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a smokedham. Aliases observados: smokedham. Conteo por tipo: domain: 1832.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | 08f0.proxy-edge-c5f.workers.dev | APTTrail |
| Domain | 12.workbencn.com | APTTrail |
| Domain | 178.159.43.206.sslip.io | APTTrail |
| Domain | 1r.rvtoolsed.com | APTTrail |
| Domain | 1s.rvtoolsai.com | APTTrail |
| Domain | 1v.rvtoollsa.com | APTTrail |
| Domain | 1v.rvtootsad.com | APTTrail |
| Domain | 1yeralti.com | APTTrail |
| Domain | 20.rvtoolsaq.com | APTTrail |
| Domain | 20.rvtoolse.info | APTTrail |
| Domain | 20.rvtoolsme.com | APTTrail |
| Domain | 21.rvtoolsen.com | APTTrail |
| Domain | 22.rvtoolsik.com | APTTrail |
| Domain | 24.rvtoolis.info | APTTrail |
| Domain | 24.rvtoolsgo.com | APTTrail |
| Domain | 27.rvtoolsax.com | APTTrail |
| Domain | 2a.rvtoolso.info | APTTrail |
| Domain | 2b.rvtoolsit.com | APTTrail |
| Domain | 2j.rvtoolsup.com | APTTrail |
| Domain | 2w.s3abrowser.com | APTTrail |
| Domain | 3g.s3brovvser.com | APTTrail |
| Domain | 3p.workbenche.com | APTTrail |
| Domain | 40.workbencse.com | APTTrail |
| Domain | 45perhour.org | APTTrail |
| Domain | 4l.rvtoolslab.com | APTTrail |
| Domain | 4t.rvtoolsacs.com | APTTrail |
| Domain | 54.rvtoolsone.com | APTTrail |
| Domain | 58.rvtoolsmax.com | APTTrail |
| Domain | 5b.rvtoolsbox.com | APTTrail |
| Domain | 5n.rvtoolsrun.com | APTTrail |
Referencias
- https://app.any.run/tasks/a9391be5-4e71-4a95-9072-477f8afd906f/
- https://gist.github.com/drb-ra/179e8e9beca45bc10feba97cf8c5c7b1
- https://github.com/cert-orangecyberdefense/cti/blob/main/smokedham/iocs
- https://medium.com/trac-labs/who-ordered-the-smokedham-backdoor-delicacies-in-the-wild-87f51e2e5bd2
- https://research.cert.orangecyberdefense.com/smokedham/smoking_out_an_affiliate.pdf
- https://www.virustotal.com/gui/file/30427b6732fea64c2cdc0b40c19695902f2bdea5f87dab16b4082bb3cf208557/detection
- https://www.virustotal.com/gui/file/3ebc0df2b92a39d1fb4491b7aaf6996425214ebe85e6243f443f1db087172f27/detection
- https://www.virustotal.com/gui/file/cbbe98e1b36eb68a7afe534c21055f9cc793c2a6a7ca63256d273020a096f7a7/detection
- https://x.com/SquiblydooBlog/status/1993311260512075967
- https://x.com/g0njxa/status/2010485906466394343
- https://x.com/g0njxa/status/2027082406847709524
- https://x.com/g0njxa/status/2031034087801012435