Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a SPECTR. Aliases observados: SPECTR, Vermin, firmachagent. Conteo por tipo: domain: 27, url: 5.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | aeroua.online | APTTrail |
| Domain | akamaicdn.ru | APTTrail |
| Domain | akamainet021.info | APTTrail |
| Domain | akamainet022.info | APTTrail |
| Domain | akamainet023.info | APTTrail |
| Domain | akamainet024.info | APTTrail |
| Domain | akamainet066.info | APTTrail |
| Domain | akamainet067.info | APTTrail |
| Domain | aviasys.somee.com | APTTrail |
| Domain | cdnakamai.ru | APTTrail |
| Domain | code.ukraero.space | APTTrail |
| Domain | firma.ukraero.space | APTTrail |
| Domain | getmod.host | APTTrail |
| Domain | gw.telegrarn.fun | APTTrail |
| Domain | mail.ukraero.space | APTTrail |
| Domain | mailukr.net | APTTrail |
| Domain | meteolink.host | APTTrail |
| Domain | netbin.host | APTTrail |
| Domain | notifymail.ru | APTTrail |
| Domain | prozorro.online | APTTrail |
| Domain | stormpredictor.host | APTTrail |
| Domain | syncapp.host | APTTrail |
| Domain | tech-adobe.dyndns.biz | APTTrail |
| Domain | telegrarn.fun | APTTrail |
| Domain | ukr.somee.com | APTTrail |
| Domain | ukraero.space | APTTrail |
| Domain | windowsupdate.kiev.ua | APTTrail |
| URL | http://171.22.120.50 | APTTrail |
| URL | http://176.119.2.194 | APTTrail |
| URL | http://176.119.2.195 | APTTrail |
Referencias
- https://cert.gov.ua/article/37815 (Ukrainian)
- https://cert.gov.ua/article/6280422
- https://malpedia.caad.fkie.fraunhofer.de/details/win.vermin
- https://www.virustotal.com/gui/file/076edddf05a35a150d4e973eca9e7acd6249abca54f2d12ca05f0464aaca37e6/detection
- https://www.virustotal.com/gui/file/250f49264ff06c39f2222d4d7e73685ad39e72effe806341ccbe73d1fc759743/detection
- https://www.virustotal.com/gui/file/621b0d5a0c91b1d90588b78bc04fa961412601ab392b91b9d3995498a417dca4/detection
- https://www.virustotal.com/gui/file/b474e4db82023d913a00b6c127e1ba6c2b65129e906c4babdf01a69ef8851e84/detection
- https://www.virustotal.com/gui/ip-address/171.22.120.50/relations
- https://www.virustotal.com/gui/ip-address/91.225.219.185/relations
- https://www.virustotal.com/gui/ip-address/94.232.249.88/relations
- https://www.welivesecurity.com/wp-content/uploads/2018/07/ESET_Quasar_Sobaken_Vermin.pdf
- https://x.com/JAMESWT_WT/status/1950522465068720460