Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a taxoff. Aliases observados: taxoff, team46. Conteo por tipo: domain: 49.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | 2025primakovreadings.info | APTTrail |
| Domain | ads-stream-api-v2.global.ssl.fastly.net | APTTrail |
| Domain | advertnow.org | APTTrail |
| Domain | adverty.info | APTTrail |
| Domain | browser-time-stats.global.ssl.fastly.net | APTTrail |
| Domain | bus-pod-tenant.global.ssl.fastly.net | APTTrail |
| Domain | clip-rdp-api.global.ssl.fastly.net | APTTrail |
| Domain | common-rdp-front.global.ssl.fastly.net | APTTrail |
| Domain | corptravel.org | APTTrail |
| Domain | cybers46.team | APTTrail |
| Domain | cybers4646.my.id | APTTrail |
| Domain | e-library.wiki | APTTrail |
| Domain | elibrary.wiki | APTTrail |
| Domain | fast-telemetry-api.global.ssl.fastly.net | APTTrail |
| Domain | feedstream.info | APTTrail |
| Domain | front-static-api.global.ssl.fastly.net | APTTrail |
| Domain | futurebull.live | APTTrail |
| Domain | futurebull.net | APTTrail |
| Domain | globaloneai.com | APTTrail |
| Domain | infosecteam.info | APTTrail |
| Domain | kant300.kantiana.info | APTTrail |
| Domain | kantiana.info | APTTrail |
| Domain | kpmedia.city | APTTrail |
| Domain | main-front-api.global.ssl.fastly.net | APTTrail |
| Domain | mediaoprosso.ru | APTTrail |
| Domain | mil-by.info | APTTrail |
| Domain | moscow.corptravel.org | APTTrail |
| Domain | ms-appdata-fonts.global.ssl.fastly.net | APTTrail |
| Domain | ms-appdata-main.global.ssl.fastly.net | APTTrail |
| Domain | ms-appdata-query.global.ssl.fastly.net | APTTrail |
Referencias
- https://app.validin.com/detail?find=Future%20Bull&type=raw&ref_id=41bde129bf6#tab=host_pairs (# 2025-06-18)
- https://global.ptsecurity.com/analytics/pt-esc-threat-intelligence/team46-and-taxoff-two-sides-of-the-same-coin
- https://habr.com/ru/companies/pt/articles/841176/
- https://securelist.com/operation-forumtroll-new-targeted-campaign/118492/
- https://securelist.com/operation-forumtroll/115989/
- https://twitter.com/k3yp0d/status/1782068601534517624
- https://twitter.com/k3yp0d/status/1782082055905690092
- https://twitter.com/k3yp0d/status/1787851479421772047
- https://twitter.com/k3yp0d/status/1787852438591910201
- https://www.virustotal.com/gui/file/387252ca8e89f7c3daceb48ab1279dfe597a9043095624a485aa5820b3c446b9/detection
- https://www.virustotal.com/gui/file/608009b402c00bb8ef65cc8d805e1522ddf1632c7479be05244ebd38483e22df/detection
- https://www.virustotal.com/gui/file/736abfe5541b4175ff013b442a673b8387209e324e3e343a628838f3e428e526/detection