Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a vampirebot. Aliases observados: vampirebot. Conteo por tipo: domain: 21, ipv4: 1.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | api.samsungcareers.work | APTTrail |
| Domain | api3.samsungcareers.work | APTTrail |
| Domain | djactuallsbuilds.com | APTTrail |
| Domain | ftp.spaceq.ovh | APTTrail |
| Domain | get-reponse-subt1.duckdns.org | APTTrail |
| Domain | get-reponse-subt2.duckdns.org | APTTrail |
| Domain | get-reponse-subt3.duckdns.org | APTTrail |
| Domain | get-reponse-subt4.duckdns.org | APTTrail |
| Domain | img.samsungcareers.work | APTTrail |
| Domain | jobs-infomarriott.com | APTTrail |
| Domain | jobs-marriott.com | APTTrail |
| Domain | jobswork.vn | APTTrail |
| Domain | mail.jobs-infomarriott.com | APTTrail |
| Domain | mail.jobs-marriott.com | APTTrail |
| Domain | mail.jobswork.vn | APTTrail |
| Domain | mysupportnetflix.com | APTTrail |
| Domain | panel2.samsungcareers.work | APTTrail |
| Domain | samsung-work.com | APTTrail |
| Domain | samsungcareers.work | APTTrail |
| Domain | spaceq.ovh | APTTrail |
| Domain | workjobs.net | APTTrail |
| IP | 5.252.235.172:4449 | APTTrail |
Referencias
- https://github.com/blackorbird/APT_REPORT/blob/master/cybercrime/BatShadow/batshadow-vietnamese-threat-group-vampire-bot-report.pdf
- https://www.virustotal.com/gui/file/14aa9c1113184d439d6f65c6c55c1bfa3654c113f7ed164d92f0b439e2134342/detection
- https://www.virustotal.com/gui/file/afed785aef35e7997e2208e45b2f91a5110d246bc282e0d9a3f6b0698cb871d6/detection
- https://www.virustotal.com/gui/ip-address/103.124.95.115/relations
- https://www.virustotal.com/gui/ip-address/103.124.95.161/relations
- https://x.com/DaveLikesMalwre/status/1861387766812078398
- https://x.com/Thisism23567356/status/1861367550774292804
- https://x.com/blackorbird/status/1975811759610208662