Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a apolloshadow. Aliases observados: apolloshadow, atg26, blue python, kazuar, kypton, snake, storm-0156, uroburos, venomous bear, wainscot, waterbug, waterbug. Conteo por tipo: domain: 203, file_path: 52, ipv4: 4, url: 9.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | 61paris.fr | APTTrail |
| Domain | academyawards.effers.com | APTTrail |
| Domain | accessdest.strangled.net | APTTrail |
| Domain | adgf.am | APTTrail |
| Domain | adstore.twilightparadox.com | APTTrail |
| Domain | agony.compress.to | APTTrail |
| Domain | archive-articles.linkpc.net | APTTrail |
| Domain | arctic-zone.bbsindex.com | APTTrail |
| Domain | arinas.tk | APTTrail |
| Domain | auberdine.etowns.net | APTTrail |
| Domain | av.master.dns-cloud.net | APTTrail |
| Domain | avmaster.dns-cloud.net | APTTrail |
| Domain | badget.ignorelist.com | APTTrail |
| Domain | baltdefcol.webredirect.org | APTTrail |
| Domain | bedrost.com | APTTrail |
| Domain | bestfunc.slyip.net | APTTrail |
| Domain | bigpen.ga | APTTrail |
| Domain | blackerror.ignorelist.com | APTTrail |
| Domain | booking.etowns.org | APTTrail |
| Domain | booking.strangled.net | APTTrail |
| Domain | bookstore.strangled.net | APTTrail |
| Domain | branter.tk | APTTrail |
| Domain | bronerg.tk | APTTrail |
| Domain | bug.ignorelist.com | APTTrail |
| Domain | buy-new-car.com | APTTrail |
| Domain | caduff-sa.chjeepcarlease.com | APTTrail |
| Domain | carleasingguru.com | APTTrail |
| Domain | cars-online.zapto.org | APTTrail |
| Domain | celestyna.tk | APTTrail |
| Domain | ceremon.2waky.com | APTTrail |
Referencias
- http://artemonsecurity.com/snake_whitepaper.pdf
- http://info.baesystemsdetica.com/rs/baesystems/images/snake_whitepaper.pdf
- https://blog.google/threat-analysis-group/continued-cyber-activity-in-eastern-europe-observed-by-tag/
- https://blog.sekoia.io/turla-new-phishing-campaign-eastern-europe/
- https://blog.talosintelligence.com/tinyturla-full-kill-chain/
- https://blog.talosintelligence.com/tinyturla-next-generation/
- https://censys.com/blog/2025-state-of-the-internet-malware-investigations
- https://cert.gov.ua/article/5213167 (# UAC-0024, UAC-0003)
- https://cyble.com/blog/tiny-backdoor-goes-undetected-suspected-turla-leveraging-msbuild-to-evade-detection/
- https://github.com/eset/malware-ioc/blob/master/turla/README.adoc
- https://github.com/eset/malware-ioc/tree/master/turla
- https://github.com/eset/malware-ioc/tree/master/turla#gamaredon-x-turla-collab-indicators-of-compromise