Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a apt-c-12. Aliases observados: apt-c-12, apt12, bluemushroom, dnscalc, dyncalc, ixeshe. Conteo por tipo: domain: 2, ipv4: 1, url: 10.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | icc.ignorelist.com | APTTrail |
| Domain | video.csmcpr.com | APTTrail |
| IP | 178.128.110.214:8080 | APTTrail |
| URL | http://128.199.73.43 | APTTrail |
| URL | http://139.59.101.236 | APTTrail |
| URL | http://139.59.110.217 | APTTrail |
| URL | http://139.59.226.29 | APTTrail |
| URL | http://139.59.230.181 | APTTrail |
| URL | http://141.108.2.157 | APTTrail |
| URL | http://159.65.127.93 | APTTrail |
| URL | http://159.65.74.97 | APTTrail |
| URL | http://188.226.144.42 | APTTrail |
| URL | http://59.73.16.165 | APTTrail |
Referencias
- https://bitofhex.com/2020/02/10/sapphire-mushroom-lnk-files/
- https://github.com/fireeye/iocs/tree/master/APT12
- https://otx.alienvault.com/pulse/5e447f6666b942ff1568cf2a
- https://twitter.com/ccxsaber/status/1189017890927726593
- https://www.fireeye.com/blog/threat-research/2014/09/darwins-favorite-apt-group-2.html
- https://www.virustotal.com/gui/file/a70d914bf690898d0737692735e99cea29741bb90360ba26e5c9cad9c59506b2/detection
- https://www.virustotal.com/gui/ip-address/141.108.2.157/relations