Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a APT DARKHYDRUS. Aliases observados: APT DARKHYDRUS. Conteo por tipo: domain: 68.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | 0ffice.com | APTTrail |
| Domain | 0ffice365.agency | APTTrail |
| Domain | 0ffice365.life | APTTrail |
| Domain | 0ffice365.services | APTTrail |
| Domain | 0ffiice.com | APTTrail |
| Domain | 0nedrive.agency | APTTrail |
| Domain | 0utl00k.net | APTTrail |
| Domain | 0utlook.accountant | APTTrail |
| Domain | 0utlook.bid | APTTrail |
| Domain | akadns.services | APTTrail |
| Domain | akamai.agency | APTTrail |
| Domain | akamaiedge.live | APTTrail |
| Domain | akamaiedge.services | APTTrail |
| Domain | akamaized.live | APTTrail |
| Domain | akdns.live | APTTrail |
| Domain | allexa.net | APTTrail |
| Domain | anyconnect.stream | APTTrail |
| Domain | asimov-win-microsoft.services | APTTrail |
| Domain | asisdns.space | APTTrail |
| Domain | asismdnu.asisdns.space | APTTrail |
| Domain | azureedge.today | APTTrail |
| Domain | bigip.stream | APTTrail |
| Domain | brit.ns.cloudfronts.services | APTTrail |
| Domain | britns.akadns.live | APTTrail |
| Domain | britns.akadns.services | APTTrail |
| Domain | cisc0.net | APTTrail |
| Domain | citriix.net | APTTrail |
| Domain | cloudfronts.services | APTTrail |
| Domain | corewindows.agency | APTTrail |
| Domain | data-microsoft.services | APTTrail |
Referencias
- https://docs.google.com/document/d/1oYX3uN6KxIX_StzTH0s0yFNNoHDnV8VgmVqU5WoeErc (DarkHydrus 2017 activity)
- https://docs.google.com/document/d/1oYX3uN6KxIX_StzTH0s0yFNNoHDnV8VgmVqU5WoeErc (DarkHydrus 2017 activity)
- https://researchcenter.paloaltonetworks.com/2018/07/unit42-new-threat-actor-group-darkhydrus-targets-middle-east-government/
- https://unit42.paloaltonetworks.com/darkhydrus-delivers-new-trojan-that-can-use-google-drive-for-c2-communications/
- https://www.virustotal.com/gui/file/270ec2945fb976823e46d6fbb346fac46f585145ff05538846ab6cefc17064c8/detection
- https://www.virustotal.com/gui/file/f81a5f0f97eb9782e425f1fde19a40f5f4c2516df6ed8e40baad68b1a9bd0a53/detection
- https://www.virustotal.com/gui/ip-address/108.177.235.92/relations