APTTrail: APT DNSPIONAGE indicators and references

Fecha
18 Jun 2026
Actor
apt-dnspionage
Tipo
Ioc
Pais
Unknown
Sector
-
Confianza
high
100
Prioridad analitica
Alta

Basado en actor, pais, IOCs, TTPs, filtracion y calidad de contexto.

30IOCs
0TTPs
apt-dnspionageActor
UnknownPais
Executive Summary
APTTrail mantiene indicadores publicos asociados a APT DNSPIONAGE. Aliases observados: APT DNSPIONAGE. Conteo por tipo: domain: 519.

Key Points

  • https://blog.talosintelligence.com/2018/11/dnspionage-campaign-targets-middle-east.html
  • https://github.com/ti-research-io/ti/blob/main/ioc_extender/ET_DNS_Query_for_DNSpionage.json
  • https://www.virustotal.com/gui/ip-address/74.63.204.32/relations
  • https://www.virustotal.com/gui/ip-address/74.63.204.99/relations

Resumen APTTrail

APTTrail mantiene indicadores publicos asociados a APT DNSPIONAGE. Aliases observados: APT DNSPIONAGE. Conteo por tipo: domain: 519.

Indicadores de Compromiso (IOCs)

TipoValorContexto
Domain0ffice36o.comAPTTrail
Domain18-79-t.netAPTTrail
Domain1qhd6v.xyzAPTTrail
Domain4f-okdsvv.comAPTTrail
Domain5-9idk-gug7-k7.comAPTTrail
Domain52-ck29jr.comAPTTrail
Domain5z-hyq-g.netAPTTrail
Domain78p3-zgs-g-mc-u.comAPTTrail
Domain8f-mxh6-hupgd-dy.comAPTTrail
Domain8faf-rngtax.comAPTTrail
Domaina87-sun0r1w.comAPTTrail
Domainac5e1f-fd2ph.comAPTTrail
Domainacyjob.tokyoAPTTrail
Domainadchum.tokyoAPTTrail
Domainadzwrq.tokyoAPTTrail
Domainakgxtu.tokyoAPTTrail
Domainaletko.tokyoAPTTrail
Domainam41-pm24ea.comAPTTrail
Domainamb29l1v3re.comAPTTrail
Domainami10t-e37n.comAPTTrail
Domainan87-24pen1d.comAPTTrail
Domainand58-65kio.comAPTTrail
Domainapply33547.comAPTTrail
Domainar5-chj-n-22d.comAPTTrail
Domainas93-attack1.comAPTTrail
Domainaso5fr-gre4.comAPTTrail
Domainau.imonju.netAPTTrail
Domainb5mjjc8s.comAPTTrail
Domainbaebod.tokyoAPTTrail
Domainban09-4w1as.comAPTTrail

Referencias

Diamond Model

Adversary
apt-dnspionage
Ver perfil →
Victim
APTTrail: APT DNSPIONAGE indicators and references
Capability
Ioc
Infrastructure
0ffice36o.com
18-79-t.net
1qhd6v.xyz
4f-okdsvv.com

Indicadores de Compromiso (IOCs)

TipoValorContextoOSINT
Domain 0ffice36o.com APTTrail VT OffSec SOCRadar
Domain 18-79-t.net APTTrail VT OffSec SOCRadar
Domain 1qhd6v.xyz APTTrail VT OffSec SOCRadar
Domain 4f-okdsvv.com APTTrail VT OffSec SOCRadar
Domain 5-9idk-gug7-k7.com APTTrail VT OffSec SOCRadar
Domain 52-ck29jr.com APTTrail VT OffSec SOCRadar
Domain 5z-hyq-g.net APTTrail VT OffSec SOCRadar
Domain 78p3-zgs-g-mc-u.com APTTrail VT OffSec SOCRadar
Domain 8f-mxh6-hupgd-dy.com APTTrail VT OffSec SOCRadar
Domain 8faf-rngtax.com APTTrail VT OffSec SOCRadar
Domain a87-sun0r1w.com APTTrail VT OffSec SOCRadar
Domain ac5e1f-fd2ph.com APTTrail VT OffSec SOCRadar
Domain acyjob.tokyo APTTrail VT OffSec SOCRadar
Domain adchum.tokyo APTTrail VT OffSec SOCRadar
Domain adzwrq.tokyo APTTrail VT OffSec SOCRadar
Domain akgxtu.tokyo APTTrail VT OffSec SOCRadar
Domain aletko.tokyo APTTrail VT OffSec SOCRadar
Domain am41-pm24ea.com APTTrail VT OffSec SOCRadar
Domain amb29l1v3re.com APTTrail VT OffSec SOCRadar
Domain ami10t-e37n.com APTTrail VT OffSec SOCRadar
Domain an87-24pen1d.com APTTrail VT OffSec SOCRadar
Domain and58-65kio.com APTTrail VT OffSec SOCRadar
Domain apply33547.com APTTrail VT OffSec SOCRadar
Domain ar5-chj-n-22d.com APTTrail VT OffSec SOCRadar
Domain as93-attack1.com APTTrail VT OffSec SOCRadar
Domain aso5fr-gre4.com APTTrail VT OffSec SOCRadar
Domain au.imonju.net APTTrail VT OffSec SOCRadar
Domain b5mjjc8s.com APTTrail VT OffSec SOCRadar
Domain baebod.tokyo APTTrail VT OffSec SOCRadar
Domain ban09-4w1as.com APTTrail VT OffSec SOCRadar

Referencias y enlaces

→ Perfil del actor apt-dnspionage en el blog → Ver apt-dnspionage en IntelTracker → URL IntelTracker: blog.talosintelligence.com→ URL IntelTracker: github.com→ URL IntelTracker: www.virustotal.com→ URL IntelTracker: www.virustotal.com → Fuente OSINT: github.com→ Fuente OSINT: raw.githubusercontent.com→ Fuente OSINT: blog.talosintelligence.com→ Fuente OSINT: github.com→ Fuente OSINT: www.virustotal.com→ Fuente OSINT: www.virustotal.com → Buscar apt-dnspionage en APTTrail → Repositorio APTTrail → Buscar en Google News → Analizar en VirusTotal → Feed RSS del blog
← Volver al panel de inteligencia

Incidentes recientes