Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a APT DRIFTINGCLOUD. Aliases observados: APT DRIFTINGCLOUD. Conteo por tipo: domain: 4, url: 8.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | akamprod.com | APTTrail |
| Domain | googleanalytics.proxydns.com | APTTrail |
| Domain | servusers.com | APTTrail |
| Domain | u2d.servusers.com | APTTrail |
| URL | http://158.247.200.24 | APTTrail |
| URL | http://180.149.38.136 | APTTrail |
| URL | http://185.82.218.66 | APTTrail |
| URL | http://192.248.152.58 | APTTrail |
| URL | http://209.250.231.67 | APTTrail |
| URL | http://5.188.228.40 | APTTrail |
| URL | http://95.85.71.20 | APTTrail |
| URL | http://95.85.71.23 | APTTrail |
Referencias
- https://github.com/volexity/threat-intel/blob/main/2022/2022-06-15%20DriftingCloud%20-%20Zero-Day%20Sophos%20Firewall%20Exploitation%20and%20an%20Insidious%20Breach/indicators/indicators.csv
- https://www.volexity.com/blog/2022/06/15/driftingcloud-zero-day-sophos-firewall-exploitation-and-an-insidious-breach/