Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a APT-Q-95. Aliases observados: APT-Q-95. Conteo por tipo: domain: 31.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | app.flowgw.com | APTTrail |
| Domain | ccproxy.org | APTTrail |
| Domain | cloud.synologyupdates.com | APTTrail |
| Domain | comfyupdate.org | APTTrail |
| Domain | coremailtech.com | APTTrail |
| Domain | daihou360.com | APTTrail |
| Domain | dashboard.daihou360.com | APTTrail |
| Domain | doubleclicked.com | APTTrail |
| Domain | e-mailrelay.com | APTTrail |
| Domain | fastapi-cdn.com | APTTrail |
| Domain | flowgw.com | APTTrail |
| Domain | fortisys.net | APTTrail |
| Domain | haprxy.org | APTTrail |
| Domain | liveupdate.wsupdatecloud.net | APTTrail |
| Domain | lvusdupdates.org | APTTrail |
| Domain | mirror1.mirrors-openjdk.org | APTTrail |
| Domain | mirrors-openjdk.org | APTTrail |
| Domain | ms-nipre.com | APTTrail |
| Domain | ms.wsupdatecloud.net | APTTrail |
| Domain | rhel.lvusdupdates.org | APTTrail |
| Domain | sangsoft.net | APTTrail |
| Domain | saperpcloud.com | APTTrail |
| Domain | shangjuyike.com | APTTrail |
| Domain | synologyupdates.com | APTTrail |
| Domain | threatbookav.com | APTTrail |
| Domain | tracking.doubleclicked.com | APTTrail |
| Domain | update.haprxy.org | APTTrail |
| Domain | update.saperpcloud.com | APTTrail |
| Domain | updates.ccproxy.org | APTTrail |
| Domain | wechatutilities.com | APTTrail |
Referencias
- https://github.com/RedDrip7/Report/blob/master/APT/Exclusive%20disclosure%20of%20the%20attack%20activities%20of%20the%20USA%20APT%20group%20NightEagle.pdf
- https://mp.weixin.qq.com/s/I907WsSIPfkTG8kYloj29w
- https://x.com/RedDrip7/status/1940637150158139764
- https://x.com/RedDrip7/status/1940780494662390135