APTTrail: APT RANCOR indicators and references

Fecha
18 Jun 2026
Actor
apt-rancor
Tipo
Ioc
Pais
United States
Sector
Tech
Confianza
high
100
Prioridad analitica
Alta

Basado en actor, pais, IOCs, TTPs, filtracion y calidad de contexto.

27IOCs
0TTPs
apt-rancorActor
United StatesPais
Executive Summary
APTTrail mantiene indicadores publicos asociados a APT RANCOR. Aliases observados: APT RANCOR. Conteo por tipo: domain: 18, ipv4: 1, url: 2.

Key Points

  • https://meltx0r.github.io/tech/2019/09/11/rancor-apt.html
  • https://otx.alienvault.com/pulse/5d94cb1196acaec6cb740e33
  • https://otx.alienvault.com/pulse/5dfa52f208b44bd6293eb130
  • https://research.checkpoint.com/rancor-the-year-of-the-phish/
  • https://twitter.com/MeltX0R/status/1172046597942915072

Resumen APTTrail

APTTrail mantiene indicadores publicos asociados a APT RANCOR. Aliases observados: APT RANCOR. Conteo por tipo: domain: 18, ipv4: 1, url: 2.

Indicadores de Compromiso (IOCs)

TipoValorContexto
Domain754d56-8523.sexidude.comAPTTrail
Domainbafunpda.xyzAPTTrail
Domaincharleseedwards.dynamic-dns.netAPTTrail
Domaindsdfdscxcv.justdied.comAPTTrail
Domaindsgsdgergrfv.toythieves.comAPTTrail
Domainfacebook-apps.comAPTTrail
Domainftp.chinhphu.ddns.msAPTTrail
Domaingoole.authorizeddns.usAPTTrail
Domainjdanief.xyzAPTTrail
Domainkfesv.xyzAPTTrail
Domainkibistation.onmypc.netAPTTrail
Domainmicrosoft.authorizeddns.usAPTTrail
Domainmicrosoft.https443.orgAPTTrail
Domainmsdns.otzo.comAPTTrail
Domainnicetiss54.lflink.comAPTTrail
Domainoui6473rf.xxuz.comAPTTrail
Domainsfstnksfcv.jungleheart.comAPTTrail
Domainvvcxvsdvx.dynamic-dns.netAPTTrail
IP139.162.14.25APTTrail
URLhttp://167.71.237.100APTTrail
URLhttp://199.247.6.253APTTrail

Referencias

Diamond Model

Adversary
apt-rancor
Ver perfil →
Victim
APTTrail: APT RANCOR indicators and references
United States
Capability
Ioc
Infrastructure
754d56-8523.sexidude.com
bafunpda.xyz
charleseedwards.dynamic-dns.net
dsdfdscxcv.justdied.com

Relations

Mapa de nodos relacionados por IOCs compartidos, actor, enlaces IntelTracker/OSINT, campanas y victimas observadas. Haz click en un nodo para abrir el post, filtro o fuente.

16 enlaces
Nodo actual
APTTrail: APT RANCOR indicators and references
apt-rancor · United States

Indicadores de Compromiso (IOCs)

TipoValorContextoOSINT
Domain 754d56-8523.sexidude.com APTTrail VT OffSec SOCRadar
Domain bafunpda.xyz APTTrail VT OffSec SOCRadar
Domain charleseedwards.dynamic-dns.net APTTrail VT OffSec SOCRadar
Domain dsdfdscxcv.justdied.com APTTrail VT OffSec SOCRadar
Domain dsgsdgergrfv.toythieves.com APTTrail VT OffSec SOCRadar
Domain facebook-apps.com APTTrail VT OffSec SOCRadar
Domain ftp.chinhphu.ddns.ms APTTrail VT OffSec SOCRadar
Domain goole.authorizeddns.us APTTrail VT OffSec SOCRadar
Domain jdanief.xyz APTTrail VT OffSec SOCRadar
Domain kfesv.xyz APTTrail VT OffSec SOCRadar
Domain kibistation.onmypc.net APTTrail VT OffSec SOCRadar
Domain microsoft.authorizeddns.us APTTrail VT OffSec SOCRadar
Domain microsoft.https443.org APTTrail VT OffSec SOCRadar
Domain msdns.otzo.com APTTrail VT OffSec SOCRadar
Domain nicetiss54.lflink.com APTTrail VT OffSec SOCRadar
Domain oui6473rf.xxuz.com APTTrail VT OffSec SOCRadar
Domain sfstnksfcv.jungleheart.com APTTrail VT OffSec SOCRadar
Domain vvcxvsdvx.dynamic-dns.net APTTrail VT OffSec SOCRadar
IP 139.162.14.25 APTTrail VT OffSec SOCRadar
URL http://167.71.237.100 APTTrail VT OffSec SOCRadar
URL http://199.247.6.253 APTTrail VT OffSec SOCRadar
Domain meltx0r.github.io Extraido del contenido VT OffSec SOCRadar
Domain otx.alienvault.com Extraido del contenido VT OffSec SOCRadar
Domain research.checkpoint.com Extraido del contenido VT OffSec SOCRadar
Domain twitter.com Extraido del contenido VT OffSec SOCRadar
Domain unit42.paloaltonetworks.com Extraido del contenido VT OffSec SOCRadar
Domain www.virustotal.com Extraido del contenido VT OffSec SOCRadar

Referencias y enlaces

→ Perfil del actor apt-rancor en el blog → Ver apt-rancor en IntelTracker → URL IntelTracker: meltx0r.github.io→ URL IntelTracker: otx.alienvault.com→ URL IntelTracker: otx.alienvault.com→ URL IntelTracker: research.checkpoint.com→ URL IntelTracker: twitter.com→ URL IntelTracker: unit42.paloaltonetworks.com → Fuente OSINT: github.com→ Fuente OSINT: raw.githubusercontent.com→ Fuente OSINT: meltx0r.github.io→ Fuente OSINT: otx.alienvault.com→ Fuente OSINT: otx.alienvault.com→ Fuente OSINT: research.checkpoint.com → Buscar apt-rancor en APTTrail → Repositorio APTTrail → Mas incidentes en United States → Buscar en Google News → Analizar en VirusTotal → Feed RSS del blog
← Volver al panel de inteligencia

Incidentes recientes