Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a APT REDFOXTROT. Aliases observados: APT REDFOXTROT. Conteo por tipo: domain: 144, ipv4: 4.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | adobesupport.net | APTTrail |
| Domain | adtl.mywire.org | APTTrail |
| Domain | anywheres.run.place | APTTrail |
| Domain | appinfo.camdvr.org | APTTrail |
| Domain | appsupport.my-router.de | APTTrail |
| Domain | appupdate.firewall-gateway.de | APTTrail |
| Domain | appupdate.my-router.de | APTTrail |
| Domain | aries.epac.to | APTTrail |
| Domain | bbsaili.camdvr.org | APTTrail |
| Domain | billing.epac.to | APTTrail |
| Domain | capture.kozow.com | APTTrail |
| Domain | cheapnews.online | APTTrail |
| Domain | chock.mywire.org | APTTrail |
| Domain | ciscoteam.ignorelist.com | APTTrail |
| Domain | coreldraw.kozow.com | APTTrail |
| Domain | czconnections.ddns.info | APTTrail |
| Domain | darkpapa.chickenkiller.com | APTTrail |
| Domain | dhsg123.jkub.com | APTTrail |
| Domain | drdo.dumb1.com | APTTrail |
| Domain | drdo.mypop3.net | APTTrail |
| Domain | dsgf.chickenkiller.com | APTTrail |
| Domain | elienceso.kozow.com | APTTrail |
| Domain | exat.dnset.com | APTTrail |
| Domain | exat.zyns.com | APTTrail |
| Domain | execserver.giize.com | APTTrail |
| Domain | exujjat.xxuz.com | APTTrail |
| Domain | fashget.theworkpc.com | APTTrail |
| Domain | fivenum.mooo.com | APTTrail |
| Domain | foreverlove.zzux.com | APTTrail |
| Domain | forum.camdvr.org | APTTrail |
Referencias
- https://github.com/Insikt-Group/Research/blob/master/RedFoxtrot%20June%202021
- https://go.recordedfuture.com/hubfs/reports/cta-2021-0616.pdf
- https://otx.alienvault.com/pulse/60cc709013f5498fe7e60120
- https://otx.alienvault.com/pulse/61544024e496818edcda5f98
- https://twitter.com/Cyberteam008/status/1781204417481679199
- https://www.recordedfuture.com/chinese-apt-groups-target-afghan-telecommunications-firm/
- https://www.virustotal.com/gui/file/00efd6ece111a99e1aea36636baba3fdf2f021eb8c9cdef84350c78654d5c99c/detection
- https://www.virustotal.com/gui/file/44538a8b50c093cf17c6fbd799a51a39bac9a5f6fe8081e3f6d169a298a54a6f/detection
- https://www.virustotal.com/gui/file/8571f53a54efaf13ab5a1eabe1f33eb5d489cac32f23581c090db28577de5efe/detection
- https://www.virustotal.com/gui/file/8a3e3de44128ae2abada62c68f1e9f21468fb5103aa52f8320c8e1ea6a13dcd1/detection
- https://www.virustotal.com/gui/file/e4fe0bd698d7d4b346f2a77440f99157388f796a98e0fe26b2448f074b38428a/detection
- https://www.virustotal.com/gui/file/ed34d7d905f4169ea14e27410028b6b34cb1b55342638649670ccb1994332c35/detection