Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a APT SHAMOON. Aliases observados: APT SHAMOON. Conteo por tipo: domain: 10.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | analytics-google.org | APTTrail |
| Domain | go-microstf.com | APTTrail |
| Domain | key8854321.pub | APTTrail |
| Domain | maps-modon.club | APTTrail |
| Domain | mol.com-ho.me | APTTrail |
| Domain | mynetwork.ddns.net | APTTrail |
| Domain | ntg-sa.com | APTTrail |
| Domain | possibletarget.ddns.com | APTTrail |
| Domain | winappupdater.com | APTTrail |
| Domain | winupdater.com | APTTrail |
Referencias
- https://github.com/advanced-threat-research/IOCs/blob/master/2017/2017-01-27-spotlight-on-shamoon/spotlight-on-shamoon.csv
- https://github.com/advanced-threat-research/IOCs/blob/master/2018/2018-12-14-shamoon-returns-to-wipe-systems-in-middle-east-europe/shamoon-returns-to-wipe-systems-in-middle-east-europe.csv
- https://github.com/advanced-threat-research/IOCs/blob/master/2018/2018-12-19-shamoon-attackers-employ-new-tool-kit-to-wipe-infected-systems/shamoon-attackers-employ-new-tool-kit-to-wipe-infected-systems.csv
- https://securityintelligence.com/the-full-shamoon-how-the-devastating-malware-was-inserted-into-networks/
- https://www.arbornetworks.com/blog/asert/additional-insights-on-shamoon2/