Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a APT TICK. Aliases observados: APT TICK. Conteo por tipo: domain: 19, url: 2.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | amamihanahana.com | APTTrail |
| Domain | englandprevail.com | APTTrail |
| Domain | han-game.com | APTTrail |
| Domain | kot.gogoblog.net | APTTrail |
| Domain | memsbay.com | APTTrail |
| Domain | menu.han-game.com | APTTrail |
| Domain | menu.rakutenline.com | APTTrail |
| Domain | menu.sa-guard.com | APTTrail |
| Domain | mssql.waterglue.org | APTTrail |
| Domain | oracle.eneygylakes.com | APTTrail |
| Domain | poi.cydisk.net | APTTrail |
| Domain | pre.englandprevail.com | APTTrail |
| Domain | rakutenline.com | APTTrail |
| Domain | rbb.gol-unkai4.com | APTTrail |
| Domain | rp.thumbbay.com | APTTrail |
| Domain | sa-guard.com | APTTrail |
| Domain | slientship.com | APTTrail |
| Domain | travelasist.com | APTTrail |
| Domain | update.saranmall.com | APTTrail |
| URL | http://103.127.124.117 | APTTrail |
| URL | http://103.127.124.119 | APTTrail |
Referencias
- https://blogs.jpcert.or.jp/ja/2019/02/tick-activity.html
- https://image.ahnlab.com/file_upload/asecissue_files/ASEC%20REPORT_vol.95.pdf
- https://otx.alienvault.com/pulse/5d10b9b00e51b1938fd552b5
- https://pastebin.com/91vYTTiZ
- https://www.welivesecurity.com/2023/03/14/slow-ticking-time-bomb-tick-apt-group-dlp-software-developer-east-asia/