Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a BackdoorDiplomacy. Aliases observados: BackdoorDiplomacy, Quarian, Turian. Conteo por tipo: domain: 67.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | 250f7cloud.crmdev.org | APTTrail |
| Domain | 29c04uc.ejalase.org | APTTrail |
| Domain | 62ffauc.ejalase.org | APTTrail |
| Domain | 7f4d9fcanet.microsoftshop.org | APTTrail |
| Domain | adboeonline.net | APTTrail |
| Domain | alberto2011.com | APTTrail |
| Domain | andyothers.acmetoy.com | APTTrail |
| Domain | bill.microsoftbuys.com | APTTrail |
| Domain | buffetfactory.oicp.io | APTTrail |
| Domain | cloud.fastpaymentser-vice.com | APTTrail |
| Domain | cloud.microsoftshop.org | APTTrail |
| Domain | cloud.skypecloud.net | APTTrail |
| Domain | crmdev.org | APTTrail |
| Domain | delldrivers.in | APTTrail |
| Domain | dnsupdate.dns1.us | APTTrail |
| Domain | dnsupdate.dns2.us | APTTrail |
| Domain | dynsystem.imbbs.in | APTTrail |
| Domain | efanshion.com | APTTrail |
| Domain | ejalase.org | APTTrail |
| Domain | fastpaymentser-vice.com | APTTrail |
| Domain | fazlol-lah.net | APTTrail |
| Domain | fazlollah.net | APTTrail |
| Domain | freedns02.dns2.us | APTTrail |
| Domain | icta.worldmessg.com | APTTrail |
| Domain | info.fazlol-lah.net | APTTrail |
| Domain | info.fazlollah.net | APTTrail |
| Domain | info.payamra-dio.com | APTTrail |
| Domain | info.payamradio.com | APTTrail |
| Domain | intelupdate.dns1.us | APTTrail |
| Domain | irir.org | APTTrail |
Referencias
- https://github.com/advanced-threat-research/IOCs/blob/master/2013/2013-10-07-quarian-group-targets-victims-with-spearphishing-attacks/quarian-group-targets-victims-with-spearphishing-attacks.csv
- https://otx.alienvault.com/pulse/60c341dc8964edd2e2fcb651
- https://otx.alienvault.com/pulse/6390cbe098c9fb94d48e7a1c
- https://otx.alienvault.com/pulse/63c82cfb80f9e85b9b69c3cc
- https://unit42.paloaltonetworks.com/playful-taurus/
- https://www.bitdefender.com/files/News/CaseStudies/study/426/Bitdefender-PR-Whitepaper-BackdoorDiplomacy-creat6507-en-EN.pdf
- https://www.welivesecurity.com/2021/06/10/backdoordiplomacy-upgrading-quarian-turian/