Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a bisonal. Aliases observados: bisonal, tonto, tontoteam. Conteo por tipo: domain: 232, file_path: 5, ipv4: 5, url: 4.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | 0906.toh.info | APTTrail |
| Domain | 21kmg.my-homeip.net | APTTrail |
| Domain | abulasha-banama.onedumb.com | APTTrail |
| Domain | acivo.serveblog.net | APTTrail |
| Domain | adobe-online.com | APTTrail |
| Domain | adoberevise.com | APTTrail |
| Domain | adobeupdata.zzux.com | APTTrail |
| Domain | adobeupdate.dns04.com | APTTrail |
| Domain | agent.my-homeip.net | APTTrail |
| Domain | alleyk.onthewifi.com | APTTrail |
| Domain | amanser951.otzo.com | APTTrail |
| Domain | anna111.epac.to | APTTrail |
| Domain | anrnet.servegame.com | APTTrail |
| Domain | applejp.myfw.us | APTTrail |
| Domain | asheepa.sytes.net | APTTrail |
| Domain | attachdaum.servecounterstrike.com | APTTrail |
| Domain | attachmaildaum.serveblog.net | APTTrail |
| Domain | attachmaildaum.servecounterstrike.com | APTTrail |
| Domain | babyhome.lflink.com | APTTrail |
| Domain | babyhome.mefound.com | APTTrail |
| Domain | baekmaonline.com | APTTrail |
| Domain | bbc.xxxy.info | APTTrail |
| Domain | beatidc.com | APTTrail |
| Domain | best.indoingwulearn.com | APTTrail |
| Domain | bitsshare.com | APTTrail |
| Domain | bizmeka.viewdns.net | APTTrail |
| Domain | bluecat.mefound.com | APTTrail |
| Domain | bluesky.jkub.com | APTTrail |
| Domain | bravojack.justdied.com | APTTrail |
| Domain | bucketnec.bounceme.net | APTTrail |
Referencias
- https://app.any.run/tasks/4c751168-358a-49c9-b751-e5b4aad9b060/
- https://asec.ahnlab.com/1298
- https://asec.ahnlab.com/en/51746/
- https://asec.ahnlab.com/ko/33948/ (Korean)
- https://blog.talosintelligence.com/2020/03/bisonal-10-years-of-play.html
- https://docs.google.com/spreadsheets/d/1lDzylI6Jymz7EE0agRVUsL3kwmJSRDjXYjr5l5MUOEk/edit#gid=127522608 (# Bisonal)
- https://go.recordedfuture.com/hubfs/reports/cta-2023-0919.pdf (# TAG-74, TAG74)
- https://otx.alienvault.com/pulse/5e612f6d1dadda20c4314b21
- https://otx.alienvault.com/pulse/62729ce9e66ec5fd15790d3a
- https://otx.alienvault.com/pulse/644fbd07a98ffc006a3e71cc
- https://researchcenter.paloaltonetworks.com/2018/07/unit42-bisonal-malware-used-attacks-russia-south-korea/
- https://securelist.com/cactuspete-apt-groups-updated-bisonal-backdoor/97962/