Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a BlueBravo. Aliases observados: BlueBravo, NOBELIUM, SilverFish, dark halo, goldfinder, goldmax, raindrop, sibot, solorigate, stellarparticle, sunburst, sunshuttle. Conteo por tipo: domain: 192, file_path: 13, ipv4: 16, url: 4.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | 1cloudserver.com | APTTrail |
| Domain | 40ort.750.credit | APTTrail |
| Domain | 6a57jk2ba1d9keg15cbg.appsync-api.eu-west-1.avsvmcloud.com | APTTrail |
| Domain | 74d6b7b2.app.giftbox4u.com | APTTrail |
| Domain | 7sbvaemscs0mc925tb99.appsync-api.us-west-2.avsvmcloud.com | APTTrail |
| Domain | actualityworld.com | APTTrail |
| Domain | adagio.betterworldshopping.com | APTTrail |
| Domain | admirer.onehourcfo.com | APTTrail |
| Domain | adsprofitnetwork.com | APTTrail |
| Domain | aimsecurity.net | APTTrail |
| Domain | alertmeter.info | APTTrail |
| Domain | apexwebtech.com | APTTrail |
| Domain | appsprovider.com | APTTrail |
| Domain | appsync-api.eu-west-1.avsvmcloud.com | APTTrail |
| Domain | appsync-api.us-east-1.avsvmcloud.com | APTTrail |
| Domain | appsync-api.us-east-2.avsvmcloud.com | APTTrail |
| Domain | appsync-api.us-west-2.avsvmcloud.com | APTTrail |
| Domain | armrvrholo.com | APTTrail |
| Domain | assetdata.net | APTTrail |
| Domain | autonetonline.com | APTTrail |
| Domain | avsvmcloud.com | APTTrail |
| Domain | bacionera.top | APTTrail |
| Domain | backup.awarfaregaming.com | APTTrail |
| Domain | bfilmnews.com | APTTrail |
| Domain | bigdataanalysts.com | APTTrail |
| Domain | bigtopweb.com | APTTrail |
| Domain | bmlor.750.credit | APTTrail |
| Domain | builder.visionarybusiness.net | APTTrail |
| Domain | camogit.com | APTTrail |
| Domain | cdnappservice.firebaseio.com | APTTrail |
Referencias
- https://blog.talosintelligence.com/2020/12/solarwinds-supplychain-coverage.html
- https://community.riskiq.com/article/9a515637/description
- https://github.com/blackorbird/APT_REPORT/blob/master/SunBurst/SilverFish_Solarwinds.pdf
- https://go.recordedfuture.com/hubfs/reports/cta-2023-0127.pdf (# GraphicalNeutrino)
- https://news.sophos.com/en-us/2021/02/03/mtr-casebook-uncovering-a-backdoor-implant-in-a-solarwinds-orion-server/
- https://otx.alienvault.com/pulse/5fd6df943558e0b56eaf3da8
- https://otx.alienvault.com/pulse/5fdce61ef056eff2ce0a90de
- https://otx.alienvault.com/pulse/6007149a5ff246c7c18229c1
- https://otx.alienvault.com/pulse/60088b53da5e673bc2825ce8
- https://otx.alienvault.com/pulse/601da173ed7d3e7e31c67c3d/
- https://otx.alienvault.com/pulse/61558f3021612e32de83311f
- https://otx.alienvault.com/pulse/62bdd4f0a8d82702782ea614