Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a brave prince. Aliases observados: brave prince, ghost419, gold dragon. Conteo por tipo: domain: 13, ipv4: 2.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | 0523qyfw.cn | APTTrail |
| Domain | 0523qyfw.com | APTTrail |
| Domain | eodo1.000webhostapp.com | APTTrail |
| Domain | followgho.byethost7.com | APTTrail |
| Domain | ink.inkboom.co.kr | APTTrail |
| Domain | nid-help-pchange.atwebpages.com | APTTrail |
| Domain | nyazz.com | APTTrail |
| Domain | one.0523qyfw.com | APTTrail |
| Domain | redi.nyazz.com | APTTrail |
| Domain | scrt1.nyazz.com | APTTrail |
| Domain | ssh.0523qyfw.cn | APTTrail |
| Domain | ssh.0523qyfw.com | APTTrail |
| Domain | trydai.000webhostapp.com | APTTrail |
| IP | 107.148.61.127:8084 | APTTrail |
| IP | 154.19.200.133:8087 | APTTrail |
Referencias
- https://securingtomorrow.mcafee.com/other-blogs/mcafee-labs/gold-dragon-widens-olympics-malware-attacks-gains-permanent-presence-on-victims-systems/
- https://www.virustotal.com/gui/file/04102f13e59243cd2a96c435e9cc3c6dc3b52c988865926434a3b8cb643e5e63/detection
- https://www.virustotal.com/gui/file/6153da017a50ba3f781c78b6a3a2be3552b9371574da657d97d0063a40b17bbf/detection
- https://x.com/malwrhunterteam/status/1851566881825538348
- https://x.com/malwrhunterteam/status/1851567599701705051