Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a clntend. Aliases observados: clntend, cxclnt, tidrone. Conteo por tipo: domain: 21, ipv4: 1.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | auto-update.microsoftsvc.com | APTTrail |
| Domain | bestadll.fghytr.com | APTTrail |
| Domain | client.wns.windowswns.com | APTTrail |
| Domain | eupractic.s3.ap-east-1.amazonaws.com | APTTrail |
| Domain | fghytr.com | APTTrail |
| Domain | hp.kt168.org | APTTrail |
| Domain | microsoftsvc.com | APTTrail |
| Domain | onmondayr.s3.ap-east-1.amazonaws.com | APTTrail |
| Domain | server.microsoftsvc.com | APTTrail |
| Domain | service.symantecsecuritycloud.com | APTTrail |
| Domain | symantecsecuritycloud.com | APTTrail |
| Domain | time.vmwaresync.com | APTTrail |
| Domain | totting.s3.ap-east-1.amazonaws.com | APTTrail |
| Domain | tpckcapital.top | APTTrail |
| Domain | update.microsoftsvc.com | APTTrail |
| Domain | upgrade.microsoftsvc.com | APTTrail |
| Domain | uppaycn.com | APTTrail |
| Domain | vmwaresync.com | APTTrail |
| Domain | windowswns.com | APTTrail |
| Domain | wns.windowswns.com | APTTrail |
| Domain | wot.tpckcapital.top | APTTrail |
| IP | 154.23.184.30:5178 | APTTrail |
Referencias
- https://www.trendmicro.com/en_us/research/24/i/tidrone-targets-military-and-satellite-industries-in-taiwan.html
- https://www.virustotal.com/gui/file/062b4a8f62ddc0ec1413c53e2603ca35262c39d5197f6373f17f3e901d023804/detection
- https://www.virustotal.com/gui/file/1f000332e413990043f2d0937b57b0599e0125ef367d9a5a557834e240493aa5/detection
- https://www.virustotal.com/gui/file/33168e7a4f00990778a0187d656ee3d3579a22c1c1786d4fe7e66fa2e089bb9b/detection
- https://www.virustotal.com/gui/file/35bd7839a815d65604f3ca85a3c473266c31779946728b9a14dc6020f0b707ac/detection
- https://www.virustotal.com/gui/file/4e9d2ca5da069bd5bbb103c836ed000dc9757ff4a7b564253abfbcc8ce95296a/detection
- https://www.virustotal.com/gui/file/57090a27a634bf87b46f28f92f0181fc2512a1ecf54fb111c793fafc1a231326/detection
- https://www.virustotal.com/gui/file/5920a5232d1daa6f860f9e652d4e770f9d0a3c3ec6dc51d3144ce0d4346246b6/detection
- https://www.virustotal.com/gui/file/8be2ac404e8f96fa9413ce70754c42424f51196b4c36107f94f01a320cbc0c74/detection
- https://www.virustotal.com/gui/file/8c49c2c2703e9a935773f96afe3ad305a34f07b1c68b0ef01d2deefcb6d2aa73/detection
- https://www.virustotal.com/gui/file/945beda7286c39f8493dc3b1bc2c46baf5300603322566bbb322c64076681ab8/detection
- https://www.virustotal.com/gui/file/95829d5acf7898d2a55efb680eb9c3f7492caabf53637aa0b00f54a77fe64ac4/detection