Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a CVE-2023-36884. Aliases observados: CVE-2023-36884, dustyhammock, meltingclaw, romcom, rustyclaw, shadyhammock, singlecamper, snipbot, uat-5647. Conteo por tipo: domain: 76, file_path: 9, ipv4: 16, url: 3.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | 1drv.fileshare.direct | APTTrail |
| Domain | 1drv.us.com | APTTrail |
| Domain | 4qzm.com | APTTrail |
| Domain | adbefnts.dev | APTTrail |
| Domain | adcreative.pictures | APTTrail |
| Domain | adobe.cloudcreative.digital | APTTrail |
| Domain | advanced-ip-scaner.com | APTTrail |
| Domain | advanced-ip-scanners.com | APTTrail |
| Domain | altimata.org | APTTrail |
| Domain | apisolving.com | APTTrail |
| Domain | aspx.io | APTTrail |
| Domain | bentaxworld.com | APTTrail |
| Domain | budgetnews.org | APTTrail |
| Domain | campanole.com | APTTrail |
| Domain | certifysop.com | APTTrail |
| Domain | cethernet.com | APTTrail |
| Domain | cloudcreative.digital | APTTrail |
| Domain | combinedresidency.org | APTTrail |
| Domain | copdaemi.top | APTTrail |
| Domain | correctiv.sbs | APTTrail |
| Domain | creativeadb.com | APTTrail |
| Domain | cwise.store | APTTrail |
| Domain | dashboard.penofach.com | APTTrail |
| Domain | devhubs.dev | APTTrail |
| Domain | devolredir.com | APTTrail |
| Domain | digitalsolutionstime.com | APTTrail |
| Domain | dns-msn.com | APTTrail |
| Domain | dnsresolver.online | APTTrail |
| Domain | docstorage.link | APTTrail |
| Domain | drv2ms.com | APTTrail |
Referencias
- https://app.validin.com/detail?find=185.225.74.94&type=ip4&ref_id=65ec9bcbe4c#tab=resolutions
- https://blog.talosintelligence.com/uat-5647-romcom/
- https://blogs.blackberry.com/en/2023/07/romcom-targets-ukraine-nato-membership-talks-at-nato-summit
- https://cert.gov.ua/article/2394117 (Ukrainian)
- https://cert.gov.ua/article/5077168 (# UAC-0168)
- https://community.emergingthreats.net/t/ruleset-update-summary-2024-11-26-v10753/2171
- https://explore.avertium.com/resource/two-microsoft-zero-day-vulnerabilities-exploited-by-attackers
- https://otx.alienvault.com/pulse/62f36c89909d6b719ba8d340
- https://twitter.com/DmitriyMelikov/status/1721991958464205142
- https://twitter.com/Joseliyo_Jstnk/status/1675803590462685185
- https://twitter.com/TLP_R3D/status/1655687889391431680
- https://twitter.com/TLP_R3D/status/1655844785075224576