APTTrail: darknights indicators and references

Fecha
18 Jun 2026
Actor
darknights
Tipo
Ioc
Pais
Unknown
Sector
-
Confianza
high
100
Prioridad analitica
Alta

Basado en actor, pais, IOCs, TTPs, filtracion y calidad de contexto.

30IOCs
0TTPs
darknightsActor
UnknownPais
Executive Summary
APTTrail mantiene indicadores publicos asociados a darknights. Aliases observados: darknights, dknife, spellbinder, wizardnet. Conteo por tipo: domain: 4, ipv4: 13, url: 10.

Key Points

  • https://blog.talosintelligence.com/knife-cutting-the-edge/
  • https://github.com/Cisco-Talos/IOCs/blob/main/2026/02/knife-cutting-the-edge.txt
  • https://github.com/eset/malware-ioc/tree/master/thewizards
  • https://www.virustotal.com/gui/file/17a2dd45f9f57161b4cc40924296c4deab65beea447efb46d3178a9e76815d06/detection
  • https://www.welivesecurity.com/en/eset-research/thewizards-apt-group-slaac-spoofing-adversary-in-the-middle-attacks/

Resumen APTTrail

APTTrail mantiene indicadores publicos asociados a darknights. Aliases observados: darknights, dknife, spellbinder, wizardnet. Conteo por tipo: domain: 4, ipv4: 13, url: 10.

Indicadores de Compromiso (IOCs)

TipoValorContexto
Domainassetsqq.comAPTTrail
Domainmkdmcdn.comAPTTrail
Domainssl-dns.comAPTTrail
Domainvv.ssl-dns.comAPTTrail
IP110.185.104.180:8000APTTrail
IP110.92.64.177:8000APTTrail
IP117.175.185.81:8003APTTrail
IP43.132.205.118:81APTTrail
IP43.155.62.54:81APTTrail
IP47.238.107.83:81APTTrail
IP47.93.54.134:8001APTTrail
IP47.93.54.134:8003APTTrail
IP47.93.54.134:8005APTTrail
IP49.89.41.187:8001APTTrail
IP49.89.41.187:8002APTTrail
IP49.89.41.187:8003APTTrail
IP89.195.5.18:4553APTTrail
URLhttp://110.92.64.117APTTrail
URLhttp://110.92.64.17APTTrail
URLhttp://117.175.185.81APTTrail
URLhttp://210.56.49.72APTTrail
URLhttp://43.132.105.118APTTrail
URLhttp://43.155.62.54APTTrail
URLhttp://47.93.54.134APTTrail
URLhttp://49.89.41.187APTTrail
URLhttp://60.205.148.180APTTrail
URLhttp://61.139.76.99APTTrail

Referencias

Diamond Model

Adversary
darknights
Ver perfil →
Victim
APTTrail: darknights indicators and references
Capability
Ioc
Infrastructure
assetsqq.com
mkdmcdn.com
ssl-dns.com
vv.ssl-dns.com

Relations

Mapa de nodos relacionados por IOCs compartidos, actor, enlaces IntelTracker/OSINT, campanas y victimas observadas. Haz click en un nodo para abrir el post, filtro o fuente.

16 enlaces
Nodo actual
APTTrail: darknights indicators and references
darknights

Indicadores de Compromiso (IOCs)

TipoValorContextoOSINT
Domain assetsqq.com APTTrail VT OffSec SOCRadar
Domain mkdmcdn.com APTTrail VT OffSec SOCRadar
Domain ssl-dns.com APTTrail VT OffSec SOCRadar
Domain vv.ssl-dns.com APTTrail VT OffSec SOCRadar
IP 110.185.104.180:8000 APTTrail VT OffSec SOCRadar
IP 110.92.64.177:8000 APTTrail VT OffSec SOCRadar
IP 117.175.185.81:8003 APTTrail VT OffSec SOCRadar
IP 43.132.205.118:81 APTTrail VT OffSec SOCRadar
IP 43.155.62.54:81 APTTrail VT OffSec SOCRadar
IP 47.238.107.83:81 APTTrail VT OffSec SOCRadar
IP 47.93.54.134:8001 APTTrail VT OffSec SOCRadar
IP 47.93.54.134:8003 APTTrail VT OffSec SOCRadar
IP 47.93.54.134:8005 APTTrail VT OffSec SOCRadar
IP 49.89.41.187:8001 APTTrail VT OffSec SOCRadar
IP 49.89.41.187:8002 APTTrail VT OffSec SOCRadar
IP 49.89.41.187:8003 APTTrail VT OffSec SOCRadar
IP 89.195.5.18:4553 APTTrail VT OffSec SOCRadar
URL http://110.92.64.117 APTTrail VT OffSec SOCRadar
URL http://110.92.64.17 APTTrail VT OffSec SOCRadar
URL http://117.175.185.81 APTTrail VT OffSec SOCRadar
URL http://210.56.49.72 APTTrail VT OffSec SOCRadar
URL http://43.132.105.118 APTTrail VT OffSec SOCRadar
URL http://43.155.62.54 APTTrail VT OffSec SOCRadar
URL http://47.93.54.134 APTTrail VT OffSec SOCRadar
URL http://49.89.41.187 APTTrail VT OffSec SOCRadar
URL http://60.205.148.180 APTTrail VT OffSec SOCRadar
URL http://61.139.76.99 APTTrail VT OffSec SOCRadar
Domain blog.talosintelligence.com Extraido del contenido VT OffSec SOCRadar
Domain github.com Extraido del contenido VT OffSec SOCRadar
Domain www.virustotal.com Extraido del contenido VT OffSec SOCRadar

Referencias y enlaces

→ Perfil del actor darknights en el blog → Ver darknights en IntelTracker → URL IntelTracker: blog.talosintelligence.com→ URL IntelTracker: github.com→ URL IntelTracker: github.com→ URL IntelTracker: www.virustotal.com→ URL IntelTracker: www.welivesecurity.com→ URL IntelTracker: x.com → Fuente OSINT: github.com→ Fuente OSINT: raw.githubusercontent.com→ Fuente OSINT: blog.talosintelligence.com→ Fuente OSINT: github.com→ Fuente OSINT: github.com→ Fuente OSINT: www.virustotal.com → Buscar darknights en APTTrail → Repositorio APTTrail → Buscar en Google News → Analizar en VirusTotal → Feed RSS del blog
← Volver al panel de inteligencia

Incidentes recientes