Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a deadringer. Aliases observados: deadringer. Conteo por tipo: domain: 63, ipv4: 21.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | a.jrmfeeder.org | APTTrail |
| Domain | afhkl.dseqoorg.com | APTTrail |
| Domain | ahzx.eicp.net | APTTrail |
| Domain | ajtkgygth.com | APTTrail |
| Domain | aloha.fekeigawy.com | APTTrail |
| Domain | articles.whynotad.com | APTTrail |
| Domain | asp.asphspes.com | APTTrail |
| Domain | asphspes.com | APTTrail |
| Domain | bbs.forcejoyt.com | APTTrail |
| Domain | bkav.imshop.in | APTTrail |
| Domain | blog.toptogear.com | APTTrail |
| Domain | cat.suttiphong.com | APTTrail |
| Domain | cent.myanmarnewsrecent.com | APTTrail |
| Domain | cpc.mashresearchb.com | APTTrail |
| Domain | dathktdga.com | APTTrail |
| Domain | dgwktifrn.com | APTTrail |
| Domain | dns.jmrmfitym.com | APTTrail |
| Domain | dns.seekvibega.com | APTTrail |
| Domain | dthjxc.com | APTTrail |
| Domain | familymart-pay.cc | APTTrail |
| Domain | fekeigawy.com | APTTrail |
| Domain | freebsd.extrimtur.com | APTTrail |
| Domain | googlemm.vicp.net | APTTrail |
| Domain | guaranteed9.strangled.net | APTTrail |
| Domain | hosts.mysaol.com | APTTrail |
| Domain | http.jmrmfitym.com | APTTrail |
| Domain | imgs09.homenet.org | APTTrail |
| Domain | java.tripadvisorsapp.com | APTTrail |
| Domain | jdk.gsvvfsso.com | APTTrail |
| Domain | jmrmfitym.com | APTTrail |
Referencias
- https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2018/03/07205555/TheNaikonAPT-MsnMM1.pdf
- https://otx.alienvault.com/pulse/6089e5d691047973f36af713
- https://otx.alienvault.com/pulse/610a4bcdb92be5581d1071f0
- https://research.checkpoint.com/2020/naikon-apt-cyber-espionage-reloaded/
- https://securelist.com/analysis/publications/69567/the-chronicles-of-the-hellsing-apt-the-empire-strikes-back/
- https://securelist.com/the-naikon-apt/69953/
- https://twitter.com/Arkbird_SOLG/status/1387548235246473220
- https://www.bitdefender.com/files/News/CaseStudies/study/396/Bitdefender-PR-Whitepaper-NAIKON-creat5397-en-EN.pdf
- https://www.cybereason.com/blog/deadringer-exposing-chinese-threat-actors-targeting-major-telcos#lateral-movement-paexec
- https://www.virustotal.com/gui/domain/familymart-pay.cc/community