Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a dinodas. Aliases observados: dinodas, dinodasrat, linodas, linodasrat. Conteo por tipo: domain: 12, ipv4: 7, url: 5.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | 115-126-98-204.hkt.cc | APTTrail |
| Domain | 118-99-6-202.hkt.cc | APTTrail |
| Domain | centos-yum.com | APTTrail |
| Domain | microsoft-setting.com | APTTrail |
| Domain | microsoft-settings.com | APTTrail |
| Domain | security-microsoft.net | APTTrail |
| Domain | server-microsoft.com | APTTrail |
| Domain | update.centos-yum.com | APTTrail |
| Domain | update.microsoft-setting.com | APTTrail |
| Domain | update.microsoft-settings.com | APTTrail |
| Domain | update.windows.server-microsoft.com | APTTrail |
| Domain | windows.server-microsoft.com | APTTrail |
| IP | 115.126.98.204:443 | APTTrail |
| IP | 118.107.221.43:443 | APTTrail |
| IP | 118.107.221.43:5000 | APTTrail |
| IP | 118.107.221.43:8080 | APTTrail |
| IP | 118.99.6.202:443 | APTTrail |
| IP | 199.231.211.19:30612 | APTTrail |
| IP | 199.231.211.19:8080 | APTTrail |
| URL | http://115.126.98.204 | APTTrail |
| URL | http://118.99.6.202 | APTTrail |
| URL | http://23.106.122.46 | APTTrail |
| URL | http://23.106.122.5 | APTTrail |
| URL | http://23.106.123.166 | APTTrail |
Referencias
- https://github.com/eset/malware-ioc/tree/master/operation_jacana
- https://securelist.com/dinodasrat-linux-implant/112284/
- https://www.trendmicro.com/content/dam/trendmicro/global/en/research/24/c/earth-krahang-exploits-intergovernmental-trust-to-launch-cross-government-attacks/earth_krahang_iocs.txt
- https://www.trendmicro.com/en_us/research/24/c/earth-krahang.html
- https://www.virustotal.com/gui/file/15412d1a6b7f79fad45bcd32cf82f9d651d9ccca082f98a0cca3ad5335284e45/detection
- https://www.virustotal.com/gui/file/18f4f14857e9b7e3aa1f6f21f21396abd5f421342b7f4d00402a4aff5a538fa1/detection
- https://www.virustotal.com/gui/file/339479cb5a54424b520ff85f297882d410b8ecf179a45bad2c112b8c14f7575c/detection
- https://www.virustotal.com/gui/file/3f0aa01ed70bc2ab29557521a65476ec2ff2c867315067cc8a5937d63bcbe815/detection
- https://www.virustotal.com/gui/file/6fd7697efc137faf2d3ad5d63ffe4743db70f905a71dbed76207beeeb04732f2/detection
- https://www.virustotal.com/gui/file/98b5b4f96d4e1a9a6e170a4b2740ce1a1dfc411ada238e42a5954e66559a5541/detection
- https://www.virustotal.com/gui/file/9edf5313596432b4bad03bb7b16537c44652289b113430de7e3ed1cb5cf0760f/detection
- https://www.virustotal.com/gui/file/a2c3073fa5587f8a70d7def7fd8355e1f6d20eb906c3cd4df8c744826cb81d91/detection