Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a DNSep. Aliases observados: DNSep, ironhusky, nccTrojan, phantomnet, piratepanda, portdoor, smanager. Conteo por tipo: domain: 86, ipv4: 13, url: 6.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | aircraft.tsagagaar.com | APTTrail |
| Domain | aiwqi.aurobindos.com | APTTrail |
| Domain | atlas.golianbooks.com | APTTrail |
| Domain | atob.kommesantor.com | APTTrail |
| Domain | aurobindos.com | APTTrail |
| Domain | beijingspring.niccenter.net | APTTrail |
| Domain | bloomberg.mefound.com | APTTrail |
| Domain | bloomberg.ns02.biz | APTTrail |
| Domain | cniitiic.com | APTTrail |
| Domain | coms.documentmeda.com | APTTrail |
| Domain | custom.songuulcomiss.com | APTTrail |
| Domain | darknightcloud.com | APTTrail |
| Domain | defensysminck.net | APTTrail |
| Domain | dm.golianbooks.com | APTTrail |
| Domain | doc.redstrpela.net | APTTrail |
| Domain | documentmeda.com | APTTrail |
| Domain | dog.darknightcloud.com | APTTrail |
| Domain | dotomater.club | APTTrail |
| Domain | ecustoms-mn.com | APTTrail |
| Domain | eye.darknightcloud.com | APTTrail |
| Domain | f1news.vzglagtime.net | APTTrail |
| Domain | fax.internnetionfax.com | APTTrail |
| Domain | foudation.sdelanasnou.com | APTTrail |
| Domain | freenow.chickenkiller.com | APTTrail |
| Domain | fuji1.aurobindos.com | APTTrail |
| Domain | gazar.ecustoms-mn.com | APTTrail |
| Domain | go.vegispaceshop.org | APTTrail |
| Domain | gogonews.organiccrap.com | APTTrail |
| Domain | golianbooks.com | APTTrail |
| Domain | govi-altai.ecustoms-mn.com | APTTrail |
Referencias
- https://app.any.run/tasks/8937295d-ea36-4398-96bd-20e7f3b193cb/
- https://app.any.run/tasks/a4701084-98e4-49d2-9938-c7ca5239e2a0/
- https://blog.group-ib.com/task (# Albaniiutas/BlueTraveller/RemShell/Tmanger/Mail-O/Webdav-O)
- https://github.com/DoctorWebLtd/malware-iocs/blob/master/APT_DNSep/README.adoc
- https://ics-cert.kaspersky.com/publications/reports/2022/08/08/targeted-attack-on-industrial-enterprises-and-public-institutions/
- https://insight-jp.nttsecurity.com/post/102gkfp/pandas-new-arsenal-part-2-albaniiutas (Japanese)
- https://insight-jp.nttsecurity.com/post/102glv5/pandas-new-arsenal-part-3-smanager
- https://insight-jp.nttsecurity.com/post/102gr6l/ta428ncctrojan
- https://labs.sentinelone.com/thundercats-hack-the-fsb-your-taxes-didnt-pay-for-this-op/
- https://otx.alienvault.com/pulse/5f74cab71bb5d12e32842814
- https://otx.alienvault.com/pulse/5fc5453982a82b8e4e6e7f58
- https://otx.alienvault.com/pulse/5fd3f1f18a7e313da2c01587