Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a earthkapre. Aliases observados: earthkapre, goldblade, redcurl, redloader, redwolf. Conteo por tipo: domain: 58, ipv4: 2.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | alphastoned.pro | APTTrail |
| Domain | amscloudhost.com | APTTrail |
| Domain | app-ins-001.amscloudhost.com | APTTrail |
| Domain | app-ins-002.amscloudhost.com | APTTrail |
| Domain | app-l01.msftcloud.click | APTTrail |
| Domain | app-l03.msftcloud.click | APTTrail |
| Domain | app-l03.servicehost.click | APTTrail |
| Domain | app-l07.servicehost.click | APTTrail |
| Domain | automatinghrservices.workers.dev | APTTrail |
| Domain | bora.teracloud.jp | APTTrail |
| Domain | buyhighroad.scienceontheweb.net | APTTrail |
| Domain | cdn.wgroadcdn.workers.dev | APTTrail |
| Domain | clever.forcloudnetworks.online | APTTrail |
| Domain | cloud-01.servicehost.click | APTTrail |
| Domain | community.rmobileappdevelopment.workers.dev | APTTrail |
| Domain | ctrl1.sm.advhost.co.uk | APTTrail |
| Domain | cvsend.resumeexpert.cloud | APTTrail |
| Domain | datascience.iotconnectivity.workers.dev | APTTrail |
| Domain | dav.automatinghrservices.workers.dev | APTTrail |
| Domain | dav.cloud-01.servicehost.click | APTTrail |
| Domain | dav.linkedin-cloud-manager.servicehost.click | APTTrail |
| Domain | eap.byethost10.com | APTTrail |
| Domain | earthmart.c1.biz | APTTrail |
| Domain | fiona.forcloudnetworks.online | APTTrail |
| Domain | forcloudnetworks.online | APTTrail |
| Domain | hfn-c-001.cc.msftcloud.click | APTTrail |
| Domain | hwsrv-1048332.hostwindsdns.com | APTTrail |
| Domain | ksg-c-001.cc.msftcloud.click | APTTrail |
| Domain | ksg-c-002.cc.msftcloud.click | APTTrail |
| Domain | ktr-cn-001.amscloudhost.com | APTTrail |
Referencias
- https://bi-zone.medium.com/hunting-the-hunter-bi-zone-traces-the-footsteps-of-red-wolf-3677783e164d
- https://community.emergingthreats.net/t/ruleset-update-summary-2023-09-07-v10412/926
- https://community.emergingthreats.net/t/ruleset-update-summary-2023-09-08-v10413/928
- https://github.com/eSentire/iocs/blob/main/EarthKapre/EarthKapre-RedCurl-IoCs-02-05-2025.txt
- https://twitter.com/k3yp0d/status/1708495262673465713
- https://twitter.com/k3yp0d/status/1710230683870785767
- https://www.esentire.com/blog/unraveling-the-many-stages-and-techniques-used-by-redcurl-earthkapre-apt
- https://www.facct.ru/blog/redcurl-2024/
- https://www.huntress.com/blog/the-hunt-for-redcurl-2
- https://www.virustotal.com/gui/file/1ea43ba4192fd793de5aa18d20b60f0821dfe201f531ea4d1739b96a35526e36/detection
- https://www.virustotal.com/gui/file/3bd054a5095806cd7e8392b749efa283735616ae8a0e707cdcc25654059bfe6b/detection
- https://www.virustotal.com/gui/file/4188c953d784049dbd5be209e655d6d73f37435d9def71fd1edb4ed74a2f9e17/detection