Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a FlowCloud. Aliases observados: FlowCloud, LookBack, LookingFrog, Witchetty. Conteo por tipo: domain: 16, ipv4: 3, url: 4.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | a.bigbluedc.com | APTTrail |
| Domain | asce.email | APTTrail |
| Domain | bigbluedc.com | APTTrail |
| Domain | cahe.microsofts.com | APTTrail |
| Domain | daveengineer.com | APTTrail |
| Domain | dlaxpcmghd.com | APTTrail |
| Domain | energysemi.com | APTTrail |
| Domain | eset-sync.com | APTTrail |
| Domain | ffca.caibi379.com | APTTrail |
| Domain | nsfwgo.com | APTTrail |
| Domain | powersafetraining.net | APTTrail |
| Domain | powersafetrainings.org | APTTrail |
| Domain | s.eset-sync.com | APTTrail |
| Domain | smtp.nsfwgo.com | APTTrail |
| Domain | translateupdate.com | APTTrail |
| Domain | update.translateupdate.com | APTTrail |
| IP | 103.139.2.93:1702 | APTTrail |
| IP | 188.131.233.27:55555 | APTTrail |
| IP | 188.131.233.27:55556 | APTTrail |
| URL | http://161.82.181.4 | APTTrail |
| URL | http://43.254.216.104 | APTTrail |
| URL | http://43.254.219.153 | APTTrail |
| URL | http://45.124.115.103 | APTTrail |
Referencias
- https://github.com/eset/malware-ioc/tree/master/ta410
- https://otx.alienvault.com/pulse/5edf9678c760e3c7ca6fdf77
- https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/witchetty-steganography-espionage
- https://threatpost.com/espionage-group-utilities-spy-tool/156425/
- https://twitter.com/AnonySecAgency/status/1316292983508013056
- https://www.proofpoint.com/us/blog/threat-insight/ta410-group-behind-lookback-attacks-against-us-utilities-sector-returns-new
- https://www.virustotal.com/gui/file/0ac8315ba368579850dfb334dbde9e418b60473c90c31334820c56b7f4ef43dc/detection
- https://www.virustotal.com/gui/file/c88d0f7d623b2a2c066dd6b15597d1f4c44d89e7a8e660e28c3494f441826ea5/detection
- https://www.virustotal.com/gui/file/ff72aba3dc218190bc40fec95ef569df3c3ecd4da5fb435ed889e24e94d2a222/detection
- https://www.welivesecurity.com/2022/04/27/lookback-ta410-umbrella-cyberespionage-ttps-activity/