Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a foudre. Aliases observados: foudre, infy. Conteo por tipo: domain: 263.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | 017eab31.space | APTTrail |
| Domain | 01ead12b.space | APTTrail |
| Domain | 0ca0453a.site | APTTrail |
| Domain | 149a673e.dynu.net | APTTrail |
| Domain | 149a673e.net | APTTrail |
| Domain | 149a673e.space | APTTrail |
| Domain | 149a673e.top | APTTrail |
| Domain | 14c7e2dc.space | APTTrail |
| Domain | 15bb747b.site | APTTrail |
| Domain | 15ce27c5.site | APTTrail |
| Domain | 16e53040.space | APTTrail |
| Domain | 177a5c4a.space | APTTrail |
| Domain | 17ecf559.site | APTTrail |
| Domain | 1cb3c4c0.space | APTTrail |
| Domain | 1d4ee030.space | APTTrail |
| Domain | 1d8bfc20.space | APTTrail |
| Domain | 1f0e7a56.space | APTTrail |
| Domain | 23dafa1e.space | APTTrail |
| Domain | 2daa46f1.space | APTTrail |
| Domain | 32c39cf4.dynu.net | APTTrail |
| Domain | 32c39cf4.net | APTTrail |
| Domain | 32c39cf4.space | APTTrail |
| Domain | 32c39cf4.top | APTTrail |
| Domain | 334edefd.dynu.net | APTTrail |
| Domain | 334edefd.net | APTTrail |
| Domain | 334edefd.space | APTTrail |
| Domain | 334edefd.top | APTTrail |
| Domain | 341a436d.space | APTTrail |
| Domain | 34231ae4.dynu.net | APTTrail |
| Domain | 34231ae4.net | APTTrail |
Referencias
- https://malpedia.caad.fkie.fraunhofer.de/details/win.infy
- https://twitter.com/ShadowChasing1/status/1339190981703266304
- https://unit42.paloaltonetworks.com/prince-of-persia-infy-malware-active-in-decade-of-targeted-attacks/
- https://unit42.paloaltonetworks.com/unit42-prince-of-persia-game-over/
- https://unit42.paloaltonetworks.com/unit42-prince-persia-ride-lightning-infy-returns-foudre/
- https://www.intezer.com/blog/research/prince-of-persia-the-sands-of-foudre/
- https://www.safebreach.com/blog/prince-of-persia-a-decade-of-an-iranian-nation-state-apt-campaign-activity/
- https://www.safebreach.com/blog/prince-of-persia-part-ii/
- https://www.virustotal.com/gui/file/a64edb19e71549fb9248b27b58f911a4a1e8cd8b8e4adff93ecfb7e15a3cdad7/detection
- https://www.virustotal.com/gui/file/f535b46ad2452d61282f615faf35993e83b6c56c9533bf22c12f97f318242e06/detection
- https://www.virustotal.com/gui/file/f6bb93dda74c0de2032963e2804cacb47128603070fe04c372f86e69fa8ce47c/detection