Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a HeaderTip. Aliases observados: HeaderTip, cosmicbeetle, scarab, spacecolon. Conteo por tipo: domain: 55, ipv4: 1, url: 3.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | Markshell.etowns.net | APTTrail |
| Domain | akamaicdnup.com | APTTrail |
| Domain | apple.dynamic-dns.net | APTTrail |
| Domain | autocar.ServeUser.com | APTTrail |
| Domain | autocar.suroot.com | APTTrail |
| Domain | b.688.org | APTTrail |
| Domain | blackblog.chatnook.com | APTTrail |
| Domain | bulldog.toh.info | APTTrail |
| Domain | cdnupdate.net | APTTrail |
| Domain | cew58e.xxxy.info | APTTrail |
| Domain | coastnews.darktech.org | APTTrail |
| Domain | d.piii.net | APTTrail |
| Domain | d1lhk2kflvant7.cloudfront.net | APTTrail |
| Domain | demon.4irc.com | APTTrail |
| Domain | dynamic.ddns.mobi | APTTrail |
| Domain | ebook.port25.biz | APTTrail |
| Domain | expert.4irc.com | APTTrail |
| Domain | football.mrbasic.com | APTTrail |
| Domain | gjjb.flnet.org | APTTrail |
| Domain | imirnov.ddns.info | APTTrail |
| Domain | jingnan88.chatnook.com | APTTrail |
| Domain | lehnjb.epac.to | APTTrail |
| Domain | lockbitblog.info | APTTrail |
| Domain | logoff.25u.com | APTTrail |
| Domain | logoff.ddns.info | APTTrail |
| Domain | ls910329.my03.com | APTTrail |
| Domain | mailru.25u.com | APTTrail |
| Domain | mert.my03.com | APTTrail |
| Domain | mydear.ddns.info | APTTrail |
| Domain | nazgul.zyns.com | APTTrail |
Referencias
- http://www.symantec.com/content/en/us/enterprise/media/security_response/docs/Scarab_IOCs_January_2015.txt
- https://cert.gov.ua/article/38097 (Ukrainian)
- https://github.com/eset/malware-ioc/tree/master/cosmicbeetle
- https://otx.alienvault.com/pulse/64e62628ed1119d03d3db75a
- https://threatfox.abuse.ch/browse/malware/win.scarab_ransom/ (# 2024-01-01)
- https://twitter.com/aRtAGGI/status/1506010831221248002
- https://twitter.com/fstenv/status/1505915405562482696
- https://twitter.com/h2jazi/status/1505887653111209994
- https://twitter.com/jaydinbas/status/1663916211975987201
- https://www.virustotal.com/gui/file/6bcb972bbd526433d9ad733eb7acfec2bc2e35686e9491a380fd5f7a09bf3276/detection
- https://www.virustotal.com/gui/file/71c87103296e5ccc2ff34316668a7e6142a64faddd6c61150025a23764c7905a/detection
- https://www.virustotal.com/gui/file/7239cac92aaf6bbbbf4e657bc65a385e495a67a15aa6bbad0e25f23407a77ba9/detection