Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a Heyoka. Aliases observados: Heyoka, Mongall, UNC94. Conteo por tipo: domain: 107, ipv4: 4, url: 3.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | adsoft.name | APTTrail |
| Domain | back.satunusa.org | APTTrail |
| Domain | baomoi.vnptnet.info | APTTrail |
| Domain | bbw.fushing.org | APTTrail |
| Domain | bca.zdungk.com | APTTrail |
| Domain | bkav.manlish.net | APTTrail |
| Domain | bkav.welikejack.com | APTTrail |
| Domain | bkavonline.vnptnet.info | APTTrail |
| Domain | bluesky1234.com | APTTrail |
| Domain | bush2015.net | APTTrail |
| Domain | cl.weststations.com | APTTrail |
| Domain | cloundvietnam.com | APTTrail |
| Domain | comnnet.net | APTTrail |
| Domain | cpt.vnptnet.inf | APTTrail |
| Domain | cvb.hotcup.pw | APTTrail |
| Domain | dellyou.com | APTTrail |
| Domain | dinhk.net | APTTrail |
| Domain | dns.foodforthought1.com | APTTrail |
| Domain | dns.lioncity.top | APTTrail |
| Domain | dns.satunusa.org | APTTrail |
| Domain | dns.zdungk.com | APTTrail |
| Domain | ds.vdcvn.com | APTTrail |
| Domain | ds.xrayccc.top | APTTrail |
| Domain | dungk.com | APTTrail |
| Domain | facebookmap.top | APTTrail |
| Domain | fbcl2.adsoft.name | APTTrail |
| Domain | fbcl2.softad.net | APTTrail |
| Domain | flower2.yyppmm.com | APTTrail |
| Domain | followag.org | APTTrail |
| Domain | foodforthought1.com | APTTrail |
Referencias
- https://twitter.com/AndreGironda/status/1757929271962550534
- https://twitter.com/alex_lanstein/status/1757855436261245194
- https://www.sentinelone.com/labs/aoqin-dragon-newly-discovered-chinese-linked-apt-has-been-quietly-spying-on-organizations-for-10-years/
- https://www.virustotal.com/gui/file/2110627fc40daaa7903210e310ee0f9ee8b79f47b6188431eb67b5f94e03a139/detection
- https://www.virustotal.com/gui/file/313355f5ecf62401247c61e147b43f74eb7fcbfdf4856c7270079265cac07026/detection
- https://www.virustotal.com/gui/file/4d082fbd76b9f8f83e29ea8fe5d2355558584e9dfb3b60b855537c786e8552e7/detection
- https://www.virustotal.com/gui/file/73125d33e358395f067849497b1694e81f0a23795bc9029ac1632ebb70f07338/detection
- https://www.virustotal.com/gui/file/7e31a7da7322546220f74b3f0556467cc1c2c41846dd9d31f4e942128b3a894f/detection
- https://www.virustotal.com/gui/file/908bdcb18265b0a3d93e7070d093050a028099a0af261ff0250a0b44a23cd3fe/detection
- https://www.virustotal.com/gui/file/9211a584ce32883437fba00adaa8df462683daad165bd740e43f2a4d6022b9a4/detection
- https://www.virustotal.com/gui/file/929eefaafc3906ae27371366addb838fba597091ab684a80117da97378164d73/detection
- https://www.virustotal.com/gui/file/bec277998b7780eb67dc6f436282652ca3f34a812a2555c8bfee87a5b890b2e7/detection