Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a Karakurt Lair. Aliases observados: Karakurt Lair, Karakurt Team. Conteo por tipo: domain: 11, ipv4: 4.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | 3f7nxkjway3d223j27lyad7v5cgmyaifesycvmwq7i7cbs23lb6llryd.onion | APTTrail |
| Domain | blog.karakurt.tech | APTTrail |
| Domain | internal.karakurt.tech | APTTrail |
| Domain | karachat.group | APTTrail |
| Domain | karachat.tech | APTTrail |
| Domain | karakurt.co | APTTrail |
| Domain | karakurt.group | APTTrail |
| Domain | karakurt.systems | APTTrail |
| Domain | karakurt.tech | APTTrail |
| Domain | karaleaks.com | APTTrail |
| Domain | omx5iqrdbsoitf3q4xexrqw5r5tfw7vp3vl3li3lfo7saabxazshnead.onion | APTTrail |
| IP | 178.255.220.111:3050 | APTTrail |
| IP | 94.156.174.204:3051 | APTTrail |
| IP | 94.156.174.204:443 | APTTrail |
| IP | 94.156.174.204:8443 | APTTrail |
Referencias
- https://gist.github.com/hrbrmstr/db75143d512faa983f7438b3f17e2f5a
- https://otx.alienvault.com/pulse/62986c1750cc114c19b706ce
- https://twitter.com/CSICCybersecur1/status/1532431727292862464
- https://twitter.com/S0ufi4n3/status/1542049327295696900
- https://www.cisa.gov/uscert/ncas/alerts/aa22-152a
- https://www.shodan.io/host/94.156.174.204
- https://www.thedfirspot.com/general-8-1
- https://www.virustotal.com/gui/ip-address/209.222.98.19/relations
- https://www.virustotal.com/gui/ip-address/78.31.67.191/relations
- https://www.virustotal.com/gui/ip-address/94.156.174.204/relations