Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a MarkiRAT. Aliases observados: MarkiRAT. Conteo por tipo: domain: 32, file_path: 4.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | accountes.google.comesignt.website | APTTrail |
| Domain | accounts.google.comisignin.online | APTTrail |
| Domain | aparat.com-view.space | APTTrail |
| Domain | com-accounts.website | APTTrail |
| Domain | com-signin.site | APTTrail |
| Domain | com-view.org | APTTrail |
| Domain | com-view.space | APTTrail |
| Domain | come-signin.quest | APTTrail |
| Domain | comesignt.website | APTTrail |
| Domain | comi-site.website | APTTrail |
| Domain | comisignin.online | APTTrail |
| Domain | comuk.space | APTTrail |
| Domain | google.comisignin.online | APTTrail |
| Domain | khabarfarsi.com-view.org | APTTrail |
| Domain | microcaft.xyz | APTTrail |
| Domain | microsoft.com-view.space | APTTrail |
| Domain | microsoft.come-site.website | APTTrail |
| Domain | microsoft.comi-site.website | APTTrail |
| Domain | microsoft.comuk.space | APTTrail |
| Domain | microsoft.microcaft.xyz | APTTrail |
| Domain | microsoft.unupdate.ml | APTTrail |
| Domain | microsoft.unupload.xyz | APTTrail |
| Domain | microsoft.updatei.com | APTTrail |
| Domain | min.come-site.website | APTTrail |
| Domain | min.comi-site.website | APTTrail |
| Domain | ns1.com-accounts.website | APTTrail |
| Domain | ns1.com-signin.site | APTTrail |
| Domain | ns2.com-accounts.website | APTTrail |
| Domain | ns2.com-signin.site | APTTrail |
| Domain | unupdate.ml | APTTrail |
Referencias
- https://securelist.com/ferocious-kitten-6-years-of-covert-surveillance-in-iran/102806/
- https://twitter.com/360CoreSec/status/1407604585896632323
- https://twitter.com/360CoreSec/status/1407653661816201226
- https://twitter.com/360CoreSec/status/1435077875703562242
- https://www.virustotal.com/gui/file/361524fb3d40dd2f275ee7aa4f40fccfe21f0552cd36ec38f48fbf7e50e66810/detection
- https://www.virustotal.com/gui/file/400eb6a94810323a1fc5f8ab31c682fe765aaec2cc61b37c31d719c7e45c9a6c/detection
- https://www.virustotal.com/gui/file/51a6686b8c5ec7c610637398f3de43589f4e9fcbe8bcc0245343c5454d3b91de/detection
- https://www.virustotal.com/gui/file/5d69c23a226a5ad1068bb77b174cb8d00aa774c277e32824024f0d2fb21de1d9/detection
- https://www.virustotal.com/gui/file/66dcd98c6b310f4429890821e609d48cc6395a6be15ffe5a121ec68b7a8f7402/detection
- https://www.virustotal.com/gui/file/99eb211ea131834d93e25ba0c1066e37d5583f7694c51611337e1c44b60b7fa5/detection
- https://www.virustotal.com/gui/file/9a38069efc55a19d50d26d300948b9095ab72538acbf4ed427ed5a77060aa259/behavior/Microsoft%20Sysinternals
- https://www.virustotal.com/gui/file/b0d85647a0715e84a569fc79f6df3b9b82bac11e388948b767b4dbc7c721af47/detection