Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a UAC-0008. Aliases observados: UAC-0008. Conteo por tipo: domain: 24, file_path: 4, url: 1.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | allwomens.eu | APTTrail |
| Domain | alt-2cdn.net | APTTrail |
| Domain | avidium.ru.com | APTTrail |
| Domain | corp-microsoft.com | APTTrail |
| Domain | cs1.wpc-v0cdn.org | APTTrail |
| Domain | edinstvennaya.eu | APTTrail |
| Domain | hdfilm-seyret.com | APTTrail |
| Domain | ipv6-microsoft.org | APTTrail |
| Domain | ipv6-wpnc.net | APTTrail |
| Domain | khabmama.eu | APTTrail |
| Domain | mail.nais-gov.org | APTTrail |
| Domain | nais-gov.com | APTTrail |
| Domain | nais-gov.org | APTTrail |
| Domain | ns2-dns.com | APTTrail |
| Domain | ns3-dns.com | APTTrail |
| Domain | redmond.corp-microsoft.com | APTTrail |
| Domain | secure-telemetry.net | APTTrail |
| Domain | services-glbdns2.com | APTTrail |
| Domain | shkolazhizni.eu | APTTrail |
| Domain | sibmama.eu | APTTrail |
| Domain | slingshop.ru.com | APTTrail |
| Domain | widget.forum-pokemon.com | APTTrail |
| Domain | wpc-v0cdn.org | APTTrail |
| Domain | zhenskoe-mnenie.eu | APTTrail |
| FILE_PATH | /g_38472341.php | APTTrail |
| FILE_PATH | engde.fr/community/viewforum.php | APTTrail |
| FILE_PATH | focus.tula.su/viewforum.php | APTTrail |
| FILE_PATH | topic.penza.su/viewtopic.php | APTTrail |
| URL | http://195.123.227.99 | APTTrail |
Referencias
- https://cert.gov.ua/article/37246
- https://otx.alienvault.com/pulse/5cf6846544f75bf827720cb4
- https://otx.alienvault.com/pulse/5d270b29fccc021c80764db4
- https://securelist.ru/buhtrap-strikes-again/90980/
- https://securelist.ru/news-buhtrap/89540/
- https://twitter.com/c_APT_ure/status/1171102216784158720
- https://www.virustotal.com/gui/file/2598455a3dc8ff8282adc081f87bceddb101281d168ebaee98bce784c21e6e40/detection
- https://www.virustotal.com/gui/file/b475f14a1ffdeaf883c73e97724544b9bba0f6c481830bd25e3ba0d0f69b9181/detection (# Win32/Spy.Buhtrap.AK, ESET-NOD32)
- https://www.welivesecurity.com/2019/07/11/buhtrap-zero-day-espionage-campaigns/