Resumen APTTrail
APTTrail mantiene indicadores publicos asociados a whiteelephant. Aliases observados: whiteelephant. Conteo por tipo: domain: 73, ipv4: 16, url: 7.
Indicadores de Compromiso (IOCs)
| Tipo | Valor | Contexto |
|---|---|---|
| Domain | abdupdates.com | APTTrail |
| Domain | alr3ady.net | APTTrail |
| Domain | antivirusreviewratings.com | APTTrail |
| Domain | authorisedsecurehost.com | APTTrail |
| Domain | bksrv3r001.com | APTTrail |
| Domain | bluecreams.com | APTTrail |
| Domain | bookshopmarket.com | APTTrail |
| Domain | brandsons.net | APTTrail |
| Domain | braninfall.net | APTTrail |
| Domain | c00lh0sting.com | APTTrail |
| Domain | c0ttenc0unty.com | APTTrail |
| Domain | cr3ator01.net | APTTrail |
| Domain | crowcatcher.com | APTTrail |
| Domain | crvhostia.net | APTTrail |
| Domain | currentnewsstore.com | APTTrail |
| Domain | customauthentication.com | APTTrail |
| Domain | devinmartin.net | APTTrail |
| Domain | directsupp0rt.com | APTTrail |
| Domain | divinepower.info | APTTrail |
| Domain | draganheart.com | APTTrail |
| Domain | easyhost-ing.com | APTTrail |
| Domain | easyslidesharing.net | APTTrail |
| Domain | f00dlover.info | APTTrail |
| Domain | filetrusty.net | APTTrail |
| Domain | follow-ship.com | APTTrail |
| Domain | forest-fire.net | APTTrail |
| Domain | foxypredators.com | APTTrail |
| Domain | freensecurehost.com | APTTrail |
| Domain | freesecurehostings.com | APTTrail |
| Domain | freewebdomainhost.com | APTTrail |
Referencias
- https://www.sentinelone.com/labs/elephant-hunting-inside-an-indian-hack-for-hire-group/
- https://www.virustotal.com/gui/file/088038c03cc1ed4a045f54c7e2bc051bc4f334a10db7f17e66db72d3e412c365/detection
- https://www.virustotal.com/gui/file/66a58da1d568fbca46462acbbce75c21b2d8f4735da5c34824feae6f8b525411/detection
- https://www.virustotal.com/gui/file/cd661a71d7f7e7076bd90af46ca5b3202b5a4af1067ac9ddff8dfcb8e6987426/detection
- https://www.virustotal.com/gui/file/d70de8d8263f54cf9dea72638e664556a6684b5f518bfb66f45271898653ad5c/detection
- https://www.virustotal.com/gui/file/f7460d0ead6b5923faa24bda2d1301fd3718893115ae5926780353a0279505a6/detection