Hunting APT Infrastructure with Validin

2024-09-19 Blackcell

https://blackcell.io/tool-tip-hunting-atp-infrastructure-with-validin/

Thumbnail for Hunting APT Infrastructure with Validin

Black Cell demonstrates an infrastructure-hunting workflow that pivots from a tweet linking domains to Kimsuky/APT43 into Validin passive DNS data. Starting with wetax-pay[.]online, the hunt follows historical resolutions to 154.90.63[.]101 and identifies additional domains using similar top-level domains, including platform[.]mycrypto-invest[.]com. The source treats the cryptocurrency-themed domain and the tweet attribution as support for Kimsuky/APT43-focused hunting, then recommends using HTTP headers and TLS certificate commonalities in tools such as Censys, FOFA, or Shodan to build detection rules.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN platform.mycrypto-invest.com 2024-09-19 2024-09-19
IPv4 154.90.63.101 2024-09-19 2024-09-19

Related Actors

Related Reports

« Back