forked from stamparm/maltrail
-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathapt_unc4899.txt
45 lines (36 loc) · 1.08 KB
/
apt_unc4899.txt
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
# Copyright (c) 2014-2025 Maltrail developers (https://github.com/stamparm/maltrail/)
# See the file 'LICENSE' for copying permission
# Aliases: JumpCloud
# Reference: https://twitter.com/blackorbird/status/1683742730617499650
# Reference: https://www.sentinelone.com/labs/jumpcloud-intrusion-attacker-infrastructure-links-compromise-to-north-korean-apt-activity/
alwaysckain.com
canolagroove.com
centos-pkg.org
centos-repos.org
datadog-cloud.com
datadog-graph.com
launchruse.com
nomadpkg.com
nomadpkgs.com
primerosauxiliosperu.com
reggedrobin.com
toyourownbeat.com
zscaler-api.org
# Reference: https://www.mandiant.com/resources/blog/north-korea-supply-chain
basketsalute.com
contortonset.com
prontoposer.com
relysudden.com
rentedpushy.com
# Reference: https://twitter.com/ThreatBookLabs/status/1686582979563581440
alwaysswarm.com
sizzlesierra.com
sweptshut.com
# Reference: https://www.sentinelone.com/labs/comrades-in-arms-north-korea-compromises-sanctioned-russian-missile-engineering-company/
redhat-packages.com
centos-packages.com
dallynk.com
yolenny.com
606qipai.com
asplinc.com
bsef.or.kr