cyber_threat_intelligence/actors/Bermuda Unknown/README.md

73 lines
4.9 KiB
Markdown
Raw Normal View History

2022-11-26 11:43:44 +00:00
# Bermuda Unknown - Cyber Threat Intelligence
These _indicators_ were reported, collected, and generated during the [VulDB CTI analysis](https://vuldb.com/?kb.cti) of the actor known as [Bermuda Unknown](https://vuldb.com/?actor.bermuda_unknown). The _activity monitoring_ correlates data from social media, forums, chat rooms, and darknet markets. It helps to determine associated actors, specific activities, expected intentions, emerging research, and ongoing attacks. Our unique _predictive model_ uses _big data_ to forecast activities and their characteristics.
_Live data_ and more _analysis capabilities_ are available at [https://vuldb.com/?actor.bermuda_unknown](https://vuldb.com/?actor.bermuda_unknown)
## IOC - Indicator of Compromise
These _indicators of compromise_ (IOC) indicate associated network resources which are known to be part of research and attack activities of Bermuda Unknown.
ID | IP address | Hostname | Campaign | Confidence
-- | ---------- | -------- | -------- | ----------
1 | [5.62.56.36](https://vuldb.com/?ip.5.62.56.36) | r-36-56-62-5.consumer-pool.prcdn.net | - | High
2 | [5.62.58.36](https://vuldb.com/?ip.5.62.58.36) | r-36-58-62-5.consumer-pool.prcdn.net | - | High
2023-06-06 08:26:07 +00:00
3 | [38.69.208.0](https://vuldb.com/?ip.38.69.208.0) | - | - | High
4 | [38.75.80.0](https://vuldb.com/?ip.38.75.80.0) | - | - | High
5 | [45.12.70.27](https://vuldb.com/?ip.45.12.70.27) | specious.get-eye.com | - | High
6 | [45.12.71.27](https://vuldb.com/?ip.45.12.71.27) | - | - | High
7 | [45.42.144.0](https://vuldb.com/?ip.45.42.144.0) | - | - | High
8 | [45.74.26.0](https://vuldb.com/?ip.45.74.26.0) | - | - | High
9 | [63.85.42.0](https://vuldb.com/?ip.63.85.42.0) | - | - | High
10 | [63.115.0.0](https://vuldb.com/?ip.63.115.0.0) | - | - | High
11 | [63.115.2.0](https://vuldb.com/?ip.63.115.2.0) | - | - | High
12 | [63.115.4.0](https://vuldb.com/?ip.63.115.4.0) | - | - | High
13 | [63.115.8.0](https://vuldb.com/?ip.63.115.8.0) | - | - | High
14 | [64.37.32.0](https://vuldb.com/?ip.64.37.32.0) | - | - | High
15 | [64.37.44.0](https://vuldb.com/?ip.64.37.44.0) | - | - | High
16 | [64.37.46.0](https://vuldb.com/?ip.64.37.46.0) | - | - | High
17 | [64.124.184.205](https://vuldb.com/?ip.64.124.184.205) | 64.124.184.205.IPYX-063261-006-ZYO.zip.zayo.com | - | High
18 | [64.147.80.0](https://vuldb.com/?ip.64.147.80.0) | 64.147.80.0.transact.bm | - | High
19 | [65.22.10.0](https://vuldb.com/?ip.65.22.10.0) | - | - | High
20 | [65.49.100.0](https://vuldb.com/?ip.65.49.100.0) | - | - | High
21 | [65.171.98.0](https://vuldb.com/?ip.65.171.98.0) | - | - | High
22 | [66.55.112.0](https://vuldb.com/?ip.66.55.112.0) | - | - | High
23 | [66.97.172.0](https://vuldb.com/?ip.66.97.172.0) | - | - | High
24 | [66.110.73.68](https://vuldb.com/?ip.66.110.73.68) | - | - | High
25 | [66.110.73.96](https://vuldb.com/?ip.66.110.73.96) | - | - | High
26 | [66.110.96.153](https://vuldb.com/?ip.66.110.96.153) | - | - | High
27 | [69.17.192.0](https://vuldb.com/?ip.69.17.192.0) | - | - | High
28 | [74.114.240.0](https://vuldb.com/?ip.74.114.240.0) | - | - | High
29 | [76.8.32.0](https://vuldb.com/?ip.76.8.32.0) | - | - | High
30 | [76.8.36.0](https://vuldb.com/?ip.76.8.36.0) | - | - | High
31 | [76.8.38.0](https://vuldb.com/?ip.76.8.38.0) | - | - | High
32 | [76.8.38.40](https://vuldb.com/?ip.76.8.38.40) | host-76-8-38-40.telebermuda.com | - | High
33 | [76.8.38.48](https://vuldb.com/?ip.76.8.38.48) | host-76-8-38-48.telebermuda.com | - | High
34 | [76.8.38.64](https://vuldb.com/?ip.76.8.38.64) | host-76-8-38-64.telebermuda.com | - | High
35 | [76.8.38.128](https://vuldb.com/?ip.76.8.38.128) | host-76-8-38-128.telebermuda.com | - | High
36 | [76.8.39.0](https://vuldb.com/?ip.76.8.39.0) | - | - | High
37 | [76.8.40.0](https://vuldb.com/?ip.76.8.40.0) | - | - | High
38 | [93.115.30.40](https://vuldb.com/?ip.93.115.30.40) | - | - | High
39 | ... | ... | ... | ...
There are 152 more IOC items available. Please use our online service to access the data.
2022-11-26 11:43:44 +00:00
## References
The following list contains _external sources_ which discuss the actor and the associated activities:
* https://github.com/firehol/blocklist-ipsets/blob/master/geolite2_country/country_bm.netset
2023-03-14 20:25:30 +00:00
* https://github.com/firehol/blocklist-ipsets/blob/master/ip2location_country/ip2location_country_bm.netset
2023-06-06 08:26:07 +00:00
* https://github.com/firehol/blocklist-ipsets/blob/master/ipip_country/ipip_country_bm.netset
2022-11-26 11:43:44 +00:00
## Literature
The following _articles_ explain our unique predictive cyber threat intelligence:
* [VulDB Cyber Threat Intelligence Documentation](https://vuldb.com/?kb.cti)
* [Cyber Threat Intelligence - Early Anticipation of Attacks](https://www.scip.ch/en/?labs.20201022)
## License
2023-01-30 12:54:37 +00:00
(c) [1997-2023](https://vuldb.com/?kb.changelog) by [vuldb.com](https://vuldb.com/?kb.about). All data on this page is shared under the license [CC BY-NC-SA 4.0](https://creativecommons.org/licenses/by-nc-sa/4.0/). Questions? Check the [FAQ](https://vuldb.com/?kb.faq), read the [documentation](https://vuldb.com/?kb) or [contact us](https://vuldb.com/?contact)!