Update
This commit is contained in:
parent
7c2038ac00
commit
eea8d18f5b
|
@ -67,8 +67,7 @@ ID | Technique | Weakness | Description | Confidence
|
|||
2 | T1040 | CWE-319 | Authentication Bypass by Capture-replay | High
|
||||
3 | T1055 | CWE-74 | Injection | High
|
||||
4 | T1059 | CWE-88, CWE-94 | Cross Site Scripting | High
|
||||
5 | T1059.007 | CWE-79, CWE-80 | Cross Site Scripting | High
|
||||
6 | ... | ... | ... | ...
|
||||
5 | ... | ... | ... | ...
|
||||
|
||||
There are 18 more TTP items available. Please use our online service to access the data.
|
||||
|
||||
|
@ -113,7 +112,7 @@ ID | Type | Indicator | Confidence
|
|||
33 | File | `/pages/apply_vacancy.php` | High
|
||||
34 | ... | ... | ...
|
||||
|
||||
There are 287 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 288 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -97,15 +97,16 @@ ID | Type | Indicator | Confidence
|
|||
39 | File | `/secure/admin/InsightDefaultCustomFieldConfig.jspa` | High
|
||||
40 | File | `/services/system/setup.json` | High
|
||||
41 | File | `/spip.php` | Medium
|
||||
42 | File | `/uncpath/` | Medium
|
||||
43 | File | `/vloggers_merch/?p=view_product` | High
|
||||
44 | File | `/webconsole/APIController` | High
|
||||
45 | File | `/websocket/exec` | High
|
||||
46 | File | `/whbs/?page=my_bookings` | High
|
||||
47 | File | `/wp-admin/admin-ajax.php` | High
|
||||
48 | ... | ... | ...
|
||||
42 | File | `/tmp` | Low
|
||||
43 | File | `/uncpath/` | Medium
|
||||
44 | File | `/vloggers_merch/?p=view_product` | High
|
||||
45 | File | `/webconsole/APIController` | High
|
||||
46 | File | `/websocket/exec` | High
|
||||
47 | File | `/whbs/?page=my_bookings` | High
|
||||
48 | File | `/wp-admin/admin-ajax.php` | High
|
||||
49 | ... | ... | ...
|
||||
|
||||
There are 419 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 425 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -18,7 +18,7 @@ These _countries_ are directly (e.g. origin of attacks) or indirectly (e.g. acce
|
|||
|
||||
* [ES](https://vuldb.com/?country.es)
|
||||
* [FR](https://vuldb.com/?country.fr)
|
||||
* [AR](https://vuldb.com/?country.ar)
|
||||
* [DE](https://vuldb.com/?country.de)
|
||||
* ...
|
||||
|
||||
There are 8 more country items available. Please use our online service to access the data.
|
||||
|
@ -61,7 +61,7 @@ ID | Technique | Weakness | Description | Confidence
|
|||
5 | T1059.007 | CWE-79, CWE-80, CWE-85 | Cross Site Scripting | High
|
||||
6 | ... | ... | ... | ...
|
||||
|
||||
There are 18 more TTP items available. Please use our online service to access the data.
|
||||
There are 21 more TTP items available. Please use our online service to access the data.
|
||||
|
||||
## IOA - Indicator of Attack
|
||||
|
||||
|
@ -69,39 +69,42 @@ These _indicators of attack_ (IOA) list the potential fragments used for technic
|
|||
|
||||
ID | Type | Indicator | Confidence
|
||||
-- | ---- | --------- | ----------
|
||||
1 | File | `/action/factory` | High
|
||||
2 | File | `/action/import_aaa_cert_file/` | High
|
||||
3 | File | `/action/import_cert_file/` | High
|
||||
4 | File | `/action/import_https_cert_file/` | High
|
||||
5 | File | `/action/import_sdk_file/` | High
|
||||
6 | File | `/action/ipcamRecordPost` | High
|
||||
7 | File | `/action/ipcamSetParamPost` | High
|
||||
8 | File | `/action/wirelessConnect` | High
|
||||
9 | File | `/admin.php/Admin/adminadd.html` | High
|
||||
10 | File | `/admin/admin.php` | High
|
||||
11 | File | `/admin/advicefeedback/list` | High
|
||||
12 | File | `/admin/conferences/list/` | High
|
||||
13 | File | `/admin/sendmailto.php?tomail=&groupid=` | High
|
||||
14 | File | `/admin/settings/save.php` | High
|
||||
15 | File | `/admin/tests/manage_test.php` | High
|
||||
16 | File | `/api/geojson` | Medium
|
||||
17 | File | `/api/v1/attack/token` | High
|
||||
18 | File | `/api/v2/open/rowsInfo` | High
|
||||
19 | File | `/asms/classes/Master.php?f=delete_img` | High
|
||||
20 | File | `/bsms_ci/index.php/user/edit_user/` | High
|
||||
21 | File | `/classes/Master.php?f=delete_img` | High
|
||||
22 | File | `/device/signin` | High
|
||||
23 | File | `/diag_ping_admin.asp` | High
|
||||
24 | File | `/fastfood/purchase.php` | High
|
||||
25 | File | `/FormLogin` | Medium
|
||||
26 | File | `/garage/editorder.php` | High
|
||||
27 | File | `/goform/form2WizardStep54` | High
|
||||
28 | File | `/goform/NatStaticSetting` | High
|
||||
29 | File | `/goform/SetNetControlList` | High
|
||||
1 | File | `/action/import_aaa_cert_file/` | High
|
||||
2 | File | `/action/import_cert_file/` | High
|
||||
3 | File | `/action/import_https_cert_file/` | High
|
||||
4 | File | `/action/ipcamRecordPost` | High
|
||||
5 | File | `/action/wirelessConnect` | High
|
||||
6 | File | `/admin.php/Admin/adminadd.html` | High
|
||||
7 | File | `/admin/admin.php` | High
|
||||
8 | File | `/admin/conferences/list/` | High
|
||||
9 | File | `/admin/settings/save.php` | High
|
||||
10 | File | `/api/audits` | Medium
|
||||
11 | File | `/api/geojson` | Medium
|
||||
12 | File | `/asms/classes/Master.php?f=delete_img` | High
|
||||
13 | File | `/bin/sh` | Low
|
||||
14 | File | `/bsms_ci/index.php/user/edit_user/` | High
|
||||
15 | File | `/calendar/viewcalendar.php` | High
|
||||
16 | File | `/classes/Master.php?f=delete_appointment` | High
|
||||
17 | File | `/classes/Master.php?f=delete_img` | High
|
||||
18 | File | `/classes/Users.php?f=delete_client` | High
|
||||
19 | File | `/depotHead/list` | High
|
||||
20 | File | `/device/signin` | High
|
||||
21 | File | `/diag_ping_admin.asp` | High
|
||||
22 | File | `/ext/phar/phar_object.c` | High
|
||||
23 | File | `/FormLogin` | Medium
|
||||
24 | File | `/garage/editorder.php` | High
|
||||
25 | File | `/goform/form2WizardStep54` | High
|
||||
26 | File | `/goform/setSysPwd` | High
|
||||
27 | File | `/goform/SysToolReboot` | High
|
||||
28 | File | `/goform/SysToolRestoreSet` | High
|
||||
29 | File | `/goform/wifiSSIDset` | High
|
||||
30 | File | `/gpac/src/bifs/unquantize.c` | High
|
||||
31 | ... | ... | ...
|
||||
31 | File | `/hrm/controller/login.php` | High
|
||||
32 | File | `/hrm/employeeadd.php` | High
|
||||
33 | File | `/hrm/index.php?msg` | High
|
||||
34 | ... | ... | ...
|
||||
|
||||
There are 261 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 290 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -10,7 +10,7 @@ These _countries_ are directly (e.g. origin of attacks) or indirectly (e.g. acce
|
|||
|
||||
* [NL](https://vuldb.com/?country.nl)
|
||||
* [US](https://vuldb.com/?country.us)
|
||||
* [IR](https://vuldb.com/?country.ir)
|
||||
* [RU](https://vuldb.com/?country.ru)
|
||||
* ...
|
||||
|
||||
There are 9 more country items available. Please use our online service to access the data.
|
||||
|
@ -62,32 +62,32 @@ ID | Type | Indicator | Confidence
|
|||
-- | ---- | --------- | ----------
|
||||
1 | File | `.travis.yml` | Medium
|
||||
2 | File | `/.env` | Low
|
||||
3 | File | `/admin.php` | Medium
|
||||
4 | File | `/admin/addemployee.php` | High
|
||||
5 | File | `/admin/add_trainers.php` | High
|
||||
6 | File | `/admin/countrymanagement.php` | High
|
||||
7 | File | `/admin/generalsettings.php` | High
|
||||
8 | File | `/admin/newsletter1.php` | High
|
||||
9 | File | `/admin/payment.php` | High
|
||||
10 | File | `/admin/subnets/ripe-query.php` | High
|
||||
11 | File | `/core/conditions/AbstractWrapper.java` | High
|
||||
12 | File | `/debug/pprof` | Medium
|
||||
13 | File | `/export` | Low
|
||||
14 | File | `/file?action=download&file` | High
|
||||
15 | File | `/filemanager/upload/drop` | High
|
||||
16 | File | `/index.php` | Medium
|
||||
17 | File | `/login.php` | Medium
|
||||
18 | File | `/medical/inventories.php` | High
|
||||
19 | File | `/mgmt/tm/util/bash` | High
|
||||
20 | File | `/mkshop/Men/profile.php` | High
|
||||
21 | File | `/monitoring` | Medium
|
||||
22 | File | `/opt/zimbra/jetty/webapps/zimbra/public` | High
|
||||
23 | File | `/pages/apply_vacancy.php` | High
|
||||
24 | File | `/php_action/createUser.php` | High
|
||||
25 | File | `/plugin/LiveChat/getChat.json.php` | High
|
||||
26 | File | `/plugins/servlet/audit/resource` | High
|
||||
27 | File | `/plugins/servlet/project-config/PROJECT/roles` | High
|
||||
28 | File | `/replication` | Medium
|
||||
3 | File | `/admin/addemployee.php` | High
|
||||
4 | File | `/admin/add_trainers.php` | High
|
||||
5 | File | `/admin/countrymanagement.php` | High
|
||||
6 | File | `/admin/generalsettings.php` | High
|
||||
7 | File | `/admin/newsletter1.php` | High
|
||||
8 | File | `/admin/payment.php` | High
|
||||
9 | File | `/admin/subnets/ripe-query.php` | High
|
||||
10 | File | `/core/conditions/AbstractWrapper.java` | High
|
||||
11 | File | `/debug/pprof` | Medium
|
||||
12 | File | `/export` | Low
|
||||
13 | File | `/file?action=download&file` | High
|
||||
14 | File | `/filemanager/upload/drop` | High
|
||||
15 | File | `/index.php` | Medium
|
||||
16 | File | `/login.php` | Medium
|
||||
17 | File | `/medical/inventories.php` | High
|
||||
18 | File | `/mgmt/tm/util/bash` | High
|
||||
19 | File | `/mkshop/Men/profile.php` | High
|
||||
20 | File | `/monitoring` | Medium
|
||||
21 | File | `/opt/zimbra/jetty/webapps/zimbra/public` | High
|
||||
22 | File | `/pages/apply_vacancy.php` | High
|
||||
23 | File | `/php_action/createUser.php` | High
|
||||
24 | File | `/plugin/LiveChat/getChat.json.php` | High
|
||||
25 | File | `/plugins/servlet/audit/resource` | High
|
||||
26 | File | `/plugins/servlet/project-config/PROJECT/roles` | High
|
||||
27 | File | `/replication` | Medium
|
||||
28 | File | `/RestAPI` | Medium
|
||||
29 | ... | ... | ...
|
||||
|
||||
There are 245 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
|
|
@ -108,19 +108,19 @@ ID | Type | Indicator | Confidence
|
|||
30 | File | `/secure/QueryComponent!Default.jspa` | High
|
||||
31 | File | `/SSOPOST/metaAlias/%realm%/idpv2` | High
|
||||
32 | File | `/start-stop` | Medium
|
||||
33 | File | `/thruk/#cgi-bin/extinfo.cgi?type=2` | High
|
||||
34 | File | `/tmp/app/.env` | High
|
||||
35 | File | `/uncpath/` | Medium
|
||||
36 | File | `/upload` | Low
|
||||
37 | File | `/usr/bin/pkexec` | High
|
||||
38 | File | `/v2/quantum/save-data-upload-big-file` | High
|
||||
39 | File | `/WEB-INF/web.xml` | High
|
||||
40 | File | `/wp-admin/admin-ajax.php` | High
|
||||
41 | File | `/wp-admin/options.php` | High
|
||||
42 | File | `/_next` | Low
|
||||
33 | File | `/start_apply.htm` | High
|
||||
34 | File | `/thruk/#cgi-bin/extinfo.cgi?type=2` | High
|
||||
35 | File | `/tmp/app/.env` | High
|
||||
36 | File | `/uncpath/` | Medium
|
||||
37 | File | `/upload` | Low
|
||||
38 | File | `/usr/bin/pkexec` | High
|
||||
39 | File | `/v2/quantum/save-data-upload-big-file` | High
|
||||
40 | File | `/WEB-INF/web.xml` | High
|
||||
41 | File | `/wp-admin/admin-ajax.php` | High
|
||||
42 | File | `/wp-admin/options.php` | High
|
||||
43 | ... | ... | ...
|
||||
|
||||
There are 370 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 371 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -15,8 +15,8 @@ The following _campaigns_ are known and can be associated with Agent Tesla:
|
|||
These _countries_ are directly (e.g. origin of attacks) or indirectly (e.g. access by proxy) associated with Agent Tesla:
|
||||
|
||||
* [US](https://vuldb.com/?country.us)
|
||||
* [CA](https://vuldb.com/?country.ca)
|
||||
* [CN](https://vuldb.com/?country.cn)
|
||||
* [CA](https://vuldb.com/?country.ca)
|
||||
* ...
|
||||
|
||||
There are 18 more country items available. Please use our online service to access the data.
|
||||
|
@ -90,21 +90,21 @@ ID | Type | Indicator | Confidence
|
|||
28 | File | `admin/import/class-import-settings.php` | High
|
||||
29 | File | `admin/index.php?id=users/action=edit/user_id=1` | High
|
||||
30 | File | `admin/sitesettings.php` | High
|
||||
31 | File | `affich.php` | Medium
|
||||
32 | File | `agent/Core/Controller/SendRequest.cpp` | High
|
||||
33 | File | `akeyActivationLogin.do` | High
|
||||
34 | File | `album_portal.php` | High
|
||||
35 | File | `apache-auth.conf` | High
|
||||
36 | File | `app/admin/routing/edit-bgp-mapping-search.php` | High
|
||||
37 | File | `Asc.exe` | Low
|
||||
38 | File | `askapache-firefox-adsense.php` | High
|
||||
39 | File | `assets/add/category.php` | High
|
||||
40 | File | `attachment.cgi` | High
|
||||
41 | File | `blueprints/sections/edit/1` | High
|
||||
42 | File | `books.php` | Medium
|
||||
31 | File | `admin_gallery.php3` | High
|
||||
32 | File | `affich.php` | Medium
|
||||
33 | File | `agent/Core/Controller/SendRequest.cpp` | High
|
||||
34 | File | `akeyActivationLogin.do` | High
|
||||
35 | File | `album_portal.php` | High
|
||||
36 | File | `apache-auth.conf` | High
|
||||
37 | File | `app/admin/routing/edit-bgp-mapping-search.php` | High
|
||||
38 | File | `Asc.exe` | Low
|
||||
39 | File | `askapache-firefox-adsense.php` | High
|
||||
40 | File | `assets/add/category.php` | High
|
||||
41 | File | `attachment.cgi` | High
|
||||
42 | File | `blueprints/sections/edit/1` | High
|
||||
43 | ... | ... | ...
|
||||
|
||||
There are 371 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 374 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -71,7 +71,7 @@ ID | Type | Indicator | Confidence
|
|||
19 | File | `app/admin/controller/api/Update.php` | High
|
||||
20 | ... | ... | ...
|
||||
|
||||
There are 165 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 167 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -129,21 +129,21 @@ ID | Type | Indicator | Confidence
|
|||
26 | File | `/ffos/classes/Master.php?f=save_category` | High
|
||||
27 | File | `/goforms/rlminfo` | High
|
||||
28 | File | `/h/calendar` | Medium
|
||||
29 | File | `/HNAP1/SetClientInfo` | High
|
||||
30 | File | `/inc/extensions.php` | High
|
||||
31 | File | `/includes/rrdtool.inc.php` | High
|
||||
32 | File | `/Items/*/RemoteImages/Download` | High
|
||||
33 | File | `/navigate/navigate_download.php` | High
|
||||
34 | File | `/nova/bin/console` | High
|
||||
35 | File | `/nova/bin/detnet` | High
|
||||
36 | File | `/ocwbs/admin/?page=user/manage_user` | High
|
||||
37 | File | `/ofrs/admin/?page=user/manage_user` | High
|
||||
38 | File | `/out.php` | Medium
|
||||
39 | File | `/password.html` | High
|
||||
40 | File | `/php_action/fetchSelectedUser.php` | High
|
||||
29 | File | `/inc/extensions.php` | High
|
||||
30 | File | `/includes/rrdtool.inc.php` | High
|
||||
31 | File | `/Items/*/RemoteImages/Download` | High
|
||||
32 | File | `/navigate/navigate_download.php` | High
|
||||
33 | File | `/nova/bin/console` | High
|
||||
34 | File | `/nova/bin/detnet` | High
|
||||
35 | File | `/ocwbs/admin/?page=user/manage_user` | High
|
||||
36 | File | `/ofrs/admin/?page=user/manage_user` | High
|
||||
37 | File | `/out.php` | Medium
|
||||
38 | File | `/password.html` | High
|
||||
39 | File | `/php_action/fetchSelectedUser.php` | High
|
||||
40 | File | `/proc/ioports` | High
|
||||
41 | ... | ... | ...
|
||||
|
||||
There are 351 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 357 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -69,22 +69,25 @@ ID | Type | Indicator | Confidence
|
|||
17 | File | `/classes/Master.php?f=delete_category` | High
|
||||
18 | File | `/classes/Master.php?f=delete_payment` | High
|
||||
19 | File | `/classes/Users.php?f=delete_client` | High
|
||||
20 | File | `/clients/profile` | High
|
||||
21 | File | `/csms/admin/?page=user/manage_user` | High
|
||||
22 | File | `/csms/admin/storages/view_storage.php` | High
|
||||
23 | File | `/diagnostic/editclient.php` | High
|
||||
24 | File | `/dotrace.asp` | Medium
|
||||
25 | File | `/etc/init0.d/S80telnetd.sh` | High
|
||||
26 | File | `/goform/SetIpMacBind` | High
|
||||
27 | File | `/goform/wizard_end` | High
|
||||
28 | File | `/home/hjsz/jsonlint/src/lexer` | High
|
||||
29 | File | `/index.php?module=entities/entities` | High
|
||||
30 | File | `/index.php?module=global_lists/lists` | High
|
||||
31 | File | `/index.php?module=users_alerts/users_alerts` | High
|
||||
32 | File | `/index1.html` | Medium
|
||||
33 | ... | ... | ...
|
||||
20 | File | `/clients/listclients.php` | High
|
||||
21 | File | `/clients/profile` | High
|
||||
22 | File | `/contacts/listcontacts.php` | High
|
||||
23 | File | `/csms/admin/?page=user/manage_user` | High
|
||||
24 | File | `/csms/admin/storages/view_storage.php` | High
|
||||
25 | File | `/Default/Bd` | Medium
|
||||
26 | File | `/diagnostic/editclient.php` | High
|
||||
27 | File | `/etc/init0.d/S80telnetd.sh` | High
|
||||
28 | File | `/goform/AddSysLogRule` | High
|
||||
29 | File | `/goform/SetIpMacBind` | High
|
||||
30 | File | `/goform/setSnmpInfo` | High
|
||||
31 | File | `/goform/setUplinkInfo` | High
|
||||
32 | File | `/goform/wizard_end` | High
|
||||
33 | File | `/home/hjsz/jsonlint/src/lexer` | High
|
||||
34 | File | `/hrm/employeeview.php` | High
|
||||
35 | File | `/index.php?module=entities/entities` | High
|
||||
36 | ... | ... | ...
|
||||
|
||||
There are 277 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 306 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -10,7 +10,7 @@ These _countries_ are directly (e.g. origin of attacks) or indirectly (e.g. acce
|
|||
|
||||
* [VN](https://vuldb.com/?country.vn)
|
||||
* [US](https://vuldb.com/?country.us)
|
||||
* [CN](https://vuldb.com/?country.cn)
|
||||
* [NL](https://vuldb.com/?country.nl)
|
||||
* ...
|
||||
|
||||
There are 6 more country items available. Please use our online service to access the data.
|
||||
|
@ -21,126 +21,125 @@ These _indicators of compromise_ (IOC) indicate associated network resources whi
|
|||
|
||||
ID | IP address | Hostname | Campaign | Confidence
|
||||
-- | ---------- | -------- | -------- | ----------
|
||||
1 | [0.42.131.123](https://vuldb.com/?ip.0.42.131.123) | - | - | High
|
||||
2 | [0.134.23.62](https://vuldb.com/?ip.0.134.23.62) | - | - | High
|
||||
3 | [0.151.228.146](https://vuldb.com/?ip.0.151.228.146) | - | - | High
|
||||
4 | [1.32.39.22](https://vuldb.com/?ip.1.32.39.22) | - | - | High
|
||||
5 | [1.39.166.217](https://vuldb.com/?ip.1.39.166.217) | 1-39-166-217.live.vodafone.in | - | High
|
||||
6 | [2.97.24.126](https://vuldb.com/?ip.2.97.24.126) | host-2-97-24-126.as13285.net | - | High
|
||||
7 | [2.190.89.140](https://vuldb.com/?ip.2.190.89.140) | - | - | High
|
||||
8 | [2.211.111.213](https://vuldb.com/?ip.2.211.111.213) | dynamic-002-211-111-213.2.211.pool.telefonica.de | - | High
|
||||
9 | [3.85.198.66](https://vuldb.com/?ip.3.85.198.66) | ec2-3-85-198-66.compute-1.amazonaws.com | - | Medium
|
||||
10 | [3.144.143.242](https://vuldb.com/?ip.3.144.143.242) | ec2-3-144-143-242.us-east-2.compute.amazonaws.com | - | Medium
|
||||
11 | [3.172.226.46](https://vuldb.com/?ip.3.172.226.46) | - | - | High
|
||||
12 | [4.165.175.212](https://vuldb.com/?ip.4.165.175.212) | - | - | High
|
||||
13 | [5.152.80.211](https://vuldb.com/?ip.5.152.80.211) | - | - | High
|
||||
14 | [5.239.33.172](https://vuldb.com/?ip.5.239.33.172) | - | - | High
|
||||
15 | [6.30.139.246](https://vuldb.com/?ip.6.30.139.246) | - | - | High
|
||||
16 | [6.249.22.42](https://vuldb.com/?ip.6.249.22.42) | - | - | High
|
||||
17 | [7.233.9.154](https://vuldb.com/?ip.7.233.9.154) | - | - | High
|
||||
18 | [8.12.181.20](https://vuldb.com/?ip.8.12.181.20) | - | - | High
|
||||
19 | [9.63.15.101](https://vuldb.com/?ip.9.63.15.101) | - | - | High
|
||||
20 | [9.240.112.25](https://vuldb.com/?ip.9.240.112.25) | - | - | High
|
||||
21 | [10.28.17.62](https://vuldb.com/?ip.10.28.17.62) | - | - | High
|
||||
22 | [11.1.201.27](https://vuldb.com/?ip.11.1.201.27) | - | - | High
|
||||
23 | [12.75.186.131](https://vuldb.com/?ip.12.75.186.131) | 131.newark-21-23rs.nj.dial-access.att.net | - | High
|
||||
24 | [12.115.36.174](https://vuldb.com/?ip.12.115.36.174) | - | - | High
|
||||
25 | [12.153.80.238](https://vuldb.com/?ip.12.153.80.238) | - | - | High
|
||||
26 | [12.202.229.195](https://vuldb.com/?ip.12.202.229.195) | - | - | High
|
||||
27 | [12.236.242.155](https://vuldb.com/?ip.12.236.242.155) | - | - | High
|
||||
28 | [13.2.200.200](https://vuldb.com/?ip.13.2.200.200) | - | - | High
|
||||
29 | [13.218.205.215](https://vuldb.com/?ip.13.218.205.215) | - | - | High
|
||||
30 | [14.7.69.141](https://vuldb.com/?ip.14.7.69.141) | - | - | High
|
||||
31 | [14.40.68.19](https://vuldb.com/?ip.14.40.68.19) | - | - | High
|
||||
32 | [14.102.170.127](https://vuldb.com/?ip.14.102.170.127) | cache-ipnet01.nexlogic.ph | - | High
|
||||
33 | [14.155.143.74](https://vuldb.com/?ip.14.155.143.74) | - | - | High
|
||||
34 | [14.163.179.250](https://vuldb.com/?ip.14.163.179.250) | static.vnpt.vn | - | High
|
||||
35 | [15.209.19.148](https://vuldb.com/?ip.15.209.19.148) | - | - | High
|
||||
36 | [18.8.71.243](https://vuldb.com/?ip.18.8.71.243) | - | - | High
|
||||
37 | [18.127.96.221](https://vuldb.com/?ip.18.127.96.221) | - | - | High
|
||||
38 | [19.32.56.182](https://vuldb.com/?ip.19.32.56.182) | - | - | High
|
||||
39 | [19.71.13.153](https://vuldb.com/?ip.19.71.13.153) | - | - | High
|
||||
40 | [20.150.149.28](https://vuldb.com/?ip.20.150.149.28) | - | - | High
|
||||
41 | [21.21.141.32](https://vuldb.com/?ip.21.21.141.32) | - | - | High
|
||||
42 | [21.29.238.98](https://vuldb.com/?ip.21.29.238.98) | - | - | High
|
||||
43 | [21.175.22.99](https://vuldb.com/?ip.21.175.22.99) | - | - | High
|
||||
44 | [21.246.85.34](https://vuldb.com/?ip.21.246.85.34) | - | - | High
|
||||
45 | [22.83.186.45](https://vuldb.com/?ip.22.83.186.45) | - | - | High
|
||||
46 | [22.175.0.90](https://vuldb.com/?ip.22.175.0.90) | - | - | High
|
||||
47 | [23.81.246.187](https://vuldb.com/?ip.23.81.246.187) | - | - | High
|
||||
48 | [23.82.19.208](https://vuldb.com/?ip.23.82.19.208) | - | - | High
|
||||
49 | [23.82.140.133](https://vuldb.com/?ip.23.82.140.133) | - | - | High
|
||||
50 | [23.82.141.184](https://vuldb.com/?ip.23.82.141.184) | - | - | High
|
||||
51 | [23.83.133.1](https://vuldb.com/?ip.23.83.133.1) | v327.er01.dal.ubiquity.io | - | High
|
||||
52 | [23.83.133.182](https://vuldb.com/?ip.23.83.133.182) | - | - | High
|
||||
53 | [23.83.133.216](https://vuldb.com/?ip.23.83.133.216) | - | - | High
|
||||
54 | [23.83.134.110](https://vuldb.com/?ip.23.83.134.110) | - | - | High
|
||||
55 | [23.83.134.136](https://vuldb.com/?ip.23.83.134.136) | - | - | High
|
||||
56 | [23.106.160.39](https://vuldb.com/?ip.23.106.160.39) | - | - | High
|
||||
57 | [23.106.160.120](https://vuldb.com/?ip.23.106.160.120) | - | - | High
|
||||
58 | [23.106.215.123](https://vuldb.com/?ip.23.106.215.123) | - | - | High
|
||||
59 | [23.108.57.13](https://vuldb.com/?ip.23.108.57.13) | - | - | High
|
||||
60 | [23.227.198.217](https://vuldb.com/?ip.23.227.198.217) | 23-227-198-217.static.hvvc.us | - | High
|
||||
61 | [23.254.201.97](https://vuldb.com/?ip.23.254.201.97) | hwsrv-974106.hostwindsdns.com | - | High
|
||||
62 | [23.254.202.59](https://vuldb.com/?ip.23.254.202.59) | hwsrv-987701.hostwindsdns.com | - | High
|
||||
63 | [23.254.217.20](https://vuldb.com/?ip.23.254.217.20) | hwsrv-984041.hostwindsdns.com | - | High
|
||||
64 | [23.254.217.222](https://vuldb.com/?ip.23.254.217.222) | hwsrv-976272.hostwindsdns.com | - | High
|
||||
65 | [23.254.227.144](https://vuldb.com/?ip.23.254.227.144) | hwsrv-982332.hostwindsdns.com | - | High
|
||||
66 | [23.254.229.131](https://vuldb.com/?ip.23.254.229.131) | ruth.gobuddy.info | - | High
|
||||
67 | [24.4.68.32](https://vuldb.com/?ip.24.4.68.32) | c-24-4-68-32.hsd1.ca.comcast.net | - | High
|
||||
68 | [24.57.185.167](https://vuldb.com/?ip.24.57.185.167) | d24-57-185-167.home.cgocable.net | - | High
|
||||
69 | [24.121.25.160](https://vuldb.com/?ip.24.121.25.160) | 24-121-25-160.sdoncmtk01.com.dyn.suddenlink.net | - | High
|
||||
70 | [25.5.198.104](https://vuldb.com/?ip.25.5.198.104) | - | - | High
|
||||
71 | [25.170.215.18](https://vuldb.com/?ip.25.170.215.18) | - | - | High
|
||||
72 | [25.181.64.39](https://vuldb.com/?ip.25.181.64.39) | - | - | High
|
||||
73 | [26.6.83.53](https://vuldb.com/?ip.26.6.83.53) | - | - | High
|
||||
74 | [28.11.143.222](https://vuldb.com/?ip.28.11.143.222) | - | - | High
|
||||
75 | [28.53.120.108](https://vuldb.com/?ip.28.53.120.108) | - | - | High
|
||||
76 | [28.107.38.196](https://vuldb.com/?ip.28.107.38.196) | - | - | High
|
||||
77 | [28.148.236.16](https://vuldb.com/?ip.28.148.236.16) | - | - | High
|
||||
78 | [29.64.0.111](https://vuldb.com/?ip.29.64.0.111) | - | - | High
|
||||
79 | [29.122.243.158](https://vuldb.com/?ip.29.122.243.158) | - | - | High
|
||||
80 | [30.17.4.146](https://vuldb.com/?ip.30.17.4.146) | - | - | High
|
||||
81 | [30.65.48.152](https://vuldb.com/?ip.30.65.48.152) | - | - | High
|
||||
82 | [30.205.76.70](https://vuldb.com/?ip.30.205.76.70) | - | - | High
|
||||
83 | [31.228.253.114](https://vuldb.com/?ip.31.228.253.114) | - | - | High
|
||||
84 | [32.181.245.23](https://vuldb.com/?ip.32.181.245.23) | - | - | High
|
||||
85 | [33.93.97.183](https://vuldb.com/?ip.33.93.97.183) | - | - | High
|
||||
86 | [33.145.184.132](https://vuldb.com/?ip.33.145.184.132) | - | - | High
|
||||
87 | [34.229.154.31](https://vuldb.com/?ip.34.229.154.31) | ec2-34-229-154-31.compute-1.amazonaws.com | - | Medium
|
||||
88 | [35.120.155.220](https://vuldb.com/?ip.35.120.155.220) | - | - | High
|
||||
89 | [36.110.58.103](https://vuldb.com/?ip.36.110.58.103) | 103.58.110.36.static.bjtelecom.net | - | High
|
||||
90 | [37.64.220.2](https://vuldb.com/?ip.37.64.220.2) | 2.220.64.37.rev.sfr.net | - | High
|
||||
91 | [37.72.174.9](https://vuldb.com/?ip.37.72.174.9) | emailmail.org.uk | - | High
|
||||
92 | [37.72.174.23](https://vuldb.com/?ip.37.72.174.23) | 37-72-174-23.static.hvvc.us | - | High
|
||||
93 | [37.120.198.248](https://vuldb.com/?ip.37.120.198.248) | - | - | High
|
||||
94 | [38.12.57.131](https://vuldb.com/?ip.38.12.57.131) | - | - | High
|
||||
95 | [39.57.152.217](https://vuldb.com/?ip.39.57.152.217) | - | - | High
|
||||
96 | [40.72.17.141](https://vuldb.com/?ip.40.72.17.141) | - | - | High
|
||||
97 | [41.28.188.77](https://vuldb.com/?ip.41.28.188.77) | vc-gp-s-41-28-188-77.umts.vodacom.co.za | - | High
|
||||
98 | [41.56.181.200](https://vuldb.com/?ip.41.56.181.200) | - | - | High
|
||||
99 | [45.3.236.177](https://vuldb.com/?ip.45.3.236.177) | 045-003-236-177.biz.spectrum.com | - | High
|
||||
100 | [45.11.19.224](https://vuldb.com/?ip.45.11.19.224) | - | - | High
|
||||
101 | [45.66.151.155](https://vuldb.com/?ip.45.66.151.155) | - | - | High
|
||||
102 | [45.84.0.13](https://vuldb.com/?ip.45.84.0.13) | vm523902.stark-industries.solutions | - | High
|
||||
103 | [45.138.172.246](https://vuldb.com/?ip.45.138.172.246) | - | - | High
|
||||
104 | [45.140.146.30](https://vuldb.com/?ip.45.140.146.30) | vm542320.stark-industries.solutions | - | High
|
||||
105 | [45.140.146.244](https://vuldb.com/?ip.45.140.146.244) | - | - | High
|
||||
106 | [45.142.214.120](https://vuldb.com/?ip.45.142.214.120) | vm516885.stark-industries.solutions | - | High
|
||||
107 | [45.142.214.167](https://vuldb.com/?ip.45.142.214.167) | - | - | High
|
||||
108 | [45.147.229.23](https://vuldb.com/?ip.45.147.229.23) | - | - | High
|
||||
109 | [45.147.229.50](https://vuldb.com/?ip.45.147.229.50) | - | - | High
|
||||
110 | [45.147.229.101](https://vuldb.com/?ip.45.147.229.101) | - | - | High
|
||||
111 | [45.147.229.177](https://vuldb.com/?ip.45.147.229.177) | - | - | High
|
||||
112 | [45.147.229.199](https://vuldb.com/?ip.45.147.229.199) | - | - | High
|
||||
113 | [45.147.231.107](https://vuldb.com/?ip.45.147.231.107) | - | - | High
|
||||
114 | [45.147.231.202](https://vuldb.com/?ip.45.147.231.202) | - | - | High
|
||||
115 | [45.153.240.139](https://vuldb.com/?ip.45.153.240.139) | - | - | High
|
||||
116 | [45.153.241.187](https://vuldb.com/?ip.45.153.241.187) | - | - | High
|
||||
117 | [45.153.241.234](https://vuldb.com/?ip.45.153.241.234) | - | - | High
|
||||
118 | ... | ... | ... | ...
|
||||
1 | [1.32.39.22](https://vuldb.com/?ip.1.32.39.22) | - | - | High
|
||||
2 | [1.39.166.217](https://vuldb.com/?ip.1.39.166.217) | 1-39-166-217.live.vodafone.in | - | High
|
||||
3 | [2.97.24.126](https://vuldb.com/?ip.2.97.24.126) | host-2-97-24-126.as13285.net | - | High
|
||||
4 | [2.190.89.140](https://vuldb.com/?ip.2.190.89.140) | - | - | High
|
||||
5 | [2.211.111.213](https://vuldb.com/?ip.2.211.111.213) | dynamic-002-211-111-213.2.211.pool.telefonica.de | - | High
|
||||
6 | [3.85.198.66](https://vuldb.com/?ip.3.85.198.66) | ec2-3-85-198-66.compute-1.amazonaws.com | - | Medium
|
||||
7 | [3.144.143.242](https://vuldb.com/?ip.3.144.143.242) | ec2-3-144-143-242.us-east-2.compute.amazonaws.com | - | Medium
|
||||
8 | [3.172.226.46](https://vuldb.com/?ip.3.172.226.46) | - | - | High
|
||||
9 | [4.165.175.212](https://vuldb.com/?ip.4.165.175.212) | - | - | High
|
||||
10 | [5.152.80.211](https://vuldb.com/?ip.5.152.80.211) | - | - | High
|
||||
11 | [5.239.33.172](https://vuldb.com/?ip.5.239.33.172) | - | - | High
|
||||
12 | [6.30.139.246](https://vuldb.com/?ip.6.30.139.246) | - | - | High
|
||||
13 | [6.249.22.42](https://vuldb.com/?ip.6.249.22.42) | - | - | High
|
||||
14 | [7.233.9.154](https://vuldb.com/?ip.7.233.9.154) | - | - | High
|
||||
15 | [8.12.181.20](https://vuldb.com/?ip.8.12.181.20) | - | - | High
|
||||
16 | [9.63.15.101](https://vuldb.com/?ip.9.63.15.101) | - | - | High
|
||||
17 | [9.240.112.25](https://vuldb.com/?ip.9.240.112.25) | - | - | High
|
||||
18 | [10.28.17.62](https://vuldb.com/?ip.10.28.17.62) | - | - | High
|
||||
19 | [11.1.201.27](https://vuldb.com/?ip.11.1.201.27) | - | - | High
|
||||
20 | [12.75.186.131](https://vuldb.com/?ip.12.75.186.131) | 131.newark-21-23rs.nj.dial-access.att.net | - | High
|
||||
21 | [12.115.36.174](https://vuldb.com/?ip.12.115.36.174) | - | - | High
|
||||
22 | [12.153.80.238](https://vuldb.com/?ip.12.153.80.238) | - | - | High
|
||||
23 | [12.202.229.195](https://vuldb.com/?ip.12.202.229.195) | - | - | High
|
||||
24 | [12.236.242.155](https://vuldb.com/?ip.12.236.242.155) | - | - | High
|
||||
25 | [13.2.200.200](https://vuldb.com/?ip.13.2.200.200) | - | - | High
|
||||
26 | [13.218.205.215](https://vuldb.com/?ip.13.218.205.215) | - | - | High
|
||||
27 | [14.7.69.141](https://vuldb.com/?ip.14.7.69.141) | - | - | High
|
||||
28 | [14.40.68.19](https://vuldb.com/?ip.14.40.68.19) | - | - | High
|
||||
29 | [14.102.170.127](https://vuldb.com/?ip.14.102.170.127) | cache-ipnet01.nexlogic.ph | - | High
|
||||
30 | [14.155.143.74](https://vuldb.com/?ip.14.155.143.74) | - | - | High
|
||||
31 | [14.163.179.250](https://vuldb.com/?ip.14.163.179.250) | static.vnpt.vn | - | High
|
||||
32 | [15.209.19.148](https://vuldb.com/?ip.15.209.19.148) | - | - | High
|
||||
33 | [18.8.71.243](https://vuldb.com/?ip.18.8.71.243) | - | - | High
|
||||
34 | [18.127.96.221](https://vuldb.com/?ip.18.127.96.221) | - | - | High
|
||||
35 | [19.32.56.182](https://vuldb.com/?ip.19.32.56.182) | - | - | High
|
||||
36 | [19.71.13.153](https://vuldb.com/?ip.19.71.13.153) | - | - | High
|
||||
37 | [20.150.149.28](https://vuldb.com/?ip.20.150.149.28) | - | - | High
|
||||
38 | [21.21.141.32](https://vuldb.com/?ip.21.21.141.32) | - | - | High
|
||||
39 | [21.29.238.98](https://vuldb.com/?ip.21.29.238.98) | - | - | High
|
||||
40 | [21.175.22.99](https://vuldb.com/?ip.21.175.22.99) | - | - | High
|
||||
41 | [21.246.85.34](https://vuldb.com/?ip.21.246.85.34) | - | - | High
|
||||
42 | [22.83.186.45](https://vuldb.com/?ip.22.83.186.45) | - | - | High
|
||||
43 | [22.175.0.90](https://vuldb.com/?ip.22.175.0.90) | - | - | High
|
||||
44 | [23.81.246.187](https://vuldb.com/?ip.23.81.246.187) | - | - | High
|
||||
45 | [23.82.19.208](https://vuldb.com/?ip.23.82.19.208) | - | - | High
|
||||
46 | [23.82.140.133](https://vuldb.com/?ip.23.82.140.133) | - | - | High
|
||||
47 | [23.82.141.184](https://vuldb.com/?ip.23.82.141.184) | - | - | High
|
||||
48 | [23.83.133.1](https://vuldb.com/?ip.23.83.133.1) | v327.er01.dal.ubiquity.io | - | High
|
||||
49 | [23.83.133.182](https://vuldb.com/?ip.23.83.133.182) | - | - | High
|
||||
50 | [23.83.133.216](https://vuldb.com/?ip.23.83.133.216) | - | - | High
|
||||
51 | [23.83.134.110](https://vuldb.com/?ip.23.83.134.110) | - | - | High
|
||||
52 | [23.83.134.136](https://vuldb.com/?ip.23.83.134.136) | - | - | High
|
||||
53 | [23.106.160.39](https://vuldb.com/?ip.23.106.160.39) | - | - | High
|
||||
54 | [23.106.160.120](https://vuldb.com/?ip.23.106.160.120) | - | - | High
|
||||
55 | [23.106.215.123](https://vuldb.com/?ip.23.106.215.123) | - | - | High
|
||||
56 | [23.108.57.13](https://vuldb.com/?ip.23.108.57.13) | - | - | High
|
||||
57 | [23.227.198.217](https://vuldb.com/?ip.23.227.198.217) | 23-227-198-217.static.hvvc.us | - | High
|
||||
58 | [23.254.201.97](https://vuldb.com/?ip.23.254.201.97) | hwsrv-974106.hostwindsdns.com | - | High
|
||||
59 | [23.254.202.59](https://vuldb.com/?ip.23.254.202.59) | hwsrv-987701.hostwindsdns.com | - | High
|
||||
60 | [23.254.217.20](https://vuldb.com/?ip.23.254.217.20) | hwsrv-984041.hostwindsdns.com | - | High
|
||||
61 | [23.254.217.222](https://vuldb.com/?ip.23.254.217.222) | hwsrv-976272.hostwindsdns.com | - | High
|
||||
62 | [23.254.227.144](https://vuldb.com/?ip.23.254.227.144) | hwsrv-982332.hostwindsdns.com | - | High
|
||||
63 | [23.254.229.131](https://vuldb.com/?ip.23.254.229.131) | ruth.gobuddy.info | - | High
|
||||
64 | [24.4.68.32](https://vuldb.com/?ip.24.4.68.32) | c-24-4-68-32.hsd1.ca.comcast.net | - | High
|
||||
65 | [24.57.185.167](https://vuldb.com/?ip.24.57.185.167) | d24-57-185-167.home.cgocable.net | - | High
|
||||
66 | [24.121.25.160](https://vuldb.com/?ip.24.121.25.160) | 24-121-25-160.sdoncmtk01.com.dyn.suddenlink.net | - | High
|
||||
67 | [25.5.198.104](https://vuldb.com/?ip.25.5.198.104) | - | - | High
|
||||
68 | [25.170.215.18](https://vuldb.com/?ip.25.170.215.18) | - | - | High
|
||||
69 | [25.181.64.39](https://vuldb.com/?ip.25.181.64.39) | - | - | High
|
||||
70 | [26.6.83.53](https://vuldb.com/?ip.26.6.83.53) | - | - | High
|
||||
71 | [28.11.143.222](https://vuldb.com/?ip.28.11.143.222) | - | - | High
|
||||
72 | [28.53.120.108](https://vuldb.com/?ip.28.53.120.108) | - | - | High
|
||||
73 | [28.107.38.196](https://vuldb.com/?ip.28.107.38.196) | - | - | High
|
||||
74 | [28.148.236.16](https://vuldb.com/?ip.28.148.236.16) | - | - | High
|
||||
75 | [29.64.0.111](https://vuldb.com/?ip.29.64.0.111) | - | - | High
|
||||
76 | [29.122.243.158](https://vuldb.com/?ip.29.122.243.158) | - | - | High
|
||||
77 | [30.17.4.146](https://vuldb.com/?ip.30.17.4.146) | - | - | High
|
||||
78 | [30.65.48.152](https://vuldb.com/?ip.30.65.48.152) | - | - | High
|
||||
79 | [30.205.76.70](https://vuldb.com/?ip.30.205.76.70) | - | - | High
|
||||
80 | [31.228.253.114](https://vuldb.com/?ip.31.228.253.114) | - | - | High
|
||||
81 | [32.181.245.23](https://vuldb.com/?ip.32.181.245.23) | - | - | High
|
||||
82 | [33.93.97.183](https://vuldb.com/?ip.33.93.97.183) | - | - | High
|
||||
83 | [33.145.184.132](https://vuldb.com/?ip.33.145.184.132) | - | - | High
|
||||
84 | [34.229.154.31](https://vuldb.com/?ip.34.229.154.31) | ec2-34-229-154-31.compute-1.amazonaws.com | - | Medium
|
||||
85 | [35.120.155.220](https://vuldb.com/?ip.35.120.155.220) | - | - | High
|
||||
86 | [36.110.58.103](https://vuldb.com/?ip.36.110.58.103) | 103.58.110.36.static.bjtelecom.net | - | High
|
||||
87 | [37.64.220.2](https://vuldb.com/?ip.37.64.220.2) | 2.220.64.37.rev.sfr.net | - | High
|
||||
88 | [37.72.174.9](https://vuldb.com/?ip.37.72.174.9) | emailmail.org.uk | - | High
|
||||
89 | [37.72.174.23](https://vuldb.com/?ip.37.72.174.23) | 37-72-174-23.static.hvvc.us | - | High
|
||||
90 | [37.120.198.248](https://vuldb.com/?ip.37.120.198.248) | - | - | High
|
||||
91 | [38.12.57.131](https://vuldb.com/?ip.38.12.57.131) | - | - | High
|
||||
92 | [39.57.152.217](https://vuldb.com/?ip.39.57.152.217) | - | - | High
|
||||
93 | [40.72.17.141](https://vuldb.com/?ip.40.72.17.141) | - | - | High
|
||||
94 | [41.28.188.77](https://vuldb.com/?ip.41.28.188.77) | vc-gp-s-41-28-188-77.umts.vodacom.co.za | - | High
|
||||
95 | [41.56.181.200](https://vuldb.com/?ip.41.56.181.200) | - | - | High
|
||||
96 | [45.3.236.177](https://vuldb.com/?ip.45.3.236.177) | 045-003-236-177.biz.spectrum.com | - | High
|
||||
97 | [45.11.19.224](https://vuldb.com/?ip.45.11.19.224) | - | - | High
|
||||
98 | [45.66.151.155](https://vuldb.com/?ip.45.66.151.155) | - | - | High
|
||||
99 | [45.84.0.13](https://vuldb.com/?ip.45.84.0.13) | vm523902.stark-industries.solutions | - | High
|
||||
100 | [45.138.172.246](https://vuldb.com/?ip.45.138.172.246) | - | - | High
|
||||
101 | [45.140.146.30](https://vuldb.com/?ip.45.140.146.30) | vm542320.stark-industries.solutions | - | High
|
||||
102 | [45.140.146.244](https://vuldb.com/?ip.45.140.146.244) | - | - | High
|
||||
103 | [45.142.214.120](https://vuldb.com/?ip.45.142.214.120) | vm516885.stark-industries.solutions | - | High
|
||||
104 | [45.142.214.167](https://vuldb.com/?ip.45.142.214.167) | - | - | High
|
||||
105 | [45.147.229.23](https://vuldb.com/?ip.45.147.229.23) | - | - | High
|
||||
106 | [45.147.229.50](https://vuldb.com/?ip.45.147.229.50) | - | - | High
|
||||
107 | [45.147.229.101](https://vuldb.com/?ip.45.147.229.101) | - | - | High
|
||||
108 | [45.147.229.177](https://vuldb.com/?ip.45.147.229.177) | - | - | High
|
||||
109 | [45.147.229.199](https://vuldb.com/?ip.45.147.229.199) | - | - | High
|
||||
110 | [45.147.231.107](https://vuldb.com/?ip.45.147.231.107) | - | - | High
|
||||
111 | [45.147.231.202](https://vuldb.com/?ip.45.147.231.202) | - | - | High
|
||||
112 | [45.153.240.139](https://vuldb.com/?ip.45.153.240.139) | - | - | High
|
||||
113 | [45.153.241.187](https://vuldb.com/?ip.45.153.241.187) | - | - | High
|
||||
114 | [45.153.241.234](https://vuldb.com/?ip.45.153.241.234) | - | - | High
|
||||
115 | [46.21.153.145](https://vuldb.com/?ip.46.21.153.145) | 145.153.21.46.static.swiftway.net | - | High
|
||||
116 | [46.44.240.53](https://vuldb.com/?ip.46.44.240.53) | 46-44-240-53.ip.welcomeitalia.it | - | High
|
||||
117 | ... | ... | ... | ...
|
||||
|
||||
There are 468 more IOC items available. Please use our online service to access the data.
|
||||
There are 466 more IOC items available. Please use our online service to access the data.
|
||||
|
||||
## TTP - Tactics, Techniques, Procedures
|
||||
|
||||
|
@ -151,11 +150,11 @@ ID | Technique | Weakness | Description | Confidence
|
|||
1 | T1006 | CWE-21, CWE-22 | Pathname Traversal | High
|
||||
2 | T1040 | CWE-294, CWE-319 | Authentication Bypass by Capture-replay | High
|
||||
3 | T1055 | CWE-74 | Injection | High
|
||||
4 | T1059 | CWE-88, CWE-94, CWE-1321 | Cross Site Scripting | High
|
||||
5 | T1059.007 | CWE-79 | Cross Site Scripting | High
|
||||
4 | T1059 | CWE-88, CWE-94 | Cross Site Scripting | High
|
||||
5 | T1059.007 | CWE-79, CWE-80, CWE-85 | Cross Site Scripting | High
|
||||
6 | ... | ... | ... | ...
|
||||
|
||||
There are 18 more TTP items available. Please use our online service to access the data.
|
||||
There are 19 more TTP items available. Please use our online service to access the data.
|
||||
|
||||
## IOA - Indicator of Attack
|
||||
|
||||
|
@ -163,32 +162,36 @@ These _indicators of attack_ (IOA) list the potential fragments used for technic
|
|||
|
||||
ID | Type | Indicator | Confidence
|
||||
-- | ---- | --------- | ----------
|
||||
1 | File | `/admin.php/Admin/adminadd.html` | High
|
||||
2 | File | `/admin/admin.php` | High
|
||||
3 | File | `/admin/controller/JobLogController.java` | High
|
||||
1 | File | `.../gogo/` | Medium
|
||||
2 | File | `/.ssh/authorized_keys` | High
|
||||
3 | File | `/admin.php/Admin/adminadd.html` | High
|
||||
4 | File | `/Admin/dashboard.php` | High
|
||||
5 | File | `/admin/problem_judge.php` | High
|
||||
6 | File | `/api/user/password/sent-reset-email` | High
|
||||
7 | File | `/asms/admin/mechanics/manage_mechanic.php` | High
|
||||
8 | File | `/asms/classes/Master.php?f=delete_mechanic` | High
|
||||
9 | File | `/asms/classes/Master.php?f=delete_service` | High
|
||||
10 | File | `/balance/service/list` | High
|
||||
11 | File | `/bsms_ci/index.php/book` | High
|
||||
12 | File | `/cgi-bin/wlogin.cgi` | High
|
||||
13 | File | `/CommunitySSORedirect.jsp` | High
|
||||
14 | File | `/Content/Template/root/reverse-shell.aspx` | High
|
||||
15 | File | `/diag_ping_admin.asp` | High
|
||||
16 | File | `/diag_tracert_admin.asp` | High
|
||||
17 | File | `/etc/passwd` | Medium
|
||||
5 | File | `/api/audits` | Medium
|
||||
6 | File | `/bsms_ci/index.php` | High
|
||||
7 | File | `/bsms_ci/index.php/book` | High
|
||||
8 | File | `/bsms_ci/index.php/user/edit_user/` | High
|
||||
9 | File | `/carbon/ndatasource/validateconnection/ajaxprocessor.jsp` | High
|
||||
10 | File | `/cgi-bin/wlogin.cgi` | High
|
||||
11 | File | `/Content/Template/root/reverse-shell.aspx` | High
|
||||
12 | File | `/diag_ping_admin.asp` | High
|
||||
13 | File | `/diag_tracert_admin.asp` | High
|
||||
14 | File | `/face-recognition-php/facepay-master/camera.php` | High
|
||||
15 | File | `/forum/away.php` | High
|
||||
16 | File | `/gpac/src/bifs/unquantize.c` | High
|
||||
17 | File | `/hrm/controller/employee.php` | High
|
||||
18 | File | `/index.php` | Medium
|
||||
19 | File | `/index/user/user_edit.html` | High
|
||||
20 | File | `/login.php` | Medium
|
||||
21 | File | `/Member/memberedit.html` | High
|
||||
22 | File | `/okm:root` | Medium
|
||||
23 | File | `/opt/zimbra/jetty/webapps/zimbra/public` | High
|
||||
24 | ... | ... | ...
|
||||
20 | File | `/leave_system/admin/?page=maintenance/department` | High
|
||||
21 | File | `/login` | Low
|
||||
22 | File | `/login.php` | Medium
|
||||
23 | File | `/Member/memberedit.html` | High
|
||||
24 | File | `/out.php` | Medium
|
||||
25 | File | `/pages/processlogin.php` | High
|
||||
26 | File | `/product/savenewproduct.php?flag=1` | High
|
||||
27 | File | `/scenegraph/svg_attributes.c` | High
|
||||
28 | ... | ... | ...
|
||||
|
||||
There are 201 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 238 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -40,7 +40,7 @@ ID | Technique | Weakness | Description | Confidence
|
|||
4 | T1059.007 | CWE-79, CWE-80 | Cross Site Scripting | High
|
||||
5 | ... | ... | ... | ...
|
||||
|
||||
There are 14 more TTP items available. Please use our online service to access the data.
|
||||
There are 15 more TTP items available. Please use our online service to access the data.
|
||||
|
||||
## IOA - Indicator of Attack
|
||||
|
||||
|
@ -59,7 +59,7 @@ ID | Type | Indicator | Confidence
|
|||
9 | File | `action/addproject.php` | High
|
||||
10 | ... | ... | ...
|
||||
|
||||
There are 74 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 75 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -13,7 +13,7 @@ These _countries_ are directly (e.g. origin of attacks) or indirectly (e.g. acce
|
|||
* [CN](https://vuldb.com/?country.cn)
|
||||
* ...
|
||||
|
||||
There are 10 more country items available. Please use our online service to access the data.
|
||||
There are 8 more country items available. Please use our online service to access the data.
|
||||
|
||||
## IOC - Indicator of Compromise
|
||||
|
||||
|
@ -99,47 +99,45 @@ ID | Type | Indicator | Confidence
|
|||
1 | File | `/.ssh/authorized_keys` | High
|
||||
2 | File | `/admin/admin.php` | High
|
||||
3 | File | `/admin/edit_members.php` | High
|
||||
4 | File | `/admin/store.php` | High
|
||||
5 | File | `/admin/submit-articles` | High
|
||||
6 | File | `/admin/users/index.php` | High
|
||||
7 | File | `/api/sys_username_passwd.cmd` | High
|
||||
8 | File | `/asms/admin/?page=transactions/manage_transaction` | High
|
||||
9 | File | `/asms/admin/mechanics/view_mechanic.php` | High
|
||||
10 | File | `/asms/admin/products/manage_product.php` | High
|
||||
11 | File | `/asms/products/view_product.php` | High
|
||||
12 | File | `/balance/service/list` | High
|
||||
13 | File | `/bsms_ci/index.php` | High
|
||||
14 | File | `/bsms_ci/index.php/user/edit_user/` | High
|
||||
15 | File | `/calendar/viewcalendar.php` | High
|
||||
16 | File | `/carbon/ndatasource/validateconnection/ajaxprocessor.jsp` | High
|
||||
17 | File | `/cgi-bin/qcmap_auth` | High
|
||||
18 | File | `/cgi-bin/wlogin.cgi` | High
|
||||
19 | File | `/classes/Master.php?f=delete_appointment` | High
|
||||
20 | File | `/classes/Master.php?f=delete_reservation` | High
|
||||
21 | File | `/classes/Users.php?f=delete_client` | High
|
||||
22 | File | `/clients/listclients.php` | High
|
||||
23 | File | `/CommunitySSORedirect.jsp` | High
|
||||
24 | File | `/Content/Template/root/reverse-shell.aspx` | High
|
||||
25 | File | `/Default/Bd` | Medium
|
||||
26 | File | `/device/acceptBind` | High
|
||||
27 | File | `/diagnostic/editclient.php` | High
|
||||
28 | File | `/event/admin/?page=user/list` | High
|
||||
29 | File | `/face-recognition-php/facepay-master/camera.php` | High
|
||||
30 | File | `/filemanager/php/connector.php` | High
|
||||
31 | File | `/forum/away.php` | High
|
||||
32 | File | `/general/search.php?searchtype=simple` | High
|
||||
33 | File | `/HNAP1` | Low
|
||||
34 | File | `/hrm/controller/employee.php` | High
|
||||
35 | File | `/hrm/employeeadd.php` | High
|
||||
36 | File | `/ims/login.php` | High
|
||||
37 | File | `/index.php/purchase_order/browse_data` | High
|
||||
38 | File | `/index.php?module=configuration/application` | High
|
||||
39 | File | `/index.php?module=entities/fields&entities_id=24` | High
|
||||
40 | File | `/index.php?module=entities/forms&entities_id=24` | High
|
||||
41 | File | `/index/user/user_edit.html` | High
|
||||
42 | ... | ... | ...
|
||||
4 | File | `/admin/submit-articles` | High
|
||||
5 | File | `/admin/users/index.php` | High
|
||||
6 | File | `/api/sys_username_passwd.cmd` | High
|
||||
7 | File | `/asms/admin/?page=transactions/manage_transaction` | High
|
||||
8 | File | `/asms/admin/mechanics/view_mechanic.php` | High
|
||||
9 | File | `/asms/admin/products/manage_product.php` | High
|
||||
10 | File | `/asms/products/view_product.php` | High
|
||||
11 | File | `/balance/service/list` | High
|
||||
12 | File | `/bsms_ci/index.php` | High
|
||||
13 | File | `/bsms_ci/index.php/user/edit_user/` | High
|
||||
14 | File | `/calendar/viewcalendar.php` | High
|
||||
15 | File | `/carbon/ndatasource/validateconnection/ajaxprocessor.jsp` | High
|
||||
16 | File | `/cgi-bin/wlogin.cgi` | High
|
||||
17 | File | `/classes/Master.php?f=delete_appointment` | High
|
||||
18 | File | `/clients/listclients.php` | High
|
||||
19 | File | `/CommunitySSORedirect.jsp` | High
|
||||
20 | File | `/Content/Template/root/reverse-shell.aspx` | High
|
||||
21 | File | `/Default/Bd` | Medium
|
||||
22 | File | `/device/acceptBind` | High
|
||||
23 | File | `/diagnostic/editclient.php` | High
|
||||
24 | File | `/event/admin/?page=user/list` | High
|
||||
25 | File | `/face-recognition-php/facepay-master/camera.php` | High
|
||||
26 | File | `/forum/away.php` | High
|
||||
27 | File | `/general/search.php?searchtype=simple` | High
|
||||
28 | File | `/HNAP1` | Low
|
||||
29 | File | `/hrm/controller/employee.php` | High
|
||||
30 | File | `/hrm/employeeadd.php` | High
|
||||
31 | File | `/hrm/employeeview.php` | High
|
||||
32 | File | `/ims/login.php` | High
|
||||
33 | File | `/index.php/purchase_order/browse_data` | High
|
||||
34 | File | `/index.php?module=configuration/application` | High
|
||||
35 | File | `/index.php?module=entities/fields&entities_id=24` | High
|
||||
36 | File | `/index.php?module=entities/forms&entities_id=24` | High
|
||||
37 | File | `/index/user/user_edit.html` | High
|
||||
38 | File | `/Member/memberedit.html` | High
|
||||
39 | File | `/okm:root` | Medium
|
||||
40 | ... | ... | ...
|
||||
|
||||
There are 364 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 348 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -49,8 +49,7 @@ ID | Technique | Weakness | Description | Confidence
|
|||
2 | T1040 | CWE-294, CWE-319 | Authentication Bypass by Capture-replay | High
|
||||
3 | T1055 | CWE-74 | Injection | High
|
||||
4 | T1059 | CWE-94 | Cross Site Scripting | High
|
||||
5 | T1059.007 | CWE-79, CWE-80 | Cross Site Scripting | High
|
||||
6 | ... | ... | ... | ...
|
||||
5 | ... | ... | ... | ...
|
||||
|
||||
There are 18 more TTP items available. Please use our online service to access the data.
|
||||
|
||||
|
@ -61,57 +60,70 @@ These _indicators of attack_ (IOA) list the potential fragments used for technic
|
|||
ID | Type | Indicator | Confidence
|
||||
-- | ---- | --------- | ----------
|
||||
1 | File | `.htaccess` | Medium
|
||||
2 | File | `/admin/conferences/list/` | High
|
||||
3 | File | `/admin/edit_admin_details.php?id=admin` | High
|
||||
4 | File | `/admin/generalsettings.php` | High
|
||||
5 | File | `/Admin/login.php` | High
|
||||
6 | File | `/admin/payment.php` | High
|
||||
7 | File | `/admin/reports.php` | High
|
||||
8 | File | `/admin/showbad.php` | High
|
||||
9 | File | `/admin_page/all-files-update-ajax.php` | High
|
||||
10 | File | `/bsms/?page=products` | High
|
||||
11 | File | `/cgi-bin/kerbynet` | High
|
||||
12 | File | `/cgi-bin/system_mgr.cgi` | High
|
||||
13 | File | `/cgi-bin/wlogin.cgi` | High
|
||||
14 | File | `/cloud_config/router_post/check_reg_verify_code` | High
|
||||
15 | File | `/debug/pprof` | Medium
|
||||
16 | File | `/dms/admin/reports/daily_collection_report.php` | High
|
||||
17 | File | `/ext/phar/phar_object.c` | High
|
||||
18 | File | `/filemanager/php/connector.php` | High
|
||||
19 | File | `/forum/away.php` | High
|
||||
20 | File | `/HNAP1` | Low
|
||||
21 | File | `/include/chart_generator.php` | High
|
||||
22 | File | `/index.php` | Medium
|
||||
23 | File | `/info.cgi` | Medium
|
||||
24 | File | `/Items/*/RemoteImages/Download` | High
|
||||
25 | File | `/lists/admin/` | High
|
||||
26 | File | `/MagickCore/image.c` | High
|
||||
27 | File | `/mgmt/tm/util/bash` | High
|
||||
28 | File | `/modx/manager/index.php` | High
|
||||
29 | File | `/out.php` | Medium
|
||||
30 | File | `/public/launchNewWindow.jsp` | High
|
||||
31 | File | `/replication` | Medium
|
||||
32 | File | `/siteminderagent/pwcgi/smpwservicescgi.exe` | High
|
||||
33 | File | `/spip.php` | Medium
|
||||
34 | File | `/TeleoptiWFM/Administration/GetOneTenant` | High
|
||||
35 | File | `/type.php` | Medium
|
||||
36 | File | `/usr/bin/pkexec` | High
|
||||
37 | File | `/WEB-INF/web.xml` | High
|
||||
38 | File | `/Wedding-Management/package_detail.php` | High
|
||||
39 | File | `/wp-content/plugins/woocommerce/templates/emails/plain/` | High
|
||||
40 | File | `4.2.0.CP09` | Medium
|
||||
41 | File | `14all.cgi/14all-1.1.cgi/traffic.cgi/mrtg.cgi` | High
|
||||
42 | File | `802dot1xclientcert.cgi` | High
|
||||
43 | File | `a2billing/customer/iridium_threed.php` | High
|
||||
44 | File | `AdClass.php` | Medium
|
||||
45 | File | `adclick.php` | Medium
|
||||
46 | File | `add.exe` | Low
|
||||
47 | File | `admin.php?m=Food&a=addsave` | High
|
||||
48 | File | `admin/conf_users_edit.php` | High
|
||||
49 | File | `admin/index.php` | High
|
||||
50 | ... | ... | ...
|
||||
2 | File | `/Admin/add-student.php` | High
|
||||
3 | File | `/admin/conferences/list/` | High
|
||||
4 | File | `/admin/edit_admin_details.php?id=admin` | High
|
||||
5 | File | `/admin/generalsettings.php` | High
|
||||
6 | File | `/Admin/login.php` | High
|
||||
7 | File | `/admin/payment.php` | High
|
||||
8 | File | `/admin/reports.php` | High
|
||||
9 | File | `/admin/showbad.php` | High
|
||||
10 | File | `/admin_page/all-files-update-ajax.php` | High
|
||||
11 | File | `/apilog.php` | Medium
|
||||
12 | File | `/bsms/?page=products` | High
|
||||
13 | File | `/cgi-bin/kerbynet` | High
|
||||
14 | File | `/cgi-bin/system_mgr.cgi` | High
|
||||
15 | File | `/cgi-bin/wlogin.cgi` | High
|
||||
16 | File | `/cloud_config/router_post/check_reg_verify_code` | High
|
||||
17 | File | `/connectors/index.php` | High
|
||||
18 | File | `/debug/pprof` | Medium
|
||||
19 | File | `/dms/admin/reports/daily_collection_report.php` | High
|
||||
20 | File | `/filemanager/php/connector.php` | High
|
||||
21 | File | `/forum/away.php` | High
|
||||
22 | File | `/hrm/employeeadd.php` | High
|
||||
23 | File | `/include/chart_generator.php` | High
|
||||
24 | File | `/index.php` | Medium
|
||||
25 | File | `/info.cgi` | Medium
|
||||
26 | File | `/Items/*/RemoteImages/Download` | High
|
||||
27 | File | `/items/view_item.php` | High
|
||||
28 | File | `/lists/admin/` | High
|
||||
29 | File | `/MagickCore/image.c` | High
|
||||
30 | File | `/manager/index.php` | High
|
||||
31 | File | `/medical/inventories.php` | High
|
||||
32 | File | `/mgmt/tm/util/bash` | High
|
||||
33 | File | `/modules/profile/index.php` | High
|
||||
34 | File | `/modules/projects/vw_files.php` | High
|
||||
35 | File | `/modules/public/calendar.php` | High
|
||||
36 | File | `/modx/manager/index.php` | High
|
||||
37 | File | `/newsDia.php` | Medium
|
||||
38 | File | `/out.php` | Medium
|
||||
39 | File | `/public/launchNewWindow.jsp` | High
|
||||
40 | File | `/Redcock-Farm/farm/category.php` | High
|
||||
41 | File | `/sacco_shield/manage_user.php` | High
|
||||
42 | File | `/siteminderagent/pwcgi/smpwservicescgi.exe` | High
|
||||
43 | File | `/spip.php` | Medium
|
||||
44 | File | `/sqlitemanager/main.php?dbsel=-1%20or%2072%20=%2072` | High
|
||||
45 | File | `/staff/bookdetails.php` | High
|
||||
46 | File | `/TeleoptiWFM/Administration/GetOneTenant` | High
|
||||
47 | File | `/user/update_booking.php` | High
|
||||
48 | File | `/usr/bin/pkexec` | High
|
||||
49 | File | `/WEB-INF/web.xml` | High
|
||||
50 | File | `/Wedding-Management-PHP/admin/photos_add.php` | High
|
||||
51 | File | `/Wedding-Management/package_detail.php` | High
|
||||
52 | File | `/wordpress/wp-admin/options-general.php` | High
|
||||
53 | File | `/wp-content/plugins/woocommerce/templates/emails/plain/` | High
|
||||
54 | File | `a2billing/customer/iridium_threed.php` | High
|
||||
55 | File | `AdClass.php` | Medium
|
||||
56 | File | `adclick.php` | Medium
|
||||
57 | File | `add.exe` | Low
|
||||
58 | File | `addtocart.asp` | High
|
||||
59 | File | `admin.php` | Medium
|
||||
60 | File | `admin.php?m=Food&a=addsave` | High
|
||||
61 | File | `admin/conf_users_edit.php` | High
|
||||
62 | File | `admin/index.php` | High
|
||||
63 | ... | ... | ...
|
||||
|
||||
There are 435 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 550 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -528,7 +528,7 @@ ID | Technique | Weakness | Description | Confidence
|
|||
2 | T1040 | CWE-294 | Authentication Bypass by Capture-replay | High
|
||||
3 | T1055 | CWE-74 | Injection | High
|
||||
4 | T1059 | CWE-94, CWE-1321 | Cross Site Scripting | High
|
||||
5 | T1059.007 | CWE-79, CWE-80, CWE-87 | Cross Site Scripting | High
|
||||
5 | T1059.007 | CWE-79, CWE-87 | Cross Site Scripting | High
|
||||
6 | ... | ... | ... | ...
|
||||
|
||||
There are 22 more TTP items available. Please use our online service to access the data.
|
||||
|
@ -544,38 +544,38 @@ ID | Type | Indicator | Confidence
|
|||
3 | File | `/admin/login.php` | High
|
||||
4 | File | `/Admin/login.php` | High
|
||||
5 | File | `/admin/students/manage.php` | High
|
||||
6 | File | `/admin/students/view_student.php` | High
|
||||
7 | File | `/admin/submit-articles` | High
|
||||
8 | File | `/admin/subnets/ripe-query.php` | High
|
||||
9 | File | `/api/RecordingList/DownloadRecord?file=` | High
|
||||
10 | File | `/api/user/upsert/<uuid>` | High
|
||||
11 | File | `/card_scan.php` | High
|
||||
12 | File | `/cgi-bin/luci/api/wireless` | High
|
||||
13 | File | `/cgi-bin/wlogin.cgi` | High
|
||||
14 | File | `/context/%2e/WEB-INF/web.xml` | High
|
||||
15 | File | `/cwc/login` | Medium
|
||||
16 | File | `/dashboard/updatelogo.php` | High
|
||||
17 | File | `/debug/pprof` | Medium
|
||||
18 | File | `/export` | Low
|
||||
19 | File | `/foms/place-order.php` | High
|
||||
20 | File | `/goform/setmac` | High
|
||||
21 | File | `/goform/wizard_end` | High
|
||||
22 | File | `/h/calendar` | Medium
|
||||
23 | File | `/h/compose` | Medium
|
||||
24 | File | `/h/search?action=voicemail&action=listen` | High
|
||||
25 | File | `/index.php` | Medium
|
||||
26 | File | `/loginVaLidation.php` | High
|
||||
27 | File | `/manage-apartment.php` | High
|
||||
28 | File | `/manager/index.php` | High
|
||||
29 | File | `/members/view_member.php` | High
|
||||
30 | File | `/mkshop/Men/profile.php` | High
|
||||
31 | File | `/modules/caddyhttp/rewrite/rewrite.go` | High
|
||||
32 | File | `/nova/bin/detnet` | High
|
||||
33 | File | `/Noxen-master/users.php` | High
|
||||
34 | File | `/opac/Actions.php?a=login` | High
|
||||
35 | File | `/opt/zimbra/jetty/webapps/zimbra/public` | High
|
||||
36 | File | `/owa/auth/logon.aspx` | High
|
||||
37 | File | `/pages/apply_vacancy.php` | High
|
||||
6 | File | `/admin/submit-articles` | High
|
||||
7 | File | `/admin/subnets/ripe-query.php` | High
|
||||
8 | File | `/api/RecordingList/DownloadRecord?file=` | High
|
||||
9 | File | `/api/user/upsert/<uuid>` | High
|
||||
10 | File | `/card_scan.php` | High
|
||||
11 | File | `/cgi-bin/luci/api/wireless` | High
|
||||
12 | File | `/cgi-bin/wlogin.cgi` | High
|
||||
13 | File | `/context/%2e/WEB-INF/web.xml` | High
|
||||
14 | File | `/cwc/login` | Medium
|
||||
15 | File | `/debug/pprof` | Medium
|
||||
16 | File | `/event/admin/?page=user/list` | High
|
||||
17 | File | `/export` | Low
|
||||
18 | File | `/foms/place-order.php` | High
|
||||
19 | File | `/goform/setmac` | High
|
||||
20 | File | `/goform/wizard_end` | High
|
||||
21 | File | `/h/calendar` | Medium
|
||||
22 | File | `/h/compose` | Medium
|
||||
23 | File | `/h/search?action=voicemail&action=listen` | High
|
||||
24 | File | `/index.php` | Medium
|
||||
25 | File | `/loginVaLidation.php` | High
|
||||
26 | File | `/manage-apartment.php` | High
|
||||
27 | File | `/manager/index.php` | High
|
||||
28 | File | `/members/view_member.php` | High
|
||||
29 | File | `/mkshop/Men/profile.php` | High
|
||||
30 | File | `/modules/caddyhttp/rewrite/rewrite.go` | High
|
||||
31 | File | `/nova/bin/detnet` | High
|
||||
32 | File | `/Noxen-master/users.php` | High
|
||||
33 | File | `/opac/Actions.php?a=login` | High
|
||||
34 | File | `/opt/zimbra/jetty/webapps/zimbra/public` | High
|
||||
35 | File | `/owa/auth/logon.aspx` | High
|
||||
36 | File | `/pages/apply_vacancy.php` | High
|
||||
37 | File | `/php-sms/classes/Master.php` | High
|
||||
38 | ... | ... | ...
|
||||
|
||||
There are 327 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
|
|
@ -77,33 +77,34 @@ ID | Type | Indicator | Confidence
|
|||
5 | File | `/admin/add-fee.php` | High
|
||||
6 | File | `/admin/baojia_list.php` | High
|
||||
7 | File | `/admin/folderrollpicture/list` | High
|
||||
8 | File | `/anony/mjpg.cgi` | High
|
||||
9 | File | `/api/common/ping` | High
|
||||
10 | File | `/api/v2/open/rowsInfo` | High
|
||||
11 | File | `/Applications/Google\ Drive.app/Contents/MacOS` | High
|
||||
12 | File | `/appointments/update_status.php` | High
|
||||
13 | File | `/authUserAction!edit.action` | High
|
||||
14 | File | `/bin/boa` | Medium
|
||||
15 | File | `/bookings/update_status.php` | High
|
||||
16 | File | `/cgi-bin/DownloadFlash` | High
|
||||
17 | File | `/classes/Master.php?f=delete_category` | High
|
||||
18 | File | `/classes/Users.php?f=delete_client` | High
|
||||
19 | File | `/contacts/listcontacts.php` | High
|
||||
20 | File | `/Core/Ap4File.cpp` | High
|
||||
21 | File | `/csms/admin/storages/view_storage.php` | High
|
||||
22 | File | `/dede/file_manage_control.php` | High
|
||||
23 | File | `/depotHead/list` | High
|
||||
24 | File | `/etc/ciel.cfg` | High
|
||||
25 | File | `/etc/openshift/server_priv.pem` | High
|
||||
26 | File | `/etc/shadow.sample` | High
|
||||
27 | File | `/forms/web_runScript` | High
|
||||
28 | File | `/garage/php_action/createBrand.php` | High
|
||||
29 | File | `/general/search.php?searchtype=simple` | High
|
||||
30 | File | `/goform/AddSysLogRule` | High
|
||||
31 | File | `/goform/formSetFirewallCfg` | High
|
||||
32 | ... | ... | ...
|
||||
8 | File | `/admin/loginc.php` | High
|
||||
9 | File | `/anony/mjpg.cgi` | High
|
||||
10 | File | `/api/common/ping` | High
|
||||
11 | File | `/api/v2/open/rowsInfo` | High
|
||||
12 | File | `/Applications/Google\ Drive.app/Contents/MacOS` | High
|
||||
13 | File | `/appointments/update_status.php` | High
|
||||
14 | File | `/authUserAction!edit.action` | High
|
||||
15 | File | `/bin/boa` | Medium
|
||||
16 | File | `/bookings/update_status.php` | High
|
||||
17 | File | `/cgi-bin/DownloadFlash` | High
|
||||
18 | File | `/classes/Master.php?f=delete_category` | High
|
||||
19 | File | `/classes/Users.php?f=delete_client` | High
|
||||
20 | File | `/contacts/listcontacts.php` | High
|
||||
21 | File | `/Core/Ap4File.cpp` | High
|
||||
22 | File | `/csms/admin/storages/view_storage.php` | High
|
||||
23 | File | `/dede/file_manage_control.php` | High
|
||||
24 | File | `/depotHead/list` | High
|
||||
25 | File | `/etc/ciel.cfg` | High
|
||||
26 | File | `/etc/openshift/server_priv.pem` | High
|
||||
27 | File | `/etc/shadow.sample` | High
|
||||
28 | File | `/forms/web_runScript` | High
|
||||
29 | File | `/garage/php_action/createBrand.php` | High
|
||||
30 | File | `/general/search.php?searchtype=simple` | High
|
||||
31 | File | `/goform/AddSysLogRule` | High
|
||||
32 | File | `/goform/formSetFirewallCfg` | High
|
||||
33 | ... | ... | ...
|
||||
|
||||
There are 276 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 283 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -49,7 +49,7 @@ ID | Technique | Weakness | Description | Confidence
|
|||
5 | T1059.007 | CWE-79, CWE-80 | Cross Site Scripting | High
|
||||
6 | ... | ... | ... | ...
|
||||
|
||||
There are 22 more TTP items available. Please use our online service to access the data.
|
||||
There are 21 more TTP items available. Please use our online service to access the data.
|
||||
|
||||
## IOA - Indicator of Attack
|
||||
|
||||
|
@ -58,35 +58,35 @@ These _indicators of attack_ (IOA) list the potential fragments used for technic
|
|||
ID | Type | Indicator | Confidence
|
||||
-- | ---- | --------- | ----------
|
||||
1 | File | `/.ssh/authorized_keys` | High
|
||||
2 | File | `/action/ipcamRecordPost` | High
|
||||
3 | File | `/admin/` | Low
|
||||
4 | File | `/admin/admin.php` | High
|
||||
5 | File | `/admin/settings/save.php` | High
|
||||
6 | File | `/auparse/auparse.c` | High
|
||||
7 | File | `/bsms_ci/index.php` | High
|
||||
8 | File | `/bsms_ci/index.php/user/edit_user/` | High
|
||||
9 | File | `/carbon/ndatasource/validateconnection/ajaxprocessor.jsp` | High
|
||||
10 | File | `/cgi-bin/qcmap_auth` | High
|
||||
11 | File | `/cgi-bin/wlogin.cgi` | High
|
||||
12 | File | `/common/info.cgi` | High
|
||||
13 | File | `/CommunitySSORedirect.jsp` | High
|
||||
14 | File | `/Content/Template/root/reverse-shell.aspx` | High
|
||||
15 | File | `/device/signin` | High
|
||||
16 | File | `/diagnostic/editclient.php` | High
|
||||
17 | File | `/diag_tracert_admin.asp` | High
|
||||
18 | File | `/edit-db.php` | Medium
|
||||
19 | File | `/event/admin/?page=user/list` | High
|
||||
20 | File | `/exec/` | Low
|
||||
21 | File | `/filemanager/php/connector.php` | High
|
||||
22 | File | `/forum/away.php` | High
|
||||
23 | File | `/hospital/hms/admin/patient-search.php` | High
|
||||
24 | File | `/hrm/controller/employee.php` | High
|
||||
25 | File | `/hrm/index.php?msg` | High
|
||||
26 | File | `/hrm/state.php` | High
|
||||
27 | File | `/index.php?module=entities/fields&entities_id=24` | High
|
||||
28 | File | `/index.php?module=global_lists/lists` | High
|
||||
29 | File | `/irj/portal/` | Medium
|
||||
30 | File | `/modules/projects/vw_files.php` | High
|
||||
2 | File | `/admin/` | Low
|
||||
3 | File | `/admin/admin.php` | High
|
||||
4 | File | `/admin/settings/save.php` | High
|
||||
5 | File | `/auparse/auparse.c` | High
|
||||
6 | File | `/bsms_ci/index.php` | High
|
||||
7 | File | `/bsms_ci/index.php/user/edit_user/` | High
|
||||
8 | File | `/carbon/ndatasource/validateconnection/ajaxprocessor.jsp` | High
|
||||
9 | File | `/cgi-bin/qcmap_auth` | High
|
||||
10 | File | `/cgi-bin/wlogin.cgi` | High
|
||||
11 | File | `/common/info.cgi` | High
|
||||
12 | File | `/CommunitySSORedirect.jsp` | High
|
||||
13 | File | `/Content/Template/root/reverse-shell.aspx` | High
|
||||
14 | File | `/device/signin` | High
|
||||
15 | File | `/diagnostic/editclient.php` | High
|
||||
16 | File | `/diag_tracert_admin.asp` | High
|
||||
17 | File | `/edit-db.php` | Medium
|
||||
18 | File | `/event/admin/?page=user/list` | High
|
||||
19 | File | `/exec/` | Low
|
||||
20 | File | `/filemanager/php/connector.php` | High
|
||||
21 | File | `/forum/away.php` | High
|
||||
22 | File | `/hospital/hms/admin/patient-search.php` | High
|
||||
23 | File | `/hrm/controller/employee.php` | High
|
||||
24 | File | `/hrm/index.php?msg` | High
|
||||
25 | File | `/hrm/state.php` | High
|
||||
26 | File | `/index.php?module=entities/fields&entities_id=24` | High
|
||||
27 | File | `/index.php?module=global_lists/lists` | High
|
||||
28 | File | `/irj/portal/` | Medium
|
||||
29 | File | `/modules/projects/vw_files.php` | High
|
||||
30 | File | `/nova/bin/sniffer` | High
|
||||
31 | File | `/odlms/?page=appointments/view_appointment` | High
|
||||
32 | File | `/okm:root` | Medium
|
||||
33 | File | `/opt/zimbra/jetty/webapps/zimbra/public` | High
|
||||
|
@ -98,7 +98,7 @@ ID | Type | Indicator | Confidence
|
|||
39 | File | `/Redcock-Farm/farm/category.php` | High
|
||||
40 | ... | ... | ...
|
||||
|
||||
There are 348 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 341 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -0,0 +1,30 @@
|
|||
# DEV-0139 - Cyber Threat Intelligence
|
||||
|
||||
These _indicators_ were reported, collected, and generated during the [VulDB CTI analysis](https://vuldb.com/?kb.cti) of the actor known as [DEV-0139](https://vuldb.com/?actor.dev-0139). The _activity monitoring_ correlates data from social media, forums, chat rooms, and darknet markets. It helps to determine associated actors, specific activities, expected intentions, emerging research, and ongoing attacks. Our unique _predictive model_ uses _big data_ to forecast activities and their characteristics.
|
||||
|
||||
_Live data_ and more _analysis capabilities_ are available at [https://vuldb.com/?actor.dev-0139](https://vuldb.com/?actor.dev-0139)
|
||||
|
||||
## IOC - Indicator of Compromise
|
||||
|
||||
These _indicators of compromise_ (IOC) indicate associated network resources which are known to be part of research and attack activities of DEV-0139.
|
||||
|
||||
ID | IP address | Hostname | Campaign | Confidence
|
||||
-- | ---------- | -------- | -------- | ----------
|
||||
1 | [198.54.115.248](https://vuldb.com/?ip.198.54.115.248) | server64-3.web-hosting.com | - | High
|
||||
|
||||
## References
|
||||
|
||||
The following list contains _external sources_ which discuss the actor and the associated activities:
|
||||
|
||||
* https://www.microsoft.com/en-us/security/blog/2022/12/06/dev-0139-launches-targeted-attacks-against-the-cryptocurrency-industry/
|
||||
|
||||
## Literature
|
||||
|
||||
The following _articles_ explain our unique predictive cyber threat intelligence:
|
||||
|
||||
* [VulDB Cyber Threat Intelligence Documentation](https://vuldb.com/?kb.cti)
|
||||
* [Cyber Threat Intelligence - Early Anticipation of Attacks](https://www.scip.ch/en/?labs.20201022)
|
||||
|
||||
## License
|
||||
|
||||
(c) [1997-2022](https://vuldb.com/?kb.changelog) by [vuldb.com](https://vuldb.com/?kb.about). All data on this page is shared under the license [CC BY-NC-SA 4.0](https://creativecommons.org/licenses/by-nc-sa/4.0/). Questions? Check the [FAQ](https://vuldb.com/?kb.faq), read the [documentation](https://vuldb.com/?kb) or [contact us](https://vuldb.com/?contact)!
|
|
@ -57,7 +57,7 @@ ID | Type | Indicator | Confidence
|
|||
13 | File | `auth-options.c` | High
|
||||
14 | ... | ... | ...
|
||||
|
||||
There are 110 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 111 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -67,7 +67,7 @@ ID | Type | Indicator | Confidence
|
|||
10 | File | `attachment_send.php` | High
|
||||
11 | ... | ... | ...
|
||||
|
||||
There are 83 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 84 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -9,11 +9,11 @@ _Live data_ and more _analysis capabilities_ are available at [https://vuldb.com
|
|||
These _countries_ are directly (e.g. origin of attacks) or indirectly (e.g. access by proxy) associated with Emotet:
|
||||
|
||||
* [VN](https://vuldb.com/?country.vn)
|
||||
* [ES](https://vuldb.com/?country.es)
|
||||
* [CN](https://vuldb.com/?country.cn)
|
||||
* [ES](https://vuldb.com/?country.es)
|
||||
* ...
|
||||
|
||||
There are 10 more country items available. Please use our online service to access the data.
|
||||
There are 8 more country items available. Please use our online service to access the data.
|
||||
|
||||
## IOC - Indicator of Compromise
|
||||
|
||||
|
@ -825,7 +825,7 @@ ID | Technique | Weakness | Description | Confidence
|
|||
5 | T1059.007 | CWE-79, CWE-80, CWE-85 | Cross Site Scripting | High
|
||||
6 | ... | ... | ... | ...
|
||||
|
||||
There are 18 more TTP items available. Please use our online service to access the data.
|
||||
There are 19 more TTP items available. Please use our online service to access the data.
|
||||
|
||||
## IOA - Indicator of Attack
|
||||
|
||||
|
@ -833,13 +833,13 @@ These _indicators of attack_ (IOA) list the potential fragments used for technic
|
|||
|
||||
ID | Type | Indicator | Confidence
|
||||
-- | ---- | --------- | ----------
|
||||
1 | File | `%ProgramData%\GOG.com` | High
|
||||
2 | File | `/.ssh/authorized_keys` | High
|
||||
3 | File | `/admin/fst_upload.inc.php` | High
|
||||
4 | File | `/admin/submit-articles` | High
|
||||
1 | File | `/.ssh/authorized_keys` | High
|
||||
2 | File | `/admin/fst_upload.inc.php` | High
|
||||
3 | File | `/admin/submit-articles` | High
|
||||
4 | File | `/api/audits` | Medium
|
||||
5 | File | `/authUserAction!edit.action` | High
|
||||
6 | File | `/bsms_ci/index.php` | High
|
||||
7 | File | `/bsms_ci/index.php/book` | High
|
||||
6 | File | `/balance/service/list` | High
|
||||
7 | File | `/bsms_ci/index.php` | High
|
||||
8 | File | `/bsms_ci/index.php/user/edit_user/` | High
|
||||
9 | File | `/carbon/ndatasource/validateconnection/ajaxprocessor.jsp` | High
|
||||
10 | File | `/cgi-bin/webproc` | High
|
||||
|
@ -851,19 +851,19 @@ ID | Type | Indicator | Confidence
|
|||
16 | File | `/gpac/src/bifs/unquantize.c` | High
|
||||
17 | File | `/hrm/controller/employee.php` | High
|
||||
18 | File | `/index.php?route=extension/module/so_filter_shop_by/filter_data` | High
|
||||
19 | File | `/login` | Low
|
||||
20 | File | `/Member/memberedit.html` | High
|
||||
19 | File | `/leave_system/admin/?page=maintenance/department` | High
|
||||
20 | File | `/login` | Low
|
||||
21 | File | `/modules/caddyhttp/rewrite/rewrite.go` | High
|
||||
22 | File | `/out.php` | Medium
|
||||
23 | File | `/pages/processlogin.php` | High
|
||||
24 | File | `/product/savenewproduct.php?flag=1` | High
|
||||
25 | File | `/proxy` | Low
|
||||
22 | File | `/product/savenewproduct.php?flag=1` | High
|
||||
23 | File | `/proxy` | Low
|
||||
24 | File | `/scenegraph/svg_attributes.c` | High
|
||||
25 | File | `/self.key` | Medium
|
||||
26 | File | `/signup_script.php` | High
|
||||
27 | File | `/spip.php` | Medium
|
||||
28 | File | `/system/sshkeys.js` | High
|
||||
29 | ... | ... | ...
|
||||
|
||||
There are 248 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 247 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -66,50 +66,50 @@ ID | Type | Indicator | Confidence
|
|||
19 | File | `/dms/admin/reports/daily_collection_report.php` | High
|
||||
20 | File | `/filemanager/php/connector.php` | High
|
||||
21 | File | `/forum/away.php` | High
|
||||
22 | File | `/include/chart_generator.php` | High
|
||||
23 | File | `/index.php` | Medium
|
||||
24 | File | `/info.cgi` | Medium
|
||||
25 | File | `/Items/*/RemoteImages/Download` | High
|
||||
26 | File | `/items/view_item.php` | High
|
||||
27 | File | `/lists/admin/` | High
|
||||
28 | File | `/MagickCore/image.c` | High
|
||||
29 | File | `/manager/index.php` | High
|
||||
30 | File | `/medical/inventories.php` | High
|
||||
31 | File | `/mgmt/tm/util/bash` | High
|
||||
32 | File | `/modules/profile/index.php` | High
|
||||
33 | File | `/modules/projects/vw_files.php` | High
|
||||
34 | File | `/modules/public/calendar.php` | High
|
||||
35 | File | `/modx/manager/index.php` | High
|
||||
36 | File | `/newsDia.php` | Medium
|
||||
37 | File | `/out.php` | Medium
|
||||
38 | File | `/public/launchNewWindow.jsp` | High
|
||||
39 | File | `/sacco_shield/manage_user.php` | High
|
||||
40 | File | `/siteminderagent/pwcgi/smpwservicescgi.exe` | High
|
||||
41 | File | `/spip.php` | Medium
|
||||
42 | File | `/sqlitemanager/main.php?dbsel=-1%20or%2072%20=%2072` | High
|
||||
43 | File | `/staff/bookdetails.php` | High
|
||||
44 | File | `/TeleoptiWFM/Administration/GetOneTenant` | High
|
||||
45 | File | `/user/update_booking.php` | High
|
||||
46 | File | `/usr/bin/pkexec` | High
|
||||
47 | File | `/WEB-INF/web.xml` | High
|
||||
48 | File | `/Wedding-Management-PHP/admin/photos_add.php` | High
|
||||
49 | File | `/Wedding-Management/package_detail.php` | High
|
||||
50 | File | `/wordpress/wp-admin/options-general.php` | High
|
||||
51 | File | `/wp-content/plugins/woocommerce/templates/emails/plain/` | High
|
||||
52 | File | `a2billing/customer/iridium_threed.php` | High
|
||||
53 | File | `AdClass.php` | Medium
|
||||
54 | File | `adclick.php` | Medium
|
||||
55 | File | `add.exe` | Low
|
||||
56 | File | `addtocart.asp` | High
|
||||
57 | File | `admin.php` | Medium
|
||||
58 | File | `admin.php?m=Food&a=addsave` | High
|
||||
59 | File | `admin/conf_users_edit.php` | High
|
||||
60 | File | `admin/index.php` | High
|
||||
61 | File | `admin/limits.php` | High
|
||||
62 | File | `admincp.php` | Medium
|
||||
22 | File | `/hrm/employeeadd.php` | High
|
||||
23 | File | `/include/chart_generator.php` | High
|
||||
24 | File | `/index.php` | Medium
|
||||
25 | File | `/info.cgi` | Medium
|
||||
26 | File | `/Items/*/RemoteImages/Download` | High
|
||||
27 | File | `/items/view_item.php` | High
|
||||
28 | File | `/lists/admin/` | High
|
||||
29 | File | `/MagickCore/image.c` | High
|
||||
30 | File | `/manager/index.php` | High
|
||||
31 | File | `/medical/inventories.php` | High
|
||||
32 | File | `/mgmt/tm/util/bash` | High
|
||||
33 | File | `/modules/profile/index.php` | High
|
||||
34 | File | `/modules/projects/vw_files.php` | High
|
||||
35 | File | `/modules/public/calendar.php` | High
|
||||
36 | File | `/modx/manager/index.php` | High
|
||||
37 | File | `/newsDia.php` | Medium
|
||||
38 | File | `/out.php` | Medium
|
||||
39 | File | `/public/launchNewWindow.jsp` | High
|
||||
40 | File | `/Redcock-Farm/farm/category.php` | High
|
||||
41 | File | `/sacco_shield/manage_user.php` | High
|
||||
42 | File | `/siteminderagent/pwcgi/smpwservicescgi.exe` | High
|
||||
43 | File | `/spip.php` | Medium
|
||||
44 | File | `/sqlitemanager/main.php?dbsel=-1%20or%2072%20=%2072` | High
|
||||
45 | File | `/staff/bookdetails.php` | High
|
||||
46 | File | `/TeleoptiWFM/Administration/GetOneTenant` | High
|
||||
47 | File | `/user/update_booking.php` | High
|
||||
48 | File | `/usr/bin/pkexec` | High
|
||||
49 | File | `/WEB-INF/web.xml` | High
|
||||
50 | File | `/Wedding-Management-PHP/admin/photos_add.php` | High
|
||||
51 | File | `/Wedding-Management/package_detail.php` | High
|
||||
52 | File | `/wordpress/wp-admin/options-general.php` | High
|
||||
53 | File | `/wp-content/plugins/woocommerce/templates/emails/plain/` | High
|
||||
54 | File | `a2billing/customer/iridium_threed.php` | High
|
||||
55 | File | `AdClass.php` | Medium
|
||||
56 | File | `adclick.php` | Medium
|
||||
57 | File | `add.exe` | Low
|
||||
58 | File | `addtocart.asp` | High
|
||||
59 | File | `admin.php` | Medium
|
||||
60 | File | `admin.php?m=Food&a=addsave` | High
|
||||
61 | File | `admin/conf_users_edit.php` | High
|
||||
62 | File | `admin/index.php` | High
|
||||
63 | ... | ... | ...
|
||||
|
||||
There are 552 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 553 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -105,18 +105,18 @@ ID | Type | Indicator | Confidence
|
|||
6 | File | `/ad_js.php` | Medium
|
||||
7 | File | `/api/RecordingList/DownloadRecord?file=` | High
|
||||
8 | File | `/apilog.php` | Medium
|
||||
9 | File | `/app/options.py` | High
|
||||
10 | File | `/cgi-bin/luci/api/wireless` | High
|
||||
11 | File | `/cgi-bin/wlogin.cgi` | High
|
||||
12 | File | `/connectors/index.php` | High
|
||||
13 | File | `/context/%2e/WEB-INF/web.xml` | High
|
||||
14 | File | `/dashboard/reports/logs/view` | High
|
||||
15 | File | `/debian/patches/load_ppp_generic_if_needed` | High
|
||||
16 | File | `/debug/pprof` | Medium
|
||||
17 | File | `/etc/hosts` | Medium
|
||||
18 | File | `/forum/away.php` | High
|
||||
19 | File | `/goform/setmac` | High
|
||||
20 | File | `/goform/wizard_end` | High
|
||||
9 | File | `/cgi-bin/luci/api/wireless` | High
|
||||
10 | File | `/cgi-bin/wlogin.cgi` | High
|
||||
11 | File | `/connectors/index.php` | High
|
||||
12 | File | `/context/%2e/WEB-INF/web.xml` | High
|
||||
13 | File | `/dashboard/reports/logs/view` | High
|
||||
14 | File | `/debian/patches/load_ppp_generic_if_needed` | High
|
||||
15 | File | `/debug/pprof` | Medium
|
||||
16 | File | `/etc/hosts` | Medium
|
||||
17 | File | `/forum/away.php` | High
|
||||
18 | File | `/goform/setmac` | High
|
||||
19 | File | `/goform/wizard_end` | High
|
||||
20 | File | `/hrm/employeeadd.php` | High
|
||||
21 | File | `/index.php` | Medium
|
||||
22 | File | `/items/view_item.php` | High
|
||||
23 | File | `/manage-apartment.php` | High
|
||||
|
@ -143,15 +143,16 @@ ID | Type | Indicator | Confidence
|
|||
44 | File | `/user/update_booking.php` | High
|
||||
45 | File | `/vendor/views/add_product.php` | High
|
||||
46 | File | `/wabt/bin/poc.wasm` | High
|
||||
47 | File | `/WEB-INF/web.xml` | High
|
||||
48 | File | `/WebInterface/UserManager/` | High
|
||||
49 | File | `/Wedding-Management-PHP/admin/photos_add.php` | High
|
||||
50 | File | `/wordpress/wp-admin/options-general.php` | High
|
||||
51 | File | `/wp-content/plugins/woocommerce/templates/emails/plain/` | High
|
||||
52 | File | `ActivityRecord.java` | High
|
||||
53 | ... | ... | ...
|
||||
47 | File | `/WebInterface/UserManager/` | High
|
||||
48 | File | `/Wedding-Management-PHP/admin/photos_add.php` | High
|
||||
49 | File | `/wordpress/wp-admin/options-general.php` | High
|
||||
50 | File | `/wp-content/plugins/woocommerce/templates/emails/plain/` | High
|
||||
51 | File | `ActivityRecord.java` | High
|
||||
52 | File | `adclick.php` | Medium
|
||||
53 | File | `addtocart.asp` | High
|
||||
54 | ... | ... | ...
|
||||
|
||||
There are 460 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 467 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -124,36 +124,35 @@ ID | Type | Indicator | Confidence
|
|||
10 | File | `/api/` | Low
|
||||
11 | File | `/appConfig/userDB.json` | High
|
||||
12 | File | `/authUserAction!edit.action` | High
|
||||
13 | File | `/bd_genie_create_account.cgi` | High
|
||||
14 | File | `/bin/httpd` | Medium
|
||||
15 | File | `/c/macho_reader.c` | High
|
||||
16 | File | `/cgi-bin/kerbynet` | High
|
||||
17 | File | `/cgi-bin/wapopen` | High
|
||||
18 | File | `/cgi-bin/webproc` | High
|
||||
19 | File | `/claire_blake` | High
|
||||
20 | File | `/classes/Master.php?f=delete_appointment` | High
|
||||
21 | File | `/cmscp/ext/collect/fetch_url.do` | High
|
||||
22 | File | `/coreframe/app/attachment/admin/index.php` | High
|
||||
23 | File | `/debug` | Low
|
||||
24 | File | `/debug/pprof` | Medium
|
||||
25 | File | `/defaultui/player/modern.html` | High
|
||||
26 | File | `/etc/init0.d/S80telnetd.sh` | High
|
||||
27 | File | `/etc/shadow.sample` | High
|
||||
28 | File | `/foms/place-order.php` | High
|
||||
29 | File | `/forum/away.php` | High
|
||||
30 | File | `/goform/SetIpMacBind` | High
|
||||
31 | File | `/goform/setmac` | High
|
||||
32 | File | `/htdocs/utils/Files.php` | High
|
||||
33 | File | `/index.php?route=extension/module/so_filter_shop_by/filter_data` | High
|
||||
34 | File | `/jfinal_cms/system/role/list` | High
|
||||
35 | File | `/librarian/edit_book_details.php` | High
|
||||
36 | File | `/management/api/rcx_management/global_config_query` | High
|
||||
37 | File | `/master/index.php` | High
|
||||
38 | File | `/mkshop/Men/profile.php` | High
|
||||
39 | File | `/modx/manager/` | High
|
||||
40 | ... | ... | ...
|
||||
13 | File | `/balance/service/list` | High
|
||||
14 | File | `/bd_genie_create_account.cgi` | High
|
||||
15 | File | `/bin/httpd` | Medium
|
||||
16 | File | `/c/macho_reader.c` | High
|
||||
17 | File | `/cgi-bin/kerbynet` | High
|
||||
18 | File | `/cgi-bin/wapopen` | High
|
||||
19 | File | `/cgi-bin/webproc` | High
|
||||
20 | File | `/claire_blake` | High
|
||||
21 | File | `/classes/Master.php?f=delete_appointment` | High
|
||||
22 | File | `/cmscp/ext/collect/fetch_url.do` | High
|
||||
23 | File | `/coreframe/app/attachment/admin/index.php` | High
|
||||
24 | File | `/debug` | Low
|
||||
25 | File | `/debug/pprof` | Medium
|
||||
26 | File | `/defaultui/player/modern.html` | High
|
||||
27 | File | `/etc/init0.d/S80telnetd.sh` | High
|
||||
28 | File | `/etc/shadow.sample` | High
|
||||
29 | File | `/foms/place-order.php` | High
|
||||
30 | File | `/forum/away.php` | High
|
||||
31 | File | `/goform/SetIpMacBind` | High
|
||||
32 | File | `/goform/setmac` | High
|
||||
33 | File | `/htdocs/utils/Files.php` | High
|
||||
34 | File | `/index.php?route=extension/module/so_filter_shop_by/filter_data` | High
|
||||
35 | File | `/jfinal_cms/system/role/list` | High
|
||||
36 | File | `/librarian/edit_book_details.php` | High
|
||||
37 | File | `/management/api/rcx_management/global_config_query` | High
|
||||
38 | File | `/master/index.php` | High
|
||||
39 | ... | ... | ...
|
||||
|
||||
There are 342 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 339 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -178,32 +178,33 @@ ID | Type | Indicator | Confidence
|
|||
6 | File | `/admin/subnets/ripe-query.php` | High
|
||||
7 | File | `/admin/transactions/update_status.php` | High
|
||||
8 | File | `/api/v1/attack/token` | High
|
||||
9 | File | `/bin/httpd` | Medium
|
||||
10 | File | `/cgi-bin/cstecgi.cgi` | High
|
||||
11 | File | `/cgi-bin/luci` | High
|
||||
12 | File | `/college_website/index.php?` | High
|
||||
13 | File | `/common/info.cgi` | High
|
||||
14 | File | `/context/%2e/WEB-INF/web.xml` | High
|
||||
15 | File | `/debug/pprof` | Medium
|
||||
9 | File | `/cgi-bin/cstecgi.cgi` | High
|
||||
10 | File | `/cgi-bin/luci` | High
|
||||
11 | File | `/college_website/index.php?` | High
|
||||
12 | File | `/common/info.cgi` | High
|
||||
13 | File | `/context/%2e/WEB-INF/web.xml` | High
|
||||
14 | File | `/debug/pprof` | Medium
|
||||
15 | File | `/Default/Bd` | Medium
|
||||
16 | File | `/DesignTools/CssEditor.aspx` | High
|
||||
17 | File | `/dev/mmz_userdev` | High
|
||||
18 | File | `/dev/shm` | Medium
|
||||
19 | File | `/ebics-server/ebics.aspx` | High
|
||||
20 | File | `/egroupware/index.php` | High
|
||||
21 | File | `/etc/openshift/server_priv.pem` | High
|
||||
22 | File | `/etc/tomcat8/Catalina/attack` | High
|
||||
23 | File | `/export` | Low
|
||||
24 | File | `/filemanager/php/connector.php` | High
|
||||
25 | File | `/garage/php_action/createBrand.php` | High
|
||||
26 | File | `/goform/setmac` | High
|
||||
27 | File | `/goform/wizard_end` | High
|
||||
28 | File | `/hospital/hms/admin/patient-search.php` | High
|
||||
29 | File | `/hrm/index.php?msg` | High
|
||||
30 | File | `/hrm/state.php` | High
|
||||
31 | File | `/images/background/1.php` | High
|
||||
32 | ... | ... | ...
|
||||
22 | File | `/etc/passwd` | Medium
|
||||
23 | File | `/etc/tomcat8/Catalina/attack` | High
|
||||
24 | File | `/export` | Low
|
||||
25 | File | `/face-recognition-php/facepay-master/camera.php` | High
|
||||
26 | File | `/filemanager/php/connector.php` | High
|
||||
27 | File | `/garage/php_action/createBrand.php` | High
|
||||
28 | File | `/goform/wizard_end` | High
|
||||
29 | File | `/hospital/hms/admin/patient-search.php` | High
|
||||
30 | File | `/hrm/employeeview.php` | High
|
||||
31 | File | `/hrm/index.php?msg` | High
|
||||
32 | File | `/hrm/state.php` | High
|
||||
33 | ... | ... | ...
|
||||
|
||||
There are 272 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 279 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -72,20 +72,22 @@ ID | Type | Indicator | Confidence
|
|||
15 | File | `/api/v2/cli/commands` | High
|
||||
16 | File | `/api/v2/open/rowsInfo` | High
|
||||
17 | File | `/asms/admin/?page=user/manage_user` | High
|
||||
18 | File | `/card/in-card.php` | High
|
||||
19 | File | `/classes/Master.php?f=delete_student` | High
|
||||
20 | File | `/connectors/index.php` | High
|
||||
21 | File | `/csms/admin/?page=system_info` | High
|
||||
22 | File | `/etc/init0.d/S80telnetd.sh` | High
|
||||
23 | File | `/etc/srapi/config/system.conf` | High
|
||||
24 | File | `/framework/core/models/expConfig.php` | High
|
||||
25 | File | `/framework/modules/core/controllers/expHTMLEditorController.php` | High
|
||||
26 | File | `/fw.login.php` | High
|
||||
18 | File | `/blog/comment` | High
|
||||
19 | File | `/card/in-card.php` | High
|
||||
20 | File | `/classes/Master.php?f=delete_student` | High
|
||||
21 | File | `/connectors/index.php` | High
|
||||
22 | File | `/csms/admin/?page=system_info` | High
|
||||
23 | File | `/etc/init0.d/S80telnetd.sh` | High
|
||||
24 | File | `/etc/srapi/config/system.conf` | High
|
||||
25 | File | `/framework/core/models/expConfig.php` | High
|
||||
26 | File | `/framework/modules/core/controllers/expHTMLEditorController.php` | High
|
||||
27 | File | `/garage/php_action/createBrand.php` | High
|
||||
28 | File | `/goform/form2WizardStep54` | High
|
||||
29 | ... | ... | ...
|
||||
28 | File | `/goform/addressNat` | High
|
||||
29 | File | `/goform/AdvSetWrlsafeset` | High
|
||||
30 | File | `/goform/editFileName` | High
|
||||
31 | ... | ... | ...
|
||||
|
||||
There are 246 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 260 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -9,11 +9,11 @@ _Live data_ and more _analysis capabilities_ are available at [https://vuldb.com
|
|||
These _countries_ are directly (e.g. origin of attacks) or indirectly (e.g. access by proxy) associated with Kraken:
|
||||
|
||||
* [US](https://vuldb.com/?country.us)
|
||||
* [TR](https://vuldb.com/?country.tr)
|
||||
* [FR](https://vuldb.com/?country.fr)
|
||||
* [RU](https://vuldb.com/?country.ru)
|
||||
* [DE](https://vuldb.com/?country.de)
|
||||
* ...
|
||||
|
||||
There are 3 more country items available. Please use our online service to access the data.
|
||||
There are 5 more country items available. Please use our online service to access the data.
|
||||
|
||||
## IOC - Indicator of Compromise
|
||||
|
||||
|
@ -34,7 +34,12 @@ _Tactics, techniques, and procedures_ (TTP) summarize the suspected MITRE ATT&CK
|
|||
|
||||
ID | Technique | Weakness | Description | Confidence
|
||||
-- | --------- | -------- | ----------- | ----------
|
||||
1 | T1059.007 | CWE-79 | Cross Site Scripting | High
|
||||
1 | T1006 | CWE-22 | Pathname Traversal | High
|
||||
2 | T1059.007 | CWE-79 | Cross Site Scripting | High
|
||||
3 | T1068 | CWE-264, CWE-269 | Execution with Unnecessary Privileges | High
|
||||
4 | ... | ... | ... | ...
|
||||
|
||||
There are 3 more TTP items available. Please use our online service to access the data.
|
||||
|
||||
## IOA - Indicator of Attack
|
||||
|
||||
|
@ -47,7 +52,7 @@ ID | Type | Indicator | Confidence
|
|||
3 | File | `data/gbconfiguration.dat` | High
|
||||
4 | ... | ... | ...
|
||||
|
||||
There are 10 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 12 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -26,7 +26,7 @@ These _countries_ are directly (e.g. origin of attacks) or indirectly (e.g. acce
|
|||
* [US](https://vuldb.com/?country.us)
|
||||
* ...
|
||||
|
||||
There are 8 more country items available. Please use our online service to access the data.
|
||||
There are 6 more country items available. Please use our online service to access the data.
|
||||
|
||||
## IOC - Indicator of Compromise
|
||||
|
||||
|
@ -272,10 +272,10 @@ ID | Technique | Weakness | Description | Confidence
|
|||
1 | T1006 | CWE-21, CWE-22, CWE-23 | Pathname Traversal | High
|
||||
2 | T1040 | CWE-319 | Authentication Bypass by Capture-replay | High
|
||||
3 | T1055 | CWE-74 | Injection | High
|
||||
4 | T1059 | CWE-88, CWE-94, CWE-1321 | Cross Site Scripting | High
|
||||
4 | T1059 | CWE-88, CWE-94 | Cross Site Scripting | High
|
||||
5 | ... | ... | ... | ...
|
||||
|
||||
There are 17 more TTP items available. Please use our online service to access the data.
|
||||
There are 18 more TTP items available. Please use our online service to access the data.
|
||||
|
||||
## IOA - Indicator of Attack
|
||||
|
||||
|
@ -286,7 +286,7 @@ ID | Type | Indicator | Confidence
|
|||
1 | File | `/admin.php/Admin/adminadd.html` | High
|
||||
2 | File | `/admin/controller/JobLogController.java` | High
|
||||
3 | File | `/Admin/dashboard.php` | High
|
||||
4 | File | `/admin/problem_judge.php` | High
|
||||
4 | File | `/api/audits` | Medium
|
||||
5 | File | `/api/user/password/sent-reset-email` | High
|
||||
6 | File | `/api/v2/cli/commands` | High
|
||||
7 | File | `/asms/admin/mechanics/manage_mechanic.php` | High
|
||||
|
@ -299,17 +299,20 @@ ID | Type | Indicator | Confidence
|
|||
14 | File | `/diag_tracert_admin.asp` | High
|
||||
15 | File | `/face-recognition-php/facepay-master/camera.php` | High
|
||||
16 | File | `/FormLogin` | Medium
|
||||
17 | File | `/goform/wizard_end` | High
|
||||
18 | File | `/gpac/src/bifs/unquantize.c` | High
|
||||
19 | File | `/hrm/controller/employee.php` | High
|
||||
20 | File | `/index/user/user_edit.html` | High
|
||||
21 | File | `/login.php` | Medium
|
||||
22 | File | `/Member/memberedit.html` | High
|
||||
23 | File | `/pages/processlogin.php` | High
|
||||
24 | File | `/product/savenewproduct.php?flag=1` | High
|
||||
25 | ... | ... | ...
|
||||
17 | File | `/forum/away.php` | High
|
||||
18 | File | `/goform/wizard_end` | High
|
||||
19 | File | `/gpac/src/bifs/unquantize.c` | High
|
||||
20 | File | `/hrm/controller/employee.php` | High
|
||||
21 | File | `/index/user/user_edit.html` | High
|
||||
22 | File | `/leave_system/admin/?page=maintenance/department` | High
|
||||
23 | File | `/login` | Low
|
||||
24 | File | `/login.php` | Medium
|
||||
25 | File | `/Member/memberedit.html` | High
|
||||
26 | File | `/pages/processlogin.php` | High
|
||||
27 | File | `/product/savenewproduct.php?flag=1` | High
|
||||
28 | ... | ... | ...
|
||||
|
||||
There are 214 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 233 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -13,7 +13,7 @@ These _countries_ are directly (e.g. origin of attacks) or indirectly (e.g. acce
|
|||
* [VN](https://vuldb.com/?country.vn)
|
||||
* ...
|
||||
|
||||
There are 22 more country items available. Please use our online service to access the data.
|
||||
There are 20 more country items available. Please use our online service to access the data.
|
||||
|
||||
## IOC - Indicator of Compromise
|
||||
|
||||
|
@ -97,7 +97,7 @@ ID | Technique | Weakness | Description | Confidence
|
|||
5 | T1059.007 | CWE-79, CWE-80 | Cross Site Scripting | High
|
||||
6 | ... | ... | ... | ...
|
||||
|
||||
There are 20 more TTP items available. Please use our online service to access the data.
|
||||
There are 19 more TTP items available. Please use our online service to access the data.
|
||||
|
||||
## IOA - Indicator of Attack
|
||||
|
||||
|
@ -108,43 +108,45 @@ ID | Type | Indicator | Confidence
|
|||
1 | File | `/about.php` | Medium
|
||||
2 | File | `/adfs/ls` | Medium
|
||||
3 | File | `/Admin/add-student.php` | High
|
||||
4 | File | `/admin/users_add.php` | High
|
||||
5 | File | `/administration/settings_registration.php` | High
|
||||
6 | File | `/ad_js.php` | Medium
|
||||
7 | File | `/app/options.py` | High
|
||||
4 | File | `/admin/submit-articles` | High
|
||||
5 | File | `/admin/users_add.php` | High
|
||||
6 | File | `/administration/settings_registration.php` | High
|
||||
7 | File | `/ad_js.php` | Medium
|
||||
8 | File | `/appConfig/userDB.json` | High
|
||||
9 | File | `/bd_genie_create_account.cgi` | High
|
||||
10 | File | `/c/macho_reader.c` | High
|
||||
11 | File | `/catcompany.php` | High
|
||||
12 | File | `/cgi-bin/luci/api/wireless` | High
|
||||
13 | File | `/claire_blake` | High
|
||||
14 | File | `/context/%2e/WEB-INF/web.xml` | High
|
||||
15 | File | `/dashboard/reports/logs/view` | High
|
||||
16 | File | `/debian/patches/load_ppp_generic_if_needed` | High
|
||||
17 | File | `/debug/pprof` | Medium
|
||||
18 | File | `/defaultui/player/modern.html` | High
|
||||
19 | File | `/ebics-server/ebics.aspx` | High
|
||||
20 | File | `/egroupware/index.php` | High
|
||||
21 | File | `/etc/hosts` | Medium
|
||||
22 | File | `/etc/init0.d/S80telnetd.sh` | High
|
||||
23 | File | `/etc/shadow.sample` | High
|
||||
24 | File | `/foms/place-order.php` | High
|
||||
25 | File | `/forum/away.php` | High
|
||||
26 | File | `/ghost/preview` | High
|
||||
9 | File | `/authUserAction!edit.action` | High
|
||||
10 | File | `/bd_genie_create_account.cgi` | High
|
||||
11 | File | `/c/macho_reader.c` | High
|
||||
12 | File | `/catcompany.php` | High
|
||||
13 | File | `/cgi-bin/luci/api/wireless` | High
|
||||
14 | File | `/claire_blake` | High
|
||||
15 | File | `/context/%2e/WEB-INF/web.xml` | High
|
||||
16 | File | `/dashboard/reports/logs/view` | High
|
||||
17 | File | `/debian/patches/load_ppp_generic_if_needed` | High
|
||||
18 | File | `/debug/pprof` | Medium
|
||||
19 | File | `/Default/Bd` | Medium
|
||||
20 | File | `/defaultui/player/modern.html` | High
|
||||
21 | File | `/ebics-server/ebics.aspx` | High
|
||||
22 | File | `/egroupware/index.php` | High
|
||||
23 | File | `/etc/init0.d/S80telnetd.sh` | High
|
||||
24 | File | `/etc/shadow.sample` | High
|
||||
25 | File | `/foms/place-order.php` | High
|
||||
26 | File | `/forum/away.php` | High
|
||||
27 | File | `/goform/SetIpMacBind` | High
|
||||
28 | File | `/goform/setmac` | High
|
||||
29 | File | `/goform/wizard_end` | High
|
||||
30 | File | `/htdocs/utils/Files.php` | High
|
||||
31 | File | `/index.php` | Medium
|
||||
32 | File | `/jfinal_cms/system/role/list` | High
|
||||
33 | File | `/librarian/edit_book_details.php` | High
|
||||
34 | File | `/Main_Login.asp?flag=1&productname=RT-AC88U&url=/downloadmaster/task.asp` | High
|
||||
35 | File | `/manage-apartment.php` | High
|
||||
36 | File | `/master/index.php` | High
|
||||
37 | File | `/members/view_member.php` | High
|
||||
38 | ... | ... | ...
|
||||
30 | File | `/hrm/employeeview.php` | High
|
||||
31 | File | `/htdocs/utils/Files.php` | High
|
||||
32 | File | `/index.php` | Medium
|
||||
33 | File | `/jfinal_cms/system/role/list` | High
|
||||
34 | File | `/librarian/edit_book_details.php` | High
|
||||
35 | File | `/Main_Login.asp?flag=1&productname=RT-AC88U&url=/downloadmaster/task.asp` | High
|
||||
36 | File | `/manage-apartment.php` | High
|
||||
37 | File | `/master/index.php` | High
|
||||
38 | File | `/members/view_member.php` | High
|
||||
39 | File | `/mkshop/Men/profile.php` | High
|
||||
40 | ... | ... | ...
|
||||
|
||||
There are 324 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 340 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -10,7 +10,7 @@ These _countries_ are directly (e.g. origin of attacks) or indirectly (e.g. acce
|
|||
|
||||
* [RU](https://vuldb.com/?country.ru)
|
||||
* [CN](https://vuldb.com/?country.cn)
|
||||
* [PT](https://vuldb.com/?country.pt)
|
||||
* [PL](https://vuldb.com/?country.pl)
|
||||
* ...
|
||||
|
||||
There are 13 more country items available. Please use our online service to access the data.
|
||||
|
@ -54,8 +54,7 @@ ID | Technique | Weakness | Description | Confidence
|
|||
2 | T1040 | CWE-319 | Authentication Bypass by Capture-replay | High
|
||||
3 | T1055 | CWE-74 | Injection | High
|
||||
4 | T1059 | CWE-94, CWE-1321 | Cross Site Scripting | High
|
||||
5 | T1059.007 | CWE-79, CWE-80 | Cross Site Scripting | High
|
||||
6 | ... | ... | ... | ...
|
||||
5 | ... | ... | ... | ...
|
||||
|
||||
There are 18 more TTP items available. Please use our online service to access the data.
|
||||
|
||||
|
@ -100,7 +99,7 @@ ID | Type | Indicator | Confidence
|
|||
33 | File | `/myAccount` | Medium
|
||||
34 | ... | ... | ...
|
||||
|
||||
There are 290 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 291 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -45,7 +45,7 @@ ID | Technique | Weakness | Description | Confidence
|
|||
3 | T1059.007 | CWE-79 | Cross Site Scripting | High
|
||||
4 | ... | ... | ... | ...
|
||||
|
||||
There are 7 more TTP items available. Please use our online service to access the data.
|
||||
There are 8 more TTP items available. Please use our online service to access the data.
|
||||
|
||||
## IOA - Indicator of Attack
|
||||
|
||||
|
@ -59,7 +59,7 @@ ID | Type | Indicator | Confidence
|
|||
4 | File | `/jsoa/hntdCustomDesktopActionContent` | High
|
||||
5 | ... | ... | ...
|
||||
|
||||
There are 28 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 29 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -21,7 +21,7 @@ These _countries_ are directly (e.g. origin of attacks) or indirectly (e.g. acce
|
|||
* [US](https://vuldb.com/?country.us)
|
||||
* ...
|
||||
|
||||
There are 2 more country items available. Please use our online service to access the data.
|
||||
There are 4 more country items available. Please use our online service to access the data.
|
||||
|
||||
## IOC - Indicator of Compromise
|
||||
|
||||
|
@ -213,7 +213,7 @@ _Tactics, techniques, and procedures_ (TTP) summarize the suspected MITRE ATT&CK
|
|||
|
||||
ID | Technique | Weakness | Description | Confidence
|
||||
-- | --------- | -------- | ----------- | ----------
|
||||
1 | T1006 | CWE-21, CWE-22, CWE-23, CWE-40 | Pathname Traversal | High
|
||||
1 | T1006 | CWE-21, CWE-22, CWE-23 | Pathname Traversal | High
|
||||
2 | T1040 | CWE-294, CWE-319 | Authentication Bypass by Capture-replay | High
|
||||
3 | T1055 | CWE-74 | Injection | High
|
||||
4 | T1059 | CWE-88, CWE-94 | Cross Site Scripting | High
|
||||
|
@ -228,42 +228,43 @@ These _indicators of attack_ (IOA) list the potential fragments used for technic
|
|||
|
||||
ID | Type | Indicator | Confidence
|
||||
-- | ---- | --------- | ----------
|
||||
1 | File | `.python-version` | High
|
||||
2 | File | `/.ssh/authorized_keys` | High
|
||||
3 | File | `/admin.php/Admin/adminadd.html` | High
|
||||
1 | File | `.FBCIndex` | Medium
|
||||
2 | File | `.python-version` | High
|
||||
3 | File | `/.ssh/authorized_keys` | High
|
||||
4 | File | `/admin/edit_members.php` | High
|
||||
5 | File | `/admin/fst_upload.inc.php` | High
|
||||
6 | File | `/admin/settings/save.php` | High
|
||||
7 | File | `/admin/submit-articles` | High
|
||||
8 | File | `/admin/users/index.php` | High
|
||||
9 | File | `/api/audits` | Medium
|
||||
10 | File | `/api/sys_username_passwd.cmd` | High
|
||||
11 | File | `/asms/admin/products/manage_product.php` | High
|
||||
12 | File | `/asms/products/view_product.php` | High
|
||||
13 | File | `/bsms_ci/index.php` | High
|
||||
14 | File | `/bsms_ci/index.php/book` | High
|
||||
15 | File | `/bsms_ci/index.php/user/edit_user/` | High
|
||||
16 | File | `/calendar/viewcalendar.php` | High
|
||||
17 | File | `/carbon/ndatasource/validateconnection/ajaxprocessor.jsp` | High
|
||||
18 | File | `/cgi-bin/webproc` | High
|
||||
19 | File | `/cgi-bin/wlogin.cgi` | High
|
||||
20 | File | `/clients/listclients.php` | High
|
||||
21 | File | `/Content/Template/root/reverse-shell.aspx` | High
|
||||
22 | File | `/Default/Bd` | Medium
|
||||
23 | File | `/device/acceptBind` | High
|
||||
24 | File | `/event/admin/?page=user/list` | High
|
||||
25 | File | `/face-recognition-php/facepay-master/camera.php` | High
|
||||
26 | File | `/forum/away.php` | High
|
||||
27 | File | `/general/search.php?searchtype=simple` | High
|
||||
28 | File | `/goform/setSysPwd` | High
|
||||
29 | File | `/gpac/src/bifs/unquantize.c` | High
|
||||
30 | File | `/hrm/controller/employee.php` | High
|
||||
31 | File | `/hrm/employeeadd.php` | High
|
||||
32 | File | `/hrm/employeeview.php` | High
|
||||
33 | File | `/ims/login.php` | High
|
||||
34 | ... | ... | ...
|
||||
6 | File | `/admin/submit-articles` | High
|
||||
7 | File | `/api/audits` | Medium
|
||||
8 | File | `/api/sys_username_passwd.cmd` | High
|
||||
9 | File | `/balance/service/list` | High
|
||||
10 | File | `/blog/comment` | High
|
||||
11 | File | `/bsms_ci/index.php` | High
|
||||
12 | File | `/bsms_ci/index.php/user/edit_user/` | High
|
||||
13 | File | `/calendar/viewcalendar.php` | High
|
||||
14 | File | `/carbon/ndatasource/validateconnection/ajaxprocessor.jsp` | High
|
||||
15 | File | `/cgi-bin/webproc` | High
|
||||
16 | File | `/cgi-bin/wlogin.cgi` | High
|
||||
17 | File | `/clients/listclients.php` | High
|
||||
18 | File | `/Content/Template/root/reverse-shell.aspx` | High
|
||||
19 | File | `/Default/Bd` | Medium
|
||||
20 | File | `/device/acceptBind` | High
|
||||
21 | File | `/event/admin/?page=user/list` | High
|
||||
22 | File | `/face-recognition-php/facepay-master/camera.php` | High
|
||||
23 | File | `/forum/away.php` | High
|
||||
24 | File | `/general/search.php?searchtype=simple` | High
|
||||
25 | File | `/goform/addressNat` | High
|
||||
26 | File | `/goform/CertListInfo` | High
|
||||
27 | File | `/goform/IPSECsave` | High
|
||||
28 | File | `/goform/L7Im` | Medium
|
||||
29 | File | `/goform/NatStaticSetting` | High
|
||||
30 | File | `/goform/qossetting` | High
|
||||
31 | File | `/goform/SafeClientFilter` | High
|
||||
32 | File | `/goform/SafeMacFilter` | High
|
||||
33 | File | `/goform/SafeUrlFilter` | High
|
||||
34 | File | `/goform/setSysPwd` | High
|
||||
35 | ... | ... | ...
|
||||
|
||||
There are 294 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 299 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -8,12 +8,12 @@ _Live data_ and more _analysis capabilities_ are available at [https://vuldb.com
|
|||
|
||||
These _countries_ are directly (e.g. origin of attacks) or indirectly (e.g. access by proxy) associated with North America Unknown:
|
||||
|
||||
* [US](https://vuldb.com/?country.us)
|
||||
* [JP](https://vuldb.com/?country.jp)
|
||||
* [SH](https://vuldb.com/?country.sh)
|
||||
* [US](https://vuldb.com/?country.us)
|
||||
* [CN](https://vuldb.com/?country.cn)
|
||||
* ...
|
||||
|
||||
There are 22 more country items available. Please use our online service to access the data.
|
||||
There are 25 more country items available. Please use our online service to access the data.
|
||||
|
||||
## IOC - Indicator of Compromise
|
||||
|
||||
|
@ -6529,7 +6529,7 @@ ID | Technique | Weakness | Description | Confidence
|
|||
5 | T1059.007 | CWE-79, CWE-80 | Cross Site Scripting | High
|
||||
6 | ... | ... | ... | ...
|
||||
|
||||
There are 21 more TTP items available. Please use our online service to access the data.
|
||||
There are 20 more TTP items available. Please use our online service to access the data.
|
||||
|
||||
## IOA - Indicator of Attack
|
||||
|
||||
|
@ -6537,41 +6537,49 @@ These _indicators of attack_ (IOA) list the potential fragments used for technic
|
|||
|
||||
ID | Type | Indicator | Confidence
|
||||
-- | ---- | --------- | ----------
|
||||
1 | File | `/admin.php/Admin/adminadd.html` | High
|
||||
2 | File | `/admin/edit.php` | High
|
||||
3 | File | `/admin/settings/save.php` | High
|
||||
4 | File | `/admin/sign/out` | High
|
||||
5 | File | `/admin/subnets/ripe-query.php` | High
|
||||
6 | File | `/api/v1/attack/falco` | High
|
||||
7 | File | `/api/v1/attack/token` | High
|
||||
8 | File | `/api/v2/open/tablesInfo` | High
|
||||
9 | File | `/balance/service/list` | High
|
||||
10 | File | `/debug/pprof` | Medium
|
||||
11 | File | `/depotHead/list` | High
|
||||
12 | File | `/forum/away.php` | High
|
||||
13 | File | `/goform/setSysAdm` | High
|
||||
14 | File | `/HNAP1` | Low
|
||||
15 | File | `/index.php` | Medium
|
||||
16 | File | `/index.php/purchase_order/browse_data` | High
|
||||
17 | File | `/lilac/main.php` | High
|
||||
18 | File | `/module/admin_bp/add_application.php` | High
|
||||
19 | File | `/module/report_event/index.php` | High
|
||||
20 | File | `/opt/zimbra/jetty/webapps/zimbra/public` | High
|
||||
21 | File | `/out.php` | Medium
|
||||
22 | File | `/php-sms/classes/Master.php?f=save_quote` | High
|
||||
23 | File | `/plugin/getList` | High
|
||||
24 | File | `/project/PROJECTNAME/reports/` | High
|
||||
25 | File | `/proxy` | Low
|
||||
26 | File | `/spip.php` | Medium
|
||||
27 | File | `/sys/duplicate/check` | High
|
||||
28 | File | `/tmp` | Low
|
||||
29 | File | `/usr/bin/pkexec` | High
|
||||
30 | File | `/usr/sbin/httpd` | High
|
||||
31 | File | `/var/log/nginx` | High
|
||||
32 | File | `/wp-content/plugins/updraftplus/admin.php` | High
|
||||
33 | ... | ... | ...
|
||||
1 | File | `.../gogo/` | Medium
|
||||
2 | File | `/admin.php/Admin/adminadd.html` | High
|
||||
3 | File | `/admin/controller/JobLogController.java` | High
|
||||
4 | File | `/Admin/dashboard.php` | High
|
||||
5 | File | `/admin/fst_upload.inc.php` | High
|
||||
6 | File | `/admin/settings/save.php` | High
|
||||
7 | File | `/admin/submit-articles` | High
|
||||
8 | File | `/admin/subnets/ripe-query.php` | High
|
||||
9 | File | `/bsms_ci/index.php` | High
|
||||
10 | File | `/bsms_ci/index.php/user/edit_user/` | High
|
||||
11 | File | `/cgi-bin/supervisor/PwdGrp.cgi` | High
|
||||
12 | File | `/confirm` | Medium
|
||||
13 | File | `/debug/pprof` | Medium
|
||||
14 | File | `/Default/Bd` | Medium
|
||||
15 | File | `/etc/passwd` | Medium
|
||||
16 | File | `/event/admin/?page=user/list` | High
|
||||
17 | File | `/face-recognition-php/facepay-master/camera.php` | High
|
||||
18 | File | `/forum/away.php` | High
|
||||
19 | File | `/goform/setDiagnoseInfo` | High
|
||||
20 | File | `/goform/setSnmpInfo` | High
|
||||
21 | File | `/goform/setSysAdm` | High
|
||||
22 | File | `/goform/setSysPwd` | High
|
||||
23 | File | `/goform/setUplinkInfo` | High
|
||||
24 | File | `/gpac/src/bifs/unquantize.c` | High
|
||||
25 | File | `/hrm/controller/employee.php` | High
|
||||
26 | File | `/hrm/employeeadd.php` | High
|
||||
27 | File | `/hrm/employeeview.php` | High
|
||||
28 | File | `/includes/login.php` | High
|
||||
29 | File | `/index.php` | Medium
|
||||
30 | File | `/index.php?module=entities/fields&entities_id=24` | High
|
||||
31 | File | `/modules/caddyhttp/rewrite/rewrite.go` | High
|
||||
32 | File | `/out.php` | Medium
|
||||
33 | File | `/pages/processlogin.php` | High
|
||||
34 | File | `/php-sms/admin/quotes/manage_remark.php` | High
|
||||
35 | File | `/plugin/getList` | High
|
||||
36 | File | `/proxy` | Low
|
||||
37 | File | `/Redcock-Farm/farm/category.php` | High
|
||||
38 | File | `/spip.php` | Medium
|
||||
39 | File | `/sys/duplicate/check` | High
|
||||
40 | File | `/template/edit` | High
|
||||
41 | ... | ... | ...
|
||||
|
||||
There are 282 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 352 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -10,10 +10,10 @@ These _countries_ are directly (e.g. origin of attacks) or indirectly (e.g. acce
|
|||
|
||||
* [US](https://vuldb.com/?country.us)
|
||||
* [DE](https://vuldb.com/?country.de)
|
||||
* [CN](https://vuldb.com/?country.cn)
|
||||
* [PT](https://vuldb.com/?country.pt)
|
||||
* ...
|
||||
|
||||
There are 2 more country items available. Please use our online service to access the data.
|
||||
There are 3 more country items available. Please use our online service to access the data.
|
||||
|
||||
## IOC - Indicator of Compromise
|
||||
|
||||
|
@ -58,41 +58,41 @@ ID | Type | Indicator | Confidence
|
|||
6 | File | `/Admin/dashboard.php` | High
|
||||
7 | File | `/admin/pages/sections_save.php` | High
|
||||
8 | File | `/admin/settings.php` | High
|
||||
9 | File | `/admin/update_currency.php` | High
|
||||
10 | File | `/admin/up_booking.php` | High
|
||||
11 | File | `/api/geojson` | Medium
|
||||
12 | File | `/api/v1/attack` | High
|
||||
13 | File | `/api/v1/attack/token` | High
|
||||
14 | File | `/apiv1/` | Low
|
||||
15 | File | `/asms/admin/?page=transactions/manage_transaction` | High
|
||||
16 | File | `/authUserAction!edit.action` | High
|
||||
17 | File | `/bsms_ci/index.php/user/edit_user/` | High
|
||||
18 | File | `/buspassms/download-pass.php` | High
|
||||
19 | File | `/calendar/viewcalendar.php` | High
|
||||
20 | File | `/classes/Users.php?f=delete_client` | High
|
||||
21 | File | `/clearance/clearance.php` | High
|
||||
22 | File | `/clients/listclients.php` | High
|
||||
23 | File | `/College/admin/teacher.php` | High
|
||||
24 | File | `/dede/file_manage_control.php` | High
|
||||
25 | File | `/DesignTools/CssEditor.aspx` | High
|
||||
26 | File | `/dev/shm` | Medium
|
||||
27 | File | `/device/` | Medium
|
||||
28 | File | `/diagnostic/edittest.php` | High
|
||||
29 | File | `/file/upload/1` | High
|
||||
30 | File | `/forums/editforum.php` | High
|
||||
31 | File | `/general/search.php?searchtype=simple` | High
|
||||
32 | File | `/gfxpoly/stroke.c` | High
|
||||
9 | File | `/admin/up_booking.php` | High
|
||||
10 | File | `/api/geojson` | Medium
|
||||
11 | File | `/api/v1/attack` | High
|
||||
12 | File | `/api/v1/attack/token` | High
|
||||
13 | File | `/apiv1/` | Low
|
||||
14 | File | `/asms/admin/?page=transactions/manage_transaction` | High
|
||||
15 | File | `/authUserAction!edit.action` | High
|
||||
16 | File | `/bsms_ci/index.php/user/edit_user/` | High
|
||||
17 | File | `/buspassms/download-pass.php` | High
|
||||
18 | File | `/calendar/viewcalendar.php` | High
|
||||
19 | File | `/classes/Users.php?f=delete_client` | High
|
||||
20 | File | `/clearance/clearance.php` | High
|
||||
21 | File | `/clients/listclients.php` | High
|
||||
22 | File | `/College/admin/teacher.php` | High
|
||||
23 | File | `/dede/file_manage_control.php` | High
|
||||
24 | File | `/DesignTools/CssEditor.aspx` | High
|
||||
25 | File | `/dev/shm` | Medium
|
||||
26 | File | `/device/` | Medium
|
||||
27 | File | `/diagnostic/edittest.php` | High
|
||||
28 | File | `/etc/puppetlabs/puppetserver/conf.d/ca.conf` | High
|
||||
29 | File | `/event/admin/?page=user/list` | High
|
||||
30 | File | `/file/upload/1` | High
|
||||
31 | File | `/forums/editforum.php` | High
|
||||
32 | File | `/general/search.php?searchtype=simple` | High
|
||||
33 | File | `/goform/AddSysLogRule` | High
|
||||
34 | File | `/goform/setDiagnoseInfo` | High
|
||||
35 | File | `/goform/SetIpMacBind` | High
|
||||
36 | File | `/hrm/controller/employee.php` | High
|
||||
37 | File | `/hrm/employeeadd.php` | High
|
||||
38 | File | `/hrm/employeeview.php` | High
|
||||
39 | File | `/index.php/admins/Fields/get_fields.html` | High
|
||||
40 | File | `/index.php?module=entities/listing_types&entities_id=24` | High
|
||||
34 | File | `/goform/editUserName` | High
|
||||
35 | File | `/goform/setDiagnoseInfo` | High
|
||||
36 | File | `/goform/SetIpMacBind` | High
|
||||
37 | File | `/goform/WifiBasicSet` | High
|
||||
38 | File | `/hrm/controller/employee.php` | High
|
||||
39 | File | `/hrm/employeeadd.php` | High
|
||||
40 | File | `/hrm/employeeview.php` | High
|
||||
41 | ... | ... | ...
|
||||
|
||||
There are 351 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 356 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -39,7 +39,7 @@ ID | Technique | Weakness | Description | Confidence
|
|||
3 | T1059 | CWE-94 | Cross Site Scripting | High
|
||||
4 | ... | ... | ... | ...
|
||||
|
||||
There are 7 more TTP items available. Please use our online service to access the data.
|
||||
There are 9 more TTP items available. Please use our online service to access the data.
|
||||
|
||||
## IOA - Indicator of Attack
|
||||
|
||||
|
@ -55,7 +55,7 @@ ID | Type | Indicator | Confidence
|
|||
6 | File | `2020\Messages\SDNotify.exe` | High
|
||||
7 | ... | ... | ...
|
||||
|
||||
There are 45 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 47 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -82,7 +82,7 @@ ID | Type | Indicator | Confidence
|
|||
29 | File | `/opt/zimbra/jetty/webapps/zimbra/public` | High
|
||||
30 | ... | ... | ...
|
||||
|
||||
There are 253 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 257 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -19,7 +19,7 @@ These _countries_ are directly (e.g. origin of attacks) or indirectly (e.g. acce
|
|||
* [RU](https://vuldb.com/?country.ru)
|
||||
* ...
|
||||
|
||||
There are 2 more country items available. Please use our online service to access the data.
|
||||
There are 3 more country items available. Please use our online service to access the data.
|
||||
|
||||
## IOC - Indicator of Compromise
|
||||
|
||||
|
@ -46,7 +46,7 @@ _Tactics, techniques, and procedures_ (TTP) summarize the suspected MITRE ATT&CK
|
|||
|
||||
ID | Technique | Weakness | Description | Confidence
|
||||
-- | --------- | -------- | ----------- | ----------
|
||||
1 | T1006 | CWE-21, CWE-22, CWE-40 | Pathname Traversal | High
|
||||
1 | T1006 | CWE-21, CWE-22 | Pathname Traversal | High
|
||||
2 | T1040 | CWE-319 | Authentication Bypass by Capture-replay | High
|
||||
3 | T1055 | CWE-74 | Injection | High
|
||||
4 | T1059 | CWE-88, CWE-94 | Cross Site Scripting | High
|
||||
|
@ -61,47 +61,43 @@ These _indicators of attack_ (IOA) list the potential fragments used for technic
|
|||
|
||||
ID | Type | Indicator | Confidence
|
||||
-- | ---- | --------- | ----------
|
||||
1 | File | `/admin.php/Admin/adminadd.html` | High
|
||||
2 | File | `/Admin/add-student.php` | High
|
||||
3 | File | `/Admin/createClass.php` | High
|
||||
4 | File | `/Admin/dashboard.php` | High
|
||||
5 | File | `/admin/edit_members.php` | High
|
||||
6 | File | `/admin/pages/sections_save.php` | High
|
||||
7 | File | `/admin/problem_judge.php` | High
|
||||
8 | File | `/admin/transactions/update_status.php` | High
|
||||
9 | File | `/admin/users/index.php` | High
|
||||
10 | File | `/apiv1/` | Low
|
||||
11 | File | `/asms/admin/products/manage_product.php` | High
|
||||
12 | File | `/asms/products/view_product.php` | High
|
||||
13 | File | `/avms/index.php` | High
|
||||
14 | File | `/bsms_ci/index.php` | High
|
||||
15 | File | `/bsms_ci/index.php/user/edit_user/` | High
|
||||
16 | File | `/calendar/viewcalendar.php` | High
|
||||
17 | File | `/clients/listclients.php` | High
|
||||
18 | File | `/College/admin/teacher.php` | High
|
||||
19 | File | `/dashboard/add-service.php` | High
|
||||
20 | File | `/device/` | Medium
|
||||
21 | File | `/event/admin/?page=user/list` | High
|
||||
22 | File | `/forums/editforum.php` | High
|
||||
23 | File | `/garage/php_action/createBrand.php` | High
|
||||
24 | File | `/general/search.php?searchtype=simple` | High
|
||||
25 | File | `/goform/AddSysLogRule` | High
|
||||
26 | File | `/goform/setDiagnoseInfo` | High
|
||||
27 | File | `/goform/SetIpMacBind` | High
|
||||
28 | File | `/goform/setSnmpInfo` | High
|
||||
29 | File | `/goform/setUplinkInfo` | High
|
||||
30 | File | `/hrm/controller/employee.php` | High
|
||||
31 | File | `/hrm/employeeadd.php` | High
|
||||
32 | File | `/hrm/employeeview.php` | High
|
||||
33 | File | `/ims/login.php` | High
|
||||
34 | File | `/index.php/admins/Fields/get_fields.html` | High
|
||||
35 | File | `/index.php?module=configuration/application` | High
|
||||
36 | File | `/index.php?module=entities/fields&entities_id=24` | High
|
||||
37 | File | `/index.php?module=entities/forms&entities_id=24` | High
|
||||
38 | File | `/index.php?module=entities/listing_types&entities_id=24` | High
|
||||
39 | ... | ... | ...
|
||||
1 | File | `/Admin/add-student.php` | High
|
||||
2 | File | `/admin/edit_members.php` | High
|
||||
3 | File | `/admin/pages/sections_save.php` | High
|
||||
4 | File | `/admin/transactions/update_status.php` | High
|
||||
5 | File | `/admin/users/index.php` | High
|
||||
6 | File | `/apiv1/` | Low
|
||||
7 | File | `/asms/admin/products/manage_product.php` | High
|
||||
8 | File | `/asms/products/view_product.php` | High
|
||||
9 | File | `/back/index.php/user/User/?1` | High
|
||||
10 | File | `/blog/comment` | High
|
||||
11 | File | `/bsms_ci/index.php` | High
|
||||
12 | File | `/bsms_ci/index.php/user/edit_user/` | High
|
||||
13 | File | `/calendar/viewcalendar.php` | High
|
||||
14 | File | `/clients/listclients.php` | High
|
||||
15 | File | `/contacts/listcontacts.php` | High
|
||||
16 | File | `/Default/Bd` | Medium
|
||||
17 | File | `/device/` | Medium
|
||||
18 | File | `/etc/puppetlabs/puppetserver/conf.d/ca.conf` | High
|
||||
19 | File | `/event/admin/?page=user/list` | High
|
||||
20 | File | `/forums/editforum.php` | High
|
||||
21 | File | `/garage/php_action/createBrand.php` | High
|
||||
22 | File | `/general/search.php?searchtype=simple` | High
|
||||
23 | File | `/goform/AddSysLogRule` | High
|
||||
24 | File | `/goform/AdvSetWrlsafeset` | High
|
||||
25 | File | `/goform/editUserName` | High
|
||||
26 | File | `/goform/IPSECsave` | High
|
||||
27 | File | `/goform/L7Im` | Medium
|
||||
28 | File | `/goform/SafeEmailFilter` | High
|
||||
29 | File | `/goform/setDiagnoseInfo` | High
|
||||
30 | File | `/goform/SetIpMacBind` | High
|
||||
31 | File | `/goform/setSnmpInfo` | High
|
||||
32 | File | `/goform/setSysPwd` | High
|
||||
33 | File | `/goform/setUplinkInfo` | High
|
||||
34 | File | `/goform/SysToolReboot` | High
|
||||
35 | ... | ... | ...
|
||||
|
||||
There are 334 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 299 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -8,12 +8,12 @@ _Live data_ and more _analysis capabilities_ are available at [https://vuldb.com
|
|||
|
||||
These _countries_ are directly (e.g. origin of attacks) or indirectly (e.g. access by proxy) associated with Raccoon Stealer:
|
||||
|
||||
* [SH](https://vuldb.com/?country.sh)
|
||||
* [US](https://vuldb.com/?country.us)
|
||||
* [CN](https://vuldb.com/?country.cn)
|
||||
* [ES](https://vuldb.com/?country.es)
|
||||
* [RU](https://vuldb.com/?country.ru)
|
||||
* ...
|
||||
|
||||
There are 3 more country items available. Please use our online service to access the data.
|
||||
There are 7 more country items available. Please use our online service to access the data.
|
||||
|
||||
## IOC - Indicator of Compromise
|
||||
|
||||
|
@ -21,12 +21,30 @@ These _indicators of compromise_ (IOC) indicate associated network resources whi
|
|||
|
||||
ID | IP address | Hostname | Campaign | Confidence
|
||||
-- | ---------- | -------- | -------- | ----------
|
||||
1 | [5.252.22.62](https://vuldb.com/?ip.5.252.22.62) | vm523526.stark-industries.solutions | - | High
|
||||
2 | [45.142.212.100](https://vuldb.com/?ip.45.142.212.100) | pikpik.top | - | High
|
||||
3 | [51.81.143.169](https://vuldb.com/?ip.51.81.143.169) | ip169.ip-51-81-143.us | - | High
|
||||
4 | ... | ... | ... | ...
|
||||
1 | [2.58.56.247](https://vuldb.com/?ip.2.58.56.247) | powered.by.rdp.sh | - | High
|
||||
2 | [5.42.199.87](https://vuldb.com/?ip.5.42.199.87) | - | - | High
|
||||
3 | [5.252.22.62](https://vuldb.com/?ip.5.252.22.62) | vm523526.stark-industries.solutions | - | High
|
||||
4 | [5.252.22.66](https://vuldb.com/?ip.5.252.22.66) | s-germany.rocks | - | High
|
||||
5 | [5.252.22.107](https://vuldb.com/?ip.5.252.22.107) | ns3.pacehost.de | - | High
|
||||
6 | [23.88.55.150](https://vuldb.com/?ip.23.88.55.150) | static.150.55.88.23.clients.your-server.de | - | High
|
||||
7 | [31.13.195.44](https://vuldb.com/?ip.31.13.195.44) | - | - | High
|
||||
8 | [45.61.136.191](https://vuldb.com/?ip.45.61.136.191) | - | - | High
|
||||
9 | [45.67.34.152](https://vuldb.com/?ip.45.67.34.152) | vm749292.stark-industries.solutions | - | High
|
||||
10 | [45.67.34.234](https://vuldb.com/?ip.45.67.34.234) | server.ga2.so-net.ne.jp | - | High
|
||||
11 | [45.67.35.251](https://vuldb.com/?ip.45.67.35.251) | vm684273.stark-industries.solutions | - | High
|
||||
12 | [45.84.0.80](https://vuldb.com/?ip.45.84.0.80) | sfixbfc.cn | - | High
|
||||
13 | [45.92.156.52](https://vuldb.com/?ip.45.92.156.52) | - | - | High
|
||||
14 | [45.92.156.53](https://vuldb.com/?ip.45.92.156.53) | - | - | High
|
||||
15 | [45.133.216.145](https://vuldb.com/?ip.45.133.216.145) | mail.axiknh.top | - | High
|
||||
16 | [45.133.216.170](https://vuldb.com/?ip.45.133.216.170) | wireguard.vasilchenko.dev | - | High
|
||||
17 | [45.133.216.249](https://vuldb.com/?ip.45.133.216.249) | vm699942.stark-industries.solutions | - | High
|
||||
18 | [45.138.74.104](https://vuldb.com/?ip.45.138.74.104) | descriptive-servant.aeza.network | - | High
|
||||
19 | [45.142.212.100](https://vuldb.com/?ip.45.142.212.100) | pikpik.top | - | High
|
||||
20 | [45.142.215.50](https://vuldb.com/?ip.45.142.215.50) | vm700900.stark-industries.solutions | - | High
|
||||
21 | [45.142.215.92](https://vuldb.com/?ip.45.142.215.92) | vm586875.stark-industries.solutions | - | High
|
||||
22 | ... | ... | ... | ...
|
||||
|
||||
There are 13 more IOC items available. Please use our online service to access the data.
|
||||
There are 83 more IOC items available. Please use our online service to access the data.
|
||||
|
||||
## TTP - Tactics, Techniques, Procedures
|
||||
|
||||
|
@ -34,14 +52,14 @@ _Tactics, techniques, and procedures_ (TTP) summarize the suspected MITRE ATT&CK
|
|||
|
||||
ID | Technique | Weakness | Description | Confidence
|
||||
-- | --------- | -------- | ----------- | ----------
|
||||
1 | T1006 | CWE-21, CWE-22, CWE-23, CWE-25 | Pathname Traversal | High
|
||||
2 | T1040 | CWE-319 | Authentication Bypass by Capture-replay | High
|
||||
1 | T1006 | CWE-21, CWE-22, CWE-23, CWE-36 | Pathname Traversal | High
|
||||
2 | T1040 | CWE-294, CWE-319 | Authentication Bypass by Capture-replay | High
|
||||
3 | T1055 | CWE-74 | Injection | High
|
||||
4 | T1059 | CWE-88, CWE-94 | Cross Site Scripting | High
|
||||
5 | T1059.007 | CWE-79, CWE-80 | Cross Site Scripting | High
|
||||
6 | ... | ... | ... | ...
|
||||
|
||||
There are 19 more TTP items available. Please use our online service to access the data.
|
||||
There are 20 more TTP items available. Please use our online service to access the data.
|
||||
|
||||
## IOA - Indicator of Attack
|
||||
|
||||
|
@ -49,40 +67,55 @@ These _indicators of attack_ (IOA) list the potential fragments used for technic
|
|||
|
||||
ID | Type | Indicator | Confidence
|
||||
-- | ---- | --------- | ----------
|
||||
1 | File | `/account/register` | High
|
||||
2 | File | `/admin.php/pic/admin/pic/del` | High
|
||||
3 | File | `/admin/deluser.php` | High
|
||||
4 | File | `/admin/sign/out` | High
|
||||
5 | File | `/admin/subnets/ripe-query.php` | High
|
||||
6 | File | `/admin/web_config.php&` | High
|
||||
7 | File | `/app/options.py` | High
|
||||
8 | File | `/apps/` | Low
|
||||
9 | File | `/bsms/?page=manage_account` | High
|
||||
10 | File | `/cmscp/ext/collect/fetch_url.do` | High
|
||||
11 | File | `/controllers/MgrDiagnosticTools.php` | High
|
||||
12 | File | `/convert/html` | High
|
||||
13 | File | `/course/api/upload/pic` | High
|
||||
14 | File | `/etc/init.d/S50dropbear.sh` | High
|
||||
15 | File | `/goform/rlmswitchr_process` | High
|
||||
16 | File | `/hocms/classes/Master.php?f=delete_phase` | High
|
||||
17 | File | `/hub/api/user` | High
|
||||
18 | File | `/modules/mindmap/index.php` | High
|
||||
19 | File | `/modules/tasks/summary.inc.php` | High
|
||||
20 | File | `/password.html` | High
|
||||
21 | File | `/pms/admin/inmates/manage_record.php` | High
|
||||
22 | File | `/pms/admin/prisons/manage_prison.php` | High
|
||||
23 | File | `/root/.keeper/` | High
|
||||
24 | File | `/rss.xml` | Medium
|
||||
25 | File | `/simple_chat_bot/admin/?page=responses/manage_response` | High
|
||||
26 | ... | ... | ...
|
||||
1 | File | `.forward` | Medium
|
||||
2 | File | `//proc/kcore` | Medium
|
||||
3 | File | `/addQuestion.php` | High
|
||||
4 | File | `/admin.php/Admin/adminadd.html` | High
|
||||
5 | File | `/admin.php/vod/admin/topic/del` | High
|
||||
6 | File | `/Admin/add-student.php` | High
|
||||
7 | File | `/admin/article/list_approve` | High
|
||||
8 | File | `/admin/communitymanagement.php` | High
|
||||
9 | File | `/admin/folderrollpicture/list` | High
|
||||
10 | File | `/admin/settings/save.php` | High
|
||||
11 | File | `/api/plugin/upload` | High
|
||||
12 | File | `/api/RecordingList/DownloadRecord?file=` | High
|
||||
13 | File | `/api/upload-resource` | High
|
||||
14 | File | `/bcms/admin/?page=service_transactions/view_details` | High
|
||||
15 | File | `/bcms/admin/?page=user/manage_user` | High
|
||||
16 | File | `/bd_genie_create_account.cgi` | High
|
||||
17 | File | `/College_Management_System/admin/display-teacher.php` | High
|
||||
18 | File | `/conf/users` | Medium
|
||||
19 | File | `/course/api/upload/pic` | High
|
||||
20 | File | `/csms/classes/Master.php?f=delete_booking` | High
|
||||
21 | File | `/ctpms/classes/Master.php?f=delete_img` | High
|
||||
22 | File | `/dev/mmz_userdev` | High
|
||||
23 | File | `/diagnostic/editcategory.php` | High
|
||||
24 | File | `/etc/passwd` | Medium
|
||||
25 | File | `/gaia-job-admin/user/add` | High
|
||||
26 | File | `/goform/aspForm` | High
|
||||
27 | File | `/goform/SetFirewallCfg` | High
|
||||
28 | File | `/goform/WifiExtraSet` | High
|
||||
29 | File | `/goform/WriteFacMac` | High
|
||||
30 | File | `/gpac/src/bifs/unquantize.c` | High
|
||||
31 | File | `/h/search?action` | High
|
||||
32 | File | `/h/search?action=voicemail&action=listen` | High
|
||||
33 | File | `/HNAP1` | Low
|
||||
34 | File | `/htdocs/upnpinc/gena.php` | High
|
||||
35 | File | `/index.asp` | Medium
|
||||
36 | File | `/index.php?module=entities/fields&entities_id=24` | High
|
||||
37 | File | `/Items/*/RemoteImages/Download` | High
|
||||
38 | File | `/jfinal_cms/system/role/list` | High
|
||||
39 | File | `/login.php` | Medium
|
||||
40 | ... | ... | ...
|
||||
|
||||
There are 215 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 341 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
The following list contains _external sources_ which discuss the actor and the associated activities:
|
||||
|
||||
* https://community.blueliv.com/#!/s/610bc7b082df417ed032f5f1
|
||||
* https://github.com/SEKOIA-IO/Community/blob/main/IOCs/raccoonstealer/raccoon_stealer_iocs_20220628.csv
|
||||
* https://www.zerofox.com/blog/brief-raccoon-stealer-version-2-0/
|
||||
|
||||
## Literature
|
||||
|
|
|
@ -122,23 +122,23 @@ ID | Type | Indicator | Confidence
|
|||
3 | File | `/files.md5` | Medium
|
||||
4 | File | `/forum/away.php` | High
|
||||
5 | File | `/horde/util/go.php` | High
|
||||
6 | File | `/images/` | Medium
|
||||
7 | File | `/inc/parser/xhtml.php` | High
|
||||
8 | File | `/login` | Low
|
||||
9 | File | `/modules/profile/index.php` | High
|
||||
10 | File | `/one_church/userregister.php` | High
|
||||
11 | File | `/out.php` | Medium
|
||||
12 | File | `/public/plugins/` | High
|
||||
13 | File | `/SAP_Information_System/controllers/add_admin.php` | High
|
||||
14 | File | `/SASWebReportStudio/logonAndRender.do` | High
|
||||
15 | File | `/secure/admin/InsightDefaultCustomFieldConfig.jspa` | High
|
||||
16 | File | `/secure/admin/ViewInstrumentation.jspa` | High
|
||||
17 | File | `/system/proxy` | High
|
||||
18 | File | `/tmp/phpglibccheck` | High
|
||||
19 | File | `/v2/quantum/save-data-upload-big-file` | High
|
||||
20 | File | `4.edu.php` | Medium
|
||||
21 | File | `adclick.php` | Medium
|
||||
22 | File | `add.php` | Low
|
||||
6 | File | `/hrm/employeeview.php` | High
|
||||
7 | File | `/images/` | Medium
|
||||
8 | File | `/inc/parser/xhtml.php` | High
|
||||
9 | File | `/login` | Low
|
||||
10 | File | `/modules/profile/index.php` | High
|
||||
11 | File | `/one_church/userregister.php` | High
|
||||
12 | File | `/out.php` | Medium
|
||||
13 | File | `/public/plugins/` | High
|
||||
14 | File | `/SAP_Information_System/controllers/add_admin.php` | High
|
||||
15 | File | `/SASWebReportStudio/logonAndRender.do` | High
|
||||
16 | File | `/secure/admin/InsightDefaultCustomFieldConfig.jspa` | High
|
||||
17 | File | `/secure/admin/ViewInstrumentation.jspa` | High
|
||||
18 | File | `/system/proxy` | High
|
||||
19 | File | `/tmp/phpglibccheck` | High
|
||||
20 | File | `/v2/quantum/save-data-upload-big-file` | High
|
||||
21 | File | `4.edu.php` | Medium
|
||||
22 | File | `adclick.php` | Medium
|
||||
23 | File | `addentry.php` | Medium
|
||||
24 | File | `addressbookprovider.php` | High
|
||||
25 | File | `admin.jcomments.php` | High
|
||||
|
@ -148,7 +148,7 @@ ID | Type | Indicator | Confidence
|
|||
29 | File | `application.js.php` | High
|
||||
30 | ... | ... | ...
|
||||
|
||||
There are 257 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 253 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -62,7 +62,8 @@ ID | Type | Indicator | Confidence
|
|||
9 | File | `/mims/login.php` | High
|
||||
10 | File | `/opt/zimbra/jetty/webapps/zimbra/public` | High
|
||||
11 | File | `/rapi/read_url` | High
|
||||
12 | ... | ... | ...
|
||||
12 | File | `/SetTriggerWPS/PIN` | High
|
||||
13 | ... | ... | ...
|
||||
|
||||
There are 97 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
|
|
|
@ -16,7 +16,7 @@ These _countries_ are directly (e.g. origin of attacks) or indirectly (e.g. acce
|
|||
|
||||
* [ES](https://vuldb.com/?country.es)
|
||||
* [US](https://vuldb.com/?country.us)
|
||||
* [FR](https://vuldb.com/?country.fr)
|
||||
* [GB](https://vuldb.com/?country.gb)
|
||||
* ...
|
||||
|
||||
There are 13 more country items available. Please use our online service to access the data.
|
||||
|
@ -136,7 +136,7 @@ ID | Technique | Weakness | Description | Confidence
|
|||
5 | T1068 | CWE-250, CWE-264, CWE-266, CWE-269, CWE-284 | Execution with Unnecessary Privileges | High
|
||||
6 | ... | ... | ... | ...
|
||||
|
||||
There are 22 more TTP items available. Please use our online service to access the data.
|
||||
There are 21 more TTP items available. Please use our online service to access the data.
|
||||
|
||||
## IOA - Indicator of Attack
|
||||
|
||||
|
@ -144,32 +144,33 @@ These _indicators of attack_ (IOA) list the potential fragments used for technic
|
|||
|
||||
ID | Type | Indicator | Confidence
|
||||
-- | ---- | --------- | ----------
|
||||
1 | File | `/admin/subnets/ripe-query.php` | High
|
||||
2 | File | `/api/index.php` | High
|
||||
3 | File | `/config/getuser` | High
|
||||
4 | File | `/configs/application.ini` | High
|
||||
5 | File | `/etc/grafana/grafana.ini` | High
|
||||
6 | File | `/etc/networkd-dispatcher` | High
|
||||
7 | File | `/export` | Low
|
||||
8 | File | `/file` | Low
|
||||
9 | File | `/forum/away.php` | High
|
||||
10 | File | `/goform/wifiSSIDset` | High
|
||||
11 | File | `/home/hjsz/jsonlint/src/lexer` | High
|
||||
12 | File | `/IISADMPWD` | Medium
|
||||
13 | File | `/index.php` | Medium
|
||||
14 | File | `/info.asp` | Medium
|
||||
15 | File | `/login` | Low
|
||||
16 | File | `/mgmt/tm/util/bash` | High
|
||||
17 | File | `/net/nfc/netlink.c` | High
|
||||
18 | File | `/obs/bookPerPub.php` | High
|
||||
19 | File | `/opt/zimbra/jetty/webapps/zimbra/public` | High
|
||||
20 | File | `/out.php` | Medium
|
||||
21 | File | `/php-sms/classes/Master.php?f=save_quote` | High
|
||||
22 | File | `/php_action/createUser.php` | High
|
||||
23 | File | `/public/plugins/` | High
|
||||
24 | ... | ... | ...
|
||||
1 | File | `%ProgramData%\GOG.com` | High
|
||||
2 | File | `/admin/subnets/ripe-query.php` | High
|
||||
3 | File | `/api/index.php` | High
|
||||
4 | File | `/carbon/ndatasource/validateconnection/ajaxprocessor.jsp` | High
|
||||
5 | File | `/config/getuser` | High
|
||||
6 | File | `/configs/application.ini` | High
|
||||
7 | File | `/etc/grafana/grafana.ini` | High
|
||||
8 | File | `/etc/networkd-dispatcher` | High
|
||||
9 | File | `/export` | Low
|
||||
10 | File | `/file` | Low
|
||||
11 | File | `/forum/away.php` | High
|
||||
12 | File | `/goform/wifiSSIDset` | High
|
||||
13 | File | `/home/hjsz/jsonlint/src/lexer` | High
|
||||
14 | File | `/hrm/employeeview.php` | High
|
||||
15 | File | `/index.php` | Medium
|
||||
16 | File | `/info.asp` | Medium
|
||||
17 | File | `/login` | Low
|
||||
18 | File | `/mgmt/tm/util/bash` | High
|
||||
19 | File | `/net/nfc/netlink.c` | High
|
||||
20 | File | `/obs/bookPerPub.php` | High
|
||||
21 | File | `/opt/zimbra/jetty/webapps/zimbra/public` | High
|
||||
22 | File | `/out.php` | Medium
|
||||
23 | File | `/php-sms/classes/Master.php?f=save_quote` | High
|
||||
24 | File | `/public/plugins/` | High
|
||||
25 | ... | ... | ...
|
||||
|
||||
There are 203 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 206 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -89,7 +89,8 @@ ID | Type | Indicator | Confidence
|
|||
21 | File | `books.php` | Medium
|
||||
22 | File | `card/pay/.../amount` | High
|
||||
23 | File | `category.cfm` | Medium
|
||||
24 | ... | ... | ...
|
||||
24 | File | `ccbord.c` | Medium
|
||||
25 | ... | ... | ...
|
||||
|
||||
There are 205 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
|
|
|
@ -59,89 +59,89 @@ ID | Type | Indicator | Confidence
|
|||
11 | File | `/dl/dl_print.php` | High
|
||||
12 | File | `/etc/master.passwd` | High
|
||||
13 | File | `/etc/passwd` | Medium
|
||||
14 | File | `/goform/Diagnosis` | High
|
||||
15 | File | `/Hospital-Management-System-master/contact.php` | High
|
||||
16 | File | `/include/friends.inc.php` | High
|
||||
17 | File | `/members/view_member.php` | High
|
||||
18 | File | `/servlet/webacc` | High
|
||||
19 | File | `/sitemagic/upgrade.php` | High
|
||||
20 | File | `/userui/ticket_list.php` | High
|
||||
21 | File | `/wp-admin/options-general.php` | High
|
||||
22 | File | `/zm/index.php` | High
|
||||
23 | File | `abook_database.php` | High
|
||||
24 | File | `accounts/inc/include.php` | High
|
||||
25 | File | `adaptive-images-script.php` | High
|
||||
26 | File | `additem.asp` | Medium
|
||||
27 | File | `addtocart.asp` | High
|
||||
28 | File | `adherents/subscription/info.php` | High
|
||||
29 | File | `admin.asp` | Medium
|
||||
30 | File | `admin.php` | Medium
|
||||
31 | File | `admin/admin.php` | High
|
||||
32 | File | `admin/admin_users.php` | High
|
||||
33 | File | `admin/article_save.php` | High
|
||||
34 | File | `admin/general.php` | High
|
||||
35 | File | `admin/header.php` | High
|
||||
36 | File | `admin/inc/change_action.php` | High
|
||||
37 | File | `admin/index.php` | High
|
||||
38 | File | `admin/info.php` | High
|
||||
39 | File | `admin/login.asp` | High
|
||||
40 | File | `admin/manage-comments.php` | High
|
||||
41 | File | `admin/manage-news.php` | High
|
||||
42 | File | `admin/plugin-settings.php` | High
|
||||
43 | File | `admin/specials.php` | High
|
||||
44 | File | `admin:de` | Medium
|
||||
45 | File | `admincp/auth/checklogin.php` | High
|
||||
46 | File | `admincp/auth/secure.php` | High
|
||||
47 | File | `administrator/components/com_media/helpers/media.php` | High
|
||||
48 | File | `administrator/index.php` | High
|
||||
49 | File | `admin_login.asp` | High
|
||||
50 | File | `adv_search.asp` | High
|
||||
51 | File | `ajax_url.php` | Medium
|
||||
52 | File | `album_portal.php` | High
|
||||
53 | File | `al_initialize.php` | High
|
||||
54 | File | `anjel.index.php` | High
|
||||
55 | File | `annonces-p-f.php` | High
|
||||
56 | File | `announce.php` | Medium
|
||||
57 | File | `announcement.php` | High
|
||||
58 | File | `announcements.php` | High
|
||||
59 | File | `app/admin/routing/edit-bgp-mapping-search.php` | High
|
||||
60 | File | `application/config/config.php` | High
|
||||
61 | File | `application/controllers/basedata/inventory.php` | High
|
||||
62 | File | `apply.cgi` | Medium
|
||||
63 | File | `apps/app_article/controller/rating.php` | High
|
||||
64 | File | `article.php` | Medium
|
||||
65 | File | `articles.php` | Medium
|
||||
66 | File | `artikel_anzeige.php` | High
|
||||
67 | File | `auktion.cgi` | Medium
|
||||
68 | File | `auth.php` | Medium
|
||||
69 | File | `authfiles/login.asp` | High
|
||||
70 | File | `basket.php` | Medium
|
||||
71 | File | `boardData103.php/boardDataJP.php/boardDataNA.php/boardDataWW.php` | High
|
||||
72 | File | `books.php` | Medium
|
||||
73 | File | `browse-category.php` | High
|
||||
74 | File | `browse.php` | Medium
|
||||
75 | File | `browse_videos.php` | High
|
||||
76 | File | `BrudaNews/BrudaGB` | High
|
||||
77 | File | `bwlist_inc.html` | High
|
||||
78 | File | `calendar.php` | Medium
|
||||
79 | File | `callme_page.php` | High
|
||||
80 | File | `cart.php` | Medium
|
||||
81 | File | `cart_add.php` | Medium
|
||||
82 | File | `case.filemanager.php` | High
|
||||
83 | File | `catalog.php` | Medium
|
||||
84 | File | `catalogshop.php` | High
|
||||
85 | File | `catalogue.asp` | High
|
||||
86 | File | `category.cfm` | Medium
|
||||
87 | File | `category.php` | Medium
|
||||
88 | File | `category_list.php` | High
|
||||
89 | File | `cgi-bin/awstats.pl` | High
|
||||
90 | File | `channel.asp` | Medium
|
||||
91 | File | `ChooseCpSearch.php` | High
|
||||
92 | File | `cmd.exe` | Low
|
||||
93 | File | `comentarii.php` | High
|
||||
14 | File | `/goform/AddSysLogRule` | High
|
||||
15 | File | `/goform/Diagnosis` | High
|
||||
16 | File | `/Hospital-Management-System-master/contact.php` | High
|
||||
17 | File | `/include/friends.inc.php` | High
|
||||
18 | File | `/index.php?module=configuration/application` | High
|
||||
19 | File | `/members/view_member.php` | High
|
||||
20 | File | `/servlet/webacc` | High
|
||||
21 | File | `/sitemagic/upgrade.php` | High
|
||||
22 | File | `/userui/ticket_list.php` | High
|
||||
23 | File | `/wp-admin/options-general.php` | High
|
||||
24 | File | `/zm/index.php` | High
|
||||
25 | File | `abook_database.php` | High
|
||||
26 | File | `accounts/inc/include.php` | High
|
||||
27 | File | `adaptive-images-script.php` | High
|
||||
28 | File | `additem.asp` | Medium
|
||||
29 | File | `addtocart.asp` | High
|
||||
30 | File | `adherents/subscription/info.php` | High
|
||||
31 | File | `admin.asp` | Medium
|
||||
32 | File | `admin.php` | Medium
|
||||
33 | File | `admin/admin.php` | High
|
||||
34 | File | `admin/admin_users.php` | High
|
||||
35 | File | `admin/article_save.php` | High
|
||||
36 | File | `admin/general.php` | High
|
||||
37 | File | `admin/header.php` | High
|
||||
38 | File | `admin/inc/change_action.php` | High
|
||||
39 | File | `admin/index.php` | High
|
||||
40 | File | `admin/info.php` | High
|
||||
41 | File | `admin/login.asp` | High
|
||||
42 | File | `admin/manage-comments.php` | High
|
||||
43 | File | `admin/manage-news.php` | High
|
||||
44 | File | `admin/plugin-settings.php` | High
|
||||
45 | File | `admin/specials.php` | High
|
||||
46 | File | `admin:de` | Medium
|
||||
47 | File | `admincp/auth/checklogin.php` | High
|
||||
48 | File | `admincp/auth/secure.php` | High
|
||||
49 | File | `administrator/components/com_media/helpers/media.php` | High
|
||||
50 | File | `administrator/index.php` | High
|
||||
51 | File | `admin_login.asp` | High
|
||||
52 | File | `adv_search.asp` | High
|
||||
53 | File | `ajax_url.php` | Medium
|
||||
54 | File | `album_portal.php` | High
|
||||
55 | File | `al_initialize.php` | High
|
||||
56 | File | `anjel.index.php` | High
|
||||
57 | File | `annonces-p-f.php` | High
|
||||
58 | File | `announce.php` | Medium
|
||||
59 | File | `announcement.php` | High
|
||||
60 | File | `announcements.php` | High
|
||||
61 | File | `app/admin/routing/edit-bgp-mapping-search.php` | High
|
||||
62 | File | `application/config/config.php` | High
|
||||
63 | File | `application/controllers/basedata/inventory.php` | High
|
||||
64 | File | `apply.cgi` | Medium
|
||||
65 | File | `apps/app_article/controller/rating.php` | High
|
||||
66 | File | `article.php` | Medium
|
||||
67 | File | `articles.php` | Medium
|
||||
68 | File | `artikel_anzeige.php` | High
|
||||
69 | File | `auktion.cgi` | Medium
|
||||
70 | File | `auth.php` | Medium
|
||||
71 | File | `authfiles/login.asp` | High
|
||||
72 | File | `basket.php` | Medium
|
||||
73 | File | `boardData103.php/boardDataJP.php/boardDataNA.php/boardDataWW.php` | High
|
||||
74 | File | `books.php` | Medium
|
||||
75 | File | `browse-category.php` | High
|
||||
76 | File | `browse.php` | Medium
|
||||
77 | File | `browse_videos.php` | High
|
||||
78 | File | `BrudaNews/BrudaGB` | High
|
||||
79 | File | `bwlist_inc.html` | High
|
||||
80 | File | `calendar.php` | Medium
|
||||
81 | File | `callme_page.php` | High
|
||||
82 | File | `cart.php` | Medium
|
||||
83 | File | `cart_add.php` | Medium
|
||||
84 | File | `case.filemanager.php` | High
|
||||
85 | File | `catalog.php` | Medium
|
||||
86 | File | `catalogshop.php` | High
|
||||
87 | File | `catalogue.asp` | High
|
||||
88 | File | `category.cfm` | Medium
|
||||
89 | File | `category.php` | Medium
|
||||
90 | File | `category_list.php` | High
|
||||
91 | File | `cgi-bin/awstats.pl` | High
|
||||
92 | File | `channel.asp` | Medium
|
||||
93 | File | `ChooseCpSearch.php` | High
|
||||
94 | ... | ... | ...
|
||||
|
||||
There are 828 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 831 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -9,8 +9,11 @@ _Live data_ and more _analysis capabilities_ are available at [https://vuldb.com
|
|||
These _countries_ are directly (e.g. origin of attacks) or indirectly (e.g. access by proxy) associated with Sysrv:
|
||||
|
||||
* [US](https://vuldb.com/?country.us)
|
||||
* [UA](https://vuldb.com/?country.ua)
|
||||
* [CN](https://vuldb.com/?country.cn)
|
||||
* [SI](https://vuldb.com/?country.si)
|
||||
* ...
|
||||
|
||||
There are 2 more country items available. Please use our online service to access the data.
|
||||
|
||||
## IOC - Indicator of Compromise
|
||||
|
||||
|
@ -45,14 +48,16 @@ These _indicators of attack_ (IOA) list the potential fragments used for technic
|
|||
ID | Type | Indicator | Confidence
|
||||
-- | ---- | --------- | ----------
|
||||
1 | File | `/admin/contenttemp` | High
|
||||
2 | File | `/member/picture/album` | High
|
||||
3 | File | `/products/details.asp` | High
|
||||
4 | File | `/services/details.asp` | High
|
||||
5 | File | `admin.php` | Medium
|
||||
6 | File | `comersus_optreviewreadexec.asp` | High
|
||||
7 | ... | ... | ...
|
||||
2 | File | `/htdocs/upnpinc/gena.php` | High
|
||||
3 | File | `/lab.html` | Medium
|
||||
4 | File | `/member/picture/album` | High
|
||||
5 | File | `/products/details.asp` | High
|
||||
6 | File | `/services/details.asp` | High
|
||||
7 | File | `/vendor` | Low
|
||||
8 | File | `admin.php` | Medium
|
||||
9 | ... | ... | ...
|
||||
|
||||
There are 48 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 70 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -82,42 +82,42 @@ ID | Type | Indicator | Confidence
|
|||
11 | File | `/modules/profile/index.php` | High
|
||||
12 | File | `/nagiosql/admin/checkcommands.php` | High
|
||||
13 | File | `/php-sms/classes/Master.php?f=save_quote` | High
|
||||
14 | File | `/tmp` | Low
|
||||
15 | File | `/uncpath/` | Medium
|
||||
16 | File | `/usr/5bin/su` | Medium
|
||||
17 | File | `/usr/bin/mail` | High
|
||||
18 | File | `/usr/bin/pkexec` | High
|
||||
19 | File | `/var/dt/` | Medium
|
||||
20 | File | `/wp-content/plugins/updraftplus/admin.php` | High
|
||||
21 | File | `00.jsp` | Low
|
||||
22 | File | `account_activations/edit` | High
|
||||
23 | File | `add_2_basket.asp` | High
|
||||
24 | File | `admin.asp` | Medium
|
||||
25 | File | `admin.jcomments.php` | High
|
||||
26 | File | `admin.php` | Medium
|
||||
27 | File | `admin/` | Low
|
||||
28 | File | `admin/?page=system_info` | High
|
||||
29 | File | `admin/aboutus.php` | High
|
||||
30 | File | `admin/article_save.php` | High
|
||||
31 | File | `admin/import/class-import-settings.php` | High
|
||||
32 | File | `admin/manage-comments.php` | High
|
||||
33 | File | `administration/comments.php` | High
|
||||
34 | File | `administrator/mail/download.cfm` | High
|
||||
35 | File | `AdminViewError/AdminAddadmin` | High
|
||||
36 | File | `admin_edit_comment.php` | High
|
||||
37 | File | `agentdisplay.php` | High
|
||||
38 | File | `apply.cgi` | Medium
|
||||
39 | File | `appointment.php` | High
|
||||
40 | File | `arch/x86/kvm/hyperv.c` | High
|
||||
41 | File | `assets/components/fred/web/elfinder/connector.php` | High
|
||||
42 | File | `auction.cgi` | Medium
|
||||
43 | File | `autologin.jsp` | High
|
||||
44 | File | `axspawn.c` | Medium
|
||||
45 | File | `base_ag_main.php` | High
|
||||
46 | File | `base_qry_main.php` | High
|
||||
14 | File | `/SysInfo.htm` | Medium
|
||||
15 | File | `/tmp` | Low
|
||||
16 | File | `/uncpath/` | Medium
|
||||
17 | File | `/usr/5bin/su` | Medium
|
||||
18 | File | `/usr/bin/mail` | High
|
||||
19 | File | `/usr/bin/pkexec` | High
|
||||
20 | File | `/var/dt/` | Medium
|
||||
21 | File | `/wp-content/plugins/updraftplus/admin.php` | High
|
||||
22 | File | `00.jsp` | Low
|
||||
23 | File | `account_activations/edit` | High
|
||||
24 | File | `add_2_basket.asp` | High
|
||||
25 | File | `admin.asp` | Medium
|
||||
26 | File | `admin.jcomments.php` | High
|
||||
27 | File | `admin.php` | Medium
|
||||
28 | File | `admin/` | Low
|
||||
29 | File | `admin/?page=system_info` | High
|
||||
30 | File | `admin/aboutus.php` | High
|
||||
31 | File | `admin/article_save.php` | High
|
||||
32 | File | `admin/import/class-import-settings.php` | High
|
||||
33 | File | `admin/manage-comments.php` | High
|
||||
34 | File | `administration/comments.php` | High
|
||||
35 | File | `administrator/mail/download.cfm` | High
|
||||
36 | File | `AdminViewError/AdminAddadmin` | High
|
||||
37 | File | `admin_edit_comment.php` | High
|
||||
38 | File | `agentdisplay.php` | High
|
||||
39 | File | `apply.cgi` | Medium
|
||||
40 | File | `appointment.php` | High
|
||||
41 | File | `arch/x86/kvm/hyperv.c` | High
|
||||
42 | File | `assets/components/fred/web/elfinder/connector.php` | High
|
||||
43 | File | `auction.cgi` | Medium
|
||||
44 | File | `autologin.jsp` | High
|
||||
45 | File | `axspawn.c` | Medium
|
||||
46 | File | `base_ag_main.php` | High
|
||||
47 | ... | ... | ...
|
||||
|
||||
There are 407 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 409 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -19,9 +19,9 @@ There are 1 more campaign items available. Please use our online service to acce
|
|||
|
||||
These _countries_ are directly (e.g. origin of attacks) or indirectly (e.g. access by proxy) associated with TA551:
|
||||
|
||||
* [SV](https://vuldb.com/?country.sv)
|
||||
* [PL](https://vuldb.com/?country.pl)
|
||||
* [RU](https://vuldb.com/?country.ru)
|
||||
* [AR](https://vuldb.com/?country.ar)
|
||||
* [ES](https://vuldb.com/?country.es)
|
||||
* [DE](https://vuldb.com/?country.de)
|
||||
* ...
|
||||
|
||||
There are 7 more country items available. Please use our online service to access the data.
|
||||
|
@ -56,13 +56,14 @@ _Tactics, techniques, and procedures_ (TTP) summarize the suspected MITRE ATT&CK
|
|||
|
||||
ID | Technique | Weakness | Description | Confidence
|
||||
-- | --------- | -------- | ----------- | ----------
|
||||
1 | T1006 | CWE-21, CWE-22 | Pathname Traversal | High
|
||||
2 | T1055 | CWE-74 | Injection | High
|
||||
3 | T1059 | CWE-94, CWE-1321 | Cross Site Scripting | High
|
||||
4 | T1059.007 | CWE-79, CWE-80 | Cross Site Scripting | High
|
||||
5 | ... | ... | ... | ...
|
||||
1 | T1006 | CWE-21, CWE-22, CWE-23, CWE-36 | Pathname Traversal | High
|
||||
2 | T1040 | CWE-319 | Authentication Bypass by Capture-replay | High
|
||||
3 | T1055 | CWE-74 | Injection | High
|
||||
4 | T1059 | CWE-94, CWE-1321 | Cross Site Scripting | High
|
||||
5 | T1059.007 | CWE-79 | Cross Site Scripting | High
|
||||
6 | ... | ... | ... | ...
|
||||
|
||||
There are 16 more TTP items available. Please use our online service to access the data.
|
||||
There are 18 more TTP items available. Please use our online service to access the data.
|
||||
|
||||
## IOA - Indicator of Attack
|
||||
|
||||
|
@ -70,32 +71,47 @@ These _indicators of attack_ (IOA) list the potential fragments used for technic
|
|||
|
||||
ID | Type | Indicator | Confidence
|
||||
-- | ---- | --------- | ----------
|
||||
1 | File | `/admin/?page=user/manage_user` | High
|
||||
2 | File | `/admin/admin.php` | High
|
||||
3 | File | `/Admin/createClass.php` | High
|
||||
4 | File | `/Admin/dashboard.php` | High
|
||||
5 | File | `/admin/problem_judge.php` | High
|
||||
6 | File | `/asms/admin/?page=transactions/manage_transaction` | High
|
||||
7 | File | `/asms/admin/?page=user/manage_user` | High
|
||||
8 | File | `/asms/classes/Master.php?f=delete_img` | High
|
||||
9 | File | `/asms/classes/Master.php?f=delete_service` | High
|
||||
10 | File | `/attachments` | Medium
|
||||
11 | File | `/avms/index.php` | High
|
||||
12 | File | `/bin/proc.cgi` | High
|
||||
13 | File | `/diag_tracert_admin.asp` | High
|
||||
14 | File | `/etc/tomcat8/Catalina/attack` | High
|
||||
15 | File | `/index.php/admins/Fields/get_fields.html` | High
|
||||
16 | File | `/isomedia/meta.c` | High
|
||||
17 | File | `/lists/admin/` | High
|
||||
18 | File | `/lists/index.php` | High
|
||||
19 | File | `/login` | Low
|
||||
20 | File | `/mgm_dev_upgrade.asp` | High
|
||||
21 | File | `/pages/processlogin.php` | High
|
||||
22 | File | `/pages/save_user.php` | High
|
||||
23 | File | `/php-sms/admin/?page=user/manage_user` | High
|
||||
24 | ... | ... | ...
|
||||
1 | File | `/Admin/add-student.php` | High
|
||||
2 | File | `/admin/loginc.php` | High
|
||||
3 | File | `/admin/pages/revisions.php` | High
|
||||
4 | File | `/apiv1/` | Low
|
||||
5 | File | `/back/index.php/user/User/?1` | High
|
||||
6 | File | `/blog/comment` | High
|
||||
7 | File | `/bsms_ci/index.php` | High
|
||||
8 | File | `/calendar/viewcalendar.php` | High
|
||||
9 | File | `/classes/Users.php?f=delete_client` | High
|
||||
10 | File | `/confirm` | Medium
|
||||
11 | File | `/face-recognition-php/facepay-master/camera.php` | High
|
||||
12 | File | `/forms/web_runScript` | High
|
||||
13 | File | `/garage/php_action/createBrand.php` | High
|
||||
14 | File | `/general/search.php?searchtype=simple` | High
|
||||
15 | File | `/goform/addUserName` | High
|
||||
16 | File | `/goform/IPSECsave` | High
|
||||
17 | File | `/goform/NatStaticSetting` | High
|
||||
18 | File | `/goform/P2pListFilter` | High
|
||||
19 | File | `/goform/SafeEmailFilter` | High
|
||||
20 | File | `/goform/SafeMacFilter` | High
|
||||
21 | File | `/goform/SafeUrlFilter` | High
|
||||
22 | File | `/goform/setSysPwd` | High
|
||||
23 | File | `/goform/setUplinkInfo` | High
|
||||
24 | File | `/goform/SysToolReboot` | High
|
||||
25 | File | `/goform/SysToolRestoreSet` | High
|
||||
26 | File | `/goform/VirtualSer` | High
|
||||
27 | File | `/goform/WifiBasicSet` | High
|
||||
28 | File | `/goform/wifiSSIDset` | High
|
||||
29 | File | `/gpac/src/bifs/unquantize.c` | High
|
||||
30 | File | `/hrm/controller/employee.php` | High
|
||||
31 | File | `/hrm/employeeadd.php` | High
|
||||
32 | File | `/index.php?module=configuration/application` | High
|
||||
33 | File | `/index.php?module=entities/fields&entities_id=24` | High
|
||||
34 | File | `/index.php?module=entities/forms&entities_id=24` | High
|
||||
35 | File | `/index.php?module=entities/listing_types&entities_id=24` | High
|
||||
36 | File | `/index.php?module=help_pages/pages&entities_id=24` | High
|
||||
37 | File | `/leave_system/classes/SystemSettings.php?f=update_settings` | High
|
||||
38 | File | `/linkedcontent/listfiles.php` | High
|
||||
39 | ... | ... | ...
|
||||
|
||||
There are 199 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 335 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -0,0 +1,64 @@
|
|||
# Truebot - Cyber Threat Intelligence
|
||||
|
||||
These _indicators_ were reported, collected, and generated during the [VulDB CTI analysis](https://vuldb.com/?kb.cti) of the actor known as [Truebot](https://vuldb.com/?actor.truebot). The _activity monitoring_ correlates data from social media, forums, chat rooms, and darknet markets. It helps to determine associated actors, specific activities, expected intentions, emerging research, and ongoing attacks. Our unique _predictive model_ uses _big data_ to forecast activities and their characteristics.
|
||||
|
||||
_Live data_ and more _analysis capabilities_ are available at [https://vuldb.com/?actor.truebot](https://vuldb.com/?actor.truebot)
|
||||
|
||||
## Countries
|
||||
|
||||
These _countries_ are directly (e.g. origin of attacks) or indirectly (e.g. access by proxy) associated with Truebot:
|
||||
|
||||
* [RU](https://vuldb.com/?country.ru)
|
||||
* [US](https://vuldb.com/?country.us)
|
||||
|
||||
## IOC - Indicator of Compromise
|
||||
|
||||
These _indicators of compromise_ (IOC) indicate associated network resources which are known to be part of research and attack activities of Truebot.
|
||||
|
||||
ID | IP address | Hostname | Campaign | Confidence
|
||||
-- | ---------- | -------- | -------- | ----------
|
||||
1 | [88.214.27.100](https://vuldb.com/?ip.88.214.27.100) | - | - | High
|
||||
2 | [88.214.27.101](https://vuldb.com/?ip.88.214.27.101) | - | - | High
|
||||
3 | [179.60.150.34](https://vuldb.com/?ip.179.60.150.34) | - | - | High
|
||||
4 | ... | ... | ... | ...
|
||||
|
||||
There are 1 more IOC items available. Please use our online service to access the data.
|
||||
|
||||
## TTP - Tactics, Techniques, Procedures
|
||||
|
||||
_Tactics, techniques, and procedures_ (TTP) summarize the suspected MITRE ATT&CK techniques used by _Truebot_. This data is unique as it uses our predictive model for actor profiling.
|
||||
|
||||
ID | Technique | Weakness | Description | Confidence
|
||||
-- | --------- | -------- | ----------- | ----------
|
||||
1 | T1055 | CWE-74 | Injection | High
|
||||
2 | T1068 | CWE-264, CWE-284 | Execution with Unnecessary Privileges | High
|
||||
3 | T1110.001 | CWE-798 | Improper Restriction of Excessive Authentication Attempts | High
|
||||
4 | ... | ... | ... | ...
|
||||
|
||||
There are 4 more TTP items available. Please use our online service to access the data.
|
||||
|
||||
## IOA - Indicator of Attack
|
||||
|
||||
These _indicators of attack_ (IOA) list the potential fragments used for technical activities like reconnaissance, exploitation, privilege escalation, and exfiltration by Truebot. This data is unique as it uses our predictive model for actor profiling.
|
||||
|
||||
ID | Type | Indicator | Confidence
|
||||
-- | ---- | --------- | ----------
|
||||
1 | File | `openssl.cnf` | Medium
|
||||
2 | File | `sftp-server.c` | High
|
||||
|
||||
## References
|
||||
|
||||
The following list contains _external sources_ which discuss the actor and the associated activities:
|
||||
|
||||
* https://blog.talosintelligence.com/breaking-the-silence-recent-truebot-activity/
|
||||
|
||||
## Literature
|
||||
|
||||
The following _articles_ explain our unique predictive cyber threat intelligence:
|
||||
|
||||
* [VulDB Cyber Threat Intelligence Documentation](https://vuldb.com/?kb.cti)
|
||||
* [Cyber Threat Intelligence - Early Anticipation of Attacks](https://www.scip.ch/en/?labs.20201022)
|
||||
|
||||
## License
|
||||
|
||||
(c) [1997-2022](https://vuldb.com/?kb.changelog) by [vuldb.com](https://vuldb.com/?kb.about). All data on this page is shared under the license [CC BY-NC-SA 4.0](https://creativecommons.org/licenses/by-nc-sa/4.0/). Questions? Check the [FAQ](https://vuldb.com/?kb.faq), read the [documentation](https://vuldb.com/?kb) or [contact us](https://vuldb.com/?contact)!
|
|
@ -39,7 +39,7 @@ These _countries_ are directly (e.g. origin of attacks) or indirectly (e.g. acce
|
|||
* [JP](https://vuldb.com/?country.jp)
|
||||
* ...
|
||||
|
||||
There are 23 more country items available. Please use our online service to access the data.
|
||||
There are 24 more country items available. Please use our online service to access the data.
|
||||
|
||||
## IOC - Indicator of Compromise
|
||||
|
||||
|
@ -16721,11 +16721,11 @@ ID | Technique | Weakness | Description | Confidence
|
|||
1 | T1006 | CWE-21, CWE-22, CWE-23 | Pathname Traversal | High
|
||||
2 | T1040 | CWE-319 | Authentication Bypass by Capture-replay | High
|
||||
3 | T1055 | CWE-74 | Injection | High
|
||||
4 | T1059 | CWE-88, CWE-94 | Cross Site Scripting | High
|
||||
4 | T1059 | CWE-94 | Cross Site Scripting | High
|
||||
5 | T1059.007 | CWE-79, CWE-80 | Cross Site Scripting | High
|
||||
6 | ... | ... | ... | ...
|
||||
|
||||
There are 19 more TTP items available. Please use our online service to access the data.
|
||||
There are 20 more TTP items available. Please use our online service to access the data.
|
||||
|
||||
## IOA - Indicator of Attack
|
||||
|
||||
|
@ -16735,35 +16735,38 @@ ID | Type | Indicator | Confidence
|
|||
-- | ---- | --------- | ----------
|
||||
1 | File | `/admin/fst_upload.inc.php` | High
|
||||
2 | File | `/api/audits` | Medium
|
||||
3 | File | `/bsms_ci/index.php` | High
|
||||
4 | File | `/bsms_ci/index.php/user/edit_user/` | High
|
||||
5 | File | `/calendar/viewcalendar.php` | High
|
||||
6 | File | `/cgi-bin/supervisor/PwdGrp.cgi` | High
|
||||
7 | File | `/cgi-bin/wlogin.cgi` | High
|
||||
8 | File | `/clients/listclients.php` | High
|
||||
9 | File | `/common/info.cgi` | High
|
||||
10 | File | `/contacts/listcontacts.php` | High
|
||||
11 | File | `/Default/Bd` | Medium
|
||||
12 | File | `/etc/passwd` | Medium
|
||||
13 | File | `/event/admin/?page=user/list` | High
|
||||
14 | File | `/face-recognition-php/facepay-master/camera.php` | High
|
||||
15 | File | `/forum/away.php` | High
|
||||
16 | File | `/forums/editforum.php` | High
|
||||
17 | File | `/general/search.php?searchtype=simple` | High
|
||||
18 | File | `/goform/setDiagnoseInfo` | High
|
||||
19 | File | `/goform/setSnmpInfo` | High
|
||||
20 | File | `/goform/setSysPwd` | High
|
||||
21 | File | `/goform/setUplinkInfo` | High
|
||||
22 | File | `/gpac/src/bifs/unquantize.c` | High
|
||||
23 | File | `/hrm/controller/employee.php` | High
|
||||
24 | File | `/hrm/employeeadd.php` | High
|
||||
25 | File | `/hrm/employeeview.php` | High
|
||||
26 | File | `/index.php?module=configuration/application` | High
|
||||
27 | File | `/index.php?module=entities/fields&entities_id=24` | High
|
||||
28 | File | `/index.php?module=entities/forms&entities_id=24` | High
|
||||
29 | ... | ... | ...
|
||||
3 | File | `/back/index.php/user/User/?1` | High
|
||||
4 | File | `/balance/service/list` | High
|
||||
5 | File | `/blog/comment` | High
|
||||
6 | File | `/bsms_ci/index.php` | High
|
||||
7 | File | `/bsms_ci/index.php/user/edit_user/` | High
|
||||
8 | File | `/calendar/viewcalendar.php` | High
|
||||
9 | File | `/cgi-bin/supervisor/PwdGrp.cgi` | High
|
||||
10 | File | `/cgi-bin/wlogin.cgi` | High
|
||||
11 | File | `/ci_hms/search` | High
|
||||
12 | File | `/clients/listclients.php` | High
|
||||
13 | File | `/contacts/listcontacts.php` | High
|
||||
14 | File | `/Default/Bd` | Medium
|
||||
15 | File | `/etc/puppetlabs/puppetserver/conf.d/ca.conf` | High
|
||||
16 | File | `/event/admin/?page=user/list` | High
|
||||
17 | File | `/forum/away.php` | High
|
||||
18 | File | `/forums/editforum.php` | High
|
||||
19 | File | `/general/search.php?searchtype=simple` | High
|
||||
20 | File | `/goform/setDiagnoseInfo` | High
|
||||
21 | File | `/goform/setSnmpInfo` | High
|
||||
22 | File | `/goform/setSysPwd` | High
|
||||
23 | File | `/goform/setUplinkInfo` | High
|
||||
24 | File | `/gpac/src/bifs/unquantize.c` | High
|
||||
25 | File | `/hrm/controller/employee.php` | High
|
||||
26 | File | `/hrm/employeeadd.php` | High
|
||||
27 | File | `/hrm/employeeview.php` | High
|
||||
28 | File | `/includes/login.php` | High
|
||||
29 | File | `/index.php?module=configuration/application` | High
|
||||
30 | File | `/index.php?module=entities/fields&entities_id=24` | High
|
||||
31 | File | `/index.php?module=help_pages/pages&entities_id=24` | High
|
||||
32 | ... | ... | ...
|
||||
|
||||
There are 246 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 274 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -62,20 +62,22 @@ ID | Type | Indicator | Confidence
|
|||
15 | File | `/api/v2/cli/commands` | High
|
||||
16 | File | `/api/v2/open/rowsInfo` | High
|
||||
17 | File | `/asms/admin/?page=user/manage_user` | High
|
||||
18 | File | `/card/in-card.php` | High
|
||||
19 | File | `/classes/Master.php?f=delete_student` | High
|
||||
20 | File | `/connectors/index.php` | High
|
||||
21 | File | `/csms/admin/?page=system_info` | High
|
||||
22 | File | `/etc/init0.d/S80telnetd.sh` | High
|
||||
23 | File | `/etc/srapi/config/system.conf` | High
|
||||
24 | File | `/framework/core/models/expConfig.php` | High
|
||||
25 | File | `/framework/modules/core/controllers/expHTMLEditorController.php` | High
|
||||
26 | File | `/fw.login.php` | High
|
||||
18 | File | `/blog/comment` | High
|
||||
19 | File | `/card/in-card.php` | High
|
||||
20 | File | `/classes/Master.php?f=delete_student` | High
|
||||
21 | File | `/connectors/index.php` | High
|
||||
22 | File | `/csms/admin/?page=system_info` | High
|
||||
23 | File | `/etc/init0.d/S80telnetd.sh` | High
|
||||
24 | File | `/etc/srapi/config/system.conf` | High
|
||||
25 | File | `/framework/core/models/expConfig.php` | High
|
||||
26 | File | `/framework/modules/core/controllers/expHTMLEditorController.php` | High
|
||||
27 | File | `/garage/php_action/createBrand.php` | High
|
||||
28 | File | `/goform/form2WizardStep54` | High
|
||||
29 | ... | ... | ...
|
||||
28 | File | `/goform/addressNat` | High
|
||||
29 | File | `/goform/AdvSetWrlsafeset` | High
|
||||
30 | File | `/goform/editFileName` | High
|
||||
31 | ... | ... | ...
|
||||
|
||||
There are 246 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 260 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -0,0 +1,37 @@
|
|||
# WSzero - Cyber Threat Intelligence
|
||||
|
||||
These _indicators_ were reported, collected, and generated during the [VulDB CTI analysis](https://vuldb.com/?kb.cti) of the actor known as [WSzero](https://vuldb.com/?actor.wszero). The _activity monitoring_ correlates data from social media, forums, chat rooms, and darknet markets. It helps to determine associated actors, specific activities, expected intentions, emerging research, and ongoing attacks. Our unique _predictive model_ uses _big data_ to forecast activities and their characteristics.
|
||||
|
||||
_Live data_ and more _analysis capabilities_ are available at [https://vuldb.com/?actor.wszero](https://vuldb.com/?actor.wszero)
|
||||
|
||||
## Campaigns
|
||||
|
||||
The following _campaigns_ are known and can be associated with WSzero:
|
||||
|
||||
* DDoS
|
||||
|
||||
## IOC - Indicator of Compromise
|
||||
|
||||
These _indicators of compromise_ (IOC) indicate associated network resources which are known to be part of research and attack activities of WSzero.
|
||||
|
||||
ID | IP address | Hostname | Campaign | Confidence
|
||||
-- | ---------- | -------- | -------- | ----------
|
||||
1 | [176.65.137.5](https://vuldb.com/?ip.176.65.137.5) | - | DDoS | High
|
||||
2 | [176.65.137.6](https://vuldb.com/?ip.176.65.137.6) | - | DDoS | High
|
||||
|
||||
## References
|
||||
|
||||
The following list contains _external sources_ which discuss the actor and the associated activities:
|
||||
|
||||
* https://blog.netlab.360.com/new-ddos-botnet-wszeor/
|
||||
|
||||
## Literature
|
||||
|
||||
The following _articles_ explain our unique predictive cyber threat intelligence:
|
||||
|
||||
* [VulDB Cyber Threat Intelligence Documentation](https://vuldb.com/?kb.cti)
|
||||
* [Cyber Threat Intelligence - Early Anticipation of Attacks](https://www.scip.ch/en/?labs.20201022)
|
||||
|
||||
## License
|
||||
|
||||
(c) [1997-2022](https://vuldb.com/?kb.changelog) by [vuldb.com](https://vuldb.com/?kb.about). All data on this page is shared under the license [CC BY-NC-SA 4.0](https://creativecommons.org/licenses/by-nc-sa/4.0/). Questions? Check the [FAQ](https://vuldb.com/?kb.faq), read the [documentation](https://vuldb.com/?kb) or [contact us](https://vuldb.com/?contact)!
|
|
@ -34,7 +34,11 @@ _Tactics, techniques, and procedures_ (TTP) summarize the suspected MITRE ATT&CK
|
|||
ID | Technique | Weakness | Description | Confidence
|
||||
-- | --------- | -------- | ----------- | ----------
|
||||
1 | T1059.007 | CWE-79 | Cross Site Scripting | High
|
||||
2 | T1068 | CWE-264, CWE-284 | Execution with Unnecessary Privileges | High
|
||||
2 | T1068 | CWE-264, CWE-269, CWE-284 | Execution with Unnecessary Privileges | High
|
||||
3 | T1505 | CWE-89 | SQL Injection | High
|
||||
4 | ... | ... | ... | ...
|
||||
|
||||
There are 2 more TTP items available. Please use our online service to access the data.
|
||||
|
||||
## IOA - Indicator of Attack
|
||||
|
||||
|
|
|
@ -120,55 +120,55 @@ These _indicators of attack_ (IOA) list the potential fragments used for technic
|
|||
ID | Type | Indicator | Confidence
|
||||
-- | ---- | --------- | ----------
|
||||
1 | File | `/+CSCOE+/logon.html` | High
|
||||
2 | File | `/.env` | Low
|
||||
3 | File | `/.ssh/authorized_keys` | High
|
||||
4 | File | `/admin/default.asp` | High
|
||||
5 | File | `/admin/moduleinterface.php` | High
|
||||
6 | File | `/ajax/networking/get_netcfg.php` | High
|
||||
7 | File | `/app/options.py` | High
|
||||
8 | File | `/assets/ctx` | Medium
|
||||
9 | File | `/bin/httpd` | Medium
|
||||
10 | File | `/cgi-bin/wapopen` | High
|
||||
11 | File | `/ci_spms/admin/category` | High
|
||||
12 | File | `/ci_spms/admin/search/searching/` | High
|
||||
13 | File | `/classes/Master.php?f=delete_appointment` | High
|
||||
14 | File | `/classes/Master.php?f=delete_train` | High
|
||||
15 | File | `/cms/print.php` | High
|
||||
16 | File | `/concat?/%2557EB-INF/web.xml` | High
|
||||
17 | File | `/Content/Template/root/reverse-shell.aspx` | High
|
||||
18 | File | `/dashboard/menu-list.php` | High
|
||||
19 | File | `/data/remove` | Medium
|
||||
20 | File | `/debug/pprof` | Medium
|
||||
21 | File | `/ffos/classes/Master.php?f=save_category` | High
|
||||
22 | File | `/forum/away.php` | High
|
||||
23 | File | `/goforms/rlminfo` | High
|
||||
24 | File | `/index.php` | Medium
|
||||
25 | File | `/Items/*/RemoteImages/Download` | High
|
||||
26 | File | `/login` | Low
|
||||
27 | File | `/members/view_member.php` | High
|
||||
28 | File | `/modules/profile/index.php` | High
|
||||
29 | File | `/navigate/navigate_download.php` | High
|
||||
30 | File | `/ocwbs/admin/?page=user/manage_user` | High
|
||||
31 | File | `/ofrs/admin/?page=user/manage_user` | High
|
||||
32 | File | `/out.php` | Medium
|
||||
33 | File | `/owa/auth/logon.aspx` | High
|
||||
34 | File | `/password.html` | High
|
||||
35 | File | `/php_action/fetchSelectedUser.php` | High
|
||||
36 | File | `/proc/ioports` | High
|
||||
37 | File | `/property-list/property_view.php` | High
|
||||
38 | File | `/ptms/classes/Users.php` | High
|
||||
39 | File | `/rest/api/2/search` | High
|
||||
40 | File | `/s/` | Low
|
||||
41 | File | `/scripts/cpan_config` | High
|
||||
42 | File | `/secure/admin/InsightDefaultCustomFieldConfig.jspa` | High
|
||||
43 | File | `/services/system/setup.json` | High
|
||||
44 | File | `/spip.php` | Medium
|
||||
45 | File | `/SSOPOST/metaAlias/%realm%/idpv2` | High
|
||||
46 | File | `/tmp` | Low
|
||||
47 | File | `/uncpath/` | Medium
|
||||
48 | File | `/vloggers_merch/?p=view_product` | High
|
||||
49 | File | `/webconsole/APIController` | High
|
||||
50 | File | `/websocket/exec` | High
|
||||
2 | File | `/.ssh/authorized_keys` | High
|
||||
3 | File | `/admin/default.asp` | High
|
||||
4 | File | `/admin/moduleinterface.php` | High
|
||||
5 | File | `/ajax/networking/get_netcfg.php` | High
|
||||
6 | File | `/app/options.py` | High
|
||||
7 | File | `/bin/httpd` | Medium
|
||||
8 | File | `/cgi-bin/wapopen` | High
|
||||
9 | File | `/ci_spms/admin/category` | High
|
||||
10 | File | `/ci_spms/admin/search/searching/` | High
|
||||
11 | File | `/classes/Master.php?f=delete_appointment` | High
|
||||
12 | File | `/classes/Master.php?f=delete_train` | High
|
||||
13 | File | `/cms/print.php` | High
|
||||
14 | File | `/concat?/%2557EB-INF/web.xml` | High
|
||||
15 | File | `/Content/Template/root/reverse-shell.aspx` | High
|
||||
16 | File | `/dashboard/menu-list.php` | High
|
||||
17 | File | `/data/remove` | Medium
|
||||
18 | File | `/debug/pprof` | Medium
|
||||
19 | File | `/ffos/classes/Master.php?f=save_category` | High
|
||||
20 | File | `/forum/away.php` | High
|
||||
21 | File | `/goforms/rlminfo` | High
|
||||
22 | File | `/index.php` | Medium
|
||||
23 | File | `/Items/*/RemoteImages/Download` | High
|
||||
24 | File | `/login` | Low
|
||||
25 | File | `/members/view_member.php` | High
|
||||
26 | File | `/modules/profile/index.php` | High
|
||||
27 | File | `/navigate/navigate_download.php` | High
|
||||
28 | File | `/ocwbs/admin/?page=user/manage_user` | High
|
||||
29 | File | `/ofrs/admin/?page=user/manage_user` | High
|
||||
30 | File | `/out.php` | Medium
|
||||
31 | File | `/owa/auth/logon.aspx` | High
|
||||
32 | File | `/password.html` | High
|
||||
33 | File | `/php_action/fetchSelectedUser.php` | High
|
||||
34 | File | `/proc/ioports` | High
|
||||
35 | File | `/property-list/property_view.php` | High
|
||||
36 | File | `/ptms/classes/Users.php` | High
|
||||
37 | File | `/rest/api/2/search` | High
|
||||
38 | File | `/s/` | Low
|
||||
39 | File | `/scripts/cpan_config` | High
|
||||
40 | File | `/secure/admin/InsightDefaultCustomFieldConfig.jspa` | High
|
||||
41 | File | `/services/system/setup.json` | High
|
||||
42 | File | `/spip.php` | Medium
|
||||
43 | File | `/SSOPOST/metaAlias/%realm%/idpv2` | High
|
||||
44 | File | `/tmp` | Low
|
||||
45 | File | `/uncpath/` | Medium
|
||||
46 | File | `/vloggers_merch/?p=view_product` | High
|
||||
47 | File | `/webconsole/APIController` | High
|
||||
48 | File | `/websocket/exec` | High
|
||||
49 | File | `/whbs/?page=my_bookings` | High
|
||||
50 | File | `/wp-json` | Medium
|
||||
51 | ... | ... | ...
|
||||
|
||||
There are 441 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
|
|
@ -16,10 +16,7 @@ These _countries_ are directly (e.g. origin of attacks) or indirectly (e.g. acce
|
|||
|
||||
* [US](https://vuldb.com/?country.us)
|
||||
* [RU](https://vuldb.com/?country.ru)
|
||||
* [NO](https://vuldb.com/?country.no)
|
||||
* ...
|
||||
|
||||
There are 1 more country items available. Please use our online service to access the data.
|
||||
* [PT](https://vuldb.com/?country.pt)
|
||||
|
||||
## IOC - Indicator of Compromise
|
||||
|
||||
|
@ -40,14 +37,14 @@ _Tactics, techniques, and procedures_ (TTP) summarize the suspected MITRE ATT&CK
|
|||
|
||||
ID | Technique | Weakness | Description | Confidence
|
||||
-- | --------- | -------- | ----------- | ----------
|
||||
1 | T1006 | CWE-21, CWE-22, CWE-23, CWE-37, CWE-40 | Pathname Traversal | High
|
||||
1 | T1006 | CWE-21, CWE-22, CWE-23, CWE-40 | Pathname Traversal | High
|
||||
2 | T1040 | CWE-294, CWE-319 | Authentication Bypass by Capture-replay | High
|
||||
3 | T1055 | CWE-74 | Injection | High
|
||||
4 | T1059 | CWE-88, CWE-94, CWE-1321 | Cross Site Scripting | High
|
||||
5 | T1059.007 | CWE-79, CWE-80 | Cross Site Scripting | High
|
||||
5 | T1059.007 | CWE-79, CWE-80, CWE-85 | Cross Site Scripting | High
|
||||
6 | ... | ... | ... | ...
|
||||
|
||||
There are 20 more TTP items available. Please use our online service to access the data.
|
||||
There are 19 more TTP items available. Please use our online service to access the data.
|
||||
|
||||
## IOA - Indicator of Attack
|
||||
|
||||
|
@ -56,39 +53,42 @@ These _indicators of attack_ (IOA) list the potential fragments used for technic
|
|||
ID | Type | Indicator | Confidence
|
||||
-- | ---- | --------- | ----------
|
||||
1 | File | `/admin.php/Admin/adminadd.html` | High
|
||||
2 | File | `/admin/?page=bookings/view_details` | High
|
||||
3 | File | `/admin/?page=orders/manage_request` | High
|
||||
4 | File | `/admin/?page=user/manage_user` | High
|
||||
5 | File | `/admin/controller/JobLogController.java` | High
|
||||
6 | File | `/Admin/createClass.php` | High
|
||||
7 | File | `/admin/fst_upload.inc.php` | High
|
||||
8 | File | `/admin/problem_judge.php` | High
|
||||
9 | File | `/admin/sign/out` | High
|
||||
10 | File | `/admin/users/index.php` | High
|
||||
11 | File | `/api/common/ping` | High
|
||||
12 | File | `/api/public/signup` | High
|
||||
13 | File | `/api/v1/attack/falco` | High
|
||||
14 | File | `/api/v1/bait/set` | High
|
||||
15 | File | `/api/v1/nics/wifi/wlan0/ping` | High
|
||||
16 | File | `/api/v2/cli/commands` | High
|
||||
17 | File | `/asms/admin/?page=user/manage_user` | High
|
||||
18 | File | `/asms/admin/mechanics/manage_mechanic.php` | High
|
||||
19 | File | `/asms/admin/products/manage_product.php` | High
|
||||
20 | File | `/asms/products/view_product.php` | High
|
||||
21 | File | `/attachments` | Medium
|
||||
22 | File | `/avms/index.php` | High
|
||||
23 | File | `/bookings/update_status.php` | High
|
||||
24 | File | `/classes/Master.php?f=delete_appointment` | High
|
||||
25 | File | `/classes/Users.php?f=delete_client` | High
|
||||
26 | File | `/clearance/clearance.php` | High
|
||||
27 | File | `/depotHead/list` | High
|
||||
28 | File | `/editorder.php` | High
|
||||
29 | File | `/foms/all-orders.php?status=Cancelled%20by%20Customer` | High
|
||||
30 | File | `/garage/editorder.php` | High
|
||||
31 | File | `/index.php/admins/Fields/get_fields.html` | High
|
||||
32 | ... | ... | ...
|
||||
2 | File | `/Admin/add-student.php` | High
|
||||
3 | File | `/admin/controller/JobLogController.java` | High
|
||||
4 | File | `/Admin/createClass.php` | High
|
||||
5 | File | `/admin/fst_upload.inc.php` | High
|
||||
6 | File | `/admin/problem_judge.php` | High
|
||||
7 | File | `/admin/transactions/update_status.php` | High
|
||||
8 | File | `/admin/users/index.php` | High
|
||||
9 | File | `/api/v1/nics/wifi/wlan0/ping` | High
|
||||
10 | File | `/api/v2/cli/commands` | High
|
||||
11 | File | `/apiv1/` | Low
|
||||
12 | File | `/asms/admin/?page=user/manage_user` | High
|
||||
13 | File | `/asms/admin/mechanics/manage_mechanic.php` | High
|
||||
14 | File | `/asms/admin/products/manage_product.php` | High
|
||||
15 | File | `/asms/products/view_product.php` | High
|
||||
16 | File | `/attachments` | Medium
|
||||
17 | File | `/avms/index.php` | High
|
||||
18 | File | `/back/index.php/user/User/?1` | High
|
||||
19 | File | `/blog/comment` | High
|
||||
20 | File | `/bsms_ci/index.php` | High
|
||||
21 | File | `/bsms_ci/index.php/user/edit_user/` | High
|
||||
22 | File | `/calendar/viewcalendar.php` | High
|
||||
23 | File | `/classes/Master.php?f=delete_appointment` | High
|
||||
24 | File | `/classes/Users.php?f=delete_client` | High
|
||||
25 | File | `/Default/Bd` | Medium
|
||||
26 | File | `/device/` | Medium
|
||||
27 | File | `/event/admin/?page=user/list` | High
|
||||
28 | File | `/foms/all-orders.php?status=Cancelled%20by%20Customer` | High
|
||||
29 | File | `/garage/php_action/createBrand.php` | High
|
||||
30 | File | `/goform/setDiagnoseInfo` | High
|
||||
31 | File | `/goform/setSysPwd` | High
|
||||
32 | File | `/goform/setUplinkInfo` | High
|
||||
33 | File | `/hrm/controller/employee.php` | High
|
||||
34 | File | `/hrm/employeeadd.php` | High
|
||||
35 | ... | ... | ...
|
||||
|
||||
There are 274 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 296 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -0,0 +1,30 @@
|
|||
# Zerobot - Cyber Threat Intelligence
|
||||
|
||||
These _indicators_ were reported, collected, and generated during the [VulDB CTI analysis](https://vuldb.com/?kb.cti) of the actor known as [Zerobot](https://vuldb.com/?actor.zerobot). The _activity monitoring_ correlates data from social media, forums, chat rooms, and darknet markets. It helps to determine associated actors, specific activities, expected intentions, emerging research, and ongoing attacks. Our unique _predictive model_ uses _big data_ to forecast activities and their characteristics.
|
||||
|
||||
_Live data_ and more _analysis capabilities_ are available at [https://vuldb.com/?actor.zerobot](https://vuldb.com/?actor.zerobot)
|
||||
|
||||
## IOC - Indicator of Compromise
|
||||
|
||||
These _indicators of compromise_ (IOC) indicate associated network resources which are known to be part of research and attack activities of Zerobot.
|
||||
|
||||
ID | IP address | Hostname | Campaign | Confidence
|
||||
-- | ---------- | -------- | -------- | ----------
|
||||
1 | [176.65.137.5](https://vuldb.com/?ip.176.65.137.5) | - | - | High
|
||||
|
||||
## References
|
||||
|
||||
The following list contains _external sources_ which discuss the actor and the associated activities:
|
||||
|
||||
* https://www.fortinet.com/blog/threat-research/zerobot-new-go-based-botnet-campaign-targets-multiple-vulnerabilities
|
||||
|
||||
## Literature
|
||||
|
||||
The following _articles_ explain our unique predictive cyber threat intelligence:
|
||||
|
||||
* [VulDB Cyber Threat Intelligence Documentation](https://vuldb.com/?kb.cti)
|
||||
* [Cyber Threat Intelligence - Early Anticipation of Attacks](https://www.scip.ch/en/?labs.20201022)
|
||||
|
||||
## License
|
||||
|
||||
(c) [1997-2022](https://vuldb.com/?kb.changelog) by [vuldb.com](https://vuldb.com/?kb.about). All data on this page is shared under the license [CC BY-NC-SA 4.0](https://creativecommons.org/licenses/by-nc-sa/4.0/). Questions? Check the [FAQ](https://vuldb.com/?kb.faq), read the [documentation](https://vuldb.com/?kb) or [contact us](https://vuldb.com/?contact)!
|
|
@ -150,19 +150,19 @@ ID | Type | Indicator | Confidence
|
|||
20 | File | `/dashboard/reports/logs/view` | High
|
||||
21 | File | `/debian/patches/load_ppp_generic_if_needed` | High
|
||||
22 | File | `/debug/pprof` | Medium
|
||||
23 | File | `/ebics-server/ebics.aspx` | High
|
||||
24 | File | `/egroupware/index.php` | High
|
||||
25 | File | `/etc/hosts` | Medium
|
||||
26 | File | `/forum/away.php` | High
|
||||
27 | File | `/fuel/sitevariables/delete/4` | High
|
||||
28 | File | `/goform/setmac` | High
|
||||
29 | File | `/goform/wizard_end` | High
|
||||
30 | File | `/hprms/admin/doctors/manage_doctor.php` | High
|
||||
31 | File | `/index.php` | Medium
|
||||
32 | File | `/index.php?module=entities/entities` | High
|
||||
23 | File | `/Default/Bd` | Medium
|
||||
24 | File | `/ebics-server/ebics.aspx` | High
|
||||
25 | File | `/egroupware/index.php` | High
|
||||
26 | File | `/etc/hosts` | Medium
|
||||
27 | File | `/forum/away.php` | High
|
||||
28 | File | `/forums/editforum.php` | High
|
||||
29 | File | `/fuel/sitevariables/delete/4` | High
|
||||
30 | File | `/goform/setmac` | High
|
||||
31 | File | `/goform/wizard_end` | High
|
||||
32 | File | `/hprms/admin/doctors/manage_doctor.php` | High
|
||||
33 | ... | ... | ...
|
||||
|
||||
There are 277 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 282 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -77,35 +77,36 @@ ID | Type | Indicator | Confidence
|
|||
16 | File | `/api/addusers` | High
|
||||
17 | File | `/api/user/upsert/<uuid>` | High
|
||||
18 | File | `/bits/stl_vector.h` | High
|
||||
19 | File | `/cgi-bin/wlogin.cgi` | High
|
||||
20 | File | `/common/info.cgi` | High
|
||||
21 | File | `/dashboard/add-portfolio.php` | High
|
||||
22 | File | `/dashboard/updatelogo.php` | High
|
||||
23 | File | `/designer/add/layout` | High
|
||||
24 | File | `/filemanager/upload/drop` | High
|
||||
25 | File | `/foms/place-order.php` | High
|
||||
26 | File | `/getImage` | Medium
|
||||
27 | File | `/goform/wizard_end` | High
|
||||
28 | File | `/h/calendar` | Medium
|
||||
29 | File | `/h/compose` | Medium
|
||||
30 | File | `/h/search?action=voicemail&action=listen` | High
|
||||
31 | File | `/htmldoc/htmldoc/html.cxx` | High
|
||||
32 | File | `/index.php` | Medium
|
||||
33 | File | `/librarian/bookdetails.php` | High
|
||||
34 | File | `/login.php` | Medium
|
||||
35 | File | `/loginVaLidation.php` | High
|
||||
36 | File | `/manage-apartment.php` | High
|
||||
37 | File | `/manager/index.php` | High
|
||||
38 | File | `/mcategory.php` | High
|
||||
39 | File | `/mkshop/Men/profile.php` | High
|
||||
40 | File | `/new` | Low
|
||||
41 | File | `/Noxen-master/users.php` | High
|
||||
42 | File | `/opac/Actions.php?a=login` | High
|
||||
43 | File | `/out.php` | Medium
|
||||
44 | File | `/pages/animals.php` | High
|
||||
45 | ... | ... | ...
|
||||
19 | File | `/bsms_ci/index.php` | High
|
||||
20 | File | `/cgi-bin/wlogin.cgi` | High
|
||||
21 | File | `/common/info.cgi` | High
|
||||
22 | File | `/dashboard/add-portfolio.php` | High
|
||||
23 | File | `/dashboard/updatelogo.php` | High
|
||||
24 | File | `/designer/add/layout` | High
|
||||
25 | File | `/filemanager/upload/drop` | High
|
||||
26 | File | `/foms/place-order.php` | High
|
||||
27 | File | `/getImage` | Medium
|
||||
28 | File | `/goform/wizard_end` | High
|
||||
29 | File | `/h/calendar` | Medium
|
||||
30 | File | `/h/compose` | Medium
|
||||
31 | File | `/h/search?action=voicemail&action=listen` | High
|
||||
32 | File | `/htmldoc/htmldoc/html.cxx` | High
|
||||
33 | File | `/index.php` | Medium
|
||||
34 | File | `/librarian/bookdetails.php` | High
|
||||
35 | File | `/login.php` | Medium
|
||||
36 | File | `/loginVaLidation.php` | High
|
||||
37 | File | `/manage-apartment.php` | High
|
||||
38 | File | `/manager/index.php` | High
|
||||
39 | File | `/mcategory.php` | High
|
||||
40 | File | `/mkshop/Men/profile.php` | High
|
||||
41 | File | `/new` | Low
|
||||
42 | File | `/Noxen-master/users.php` | High
|
||||
43 | File | `/opac/Actions.php?a=login` | High
|
||||
44 | File | `/out.php` | Medium
|
||||
45 | File | `/pages/animals.php` | High
|
||||
46 | ... | ... | ...
|
||||
|
||||
There are 389 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 394 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -80,32 +80,32 @@ ID | Type | Indicator | Confidence
|
|||
20 | File | `/groups/31-twitter-basics` | High
|
||||
21 | File | `/login` | Low
|
||||
22 | File | `/modules/profile/index.php` | High
|
||||
23 | File | `/tmp` | Low
|
||||
24 | File | `/tmp/before` | Medium
|
||||
25 | File | `/User/saveUser` | High
|
||||
26 | File | `/usr/bin/vmware-mount` | High
|
||||
27 | File | `/var/WEB-GUI/cgi-bin/downloadfile.cgi` | High
|
||||
28 | File | `/WEB-INF/web.xml` | High
|
||||
29 | File | `/_vti_pvt/access.cnf` | High
|
||||
30 | File | `3/qq_connect2.0/API/class/ErrorCase.class.php` | High
|
||||
31 | File | `accountsettings_add.html` | High
|
||||
32 | File | `aclient.exe` | Medium
|
||||
33 | File | `adclick.php` | Medium
|
||||
34 | File | `addentry.php` | Medium
|
||||
35 | File | `admin.php` | Medium
|
||||
36 | File | `admin.php?c=update&f=unzip` | High
|
||||
37 | File | `admin/ajax/op_kandidat.php` | High
|
||||
38 | File | `admin/conf_users_edit.php` | High
|
||||
39 | File | `admin/domain-fields/` | High
|
||||
40 | File | `admin/index.asp` | High
|
||||
41 | File | `admin/member_deal.php` | High
|
||||
42 | File | `admin/news.php` | High
|
||||
43 | File | `AdminLoginInterceptor.java` | High
|
||||
44 | File | `admins.js` | Medium
|
||||
45 | File | `advancedsearch.php` | High
|
||||
23 | File | `/sys/dict/queryTableData` | High
|
||||
24 | File | `/tmp` | Low
|
||||
25 | File | `/tmp/before` | Medium
|
||||
26 | File | `/User/saveUser` | High
|
||||
27 | File | `/usr/bin/vmware-mount` | High
|
||||
28 | File | `/var/WEB-GUI/cgi-bin/downloadfile.cgi` | High
|
||||
29 | File | `/WEB-INF/web.xml` | High
|
||||
30 | File | `/_vti_pvt/access.cnf` | High
|
||||
31 | File | `3/qq_connect2.0/API/class/ErrorCase.class.php` | High
|
||||
32 | File | `accountsettings_add.html` | High
|
||||
33 | File | `aclient.exe` | Medium
|
||||
34 | File | `adclick.php` | Medium
|
||||
35 | File | `addentry.php` | Medium
|
||||
36 | File | `admin.php` | Medium
|
||||
37 | File | `admin.php?c=update&f=unzip` | High
|
||||
38 | File | `admin/ajax/op_kandidat.php` | High
|
||||
39 | File | `admin/conf_users_edit.php` | High
|
||||
40 | File | `admin/domain-fields/` | High
|
||||
41 | File | `admin/index.asp` | High
|
||||
42 | File | `admin/member_deal.php` | High
|
||||
43 | File | `admin/news.php` | High
|
||||
44 | File | `AdminLoginInterceptor.java` | High
|
||||
45 | File | `admins.js` | Medium
|
||||
46 | ... | ... | ...
|
||||
|
||||
There are 396 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 395 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -98,7 +98,7 @@ ID | Type | Indicator | Confidence
|
|||
40 | File | `/var/log/nginx` | High
|
||||
41 | ... | ... | ...
|
||||
|
||||
There are 354 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 356 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -10,10 +10,10 @@ These _countries_ are directly (e.g. origin of attacks) or indirectly (e.g. acce
|
|||
|
||||
* [VN](https://vuldb.com/?country.vn)
|
||||
* [US](https://vuldb.com/?country.us)
|
||||
* [SE](https://vuldb.com/?country.se)
|
||||
* [NL](https://vuldb.com/?country.nl)
|
||||
* ...
|
||||
|
||||
There are 5 more country items available. Please use our online service to access the data.
|
||||
There are 7 more country items available. Please use our online service to access the data.
|
||||
|
||||
## Actors
|
||||
|
||||
|
@ -167,7 +167,7 @@ _Tactics, techniques, and procedures_ (TTP) summarize the suspected MITRE ATT&CK
|
|||
|
||||
ID | Technique | Weakness | Description | Confidence
|
||||
-- | --------- | -------- | ----------- | ----------
|
||||
1 | T1006 | CWE-21, CWE-22 | Pathname Traversal | High
|
||||
1 | T1006 | CWE-21, CWE-22, CWE-23 | Pathname Traversal | High
|
||||
2 | T1040 | CWE-294, CWE-319 | Authentication Bypass by Capture-replay | High
|
||||
3 | T1055 | CWE-74 | Injection | High
|
||||
4 | T1059 | CWE-88, CWE-94 | Cross Site Scripting | High
|
||||
|
@ -185,33 +185,33 @@ ID | Type | Indicator | Confidence
|
|||
1 | File | `.../gogo/` | Medium
|
||||
2 | File | `/.ssh/authorized_keys` | High
|
||||
3 | File | `/admin.php/Admin/adminadd.html` | High
|
||||
4 | File | `/admin/controller/JobLogController.java` | High
|
||||
5 | File | `/Admin/dashboard.php` | High
|
||||
6 | File | `/api/user/password/sent-reset-email` | High
|
||||
7 | File | `/asms/admin/mechanics/manage_mechanic.php` | High
|
||||
8 | File | `/asms/classes/Master.php?f=delete_mechanic` | High
|
||||
9 | File | `/asms/classes/Master.php?f=delete_service` | High
|
||||
10 | File | `/bsms_ci/index.php` | High
|
||||
11 | File | `/bsms_ci/index.php/book` | High
|
||||
12 | File | `/bsms_ci/index.php/user/edit_user/` | High
|
||||
13 | File | `/carbon/ndatasource/validateconnection/ajaxprocessor.jsp` | High
|
||||
14 | File | `/cgi-bin/wlogin.cgi` | High
|
||||
15 | File | `/Content/Template/root/reverse-shell.aspx` | High
|
||||
16 | File | `/diag_ping_admin.asp` | High
|
||||
17 | File | `/diag_tracert_admin.asp` | High
|
||||
18 | File | `/face-recognition-php/facepay-master/camera.php` | High
|
||||
19 | File | `/forum/away.php` | High
|
||||
20 | File | `/gpac/src/bifs/unquantize.c` | High
|
||||
21 | File | `/hrm/controller/employee.php` | High
|
||||
22 | File | `/index.php` | Medium
|
||||
23 | File | `/index/user/user_edit.html` | High
|
||||
24 | File | `/login` | Low
|
||||
25 | File | `/login.php` | Medium
|
||||
26 | File | `/Member/memberedit.html` | High
|
||||
27 | File | `/out.php` | Medium
|
||||
4 | File | `/api/audits` | Medium
|
||||
5 | File | `/bsms_ci/index.php` | High
|
||||
6 | File | `/bsms_ci/index.php/book` | High
|
||||
7 | File | `/bsms_ci/index.php/user/edit_user/` | High
|
||||
8 | File | `/carbon/ndatasource/validateconnection/ajaxprocessor.jsp` | High
|
||||
9 | File | `/cgi-bin/wlogin.cgi` | High
|
||||
10 | File | `/Content/Template/root/reverse-shell.aspx` | High
|
||||
11 | File | `/face-recognition-php/facepay-master/camera.php` | High
|
||||
12 | File | `/forum/away.php` | High
|
||||
13 | File | `/goform/addressNat` | High
|
||||
14 | File | `/goform/CertListInfo` | High
|
||||
15 | File | `/goform/IPSECsave` | High
|
||||
16 | File | `/goform/L7Im` | Medium
|
||||
17 | File | `/goform/NatStaticSetting` | High
|
||||
18 | File | `/goform/qossetting` | High
|
||||
19 | File | `/goform/SafeClientFilter` | High
|
||||
20 | File | `/goform/SafeMacFilter` | High
|
||||
21 | File | `/goform/SafeUrlFilter` | High
|
||||
22 | File | `/goform/SysToolReboot` | High
|
||||
23 | File | `/goform/SysToolRestoreSet` | High
|
||||
24 | File | `/goform/VirtualSer` | High
|
||||
25 | File | `/gpac/src/bifs/unquantize.c` | High
|
||||
26 | File | `/hrm/controller/employee.php` | High
|
||||
27 | File | `/index.php` | Medium
|
||||
28 | ... | ... | ...
|
||||
|
||||
There are 233 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 240 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -13,7 +13,7 @@ These _countries_ are directly (e.g. origin of attacks) or indirectly (e.g. acce
|
|||
* [US](https://vuldb.com/?country.us)
|
||||
* ...
|
||||
|
||||
There are 5 more country items available. Please use our online service to access the data.
|
||||
There are 6 more country items available. Please use our online service to access the data.
|
||||
|
||||
## Actors
|
||||
|
||||
|
@ -181,18 +181,18 @@ ID | Type | Indicator | Confidence
|
|||
13 | File | `/context/%2e/WEB-INF/web.xml` | High
|
||||
14 | File | `/debug/pprof` | Medium
|
||||
15 | File | `/diagnostic/editclient.php` | High
|
||||
16 | File | `/etc/sudoers` | Medium
|
||||
17 | File | `/filemanager/php/connector.php` | High
|
||||
18 | File | `/forum/away.php` | High
|
||||
19 | File | `/goform/wizard_end` | High
|
||||
20 | File | `/index.php?module=global_lists/lists` | High
|
||||
21 | File | `/modules/caddyhttp/rewrite/rewrite.go` | High
|
||||
22 | File | `/modules/profile/index.php` | High
|
||||
23 | File | `/okm:root` | Medium
|
||||
24 | File | `/opt/zimbra/jetty/webapps/zimbra/public` | High
|
||||
25 | File | `/out.php` | Medium
|
||||
26 | File | `/proxy` | Low
|
||||
27 | File | `/public_html/animals` | High
|
||||
16 | File | `/filemanager/php/connector.php` | High
|
||||
17 | File | `/forum/away.php` | High
|
||||
18 | File | `/goform/wizard_end` | High
|
||||
19 | File | `/index.php?module=global_lists/lists` | High
|
||||
20 | File | `/modules/caddyhttp/rewrite/rewrite.go` | High
|
||||
21 | File | `/modules/profile/index.php` | High
|
||||
22 | File | `/okm:root` | Medium
|
||||
23 | File | `/opt/zimbra/jetty/webapps/zimbra/public` | High
|
||||
24 | File | `/out.php` | Medium
|
||||
25 | File | `/proxy` | Low
|
||||
26 | File | `/public_html/animals` | High
|
||||
27 | File | `/self.key` | Medium
|
||||
28 | File | `/spip.php` | Medium
|
||||
29 | File | `/sqfs/bin/sccd` | High
|
||||
30 | File | `/text/pdf/PdfReader.java` | High
|
||||
|
@ -201,7 +201,7 @@ ID | Type | Indicator | Confidence
|
|||
33 | File | `/usr/bin/pkexec` | High
|
||||
34 | ... | ... | ...
|
||||
|
||||
There are 288 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 291 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -88,7 +88,7 @@ ID | Type | Indicator | Confidence
|
|||
29 | File | `/index.php?module=entities/fields&entities_id=24` | High
|
||||
30 | ... | ... | ...
|
||||
|
||||
There are 254 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 256 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -58,7 +58,7 @@ ID | Technique | Weakness | Description | Confidence
|
|||
6 | T1068 | CWE-264, CWE-266, CWE-269, CWE-271, CWE-284 | Execution with Unnecessary Privileges | High
|
||||
7 | ... | ... | ... | ...
|
||||
|
||||
There are 23 more TTP items available. Please use our online service to access the data.
|
||||
There are 24 more TTP items available. Please use our online service to access the data.
|
||||
|
||||
## IOA - Indicator of Attack
|
||||
|
||||
|
@ -74,36 +74,36 @@ ID | Type | Indicator | Confidence
|
|||
6 | File | `/admin/edit_members.php` | High
|
||||
7 | File | `/admin/foldernotice/list` | High
|
||||
8 | File | `/admin/fst_upload.inc.php` | High
|
||||
9 | File | `/admin/image/list` | High
|
||||
10 | File | `/admin/users/index.php` | High
|
||||
11 | File | `/api` | Low
|
||||
12 | File | `/asms/classes/Master.php?f=delete_service` | High
|
||||
13 | File | `/baseOpLog.do` | High
|
||||
14 | File | `/bsms_ci/index.php/user/edit_user/` | High
|
||||
15 | File | `/buspassms/download-pass.php` | High
|
||||
16 | File | `/cgi-bin/cstecgi.cgi` | High
|
||||
17 | File | `/classes/Users.php?f=delete_client` | High
|
||||
18 | File | `/clients/listclients.php` | High
|
||||
19 | File | `/clients/profile` | High
|
||||
20 | File | `/confirm` | Medium
|
||||
21 | File | `/contacts/listcontacts.php` | High
|
||||
22 | File | `/csms/?page=contact_us` | High
|
||||
23 | File | `/csms/admin/?page=user/manage_user` | High
|
||||
24 | File | `/csms/admin/storages/view_storage.php` | High
|
||||
25 | File | `/debug` | Low
|
||||
26 | File | `/Default/Bd` | Medium
|
||||
27 | File | `/diagnostic/editclient.php` | High
|
||||
28 | File | `/goform/AddSysLogRule` | High
|
||||
29 | File | `/goform/PowerSaveSet` | High
|
||||
9 | File | `/admin/users/index.php` | High
|
||||
10 | File | `/api` | Low
|
||||
11 | File | `/asms/classes/Master.php?f=delete_service` | High
|
||||
12 | File | `/baseOpLog.do` | High
|
||||
13 | File | `/bsms_ci/index.php/user/edit_user/` | High
|
||||
14 | File | `/buspassms/download-pass.php` | High
|
||||
15 | File | `/cgi-bin/cstecgi.cgi` | High
|
||||
16 | File | `/classes/Users.php?f=delete_client` | High
|
||||
17 | File | `/clients/listclients.php` | High
|
||||
18 | File | `/clients/profile` | High
|
||||
19 | File | `/confirm` | Medium
|
||||
20 | File | `/contacts/listcontacts.php` | High
|
||||
21 | File | `/csms/?page=contact_us` | High
|
||||
22 | File | `/csms/admin/?page=user/manage_user` | High
|
||||
23 | File | `/csms/admin/storages/view_storage.php` | High
|
||||
24 | File | `/debug` | Low
|
||||
25 | File | `/Default/Bd` | Medium
|
||||
26 | File | `/diagnostic/editclient.php` | High
|
||||
27 | File | `/goform/AddSysLogRule` | High
|
||||
28 | File | `/goform/PowerSaveSet` | High
|
||||
29 | File | `/goform/SafeEmailFilter` | High
|
||||
30 | File | `/goform/SetIpMacBind` | High
|
||||
31 | File | `/goform/setSnmpInfo` | High
|
||||
32 | File | `/goform/setUplinkInfo` | High
|
||||
33 | File | `/home/hjsz/jsonlint/src/lexer` | High
|
||||
34 | File | `/hrm/employeeview.php` | High
|
||||
35 | File | `/htdocs/upnpinc/gena.php` | High
|
||||
33 | File | `/goform/SysToolReboot` | High
|
||||
34 | File | `/home/hjsz/jsonlint/src/lexer` | High
|
||||
35 | File | `/hrm/employeeview.php` | High
|
||||
36 | ... | ... | ...
|
||||
|
||||
There are 309 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 307 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -112,7 +112,7 @@ ID | Type | Indicator | Confidence
|
|||
46 | File | `ashnews.php/ashheadlines.php` | High
|
||||
47 | ... | ... | ...
|
||||
|
||||
There are 408 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 410 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -118,50 +118,48 @@ These _indicators of attack_ (IOA) list the potential fragments used for technic
|
|||
|
||||
ID | Type | Indicator | Confidence
|
||||
-- | ---- | --------- | ----------
|
||||
1 | File | `/.ssh/authorized_keys` | High
|
||||
2 | File | `/admin/admin.php` | High
|
||||
3 | File | `/admin/edit_members.php` | High
|
||||
4 | File | `/admin/store.php` | High
|
||||
5 | File | `/admin/submit-articles` | High
|
||||
6 | File | `/admin/users/index.php` | High
|
||||
7 | File | `/api/sys_username_passwd.cmd` | High
|
||||
8 | File | `/asms/admin/?page=transactions/manage_transaction` | High
|
||||
9 | File | `/asms/admin/mechanics/view_mechanic.php` | High
|
||||
10 | File | `/asms/admin/products/manage_product.php` | High
|
||||
11 | File | `/asms/products/view_product.php` | High
|
||||
12 | File | `/balance/service/list` | High
|
||||
1 | File | `.FBCIndex` | Medium
|
||||
2 | File | `/.ssh/authorized_keys` | High
|
||||
3 | File | `/admin/admin.php` | High
|
||||
4 | File | `/admin/edit_members.php` | High
|
||||
5 | File | `/admin/users/index.php` | High
|
||||
6 | File | `/api/sys_username_passwd.cmd` | High
|
||||
7 | File | `/asms/admin/?page=transactions/manage_transaction` | High
|
||||
8 | File | `/asms/admin/mechanics/view_mechanic.php` | High
|
||||
9 | File | `/asms/admin/products/manage_product.php` | High
|
||||
10 | File | `/asms/products/view_product.php` | High
|
||||
11 | File | `/balance/service/list` | High
|
||||
12 | File | `/blog/comment` | High
|
||||
13 | File | `/bsms_ci/index.php` | High
|
||||
14 | File | `/bsms_ci/index.php/user/edit_user/` | High
|
||||
15 | File | `/calendar/viewcalendar.php` | High
|
||||
16 | File | `/carbon/ndatasource/validateconnection/ajaxprocessor.jsp` | High
|
||||
17 | File | `/cgi-bin/qcmap_auth` | High
|
||||
18 | File | `/cgi-bin/wlogin.cgi` | High
|
||||
19 | File | `/classes/Master.php?f=delete_appointment` | High
|
||||
20 | File | `/classes/Master.php?f=delete_reservation` | High
|
||||
21 | File | `/classes/Users.php?f=delete_client` | High
|
||||
22 | File | `/clients/listclients.php` | High
|
||||
23 | File | `/CommunitySSORedirect.jsp` | High
|
||||
24 | File | `/Content/Template/root/reverse-shell.aspx` | High
|
||||
25 | File | `/Default/Bd` | Medium
|
||||
26 | File | `/device/acceptBind` | High
|
||||
27 | File | `/diagnostic/editclient.php` | High
|
||||
28 | File | `/event/admin/?page=user/list` | High
|
||||
29 | File | `/face-recognition-php/facepay-master/camera.php` | High
|
||||
30 | File | `/filemanager/php/connector.php` | High
|
||||
31 | File | `/forum/away.php` | High
|
||||
32 | File | `/general/search.php?searchtype=simple` | High
|
||||
33 | File | `/HNAP1` | Low
|
||||
34 | File | `/hrm/controller/employee.php` | High
|
||||
35 | File | `/hrm/employeeadd.php` | High
|
||||
36 | File | `/ims/login.php` | High
|
||||
37 | File | `/index.php/purchase_order/browse_data` | High
|
||||
38 | File | `/index.php?module=configuration/application` | High
|
||||
39 | File | `/index.php?module=entities/fields&entities_id=24` | High
|
||||
40 | File | `/index.php?module=entities/forms&entities_id=24` | High
|
||||
41 | File | `/index/user/user_edit.html` | High
|
||||
42 | ... | ... | ...
|
||||
17 | File | `/cgi-bin/wlogin.cgi` | High
|
||||
18 | File | `/clients/listclients.php` | High
|
||||
19 | File | `/CommunitySSORedirect.jsp` | High
|
||||
20 | File | `/Content/Template/root/reverse-shell.aspx` | High
|
||||
21 | File | `/Default/Bd` | Medium
|
||||
22 | File | `/device/acceptBind` | High
|
||||
23 | File | `/diagnostic/editclient.php` | High
|
||||
24 | File | `/event/admin/?page=user/list` | High
|
||||
25 | File | `/face-recognition-php/facepay-master/camera.php` | High
|
||||
26 | File | `/forum/away.php` | High
|
||||
27 | File | `/general/search.php?searchtype=simple` | High
|
||||
28 | File | `/goform/L7Im` | Medium
|
||||
29 | File | `/HNAP1` | Low
|
||||
30 | File | `/hrm/controller/employee.php` | High
|
||||
31 | File | `/hrm/employeeadd.php` | High
|
||||
32 | File | `/hrm/employeeview.php` | High
|
||||
33 | File | `/ims/login.php` | High
|
||||
34 | File | `/index.php/purchase_order/browse_data` | High
|
||||
35 | File | `/index.php?module=configuration/application` | High
|
||||
36 | File | `/index.php?module=entities/fields&entities_id=24` | High
|
||||
37 | File | `/index.php?module=entities/forms&entities_id=24` | High
|
||||
38 | File | `/index/user/user_edit.html` | High
|
||||
39 | File | `/Member/memberedit.html` | High
|
||||
40 | ... | ... | ...
|
||||
|
||||
There are 364 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 343 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -64,9 +64,10 @@ ID | Type | Indicator | Confidence
|
|||
7 | File | `/thruk/#cgi-bin/extinfo.cgi?type=2` | High
|
||||
8 | File | `/uncpath/` | Medium
|
||||
9 | File | `/wp-admin/options.php` | High
|
||||
10 | ... | ... | ...
|
||||
10 | File | `AppCompatCache.exe` | High
|
||||
11 | ... | ... | ...
|
||||
|
||||
There are 79 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 80 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -98,9 +98,10 @@ ID | Type | Indicator | Confidence
|
|||
29 | File | `/modules/caddyhttp/rewrite/rewrite.go` | High
|
||||
30 | File | `/pages/apply_vacancy.php` | High
|
||||
31 | File | `/pms/update_patient.php` | High
|
||||
32 | ... | ... | ...
|
||||
32 | File | `/proc/<PID>/mem` | High
|
||||
33 | ... | ... | ...
|
||||
|
||||
There are 277 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 278 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -158,7 +158,7 @@ ID | Type | Indicator | Confidence
|
|||
95 | File | `category_list.php` | High
|
||||
96 | ... | ... | ...
|
||||
|
||||
There are 852 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 850 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -0,0 +1,180 @@
|
|||
# DDoS - Cyber Threat Intelligence
|
||||
|
||||
These _indicators_ were reported, collected, and generated during the [VulDB CTI analysis](https://vuldb.com/?kb.cti) of the campaign known as _DDoS_. The _activity monitoring_ correlates data from social media, forums, chat rooms, and darknet markets. It helps to determine associated actors, specific activities, expected intentions, emerging research, and ongoing attacks. Our unique _predictive model_ uses _big data_ to forecast activities and their characteristics.
|
||||
|
||||
_Live data_ and more _analysis capabilities_ are available at [https://vuldb.com/?actor](https://vuldb.com/?actor)
|
||||
|
||||
## Countries
|
||||
|
||||
These _countries_ are directly (e.g. origin of attacks) or indirectly (e.g. access by proxy) associated with DDoS:
|
||||
|
||||
* [US](https://vuldb.com/?country.us)
|
||||
* [CN](https://vuldb.com/?country.cn)
|
||||
* [RU](https://vuldb.com/?country.ru)
|
||||
* ...
|
||||
|
||||
There are 1 more country items available. Please use our online service to access the data.
|
||||
|
||||
## Actors
|
||||
|
||||
These _actors_ are associated with DDoS or other actors linked to the campaign.
|
||||
|
||||
ID | Actor | Confidence
|
||||
-- | ----- | ----------
|
||||
1 | [Mirai](https://vuldb.com/?actor.mirai) | High
|
||||
2 | [Gafgyt](https://vuldb.com/?actor.gafgyt) | High
|
||||
3 | [Moobot](https://vuldb.com/?actor.moobot) | High
|
||||
4 | ... | ...
|
||||
|
||||
There are 2 more actor items available. Please use our online service to access the data.
|
||||
|
||||
## IOC - Indicator of Compromise
|
||||
|
||||
These _indicators of compromise_ (IOC) indicate associated network resources which are known to be part of research and attack activities of DDoS.
|
||||
|
||||
ID | IP address | Hostname | Actor | Confidence
|
||||
-- | ---------- | -------- | ----- | ----------
|
||||
1 | [45.61.136.130](https://vuldb.com/?ip.45.61.136.130) | - | [Mirai](https://vuldb.com/?actor.mirai) | High
|
||||
2 | [45.61.186.13](https://vuldb.com/?ip.45.61.186.13) | - | [Mirai](https://vuldb.com/?actor.mirai) | High
|
||||
3 | [46.29.166.105](https://vuldb.com/?ip.46.29.166.105) | - | [Mirai](https://vuldb.com/?actor.mirai) | High
|
||||
4 | [46.249.32.109](https://vuldb.com/?ip.46.249.32.109) | reverse.hostingbb.com | [Gafgyt](https://vuldb.com/?actor.gafgyt) | High
|
||||
5 | ... | ... | ... | ...
|
||||
|
||||
There are 15 more IOC items available. Please use our online service to access the data.
|
||||
|
||||
## TTP - Tactics, Techniques, Procedures
|
||||
|
||||
_Tactics, techniques, and procedures_ (TTP) summarize the suspected MITRE ATT&CK techniques used within DDoS. This data is unique as it uses our predictive model for actor profiling.
|
||||
|
||||
ID | Technique | Weakness | Description | Confidence
|
||||
-- | --------- | -------- | ----------- | ----------
|
||||
1 | T1006 | CWE-21, CWE-22, CWE-23 | Pathname Traversal | High
|
||||
2 | T1055 | CWE-74 | Injection | High
|
||||
3 | T1059 | CWE-94 | Cross Site Scripting | High
|
||||
4 | T1059.007 | CWE-79, CWE-80 | Cross Site Scripting | High
|
||||
5 | ... | ... | ... | ...
|
||||
|
||||
There are 14 more TTP items available. Please use our online service to access the data.
|
||||
|
||||
## IOA - Indicator of Attack
|
||||
|
||||
These _indicators of attack_ (IOA) list the potential fragments used for technical activities like reconnaissance, exploitation, privilege escalation, and exfiltration during DDoS. This data is unique as it uses our predictive model for actor profiling.
|
||||
|
||||
ID | Type | Indicator | Confidence
|
||||
-- | ---- | --------- | ----------
|
||||
1 | File | `/about.php` | Medium
|
||||
2 | File | `/admin.php` | Medium
|
||||
3 | File | `/admin/doctors/view_doctor.php` | High
|
||||
4 | File | `/admin/modules/bibliography/index.php` | High
|
||||
5 | File | `/admin/students/manage.php` | High
|
||||
6 | File | `/adminlogin.asp` | High
|
||||
7 | File | `/app/controller/Books.php` | High
|
||||
8 | File | `/aqpg/users/login.php` | High
|
||||
9 | File | `/controller/Index.php` | High
|
||||
10 | File | `/coreframe/app/content/admin/content.php` | High
|
||||
11 | File | `/dl/dl_print.php` | High
|
||||
12 | File | `/etc/master.passwd` | High
|
||||
13 | File | `/etc/passwd` | Medium
|
||||
14 | File | `/forum/away.php` | High
|
||||
15 | File | `/goform/AddSysLogRule` | High
|
||||
16 | File | `/goform/Diagnosis` | High
|
||||
17 | File | `/Hospital-Management-System-master/contact.php` | High
|
||||
18 | File | `/include/friends.inc.php` | High
|
||||
19 | File | `/index.php?module=configuration/application` | High
|
||||
20 | File | `/members/view_member.php` | High
|
||||
21 | File | `/plesk-site-preview/` | High
|
||||
22 | File | `/scas/admin/` | Medium
|
||||
23 | File | `/servlet/webacc` | High
|
||||
24 | File | `/sitemagic/upgrade.php` | High
|
||||
25 | File | `/src/njs/src/njs_module.c` | High
|
||||
26 | File | `/tmp` | Low
|
||||
27 | File | `/userui/ticket_list.php` | High
|
||||
28 | File | `/vloggers_merch/classes/Master.php?f=delete_category` | High
|
||||
29 | File | `/wp-admin/options-general.php` | High
|
||||
30 | File | `/zm/index.php` | High
|
||||
31 | File | `abook_database.php` | High
|
||||
32 | File | `accounts/inc/include.php` | High
|
||||
33 | File | `adaptive-images-script.php` | High
|
||||
34 | File | `adclick.php` | Medium
|
||||
35 | File | `additem.asp` | Medium
|
||||
36 | File | `adherents/subscription/info.php` | High
|
||||
37 | File | `admin.asp` | Medium
|
||||
38 | File | `admin.php` | Medium
|
||||
39 | File | `admin/admin.php` | High
|
||||
40 | File | `admin/admin_users.php` | High
|
||||
41 | File | `admin/article_save.php` | High
|
||||
42 | File | `admin/general.php` | High
|
||||
43 | File | `admin/header.php` | High
|
||||
44 | File | `admin/inc/change_action.php` | High
|
||||
45 | File | `admin/index.php` | High
|
||||
46 | File | `admin/info.php` | High
|
||||
47 | File | `admin/login.asp` | High
|
||||
48 | File | `admin/manage-comments.php` | High
|
||||
49 | File | `admin/manage-news.php` | High
|
||||
50 | File | `admin/plugin-settings.php` | High
|
||||
51 | File | `admin/specials.php` | High
|
||||
52 | File | `admin:de` | Medium
|
||||
53 | File | `admincp/auth/checklogin.php` | High
|
||||
54 | File | `admincp/auth/secure.php` | High
|
||||
55 | File | `administrator/components/com_media/helpers/media.php` | High
|
||||
56 | File | `administrator/index.php` | High
|
||||
57 | File | `admin_login.asp` | High
|
||||
58 | File | `ajax_url.php` | Medium
|
||||
59 | File | `album_portal.php` | High
|
||||
60 | File | `al_initialize.php` | High
|
||||
61 | File | `anjel.index.php` | High
|
||||
62 | File | `annonces-p-f.php` | High
|
||||
63 | File | `announce.php` | Medium
|
||||
64 | File | `announcement.php` | High
|
||||
65 | File | `announcements.php` | High
|
||||
66 | File | `app/admin/routing/edit-bgp-mapping-search.php` | High
|
||||
67 | File | `app/models/user.rb` | High
|
||||
68 | File | `application/config/config.php` | High
|
||||
69 | File | `application/controllers/basedata/inventory.php` | High
|
||||
70 | File | `apply.cgi` | Medium
|
||||
71 | File | `apps/app_article/controller/rating.php` | High
|
||||
72 | File | `article.php` | Medium
|
||||
73 | File | `articles.php` | Medium
|
||||
74 | File | `artikel_anzeige.php` | High
|
||||
75 | File | `auktion.cgi` | Medium
|
||||
76 | File | `auth.php` | Medium
|
||||
77 | File | `authfiles/login.asp` | High
|
||||
78 | File | `basket.php` | Medium
|
||||
79 | File | `books.php` | Medium
|
||||
80 | File | `browse-category.php` | High
|
||||
81 | File | `browse.php` | Medium
|
||||
82 | File | `browse_videos.php` | High
|
||||
83 | File | `BrudaNews/BrudaGB` | High
|
||||
84 | File | `bwlist_inc.html` | High
|
||||
85 | File | `calendar.php` | Medium
|
||||
86 | File | `callme_page.php` | High
|
||||
87 | File | `cart.php` | Medium
|
||||
88 | File | `cart_add.php` | Medium
|
||||
89 | File | `case.filemanager.php` | High
|
||||
90 | File | `catalog.php` | Medium
|
||||
91 | File | `catalogshop.php` | High
|
||||
92 | File | `catalogue.asp` | High
|
||||
93 | File | `category.cfm` | Medium
|
||||
94 | File | `category.php` | Medium
|
||||
95 | File | `category_list.php` | High
|
||||
96 | ... | ... | ...
|
||||
|
||||
There are 850 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
The following list contains _external sources_ which discuss the campaign and the associated activities:
|
||||
|
||||
* https://blog.netlab.360.com/new-ddos-botnet-wszeor/
|
||||
* https://blog.netlab.360.com/some_details_of_the_ddos_attacks_targeting_ukraine_and_russia_in_recent_days/
|
||||
|
||||
## Literature
|
||||
|
||||
The following _articles_ explain our unique predictive cyber threat intelligence:
|
||||
|
||||
* [VulDB Cyber Threat Intelligence Documentation](https://vuldb.com/?kb.cti)
|
||||
* [Cyber Threat Intelligence - Early Anticipation of Attacks](https://www.scip.ch/en/?labs.20201022)
|
||||
|
||||
## License
|
||||
|
||||
(c) [1997-2022](https://vuldb.com/?kb.changelog) by [vuldb.com](https://vuldb.com/?kb.about). All data on this page is shared under the license [CC BY-NC-SA 4.0](https://creativecommons.org/licenses/by-nc-sa/4.0/). Questions? Check the [FAQ](https://vuldb.com/?kb.faq), read the [documentation](https://vuldb.com/?kb) or [contact us](https://vuldb.com/?contact)!
|
|
@ -97,16 +97,17 @@ ID | Type | Indicator | Confidence
|
|||
38 | File | `/secure/admin/InsightDefaultCustomFieldConfig.jspa` | High
|
||||
39 | File | `/services/system/setup.json` | High
|
||||
40 | File | `/spip.php` | Medium
|
||||
41 | File | `/uncpath/` | Medium
|
||||
42 | File | `/vloggers_merch/?p=view_product` | High
|
||||
43 | File | `/webconsole/APIController` | High
|
||||
44 | File | `/websocket/exec` | High
|
||||
45 | File | `/whbs/?page=my_bookings` | High
|
||||
46 | File | `/wp-admin/admin-ajax.php` | High
|
||||
47 | File | `/wp-json` | Medium
|
||||
48 | ... | ... | ...
|
||||
41 | File | `/tmp` | Low
|
||||
42 | File | `/uncpath/` | Medium
|
||||
43 | File | `/vloggers_merch/?p=view_product` | High
|
||||
44 | File | `/webconsole/APIController` | High
|
||||
45 | File | `/websocket/exec` | High
|
||||
46 | File | `/whbs/?page=my_bookings` | High
|
||||
47 | File | `/wp-admin/admin-ajax.php` | High
|
||||
48 | File | `/wp-json` | Medium
|
||||
49 | ... | ... | ...
|
||||
|
||||
There are 419 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 425 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -8,8 +8,8 @@ _Live data_ and more _analysis capabilities_ are available at [https://vuldb.com
|
|||
|
||||
These _countries_ are directly (e.g. origin of attacks) or indirectly (e.g. access by proxy) associated with Europe:
|
||||
|
||||
* [US](https://vuldb.com/?country.us)
|
||||
* [JP](https://vuldb.com/?country.jp)
|
||||
* [US](https://vuldb.com/?country.us)
|
||||
* [CN](https://vuldb.com/?country.cn)
|
||||
* ...
|
||||
|
||||
|
@ -7993,30 +7993,30 @@ ID | Type | Indicator | Confidence
|
|||
5 | File | `/admin/fst_upload.inc.php` | High
|
||||
6 | File | `/admin/settings/save.php` | High
|
||||
7 | File | `/admin/submit-articles` | High
|
||||
8 | File | `/balance/service/list` | High
|
||||
9 | File | `/bsms_ci/index.php` | High
|
||||
10 | File | `/bsms_ci/index.php/user/edit_user/` | High
|
||||
11 | File | `/cgi-bin/supervisor/PwdGrp.cgi` | High
|
||||
12 | File | `/cgi-bin/webproc` | High
|
||||
13 | File | `/confirm` | Medium
|
||||
14 | File | `/debug/pprof` | Medium
|
||||
15 | File | `/Default/Bd` | Medium
|
||||
16 | File | `/etc/passwd` | Medium
|
||||
17 | File | `/event/admin/?page=user/list` | High
|
||||
18 | File | `/face-recognition-php/facepay-master/camera.php` | High
|
||||
19 | File | `/forum/away.php` | High
|
||||
8 | File | `/bsms_ci/index.php` | High
|
||||
9 | File | `/bsms_ci/index.php/user/edit_user/` | High
|
||||
10 | File | `/cgi-bin/supervisor/PwdGrp.cgi` | High
|
||||
11 | File | `/cgi-bin/webproc` | High
|
||||
12 | File | `/confirm` | Medium
|
||||
13 | File | `/debug/pprof` | Medium
|
||||
14 | File | `/Default/Bd` | Medium
|
||||
15 | File | `/etc/passwd` | Medium
|
||||
16 | File | `/event/admin/?page=user/list` | High
|
||||
17 | File | `/face-recognition-php/facepay-master/camera.php` | High
|
||||
18 | File | `/forum/away.php` | High
|
||||
19 | File | `/goform/setSnmpInfo` | High
|
||||
20 | File | `/goform/setSysAdm` | High
|
||||
21 | File | `/gpac/src/bifs/unquantize.c` | High
|
||||
22 | File | `/hrm/controller/employee.php` | High
|
||||
23 | File | `/hrm/employeeadd.php` | High
|
||||
24 | File | `/hrm/employeeview.php` | High
|
||||
25 | File | `/index.php` | Medium
|
||||
26 | File | `/index.php/purchase_order/browse_data` | High
|
||||
27 | File | `/index.php?module=entities/fields&entities_id=24` | High
|
||||
28 | File | `/index.php?route=extension/module/so_filter_shop_by/filter_data` | High
|
||||
29 | File | `/modules/caddyhttp/rewrite/rewrite.go` | High
|
||||
30 | File | `/modx/manager/` | High
|
||||
31 | File | `/opt/zimbra/jetty/webapps/zimbra/public` | High
|
||||
21 | File | `/goform/setSysPwd` | High
|
||||
22 | File | `/gpac/src/bifs/unquantize.c` | High
|
||||
23 | File | `/hrm/controller/employee.php` | High
|
||||
24 | File | `/hrm/employeeadd.php` | High
|
||||
25 | File | `/hrm/employeeview.php` | High
|
||||
26 | File | `/includes/login.php` | High
|
||||
27 | File | `/index.php` | Medium
|
||||
28 | File | `/index.php?module=entities/fields&entities_id=24` | High
|
||||
29 | File | `/index.php?route=extension/module/so_filter_shop_by/filter_data` | High
|
||||
30 | File | `/modules/caddyhttp/rewrite/rewrite.go` | High
|
||||
31 | File | `/modx/manager/` | High
|
||||
32 | File | `/out.php` | Medium
|
||||
33 | File | `/pages/processlogin.php` | High
|
||||
34 | File | `/php-sms/admin/quotes/manage_remark.php` | High
|
||||
|
@ -8025,11 +8025,10 @@ ID | Type | Indicator | Confidence
|
|||
37 | File | `/Redcock-Farm/farm/category.php` | High
|
||||
38 | File | `/spip.php` | Medium
|
||||
39 | File | `/sys/duplicate/check` | High
|
||||
40 | File | `/tmp` | Low
|
||||
41 | File | `/transcation.php` | High
|
||||
42 | ... | ... | ...
|
||||
40 | File | `/template/edit` | High
|
||||
41 | ... | ... | ...
|
||||
|
||||
There are 362 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 358 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -56,7 +56,8 @@ ID | Technique | Weakness | Description | Confidence
|
|||
2 | T1040 | CWE-319 | Authentication Bypass by Capture-replay | High
|
||||
3 | T1055 | CWE-74 | Injection | High
|
||||
4 | T1059 | CWE-88, CWE-94 | Cross Site Scripting | High
|
||||
5 | ... | ... | ... | ...
|
||||
5 | T1059.007 | CWE-79, CWE-80, CWE-85 | Cross Site Scripting | High
|
||||
6 | ... | ... | ... | ...
|
||||
|
||||
There are 18 more TTP items available. Please use our online service to access the data.
|
||||
|
||||
|
@ -70,27 +71,27 @@ ID | Type | Indicator | Confidence
|
|||
2 | File | `/admin/controller/JobLogController.java` | High
|
||||
3 | File | `/Admin/dashboard.php` | High
|
||||
4 | File | `/admin/problem_judge.php` | High
|
||||
5 | File | `/api/user/password/sent-reset-email` | High
|
||||
6 | File | `/asms/admin/mechanics/manage_mechanic.php` | High
|
||||
7 | File | `/asms/classes/Master.php?f=delete_mechanic` | High
|
||||
8 | File | `/asms/classes/Master.php?f=delete_service` | High
|
||||
9 | File | `/balance/service/list` | High
|
||||
5 | File | `/api/audits` | Medium
|
||||
6 | File | `/api/user/password/sent-reset-email` | High
|
||||
7 | File | `/asms/admin/mechanics/manage_mechanic.php` | High
|
||||
8 | File | `/asms/classes/Master.php?f=delete_mechanic` | High
|
||||
9 | File | `/asms/classes/Master.php?f=delete_service` | High
|
||||
10 | File | `/bsms_ci/index.php` | High
|
||||
11 | File | `/bsms_ci/index.php/book` | High
|
||||
12 | File | `/bsms_ci/index.php/user/edit_user/` | High
|
||||
13 | File | `/diag_ping_admin.asp` | High
|
||||
14 | File | `/diag_tracert_admin.asp` | High
|
||||
15 | File | `/face-recognition-php/facepay-master/camera.php` | High
|
||||
16 | File | `/gpac/src/bifs/unquantize.c` | High
|
||||
17 | File | `/hrm/controller/employee.php` | High
|
||||
18 | File | `/index/user/user_edit.html` | High
|
||||
19 | File | `/login.php` | Medium
|
||||
20 | File | `/Member/memberedit.html` | High
|
||||
21 | File | `/pages/processlogin.php` | High
|
||||
22 | File | `/plugin/getList` | High
|
||||
16 | File | `/forum/away.php` | High
|
||||
17 | File | `/gpac/src/bifs/unquantize.c` | High
|
||||
18 | File | `/hrm/controller/employee.php` | High
|
||||
19 | File | `/index/user/user_edit.html` | High
|
||||
20 | File | `/leave_system/admin/?page=maintenance/department` | High
|
||||
21 | File | `/login` | Low
|
||||
22 | File | `/login.php` | Medium
|
||||
23 | ... | ... | ...
|
||||
|
||||
There are 194 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 191 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -90,7 +90,7 @@ ID | Type | Indicator | Confidence
|
|||
34 | File | `/php/passport/index.php` | High
|
||||
35 | ... | ... | ...
|
||||
|
||||
There are 299 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 297 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -89,30 +89,29 @@ ID | Type | Indicator | Confidence
|
|||
8 | File | `/files.md5` | Medium
|
||||
9 | File | `/forum/away.php` | High
|
||||
10 | File | `/h/calendar` | Medium
|
||||
11 | File | `/images/` | Medium
|
||||
12 | File | `/inc/extensions.php` | High
|
||||
13 | File | `/index.php` | Medium
|
||||
14 | File | `/lists/index.php` | High
|
||||
15 | File | `/login` | Low
|
||||
16 | File | `/members/view_member.php` | High
|
||||
17 | File | `/modules/profile/index.php` | High
|
||||
18 | File | `/nova/bin/console` | High
|
||||
19 | File | `/nova/bin/detnet` | High
|
||||
20 | File | `/objects/getImageMP4.php` | High
|
||||
21 | File | `/one_church/userregister.php` | High
|
||||
22 | File | `/out.php` | Medium
|
||||
23 | File | `/owa/auth/logon.aspx` | High
|
||||
24 | File | `/public/plugins/` | High
|
||||
25 | File | `/replication` | Medium
|
||||
26 | File | `/req_password_user.php` | High
|
||||
27 | File | `/SAP_Information_System/controllers/add_admin.php` | High
|
||||
28 | File | `/SASWebReportStudio/logonAndRender.do` | High
|
||||
29 | File | `/secure/admin/InsightDefaultCustomFieldConfig.jspa` | High
|
||||
30 | File | `/secure/admin/ViewInstrumentation.jspa` | High
|
||||
31 | File | `/secure/QueryComponent!Default.jspa` | High
|
||||
32 | ... | ... | ...
|
||||
11 | File | `/hrm/employeeview.php` | High
|
||||
12 | File | `/images/` | Medium
|
||||
13 | File | `/inc/extensions.php` | High
|
||||
14 | File | `/index.php` | Medium
|
||||
15 | File | `/lists/index.php` | High
|
||||
16 | File | `/login` | Low
|
||||
17 | File | `/members/view_member.php` | High
|
||||
18 | File | `/modules/profile/index.php` | High
|
||||
19 | File | `/nova/bin/console` | High
|
||||
20 | File | `/nova/bin/detnet` | High
|
||||
21 | File | `/objects/getImageMP4.php` | High
|
||||
22 | File | `/one_church/userregister.php` | High
|
||||
23 | File | `/out.php` | Medium
|
||||
24 | File | `/owa/auth/logon.aspx` | High
|
||||
25 | File | `/public/plugins/` | High
|
||||
26 | File | `/replication` | Medium
|
||||
27 | File | `/req_password_user.php` | High
|
||||
28 | File | `/SAP_Information_System/controllers/add_admin.php` | High
|
||||
29 | File | `/SASWebReportStudio/logonAndRender.do` | High
|
||||
30 | File | `/secure/admin/InsightDefaultCustomFieldConfig.jspa` | High
|
||||
31 | ... | ... | ...
|
||||
|
||||
There are 273 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 266 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -34,25 +34,25 @@ ID | IP address | Hostname | Actor | Confidence
|
|||
4 | [31.24.228.170](https://vuldb.com/?ip.31.24.228.170) | 31.24.228.170.static.midphase.com | [IcedID](https://vuldb.com/?actor.icedid) | High
|
||||
5 | [31.184.199.11](https://vuldb.com/?ip.31.184.199.11) | dalesmanager.com | [IcedID](https://vuldb.com/?actor.icedid) | High
|
||||
6 | [37.120.222.100](https://vuldb.com/?ip.37.120.222.100) | - | [IcedID](https://vuldb.com/?actor.icedid) | High
|
||||
7 | [45.8.146.139](https://vuldb.com/?ip.45.8.146.139) | vm580483.stark-industries.solutions | [TA551](https://vuldb.com/?actor.ta551) | High
|
||||
8 | [45.129.99.241](https://vuldb.com/?ip.45.129.99.241) | 354851-vds-mamozw.gmhost.pp.ua | [IcedID](https://vuldb.com/?actor.icedid) | High
|
||||
9 | [45.138.172.179](https://vuldb.com/?ip.45.138.172.179) | - | [IcedID](https://vuldb.com/?actor.icedid) | High
|
||||
10 | [45.147.228.198](https://vuldb.com/?ip.45.147.228.198) | - | [IcedID](https://vuldb.com/?actor.icedid) | High
|
||||
11 | [45.147.230.82](https://vuldb.com/?ip.45.147.230.82) | - | [IcedID](https://vuldb.com/?actor.icedid) | High
|
||||
12 | [45.147.230.88](https://vuldb.com/?ip.45.147.230.88) | mailnode7.bulletproof-mail.biz | [IcedID](https://vuldb.com/?actor.icedid) | High
|
||||
13 | [45.147.231.113](https://vuldb.com/?ip.45.147.231.113) | - | [IcedID](https://vuldb.com/?actor.icedid) | High
|
||||
14 | [45.153.240.135](https://vuldb.com/?ip.45.153.240.135) | - | [IcedID](https://vuldb.com/?actor.icedid) | High
|
||||
15 | [45.153.241.115](https://vuldb.com/?ip.45.153.241.115) | - | [IcedID](https://vuldb.com/?actor.icedid) | High
|
||||
16 | [46.17.98.191](https://vuldb.com/?ip.46.17.98.191) | - | [IcedID](https://vuldb.com/?actor.icedid) | High
|
||||
17 | [46.21.153.211](https://vuldb.com/?ip.46.21.153.211) | 211.153.21.46.static.swiftway.net | [TA551](https://vuldb.com/?actor.ta551) | High
|
||||
18 | [46.249.62.199](https://vuldb.com/?ip.46.249.62.199) | - | [IcedID](https://vuldb.com/?actor.icedid) | High
|
||||
19 | [64.227.108.27](https://vuldb.com/?ip.64.227.108.27) | - | [TA551](https://vuldb.com/?actor.ta551) | High
|
||||
20 | [79.141.161.176](https://vuldb.com/?ip.79.141.161.176) | zzs7bp73.copycomdigital.com | [IcedID](https://vuldb.com/?actor.icedid) | High
|
||||
21 | [79.141.164.241](https://vuldb.com/?ip.79.141.164.241) | x6ts.mtsgamingpro.fun | [IcedID](https://vuldb.com/?actor.icedid) | High
|
||||
22 | [79.141.166.39](https://vuldb.com/?ip.79.141.166.39) | webimpa.com | [IcedID](https://vuldb.com/?actor.icedid) | High
|
||||
7 | [37.252.11.221](https://vuldb.com/?ip.37.252.11.221) | - | [IcedID](https://vuldb.com/?actor.icedid) | High
|
||||
8 | [45.8.146.139](https://vuldb.com/?ip.45.8.146.139) | vm580483.stark-industries.solutions | [TA551](https://vuldb.com/?actor.ta551) | High
|
||||
9 | [45.129.99.241](https://vuldb.com/?ip.45.129.99.241) | 354851-vds-mamozw.gmhost.pp.ua | [IcedID](https://vuldb.com/?actor.icedid) | High
|
||||
10 | [45.138.172.179](https://vuldb.com/?ip.45.138.172.179) | - | [IcedID](https://vuldb.com/?actor.icedid) | High
|
||||
11 | [45.147.228.198](https://vuldb.com/?ip.45.147.228.198) | - | [IcedID](https://vuldb.com/?actor.icedid) | High
|
||||
12 | [45.147.230.82](https://vuldb.com/?ip.45.147.230.82) | - | [IcedID](https://vuldb.com/?actor.icedid) | High
|
||||
13 | [45.147.230.88](https://vuldb.com/?ip.45.147.230.88) | mailnode7.bulletproof-mail.biz | [IcedID](https://vuldb.com/?actor.icedid) | High
|
||||
14 | [45.147.231.113](https://vuldb.com/?ip.45.147.231.113) | - | [IcedID](https://vuldb.com/?actor.icedid) | High
|
||||
15 | [45.153.240.135](https://vuldb.com/?ip.45.153.240.135) | - | [IcedID](https://vuldb.com/?actor.icedid) | High
|
||||
16 | [45.153.241.115](https://vuldb.com/?ip.45.153.241.115) | - | [IcedID](https://vuldb.com/?actor.icedid) | High
|
||||
17 | [46.17.98.191](https://vuldb.com/?ip.46.17.98.191) | - | [IcedID](https://vuldb.com/?actor.icedid) | High
|
||||
18 | [46.21.153.211](https://vuldb.com/?ip.46.21.153.211) | 211.153.21.46.static.swiftway.net | [TA551](https://vuldb.com/?actor.ta551) | High
|
||||
19 | [46.249.62.199](https://vuldb.com/?ip.46.249.62.199) | - | [IcedID](https://vuldb.com/?actor.icedid) | High
|
||||
20 | [64.227.108.27](https://vuldb.com/?ip.64.227.108.27) | - | [TA551](https://vuldb.com/?actor.ta551) | High
|
||||
21 | [79.141.161.176](https://vuldb.com/?ip.79.141.161.176) | zzs7bp73.copycomdigital.com | [IcedID](https://vuldb.com/?actor.icedid) | High
|
||||
22 | [79.141.164.241](https://vuldb.com/?ip.79.141.164.241) | x6ts.mtsgamingpro.fun | [IcedID](https://vuldb.com/?actor.icedid) | High
|
||||
23 | ... | ... | ... | ...
|
||||
|
||||
There are 87 more IOC items available. Please use our online service to access the data.
|
||||
There are 90 more IOC items available. Please use our online service to access the data.
|
||||
|
||||
## TTP - Tactics, Techniques, Procedures
|
||||
|
||||
|
@ -88,6 +88,7 @@ The following list contains _external sources_ which discuss the campaign and th
|
|||
|
||||
* https://blog.talosintelligence.com/2018/04/icedid-banking-trojan.html
|
||||
* https://cert.gov.ua/article/39609
|
||||
* https://github.com/A-dd-Y/secops/blob/main/MalwareIOC/mwdb-icedid-c2.txt
|
||||
* https://isc.sans.edu/diary/IcedID+%28Bokbot%29+with+Dark+VNC+and+Cobalt+Strike/28884
|
||||
* https://isc.sans.edu/diary/Monster+Libra+%28TA551Shathak%29+--%3E+IcedID+%28Bokbot%29+--%3E+Cobalt+Strike+%26+DarkVNC/28974
|
||||
* https://isc.sans.edu/diary/Monster+Libra+%28TA551Shathak%29+pushes+IcedID+%28Bokbot%29+with+Dark+VNC+and+Cobalt+Strike/28934
|
||||
|
|
|
@ -74,20 +74,22 @@ ID | Type | Indicator | Confidence
|
|||
15 | File | `/api/v2/cli/commands` | High
|
||||
16 | File | `/api/v2/open/rowsInfo` | High
|
||||
17 | File | `/asms/admin/?page=user/manage_user` | High
|
||||
18 | File | `/card/in-card.php` | High
|
||||
19 | File | `/classes/Master.php?f=delete_student` | High
|
||||
20 | File | `/connectors/index.php` | High
|
||||
21 | File | `/csms/admin/?page=system_info` | High
|
||||
22 | File | `/etc/init0.d/S80telnetd.sh` | High
|
||||
23 | File | `/etc/srapi/config/system.conf` | High
|
||||
24 | File | `/framework/core/models/expConfig.php` | High
|
||||
25 | File | `/framework/modules/core/controllers/expHTMLEditorController.php` | High
|
||||
26 | File | `/fw.login.php` | High
|
||||
18 | File | `/blog/comment` | High
|
||||
19 | File | `/card/in-card.php` | High
|
||||
20 | File | `/classes/Master.php?f=delete_student` | High
|
||||
21 | File | `/connectors/index.php` | High
|
||||
22 | File | `/csms/admin/?page=system_info` | High
|
||||
23 | File | `/etc/init0.d/S80telnetd.sh` | High
|
||||
24 | File | `/etc/srapi/config/system.conf` | High
|
||||
25 | File | `/framework/core/models/expConfig.php` | High
|
||||
26 | File | `/framework/modules/core/controllers/expHTMLEditorController.php` | High
|
||||
27 | File | `/garage/php_action/createBrand.php` | High
|
||||
28 | File | `/goform/form2WizardStep54` | High
|
||||
29 | ... | ... | ...
|
||||
28 | File | `/goform/addressNat` | High
|
||||
29 | File | `/goform/AdvSetWrlsafeset` | High
|
||||
30 | File | `/goform/editFileName` | High
|
||||
31 | ... | ... | ...
|
||||
|
||||
There are 246 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 260 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -13,7 +13,7 @@ These _countries_ are directly (e.g. origin of attacks) or indirectly (e.g. acce
|
|||
* [CH](https://vuldb.com/?country.ch)
|
||||
* ...
|
||||
|
||||
There are 7 more country items available. Please use our online service to access the data.
|
||||
There are 6 more country items available. Please use our online service to access the data.
|
||||
|
||||
## Actors
|
||||
|
||||
|
@ -132,29 +132,28 @@ ID | Type | Indicator | Confidence
|
|||
19 | File | `/bsms_ci/index.php` | High
|
||||
20 | File | `/bsms_ci/index.php/user/edit_user/` | High
|
||||
21 | File | `/calendar/viewcalendar.php` | High
|
||||
22 | File | `/category.php` | High
|
||||
23 | File | `/cgi-bin/wlogin.cgi` | High
|
||||
24 | File | `/classes/Users.php?f=delete_client` | High
|
||||
25 | File | `/clearance/clearance.php` | High
|
||||
26 | File | `/clients/listclients.php` | High
|
||||
27 | File | `/csms/admin/?page=user/manage_user` | High
|
||||
28 | File | `/dev/shm` | Medium
|
||||
29 | File | `/etc/openshift/server_priv.pem` | High
|
||||
30 | File | `/event/admin/?page=user/list` | High
|
||||
31 | File | `/forum/away.php` | High
|
||||
32 | File | `/forums/editforum.php` | High
|
||||
33 | File | `/goform/setDiagnoseInfo` | High
|
||||
34 | File | `/goform/SetIpMacBind` | High
|
||||
35 | File | `/goform/SetPptpServerCfg` | High
|
||||
36 | File | `/goform/setUplinkInfo` | High
|
||||
37 | File | `/h/search?action=voicemail&action=listen` | High
|
||||
38 | File | `/hospital/hms/admin/patient-search.php` | High
|
||||
39 | File | `/hrm/employeeadd.php` | High
|
||||
40 | File | `/hrm/employeeview.php` | High
|
||||
41 | File | `/index.php/admins/Fields/get_fields.html` | High
|
||||
42 | ... | ... | ...
|
||||
22 | File | `/cgi-bin/wlogin.cgi` | High
|
||||
23 | File | `/classes/Users.php?f=delete_client` | High
|
||||
24 | File | `/clearance/clearance.php` | High
|
||||
25 | File | `/clients/listclients.php` | High
|
||||
26 | File | `/csms/admin/?page=user/manage_user` | High
|
||||
27 | File | `/dev/shm` | Medium
|
||||
28 | File | `/etc/openshift/server_priv.pem` | High
|
||||
29 | File | `/event/admin/?page=user/list` | High
|
||||
30 | File | `/forum/away.php` | High
|
||||
31 | File | `/forums/editforum.php` | High
|
||||
32 | File | `/goform/setDiagnoseInfo` | High
|
||||
33 | File | `/goform/SetIpMacBind` | High
|
||||
34 | File | `/goform/SetPptpServerCfg` | High
|
||||
35 | File | `/goform/setUplinkInfo` | High
|
||||
36 | File | `/h/search?action=voicemail&action=listen` | High
|
||||
37 | File | `/hospital/hms/admin/patient-search.php` | High
|
||||
38 | File | `/hrm/employeeadd.php` | High
|
||||
39 | File | `/hrm/employeeview.php` | High
|
||||
40 | File | `/index.php/admins/Fields/get_fields.html` | High
|
||||
41 | ... | ... | ...
|
||||
|
||||
There are 361 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 354 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -10,10 +10,10 @@ These _countries_ are directly (e.g. origin of attacks) or indirectly (e.g. acce
|
|||
|
||||
* [VN](https://vuldb.com/?country.vn)
|
||||
* [US](https://vuldb.com/?country.us)
|
||||
* [CN](https://vuldb.com/?country.cn)
|
||||
* [JP](https://vuldb.com/?country.jp)
|
||||
* ...
|
||||
|
||||
There are 20 more country items available. Please use our online service to access the data.
|
||||
There are 21 more country items available. Please use our online service to access the data.
|
||||
|
||||
## Actors
|
||||
|
||||
|
@ -4917,7 +4917,7 @@ ID | Technique | Weakness | Description | Confidence
|
|||
5 | T1059.007 | CWE-79, CWE-80 | Cross Site Scripting | High
|
||||
6 | ... | ... | ... | ...
|
||||
|
||||
There are 19 more TTP items available. Please use our online service to access the data.
|
||||
There are 20 more TTP items available. Please use our online service to access the data.
|
||||
|
||||
## IOA - Indicator of Attack
|
||||
|
||||
|
@ -4925,43 +4925,41 @@ These _indicators of attack_ (IOA) list the potential fragments used for technic
|
|||
|
||||
ID | Type | Indicator | Confidence
|
||||
-- | ---- | --------- | ----------
|
||||
1 | File | `/admin/controller/JobLogController.java` | High
|
||||
2 | File | `/admin/fst_upload.inc.php` | High
|
||||
3 | File | `/api/audits` | Medium
|
||||
4 | File | `/authUserAction!edit.action` | High
|
||||
5 | File | `/bsms_ci/index.php` | High
|
||||
6 | File | `/bsms_ci/index.php/user/edit_user/` | High
|
||||
7 | File | `/calendar/viewcalendar.php` | High
|
||||
8 | File | `/cgi-bin/supervisor/PwdGrp.cgi` | High
|
||||
9 | File | `/cgi-bin/wlogin.cgi` | High
|
||||
10 | File | `/clients/listclients.php` | High
|
||||
11 | File | `/common/info.cgi` | High
|
||||
12 | File | `/confirm` | Medium
|
||||
13 | File | `/contacts/listcontacts.php` | High
|
||||
14 | File | `/Content/Template/root/reverse-shell.aspx` | High
|
||||
15 | File | `/Default/Bd` | Medium
|
||||
16 | File | `/etc/passwd` | Medium
|
||||
17 | File | `/event/admin/?page=user/list` | High
|
||||
18 | File | `/face-recognition-php/facepay-master/camera.php` | High
|
||||
19 | File | `/forum/away.php` | High
|
||||
20 | File | `/forums/editforum.php` | High
|
||||
21 | File | `/general/search.php?searchtype=simple` | High
|
||||
22 | File | `/goform/setSnmpInfo` | High
|
||||
23 | File | `/goform/setSysPwd` | High
|
||||
24 | File | `/goform/setUplinkInfo` | High
|
||||
25 | File | `/gpac/src/bifs/unquantize.c` | High
|
||||
26 | File | `/hrm/controller/employee.php` | High
|
||||
27 | File | `/hrm/employeeadd.php` | High
|
||||
28 | File | `/hrm/employeeview.php` | High
|
||||
29 | File | `/index.php` | Medium
|
||||
30 | File | `/index.php?module=configuration/application` | High
|
||||
31 | File | `/index.php?module=entities/fields&entities_id=24` | High
|
||||
32 | File | `/index.php?module=entities/forms&entities_id=24` | High
|
||||
33 | File | `/index.php?module=entities/listing_types&entities_id=24` | High
|
||||
34 | File | `/index.php?module=help_pages/pages&entities_id=24` | High
|
||||
35 | ... | ... | ...
|
||||
1 | File | `/api/audits` | Medium
|
||||
2 | File | `/balance/service/list` | High
|
||||
3 | File | `/blog/comment` | High
|
||||
4 | File | `/bsms_ci/index.php` | High
|
||||
5 | File | `/bsms_ci/index.php/user/edit_user/` | High
|
||||
6 | File | `/calendar/viewcalendar.php` | High
|
||||
7 | File | `/cgi-bin/supervisor/PwdGrp.cgi` | High
|
||||
8 | File | `/cgi-bin/wlogin.cgi` | High
|
||||
9 | File | `/ci_hms/search` | High
|
||||
10 | File | `/common/info.cgi` | High
|
||||
11 | File | `/contacts/listcontacts.php` | High
|
||||
12 | File | `/Content/Template/root/reverse-shell.aspx` | High
|
||||
13 | File | `/Default/Bd` | Medium
|
||||
14 | File | `/etc/passwd` | Medium
|
||||
15 | File | `/event/admin/?page=user/list` | High
|
||||
16 | File | `/face-recognition-php/facepay-master/camera.php` | High
|
||||
17 | File | `/forum/away.php` | High
|
||||
18 | File | `/forums/editforum.php` | High
|
||||
19 | File | `/general/search.php?searchtype=simple` | High
|
||||
20 | File | `/goform/setDiagnoseInfo` | High
|
||||
21 | File | `/goform/setSnmpInfo` | High
|
||||
22 | File | `/goform/setSysPwd` | High
|
||||
23 | File | `/goform/setUplinkInfo` | High
|
||||
24 | File | `/gpac/src/bifs/unquantize.c` | High
|
||||
25 | File | `/hrm/controller/employee.php` | High
|
||||
26 | File | `/hrm/employeeadd.php` | High
|
||||
27 | File | `/hrm/employeeview.php` | High
|
||||
28 | File | `/includes/login.php` | High
|
||||
29 | File | `/index.php?module=configuration/application` | High
|
||||
30 | File | `/index.php?module=entities/fields&entities_id=24` | High
|
||||
31 | File | `/index.php?module=entities/forms&entities_id=24` | High
|
||||
32 | File | `/index.php?module=entities/listing_types&entities_id=24` | High
|
||||
33 | ... | ... | ...
|
||||
|
||||
There are 302 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 285 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -48,7 +48,7 @@ ID | Technique | Weakness | Description | Confidence
|
|||
3 | T1059.007 | CWE-79 | Cross Site Scripting | High
|
||||
4 | ... | ... | ... | ...
|
||||
|
||||
There are 7 more TTP items available. Please use our online service to access the data.
|
||||
There are 8 more TTP items available. Please use our online service to access the data.
|
||||
|
||||
## IOA - Indicator of Attack
|
||||
|
||||
|
@ -62,7 +62,7 @@ ID | Type | Indicator | Confidence
|
|||
4 | File | `/jsoa/hntdCustomDesktopActionContent` | High
|
||||
5 | ... | ... | ...
|
||||
|
||||
There are 28 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 29 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -102,20 +102,21 @@ ID | Type | Indicator | Confidence
|
|||
20 | File | `/dede/file_manage_control.php` | High
|
||||
21 | File | `/depotHead/list` | High
|
||||
22 | File | `/etc/openshift/server_priv.pem` | High
|
||||
23 | File | `/foms/place-order.php` | High
|
||||
24 | File | `/forms/web_runScript` | High
|
||||
25 | File | `/forum/away.php` | High
|
||||
26 | File | `/garage/php_action/createBrand.php` | High
|
||||
27 | File | `/general/search.php?searchtype=simple` | High
|
||||
28 | File | `/goform/AddSysLogRule` | High
|
||||
29 | File | `/goform/formSetFirewallCfg` | High
|
||||
30 | File | `/goform/NTPSyncWithHost` | High
|
||||
23 | File | `/etc/pki/pulp/nodes/` | High
|
||||
24 | File | `/foms/place-order.php` | High
|
||||
25 | File | `/forms/web_runScript` | High
|
||||
26 | File | `/forum/away.php` | High
|
||||
27 | File | `/garage/php_action/createBrand.php` | High
|
||||
28 | File | `/general/search.php?searchtype=simple` | High
|
||||
29 | File | `/goform/AddSysLogRule` | High
|
||||
30 | File | `/goform/formSetFirewallCfg` | High
|
||||
31 | File | `/hrm/employeeview.php` | High
|
||||
32 | File | `/index.asp` | Medium
|
||||
33 | File | `/isomedia/meta.c` | High
|
||||
34 | ... | ... | ...
|
||||
32 | File | `/isomedia/meta.c` | High
|
||||
33 | File | `/meetings/listmeetings.php` | High
|
||||
34 | File | `/odlms/?page=appointments/view_appointment` | High
|
||||
35 | ... | ... | ...
|
||||
|
||||
There are 288 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 300 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -95,17 +95,16 @@ ID | Type | Indicator | Confidence
|
|||
28 | File | `/etc/hosts` | Medium
|
||||
29 | File | `/foms/place-order.php` | High
|
||||
30 | File | `/forum/away.php` | High
|
||||
31 | File | `/fuel/index.php/fuel/logs/items` | High
|
||||
32 | File | `/fuel/sitevariables/delete/4` | High
|
||||
33 | File | `/goform/setmac` | High
|
||||
34 | File | `/goform/wizard_end` | High
|
||||
35 | File | `/hprms/admin/doctors/manage_doctor.php` | High
|
||||
36 | File | `/index.php` | Medium
|
||||
37 | File | `/index/jobfairol/show/` | High
|
||||
38 | File | `/jsoa/hntdCustomDesktopActionContent` | High
|
||||
39 | ... | ... | ...
|
||||
31 | File | `/fuel/sitevariables/delete/4` | High
|
||||
32 | File | `/goform/setmac` | High
|
||||
33 | File | `/goform/wizard_end` | High
|
||||
34 | File | `/hprms/admin/doctors/manage_doctor.php` | High
|
||||
35 | File | `/index.php` | Medium
|
||||
36 | File | `/index/jobfairol/show/` | High
|
||||
37 | File | `/jsoa/hntdCustomDesktopActionContent` | High
|
||||
38 | ... | ... | ...
|
||||
|
||||
There are 338 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 331 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -70,40 +70,40 @@ ID | Type | Indicator | Confidence
|
|||
16 | File | `admin/index.php?id=users/action=edit/user_id=1` | High
|
||||
17 | File | `admin/memberviewdetails.php` | High
|
||||
18 | File | `admin/sitesettings.php` | High
|
||||
19 | File | `affich.php` | Medium
|
||||
20 | File | `agent/Core/Controller/SendRequest.cpp` | High
|
||||
21 | File | `akeyActivationLogin.do` | High
|
||||
22 | File | `album_portal.php` | High
|
||||
23 | File | `apache-auth.conf` | High
|
||||
24 | File | `askapache-firefox-adsense.php` | High
|
||||
25 | File | `attachment.cgi` | High
|
||||
26 | File | `basic_search_result.php` | High
|
||||
27 | File | `blueprints/sections/edit/1` | High
|
||||
28 | File | `books.php` | Medium
|
||||
29 | File | `cart_add.php` | Medium
|
||||
30 | File | `CFS.c` | Low
|
||||
31 | File | `cgi-bin/gnudip.cgi` | High
|
||||
32 | File | `checktransferstatus.php` | High
|
||||
33 | File | `checkuser.php` | High
|
||||
34 | File | `class.SystemAction.php` | High
|
||||
35 | File | `clientarea.php` | High
|
||||
36 | File | `cmdmon.c` | Medium
|
||||
37 | File | `collectivite.class.php` | High
|
||||
38 | File | `confirm.php` | Medium
|
||||
39 | File | `contact` | Low
|
||||
40 | File | `control.c` | Medium
|
||||
41 | File | `core-util.c` | Medium
|
||||
42 | File | `core/coreuserinputhandler.cpp` | High
|
||||
43 | File | `cve-bin/moreBlockInfo.cgi` | High
|
||||
44 | File | `d1_both.c` | Medium
|
||||
45 | File | `data/gbconfiguration.dat` | High
|
||||
46 | File | `Debug_command_page.asp` | High
|
||||
47 | File | `details_view.php` | High
|
||||
48 | File | `Diagnose.exe` | Medium
|
||||
49 | File | `DigiDocSAXParser.c` | High
|
||||
19 | File | `admin_gallery.php3` | High
|
||||
20 | File | `affich.php` | Medium
|
||||
21 | File | `agent/Core/Controller/SendRequest.cpp` | High
|
||||
22 | File | `akeyActivationLogin.do` | High
|
||||
23 | File | `album_portal.php` | High
|
||||
24 | File | `apache-auth.conf` | High
|
||||
25 | File | `askapache-firefox-adsense.php` | High
|
||||
26 | File | `attachment.cgi` | High
|
||||
27 | File | `basic_search_result.php` | High
|
||||
28 | File | `blueprints/sections/edit/1` | High
|
||||
29 | File | `books.php` | Medium
|
||||
30 | File | `cart_add.php` | Medium
|
||||
31 | File | `CFS.c` | Low
|
||||
32 | File | `cgi-bin/gnudip.cgi` | High
|
||||
33 | File | `checktransferstatus.php` | High
|
||||
34 | File | `checkuser.php` | High
|
||||
35 | File | `class.SystemAction.php` | High
|
||||
36 | File | `clientarea.php` | High
|
||||
37 | File | `cmdmon.c` | Medium
|
||||
38 | File | `collectivite.class.php` | High
|
||||
39 | File | `confirm.php` | Medium
|
||||
40 | File | `contact` | Low
|
||||
41 | File | `control.c` | Medium
|
||||
42 | File | `core-util.c` | Medium
|
||||
43 | File | `core/coreuserinputhandler.cpp` | High
|
||||
44 | File | `cve-bin/moreBlockInfo.cgi` | High
|
||||
45 | File | `d1_both.c` | Medium
|
||||
46 | File | `data/gbconfiguration.dat` | High
|
||||
47 | File | `Debug_command_page.asp` | High
|
||||
48 | File | `details_view.php` | High
|
||||
49 | File | `Diagnose.exe` | Medium
|
||||
50 | ... | ... | ...
|
||||
|
||||
There are 439 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 432 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -143,28 +143,28 @@ ID | Type | Indicator | Confidence
|
|||
32 | File | `/pages/apply_vacancy.php` | High
|
||||
33 | File | `/proc/<PID>/mem` | High
|
||||
34 | File | `/proxy` | Low
|
||||
35 | File | `/public/launchNewWindow.jsp` | High
|
||||
36 | File | `/Redcock-Farm/farm/category.php` | High
|
||||
37 | File | `/sacco_shield/manage_user.php` | High
|
||||
38 | File | `/spip.php` | Medium
|
||||
39 | File | `/sqlitemanager/main.php?dbsel=-1%20or%2072%20=%2072` | High
|
||||
40 | File | `/staff/bookdetails.php` | High
|
||||
41 | File | `/uncpath/` | Medium
|
||||
42 | File | `/upload` | Low
|
||||
43 | File | `/user/update_booking.php` | High
|
||||
44 | File | `/vendor/views/add_product.php` | High
|
||||
45 | File | `/wabt/bin/poc.wasm` | High
|
||||
46 | File | `/WebInterface/UserManager/` | High
|
||||
47 | File | `/Wedding-Management-PHP/admin/photos_add.php` | High
|
||||
48 | File | `/wordpress/wp-admin/options-general.php` | High
|
||||
49 | File | `/wp-content/plugins/woocommerce/templates/emails/plain/` | High
|
||||
50 | File | `ActivityRecord.java` | High
|
||||
51 | File | `adclick.php` | Medium
|
||||
52 | File | `addtocart.asp` | High
|
||||
53 | File | `admin.php` | Medium
|
||||
35 | File | `/Redcock-Farm/farm/category.php` | High
|
||||
36 | File | `/sacco_shield/manage_user.php` | High
|
||||
37 | File | `/spip.php` | Medium
|
||||
38 | File | `/sqlitemanager/main.php?dbsel=-1%20or%2072%20=%2072` | High
|
||||
39 | File | `/staff/bookdetails.php` | High
|
||||
40 | File | `/uncpath/` | Medium
|
||||
41 | File | `/upload` | Low
|
||||
42 | File | `/user/update_booking.php` | High
|
||||
43 | File | `/vendor/views/add_product.php` | High
|
||||
44 | File | `/wabt/bin/poc.wasm` | High
|
||||
45 | File | `/WebInterface/UserManager/` | High
|
||||
46 | File | `/Wedding-Management-PHP/admin/photos_add.php` | High
|
||||
47 | File | `/wordpress/wp-admin/options-general.php` | High
|
||||
48 | File | `/wp-content/plugins/woocommerce/templates/emails/plain/` | High
|
||||
49 | File | `ActivityRecord.java` | High
|
||||
50 | File | `adclick.php` | Medium
|
||||
51 | File | `addtocart.asp` | High
|
||||
52 | File | `admin.php` | Medium
|
||||
53 | File | `admin.php3` | Medium
|
||||
54 | ... | ... | ...
|
||||
|
||||
There are 466 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 468 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -13,7 +13,7 @@ These _countries_ are directly (e.g. origin of attacks) or indirectly (e.g. acce
|
|||
* [CN](https://vuldb.com/?country.cn)
|
||||
* ...
|
||||
|
||||
There are 11 more country items available. Please use our online service to access the data.
|
||||
There are 9 more country items available. Please use our online service to access the data.
|
||||
|
||||
## Actors
|
||||
|
||||
|
@ -48,7 +48,7 @@ _Tactics, techniques, and procedures_ (TTP) summarize the suspected MITRE ATT&CK
|
|||
ID | Technique | Weakness | Description | Confidence
|
||||
-- | --------- | -------- | ----------- | ----------
|
||||
1 | T1006 | CWE-21, CWE-22, CWE-23, CWE-40 | Pathname Traversal | High
|
||||
2 | T1040 | CWE-294, CWE-319 | Authentication Bypass by Capture-replay | High
|
||||
2 | T1040 | CWE-319 | Authentication Bypass by Capture-replay | High
|
||||
3 | T1055 | CWE-74 | Injection | High
|
||||
4 | T1059 | CWE-88, CWE-94 | Cross Site Scripting | High
|
||||
5 | T1059.007 | CWE-79, CWE-80, CWE-85 | Cross Site Scripting | High
|
||||
|
@ -80,14 +80,14 @@ ID | Type | Indicator | Confidence
|
|||
16 | File | `/asms/products/view_product.php` | High
|
||||
17 | File | `/attachments` | Medium
|
||||
18 | File | `/avms/index.php` | High
|
||||
19 | File | `/bsms_ci/index.php` | High
|
||||
20 | File | `/bsms_ci/index.php/user/edit_user/` | High
|
||||
21 | File | `/calendar/viewcalendar.php` | High
|
||||
22 | File | `/config/getuser` | High
|
||||
23 | File | `/Default/Bd` | Medium
|
||||
24 | File | `/device/` | Medium
|
||||
25 | File | `/event/admin/?page=user/list` | High
|
||||
26 | File | `/foms/all-orders.php?status=Cancelled%20by%20Customer` | High
|
||||
19 | File | `/back/index.php/user/User/?1` | High
|
||||
20 | File | `/bsms_ci/index.php` | High
|
||||
21 | File | `/bsms_ci/index.php/user/edit_user/` | High
|
||||
22 | File | `/calendar/viewcalendar.php` | High
|
||||
23 | File | `/config/getuser` | High
|
||||
24 | File | `/Default/Bd` | Medium
|
||||
25 | File | `/device/` | Medium
|
||||
26 | File | `/event/admin/?page=user/list` | High
|
||||
27 | File | `/garage/php_action/createBrand.php` | High
|
||||
28 | File | `/goform/setDiagnoseInfo` | High
|
||||
29 | File | `/goform/setSysPwd` | High
|
||||
|
@ -102,7 +102,7 @@ ID | Type | Indicator | Confidence
|
|||
38 | File | `/index.php?module=help_pages/pages&entities_id=24` | High
|
||||
39 | ... | ... | ...
|
||||
|
||||
There are 331 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 336 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -10,7 +10,7 @@ These _countries_ are directly (e.g. origin of attacks) or indirectly (e.g. acce
|
|||
|
||||
* [US](https://vuldb.com/?country.us)
|
||||
* [CN](https://vuldb.com/?country.cn)
|
||||
* [BR](https://vuldb.com/?country.br)
|
||||
* [RU](https://vuldb.com/?country.ru)
|
||||
* ...
|
||||
|
||||
There are 29 more country items available. Please use our online service to access the data.
|
||||
|
@ -109,7 +109,7 @@ ID | Type | Indicator | Confidence
|
|||
49 | File | `/wp-admin/admin-ajax.php` | High
|
||||
50 | ... | ... | ...
|
||||
|
||||
There are 434 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 432 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -125,7 +125,7 @@ ID | Type | Indicator | Confidence
|
|||
26 | File | `/zm/index.php` | High
|
||||
27 | ... | ... | ...
|
||||
|
||||
There are 225 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 223 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -64,7 +64,7 @@ ID | Technique | Weakness | Description | Confidence
|
|||
5 | T1059.007 | CWE-79, CWE-80, CWE-85 | Cross Site Scripting | High
|
||||
6 | ... | ... | ... | ...
|
||||
|
||||
There are 19 more TTP items available. Please use our online service to access the data.
|
||||
There are 20 more TTP items available. Please use our online service to access the data.
|
||||
|
||||
## IOA - Indicator of Attack
|
||||
|
||||
|
@ -77,30 +77,30 @@ ID | Type | Indicator | Confidence
|
|||
3 | File | `/admin/controller/JobLogController.java` | High
|
||||
4 | File | `/Admin/dashboard.php` | High
|
||||
5 | File | `/admin/pages/sections_save.php` | High
|
||||
6 | File | `/admin/problem_judge.php` | High
|
||||
7 | File | `/admin/settings/save.php` | High
|
||||
8 | File | `/admin/transactions/update_status.php` | High
|
||||
9 | File | `/admin/users/index.php` | High
|
||||
10 | File | `/api/audits` | Medium
|
||||
11 | File | `/api/geojson` | Medium
|
||||
12 | File | `/api/user/password/sent-reset-email` | High
|
||||
13 | File | `/asms/admin/mechanics/manage_mechanic.php` | High
|
||||
14 | File | `/asms/admin/products/manage_product.php` | High
|
||||
15 | File | `/asms/classes/Master.php?f=delete_mechanic` | High
|
||||
16 | File | `/asms/classes/Master.php?f=delete_service` | High
|
||||
17 | File | `/asms/products/view_product.php` | High
|
||||
18 | File | `/bsms_ci/index.php` | High
|
||||
19 | File | `/bsms_ci/index.php/book` | High
|
||||
20 | File | `/bsms_ci/index.php/user/edit_user/` | High
|
||||
21 | File | `/diag_ping_admin.asp` | High
|
||||
22 | File | `/diag_tracert_admin.asp` | High
|
||||
23 | File | `/face-recognition-php/facepay-master/camera.php` | High
|
||||
24 | File | `/forum/away.php` | High
|
||||
25 | File | `/goform/form2IPQoSTcAdd` | High
|
||||
26 | File | `/goform/form2WizardStep4` | High
|
||||
6 | File | `/admin/settings/save.php` | High
|
||||
7 | File | `/admin/transactions/update_status.php` | High
|
||||
8 | File | `/admin/users/index.php` | High
|
||||
9 | File | `/api/audits` | Medium
|
||||
10 | File | `/api/geojson` | Medium
|
||||
11 | File | `/api/user/password/sent-reset-email` | High
|
||||
12 | File | `/asms/admin/mechanics/manage_mechanic.php` | High
|
||||
13 | File | `/asms/admin/products/manage_product.php` | High
|
||||
14 | File | `/asms/classes/Master.php?f=delete_mechanic` | High
|
||||
15 | File | `/asms/classes/Master.php?f=delete_service` | High
|
||||
16 | File | `/asms/products/view_product.php` | High
|
||||
17 | File | `/bsms_ci/index.php` | High
|
||||
18 | File | `/bsms_ci/index.php/book` | High
|
||||
19 | File | `/bsms_ci/index.php/user/edit_user/` | High
|
||||
20 | File | `/diag_ping_admin.asp` | High
|
||||
21 | File | `/diag_tracert_admin.asp` | High
|
||||
22 | File | `/face-recognition-php/facepay-master/camera.php` | High
|
||||
23 | File | `/forum/away.php` | High
|
||||
24 | File | `/goform/form2IPQoSTcAdd` | High
|
||||
25 | File | `/goform/form2WizardStep4` | High
|
||||
26 | File | `/goform/form2WizardStep54` | High
|
||||
27 | ... | ... | ...
|
||||
|
||||
There are 226 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 227 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -72,7 +72,8 @@ ID | Technique | Weakness | Description | Confidence
|
|||
2 | T1040 | CWE-319 | Authentication Bypass by Capture-replay | High
|
||||
3 | T1055 | CWE-74 | Injection | High
|
||||
4 | T1059 | CWE-88, CWE-94 | Cross Site Scripting | High
|
||||
5 | ... | ... | ... | ...
|
||||
5 | T1059.007 | CWE-79, CWE-80, CWE-85 | Cross Site Scripting | High
|
||||
6 | ... | ... | ... | ...
|
||||
|
||||
There are 18 more TTP items available. Please use our online service to access the data.
|
||||
|
||||
|
@ -97,16 +98,16 @@ ID | Type | Indicator | Confidence
|
|||
13 | File | `/diag_ping_admin.asp` | High
|
||||
14 | File | `/diag_tracert_admin.asp` | High
|
||||
15 | File | `/face-recognition-php/facepay-master/camera.php` | High
|
||||
16 | File | `/gpac/src/bifs/unquantize.c` | High
|
||||
17 | File | `/hrm/controller/employee.php` | High
|
||||
18 | File | `/index/user/user_edit.html` | High
|
||||
19 | File | `/login` | Low
|
||||
20 | File | `/login.php` | Medium
|
||||
21 | File | `/Member/memberedit.html` | High
|
||||
22 | File | `/pages/processlogin.php` | High
|
||||
16 | File | `/forum/away.php` | High
|
||||
17 | File | `/gpac/src/bifs/unquantize.c` | High
|
||||
18 | File | `/hrm/controller/employee.php` | High
|
||||
19 | File | `/index/user/user_edit.html` | High
|
||||
20 | File | `/leave_system/admin/?page=maintenance/department` | High
|
||||
21 | File | `/login` | Low
|
||||
22 | File | `/login.php` | Medium
|
||||
23 | ... | ... | ...
|
||||
|
||||
There are 188 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 193 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -69,7 +69,7 @@ ID | Type | Indicator | Confidence
|
|||
10 | File | `account_activations/edit` | High
|
||||
11 | ... | ... | ...
|
||||
|
||||
There are 82 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 83 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -76,7 +76,7 @@ ID | Type | Indicator | Confidence
|
|||
11 | File | `BlogEngine/BlogEngine.Core/Services/Security/Security.cs` | High
|
||||
12 | ... | ... | ...
|
||||
|
||||
There are 94 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 95 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -89,7 +89,8 @@ ID | Technique | Weakness | Description | Confidence
|
|||
2 | T1040 | CWE-319 | Authentication Bypass by Capture-replay | High
|
||||
3 | T1055 | CWE-74 | Injection | High
|
||||
4 | T1059 | CWE-88, CWE-94 | Cross Site Scripting | High
|
||||
5 | ... | ... | ... | ...
|
||||
5 | T1059.007 | CWE-79, CWE-80, CWE-85 | Cross Site Scripting | High
|
||||
6 | ... | ... | ... | ...
|
||||
|
||||
There are 18 more TTP items available. Please use our online service to access the data.
|
||||
|
||||
|
@ -116,14 +117,14 @@ ID | Type | Indicator | Confidence
|
|||
15 | File | `/diag_tracert_admin.asp` | High
|
||||
16 | File | `/etc/openshift/server_priv.pem` | High
|
||||
17 | File | `/face-recognition-php/facepay-master/camera.php` | High
|
||||
18 | File | `/gpac/src/bifs/unquantize.c` | High
|
||||
19 | File | `/hrm/controller/employee.php` | High
|
||||
20 | File | `/index/user/user_edit.html` | High
|
||||
21 | File | `/login` | Low
|
||||
22 | File | `/login.php` | Medium
|
||||
18 | File | `/forum/away.php` | High
|
||||
19 | File | `/gpac/src/bifs/unquantize.c` | High
|
||||
20 | File | `/hrm/controller/employee.php` | High
|
||||
21 | File | `/index/user/user_edit.html` | High
|
||||
22 | File | `/leave_system/admin/?page=maintenance/department` | High
|
||||
23 | ... | ... | ...
|
||||
|
||||
There are 193 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 196 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -102,10 +102,9 @@ ID | Type | Indicator | Confidence
|
|||
24 | File | `/vendor/htmlawed/htmlawed/htmLawedTest.php` | High
|
||||
25 | File | `/websocket/exec` | High
|
||||
26 | File | `/wp-admin/admin-ajax.php` | High
|
||||
27 | File | `/x_program_center/jaxrs/invoke` | High
|
||||
28 | ... | ... | ...
|
||||
27 | ... | ... | ...
|
||||
|
||||
There are 233 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 231 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -76,33 +76,34 @@ ID | Type | Indicator | Confidence
|
|||
5 | File | `/admin/add-fee.php` | High
|
||||
6 | File | `/admin/baojia_list.php` | High
|
||||
7 | File | `/admin/folderrollpicture/list` | High
|
||||
8 | File | `/anony/mjpg.cgi` | High
|
||||
9 | File | `/api/common/ping` | High
|
||||
10 | File | `/api/v2/open/rowsInfo` | High
|
||||
11 | File | `/Applications/Google\ Drive.app/Contents/MacOS` | High
|
||||
12 | File | `/appointments/update_status.php` | High
|
||||
13 | File | `/authUserAction!edit.action` | High
|
||||
14 | File | `/bin/boa` | Medium
|
||||
15 | File | `/bookings/update_status.php` | High
|
||||
16 | File | `/cgi-bin/DownloadFlash` | High
|
||||
17 | File | `/classes/Master.php?f=delete_category` | High
|
||||
18 | File | `/classes/Users.php?f=delete_client` | High
|
||||
19 | File | `/contacts/listcontacts.php` | High
|
||||
20 | File | `/Core/Ap4File.cpp` | High
|
||||
21 | File | `/csms/admin/storages/view_storage.php` | High
|
||||
22 | File | `/dede/file_manage_control.php` | High
|
||||
23 | File | `/depotHead/list` | High
|
||||
24 | File | `/etc/ciel.cfg` | High
|
||||
25 | File | `/etc/openshift/server_priv.pem` | High
|
||||
26 | File | `/etc/shadow.sample` | High
|
||||
27 | File | `/forms/web_runScript` | High
|
||||
28 | File | `/garage/php_action/createBrand.php` | High
|
||||
29 | File | `/general/search.php?searchtype=simple` | High
|
||||
30 | File | `/goform/AddSysLogRule` | High
|
||||
31 | File | `/goform/formSetFirewallCfg` | High
|
||||
32 | ... | ... | ...
|
||||
8 | File | `/admin/loginc.php` | High
|
||||
9 | File | `/anony/mjpg.cgi` | High
|
||||
10 | File | `/api/common/ping` | High
|
||||
11 | File | `/api/v2/open/rowsInfo` | High
|
||||
12 | File | `/Applications/Google\ Drive.app/Contents/MacOS` | High
|
||||
13 | File | `/appointments/update_status.php` | High
|
||||
14 | File | `/authUserAction!edit.action` | High
|
||||
15 | File | `/bin/boa` | Medium
|
||||
16 | File | `/bookings/update_status.php` | High
|
||||
17 | File | `/cgi-bin/DownloadFlash` | High
|
||||
18 | File | `/classes/Master.php?f=delete_category` | High
|
||||
19 | File | `/classes/Users.php?f=delete_client` | High
|
||||
20 | File | `/contacts/listcontacts.php` | High
|
||||
21 | File | `/Core/Ap4File.cpp` | High
|
||||
22 | File | `/csms/admin/storages/view_storage.php` | High
|
||||
23 | File | `/dede/file_manage_control.php` | High
|
||||
24 | File | `/depotHead/list` | High
|
||||
25 | File | `/etc/ciel.cfg` | High
|
||||
26 | File | `/etc/openshift/server_priv.pem` | High
|
||||
27 | File | `/etc/shadow.sample` | High
|
||||
28 | File | `/forms/web_runScript` | High
|
||||
29 | File | `/garage/php_action/createBrand.php` | High
|
||||
30 | File | `/general/search.php?searchtype=simple` | High
|
||||
31 | File | `/goform/AddSysLogRule` | High
|
||||
32 | File | `/goform/formSetFirewallCfg` | High
|
||||
33 | ... | ... | ...
|
||||
|
||||
There are 276 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 283 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -36,7 +36,11 @@ _Tactics, techniques, and procedures_ (TTP) summarize the suspected MITRE ATT&CK
|
|||
ID | Technique | Weakness | Description | Confidence
|
||||
-- | --------- | -------- | ----------- | ----------
|
||||
1 | T1059.007 | CWE-79 | Cross Site Scripting | High
|
||||
2 | T1068 | CWE-264, CWE-284 | Execution with Unnecessary Privileges | High
|
||||
2 | T1068 | CWE-264, CWE-269, CWE-284 | Execution with Unnecessary Privileges | High
|
||||
3 | T1505 | CWE-89 | SQL Injection | High
|
||||
4 | ... | ... | ... | ...
|
||||
|
||||
There are 2 more TTP items available. Please use our online service to access the data.
|
||||
|
||||
## IOA - Indicator of Attack
|
||||
|
||||
|
|
|
@ -10,10 +10,7 @@ These _countries_ are directly (e.g. origin of attacks) or indirectly (e.g. acce
|
|||
|
||||
* [US](https://vuldb.com/?country.us)
|
||||
* [RU](https://vuldb.com/?country.ru)
|
||||
* [NO](https://vuldb.com/?country.no)
|
||||
* ...
|
||||
|
||||
There are 1 more country items available. Please use our online service to access the data.
|
||||
* [PT](https://vuldb.com/?country.pt)
|
||||
|
||||
## Actors
|
||||
|
||||
|
@ -42,14 +39,14 @@ _Tactics, techniques, and procedures_ (TTP) summarize the suspected MITRE ATT&CK
|
|||
|
||||
ID | Technique | Weakness | Description | Confidence
|
||||
-- | --------- | -------- | ----------- | ----------
|
||||
1 | T1006 | CWE-21, CWE-22, CWE-23, CWE-37, CWE-40 | Pathname Traversal | High
|
||||
1 | T1006 | CWE-21, CWE-22, CWE-23, CWE-40 | Pathname Traversal | High
|
||||
2 | T1040 | CWE-294, CWE-319 | Authentication Bypass by Capture-replay | High
|
||||
3 | T1055 | CWE-74 | Injection | High
|
||||
4 | T1059 | CWE-88, CWE-94, CWE-1321 | Cross Site Scripting | High
|
||||
5 | T1059.007 | CWE-79, CWE-80 | Cross Site Scripting | High
|
||||
5 | T1059.007 | CWE-79, CWE-80, CWE-85 | Cross Site Scripting | High
|
||||
6 | ... | ... | ... | ...
|
||||
|
||||
There are 20 more TTP items available. Please use our online service to access the data.
|
||||
There are 19 more TTP items available. Please use our online service to access the data.
|
||||
|
||||
## IOA - Indicator of Attack
|
||||
|
||||
|
@ -58,39 +55,42 @@ These _indicators of attack_ (IOA) list the potential fragments used for technic
|
|||
ID | Type | Indicator | Confidence
|
||||
-- | ---- | --------- | ----------
|
||||
1 | File | `/admin.php/Admin/adminadd.html` | High
|
||||
2 | File | `/admin/?page=bookings/view_details` | High
|
||||
3 | File | `/admin/?page=orders/manage_request` | High
|
||||
4 | File | `/admin/?page=user/manage_user` | High
|
||||
5 | File | `/admin/controller/JobLogController.java` | High
|
||||
6 | File | `/Admin/createClass.php` | High
|
||||
7 | File | `/admin/fst_upload.inc.php` | High
|
||||
8 | File | `/admin/problem_judge.php` | High
|
||||
9 | File | `/admin/sign/out` | High
|
||||
10 | File | `/admin/users/index.php` | High
|
||||
11 | File | `/api/common/ping` | High
|
||||
12 | File | `/api/public/signup` | High
|
||||
13 | File | `/api/v1/attack/falco` | High
|
||||
14 | File | `/api/v1/bait/set` | High
|
||||
15 | File | `/api/v1/nics/wifi/wlan0/ping` | High
|
||||
16 | File | `/api/v2/cli/commands` | High
|
||||
17 | File | `/asms/admin/?page=user/manage_user` | High
|
||||
18 | File | `/asms/admin/mechanics/manage_mechanic.php` | High
|
||||
19 | File | `/asms/admin/products/manage_product.php` | High
|
||||
20 | File | `/asms/products/view_product.php` | High
|
||||
21 | File | `/attachments` | Medium
|
||||
22 | File | `/avms/index.php` | High
|
||||
23 | File | `/bookings/update_status.php` | High
|
||||
24 | File | `/classes/Master.php?f=delete_appointment` | High
|
||||
25 | File | `/classes/Users.php?f=delete_client` | High
|
||||
26 | File | `/clearance/clearance.php` | High
|
||||
27 | File | `/depotHead/list` | High
|
||||
28 | File | `/editorder.php` | High
|
||||
29 | File | `/foms/all-orders.php?status=Cancelled%20by%20Customer` | High
|
||||
30 | File | `/garage/editorder.php` | High
|
||||
31 | File | `/index.php/admins/Fields/get_fields.html` | High
|
||||
32 | ... | ... | ...
|
||||
2 | File | `/Admin/add-student.php` | High
|
||||
3 | File | `/admin/controller/JobLogController.java` | High
|
||||
4 | File | `/Admin/createClass.php` | High
|
||||
5 | File | `/admin/fst_upload.inc.php` | High
|
||||
6 | File | `/admin/problem_judge.php` | High
|
||||
7 | File | `/admin/transactions/update_status.php` | High
|
||||
8 | File | `/admin/users/index.php` | High
|
||||
9 | File | `/api/v1/nics/wifi/wlan0/ping` | High
|
||||
10 | File | `/api/v2/cli/commands` | High
|
||||
11 | File | `/apiv1/` | Low
|
||||
12 | File | `/asms/admin/?page=user/manage_user` | High
|
||||
13 | File | `/asms/admin/mechanics/manage_mechanic.php` | High
|
||||
14 | File | `/asms/admin/products/manage_product.php` | High
|
||||
15 | File | `/asms/products/view_product.php` | High
|
||||
16 | File | `/attachments` | Medium
|
||||
17 | File | `/avms/index.php` | High
|
||||
18 | File | `/back/index.php/user/User/?1` | High
|
||||
19 | File | `/blog/comment` | High
|
||||
20 | File | `/bsms_ci/index.php` | High
|
||||
21 | File | `/bsms_ci/index.php/user/edit_user/` | High
|
||||
22 | File | `/calendar/viewcalendar.php` | High
|
||||
23 | File | `/classes/Master.php?f=delete_appointment` | High
|
||||
24 | File | `/classes/Users.php?f=delete_client` | High
|
||||
25 | File | `/Default/Bd` | Medium
|
||||
26 | File | `/device/` | Medium
|
||||
27 | File | `/event/admin/?page=user/list` | High
|
||||
28 | File | `/foms/all-orders.php?status=Cancelled%20by%20Customer` | High
|
||||
29 | File | `/garage/php_action/createBrand.php` | High
|
||||
30 | File | `/goform/setDiagnoseInfo` | High
|
||||
31 | File | `/goform/setSysPwd` | High
|
||||
32 | File | `/goform/setUplinkInfo` | High
|
||||
33 | File | `/hrm/controller/employee.php` | High
|
||||
34 | File | `/hrm/employeeadd.php` | High
|
||||
35 | ... | ... | ...
|
||||
|
||||
There are 274 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 296 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
|
@ -143,7 +143,7 @@ ID | Type | Indicator | Confidence
|
|||
31 | File | `/secure/admin/InsightDefaultCustomFieldConfig.jspa` | High
|
||||
32 | ... | ... | ...
|
||||
|
||||
There are 276 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
There are 274 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.
|
||||
|
||||
## References
|
||||
|
||||
|
|
Loading…
Reference in New Issue