cyber_threat_intelligence/actors/Malaysia Unknown/README.md
2023-02-20 20:18:09 +01:00

22 KiB

Malaysia Unknown - Cyber Threat Intelligence

These indicators were reported, collected, and generated during the VulDB CTI analysis of the actor known as Malaysia Unknown. The activity monitoring correlates data from social media, forums, chat rooms, and darknet markets. It helps to determine associated actors, specific activities, expected intentions, emerging research, and ongoing attacks. Our unique predictive model uses big data to forecast activities and their characteristics.

Live data and more analysis capabilities are available at https://vuldb.com/?actor.malaysia_unknown

Countries

These countries are directly (e.g. origin of attacks) or indirectly (e.g. access by proxy) associated with Malaysia Unknown:

There are 24 more country items available. Please use our online service to access the data.

IOC - Indicator of Compromise

These indicators of compromise (IOC) indicate associated network resources which are known to be part of research and attack activities of Malaysia Unknown.

ID IP address Hostname Campaign Confidence
1 1.9.0.0 - - High
2 1.32.0.0 - - High
3 5.181.34.0 visit.keznews.com - High
4 8.39.125.0 - - High
5 13.106.230.0 - - High
6 14.0.48.0 - - High
7 14.0.57.0 - - High
8 14.1.128.0 - - High
9 14.102.144.0 - - High
10 14.192.49.0 - - High
11 14.192.50.0 - - High
12 14.192.64.0 - - High
13 14.192.192.0 - - High
14 17.80.227.0 - - High
15 20.139.35.0 - - High
16 23.15.10.83 a23-15-10-83.deploy.static.akamaitechnologies.com - High
17 23.15.10.84 a23-15-10-84.deploy.static.akamaitechnologies.com - High
18 23.15.10.88 a23-15-10-88.deploy.static.akamaitechnologies.com - High
19 23.15.10.100 a23-15-10-100.deploy.static.akamaitechnologies.com - High
20 23.15.10.104 a23-15-10-104.deploy.static.akamaitechnologies.com - High
21 23.15.10.112 a23-15-10-112.deploy.static.akamaitechnologies.com - High
22 23.15.10.114 a23-15-10-114.deploy.static.akamaitechnologies.com - High
23 23.45.232.68 a23-45-232-68.deploy.static.akamaitechnologies.com - High
24 23.45.232.76 a23-45-232-76.deploy.static.akamaitechnologies.com - High
25 23.45.232.84 a23-45-232-84.deploy.static.akamaitechnologies.com - High
26 23.45.232.92 a23-45-232-92.deploy.static.akamaitechnologies.com - High
27 23.45.232.100 a23-45-232-100.deploy.static.akamaitechnologies.com - High
28 23.45.232.108 a23-45-232-108.deploy.static.akamaitechnologies.com - High
29 23.45.232.110 a23-45-232-110.deploy.static.akamaitechnologies.com - High
30 23.45.232.116 a23-45-232-116.deploy.static.akamaitechnologies.com - High
31 23.45.232.132 a23-45-232-132.deploy.static.akamaitechnologies.com - High
32 23.45.232.134 a23-45-232-134.deploy.static.akamaitechnologies.com - High
33 23.45.232.140 a23-45-232-140.deploy.static.akamaitechnologies.com - High
34 23.45.232.148 a23-45-232-148.deploy.static.akamaitechnologies.com - High
35 23.45.232.156 a23-45-232-156.deploy.static.akamaitechnologies.com - High
36 23.45.232.164 a23-45-232-164.deploy.static.akamaitechnologies.com - High
37 23.45.232.172 a23-45-232-172.deploy.static.akamaitechnologies.com - High
38 23.48.168.36 a23-48-168-36.deploy.static.akamaitechnologies.com - High
39 23.48.168.44 a23-48-168-44.deploy.static.akamaitechnologies.com - High
40 23.48.168.52 a23-48-168-52.deploy.static.akamaitechnologies.com - High
41 23.48.168.60 a23-48-168-60.deploy.static.akamaitechnologies.com - High
42 23.103.138.144 - - High
43 23.198.99.122 a23-198-99-122.deploy.static.akamaitechnologies.com - High
44 23.198.99.124 a23-198-99-124.deploy.static.akamaitechnologies.com - High
45 23.198.99.128 a23-198-99-128.deploy.static.akamaitechnologies.com - High
46 23.198.99.132 a23-198-99-132.deploy.static.akamaitechnologies.com - High
47 23.198.99.134 a23-198-99-134.deploy.static.akamaitechnologies.com - High
48 23.198.99.195 a23-198-99-195.deploy.static.akamaitechnologies.com - High
49 23.198.99.196 a23-198-99-196.deploy.static.akamaitechnologies.com - High
50 23.198.99.200 a23-198-99-200.deploy.static.akamaitechnologies.com - High
51 23.198.99.204 a23-198-99-204.deploy.static.akamaitechnologies.com - High
52 23.198.99.206 a23-198-99-206.deploy.static.akamaitechnologies.com - High
53 23.198.99.209 a23-198-99-209.deploy.static.akamaitechnologies.com - High
54 23.198.99.210 a23-198-99-210.deploy.static.akamaitechnologies.com - High
55 23.198.99.212 a23-198-99-212.deploy.static.akamaitechnologies.com - High
56 23.198.99.216 a23-198-99-216.deploy.static.akamaitechnologies.com - High
57 23.198.99.224 a23-198-99-224.deploy.static.akamaitechnologies.com - High
58 23.213.185.178 a23-213-185-178.deploy.static.akamaitechnologies.com - High
59 23.213.185.180 a23-213-185-180.deploy.static.akamaitechnologies.com - High
60 23.213.185.186 a23-213-185-186.deploy.static.akamaitechnologies.com - High
61 23.213.185.188 a23-213-185-188.deploy.static.akamaitechnologies.com - High
62 23.213.185.194 a23-213-185-194.deploy.static.akamaitechnologies.com - High
63 23.213.185.196 a23-213-185-196.deploy.static.akamaitechnologies.com - High
64 23.251.122.0 - - High
65 27.0.4.0 - - High
66 27.110.80.0 - - High
67 27.121.108.0 - - High
68 27.125.224.0 - - High
69 27.126.156.0 - - High
70 27.131.32.0 static-27-131-32-0.mykris.net - High
71 27.146.0.0 - - High
72 34.98.228.0 0.228.98.34.bc.googleusercontent.com - Medium
73 34.98.244.0 0.244.98.34.bc.googleusercontent.com - Medium
74 34.103.4.0 0.4.103.34.bc.googleusercontent.com - Medium
75 35.187.238.37 37.238.187.35.bc.googleusercontent.com - Medium
76 36.255.140.0 - - High
77 37.230.182.0 - - High
78 40.79.200.0 - - High
79 40.80.8.0 - - High
80 40.95.250.0 - - High
81 40.96.14.16 - - High
82 40.96.14.112 - - High
83 40.96.14.128 - - High
84 40.96.15.48 - - High
85 40.96.16.176 - - High
86 40.96.16.192 - - High
87 40.96.17.48 - - High
88 40.96.24.120 - - High
89 40.96.25.80 - - High
90 40.96.25.96 - - High
91 40.96.25.112 - - High
92 40.96.47.224 - - High
93 40.100.16.0 - - High
94 40.103.28.112 - - High
95 40.103.28.176 - - High
96 40.103.28.240 - - High
97 40.103.29.48 - - High
98 42.0.28.0 - - High
99 42.1.60.0 - - High
100 42.152.0.0 - - High
101 42.188.0.0 - - High
102 43.224.88.0 - - High
103 43.225.108.0 - - High
104 43.226.230.0 - - High
105 43.228.158.0 - - High
106 43.228.200.0 - - High
107 43.228.244.0 - - High
108 43.228.248.0 - - High
109 43.230.96.0 - - High
110 43.230.181.108 - - High
111 43.230.182.108 - - High
112 43.231.4.0 - - High
113 43.231.72.0 - - High
114 43.231.224.0 - - High
115 43.239.233.0 - - High
116 43.239.234.0 - - High
117 43.239.252.0 - - High
118 43.240.20.0 - - High
119 43.241.40.0 - - High
120 43.241.96.0 - - High
121 43.242.108.0 - - High
122 43.245.61.224 - - High
123 43.245.124.0 - - High
124 43.246.164.0 - - High
125 43.246.176.0 - - High
126 43.251.113.0 - - High
127 43.251.136.0 - - High
128 43.251.167.128 - - High
129 43.251.208.0 - - High
130 43.252.36.0 - - High
131 43.252.44.0 - - High
132 43.252.152.0 - - High
133 43.252.212.0 - - High
134 43.252.216.0 - - High
135 43.252.232.0 - - High
136 43.254.76.0 - - High
137 43.254.120.0 a43-254-120-0.deploy.static.akamaitechnologies.com - High
138 43.255.81.0 - - High
139 43.255.172.0 - - High
140 45.12.70.159 ifup-good-vm1.alltieinc.com - High
141 45.12.71.159 - - High
142 45.64.168.0 - - High
143 45.112.196.0 - - High
144 45.114.28.0 - - High
145 45.114.100.0 - - High
146 45.115.220.0 - - High
147 45.116.12.0 - - High
148 45.116.160.0 - - High
149 45.116.172.0 - - High
150 45.116.176.0 - - High
151 45.116.236.0 - - High
152 45.116.240.0 - - High
153 45.117.120.0 - - High
154 45.117.228.0 - - High
155 45.117.236.0 - - High
156 45.119.160.0 - - High
157 45.120.52.0 - - High
158 45.120.128.0 - - High
159 45.120.203.0 - - High
160 45.121.36.0 - - High
161 45.121.144.0 - - High
162 45.123.100.0 - - High
163 45.123.124.0 - - High
164 45.126.88.0 - - High
165 45.127.4.0 - - High
166 45.195.248.0 - - High
167 45.248.38.0 - - High
168 45.248.53.0 - - High
169 45.255.252.0 - - High
170 46.36.202.31 - - High
171 46.244.29.128 - - High
172 47.250.0.0 - - High
173 47.254.192.0 - - High
174 49.50.12.0 - - High
175 49.50.236.0 - - High
176 49.124.0.0 - - High
177 49.236.192.0 - - High
178 52.98.34.240 - - High
179 52.98.37.128 - - High
180 52.98.40.104 - - High
181 52.98.43.128 - - High
182 52.98.94.128 - - High
183 52.99.128.144 - - High
184 52.99.128.160 - - High
185 57.73.128.0 - - High
186 58.26.0.0 - - High
187 58.27.0.0 - - High
188 58.71.128.0 - - High
189 58.84.8.0 - - High
190 58.84.16.0 - - High
191 58.84.40.0 - - High
192 58.139.0.0 - - High
193 59.152.46.0 - - High
194 ... ... ... ...

There are 774 more IOC items available. Please use our online service to access the data.

TTP - Tactics, Techniques, Procedures

Tactics, techniques, and procedures (TTP) summarize the suspected MITRE ATT&CK techniques used by Malaysia Unknown. This data is unique as it uses our predictive model for actor profiling.

ID Technique Weakness Description Confidence
1 T1006 CWE-22 Pathname Traversal High
2 T1055 CWE-74 Injection High
3 T1059 CWE-88, CWE-94, CWE-1321 Cross Site Scripting High
4 T1059.007 CWE-79, CWE-80 Cross Site Scripting High
5 T1068 CWE-250, CWE-264, CWE-269, CWE-284 Execution with Unnecessary Privileges High
6 ... ... ... ...

There are 18 more TTP items available. Please use our online service to access the data.

IOA - Indicator of Attack

These indicators of attack (IOA) list the potential fragments used for technical activities like reconnaissance, exploitation, privilege escalation, and exfiltration by Malaysia Unknown. This data is unique as it uses our predictive model for actor profiling.

ID Type Indicator Confidence
1 File .github/workflows/combine-prs.yml High
2 File .php.gif Medium
3 File /admin/api/admin/articles/ High
4 File /admin/submit-articles High
5 File /adms/admin/?page=vehicles/sell_vehicle High
6 File /adms/admin/?page=vehicles/view_transaction High
7 File /apilog.php Medium
8 File /bin/httpd Medium
9 File /Default/Bd Medium
10 File /dev/block/mmcblk0rpmb High
11 File /DocSystem/Repos/getReposAllUsers.do High
12 File /face-recognition-php/facepay-master/camera.php High
13 File /forum/away.php High
14 File /forum/PostPrivateMessage High
15 File /fos/admin/ajax.php?action=login High
16 File /fos/admin/index.php?page=menu High
17 File /home/masterConsole High
18 File /home/sendBroadcast High
19 File /hrm/controller/employee.php High
20 File /hrm/employeeadd.php High
21 File /hrm/employeeview.php High
22 File /index.php Medium
23 File /items/view_item.php High
24 File /jsoa/hntdCustomDesktopActionContent High
25 File /login/index.php High
26 File /lookin/info Medium
27 File /manager/index.php High
28 File /medical/inventories.php High
29 File /modules/profile/index.php High
30 File /modules/projects/vw_files.php High
31 File /modules/public/calendar.php High
32 File /newsDia.php Medium
33 File /out.php Medium
34 File /php_action/editProductImage.php High
35 File /product/savenewproduct.php?flag=1 High
36 File /proxy Low
37 File /Redcock-Farm/farm/category.php High
38 File /reports/rwservlet High
39 File /sacco_shield/manage_user.php High
40 File /services/Card/findUser High
41 File /spip.php Medium
42 File /sqlitemanager/main.php?dbsel=-1%20or%2072%20=%2072 High
43 File /staff/bookdetails.php High
44 File /uncpath/ Medium
45 File /user/update_booking.php High
46 File /view-property.php High
47 File /Wedding-Management-PHP/admin/photos_add.php High
48 File /wireless/security.asp High
49 File /wordpress/wp-admin/options-general.php High
50 File /wp-content/plugins/updraftplus/admin.php High
51 File 01article.php High
52 File AbstractScheduleJob.java High
53 File action.php Medium
54 File actionphp/download.File.php High
55 File adclick.php Medium
56 File addtocart.asp High
57 File admin.php Medium
58 File admin/abc.php High
59 File admin/admin/adminsave.html High
60 ... ... ...

There are 523 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.

References

The following list contains external sources which discuss the actor and the associated activities:

Literature

The following articles explain our unique predictive cyber threat intelligence:

License

(c) 1997-2023 by vuldb.com. All data on this page is shared under the license CC BY-NC-SA 4.0. Questions? Check the FAQ, read the documentation or contact us!