cyber_threat_intelligence/actors/Slovenia Unknown
2023-10-16 15:34:26 +02:00
..
README.md Update October 2023 2023-10-16 15:34:26 +02:00

Slovenia Unknown - Cyber Threat Intelligence

These indicators were reported, collected, and generated during the VulDB CTI analysis of the actor known as Slovenia Unknown. The activity monitoring correlates data from social media, forums, chat rooms, and darknet markets. It helps to determine associated actors, specific activities, expected intentions, emerging research, and ongoing attacks. Our unique predictive model uses big data to forecast activities and their characteristics.

Live data and more analysis capabilities are available at https://vuldb.com/?actor.slovenia_unknown

Countries

These countries are directly (e.g. origin of attacks) or indirectly (e.g. access by proxy) associated with Slovenia Unknown:

There are 19 more country items available. Please use our online service to access the data.

IOC - Indicator of Compromise

These indicators of compromise (IOC) indicate associated network resources which are known to be part of research and attack activities of Slovenia Unknown.

ID IP address Hostname Campaign Confidence
1 5.32.136.0 - - High
2 5.62.61.144 r-144-61-62-5.consumer-pool.prcdn.net - High
3 5.62.63.124 r-124-63-62-5.consumer-pool.prcdn.net - High
4 5.132.128.0 - - High
5 5.157.72.0 - - High
6 5.249.176.0 - - High
7 23.226.112.0 icnet4.intercoding.net - High
8 31.6.59.0 undefined.hostname.localhost - High
9 31.7.192.0 - - High
10 31.15.128.0 - - High
11 32.106.114.0 - - High
12 32.112.59.0 - - High
13 34.99.184.0 0.184.99.34.bc.googleusercontent.com - Medium
14 34.103.136.0 0.136.103.34.bc.googleusercontent.com - Medium
15 34.103.200.0 0.200.103.34.bc.googleusercontent.com - Medium
16 34.103.245.0 0.245.103.34.bc.googleusercontent.com - Medium
17 37.1.89.192 - - High
18 37.18.224.0 - - High
19 37.19.64.0 - - High
20 37.19.68.0 - - High
21 37.230.133.0 - - High
22 37.252.224.0 - - High
23 43.113.226.0 - - High
24 45.10.240.0 ddos-guard.net - High
25 45.12.70.201 polygynous.globalhilive.com - High
26 45.12.71.201 - - High
27 45.13.73.0 - - High
28 45.15.64.0 - - High
29 45.15.65.0 - - High
30 45.15.66.0 - - High
31 45.64.114.0 - - High
32 45.94.244.0 - - High
33 45.95.48.0 - - High
34 45.136.188.0 - - High
35 45.138.220.0 - - High
36 45.138.244.0 - - High
37 45.138.252.0 - - High
38 45.141.168.0 - - High
39 45.146.232.0 - - High
40 45.147.136.0 - - High
41 45.149.92.0 - - High
42 45.150.20.0 - - High
43 45.157.4.0 - - High
44 45.157.5.0 - - High
45 45.157.6.0 - - High
46 45.157.252.0 - - High
47 45.158.60.0 - - High
48 45.158.236.0 - - High
49 46.19.8.0 - - High
50 46.23.0.0 - - High
51 46.54.128.0 - - High
52 46.99.251.50 - - High
53 46.122.0.0 - - High
54 46.150.32.0 - - High
55 46.151.232.0 - - High
56 46.163.0.0 - - High
57 46.163.4.0 - - High
58 46.163.8.0 - - High
59 46.163.16.0 - - High
60 46.163.32.0 - - High
61 46.163.51.0 - - High
62 46.163.52.0 - - High
63 46.163.56.0 - - High
64 46.163.57.0 - - High
65 46.164.0.0 cpe-46-164-0-0.dynamic.amis.net - High
66 46.182.224.0 - - High
67 46.248.64.0 46-248-64-0.dynamic.t-2.net - High
68 46.254.0.0 - - High
69 46.254.56.0 - - High
70 46.254.144.0 - - High
71 57.90.64.0 - - High
72 57.90.224.0 - - High
73 62.84.224.0 cpe-62-84-224-0.dynamic.amis.net - High
74 63.167.237.196 - - High
75 67.221.242.0 - - High
76 67.221.244.0 network.6connect.net - High
77 67.221.246.0 network.6connect.net - High
78 77.38.0.0 - - High
79 77.73.104.0 77-73-104-0.ipv4.telemach.net - High
80 77.94.128.0 bsn-77-94-128-0.static.stelkom.net - High
81 77.111.0.0 - - High
82 77.234.128.0 - - High
83 78.153.32.0 - - High
84 80.68.153.0 - - High
85 80.95.224.0 - - High
86 80.246.224.0 - - High
87 81.17.224.0 n224-h0.loc-a.akton.net - High
88 81.17.232.0 n232-h0.loc-d.akton.net - High
89 81.17.234.0 - - High
90 81.17.236.0 n236-h0.loc-s.akton.net - High
91 82.149.0.0 - - High
92 82.192.32.0 - - High
93 82.214.64.0 c82-214-64-0.loc.akton.net - High
94 82.214.72.0 c82-214-72-0.loc.akton.net - High
95 82.214.79.0 c82-214-79-0.loc.akton.net - High
96 82.214.80.0 c82-214-80-0.loc.akton.net - High
97 82.214.84.0 c82-214-84-0.loc.akton.net - High
98 82.214.88.0 c82-214-88-0.loc.akton.net - High
99 82.214.96.0 c82-214-96-0.loc.akton.net - High
100 82.214.104.0 c82-214-104-0.loc.akton.net - High
101 82.214.106.0 c82-214-106-0.loc.akton.net - High
102 82.214.120.0 c82-214-120-0.loc.akton.net - High
103 82.214.122.0 c82-214-122-0.loc.akton.net - High
104 82.214.124.0 c82-214-124-0.loc.akton.net - High
105 84.20.224.0 - - High
106 84.39.208.0 external-0-208.gov.si - High
107 84.41.0.0 - - High
108 84.41.64.0 - - High
109 84.41.96.0 - - High
110 84.41.109.0 - - High
111 84.41.110.0 - - High
112 84.41.112.0 - - High
113 84.41.114.0 - - High
114 84.41.119.0 - - High
115 84.41.120.0 - - High
116 84.41.122.0 - - High
117 84.41.124.0 - - High
118 84.52.128.0 - - High
119 84.54.32.0 - - High
120 84.255.192.0 84-255-192-0.static.t-2.net - High
121 85.10.0.0 - - High
122 85.10.32.0 - - High
123 85.208.172.0 - - High
124 86.58.0.0 - - High
125 86.61.0.0 - - High
126 86.61.64.0 BSN-61-64-0.static.siol.net - High
127 86.61.80.0 - - High
128 86.61.88.0 BSN-61-88-0.dynamic.siol.net - High
129 86.61.92.0 - - High
130 86.61.95.0 BSN-61-95-0.dynamic.siol.net - High
131 86.61.96.0 - - High
132 87.119.128.0 - - High
133 88.200.0.0 - - High
134 89.116.184.0 - - High
135 89.142.0.0 BSN-142-0-0.dynamic.siol.net - High
136 89.143.0.0 - - High
137 89.143.128.0 BSN-143-128-0.dynamic.siol.net - High
138 89.143.192.0 - - High
139 89.143.224.0 - - High
140 89.143.244.0 bsn-143-244-0.static.siol.net - High
141 89.143.248.0 BSN-143-248-0.static.siol.net - High
142 89.185.79.0 - - High
143 89.212.0.0 89-212-0-0.static.t-2.net - High
144 89.233.112.0 89-233-112-0.dynamic.t-2.net - High
145 90.157.128.0 cpe-90-157-128-0.dynamic.amis.net - High
146 91.132.72.0 - - High
147 91.132.208.0 91-132-208-0.ipv4.telemach.net - High
148 91.185.192.0 - - High
149 91.195.146.0 - - High
150 91.198.0.0 - - High
151 91.198.52.0 - - High
152 91.198.96.0 - - High
153 91.198.112.0 - - High
154 91.198.190.0 - - High
155 91.198.214.0 - - High
156 91.199.23.0 - - High
157 91.199.61.0 - - High
158 91.199.124.0 - - High
159 91.199.131.0 - - High
160 91.199.142.0 - - High
161 ... ... ... ...

There are 638 more IOC items available. Please use our online service to access the data.

TTP - Tactics, Techniques, Procedures

Tactics, techniques, and procedures (TTP) summarize the suspected MITRE ATT&CK techniques used by Slovenia Unknown. This data is unique as it uses our predictive model for actor profiling.

ID Technique Weakness Description Confidence
1 T1006 CWE-21, CWE-22, CWE-23 Pathname Traversal High
2 T1040 CWE-319 Authentication Bypass by Capture-replay High
3 T1055 CWE-74 Injection High
4 T1059 CWE-88, CWE-94, CWE-1321 Cross Site Scripting High
5 T1059.007 CWE-79, CWE-80 Cross Site Scripting High
6 ... ... ... ...

There are 20 more TTP items available. Please use our online service to access the data.

IOA - Indicator of Attack

These indicators of attack (IOA) list the potential fragments used for technical activities like reconnaissance, exploitation, privilege escalation, and exfiltration by Slovenia Unknown. This data is unique as it uses our predictive model for actor profiling.

ID Type Indicator Confidence
1 File //WEB-INF Medium
2 File /about.php Medium
3 File /admin.php/update/getFile.html High
4 File /admin/cashadvance_row.php High
5 File /admin/maintenance/view_designation.php High
6 File /admin/save.php High
7 File /admin/sys_sql_query.php High
8 File /admin/userprofile.php High
9 File /api/baskets/{name} High
10 File /api/download High
11 File /api/v1/terminal/sessions/?limit=1 High
12 File /APR/login.php High
13 File /bitrix/admin/ldap_server_edit.php High
14 File /category.php High
15 File /categorypage.php High
16 File /cgi-bin/luci/api/wireless High
17 File /cgi-bin/vitogate.cgi High
18 File /cgi-bin/wapopen High
19 File /company/store High
20 File /Content/Template/root/reverse-shell.aspx High
21 File /Controller/Ajaxfileupload.ashx High
22 File /core/conditions/AbstractWrapper.java High
23 File /etc/passwd Medium
24 File /feeds/post/publish High
25 File /forum/away.php High
26 File /h/ Low
27 File /HNAP1 Low
28 File /inc/jquery/uploadify/uploadify.php High
29 File /index.php?app=main&func=passport&action=login High
30 File /index.php?page=category_list High
31 File /jeecg-boot/sys/common/upload High
32 File /jobinfo/ Medium
33 File /Moosikay/order.php High
34 File /mygym/admin/index.php?view_exercises High
35 File /opac/Actions.php?a=login High
36 File /php-opos/index.php High
37 File /PreviewHandler.ashx High
38 File /public/launchNewWindow.jsp High
39 File /recipe-result High
40 File /register.do Medium
41 File /reservation/add_message.php High
42 File /RPS2019Service/status.html High
43 File /Service/ImageStationDataService.asmx High
44 File /sicweb-ajax/tmproot/ High
45 File /spip.php Medium
46 File /student/bookdetails.php High
47 File /SystemManage/User/GetGridJson?_search=false&nd=1680855479750&rows=50&page=1&sidx=F_CreatorTime+desc&sord=asc High
48 File /uploads/exam_question/ High
49 File /user/ticket/create High
50 File /user/updatePwd High
51 File /UserSelfServiceSettings.jsp High
52 File /var/lib/docker/<remapping> High
53 File /wp-admin/admin-ajax.php High
54 File /xxl-job-admin/user/add High
55 File a-forms.php Medium
56 File activenews_view.asp High
57 ... ... ...

There are 496 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.

References

The following list contains external sources which discuss the actor and the associated activities:

Literature

The following articles explain our unique predictive cyber threat intelligence:

License

(c) 1997-2023 by vuldb.com. All data on this page is shared under the license CC BY-NC-SA 4.0. Questions? Check the FAQ, read the documentation or contact us!