cyber_threat_intelligence/actors/South Korea Unknown
2023-08-01 08:06:09 +02:00
..
README.md Update August 2023 2023-08-01 08:06:09 +02:00

South Korea Unknown - Cyber Threat Intelligence

These indicators were reported, collected, and generated during the VulDB CTI analysis of the actor known as South Korea Unknown. The activity monitoring correlates data from social media, forums, chat rooms, and darknet markets. It helps to determine associated actors, specific activities, expected intentions, emerging research, and ongoing attacks. Our unique predictive model uses big data to forecast activities and their characteristics.

Live data and more analysis capabilities are available at https://vuldb.com/?actor.south_korea_unknown

Countries

These countries are directly (e.g. origin of attacks) or indirectly (e.g. access by proxy) associated with South Korea Unknown:

There are 21 more country items available. Please use our online service to access the data.

IOC - Indicator of Compromise

These indicators of compromise (IOC) indicate associated network resources which are known to be part of research and attack activities of South Korea Unknown.

ID IP address Hostname Campaign Confidence
1 1.11.0.0 - - High
2 1.16.0.0 - - High
3 1.96.0.0 - - High
4 1.176.0.0 - - High
5 1.201.0.0 - - High
6 1.208.0.0 - - High
7 1.224.0.0 - - High
8 2.59.153.0 - - High
9 5.62.35.32 r-32.35.62.5.ptr.avast.com - High
10 5.189.200.128 - - High
11 5.231.77.0 - - High
12 8.38.149.0 - - High
13 13.104.47.0 - - High
14 13.104.56.0 - - High
15 13.104.60.0 - - High
16 13.104.62.0 - - High
17 13.104.63.0 - - High
18 13.104.96.88 - - High
19 13.104.96.176 - - High
20 13.104.96.192 - - High
21 13.104.96.200 - - High
22 13.104.157.0 - - High
23 13.106.90.0 - - High
24 13.106.92.0 - - High
25 13.106.224.0 - - High
26 13.107.185.148 - - High
27 13.107.185.160 - - High
28 13.107.194.20 - - High
29 13.124.0.0 ec2-13-124-0-0.ap-northeast-2.compute.amazonaws.com - Medium
30 13.209.0.0 ec2-13-209-0-0.ap-northeast-2.compute.amazonaws.com - Medium
31 14.0.32.0 - - High
32 14.0.64.0 - - High
33 14.4.0.0 - - High
34 14.32.0.0 - - High
35 14.64.0.0 - - High
36 14.128.48.0 - - High
37 14.128.128.0 - - High
38 14.129.0.0 - - High
39 14.138.0.0 - - High
40 14.192.80.0 - - High
41 14.206.0.0 - - High
42 15.164.0.0 ec2-15-164-0-0.ap-northeast-2.compute.amazonaws.com - Medium
43 17.91.200.0 - - High
44 17.253.114.0 - - High
45 20.39.168.0 - - High
46 20.39.184.0 - - High
47 20.39.192.0 - - High
48 20.41.64.0 - - High
49 20.44.24.0 - - High
50 20.150.4.0 - - High
51 20.150.14.0 - - High
52 20.190.144.128 - - High
53 20.190.148.0 - - High
54 20.190.179.0 - - High
55 20.190.180.0 - - High
56 23.15.13.0 a23-15-13-0.deploy.static.akamaitechnologies.com - High
57 23.35.218.4 a23-35-218-4.deploy.static.akamaitechnologies.com - High
58 23.35.218.12 a23-35-218-12.deploy.static.akamaitechnologies.com - High
59 23.35.218.20 a23-35-218-20.deploy.static.akamaitechnologies.com - High
60 23.35.218.28 a23-35-218-28.deploy.static.akamaitechnologies.com - High
61 23.35.218.36 a23-35-218-36.deploy.static.akamaitechnologies.com - High
62 23.35.218.44 a23-35-218-44.deploy.static.akamaitechnologies.com - High
63 23.35.218.52 a23-35-218-52.deploy.static.akamaitechnologies.com - High
64 23.35.218.60 a23-35-218-60.deploy.static.akamaitechnologies.com - High
65 23.35.218.68 a23-35-218-68.deploy.static.akamaitechnologies.com - High
66 23.35.218.76 a23-35-218-76.deploy.static.akamaitechnologies.com - High
67 23.35.218.84 a23-35-218-84.deploy.static.akamaitechnologies.com - High
68 23.35.218.92 a23-35-218-92.deploy.static.akamaitechnologies.com - High
69 23.35.218.100 a23-35-218-100.deploy.static.akamaitechnologies.com - High
70 23.35.218.108 a23-35-218-108.deploy.static.akamaitechnologies.com - High
71 23.35.218.116 a23-35-218-116.deploy.static.akamaitechnologies.com - High
72 23.35.218.124 a23-35-218-124.deploy.static.akamaitechnologies.com - High
73 23.44.173.4 a23-44-173-4.deploy.static.akamaitechnologies.com - High
74 23.44.173.12 a23-44-173-12.deploy.static.akamaitechnologies.com - High
75 23.44.173.20 a23-44-173-20.deploy.static.akamaitechnologies.com - High
76 23.44.173.28 a23-44-173-28.deploy.static.akamaitechnologies.com - High
77 23.44.173.36 a23-44-173-36.deploy.static.akamaitechnologies.com - High
78 23.44.173.44 a23-44-173-44.deploy.static.akamaitechnologies.com - High
79 23.44.173.52 a23-44-173-52.deploy.static.akamaitechnologies.com - High
80 23.44.173.60 a23-44-173-60.deploy.static.akamaitechnologies.com - High
81 23.44.173.68 a23-44-173-68.deploy.static.akamaitechnologies.com - High
82 23.44.173.76 a23-44-173-76.deploy.static.akamaitechnologies.com - High
83 23.44.173.84 a23-44-173-84.deploy.static.akamaitechnologies.com - High
84 23.59.72.78 a23-59-72-78.deploy.static.akamaitechnologies.com - High
85 23.59.72.84 a23-59-72-84.deploy.static.akamaitechnologies.com - High
86 23.59.72.92 a23-59-72-92.deploy.static.akamaitechnologies.com - High
87 23.59.72.100 a23-59-72-100.deploy.static.akamaitechnologies.com - High
88 23.59.72.108 a23-59-72-108.deploy.static.akamaitechnologies.com - High
89 23.59.72.116 a23-59-72-116.deploy.static.akamaitechnologies.com - High
90 23.59.72.132 a23-59-72-132.deploy.static.akamaitechnologies.com - High
91 23.59.72.140 a23-59-72-140.deploy.static.akamaitechnologies.com - High
92 23.59.72.148 a23-59-72-148.deploy.static.akamaitechnologies.com - High
93 23.59.72.156 a23-59-72-156.deploy.static.akamaitechnologies.com - High
94 23.59.72.164 a23-59-72-164.deploy.static.akamaitechnologies.com - High
95 23.59.72.172 a23-59-72-172.deploy.static.akamaitechnologies.com - High
96 23.59.72.180 a23-59-72-180.deploy.static.akamaitechnologies.com - High
97 23.59.72.196 a23-59-72-196.deploy.static.akamaitechnologies.com - High
98 23.59.151.4 a23-59-151-4.deploy.static.akamaitechnologies.com - High
99 23.59.151.12 a23-59-151-12.deploy.static.akamaitechnologies.com - High
100 23.59.151.20 a23-59-151-20.deploy.static.akamaitechnologies.com - High
101 23.59.151.28 a23-59-151-28.deploy.static.akamaitechnologies.com - High
102 23.59.151.36 a23-59-151-36.deploy.static.akamaitechnologies.com - High
103 23.59.151.44 a23-59-151-44.deploy.static.akamaitechnologies.com - High
104 23.59.151.52 a23-59-151-52.deploy.static.akamaitechnologies.com - High
105 23.59.151.60 a23-59-151-60.deploy.static.akamaitechnologies.com - High
106 23.59.151.68 a23-59-151-68.deploy.static.akamaitechnologies.com - High
107 23.59.151.76 a23-59-151-76.deploy.static.akamaitechnologies.com - High
108 23.59.151.84 a23-59-151-84.deploy.static.akamaitechnologies.com - High
109 23.59.151.92 a23-59-151-92.deploy.static.akamaitechnologies.com - High
110 23.59.151.100 a23-59-151-100.deploy.static.akamaitechnologies.com - High
111 23.59.151.108 a23-59-151-108.deploy.static.akamaitechnologies.com - High
112 23.59.151.116 a23-59-151-116.deploy.static.akamaitechnologies.com - High
113 23.59.151.124 a23-59-151-124.deploy.static.akamaitechnologies.com - High
114 23.65.188.30 a23-65-188-30.deploy.static.akamaitechnologies.com - High
115 23.65.188.36 a23-65-188-36.deploy.static.akamaitechnologies.com - High
116 23.65.188.44 a23-65-188-44.deploy.static.akamaitechnologies.com - High
117 23.65.188.52 a23-65-188-52.deploy.static.akamaitechnologies.com - High
118 23.65.188.60 a23-65-188-60.deploy.static.akamaitechnologies.com - High
119 23.65.188.68 a23-65-188-68.deploy.static.akamaitechnologies.com - High
120 23.67.53.55 a23-67-53-55.deploy.static.akamaitechnologies.com - High
121 23.67.53.60 a23-67-53-60.deploy.static.akamaitechnologies.com - High
122 23.67.53.62 a23-67-53-62.deploy.static.akamaitechnologies.com - High
123 23.67.53.68 a23-67-53-68.deploy.static.akamaitechnologies.com - High
124 23.67.53.76 a23-67-53-76.deploy.static.akamaitechnologies.com - High
125 23.67.53.84 a23-67-53-84.deploy.static.akamaitechnologies.com - High
126 23.67.53.92 a23-67-53-92.deploy.static.akamaitechnologies.com - High
127 23.67.53.100 a23-67-53-100.deploy.static.akamaitechnologies.com - High
128 23.67.53.117 a23-67-53-117.deploy.static.akamaitechnologies.com - High
129 23.67.53.118 a23-67-53-118.deploy.static.akamaitechnologies.com - High
130 23.67.53.196 a23-67-53-196.deploy.static.akamaitechnologies.com - High
131 23.67.53.204 a23-67-53-204.deploy.static.akamaitechnologies.com - High
132 23.67.53.206 a23-67-53-206.deploy.static.akamaitechnologies.com - High
133 23.103.138.0 - - High
134 23.103.141.128 - - High
135 23.103.141.192 - - High
136 23.211.117.55 a23-211-117-55.deploy.static.akamaitechnologies.com - High
137 23.211.117.60 a23-211-117-60.deploy.static.akamaitechnologies.com - High
138 23.211.117.68 a23-211-117-68.deploy.static.akamaitechnologies.com - High
139 23.211.117.70 a23-211-117-70.deploy.static.akamaitechnologies.com - High
140 23.248.160.0 - - High
141 23.251.124.0 - - High
142 27.0.236.0 - - High
143 27.1.0.0 - - High
144 27.35.0.0 - - High
145 27.96.128.0 - - High
146 27.100.128.0 - - High
147 27.101.0.0 - - High
148 27.102.0.0 - - High
149 27.111.96.0 - - High
150 27.112.128.0 - - High
151 27.113.0.0 - - High
152 27.115.128.0 - - High
153 27.116.64.0 - - High
154 27.116.128.0 - - High
155 27.117.0.0 - - High
156 27.118.64.0 - - High
157 27.118.128.0 - - High
158 27.119.0.0 - - High
159 27.120.0.0 - - High
160 27.122.128.0 - - High
161 27.124.8.0 - - High
162 27.124.128.0 - - High
163 27.125.0.0 - - High
164 27.126.0.0 - - High
165 27.160.0.0 - - High
166 27.176.0.0 - - High
167 27.232.0.0 - - High
168 27.255.64.0 - - High
169 34.98.164.0 0.164.98.34.bc.googleusercontent.com - Medium
170 34.98.174.0 0.174.98.34.bc.googleusercontent.com - Medium
171 36.38.0.0 - - High
172 37.153.134.128 - - High
173 37.156.6.0 - - High
174 37.252.244.0 - - High
175 39.4.0.0 - - High
176 39.16.0.0 - - High
177 39.112.0.0 - - High
178 40.66.64.136 - - High
179 40.66.92.0 - - High
180 40.79.220.0 - - High
181 40.80.32.0 - - High
182 40.80.168.0 koreasouth03.rnm.core.windows.net - High
183 40.80.224.0 - - High
184 40.82.128.0 - - High
185 40.89.192.0 - - High
186 40.90.17.224 - - High
187 40.90.128.176 - - High
188 40.90.131.128 - - High
189 40.90.139.128 - - High
190 40.90.156.64 msnbot-40-90-156-64.search.msn.com - High
191 40.90.157.32 msnbot-40-90-157-32.search.msn.com - High
192 40.92.84.0 - - High
193 40.92.242.0 - - High
194 40.92.254.0 - - High
195 40.93.86.0 - - High
196 40.93.242.0 - - High
197 40.93.254.0 - - High
198 40.94.227.0 - - High
199 40.94.233.0 - - High
200 40.94.234.0 - - High
201 40.94.241.0 - - High
202 40.94.242.0 - - High
203 40.94.244.0 - - High
204 40.94.246.0 - - High
205 40.94.254.0 - - High
206 40.95.83.0 - - High
207 40.95.242.0 - - High
208 40.95.254.0 - - High
209 40.96.2.144 - - High
210 40.96.2.160 - - High
211 40.96.2.192 - - High
212 40.96.3.0 - - High
213 40.96.7.160 - - High
214 40.96.17.64 - - High
215 40.96.17.128 - - High
216 40.96.17.160 - - High
217 40.96.47.8 - - High
218 40.96.47.64 - - High
219 40.96.47.128 - - High
220 40.96.47.192 - - High
221 40.100.20.0 - - High
222 40.100.44.0 - - High
223 40.100.48.0 - - High
224 40.103.28.64 - - High
225 40.103.28.128 - - High
226 40.103.28.192 - - High
227 40.103.29.0 - - High
228 40.107.128.0 mail-eopbgr1280000.outbound.protection.outlook.com - High
229 40.107.132.0 mail-eopbgr1320000.outbound.protection.outlook.com - High
230 40.107.226.0 - - High
231 40.107.230.0 - - High
232 40.107.233.0 - - High
233 40.108.153.0 - - High
234 40.108.156.0 - - High
235 40.126.16.128 - - High
236 40.126.20.0 - - High
237 40.126.51.0 - - High
238 40.126.51.32 - - High
239 40.126.52.0 - - High
240 40.126.52.128 - - High
241 42.8.0.0 - - High
242 42.16.0.0 - - High
243 42.32.0.0 - - High
244 42.82.0.0 - - High
245 43.224.104.0 - - High
246 43.226.228.0 - - High
247 43.226.231.0 - - High
248 43.227.116.0 - - High
249 43.227.120.0 - - High
250 43.228.160.0 - - High
251 43.229.0.0 - - High
252 43.230.0.0 - - High
253 43.230.76.0 - - High
254 43.230.80.0 - - High
255 43.230.216.0 - - High
256 43.241.44.0 - - High
257 43.241.104.0 - - High
258 43.242.0.0 - - High
259 43.242.112.0 - - High
260 43.243.216.0 - - High
261 43.246.152.0 - - High
262 43.246.180.0 - - High
263 43.247.104.0 - - High
264 43.247.192.0 - - High
265 43.249.128.0 - - High
266 43.249.129.0 - - High
267 43.249.130.128 - - High
268 43.249.131.128 - - High
269 43.250.152.0 - - High
270 43.251.28.0 - - High
271 43.251.68.0 - - High
272 43.251.120.0 - - High
273 43.254.244.0 - - High
274 43.255.248.0 - - High
275 45.12.70.123 halflearned.yourbandinc.com - High
276 45.12.71.123 - - High
277 45.43.40.0 - - High
278 45.64.140.0 - - High
279 45.64.144.0 - - High
280 45.64.152.0 - - High
281 45.64.172.0 - - High
282 45.67.97.0 - - High
283 45.91.225.0 - - High
284 45.94.152.0 - - High
285 45.112.88.0 - - High
286 45.112.96.0 - - High
287 45.112.112.0 - - High
288 45.112.152.0 - - High
289 45.112.160.0 - - High
290 45.112.168.0 - - High
291 45.113.44.0 - - High
292 45.113.48.0 - - High
293 45.113.82.0 - - High
294 45.114.128.0 - - High
295 45.114.131.0 - - High
296 45.115.25.0 - - High
297 45.115.152.0 - - High
298 45.117.12.0 - - High
299 45.119.40.0 - - High
300 45.119.144.0 - - High
301 45.120.64.0 - - High
302 45.120.200.0 - - High
303 45.121.164.0 - - High
304 45.125.232.0 - - High
305 45.126.148.0 - - High
306 45.130.33.0 - - High
307 45.138.209.0 - - High
308 45.142.153.0 - - High
309 45.146.240.0 - - High
310 45.150.140.0 45.150.140.0.ipv4.telcom.network - High
311 45.150.172.0 - - High
312 45.154.156.0 - - High
313 ... ... ... ...

There are 1247 more IOC items available. Please use our online service to access the data.

TTP - Tactics, Techniques, Procedures

Tactics, techniques, and procedures (TTP) summarize the suspected MITRE ATT&CK techniques used by South Korea Unknown. This data is unique as it uses our predictive model for actor profiling.

ID Technique Weakness Description Confidence
1 T1006 CWE-21, CWE-22, CWE-35, CWE-36 Pathname Traversal High
2 T1040 CWE-319 Authentication Bypass by Capture-replay High
3 T1055 CWE-74 Injection High
4 T1059 CWE-88, CWE-94 Cross Site Scripting High
5 T1059.007 CWE-79, CWE-80 Cross Site Scripting High
6 ... ... ... ...

There are 18 more TTP items available. Please use our online service to access the data.

IOA - Indicator of Attack

These indicators of attack (IOA) list the potential fragments used for technical activities like reconnaissance, exploitation, privilege escalation, and exfiltration by South Korea Unknown. This data is unique as it uses our predictive model for actor profiling.

ID Type Indicator Confidence
1 File //WEB-INF Medium
2 File /about.php Medium
3 File /admin.php/update/getFile.html High
4 File /admin/ Low
5 File /admin/cashadvance_row.php High
6 File /admin/maintenance/view_designation.php High
7 File /admin/read.php?mudi=getSignal High
8 File /admin/sys_sql_query.php High
9 File /admin/userprofile.php High
10 File /Application/Admin/Controller/ConfigController.class.php High
11 File /APR/login.php High
12 File /APR/signup.php High
13 File /bin/boa Medium
14 File /cgi-bin/wapopen High
15 File /cgi-bin/wlogin.cgi High
16 File /cimom Low
17 File /company/store High
18 File /Controller/Ajaxfileupload.ashx High
19 File /E-mobile/App/System/File/downfile.php High
20 File /Electron/download High
21 File /feeds/post/publish High
22 File /forum/away.php High
23 File /h/ Low
24 File /inc/jquery/uploadify/uploadify.php High
25 File /index.php?app=main&func=passport&action=login High
26 File /index.php?page=category_list High
27 File /jobinfo/ Medium
28 File /mims/login.php High
29 File /Moosikay/order.php High
30 File /opac/Actions.php?a=login High
31 File /PreviewHandler.ashx High
32 File /proxy Low
33 File /public/launchNewWindow.jsp High
34 File /recipe-result High
35 File /reservation/add_message.php High
36 File /reviewer/system/system/admins/manage/users/user-update.php High
37 File /send_order.cgi?parameter=access_detect High
38 File /Service/ImageStationDataService.asmx High
39 File /student/bookdetails.php High
40 File /text/pdf/PdfReader.java High
41 File /textpattern/index.php High
42 File /tmp Low
43 File /uploads/exam_question/ High
44 File /user/ticket/create High
45 File /user/updatePwd High
46 File /var/lib/docker/<remapping> High
47 File /wp-admin/admin-ajax.php High
48 File a-forms.php Medium
49 File account/signup.php High
50 File activenews_view.asp High
51 File adclick.php Medium
52 File addentry.php Medium
53 File addressbook/backends/ldap/e-book-backend-ldap.c High
54 File admin.a6mambocredits.php High
55 File admin.cropcanvas.php High
56 ... ... ...

There are 487 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.

References

The following list contains external sources which discuss the actor and the associated activities:

Literature

The following articles explain our unique predictive cyber threat intelligence:

License

(c) 1997-2023 by vuldb.com. All data on this page is shared under the license CC BY-NC-SA 4.0. Questions? Check the FAQ, read the documentation or contact us!