cyber_threat_intelligence/actors/Turkey Unknown
2023-04-15 09:05:29 +02:00
..
README.md Update April 2023 2023-04-15 09:05:29 +02:00

Turkey Unknown - Cyber Threat Intelligence

These indicators were reported, collected, and generated during the VulDB CTI analysis of the actor known as Turkey Unknown. The activity monitoring correlates data from social media, forums, chat rooms, and darknet markets. It helps to determine associated actors, specific activities, expected intentions, emerging research, and ongoing attacks. Our unique predictive model uses big data to forecast activities and their characteristics.

Live data and more analysis capabilities are available at https://vuldb.com/?actor.turkey_unknown

Countries

These countries are directly (e.g. origin of attacks) or indirectly (e.g. access by proxy) associated with Turkey Unknown:

There are 24 more country items available. Please use our online service to access the data.

IOC - Indicator of Compromise

These indicators of compromise (IOC) indicate associated network resources which are known to be part of research and attack activities of Turkey Unknown.

ID IP address Hostname Campaign Confidence
1 2.16.88.0 a2-16-88-0.deploy.static.akamaitechnologies.com - High
2 2.16.88.4 a2-16-88-4.deploy.static.akamaitechnologies.com - High
3 2.16.88.12 a2-16-88-12.deploy.static.akamaitechnologies.com - High
4 2.16.88.20 a2-16-88-20.deploy.static.akamaitechnologies.com - High
5 2.16.88.28 a2-16-88-28.deploy.static.akamaitechnologies.com - High
6 2.16.88.36 a2-16-88-36.deploy.static.akamaitechnologies.com - High
7 2.16.88.44 a2-16-88-44.deploy.static.akamaitechnologies.com - High
8 2.16.88.52 a2-16-88-52.deploy.static.akamaitechnologies.com - High
9 2.16.88.60 a2-16-88-60.deploy.static.akamaitechnologies.com - High
10 2.16.88.68 a2-16-88-68.deploy.static.akamaitechnologies.com - High
11 2.16.88.76 a2-16-88-76.deploy.static.akamaitechnologies.com - High
12 2.16.88.84 a2-16-88-84.deploy.static.akamaitechnologies.com - High
13 2.16.88.92 a2-16-88-92.deploy.static.akamaitechnologies.com - High
14 2.16.88.100 a2-16-88-100.deploy.static.akamaitechnologies.com - High
15 2.16.88.108 a2-16-88-108.deploy.static.akamaitechnologies.com - High
16 2.16.88.116 a2-16-88-116.deploy.static.akamaitechnologies.com - High
17 2.16.88.124 a2-16-88-124.deploy.static.akamaitechnologies.com - High
18 2.16.150.0 a2-16-150-0.deploy.static.akamaitechnologies.com - High
19 2.17.136.0 a2-17-136-0.deploy.static.akamaitechnologies.com - High
20 2.17.224.0 a2-17-224-0.deploy.static.akamaitechnologies.com - High
21 2.17.252.0 a2-17-252-0.deploy.static.akamaitechnologies.com - High
22 2.17.254.0 a2-17-254-0.deploy.static.akamaitechnologies.com - High
23 2.18.4.0 a2-18-4-0.deploy.static.akamaitechnologies.com - High
24 2.18.192.0 a2-18-192-0.deploy.static.akamaitechnologies.com - High
25 2.19.193.0 a2-19-193-0.deploy.static.akamaitechnologies.com - High
26 2.19.200.0 a2-19-200-0.deploy.static.akamaitechnologies.com - High
27 2.19.202.0 a2-19-202-0.deploy.static.akamaitechnologies.com - High
28 2.19.210.0 a2-19-210-0.deploy.static.akamaitechnologies.com - High
29 2.19.212.0 a2-19-212-0.deploy.static.akamaitechnologies.com - High
30 2.20.24.0 a2-20-24-0.deploy.static.akamaitechnologies.com - High
31 2.20.76.0 a2-20-76-0.deploy.static.akamaitechnologies.com - High
32 2.20.134.0 a2-20-134-0.deploy.static.akamaitechnologies.com - High
33 2.20.148.0 a2-20-148-0.deploy.static.akamaitechnologies.com - High
34 2.21.238.0 a2-21-238-0.deploy.static.akamaitechnologies.com - High
35 2.21.248.0 a2-21-248-0.deploy.static.akamaitechnologies.com - High
36 2.56.7.0 - - High
37 2.56.60.0 host-2-56-60-0.ttnetdc.com - High
38 2.56.152.0 - - High
39 2.57.188.0 - - High
40 2.58.40.0 - - High
41 2.58.124.0 - - High
42 2.58.140.0 - - High
43 2.59.116.0 - - High
44 2.59.118.0 - - High
45 5.1.107.0 - - High
46 5.2.80.0 - - High
47 5.10.140.0 - - High
48 5.11.128.0 - - High
49 5.23.8.0 - - High
50 5.23.16.8 - - High
51 5.23.120.0 - - High
52 5.24.0.0 - - High
53 5.44.80.0 - - High
54 5.44.144.0 - - High
55 5.46.0.0 - - High
56 5.57.215.0 - - High
57 5.100.156.0 - - High
58 5.104.0.0 - - High
59 5.104.72.0 - - High
60 5.132.151.0 - - High
61 5.132.152.0 - - High
62 5.133.100.0 - - High
63 5.133.124.0 - - High
64 5.157.34.0 - - High
65 5.159.248.0 - - High
66 5.176.0.0 - - High
67 5.180.40.0 0.40-180-5.rdns.scalabledns.com - High
68 5.180.104.0 - - High
69 5.180.176.0 - - High
70 5.180.184.0 - - High
71 5.181.16.0 - - High
72 5.181.18.0 - - High
73 5.181.140.0 - - High
74 5.181.168.0 - - High
75 5.181.212.0 - - High
76 5.182.76.0 - - High
77 5.182.204.0 - - High
78 5.182.224.0 - - High
79 5.182.244.0 - - High
80 5.183.88.0 - - High
81 5.183.112.0 - - High
82 5.188.36.0 subnet.gcore.lu - High
83 5.188.168.0 subnet.gcore.lu - High
84 5.188.190.0 subnet.gcore.lu - High
85 5.226.192.0 - - High
86 5.229.0.0 - - High
87 5.250.240.0 hosted.by.aysima.net - High
88 5.252.4.0 - - High
89 5.252.96.0 - - High
90 5.252.204.0 0.204.252.5.in-addr.arpa.makdos-arpa.com - High
91 5.253.140.0 - - High
92 5.253.168.0 - - High
93 5.253.220.0 - - High
94 5.253.247.0 - - High
95 5.253.248.0 - - High
96 5.254.65.9 fra-in3-01c.voxility.net - High
97 5.255.195.0 - - High
98 5.255.251.128 - - High
99 8.18.196.0 - - High
100 8.25.249.0 - - High
101 8.39.214.0 - - High
102 17.67.198.0 - - High
103 17.69.240.0 - - High
104 17.73.40.0 - - High
105 17.75.224.0 - - High
106 17.75.248.0 - - High
107 17.77.148.0 - - High
108 17.77.164.0 - - High
109 23.14.112.0 a23-14-112-0.deploy.static.akamaitechnologies.com - High
110 23.55.52.0 a23-55-52-0.deploy.static.akamaitechnologies.com - High
111 23.58.222.0 a23-58-222-0.deploy.static.akamaitechnologies.com - High
112 23.58.223.4 a23-58-223-4.deploy.static.akamaitechnologies.com - High
113 23.58.223.12 a23-58-223-12.deploy.static.akamaitechnologies.com - High
114 23.58.223.20 a23-58-223-20.deploy.static.akamaitechnologies.com - High
115 23.58.223.28 a23-58-223-28.deploy.static.akamaitechnologies.com - High
116 23.58.223.36 a23-58-223-36.deploy.static.akamaitechnologies.com - High
117 23.58.223.44 a23-58-223-44.deploy.static.akamaitechnologies.com - High
118 23.58.223.52 a23-58-223-52.deploy.static.akamaitechnologies.com - High
119 23.58.223.60 a23-58-223-60.deploy.static.akamaitechnologies.com - High
120 23.58.223.68 a23-58-223-68.deploy.static.akamaitechnologies.com - High
121 23.58.223.77 a23-58-223-77.deploy.static.akamaitechnologies.com - High
122 23.58.223.78 a23-58-223-78.deploy.static.akamaitechnologies.com - High
123 23.58.223.84 a23-58-223-84.deploy.static.akamaitechnologies.com - High
124 23.58.223.92 a23-58-223-92.deploy.static.akamaitechnologies.com - High
125 23.58.223.100 a23-58-223-100.deploy.static.akamaitechnologies.com - High
126 23.58.223.108 a23-58-223-108.deploy.static.akamaitechnologies.com - High
127 23.58.223.116 a23-58-223-116.deploy.static.akamaitechnologies.com - High
128 23.214.0.0 a23-214-0-0.deploy.static.akamaitechnologies.com - High
129 23.221.160.0 a23-221-160-0.deploy.static.akamaitechnologies.com - High
130 23.221.192.0 a23-221-192-0.deploy.static.akamaitechnologies.com - High
131 23.221.196.0 a23-221-196-0.deploy.static.akamaitechnologies.com - High
132 23.227.177.0 23-227-177-0.static.hvvc.us - High
133 23.229.3.64 - - High
134 23.229.3.104 - - High
135 23.247.238.0 - - High
136 23.252.66.0 . - High
137 23.252.68.0 . - High
138 23.252.71.255 . - High
139 23.252.72.0 23-252-72-0.customers.wareconsult.net - High
140 23.252.76.0 . - High
141 24.133.0.0 - - High
142 31.3.0.0 - - High
143 31.3.3.0 - - High
144 31.3.4.0 - - High
145 31.6.37.0 - - High
146 31.6.38.128 - - High
147 31.6.80.0 - - High
148 31.7.32.0 - - High
149 31.14.52.0 - - High
150 31.14.64.0 - - High
151 31.14.75.0 - - High
152 31.14.218.0 - - High
153 31.14.232.0 - - High
154 31.14.253.0 - - High
155 31.25.168.0 - - High
156 31.40.196.0 - - High
157 31.40.204.0 - - High
158 31.40.220.0 - - High
159 31.40.228.0 - - High
160 31.44.106.0 lan-31-44-106-0.vln.penki.lt - High
161 31.44.192.0 - - High
162 31.140.0.0 - - High
163 31.145.0.0 - - High
164 31.155.0.0 - - High
165 31.169.64.0 - - High
166 31.176.0.0 - - High
167 31.177.128.0 - - High
168 31.186.0.0 - - High
169 31.192.208.0 - - High
170 31.200.0.0 - - High
171 31.206.0.0 - - High
172 31.207.80.0 - - High
173 31.209.96.0 - - High
174 31.209.100.0 - - High
175 31.209.104.0 - - High
176 31.210.8.0 - - High
177 31.210.13.0 - - High
178 31.210.14.0 - - High
179 31.210.17.0 - - High
180 31.210.32.0 static-0-32-210-31.sadecehosting.net - High
181 31.210.36.0 static-0-36-210-31.sadecehosting.net - High
182 31.210.38.0 - - High
183 31.210.40.0 static-0-40-210-31.sadecehosting.net - High
184 31.210.48.0 static-0-48-210-31.sunucu.com.tr - High
185 31.210.64.0 server-31.210.64.0.as42926.net - High
186 31.210.152.0 host-31.210.152.0.routergate.com - High
187 31.214.129.0 hosted-by.muvhost.com - High
188 31.214.152.0 hosted-by.muvhost.com - High
189 31.223.0.0 - - High
190 32.106.129.0 slip32-106-129-0.ibl.tr.prserv.net - High
191 32.106.130.0 - - High
192 34.99.192.0 0.192.99.34.bc.googleusercontent.com - Medium
193 34.103.134.0 0.134.103.34.bc.googleusercontent.com - Medium
194 34.103.208.0 0.208.103.34.bc.googleusercontent.com - Medium
195 34.103.248.0 0.248.103.34.bc.googleusercontent.com - Medium
196 37.9.200.0 - - High
197 37.18.62.0 37.18.62.0.ip.goknet.com.tr - High
198 37.18.96.0 37.18.96.0.ip.goknet.com.tr - High
199 37.19.208.0 unn-37-19-208-0.datapacket.com - High
200 37.34.0.0 - - High
201 37.44.194.0 - - High
202 37.44.228.0 - - High
203 37.58.16.0 - - High
204 37.58.21.0 - - High
205 37.58.22.0 - - High
206 37.72.48.0 0-48-72-37.gold-surf.com - High
207 37.75.8.0 - - High
208 37.77.0.0 - - High
209 37.122.136.0 37.122.136.0.dynamic-pppoe.dt.ipv4.wtnet.de - High
210 37.122.224.0 - - High
211 37.123.0.0 - - High
212 37.123.96.0 spd.net.tr - High
213 37.130.64.0 - - High
214 37.131.248.0 - - High
215 37.140.208.0 - - High
216 37.140.223.0 - - High
217 37.140.242.0 - - High
218 37.148.208.0 37-148-208-0.cizgi.net.tr - High
219 37.152.72.0 - - High
220 37.152.74.0 - - High
221 37.152.76.0 - - High
222 37.154.0.0 - - High
223 37.156.246.0 - - High
224 37.200.87.0 - - High
225 37.200.104.0 - - High
226 37.202.48.0 37-202-48-0.servers.3c1b.net - High
227 37.205.0.0 - - High
228 37.218.196.0 - - High
229 37.221.76.0 - - High
230 37.230.104.0 - - High
231 37.235.72.0 - - High
232 37.246.16.0 - - High
233 37.246.88.0 - - High
234 37.246.168.0 - - High
235 37.247.96.0 host-37-247-96-0.routergate.com - High
236 37.247.112.0 37-247-112-0.static.internetadresi.com - High
237 37.247.119.0 37-247-119-0.static.internetadresi.com - High
238 38.10.68.0 - - High
239 43.225.191.0 - - High
240 44.31.49.0 - - High
241 45.8.24.0 - - High
242 45.8.99.0 - - High
243 45.10.56.0 - - High
244 45.10.59.0 - - High
245 45.10.72.0 - - High
246 45.10.76.0 - - High
247 45.10.148.0 - - High
248 45.10.252.0 - - High
249 45.11.40.0 - - High
250 45.11.96.0 - - High
251 45.11.184.0 - - High
252 45.11.200.0 ns2.oristelekom.com - High
253 45.12.20.0 - - High
254 45.12.52.0 - - High
255 45.12.56.0 - - High
256 45.12.64.0 - - High
257 45.12.70.226 clung-reaper.globalhilive.com - High
258 45.12.71.226 - - High
259 45.12.81.0 - - High
260 45.12.84.0 - - High
261 45.13.188.0 - - High
262 45.14.32.0 - - High
263 45.14.80.0 - - High
264 45.14.82.0 - - High
265 45.67.152.0 - - High
266 45.67.232.0 0.232.67.45.in-addr.arpa.makdos-arpa.com - High
267 45.80.172.0 - - High
268 45.81.58.0 - - High
269 45.81.100.0 ns1.oristelekom.com - High
270 45.81.140.0 - - High
271 45.82.13.0 subnet.reserved.ispsystem.net - High
272 45.82.92.0 - - High
273 45.82.140.0 - - High
274 45.83.32.0 - - High
275 45.83.180.0 - - High
276 45.84.16.0 - - High
277 45.84.188.0 0p1nlyu.guzel.net.tr - High
278 45.84.220.0 45-84-220-0.rdns.euronet.net.tr - High
279 45.85.249.0 - - High
280 45.86.116.0 mta-2d567400.ip4.emsmtp.us - High
281 45.88.32.0 - - High
282 45.88.97.0 - - High
283 45.88.136.0 - - High
284 45.89.48.0 - - High
285 45.89.236.0 45-89-236-0.faraso.org - High
286 45.89.246.0 server-45.89.246.0.as42926.net - High
287 45.90.148.0 - - High
288 45.91.66.0 - - High
289 45.91.148.0 - - High
290 45.91.252.0 - - High
291 45.93.244.0 - - High
292 45.94.4.0 - - High
293 45.94.56.0 - - High
294 45.94.80.0 - - High
295 45.94.148.0 0-148-94-45.ip.netbone.com.tr - High
296 45.94.212.0 - - High
297 45.94.244.0 - - High
298 45.95.48.0 - - High
299 45.95.232.0 hosted-by.technox.com.tr - High
300 45.116.168.0 - - High
301 45.123.116.0 - - High
302 45.123.118.0 - - High
303 45.129.120.0 - - High
304 45.129.184.0 hosted-by.technox.com.tr - High
305 45.130.12.0 network.bulutistan.com - High
306 45.130.156.0 - - High
307 45.131.0.0 ip.serverscity.net - High
308 45.131.3.0 - - High
309 45.131.112.0 - - High
310 45.131.144.0 - - High
311 45.131.196.0 hosted.dynet.net - High
312 45.132.158.0 ip-45-132-158-0.static.contabo.net - High
313 45.132.181.0 - - High
314 45.133.36.0 - - High
315 45.133.40.0 - - High
316 45.133.44.0 - - High
317 45.134.192.0 45.134.192.0.not.updated.openip-cs.net - High
318 45.134.212.0 unn-45-134-212-0.datapacket.com - High
319 45.135.204.0 45.135.204.0.netspeed.com.tr - High
320 45.136.4.0 host-45.136.4.0.saga.net.tr - High
321 45.136.104.0 - - High
322 45.136.152.0 unn-45-136-152-0.datapacket.com - High
323 45.136.212.0 - - High
324 45.137.17.0 - - High
325 45.137.192.0 - - High
326 45.138.24.0 - - High
327 45.138.124.0 - - High
328 45.139.4.0 - - High
329 45.139.196.0 - - High
330 45.139.200.0 - - High
331 45.139.220.0 - - High
332 45.141.148.0 - - High
333 45.141.224.0 - - High
334 45.143.96.0 - - High
335 45.143.188.0 - - High
336 45.144.108.0 - - High
337 45.144.212.0 - - High
338 45.144.214.0 ozbaybilisim.com - High
339 45.145.20.0 - - High
340 45.145.28.0 45-145-28-0.g3ns.net - High
341 45.145.156.0 - - High
342 45.146.161.0 - - High
343 45.147.16.0 - - High
344 45.147.44.0 host-45.147.44.0.hostinget.com - High
345 45.149.131.0 - - High
346 45.151.2.0 ozbaybilisim.com - High
347 45.151.12.0 45-151-12-0.ip.welcomeitalia.it - High
348 45.151.64.0 45-151-64-0.ip.welcomeitalia.it - High
349 45.151.248.0 - - High
350 45.153.91.0 - - High
351 45.153.248.0 hermes.sendersbox.com - High
352 45.154.159.0 - - High
353 45.155.72.0 - - High
354 45.155.124.0 - - High
355 45.156.12.0 - - High
356 45.156.28.0 - - High
357 45.156.72.0 orbittelekom.com - High
358 45.156.119.0 - - High
359 45.157.244.0 - - High
360 45.158.12.0 - - High
361 45.158.136.0 static.orbittelekom.com - High
362 45.159.28.0 - - High
363 45.221.96.0 - - High
364 46.1.0.0 - - High
365 46.2.0.0 - - High
366 46.17.128.0 - - High
367 46.18.105.0 - - High
368 46.20.0.0 host-46-20-0-0.oxv - High
369 46.20.144.0 static.doratelekom.com - High
370 46.20.152.0 - - High
371 46.20.157.0 - - High
372 46.20.158.0 - - High
373 46.28.232.0 - - High
374 46.29.0.0 0.0.29.46.static.freenetsk.sk - High
375 46.30.176.0 - - High
376 46.31.76.0 protectme-ddos-LT.secureuplink.com.tr - High
377 46.31.112.0 - - High
378 46.31.144.0 - - High
379 46.34.64.0 - - High
380 46.34.90.0 - - High
381 46.45.128.0 ns1648.ztomy.com - High
382 46.102.106.0 subnet.spec.ispiria.net - High
383 46.104.0.0 - - High
384 46.106.0.0 - - High
385 46.106.128.0 - - High
386 46.106.192.0 - - High
387 46.106.201.0 - - High
388 46.106.202.0 - - High
389 46.106.204.0 - - High
390 46.106.208.0 - - High
391 46.106.224.0 - - High
392 46.149.160.0 - - High
393 46.154.0.0 - - High
394 46.161.57.0 - - High
395 46.182.64.0 - - High
396 46.182.168.0 - - High
397 46.196.0.0 - - High
398 46.221.0.0 - - High
399 46.226.121.0 - - High
400 46.234.0.0 - - High
401 46.235.8.0 - - High
402 46.245.160.0 - - High
403 46.252.96.0 - - High
404 46.254.48.0 46-254-48-0.aa.net.tr - High
405 50.114.110.0 - - High
406 50.114.127.0 - - High
407 57.90.240.0 - - High
408 57.94.32.0 - - High
409 57.94.64.0 - - High
410 57.94.128.0 - - High
411 62.29.0.0 - - High
412 62.106.71.0 - - High
413 62.106.94.0 - - High
414 62.108.64.0 - - High
415 ... ... ... ...

There are 1656 more IOC items available. Please use our online service to access the data.

TTP - Tactics, Techniques, Procedures

Tactics, techniques, and procedures (TTP) summarize the suspected MITRE ATT&CK techniques used by Turkey Unknown. This data is unique as it uses our predictive model for actor profiling.

ID Technique Weakness Description Confidence
1 T1006 CWE-21, CWE-22, CWE-23, CWE-28 Pathname Traversal High
2 T1040 CWE-294, CWE-319 Authentication Bypass by Capture-replay High
3 T1055 CWE-74 Injection High
4 T1059 CWE-88, CWE-94, CWE-1321 Cross Site Scripting High
5 T1059.007 CWE-79, CWE-80 Cross Site Scripting High
6 ... ... ... ...

There are 20 more TTP items available. Please use our online service to access the data.

IOA - Indicator of Attack

These indicators of attack (IOA) list the potential fragments used for technical activities like reconnaissance, exploitation, privilege escalation, and exfiltration by Turkey Unknown. This data is unique as it uses our predictive model for actor profiling.

ID Type Indicator Confidence
1 File .github/workflows/combine-prs.yml High
2 File /admin.php/accessory/filesdel.html High
3 File /admin/?page=user/manage High
4 File /admin/add-new.php High
5 File /admin/api/admin/articles/ High
6 File /admin/cashadvance_row.php High
7 File /admin/doctors.php High
8 File /adms/admin/?page=vehicles/sell_vehicle High
9 File /adms/admin/?page=vehicles/view_transaction High
10 File /alphaware/summary.php High
11 File /api/ Low
12 File /api/admin/store/product/list High
13 File /APR/login.php High
14 File /attachments Medium
15 File /bin/httpd Medium
16 File /boat/login.php High
17 File /bsms_ci/index.php/book High
18 File /cgi-bin/wapopen High
19 File /cgi-bin/webadminget.cgi High
20 File /cgi-bin/wlogin.cgi High
21 File /debug/pprof Medium
22 File /dev/block/mmcblk0rpmb High
23 File /DocSystem/Repos/getReposAllUsers.do High
24 File /etc/hosts Medium
25 File /face-recognition-php/facepay-master/camera.php High
26 File /forum/away.php High
27 File /fos/admin/ajax.php?action=login High
28 File /fos/admin/index.php?page=menu High
29 File /home/masterConsole High
30 File /home/sendBroadcast High
31 File /hrm/employeeadd.php High
32 File /hrm/employeeview.php High
33 File /jsoa/hntdCustomDesktopActionContent High
34 File /lookin/info Medium
35 File /medicines/profile.php High
36 File /mygym/admin/index.php?view_exercises High
37 File /out.php Medium
38 File /php-fusion/infusions/shoutbox_panel/shoutbox_archive.php High
39 File /php-opos/index.php High
40 File /proxy Low
41 File /public/launchNewWindow.jsp High
42 File /reports/rwservlet High
43 File /reservation/add_message.php High
44 File /scripts Medium
45 File /spip.php Medium
46 File /tmp Low
47 File /uncpath/ Medium
48 File /user/updatePwd High
49 File /var/www/core/controller/index.php High
50 File /vendor/htmlawed/htmlawed/htmLawedTest.php High
51 File /video-sharing-script/watch-video.php High
52 File /wireless/security.asp High
53 File 01article.php High
54 File AbstractScheduleJob.java High
55 ... ... ...

There are 482 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.

References

The following list contains external sources which discuss the actor and the associated activities:

Literature

The following articles explain our unique predictive cyber threat intelligence:

License

(c) 1997-2023 by vuldb.com. All data on this page is shared under the license CC BY-NC-SA 4.0. Questions? Check the FAQ, read the documentation or contact us!