cyber_threat_intelligence/actors/Sliver
2023-10-27 13:52:44 +02:00
..
README.md Update October 2023 2023-10-27 13:52:44 +02:00

Sliver - Cyber Threat Intelligence

These indicators were reported, collected, and generated during the VulDB CTI analysis of the actor known as Sliver. The activity monitoring correlates data from social media, forums, chat rooms, and darknet markets. It helps to determine associated actors, specific activities, expected intentions, emerging research, and ongoing attacks. Our unique predictive model uses big data to forecast activities and their characteristics.

Live data and more analysis capabilities are available at https://vuldb.com/?actor.sliver

Countries

These countries are directly (e.g. origin of attacks) or indirectly (e.g. access by proxy) associated with Sliver:

There are 16 more country items available. Please use our online service to access the data.

IOC - Indicator of Compromise

These indicators of compromise (IOC) indicate associated network resources which are known to be part of research and attack activities of Sliver.

ID IP address Hostname Campaign Confidence
1 1.13.17.105 - - High
2 1.13.174.161 - - High
3 1.13.180.253 - - High
4 1.14.65.206 - - High
5 2.57.149.93 - - High
6 3.8.115.155 ec2-3-8-115-155.eu-west-2.compute.amazonaws.com - Medium
7 3.18.103.195 ec2-3-18-103-195.us-east-2.compute.amazonaws.com - Medium
8 3.32.156.37 ec2-3-32-156-37.us-gov-west-1.compute.amazonaws.com - Medium
9 3.33.238.117 afa66be65b4910efa.awsglobalaccelerator.com - High
10 3.37.1.94 ec2-3-37-1-94.ap-northeast-2.compute.amazonaws.com - Medium
11 3.67.84.194 ec2-3-67-84-194.eu-central-1.compute.amazonaws.com - Medium
12 3.68.73.20 ec2-3-68-73-20.eu-central-1.compute.amazonaws.com - Medium
13 3.70.227.81 ec2-3-70-227-81.eu-central-1.compute.amazonaws.com - Medium
14 3.71.1.246 ec2-3-71-1-246.eu-central-1.compute.amazonaws.com - Medium
15 3.71.181.49 ec2-3-71-181-49.eu-central-1.compute.amazonaws.com - Medium
16 3.75.222.122 ec2-3-75-222-122.eu-central-1.compute.amazonaws.com - Medium
17 3.76.104.227 ec2-3-76-104-227.eu-central-1.compute.amazonaws.com - Medium
18 3.76.222.154 ec2-3-76-222-154.eu-central-1.compute.amazonaws.com - Medium
19 3.76.250.91 ec2-3-76-250-91.eu-central-1.compute.amazonaws.com - Medium
20 3.79.95.174 ec2-3-79-95-174.eu-central-1.compute.amazonaws.com - Medium
21 3.79.181.53 ec2-3-79-181-53.eu-central-1.compute.amazonaws.com - Medium
22 3.79.246.57 ec2-3-79-246-57.eu-central-1.compute.amazonaws.com - Medium
23 3.80.71.248 ec2-3-80-71-248.compute-1.amazonaws.com - Medium
24 3.82.226.95 ec2-3-82-226-95.compute-1.amazonaws.com - Medium
25 3.85.22.130 ec2-3-85-22-130.compute-1.amazonaws.com - Medium
26 3.88.34.220 ec2-3-88-34-220.compute-1.amazonaws.com - Medium
27 3.91.200.115 ec2-3-91-200-115.compute-1.amazonaws.com - Medium
28 3.92.41.116 ec2-3-92-41-116.compute-1.amazonaws.com - Medium
29 3.93.154.104 ec2-3-93-154-104.compute-1.amazonaws.com - Medium
30 3.101.117.8 ec2-3-101-117-8.us-west-1.compute.amazonaws.com - Medium
31 3.104.54.39 ec2-3-104-54-39.ap-southeast-2.compute.amazonaws.com - Medium
32 3.120.187.11 ec2-3-120-187-11.eu-central-1.compute.amazonaws.com - Medium
33 3.121.212.242 ec2-3-121-212-242.eu-central-1.compute.amazonaws.com - Medium
34 3.128.135.199 ec2-3-128-135-199.us-east-2.compute.amazonaws.com - Medium
35 3.130.73.232 ec2-3-130-73-232.us-east-2.compute.amazonaws.com - Medium
36 3.132.127.123 ec2-3-132-127-123.us-east-2.compute.amazonaws.com - Medium
37 3.134.102.71 ec2-3-134-102-71.us-east-2.compute.amazonaws.com - Medium
38 3.142.79.130 ec2-3-142-79-130.us-east-2.compute.amazonaws.com - Medium
39 3.212.234.126 ec2-3-212-234-126.compute-1.amazonaws.com - Medium
40 3.228.129.243 ec2-3-228-129-243.compute-1.amazonaws.com - Medium
41 3.232.215.227 ec2-3-232-215-227.compute-1.amazonaws.com - Medium
42 3.235.153.136 ec2-3-235-153-136.compute-1.amazonaws.com - Medium
43 3.237.92.13 ec2-3-237-92-13.compute-1.amazonaws.com - Medium
44 3.238.195.247 ec2-3-238-195-247.compute-1.amazonaws.com - Medium
45 4.240.86.147 - - High
46 5.45.83.33 - - High
47 5.75.185.92 static.92.185.75.5.clients.your-server.de - High
48 5.75.238.234 static.234.238.75.5.clients.your-server.de - High
49 5.78.102.166 static.166.102.78.5.clients.your-server.de - High
50 5.161.206.45 static.45.206.161.5.clients.your-server.de - High
51 5.178.2.76 - - High
52 5.181.23.179 vm1584927.stark-industries.solutions - High
53 5.188.34.63 monting10136.example.com - High
54 5.199.168.209 - - High
55 5.199.173.106 - - High
56 5.199.173.134 - - High
57 5.199.174.230 - - High
58 5.252.176.26 5-252-176-26.mivocloud.com - High
59 5.255.114.206 - - High
60 5.255.120.28 - - High
61 8.212.148.49 - - High
62 8.213.132.159 - - High
63 8.217.54.75 - - High
64 8.218.149.214 - - High
65 8.218.200.114 - - High
66 8.218.204.19 - - High
67 8.219.200.180 - - High
68 13.48.204.226 ec2-13-48-204-226.eu-north-1.compute.amazonaws.com - Medium
69 13.49.46.31 ec2-13-49-46-31.eu-north-1.compute.amazonaws.com - Medium
70 13.52.234.113 ec2-13-52-234-113.us-west-1.compute.amazonaws.com - Medium
71 13.56.236.146 ec2-13-56-236-146.us-west-1.compute.amazonaws.com - Medium
72 13.91.106.22 - - High
73 13.115.21.133 ec2-13-115-21-133.ap-northeast-1.compute.amazonaws.com - Medium
74 13.229.251.52 ec2-13-229-251-52.ap-southeast-1.compute.amazonaws.com - Medium
75 13.236.149.120 ec2-13-236-149-120.ap-southeast-2.compute.amazonaws.com - Medium
76 13.238.218.206 ec2-13-238-218-206.ap-southeast-2.compute.amazonaws.com - Medium
77 13.239.102.0 ec2-13-239-102-0.ap-southeast-2.compute.amazonaws.com - Medium
78 13.245.183.173 ec2-13-245-183-173.af-south-1.compute.amazonaws.com - Medium
79 14.1.29.189 - - High
80 15.197.228.221 afa66be65b4910efa.awsglobalaccelerator.com - High
81 15.235.166.83 vps-09419904.vps.ovh.ca - High
82 15.237.24.169 ec2-15-237-24-169.eu-west-3.compute.amazonaws.com - Medium
83 16.16.172.16 ec2-16-16-172-16.eu-north-1.compute.amazonaws.com - Medium
84 18.140.228.104 ec2-18-140-228-104.ap-southeast-1.compute.amazonaws.com - Medium
85 18.157.163.215 ec2-18-157-163-215.eu-central-1.compute.amazonaws.com - Medium
86 18.159.62.29 ec2-18-159-62-29.eu-central-1.compute.amazonaws.com - Medium
87 18.163.80.92 ec2-18-163-80-92.ap-east-1.compute.amazonaws.com - Medium
88 18.176.32.89 ec2-18-176-32-89.ap-northeast-1.compute.amazonaws.com - Medium
89 18.184.113.135 ec2-18-184-113-135.eu-central-1.compute.amazonaws.com - Medium
90 18.184.208.136 ec2-18-184-208-136.eu-central-1.compute.amazonaws.com - Medium
91 18.196.240.144 ec2-18-196-240-144.eu-central-1.compute.amazonaws.com - Medium
92 18.197.69.9 ec2-18-197-69-9.eu-central-1.compute.amazonaws.com - Medium
93 18.205.146.13 ec2-18-205-146-13.compute-1.amazonaws.com - Medium
94 18.216.108.112 ec2-18-216-108-112.us-east-2.compute.amazonaws.com - Medium
95 18.216.116.172 ec2-18-216-116-172.us-east-2.compute.amazonaws.com - Medium
96 18.219.46.104 ec2-18-219-46-104.us-east-2.compute.amazonaws.com - Medium
97 18.220.125.151 ec2-18-220-125-151.us-east-2.compute.amazonaws.com - Medium
98 18.234.7.23 ec2-18-234-7-23.compute-1.amazonaws.com - Medium
99 20.1.134.133 - - High
100 20.58.167.202 - - High
101 20.61.4.19 - - High
102 20.118.135.66 - - High
103 20.121.237.146 - - High
104 20.123.75.93 - - High
105 20.227.28.202 - - High
106 20.248.225.130 - - High
107 23.19.227.106 - - High
108 23.81.246.193 - - High
109 23.82.141.146 - - High
110 23.83.127.233 - - High
111 23.83.133.53 - - High
112 23.94.131.51 beikeet.com - High
113 23.94.200.202 ju7-ry.insulin-pumpers.org - High
114 23.95.44.80 23-95-44-80-host.colocrossing.com - High
115 23.105.193.194 cs.hax0x.win - High
116 23.224.135.138 - - High
117 23.224.135.139 - - High
118 23.224.135.140 - - High
119 23.224.135.141 - - High
120 23.224.135.142 - - High
121 23.234.199.141 141-199-234-23-dedicated.multacom.com - High
122 23.234.200.38 - - High
123 23.234.203.187 erfd4e.terminatingworries.info - High
124 23.239.30.17 23-239-30-17.ip.linodeusercontent.com - High
125 31.41.44.19 huotovich.maks.example.com - High
126 31.147.205.87 www.hrzz.hr - High
127 31.172.83.48 - - High
128 34.69.252.38 38.252.69.34.bc.googleusercontent.com - Medium
129 34.71.72.45 45.72.71.34.bc.googleusercontent.com - Medium
130 34.77.164.25 25.164.77.34.bc.googleusercontent.com - Medium
131 34.90.195.133 133.195.90.34.bc.googleusercontent.com - Medium
132 34.91.1.44 44.1.91.34.bc.googleusercontent.com - Medium
133 34.95.30.177 177.30.95.34.bc.googleusercontent.com - Medium
134 34.95.37.163 163.37.95.34.bc.googleusercontent.com - Medium
135 34.95.63.26 26.63.95.34.bc.googleusercontent.com - Medium
136 34.105.151.117 117.151.105.34.bc.googleusercontent.com - Medium
137 34.126.74.251 251.74.126.34.bc.googleusercontent.com - Medium
138 34.126.163.54 54.163.126.34.bc.googleusercontent.com - Medium
139 34.136.159.101 101.159.136.34.bc.googleusercontent.com - Medium
140 34.142.207.150 150.207.142.34.bc.googleusercontent.com - Medium
141 34.143.153.255 255.153.143.34.bc.googleusercontent.com - Medium
142 34.143.209.90 90.209.143.34.bc.googleusercontent.com - Medium
143 34.143.223.175 175.223.143.34.bc.googleusercontent.com - Medium
144 34.148.19.100 100.19.148.34.bc.googleusercontent.com - Medium
145 34.150.49.203 203.49.150.34.bc.googleusercontent.com - Medium
146 34.162.188.150 150.188.162.34.bc.googleusercontent.com - Medium
147 34.168.149.233 233.149.168.34.bc.googleusercontent.com - Medium
148 34.171.81.60 60.81.171.34.bc.googleusercontent.com - Medium
149 34.172.52.13 13.52.172.34.bc.googleusercontent.com - Medium
150 34.176.0.227 227.0.176.34.bc.googleusercontent.com - Medium
151 34.201.98.138 ec2-34-201-98-138.compute-1.amazonaws.com - Medium
152 34.212.32.244 ec2-34-212-32-244.us-west-2.compute.amazonaws.com - Medium
153 34.221.238.130 ec2-34-221-238-130.us-west-2.compute.amazonaws.com - Medium
154 35.72.242.198 ec2-35-72-242-198.ap-northeast-1.compute.amazonaws.com - Medium
155 35.156.61.119 ec2-35-156-61-119.eu-central-1.compute.amazonaws.com - Medium
156 35.159.38.229 ec2-35-159-38-229.eu-central-1.compute.amazonaws.com - Medium
157 35.167.111.43 ec2-35-167-111-43.us-west-2.compute.amazonaws.com - Medium
158 35.168.213.32 ec2-35-168-213-32.compute-1.amazonaws.com - Medium
159 35.180.5.225 ec2-35-180-5-225.eu-west-3.compute.amazonaws.com - Medium
160 35.180.135.137 ec2-35-180-135-137.eu-west-3.compute.amazonaws.com - Medium
161 35.185.58.57 57.58.185.35.bc.googleusercontent.com - Medium
162 35.195.109.194 194.109.195.35.bc.googleusercontent.com - Medium
163 35.198.198.102 102.198.198.35.bc.googleusercontent.com - Medium
164 35.198.225.38 38.225.198.35.bc.googleusercontent.com - Medium
165 35.203.17.14 14.17.203.35.bc.googleusercontent.com - Medium
166 35.203.35.135 135.35.203.35.bc.googleusercontent.com - Medium
167 35.203.83.183 183.83.203.35.bc.googleusercontent.com - Medium
168 35.212.172.98 98.172.212.35.bc.googleusercontent.com - Medium
169 35.216.181.214 214.181.216.35.bc.googleusercontent.com - Medium
170 35.222.116.63 63.116.222.35.bc.googleusercontent.com - Medium
171 35.225.60.206 206.60.225.35.bc.googleusercontent.com - Medium
172 35.226.14.60 60.14.226.35.bc.googleusercontent.com - Medium
173 35.226.166.202 202.166.226.35.bc.googleusercontent.com - Medium
174 35.226.172.143 143.172.226.35.bc.googleusercontent.com - Medium
175 35.232.88.10 10.88.232.35.bc.googleusercontent.com - Medium
176 35.232.112.155 155.112.232.35.bc.googleusercontent.com - Medium
177 35.232.164.7 7.164.232.35.bc.googleusercontent.com - Medium
178 35.234.251.236 236.251.234.35.bc.googleusercontent.com - Medium
179 35.236.117.76 76.117.236.35.bc.googleusercontent.com - Medium
180 35.238.12.241 241.12.238.35.bc.googleusercontent.com - Medium
181 35.238.243.118 118.243.238.35.bc.googleusercontent.com - Medium
182 35.240.143.100 100.143.240.35.bc.googleusercontent.com - Medium
183 35.240.171.140 140.171.240.35.bc.googleusercontent.com - Medium
184 35.240.180.169 169.180.240.35.bc.googleusercontent.com - Medium
185 ... ... ... ...

There are 737 more IOC items available. Please use our online service to access the data.

TTP - Tactics, Techniques, Procedures

Tactics, techniques, and procedures (TTP) summarize the suspected MITRE ATT&CK techniques used by Sliver. This data is unique as it uses our predictive model for actor profiling.

ID Technique Weakness Description Confidence
1 T1006 CWE-21, CWE-22, CWE-23 Pathname Traversal High
2 T1055 CWE-74 Injection High
3 T1059 CWE-94, CWE-1321 Cross Site Scripting High
4 T1059.007 CWE-79, CWE-80 Cross Site Scripting High
5 T1068 CWE-250, CWE-264, CWE-269, CWE-270, CWE-284 J2EE Misconfiguration: Weak Access Permissions for EJB Methods High
6 ... ... ... ...

There are 21 more TTP items available. Please use our online service to access the data.

IOA - Indicator of Attack

These indicators of attack (IOA) list the potential fragments used for technical activities like reconnaissance, exploitation, privilege escalation, and exfiltration by Sliver. This data is unique as it uses our predictive model for actor profiling.

ID Type Indicator Confidence
1 File /academy/tutor/filter High
2 File /admin/about-us.php High
3 File /admin/save.php High
4 File /admin/sys_sql_query.php High
5 File /api/baskets/{name} High
6 File /api/download High
7 File /api/v1/alerts High
8 File /api/v1/terminal/sessions/?limit=1 High
9 File /bitrix/admin/ldap_server_edit.php High
10 File /book-services.php High
11 File /category.php High
12 File /categorypage.php High
13 File /cgi-bin/luci/api/wireless High
14 File /cgi-bin/vitogate.cgi High
15 File /company/store High
16 File /Content/Template/root/reverse-shell.aspx High
17 File /Controller/Ajaxfileupload.ashx High
18 File /core/conditions/AbstractWrapper.java High
19 File /etc/passwd Medium
20 File /fcgi/scrut_fcgi.fcgi High
21 File /forum/away.php High
22 File /HNAP1 Low
23 File /index.php Medium
24 File /install/index.php High
25 File /jeecg-boot/sys/common/upload High
26 File /mhds/clinic/view_details.php High
27 File /OA_HTML/cabo/jsps/a.jsp High
28 File /pharmacy-sales-and-inventory-system/manage_user.php High
29 File /proxy Low
30 File /recipe-result High
31 File /register.do Medium
32 File /RPS2019Service/status.html High
33 File /Service/ImageStationDataService.asmx High
34 File /sicweb-ajax/tmproot/ High
35 File /spip.php Medium
36 File /squashfs-root/etc_ro/custom.conf High
37 File /staff/edit_book_details.php High
38 File /subsys/net/l2/wifi/wifi_shell.c High
39 File /SysManage/AddUpdateRole.aspx High
40 File /sysmanage/importconf.php High
41 File /SystemManage/User/GetGridJson?_search=false&nd=1680855479750&rows=50&page=1&sidx=F_CreatorTime+desc&sord=asc High
42 File /user/profile High
43 ... ... ...

There are 368 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.

References

The following list contains external sources which discuss the actor and the associated activities:

Literature

The following articles explain our unique predictive cyber threat intelligence:

License

(c) 1997-2023 by vuldb.com. All data on this page is shared under the license CC BY-NC-SA 4.0. Questions? Check the FAQ, read the documentation or contact us!