cyber_threat_intelligence/campaigns/Hidden Cobra
2022-04-23 11:50:32 +02:00
..
README.md Update 2022-04-23 11:50:32 +02:00

Hidden Cobra - Cyber Threat Intelligence

These indicators were reported, collected, and generated during the VulDB CTI analysis of the campaign known as Hidden Cobra. The activity monitoring correlates data from social media, forums, chat rooms, and darknet markets. It helps to determine associated actors, specific activities, expected intentions, emerging research, and ongoing attacks. Our unique predictive model uses big data to forecast activities and their characteristics.

Live data and more analysis capabilities are available at https://vuldb.com/?actor

Countries

These countries are directly (e.g. origin of attacks) or indirectly (e.g. access by proxy) associated with Hidden Cobra:

There are 6 more country items available. Please use our online service to access the data.

Actors

These actors are associated with Hidden Cobra or other actors linked to the campaign.

ID Actor Confidence
1 Lazarus High

IOC - Indicator of Compromise

These indicators of compromise (IOC) indicate associated network resources which are known to be part of research and attack activities of Hidden Cobra.

ID IP address Hostname Actor Confidence
1 2.50.22.137 - Lazarus High
2 2.50.22.189 - Lazarus High
3 2.50.25.205 - Lazarus High
4 2.50.27.239 - Lazarus High
5 2.50.40.245 - Lazarus High
6 2.93.86.36 - Lazarus High
7 2.93.86.38 - Lazarus High
8 2.93.86.65 - Lazarus High
9 2.93.86.89 - Lazarus High
10 2.93.86.106 - Lazarus High
11 2.93.86.136 - Lazarus High
12 2.93.86.150 - Lazarus High
13 2.93.86.194 - Lazarus High
14 2.93.86.197 - Lazarus High
15 2.93.86.224 - Lazarus High
16 2.93.86.226 - Lazarus High
17 2.93.86.247 - Lazarus High
18 2.93.86.251 - Lazarus High
19 2.93.86.253 - Lazarus High
20 2.93.131.116 - Lazarus High
21 2.93.131.179 - Lazarus High
22 2.93.238.2 - Lazarus High
23 2.93.238.12 - Lazarus High
24 2.93.238.20 - Lazarus High
25 2.93.238.26 - Lazarus High
26 2.93.238.35 - Lazarus High
27 2.93.238.93 - Lazarus High
28 2.93.238.146 - Lazarus High
29 2.93.238.167 - Lazarus High
30 2.93.238.176 - Lazarus High
31 2.93.238.183 - Lazarus High
32 2.93.238.199 - Lazarus High
33 2.93.238.213 - Lazarus High
34 2.93.238.215 - Lazarus High
35 2.93.238.222 - Lazarus High
36 2.93.238.252 - Lazarus High
37 2.93.238.253 - Lazarus High
38 2.93.248.5 - Lazarus High
39 2.93.248.46 - Lazarus High
40 2.94.53.139 - Lazarus High
41 2.94.65.211 - Lazarus High
42 2.94.65.246 - Lazarus High
43 2.94.82.42 - Lazarus High
44 2.94.117.30 - Lazarus High
45 2.94.117.46 - Lazarus High
46 2.94.117.47 - Lazarus High
47 2.94.117.56 - Lazarus High
48 2.94.209.30 - Lazarus High
49 2.187.99.180 - Lazarus High
50 5.22.137.178 mail.bpdl.co.uk Lazarus High
51 5.22.140.93 5-22-140-93.host.as51043.net Lazarus High
52 5.41.88.137 - Lazarus High
53 5.41.89.32 - Lazarus High
54 5.41.94.221 - Lazarus High
55 5.41.190.7 - Lazarus High
56 5.41.201.151 - Lazarus High
57 5.41.237.214 - Lazarus High
58 5.98.91.76 host-5-98-91-76.business.telecomitalia.it Lazarus High
59 5.141.87.156 5-141-97-156.static-adsl.isurgut.ru Lazarus High
60 5.189.190.67 m2767.contaboserver.net Lazarus High
61 5.200.154.208 - Lazarus High
62 5.200.177.218 - Lazarus High
63 5.200.191.104 - Lazarus High
64 5.200.198.10 - Lazarus High
65 5.200.202.99 - Lazarus High
66 14.140.123.179 14.140.123.179.static-pune-vsnl.net.in Lazarus High
67 14.141.27.100 14.141.26.100.static-Mumbai.vsnl.net.in Lazarus High
68 14.149.149.211 - Lazarus High
69 27.96.110.130 130.110.96.27.static.m1net.com.sg Lazarus High
70 27.125.35.229 - Lazarus High
71 31.47.47.130 - Lazarus High
72 31.54.73.156 host31-54-73-156.range31-54.btcentralplus.com Lazarus High
73 31.54.74.176 host31-54-74-176.range31-54.btcentralplus.com Lazarus High
74 31.146.136.6 31-146-136-6.dsl.utg.ge Lazarus High
75 31.168.203.44 bzq-203-168-31-44.red.bezeqint.net Lazarus High
76 37.34.240.177 - Lazarus High
77 37.48.106.69 high-convey.blockother.com Lazarus High
78 37.71.50.2 2.50.71.37.rev.sfr.net Lazarus High
79 37.75.0.98 - Lazarus High
80 37.75.2.203 - Lazarus High
81 37.75.10.194 mail.kplus.com.tr Lazarus High
82 37.75.11.162 37-75-11-162.rdns.saglayici.net Lazarus High
83 37.104.24.220 - Lazarus High
84 37.104.50.144 - Lazarus High
85 37.104.67.33 - Lazarus High
86 37.105.234.200 - Lazarus High
87 37.106.115.3 - Lazarus High
88 37.143.29.10 - Lazarus High
89 37.148.209.156 37-148-209-156.cizgi.net.tr Lazarus High
90 37.216.213.70 - Lazarus High
91 41.57.108.68 - Lazarus High
92 41.67.136.38 netcomafrica.com Lazarus High
93 41.67.136.39 netcomafrica.com Lazarus High
94 41.72.99.5 - Lazarus High
95 41.72.101.138 - Lazarus High
96 41.74.166.253 - Lazarus High
97 41.110.179.197 - Lazarus High
98 41.128.226.60 - Lazarus High
99 41.131.49.228 host-41-131-49-228.static.link.com.eg Lazarus High
100 41.131.164.156 - Lazarus High
101 41.134.208.234 41-134-208-234.dsl.mweb.co.za Lazarus High
102 41.182.252.56 ADSL-41-182-252-56.ipb.na Lazarus High
103 41.205.139.34 ADSL-41-205-139-34.ipb.na Lazarus High
104 41.208.106.68 owa.altaqnya.com.ly Lazarus High
105 41.208.106.70 dc1.Mail.dsmhlc.ly Lazarus High
106 41.215.250.40 - Lazarus High
107 41.223.30.20 host30-20.creolink.com Lazarus High
108 41.224.254.90 - Lazarus High
109 45.120.61.145 - Lazarus High
110 46.19.101.186 ip-46-19-101-186.gnc.net Lazarus High
111 46.52.131.102 - Lazarus High
112 46.121.242.180 46-121-242-180.static.012.net.il Lazarus High
113 46.174.116.60 - Lazarus High
114 46.174.116.87 - Lazarus High
115 46.174.116.90 - Lazarus High
116 46.174.116.99 - Lazarus High
117 46.174.116.221 - Lazarus High
118 46.174.116.231 - Lazarus High
119 46.174.116.234 - Lazarus High
120 46.174.117.15 - Lazarus High
121 46.174.117.32 - Lazarus High
122 46.174.117.36 - Lazarus High
123 46.174.117.42 - Lazarus High
124 46.174.117.44 - Lazarus High
125 46.174.117.50 - Lazarus High
126 ... ... ... ...

There are 502 more IOC items available. Please use our online service to access the data.

TTP - Tactics, Techniques, Procedures

Tactics, techniques, and procedures (TTP) summarize the suspected MITRE ATT&CK techniques used within Hidden Cobra. This data is unique as it uses our predictive model for actor profiling.

ID Technique Weakness Description Confidence
1 T1059.007 CWE-79, CWE-80 Cross Site Scripting High
2 T1068 CWE-264, CWE-284 Execution with Unnecessary Privileges High
3 T1110.001 CWE-798 Improper Restriction of Excessive Authentication Attempts High
4 ... ... ... ...

There are 7 more TTP items available. Please use our online service to access the data.

IOA - Indicator of Attack

These indicators of attack (IOA) list the potential fragments used for technical activities like reconnaissance, exploitation, privilege escalation, and exfiltration during Hidden Cobra. This data is unique as it uses our predictive model for actor profiling.

ID Type Indicator Confidence
1 File /admin.php?action=themeinstall High
2 File /catcompany.php High
3 File /config/netconf.cmd High
4 File /export Low
5 File /forgetpassword.php High
6 File /forum/away.php High
7 File /graphStatus/displayServiceStatus.php High
8 File /modules/profile/index.php High
9 File /osm/REGISTER.cmd High
10 File /out.php Medium
11 File /pages/items Medium
12 File /proc/pid/syscall High
13 File /secure/admin/InsightDefaultCustomFieldConfig.jspa High
14 File /secure/admin/ViewInstrumentation.jspa High
15 File /servlet.gupld High
16 File /sql/sql_type.cc High
17 File /status Low
18 File /tools/developerConsoleOperations.jsp High
19 File /uncpath/ Medium
20 File /usr/bin/pkexec High
21 File /WEB-INF/web.xml High
22 ... ... ...

There are 179 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.

References

The following list contains external sources which discuss the campaign and the associated activities:

Literature

The following articles explain our unique predictive cyber threat intelligence:

License

(c) 1997-2022 by vuldb.com. All data on this page is shared under the license CC BY-NC-SA 4.0. Questions? Check the FAQ, read the documentation or contact us!