cyber_threat_intelligence/actors/Saudi Arabia Unknown
2023-01-23 12:25:30 +01:00
..
README.md Update January 2023 2023-01-23 12:25:30 +01:00

Saudi Arabia Unknown - Cyber Threat Intelligence

These indicators were reported, collected, and generated during the VulDB CTI analysis of the actor known as Saudi Arabia Unknown. The activity monitoring correlates data from social media, forums, chat rooms, and darknet markets. It helps to determine associated actors, specific activities, expected intentions, emerging research, and ongoing attacks. Our unique predictive model uses big data to forecast activities and their characteristics.

Live data and more analysis capabilities are available at https://vuldb.com/?actor.saudi_arabia_unknown

Countries

These countries are directly (e.g. origin of attacks) or indirectly (e.g. access by proxy) associated with Saudi Arabia Unknown:

There are 20 more country items available. Please use our online service to access the data.

IOC - Indicator of Compromise

These indicators of compromise (IOC) indicate associated network resources which are known to be part of research and attack activities of Saudi Arabia Unknown.

ID IP address Hostname Campaign Confidence
1 2.88.0.0 - - High
2 5.1.41.0 - - High
3 5.23.20.0 unknown.bitgravity.com - High
4 5.41.0.0 - - High
5 5.42.224.0 - - High
6 5.62.61.124 r-124-61-62-5.consumer-pool.prcdn.net - High
7 5.62.63.104 r-104-63-62-5.consumer-pool.prcdn.net - High
8 5.82.0.0 - - High
9 5.108.0.0 - - High
10 5.132.192.0 - - High
11 5.149.128.0 - - High
12 5.156.0.0 - - High
13 5.163.0.0 - - High
14 5.244.0.0 - - High
15 5.253.80.0 - - High
16 17.69.248.0 - - High
17 23.232.248.0 - - High
18 31.166.0.0 - - High
19 31.187.65.128 - - High
20 34.99.180.0 0.180.99.34.bc.googleusercontent.com - Medium
21 34.99.252.0 0.252.99.34.bc.googleusercontent.com - Medium
22 34.103.196.0 0.196.103.34.bc.googleusercontent.com - Medium
23 37.16.32.0 - - High
24 37.16.128.0 - - High
25 37.25.0.0 - - High
26 37.37.37.37 - - High
27 37.42.0.0 - - High
28 37.56.0.0 - - High
29 37.76.224.0 - - High
30 37.99.128.0 - - High
31 37.104.0.0 - - High
32 37.121.0.0 - - High
33 37.124.0.0 - - High
34 37.141.0.0 - - High
35 37.186.24.0 - - High
36 37.216.0.0 - - High
37 37.224.0.0 - - High
38 37.240.0.0 - - High
39 45.12.70.194 cosh-say.globalhilive.com - High
40 45.12.71.194 - - High
41 45.65.72.0 - - High
42 45.74.1.0 - - High
43 45.90.72.0 - - High
44 45.90.204.0 - - High
45 45.94.12.0 - - High
46 45.135.112.0 - - High
47 45.156.224.0 - - High
48 46.18.160.0 - - High
49 46.29.80.0 - - High
50 46.38.64.0 - - High
51 46.44.64.0 - - High
52 46.49.128.0 - - High
53 46.52.0.0 - - High
54 46.143.128.0 - - High
55 46.149.0.0 - - High
56 46.151.208.0 - - High
57 46.152.0.0 - - High
58 46.161.58.0 - - High
59 46.184.0.0 - - High
60 46.230.0.0 - - High
61 46.235.88.0 - - High
62 46.240.0.0 - - High
63 46.251.128.0 - - High
64 50.60.0.0 - - High
65 50.119.0.0 - - High
66 51.36.0.0 - - High
67 51.39.0.0 - - High
68 51.211.0.0 - - High
69 51.218.0.0 - - High
70 51.223.0.0 - - High
71 51.235.0.0 - - High
72 51.252.0.0 - - High
73 57.88.208.0 - - High
74 57.188.19.0 - - High
75 62.3.0.0 - - High
76 62.3.33.0 - - High
77 62.3.34.0 - - High
78 62.3.36.0 - - High
79 62.3.40.0 - - High
80 62.3.48.0 - - High
81 62.3.52.0 - - High
82 62.3.57.0 - - High
83 62.3.58.0 subnet.time-host.net - High
84 62.3.60.0 - - High
85 62.120.0.0 - - High
86 62.149.64.0 riy-marathon1-sub1.saudi.net.sa - High
87 63.164.12.48 - - High
88 64.16.192.0 - - High
89 64.65.64.0 - - High
90 64.137.192.0 - - High
91 66.78.28.0 - - High
92 66.118.128.0 - - High
93 66.212.96.0 - - High
94 77.30.0.0 - - High
95 77.64.0.0 - - High
96 77.87.16.0 - - High
97 77.90.192.0 - - High
98 77.95.216.0 - - High
99 77.95.221.0 - - High
100 77.95.222.0 - - High
101 77.110.64.0 - - High
102 77.220.116.0 - - High
103 77.221.96.0 - - High
104 77.223.224.0 - - High
105 77.232.96.0 - - High
106 77.232.176.0 - - High
107 77.236.128.0 - - High
108 77.240.80.0 - - High
109 77.240.128.0 - - High
110 77.247.32.0 - - High
111 78.93.0.0 - - High
112 78.95.0.0 - - High
113 78.110.0.0 - - High
114 78.138.192.0 - - High
115 79.139.32.0 - - High
116 79.139.72.0 - - High
117 79.170.0.0 - - High
118 79.170.48.0 - - High
119 79.170.120.0 - - High
120 ... ... ... ...

There are 475 more IOC items available. Please use our online service to access the data.

TTP - Tactics, Techniques, Procedures

Tactics, techniques, and procedures (TTP) summarize the suspected MITRE ATT&CK techniques used by Saudi Arabia Unknown. This data is unique as it uses our predictive model for actor profiling.

ID Technique Weakness Description Confidence
1 T1006 CWE-21, CWE-22, CWE-23 Pathname Traversal High
2 T1040 CWE-294 Authentication Bypass by Capture-replay High
3 T1055 CWE-74 Injection High
4 T1059 CWE-94, CWE-1321 Cross Site Scripting High
5 T1059.007 CWE-79, CWE-80 Cross Site Scripting High
6 ... ... ... ...

There are 18 more TTP items available. Please use our online service to access the data.

IOA - Indicator of Attack

These indicators of attack (IOA) list the potential fragments used for technical activities like reconnaissance, exploitation, privilege escalation, and exfiltration by Saudi Arabia Unknown. This data is unique as it uses our predictive model for actor profiling.

ID Type Indicator Confidence
1 File .github/workflows/combine-prs.yml High
2 File .htaccess Medium
3 File /Admin/add-student.php High
4 File /admin/api/admin/articles/ High
5 File /admin/conferences/list/ High
6 File /admin/edit_admin_details.php?id=admin High
7 File /admin/generalsettings.php High
8 File /Admin/login.php High
9 File /admin/payment.php High
10 File /admin/reports.php High
11 File /admin/showbad.php High
12 File /admin_page/all-files-update-ajax.php High
13 File /apilog.php Medium
14 File /cgi-bin/kerbynet High
15 File /cgi-bin/wlogin.cgi High
16 File /connectors/index.php High
17 File /dms/admin/reports/daily_collection_report.php High
18 File /DocSystem/Repos/getReposAllUsers.do High
19 File /face-recognition-php/facepay-master/camera.php High
20 File /forum/away.php High
21 File /hrm/employeeadd.php High
22 File /hrm/employeeview.php High
23 File /index.php Medium
24 File /info.cgi Medium
25 File /Items/*/RemoteImages/Download High
26 File /items/view_item.php High
27 File /jsoa/hntdCustomDesktopActionContent High
28 File /lists/admin/ High
29 File /lookin/info Medium
30 File /MagickCore/image.c High
31 File /manager/index.php High
32 File /medical/inventories.php High
33 File /modules/profile/index.php High
34 File /modules/projects/vw_files.php High
35 File /modules/public/calendar.php High
36 File /newsDia.php Medium
37 File /out.php Medium
38 File /proxy Low
39 File /public/launchNewWindow.jsp High
40 File /Redcock-Farm/farm/category.php High
41 File /reports/rwservlet High
42 File /sacco_shield/manage_user.php High
43 File /spip.php Medium
44 File /sqlitemanager/main.php?dbsel=-1%20or%2072%20=%2072 High
45 File /staff/bookdetails.php High
46 File /TeleoptiWFM/Administration/GetOneTenant High
47 File /user/update_booking.php High
48 File /WEB-INF/web.xml High
49 File /Wedding-Management-PHP/admin/photos_add.php High
50 File /Wedding-Management/package_detail.php High
51 File /wordpress/wp-admin/options-general.php High
52 File /wp-content/plugins/woocommerce/templates/emails/plain/ High
53 File a2billing/customer/iridium_threed.php High
54 File AbstractScheduleJob.java High
55 File actionphp/download.File.php High
56 File AdClass.php Medium
57 File adclick.php Medium
58 File addtocart.asp High
59 File admin.php Medium
60 ... ... ...

There are 529 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.

References

The following list contains external sources which discuss the actor and the associated activities:

Literature

The following articles explain our unique predictive cyber threat intelligence:

License

(c) 1997-2023 by vuldb.com. All data on this page is shared under the license CC BY-NC-SA 4.0. Questions? Check the FAQ, read the documentation or contact us!