cyber_threat_intelligence/actors/Ukraine Unknown/README.md
2023-05-12 07:27:28 +02:00

69 KiB

Ukraine Unknown - Cyber Threat Intelligence

These indicators were reported, collected, and generated during the VulDB CTI analysis of the actor known as Ukraine Unknown. The activity monitoring correlates data from social media, forums, chat rooms, and darknet markets. It helps to determine associated actors, specific activities, expected intentions, emerging research, and ongoing attacks. Our unique predictive model uses big data to forecast activities and their characteristics.

Live data and more analysis capabilities are available at https://vuldb.com/?actor.ukraine_unknown

Countries

These countries are directly (e.g. origin of attacks) or indirectly (e.g. access by proxy) associated with Ukraine Unknown:

There are 20 more country items available. Please use our online service to access the data.

IOC - Indicator of Compromise

These indicators of compromise (IOC) indicate associated network resources which are known to be part of research and attack activities of Ukraine Unknown.

ID IP address Hostname Campaign Confidence
1 2.21.89.0 a2-21-89-0.deploy.static.akamaitechnologies.com - High
2 2.21.173.0 a2-21-173-0.deploy.static.akamaitechnologies.com - High
3 2.56.108.0 vmta2.gcwsm0.imagirize.com - High
4 2.56.136.0 - - High
5 2.56.168.0 0.168.56.2.gn.in.ua - High
6 2.57.36.0 - - High
7 2.57.39.0 - - High
8 2.57.112.0 - - High
9 2.57.150.0 - - High
10 2.57.204.0 - - High
11 2.58.204.0 - - High
12 2.59.76.0 - - High
13 2.59.220.0 - - High
14 5.1.0.0 - - High
15 5.8.32.0 subnet.gcore.lu - High
16 5.8.34.0 subnet.gcore.lu - High
17 5.22.156.0 - - High
18 5.34.176.0 subnet.ipv4.layer6.net - High
19 5.34.182.0 subnet.ipv4.layer6.net - High
20 5.44.252.0 - - High
21 5.53.112.0 - - High
22 5.56.24.0 - - High
23 5.57.64.0 - - High
24 5.58.0.0 - - High
25 5.59.38.0 - - High
26 5.59.54.0 - - High
27 5.59.104.0 - - High
28 5.59.170.0 - - High
29 5.62.61.196 r-196-61-62-5.consumer-pool.prcdn.net - High
30 5.62.63.184 r-184-63-62-5.consumer-pool.prcdn.net - High
31 5.83.16.0 5.83.16.0.best.net.ua - High
32 5.101.208.0 - - High
33 5.102.36.0 - - High
34 5.104.32.0 - - High
35 5.105.0.0 - - High
36 5.132.148.0 - - High
37 5.149.120.0 5.149.120.0.mirohost.net - High
38 5.149.208.0 - - High
39 5.153.128.0 - - High
40 5.153.160.0 - - High
41 5.153.168.0 - - High
42 5.153.176.0 0.176.isphost.donbass.com - High
43 5.175.150.128 - - High
44 5.180.100.0 - - High
45 5.180.128.0 - - High
46 5.180.176.0 - - High
47 5.181.84.0 - - High
48 5.181.87.0 - - High
49 5.181.196.0 - - High
50 5.181.248.0 - - High
51 5.182.96.0 - - High
52 5.183.64.0 - - High
53 5.183.128.0 - - High
54 5.183.200.0 net-200-0-63.bg.net.ua - High
55 5.188.6.0 subnet.gcore.lu - High
56 5.188.61.0 - - High
57 5.188.136.0 - - High
58 5.188.144.0 - - High
59 5.188.149.0 subnet.edgecenter.ru - High
60 5.188.191.0 subnet.gcore.lu - High
61 5.199.232.0 - - High
62 5.207.0.0 - - High
63 5.248.0.0 5-248-0-0.broadband.kyivstar.net - High
64 5.252.180.0 - - High
65 5.255.32.0 ppp-5-255-32-0.wildpark.net - High
66 5.255.160.0 5-255-160-0-kh.maxnet.ua - High
67 8.42.51.0 - - High
68 23.56.98.0 a23-56-98-0.deploy.static.akamaitechnologies.com - High
69 31.3.24.0 - - High
70 31.3.192.0 - - High
71 31.6.8.0 - - High
72 31.6.96.0 - - High
73 31.12.128.0 31-12-128-0.vf-ua.net - High
74 31.24.208.0 - - High
75 31.28.1.0 - - High
76 31.28.1.128 - - High
77 31.28.160.0 - - High
78 31.28.224.0 - - High
79 31.31.96.0 subnet96-0-24.tenet.odessa.ua - High
80 31.40.16.0 - - High
81 31.40.104.0 0.104.40.31.ukrtelebud.com.ua - High
82 31.40.128.0 - - High
83 31.40.128.70 - - High
84 31.41.48.0 - - High
85 31.41.64.0 0.64.41.31.clients.uainet.net - High
86 31.41.88.0 0-88-41-31.users.novi.uz.ua - High
87 31.41.104.0 - - High
88 31.41.112.0 - - High
89 31.41.128.0 - - High
90 31.41.216.0 - - High
91 31.42.48.0 - - High
92 31.42.64.0 - - High
93 31.42.112.0 - - High
94 31.42.160.0 - - High
95 31.42.178.0 - - High
96 31.42.184.0 dedicated.vsys.host - High
97 31.43.0.0 net.dks.com.ua - High
98 31.43.128.0 net-31.43.128.0.corbina.com.ua - High
99 31.43.160.0 - - High
100 31.43.168.0 - - High
101 31.43.178.0 - - High
102 31.43.180.0 - - High
103 31.43.185.0 - - High
104 31.43.188.0 - - High
105 31.43.224.0 - - High
106 31.44.188.0 - - High
107 31.44.190.0 - - High
108 31.128.64.0 - - High
109 31.128.160.0 - - High
110 31.128.224.0 - - High
111 31.129.64.0 - - High
112 31.129.160.0 - - High
113 31.129.224.0 - - High
114 31.131.16.0 - - High
115 31.131.32.0 - - High
116 31.131.64.0 - - High
117 31.131.96.0 - - High
118 31.131.128.0 - - High
119 31.133.44.0 - - High
120 31.133.46.0 - - High
121 31.133.48.0 - - High
122 31.133.64.0 pool-31-133-64-0.optima-east.net - High
123 31.133.96.0 - - High
124 31.133.112.0 - - High
125 31.133.114.0 - - High
126 31.133.116.0 - - High
127 31.134.64.0 - - High
128 31.134.104.0 ip-31-134-104-0.dss-group.net - High
129 31.134.112.0 - - High
130 31.134.208.0 - - High
131 31.135.96.0 - - High
132 31.135.128.0 - - High
133 31.135.176.0 - - High
134 31.144.0.0 31.144-0-0.staticip.vf-ua.net - High
135 31.148.7.0 - - High
136 31.148.20.0 - - High
137 31.148.20.16 - - High
138 31.148.20.24 - - High
139 31.148.20.28 - - High
140 31.148.20.30 - - High
141 31.148.20.32 - - High
142 31.148.20.64 - - High
143 31.148.20.128 - - High
144 31.148.23.0 - - High
145 31.148.25.0 - - High
146 31.148.28.0 - - High
147 31.148.51.0 - - High
148 31.148.52.0 - - High
149 31.148.56.0 - - High
150 31.148.134.0 pppoe-31-148-134-0.customer.ternet.com.ua - High
151 31.148.149.0 - - High
152 31.148.150.0 pppoe-31-148-150-0.customer.ternet.com.ua - High
153 31.148.168.0 - - High
154 31.148.171.0 - - High
155 31.148.175.0 - - High
156 31.148.176.0 - - High
157 31.148.206.0 - - High
158 31.148.218.0 - - High
159 31.148.221.0 - - High
160 31.148.245.0 - - High
161 31.148.252.0 - - High
162 31.170.128.0 - - High
163 31.172.65.0 - - High
164 31.172.69.0 - - High
165 31.172.136.0 - - High
166 31.193.80.0 - - High
167 31.202.0.0 - - High
168 31.204.51.0 - - High
169 31.216.57.0 - - High
170 31.216.63.0 - - High
171 31.217.252.0 - - High
172 31.222.235.0 - - High
173 31.222.236.0 - - High
174 31.223.224.0 obolon3-vl823-unicast.voks.ua - High
175 34.99.194.0 0.194.99.34.bc.googleusercontent.com - Medium
176 34.103.138.0 0.138.103.34.bc.googleusercontent.com - Medium
177 34.103.210.0 0.210.103.34.bc.googleusercontent.com - Medium
178 34.103.249.0 0.249.103.34.bc.googleusercontent.com - Medium
179 37.17.240.0 - - High
180 37.19.128.0 - - High
181 37.19.218.0 unn-37-19-218-0.datapacket.com - High
182 37.25.32.1 - - High
183 37.25.32.2 - - High
184 37.25.32.4 - - High
185 37.25.32.8 - - High
186 37.25.32.16 - - High
187 37.25.32.32 - - High
188 37.25.32.64 - - High
189 37.25.32.128 - - High
190 37.25.33.0 - - High
191 37.25.34.0 - - High
192 37.25.36.0 - - High
193 37.25.96.0 ppp-37-25-96-0.wildpark.net - High
194 37.44.232.0 37-44-232-0.arx.com.ua - High
195 37.46.216.0 - - High
196 37.46.224.0 0.224.46.37.triolan.net - High
197 37.52.0.0 0-0-52-37.pool.ukrtel.net - High
198 37.57.0.0 0.0.57.37.triolan.net - High
199 37.72.40.0 dynamicip.pppoe.37.72.40.0.vntp.net - High
200 37.72.128.0 - - High
201 37.73.0.0 - - High
202 37.75.216.0 - - High
203 37.115.0.0 37-115-0-0.broadband.kyivstar.net - High
204 37.139.96.0 - - High
205 37.139.160.0 37-139-160-0.dynamic-pool.mclaut.net - High
206 37.140.250.0 - - High
207 37.143.88.0 - - High
208 37.143.132.0 - - High
209 37.203.0.0 subnet-0-24.tenet.odessa.ua - High
210 37.221.128.0 - - High
211 37.229.0.0 37-229-0-0.broadband.kyivstar.net - High
212 37.230.163.3 37.230.163.3.leadertelecom.ru - High
213 45.8.89.0 - - High
214 45.9.28.0 - - High
215 45.9.40.0 - - High
216 45.9.236.0 45.9.236.0.deltahost-ptr - High
217 45.10.32.0 - - High
218 45.10.88.0 - - High
219 45.11.4.0 - - High
220 45.11.56.0 dedicated.vsys.host - High
221 45.11.57.0 dedicated.vsys.host - High
222 45.11.58.0 dedicated.vsys.host - High
223 45.12.0.0 dedicated.vsys.host - High
224 45.12.24.0 - - High
225 45.12.70.231 scotticism.globalhilive.com - High
226 45.12.71.231 - - High
227 45.13.188.0 - - High
228 45.13.190.0 - - High
229 45.14.24.0 - - High
230 45.14.108.0 - - High
231 45.15.232.0 - - High
232 45.66.55.0 - - High
233 45.67.20.0 - - High
234 45.67.120.0 - - High
235 45.67.215.0 - - High
236 45.80.108.0 - - High
237 45.81.112.0 - - High
238 45.82.8.0 0.8.82.45.ukrtelebud.com.ua - High
239 45.82.84.0 45.82.84.0.deltahost-ptr - High
240 45.82.162.0 - - High
241 45.83.0.0 - - High
242 45.83.176.0 - - High
243 45.84.0.116 n5336.md - High
244 45.84.31.0 - - High
245 45.84.92.0 0.92.84.45.unknown.m-x.net.ua - High
246 45.84.148.0 - - High
247 45.85.36.0 - - High
248 45.86.44.0 - - High
249 45.87.88.0 - - High
250 45.87.155.0 . - High
251 45.88.136.0 - - High
252 45.88.137.0 - - High
253 45.88.138.0 - - High
254 45.88.159.0 - - High
255 45.89.72.0 - - High
256 45.89.88.0 - - High
257 45.90.176.0 - - High
258 45.91.128.0 - - High
259 45.91.168.0 - - High
260 45.91.216.0 - - High
261 45.93.8.0 subnet.stark-industries.solutions - High
262 45.94.92.0 - - High
263 45.94.156.0 - - High
264 45.94.168.0 - - High
265 45.95.164.0 45-95-164-0.dynamic-pool.mclaut.net - High
266 45.95.188.0 - - High
267 45.95.235.0 - - High
268 45.128.148.0 subnet.isplevel.name - High
269 45.128.188.0 - - High
270 45.129.72.0 - - High
271 45.129.97.0 subnet.gmhost.hosting - High
272 45.129.98.0 subnet.gmhost.hosting - High
273 45.130.0.0 45-130-0-0.broadband.tenet.odessa.ua - High
274 45.130.244.0 - - High
275 45.131.164.0 - - High
276 45.132.92.0 - - High
277 45.132.180.0 - - High
278 45.132.182.0 - - High
279 45.133.41.0 - - High
280 45.135.0.0 - - High
281 45.135.167.0 0.167.135.45.vikhost.com - High
282 45.135.235.0 - - High
283 45.136.206.0 0.206.136.45.vikhost.com - High
284 45.137.155.0 . - High
285 45.138.75.0 - - High
286 45.138.180.0 - - High
287 45.140.19.0 subnet.housevds.com - High
288 45.140.44.0 - - High
289 45.140.80.0 - - High
290 45.140.108.0 - - High
291 45.140.120.0 45-140-120-0.broadband.tenet.odessa.ua - High
292 45.140.146.17 vm545760.stark-industries.solutions - High
293 45.141.156.0 - - High
294 45.141.186.0 - - High
295 45.142.88.0 - - High
296 45.142.123.0 - - High
297 45.143.48.0 45-143-48-0.dynamic-pool.mclaut.net - High
298 45.143.253.0 - - High
299 45.143.255.0 - - High
300 45.144.212.0 - - High
301 45.144.213.0 - - High
302 45.144.215.0 - - High
303 45.146.116.0 - - High
304 45.146.170.0 - - High
305 45.147.140.0 - - High
306 45.148.148.0 - - High
307 45.148.152.0 - - High
308 45.148.228.0 - - High
309 45.149.24.0 - - High
310 45.149.40.0 - - High
311 45.149.133.0 - - High
312 45.149.232.0 45-149-232-0.interiorhosting.com - High
313 45.149.244.0 - - High
314 45.150.32.0 - - High
315 45.150.56.0 - - High
316 45.151.0.0 - - High
317 45.151.3.0 - - High
318 45.151.89.0 - - High
319 45.151.90.0 45-151-90-0.whizcyber.com - High
320 45.151.147.0 0-147-151-45-yarcom.com.ua - High
321 45.151.236.0 - - High
322 45.152.24.0 - - High
323 45.152.72.0 - - High
324 45.152.164.0 - - High
325 45.153.208.0 - - High
326 45.153.229.0 . - High
327 45.154.116.0 subnet.thehost.ua - High
328 45.154.128.0 - - High
329 45.155.80.0 - - High
330 45.156.36.0 45-156-36-0.broadband.tenet.odessa.ua - High
331 45.157.204.0 - - High
332 45.158.48.0 45-158-48-0.dynamic-pool.mclaut.net - High
333 45.158.128.0 - - High
334 45.158.244.0 - - High
335 45.159.100.0 - - High
336 46.8.23.0 - - High
337 46.8.28.0 - - High
338 46.8.34.0 - - High
339 46.8.37.0 - - High
340 46.17.240.0 46-17-240-0.aries.od.ua - High
341 46.18.0.0 - - High
342 46.21.250.0 subnet.zomro.com - High
343 46.28.64.0 subnet.ipv4.layer6.net - High
344 46.28.192.0 - - High
345 46.29.128.0 - - High
346 46.30.160.0 160.30.46.0.access.ipnet.ua - High
347 46.33.32.0 - - High
348 46.33.224.0 ppp-46-33-224-0.wildpark.net - High
349 46.35.224.0 - - High
350 46.36.201.16 - - High
351 46.36.201.20 - - High
352 46.36.201.51 - - High
353 46.36.201.52 - - High
354 46.36.201.97 - - High
355 46.36.201.98 - - High
356 46.36.202.81 - - High
357 46.36.202.82 - - High
358 46.36.202.84 - - High
359 46.36.202.88 - - High
360 46.36.202.90 - - High
361 46.36.202.211 - - High
362 46.36.202.212 - - High
363 46.36.202.216 - - High
364 46.36.202.224 - - High
365 46.36.202.228 - - High
366 46.36.202.230 - - High
367 46.37.192.0 0.pool-46.37.192.icn.ua - High
368 46.39.64.0 - - High
369 46.46.64.0 - - High
370 46.63.0.0 pool-46-63-0-0.x-city.ua - High
371 46.96.0.0 - - High
372 46.98.0.0 PPPoE.fregat.ua - High
373 46.107.228.0 - - High
374 46.118.0.0 46-118-0-0.broadband.kyivstar.net - High
375 46.133.0.0 46-133-0-0.mobile.vf-ua.net - High
376 46.148.16.0 ip-46-148-16-0.infiumhost.net - High
377 46.148.112.0 - - High
378 46.148.115.0 - - High
379 46.148.116.0 - - High
380 46.148.118.0 - - High
381 46.148.120.0 - - High
382 46.148.122.0 - - High
383 46.148.176.0 - - High
384 46.149.48.0 - - High
385 46.149.80.0 - - High
386 46.149.173.0 - - High
387 46.149.176.0 - - High
388 46.150.0.0 - - High
389 46.150.64.0 46.150.64.0.mlt.volia.net - High
390 46.151.40.0 - - High
391 46.151.48.0 net48-151-46.reedlan.com - High
392 46.151.80.0 - - High
393 46.151.144.0 - - High
394 46.151.176.0 - - High
395 46.151.192.0 - - High
396 46.151.248.0 ip-46-151-248-0.ctn.cv.ua - High
397 46.160.64.0 - - High
398 46.161.40.0 - - High
399 46.161.62.128 pinspb.ru - High
400 46.162.0.0 - - High
401 46.164.128.0 - - High
402 46.172.64.0 - - High
403 46.172.128.0 - - High
404 46.172.192.0 - - High
405 46.173.64.0 - - High
406 46.173.96.0 - - High
407 46.173.128.0 - - High
408 46.173.160.0 - - High
409 46.174.64.0 - - High
410 46.174.120.0 - - High
411 46.174.160.0 network.46-174-160-0.it-mark.net - High
412 46.174.190.0 - - High
413 46.174.216.0 - - High
414 46.174.240.0 - - High
415 46.175.16.0 UNUSED.imc-ua.net - High
416 46.175.64.0 - - High
417 46.175.80.0 - - High
418 46.175.136.0 - - High
419 46.175.144.0 - - High
420 46.175.160.0 - - High
421 46.175.184.0 - - High
422 46.175.240.0 - - High
423 46.182.80.0 - - High
424 46.185.0.0 46-185-0-0.broadband.kyivstar.net - High
425 46.200.0.0 0-0-200-46.pool.ukrtel.net - High
426 46.211.0.0 46-211-0-0.mobile.kyivstar.net - High
427 46.219.0.0 - - High
428 46.227.136.0 dynamicip.pppoe.46.227.136.0.vntp.net - High
429 46.229.48.0 46-229-48-0.kievnet.com.ua - High
430 46.231.224.0 - - High
431 46.232.232.0 - - High
432 46.243.209.0 - - High
433 46.247.128.0 - - High
434 46.250.0.0 46.250.0.0.pool.breezein.net - High
435 46.250.96.0 - - High
436 46.252.208.0 - - High
437 46.253.131.0 - - High
438 46.253.140.0 - - High
439 46.254.107.0 - - High
440 46.255.32.0 46-255-32-0.dynamic-pool.mclaut.net - High
441 50.7.248.0 - - High
442 57.87.192.0 - - High
443 57.90.120.0 - - High
444 62.4.111.0 - - High
445 62.16.0.0 subnet124-0-24.tenet.odessa.ua - High
446 62.64.64.0 - - High
447 62.72.160.0 - - High
448 62.76.12.0 - - High
449 62.80.160.0 - - High
450 62.84.248.0 62.84.248.0.best.net.ua - High
451 62.106.68.0 test2.hostoasis.net - High
452 62.106.84.0 hostingturkiye.com.tr - High
453 62.122.0.0 - - High
454 62.122.56.0 - - High
455 62.122.64.0 - - High
456 62.122.104.0 - - High
457 62.122.152.0 pe-sh-pbsrv-net.ollie.com.ua - High
458 62.122.200.0 - - High
459 62.122.220.0 - - High
460 62.140.236.0 62-140-236-0.fiord.ru - High
461 62.140.239.0 62-140-239-0.fiord.net - High
462 62.140.239.128 msk-m9-b1-ae7-vlan305.fiord.net - High
463 62.140.239.192 62-140-239-192.fiord.net - High
464 62.140.239.224 62-140-239-224.fiord.net - High
465 62.140.239.240 62-140-239-240.fiord.net - High
466 62.140.239.242 62-140-239-242-fiord.net - High
467 62.140.239.244 msk-m9-b1-ae22-vlan2042.fiord.net - High
468 62.140.239.248 62-140-239-248.fiord.net - High
469 62.149.0.0 - - High
470 62.182.64.0 - - High
471 62.182.80.0 host-0.dedicated.vsys.host - High
472 62.182.120.0 unused.imc-ua.net - High
473 62.182.160.0 62.182.160.0.serverel.net - High
474 62.187.208.0 - - High
475 62.192.154.0 - - High
476 62.204.57.0 - - High
477 62.205.128.0 - - High
478 62.216.32.0 - - High
479 62.221.32.0 - - High
480 62.244.0.0 - - High
481 63.168.72.4 - - High
482 63.246.139.0 - - High
483 66.96.119.128 - - High
484 69.168.237.0 - - High
485 69.168.239.0 - - High
486 76.9.27.0 - - High
487 77.47.128.0 net-v319.r7.kpi.ua - High
488 77.47.136.0 - - High
489 77.47.140.0 - - High
490 77.47.144.0 - - High
491 77.47.160.0 0.160.47.77.pptp.kpi.ua - High
492 77.47.176.0 0.176.47.77.pptp.kpi.ua - High
493 77.47.184.0 - - High
494 77.47.192.0 ip0.kiev.ua - High
495 77.47.208.0 - - High
496 77.47.214.0 - - High
497 77.47.216.0 - - High
498 77.47.224.0 - - High
499 77.47.240.0 - - High
500 77.47.244.0 - - High
501 77.47.246.0 - - High
502 77.47.248.0 - - High
503 77.52.0.0 77-52-0-0.staticip.vf-ua.net - High
504 77.72.128.0 - - High
505 77.75.144.0 facebook.dataline.ua - High
506 77.83.36.0 - - High
507 77.83.37.0 undefined.hostname.localhost - High
508 77.83.100.0 - - High
509 77.83.102.0 - - High
510 77.83.188.0 - - High
511 77.83.193.0 - - High
512 77.83.204.0 - - High
513 77.87.32.0 - - High
514 77.87.120.0 - - High
515 77.87.123.0 - - High
516 77.87.127.0 network16.thehost.ua - High
517 77.87.144.0 77.87.144.0.sta.pautina.ua - High
518 77.87.192.0 77.87.192.0.mirohost.net - High
519 77.88.192.0 - - High
520 77.88.238.0 ucloud-net.onix.kiev.ua - High
521 77.88.240.0 - - High
522 77.93.32.0 - - High
523 77.109.0.0 - - High
524 77.111.244.0 - - High
525 77.120.0.0 unknown.volia.net - High
526 77.120.32.0 77.120.32.0.lvv.volia.net - High
527 77.120.48.0 ip.77.121.13.0.volia.net - High
528 77.120.60.0 metro.volia.net - High
529 77.120.64.0 77.120.64.0.kir.volia.net - High
530 77.120.128.0 77.120.128.0.kha.volia.net - High
531 77.121.0.0 77.121.0.0.khe.volia.net - High
532 77.121.8.0 77.121.8.0.pol.volia.net - High
533 77.121.12.0 77.121.12.0.head.sum.volia.net - High
534 77.121.15.0 77.121.15.0.ter.volia.net - High
535 77.121.16.0 77.121.16.0.lut.volia.net - High
536 77.121.32.0 - - High
537 77.121.64.0 77.121.64.0.lut.volia.net - High
538 77.121.128.0 77.121.128.0.zap.volia.net - High
539 77.122.0.0 77.122.0.0.kha.volia.net - High
540 77.123.0.0 77.123.0.0.rov.volia.net - High
541 77.123.128.0 0.128.123.77.colo.static.dcvolia.com - High
542 77.123.192.0 - - High
543 77.222.128.0 - - High
544 77.239.160.0 77-239-160-0.static.vega-ua.net - High
545 77.244.32.0 77.244.32.0.kha.volia.net - High
546 77.246.248.0 - - High
547 77.247.16.0 ppp-77-247-16-0.wildpark.net - High
548 77.247.216.0 - - High
549 78.24.72.0 - - High
550 78.24.75.0 - - High
551 78.24.76.0 - - High
552 78.24.78.0 - - High
553 78.25.0.0 - - High
554 78.26.128.0 net-78.26.128-255.Odessa.TV - High
555 78.27.128.0 pool128-000.domashka.kiev.ua - High
556 78.30.192.0 - - High
557 78.31.176.0 - - High
558 78.31.189.0 ip-78-31-189-0.infiumhost.net - High
559 78.41.107.0 - - High
560 78.109.16.0 0.16.109.78.hosting.ua - High
561 78.111.16.0 dsl-16br0.vil.com.ua - High
562 78.111.176.0 - - High
563 78.111.208.0 208-0.pppoe.mp.farlep.net - High
564 78.137.0.0 78-137-0-0.static-ppp-pool.2mcl.com - High
565 78.138.25.0 - - High
566 78.152.160.0 - - High
567 78.153.137.0 - - High
568 78.153.138.0 - - High
569 78.153.147.0 - - High
570 78.154.160.0 78.154.160.0.ett.ua - High
571 78.158.192.0 - - High
572 78.159.32.0 - - High
573 79.98.240.0 - - High
574 79.110.17.0 - - High
575 79.110.18.0 - - High
576 79.110.20.0 - - High
577 79.110.22.0 - - High
578 79.110.23.0 - - High
579 79.110.24.0 - - High
580 79.110.25.0 - - High
581 79.110.25.128 - - High
582 79.110.26.0 - - High
583 79.110.28.0 - - High
584 79.110.31.0 - - High
585 79.110.96.0 79.110.96.0.serverel.net - High
586 79.110.128.0 - - High
587 79.110.188.0 - - High
588 79.110.208.0 79.110.208.0.serverel.net - High
589 79.110.209.0 serverel.net - High
590 79.110.210.0 serverel.net - High
591 79.124.128.0 0.128.124.79.in-addr.arpa - High
592 79.133.108.0 - - High
593 79.135.192.0 0.pool-79.135.192.icn.ua - High
594 79.140.0.0 subnet79-0-24.Te.NeT.UA - High
595 79.142.192.0 - - High
596 79.143.32.0 79.143.32.0.vntp.net - High
597 79.171.120.0 - - High
598 80.64.80.0 80.64.80.0.untc.net - High
599 80.66.76.187 - - High
600 80.66.81.0 - - High
601 80.66.85.0 - - High
602 80.66.196.0 - - High
603 80.70.64.0 - - High
604 80.71.158.0 - - High
605 80.73.0.0 0.0.73.80.triolan.net - High
606 80.77.32.0 - - High
607 80.78.32.0 80-78-32-0.nbi.com.ua - High
608 80.82.198.0 - - High
609 80.84.176.0 - - High
610 80.90.224.0 - - High
611 80.91.160.0 - - High
612 80.92.224.0 - - High
613 80.93.112.0 nw-servers.ett.ua - High
614 80.242.96.0 - - High
615 80.243.144.0 - - High
616 80.245.112.0 - - High
617 80.245.115.0 ip0-115-245-80.crelcom.ru - High
618 80.245.116.0 ip0-116-245-80.crelcom.ru - High
619 80.245.121.0 ip0-121.245.80.mobile-win.ru - High
620 80.249.224.0 - - High
621 80.252.240.0 ppp-80-252-240-0.wildpark.net - High
622 80.254.0.0 0-net.express.net.ua - High
623 80.255.64.0 - - High
624 81.2.149.96 - - High
625 81.17.128.0 - - High
626 81.17.137.0 - - High
627 81.17.138.0 - - High
628 81.17.140.0 - - High
629 81.21.0.0 - - High
630 81.22.128.0 - - High
631 81.23.16.0 - - High
632 81.24.208.0 81.24.208.0.trion.mk.ua - High
633 81.25.224.0 Skyline-NET.sky.od.ua - High
634 81.26.156.0 - - High
635 81.26.158.0 - - High
636 81.30.160.0 - - High
637 81.85.14.0 - - High
638 81.90.224.0 bs-vm-net-1.radiocom.net.ua - High
639 81.95.176.0 - - High
640 81.162.56.0 - - High
641 81.162.64.0 - - High
642 81.162.96.0 - - High
643 81.162.216.0 - - High
644 81.162.224.0 - - High
645 81.163.88.0 - - High
646 81.163.112.0 - - High
647 81.163.152.0 - - High
648 81.163.208.0 - - High
649 82.117.224.0 VELTON-GPONK2-KH-NET1.224.117.82.in-addr.arpa - High
650 82.117.240.0 VELTON-GPON-NET-240.240.117.82.in-addr.arpa - High
651 82.117.248.0 VELTON-GPON-X00-KH-NET-248.248.117.82.in-addr.arpa - High
652 82.117.254.0 subnet.ipv4.layer6.net - High
653 82.118.16.0 subnet.ipv4.layer6.net - High
654 82.144.192.0 unknown.volia.net - High
655 82.193.96.0 - - High
656 82.207.0.0 - - High
657 83.137.88.0 - - High
658 83.142.48.0 83-142-48-0.dynamic-pool.mclaut.net - High
659 83.142.104.0 - - High
660 83.142.208.0 - - High
661 83.142.232.0 base-office.skyvision.net.ua - High
662 83.143.200.0 net83.143.200.reedlan.com - High
663 83.143.232.0 - - High
664 83.150.204.0 network.starlink.ua - High
665 83.170.192.0 ll-0.192.170.83.lv.sovam.net.ua - High
666 83.218.224.0 - - High
667 83.242.96.0 - - High
668 84.21.160.0 - - High
669 84.47.132.0 - - High
670 84.47.179.0 - - High
671 84.234.104.0 - - High
672 84.234.108.0 - - High
673 84.246.80.0 - - High
674 84.246.84.0 - - High
675 84.246.86.0 - - High
676 84.246.106.0 - - High
677 84.246.109.0 - - High
678 85.90.192.0 VELTON-PA-CORE-NET.192.90.85.in-addr.arpa - High
679 85.91.197.233 - - High
680 85.114.192.0 - - High
681 85.159.0.0 - - High
682 85.198.128.0 128-0.trifle.net - High
683 85.209.44.0 85-209-44-0.ibnet.ua - High
684 85.209.120.0 - - High
685 85.209.122.0 - - High
686 85.217.128.0 - - High
687 85.223.128.0 - - High
688 85.238.96.0 subnet96-0-26.tenet.odessa.ua - High
689 85.255.176.0 - - High
690 86.62.44.0 44-62-86.net.arkada-x.com - High
691 86.106.83.0 - - High
692 86.111.64.0 - - High
693 86.111.224.0 - - High
694 87.76.128.0 - - High
695 87.120.36.0 no-rdns.mykone.info - High
696 87.121.222.0 - - High
697 87.236.151.0 - - High
698 87.238.152.0 152.238.87.privatbank.ua - High
699 87.244.128.0 - - High
700 87.245.216.0 - - High
701 87.245.222.0 - - High
702 87.245.222.64 - - High
703 87.245.237.0 ae5-209.RT.NTL.KIV.UA.retn.net - High
704 87.245.239.0 - - High
705 87.245.247.0 - - High
706 87.247.152.0 87.247.152.0.deltahost-ptr - High
707 87.251.74.0 - - High
708 88.81.224.0 - - High
709 88.135.80.0 - - High
710 88.135.112.0 - - High
711 88.135.192.0 - - High
712 88.151.12.0 network17.thehost.ua - High
713 88.151.15.0 - - High
714 88.154.0.0 - - High
715 88.214.8.0 88-214-8-0.broadband.tenet.odessa.ua - High
716 88.214.27.0 - - High
717 88.214.64.0 88-214-64-0.vf-ua.net - High
718 88.218.29.0 - - High
719 88.218.30.0 - - High
720 88.218.180.0 - - High
721 88.218.188.0 subnet.thehost.ua - High
722 89.19.96.0 - - High
723 89.21.72.0 - - High
724 89.21.80.0 - - High
725 89.21.84.0 - - High
726 89.21.88.0 - - High
727 89.22.40.0 undef.isys.net.ua - High
728 89.22.200.0 - - High
729 89.22.240.0 - - High
730 89.28.200.0 - - High
731 89.105.224.0 net-224--0-127.kiev.farlep.net - High
732 89.107.14.0 - - High
733 89.107.136.0 - - High
734 89.110.64.0 - - High
735 89.162.128.0 karavanska.lv.sovam.net.ua - High
736 89.184.64.0 89.184.64.0.mirohost.net - High
737 89.185.0.0 - - High
738 89.187.0.0 host-0-0.wi.com.ua - High
739 89.200.232.0 - - High
740 89.200.248.0 - - High
741 89.209.0.0 - - High
742 89.248.70.0 - - High
743 89.251.16.0 - - High
744 89.252.0.0 89.252.0.0.freenet.com.ua - High
745 91.90.8.0 - - High
746 91.90.16.0 net-91-90-16.skif.com.ua - High
747 91.90.196.0 - - High
748 91.92.2.0 - - High
749 91.102.176.0 - - High
750 91.103.110.0 - - High
751 91.103.120.0 - - High
752 91.105.204.0 border0.koma.tv - High
753 91.105.236.0 - - High
754 91.108.52.0 - - High
755 91.123.144.0 - - High
756 91.124.0.0 - - High
757 91.132.132.0 - - High
758 91.132.140.0 - - High
759 91.132.148.0 - - High
760 91.132.164.0 - - High
761 91.132.184.0 - - High
762 91.142.160.0 - - High
763 91.145.192.0 192.145.91.in-addr.arpa - High
764 91.184.224.0 - - High
765 91.189.128.0 - - High
766 91.189.152.0 - - High
767 91.190.153.0 - - High
768 91.192.44.0 - - High
769 91.192.104.0 - - High
770 91.192.128.0 subnet-128-0.lan-telecom.net - High
771 91.192.136.0 - - High
772 91.192.152.0 - - High
773 91.192.160.0 - - High
774 91.192.180.0 - - High
775 91.192.184.0 - - High
776 91.192.200.0 - - High
777 91.192.216.0 UNUSED.airport.net.ua - High
778 91.193.32.0 v68.mpls.i4.norden-lilljorm.under.net.ua - High
779 91.193.68.0 - - High
780 91.193.76.0 - - High
781 91.193.80.0 - - High
782 91.193.124.0 - - High
783 91.193.128.0 - - High
784 91.193.164.0 91.193.164.000.kievline.net - High
785 91.193.172.0 0.172.193.91.triolan.net - High
786 91.193.192.0 - - High
787 91.193.204.0 - - High
788 91.193.252.0 - - High
789 91.194.34.0 - - High
790 91.194.40.0 - - High
791 91.194.50.0 - - High
792 91.194.56.0 - - High
793 91.194.72.0 - - High
794 91.194.78.0 subnet-78-24-dca.te.net.ua - High
795 91.194.80.0 - - High
796 91.194.88.0 - - High
797 91.194.134.0 - - High
798 91.194.162.0 - - High
799 91.194.168.0 - - High
800 91.194.192.0 - - High
801 91.194.238.0 - - High
802 91.194.250.0 - - High
803 91.195.2.0 - - High
804 91.195.10.0 - - High
805 91.195.52.0 nocservice.biz - High
806 91.195.68.0 - - High
807 91.195.74.0 91.195.74.0.telegroup.kiev.ua - High
808 91.195.86.0 - - High
809 91.195.90.0 - - High
810 91.195.96.0 - - High
811 91.195.120.0 - - High
812 91.195.156.0 - - High
813 91.195.172.0 0-172-195-91.users.novi.uz.ua - High
814 91.195.184.0 - - High
815 91.195.214.0 - - High
816 91.195.230.0 - - High
817 91.195.244.0 popelnya.net - High
818 91.195.248.0 0.248.195.91.akson45.net - High
819 91.196.0.0 colo-198-0.hostbizua.com - High
820 91.196.52.0 pppoe.komitex.net - High
821 91.196.60.0 - - High
822 91.196.80.0 - - High
823 91.196.88.0 - - High
824 91.196.96.0 91.196.96.0.untc.net - High
825 91.196.120.0 - - High
826 91.196.132.0 net-91-196-132-0.prmt-eu.com - High
827 91.196.148.0 - - High
828 91.196.156.0 - - High
829 91.196.160.0 - - High
830 91.196.176.0 backbone0-net.lux-net.com.ua - High
831 91.196.192.0 pool192-000.domashka.kiev.ua - High
832 91.196.228.0 0-228.196.91-nat.expres.net.ua - High
833 91.197.4.0 - - High
834 ... ... ... ...

There are 3333 more IOC items available. Please use our online service to access the data.

TTP - Tactics, Techniques, Procedures

Tactics, techniques, and procedures (TTP) summarize the suspected MITRE ATT&CK techniques used by Ukraine Unknown. This data is unique as it uses our predictive model for actor profiling.

ID Technique Weakness Description Confidence
1 T1006 CWE-21, CWE-22, CWE-23 Pathname Traversal High
2 T1040 CWE-294, CWE-319 Authentication Bypass by Capture-replay High
3 T1055 CWE-74 Injection High
4 T1059 CWE-88, CWE-94, CWE-1321 Cross Site Scripting High
5 T1059.007 CWE-79, CWE-80 Cross Site Scripting High
6 ... ... ... ...

There are 19 more TTP items available. Please use our online service to access the data.

IOA - Indicator of Attack

These indicators of attack (IOA) list the potential fragments used for technical activities like reconnaissance, exploitation, privilege escalation, and exfiltration by Ukraine Unknown. This data is unique as it uses our predictive model for actor profiling.

ID Type Indicator Confidence
1 File .github/workflows/combine-prs.yml High
2 File /admin.php/accessory/filesdel.html High
3 File /admin/?page=user/manage High
4 File /admin/add-new.php High
5 File /admin/cashadvance_row.php High
6 File /Admin/createClass.php High
7 File /admin/doctors.php High
8 File /admin/index2.html High
9 File /admin/maintenance/view_designation.php High
10 File /admin/userprofile.php High
11 File /adms/admin/?page=vehicles/sell_vehicle High
12 File /adms/admin/?page=vehicles/view_transaction High
13 File /alphaware/summary.php High
14 File /api/ Low
15 File /api/admin/store/product/list High
16 File /api/v2/cli/commands High
17 File /APR/login.php High
18 File /bin/httpd Medium
19 File /boat/login.php High
20 File /bsms_ci/index.php/book High
21 File /cgi-bin/wapopen High
22 File /cgi-bin/wlogin.cgi High
23 File /debug/pprof Medium
24 File /dev/block/mmcblk0rpmb High
25 File /forum/away.php High
26 File /fos/admin/ajax.php?action=login High
27 File /fos/admin/index.php?page=menu High
28 File /home/masterConsole High
29 File /home/sendBroadcast High
30 File /medicines/profile.php High
31 File /mygym/admin/index.php?view_exercises High
32 File /news/list?limit=10&offset=0&order=desc High
33 File /owa/auth/logon.aspx High
34 File /php-opos/index.php High
35 File /proxy Low
36 File /public/launchNewWindow.jsp High
37 File /reports/rwservlet High
38 File /reservation/add_message.php High
39 File /spip.php Medium
40 File /uncpath/ Medium
41 File /user/updatePwd High
42 File /vendor/htmlawed/htmlawed/htmLawedTest.php High
43 File /video-sharing-script/watch-video.php High
44 File /wireless/security.asp High
45 File /zm/index.php High
46 File 01article.php High
47 File AcquisiAction.class.php High
48 File activenews_view.asp High
49 File adclick.php Medium
50 File admin.a6mambocredits.php High
51 File admin.cropcanvas.php High
52 File admin.jcomments.php High
53 File admin/?page=reports&date_from=2023-02-17&date_to=2023-03-17 High
54 File admin/abc.php High
55 File admin/add_payment.php High
56 File admin/admin.php?action=users&mode=info&user=2 High
57 File admin/admin/adminsave.html High
58 File admin/ajax/op_kandidat.php High
59 ... ... ...

There are 517 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.

References

The following list contains external sources which discuss the actor and the associated activities:

Literature

The following articles explain our unique predictive cyber threat intelligence:

License

(c) 1997-2023 by vuldb.com. All data on this page is shared under the license CC BY-NC-SA 4.0. Questions? Check the FAQ, read the documentation or contact us!