cyber_threat_intelligence/actors/Romania Unknown
2023-06-06 10:26:07 +02:00
..
README.md Update June 2023 2023-06-06 10:26:07 +02:00

Romania Unknown - Cyber Threat Intelligence

These indicators were reported, collected, and generated during the VulDB CTI analysis of the actor known as Romania Unknown. The activity monitoring correlates data from social media, forums, chat rooms, and darknet markets. It helps to determine associated actors, specific activities, expected intentions, emerging research, and ongoing attacks. Our unique predictive model uses big data to forecast activities and their characteristics.

Live data and more analysis capabilities are available at https://vuldb.com/?actor.romania_unknown

Countries

These countries are directly (e.g. origin of attacks) or indirectly (e.g. access by proxy) associated with Romania Unknown:

There are 19 more country items available. Please use our online service to access the data.

IOC - Indicator of Compromise

These indicators of compromise (IOC) indicate associated network resources which are known to be part of research and attack activities of Romania Unknown.

ID IP address Hostname Campaign Confidence
1 2.17.116.0 a2-17-116-0.deploy.static.akamaitechnologies.com - High
2 2.20.96.0 a2-20-96-0.deploy.static.akamaitechnologies.com - High
3 2.56.44.0 - - High
4 2.56.48.0 - - High
5 2.56.148.0 - - High
6 2.56.166.0 - - High
7 2.57.120.0 - - High
8 2.57.144.0 - - High
9 2.58.128.0 - - High
10 2.59.8.0 - - High
11 2.59.10.0 - - High
12 2.59.12.0 - - High
13 5.2.128.0 static-5-2-128-0.rdsnet.ro - High
14 5.12.0.0 5-12-0-0.residential.rdsnet.ro - High
15 5.35.208.0 - - High
16 5.42.198.0 - - High
17 5.62.61.104 r-104-61-62-5.consumer-pool.prcdn.net - High
18 5.62.63.80 r-80-63-62-5.consumer-pool.prcdn.net - High
19 5.83.32.0 - - High
20 5.101.45.0 - - High
21 5.101.92.0 subnet.llhost-inc.com - High
22 5.104.158.0 - - High
23 5.104.159.0 - - High
24 5.154.170.0 - - High
25 5.154.171.0 - - High
26 5.154.172.0 - - High
27 5.154.175.0 - - High
28 5.154.176.0 - - High
29 5.154.180.0 - - High
30 5.154.185.0 - - High
31 5.154.186.0 - - High
32 5.154.190.0 - - High
33 5.154.224.0 - - High
34 5.154.226.0 host-5-154-226-0.zadata.de - High
35 5.154.230.0 host-5-154-230-0.zadata.de - High
36 5.154.233.0 - - High
37 5.154.234.0 - - High
38 5.154.236.0 - - High
39 5.154.239.0 - - High
40 5.154.241.0 - - High
41 5.154.243.0 - - High
42 5.154.252.0 - - High
43 5.157.19.0 undefined.hostname.localhost - High
44 5.157.26.0 undefined.hostname.localhost - High
45 5.157.128.0 - - High
46 5.157.132.0 mail4.pholdfarad.com - High
47 5.157.136.0 mx1.longboatshipping.com - High
48 5.157.137.0 - - High
49 5.157.138.0 - - High
50 5.157.140.0 - - High
51 5.157.144.0 - - High
52 5.157.160.0 - - High
53 5.157.176.0 - - High
54 5.157.192.0 - - High
55 5.157.208.0 mx1.havecornerwheel.com - High
56 5.157.216.0 mx3.gridslifemusic.com - High
57 5.157.224.0 - - High
58 5.157.240.0 - - High
59 5.180.76.8 rdns8.gmaigoosetongue.pw - High
60 5.180.76.13 rdns13.gmaigoosetongue.pw - High
61 5.180.76.193 reverse193.gmaigooserumped.pw - High
62 5.180.76.196 reverse196.gmaigooserumped.pw - High
63 5.180.77.5 scan5.gmaigoosenecked.pw - High
64 5.180.77.17 scan17.gmaigoosenecked.pw - High
65 5.180.77.181 la181.gmaigooseflower.pw - High
66 5.180.77.182 la182.gmaigooseflower.pw - High
67 5.180.156.0 - - High
68 5.181.25.0 subnet.gcore.lu - High
69 5.181.68.0 - - High
70 5.181.202.0 subnet.reserved.ispsystem.net - High
71 5.181.233.184 - - High
72 5.181.234.232 mx1.xafeyila.com - High
73 5.182.37.0 . - High
74 5.183.103.2 irb-0.agg1v.mad1.es.m247.com - High
75 5.183.103.130 irb-0.agg1v.mad1.es.m247.com - High
76 5.183.168.0 - - High
77 5.183.178.113 - - High
78 5.183.178.122 - - High
79 5.183.208.0 - - High
80 5.183.210.0 - - High
81 5.188.178.0 - - High
82 5.188.205.0 - - High
83 5.189.217.0 subnet.reserved.ispsystem.net - High
84 5.252.178.0 5-252-178-0.mivocloud.com - High
85 5.253.52.0 - - High
86 5.253.116.0 - - High
87 5.253.124.0 - - High
88 5.253.160.0 - - High
89 5.253.188.0 - - High
90 5.254.48.0 - - High
91 5.254.49.0 - - High
92 5.254.50.0 - - High
93 5.254.52.0 - - High
94 5.254.54.0 - - High
95 5.254.56.0 - - High
96 5.254.59.0 - - High
97 5.254.65.0 - - High
98 5.254.65.8 - - High
99 5.254.65.10 fra-in3-01rs.voxility.net - High
100 5.254.65.12 - - High
101 5.254.65.16 - - High
102 5.254.65.32 - - High
103 5.254.65.64 - - High
104 5.254.65.128 - - High
105 5.254.66.0 protected.javapipe.com - High
106 5.254.69.0 - - High
107 5.254.73.0 - - High
108 5.254.73.128 - - High
109 5.254.73.192 - - High
110 5.254.73.208 - - High
111 5.254.73.224 - - High
112 5.254.78.80 - - High
113 5.254.83.0 - - High
114 5.254.92.0 - - High
115 5.254.96.0 - - High
116 5.254.98.0 - - High
117 5.254.100.0 - - High
118 5.254.112.224 - - High
119 5.254.113.0 - - High
120 5.254.116.0 - - High
121 5.254.118.0 - - High
122 5.254.125.0 - - High
123 8.43.226.0 - - High
124 8.238.132.0 - - High
125 8.241.99.0 - - High
126 8.254.104.0 - - High
127 13.104.140.16 - - High
128 13.104.140.180 - - High
129 13.104.140.182 - - High
130 13.104.140.204 - - High
131 13.104.187.32 - - High
132 13.248.100.96 - - High
133 13.248.100.128 - - High
134 23.15.176.0 a23-15-176-0.deploy.static.akamaitechnologies.com - High
135 23.26.195.0 - - High
136 23.33.98.242 a23-33-98-242.deploy.static.akamaitechnologies.com - High
137 23.33.98.244 a23-33-98-244.deploy.static.akamaitechnologies.com - High
138 23.33.98.246 a23-33-98-246.deploy.static.akamaitechnologies.com - High
139 23.33.98.248 a23-33-98-248.deploy.static.akamaitechnologies.com - High
140 23.33.98.250 a23-33-98-250.deploy.static.akamaitechnologies.com - High
141 23.33.98.252 a23-33-98-252.deploy.static.akamaitechnologies.com - High
142 23.229.117.0 - - High
143 31.5.0.0 - - High
144 31.6.14.0 - - High
145 31.13.189.104 mx1.ellssomon.com - High
146 31.13.191.224 dominae224.colelan.com - High
147 31.14.8.0 - - High
148 31.14.10.0 - - High
149 31.14.12.0 0-namebox.ro - High
150 31.14.16.0 31.14.16.0.banat-net.ro - High
151 31.14.18.0 - - High
152 31.14.20.0 - - High
153 31.14.24.0 - - High
154 31.14.25.0 - - High
155 31.14.27.0 - - High
156 31.14.34.0 - - High
157 31.14.36.0 - - High
158 31.14.40.0 - - High
159 31.14.45.0 - - High
160 31.14.49.0 - - High
161 31.14.53.0 - - High
162 31.14.54.0 - - High
163 31.14.56.0 cw31-ad-ef0.romania-webhosting.com - High
164 31.14.64.0 - - High
165 31.14.65.0 - - High
166 31.14.68.0 - - High
167 31.14.100.0 - - High
168 31.14.102.0 - - High
169 31.14.104.0 - - High
170 31.14.160.0 - - High
171 31.14.163.0 - - High
172 31.14.192.0 - - High
173 31.14.196.0 - - High
174 31.14.199.0 - - High
175 31.14.218.0 - - High
176 31.14.220.0 - - High
177 31.14.224.0 - - High
178 31.14.232.0 - - High
179 31.14.236.0 - - High
180 31.14.239.0 - - High
181 31.14.252.0 no-rdns.clues.ro - High
182 31.14.254.0 - - High
183 31.25.10.0 - - High
184 31.40.224.0 - - High
185 31.42.128.0 - - High
186 31.46.19.0 - - High
187 31.46.44.0 - - High
188 31.47.208.0 - - High
189 31.130.240.0 - - High
190 31.131.8.0 - - High
191 31.131.12.0 no-rdns.appnicery.com - High
192 31.131.15.0 - - High
193 31.131.40.0 no-reverse.techno-blade.net - High
194 31.131.160.0 - - High
195 31.132.192.0 - - High
196 31.133.24.0 mx1.pancakecorn.com - High
197 31.133.28.0 - - High
198 31.133.192.0 - - High
199 31.135.0.0 - - High
200 31.135.3.0 - - High
201 31.193.188.0 - - High
202 31.210.18.0 - - High
203 31.220.128.0 - - High
204 32.112.58.0 - - High
205 32.112.163.74 - - High
206 32.112.163.82 - - High
207 32.112.166.46 - - High
208 34.99.178.0 0.178.99.34.bc.googleusercontent.com - Medium
209 34.99.250.0 0.250.99.34.bc.googleusercontent.com - Medium
210 34.103.194.0 0.194.103.34.bc.googleusercontent.com - Medium
211 34.103.242.0 0.242.103.34.bc.googleusercontent.com - Medium
212 37.19.193.134 unn-37-19-193-134.cdn77.com - High
213 37.35.32.0 - - High
214 37.35.38.0 - - High
215 37.35.44.0 - - High
216 37.35.48.0 mx1.holdfatemaritime.com - High
217 37.35.52.0 - - High
218 37.35.53.0 - - High
219 37.35.55.0 - - High
220 37.35.56.0 - - High
221 37.35.183.138 138.183.35.37.dynamic.jazztel.es - High
222 37.43.3.0 - - High
223 37.59.149.28 logs.nethink.com - High
224 37.97.112.0 - - High
225 37.97.120.0 - - High
226 37.97.121.0 - - High
227 37.97.122.0 - - High
228 37.120.129.0 - - High
229 37.120.138.160 mx1.celrustic.com - High
230 37.120.140.0 - - High
231 37.120.146.0 - - High
232 37.120.150.0 rfl0.rottenspite.us - High
233 37.120.157.0 - - High
234 37.120.157.88 - - High
235 37.120.202.40 - - High
236 37.120.202.56 - - High
237 37.120.202.64 - - High
238 37.120.206.0 - - High
239 37.120.214.0 - - High
240 37.120.214.8 - - High
241 37.120.214.28 - - High
242 37.120.216.216 emptum216.honshed.com - High
243 37.120.219.220 - - High
244 37.120.219.224 - - High
245 37.120.224.0 - - High
246 37.120.240.0 - - High
247 37.120.245.0 - - High
248 37.120.246.0 - - High
249 37.120.248.0 - - High
250 37.120.254.0 - - High
251 37.128.224.0 - - High
252 37.140.243.0 - - High
253 37.143.160.0 - - High
254 37.153.133.0 - - High
255 37.153.136.0 - - High
256 37.153.140.0 0.140.153.37.rev.aif.tel - High
257 37.153.152.0 - - High
258 37.153.158.0 - - High
259 37.153.159.0 - - High
260 37.156.4.0 - - High
261 37.156.7.0 - - High
262 37.156.32.0 - - High
263 37.156.35.0 - - High
264 37.156.36.0 - - High
265 37.156.67.0 - - High
266 37.156.68.0 - - High
267 37.156.71.0 - - High
268 37.156.172.0 - - High
269 37.156.174.0 37-156-174-0.virtualsolution.net - High
270 37.156.180.0 cw37-aef-ah00.romania-webhosting.com - High
271 37.156.224.0 - - High
272 37.156.227.0 - - High
273 37.156.244.0 network.mi.dc3.vhosting-it.com - High
274 37.156.245.0 - - High
275 37.221.112.34 - - High
276 37.221.112.42 - - High
277 37.221.112.46 - - High
278 37.221.160.0 - - High
279 37.221.160.128 - - High
280 37.221.160.192 - - High
281 37.221.160.224 - - High
282 37.221.160.240 - - High
283 37.221.160.242 - - High
284 37.221.160.244 - - High
285 37.221.160.246 - - High
286 37.221.160.248 - - High
287 37.221.160.250 - - High
288 37.221.160.252 - - High
289 37.221.160.254 - - High
290 37.221.161.0 - - High
291 37.221.162.0 - - High
292 37.221.164.0 - - High
293 37.221.168.0 - - High
294 37.221.170.0 - - High
295 37.228.128.0 - - High
296 37.233.1.253 37-233-1-253.starnet.md - High
297 37.233.1.254 37-233-1-254.starnet.md - High
298 37.251.128.0 - - High
299 37.251.160.0 - - High
300 37.251.192.0 - - High
301 37.251.208.0 - - High
302 37.251.248.0 - - High
303 38.95.108.185 dns185.talcumapp-dec.com - High
304 38.95.108.186 dns186.talcumapp-dec.com - High
305 38.95.110.12 - - High
306 38.95.110.88 - - High
307 38.95.110.176 - - High
308 38.95.110.185 - - High
309 38.95.110.186 - - High
310 38.95.111.64 - - High
311 38.95.111.72 mx2.thesavingshut.com - High
312 38.95.111.76 a41-60.smtp-out.us-west-1.everydaysavingsbenefits.com - High
313 38.95.111.78 a81-100.smtp-out.us-west-1.everydaysavingsbenefits.com - High
314 38.95.111.80 - - High
315 38.95.111.96 hssga96.curerm.com - High
316 38.104.127.28 - - High
317 38.132.96.96 mx1.azuredry.com - High
318 38.132.97.84 - - High
319 38.132.97.92 - - High
320 38.132.97.148 mx1.areclet.com - High
321 38.132.98.64 mx1.ronitaly.com - High
322 38.132.99.24 mx1.grisfull.com - High
323 38.132.99.112 - - High
324 38.132.100.0 mx1.lumagfic.com - High
325 38.132.100.24 mx1.boxspi.com - High
326 38.132.100.48 ext.misterpsplace.com - High
327 38.132.101.52 mx1.sangriaest.com - High
328 38.132.102.160 haec160.colelan.com - High
329 38.132.103.52 - - High
330 38.132.103.104 mx1.oldcolus.com - High
331 38.132.105.0 - - High
332 38.132.105.16 - - High
333 38.132.105.48 original48.gusitble.com - High
334 38.132.105.65 mta4.safetyglobespecials.com - High
335 38.132.105.66 mta5.safetyglobespecials.com - High
336 38.132.105.68 mta4.manualvenuedocs.com - High
337 38.132.105.72 mta6.accessvenuedocs.com - High
338 38.132.105.80 - - High
339 38.132.105.88 outbound2.geckoscorewatch.com - High
340 38.132.105.92 mx0a-0035d301.geckoscoreapprove.com - High
341 38.132.106.0 priv0.psyost.com - High
342 38.132.106.13 - - High
343 38.132.106.14 - - High
344 38.132.106.18 mta4.multidealz.com - High
345 38.132.106.20 app6.curateddealsforyou.com - High
346 38.132.106.24 app10.curateddealsforyou.com - High
347 38.132.106.28 app9.dealsmarvel.com - High
348 38.132.106.30 m225-206.theidealcar.com - High
349 38.132.107.136 mx1.wifdata.com - High
350 38.132.107.146 mta36.email2.winsomelife.com - High
351 38.132.107.148 mta37.email2.winsomelife.com - High
352 38.132.107.152 app9.merchandisesavings.com - High
353 38.132.107.156 mta.f.dealershut.com - High
354 38.132.107.158 mta.h.dealershut.com - High
355 38.132.107.160 mx1.sperost.com - High
356 38.132.108.4 - - High
357 38.132.108.176 mx1.glefarad.com - High
358 38.132.108.208 - - High
359 38.132.109.64 - - High
360 38.132.110.64 ptr64.floordeep.com - High
361 38.132.111.240 pupa240.gusitble.com - High
362 38.132.112.16 host16.uncelife.com - High
363 38.132.112.112 mx1.envbaned.com - High
364 38.132.112.114 mx3.envbaned.com - High
365 38.132.112.200 mx1.honssilk.com - High
366 38.132.112.204 mx1.mellowlong.com - High
367 38.132.112.207 mx4.mellowlong.com - High
368 38.132.113.36 domain11336.com - High
369 38.132.114.0 rev0.indgim.com - High
370 38.132.114.12 huiwa102.summerfan.eu - High
371 38.132.116.72 bystander.trucidolotro.com - High
372 38.132.118.50 - - High
373 38.132.125.146 - - High
374 38.200.176.0 38-200-176-0.hostinggreat.net - High
375 38.200.252.0 38-200-252-0.hostinggreat.net - High
376 38.201.0.0 - - High
377 38.201.128.0 - - High
378 38.202.52.0 - - High
379 38.202.172.0 echo0.extratier.com - High
380 38.203.0.0 38-203-0-0.telecom-web.com - High
381 38.203.132.0 - - High
382 38.203.136.0 - - High
383 38.203.144.0 - - High
384 38.203.160.0 - - High
385 38.203.192.0 38-203-192-0.telecom-web.com - High
386 38.204.0.0 38-204-0-0.cloud-sight.com - High
387 38.204.192.0 - - High
388 40.66.0.41 - - High
389 40.90.65.57 - - High
390 40.90.65.77 - - High
391 44.31.29.0 - - High
392 44.31.31.0 - - High
393 44.182.0.0 - - High
394 44.182.4.0 - - High
395 44.182.7.0 - - High
396 44.182.8.0 - - High
397 44.182.25.0 - - High
398 44.182.34.0 - - High
399 44.182.52.0 - - High
400 44.182.84.0 - - High
401 45.8.44.0 - - High
402 45.9.176.0 - - High
403 45.10.96.0 - - High
404 45.11.1.143 nyc01.gmaigoodmanship.pw - High
405 45.11.1.173 nyc02.gmaigoodmanship.pw - High
406 45.11.2.91 ch91.gmaigoodishness.pw - High
407 45.11.2.98 ch98.gmaigoodishness.pw - High
408 45.11.2.130 dallas130.digspacetylsalol.space - High
409 45.11.2.181 dallas181.digspacetylsalol.space - High
410 45.11.181.0 - - High
411 45.11.228.0 - - High
412 45.12.56.0 - - High
413 45.12.70.190 gall-preamble.alltieinc.com - High
414 45.12.71.190 - - High
415 45.12.240.0 45.12.240.0.g.network - High
416 45.13.36.0 - - High
417 45.13.136.0 - - High
418 45.13.176.0 - - High
419 45.13.212.0 - - High
420 45.14.56.0 - - High
421 45.14.100.0 - - High
422 45.14.148.0 o0.p40.mailjet.com - High
423 45.14.236.0 - - High
424 45.15.20.0 - - High
425 45.15.22.0 - - High
426 45.43.65.0 - - High
427 45.57.80.0 - - High
428 45.66.132.8 music08.xunivoltine.space - High
429 45.66.236.0 - - High
430 45.67.34.0 . - High
431 45.67.36.0 - - High
432 45.67.52.0 - - High
433 45.67.60.0 - - High
434 45.67.100.0 - - High
435 45.67.176.0 - - High
436 45.74.30.0 - - High
437 45.80.148.0 - - High
438 45.80.150.0 - - High
439 45.80.200.0 - - High
440 45.80.244.0 45.80.244.0.g.network - High
441 45.81.161.0 - - High
442 45.82.24.0 - - High
443 45.82.28.0 - - High
444 45.82.102.0 subnet.gcore.lu - High
445 45.83.56.0 45-83-56-0.virtualsolution.net - High
446 45.83.89.0 - - High
447 45.83.224.0 - - High
448 45.85.116.0 - - High
449 45.85.117.0 subnet.reserved.ispsystem.net - High
450 45.86.136.0 - - High
451 45.86.144.0 45-86-144-0.virtualsolution.net - High
452 45.86.220.0 - - High
453 45.86.240.0 - - High
454 45.86.241.0 - - High
455 45.86.242.0 - - High
456 45.87.120.0 undefined.hostname.localhost - High
457 45.87.121.0 - - High
458 45.87.122.0 - - High
459 45.87.168.0 - - High
460 45.88.41.99 tx99.digspacetylation.space - High
461 45.88.41.125 tx125.digspacetylation.space - High
462 45.88.41.132 hou132.digspacetylamine.space - High
463 45.88.41.135 hou135.digspacetylamine.space - High
464 45.88.42.139 horn-139.digonify.com - High
465 45.88.42.146 horn-double-146.digonify.com - High
466 45.88.43.18 bal18.digonious.com - High
467 45.88.43.28 bal28.digonious.com - High
468 45.88.43.132 no.rdns.yet.132.digonoid.com - High
469 45.88.43.137 no.rdns.yet.137.digonoid.com - High
470 45.88.100.0 - - High
471 45.88.172.0 - - High
472 45.89.164.0 - - High
473 45.89.173.0 - - High
474 45.89.175.0 - - High
475 45.90.128.0 - - High
476 45.90.140.0 - - High
477 45.91.4.0 wehost.ro - High
478 45.91.36.0 - - High
479 45.91.40.0 - - High
480 45.91.236.0 - - High
481 45.91.238.0 - - High
482 45.92.33.0 - - High
483 45.92.120.0 45.92.120.0.g.network - High
484 45.93.128.0 - - High
485 45.93.196.0 - - High
486 45.93.216.0 - - High
487 45.95.38.0 - - High
488 45.95.129.0 - - High
489 45.95.220.0 - - High
490 45.95.228.0 - - High
491 45.95.244.0 - - High
492 45.114.8.0 - - High
493 45.128.116.0 - - High
494 45.128.168.0 - - High
495 45.129.12.0 - - High
496 45.129.64.0 - - High
497 45.129.76.0 - - High
498 45.129.78.0 - - High
499 45.129.138.0 - - High
500 45.130.214.0 - - High
501 45.131.92.0 - - High
502 45.131.104.0 - - High
503 45.131.128.0 - - High
504 45.131.140.0 - - High
505 45.131.145.0 - - High
506 45.131.162.0 - - High
507 45.131.224.0 - - High
508 45.132.130.0 - - High
509 45.132.178.0 - - High
510 45.133.120.0 45.133.120.0.g.network - High
511 45.133.128.0 45.133.128.0.g.network - High
512 45.133.136.0 - - High
513 45.133.152.0 - - High
514 45.133.180.0 - - High
515 45.134.48.0 - - High
516 45.134.49.0 - - High
517 45.134.50.0 - - High
518 45.134.160.0 - - High
519 45.135.224.0 - - High
520 45.136.40.0 - - High
521 45.136.199.0 subnet.spec.ispiria.net - High
522 45.137.0.0 - - High
523 45.138.64.0 - - High
524 45.138.87.0 - - High
525 45.139.68.0 - - High
526 45.139.232.0 - - High
527 45.140.104.0 - - High
528 45.141.132.0 45.141.132.0.g.network - High
529 45.141.153.254 - - High
530 45.142.8.0 - - High
531 45.142.193.0 - - High
532 45.142.194.0 - - High
533 45.143.172.0 - - High
534 45.143.228.0 - - High
535 45.145.0.0 - - High
536 45.145.16.0 - - High
537 45.145.48.0 45.145.48.0.g.network - High
538 45.147.60.0 - - High
539 45.148.200.0 - - High
540 45.149.20.0 - - High
541 45.149.188.0 45.149.188.0.g.network - High
542 45.150.4.0 - - High
543 45.150.80.0 - - High
544 45.150.252.0 - - High
545 45.152.180.96 - - High
546 45.152.180.120 mx1.fryooo.com - High
547 45.152.232.0 45.152.232.0.g.network - High
548 45.153.88.0 s8-0.gazduirejocuri.ro - High
549 45.154.120.0 - - High
550 45.155.120.0 subnet.reserved.ispsystem.net - High
551 45.155.122.0 subnet.reserved.ispsystem.net - High
552 45.156.236.0 - - High
553 45.158.80.0 - - High
554 45.158.132.0 - - High
555 45.158.212.0 - - High
556 45.159.120.0 - - High
557 45.159.122.0 - - High
558 45.159.132.0 - - High
559 45.192.130.0 - - High
560 46.3.101.0 - - High
561 46.18.108.0 - - High
562 46.19.104.0 - - High
563 46.20.128.0 - - High
564 46.51.108.0 - - High
565 46.97.0.0 - - High
566 46.102.0.0 - - High
567 46.102.64.0 - - High
568 46.102.101.0 host-46-102-101-0.access.redder.net - High
569 46.102.103.1 - - High
570 46.102.104.0 46.102.104.0.gazduiresite.ro - High
571 46.102.108.0 - - High
572 46.102.118.0 - - High
573 46.102.144.0 - - High
574 46.102.153.0 - - High
575 46.102.155.0 - - High
576 46.102.156.0 - - High
577 46.102.168.0 - - High
578 46.102.173.0 - - High
579 46.102.175.0 - - High
580 46.102.180.0 - - High
581 46.102.190.0 - - High
582 46.102.191.0 0.191.102.46.ipv4.tvpost.ro - High
583 46.102.232.0 - - High
584 46.102.236.0 - - High
585 46.102.238.0 - - High
586 46.102.248.0 - - High
587 46.102.249.0 0-123-static.mxserver.ro - High
588 46.102.250.0 - - High
589 46.102.254.0 - - High
590 46.107.14.0 - - High
591 46.108.39.49 - - High
592 46.108.156.0 - - High
593 46.148.113.0 subnet.reserved.ispsystem.net - High
594 46.151.32.0 - - High
595 46.151.160.0 - - High
596 46.151.224.0 - - High
597 46.173.240.0 - - High
598 46.173.248.0 - - High
599 46.174.144.0 46.174.144.0.emag.ro - High
600 46.174.200.0 - - High
601 46.175.152.0 - - High
602 46.214.0.0 46-214-0-0.next-gen.ro - High
603 46.226.123.0 - - High
604 46.232.208.0 - - High
605 46.243.112.0 - - High
606 46.243.223.0 - - High
607 52.84.218.0 server-52-84-218-0.otp50.r.cloudfront.net - High
608 52.85.10.0 server-52-85-10-0.otp50.r.cloudfront.net - High
609 52.144.60.0 mx1.supercomputercommodity.com - High
610 54.192.232.0 server-54-192-232-0.otp50.r.cloudfront.net - High
611 54.230.156.0 server-54-230-156-0.otp50.r.cloudfront.net - High
612 54.230.232.0 server-54-230-232-0.otp50.r.cloudfront.net - High
613 54.239.195.0 server-54-239-195-0.otp50.r.cloudfront.net - High
614 57.90.176.0 - - High
615 57.90.177.0 - - High
616 57.90.177.16 - - High
617 57.90.177.24 - - High
618 57.90.177.30 - - High
619 57.90.177.32 - - High
620 57.90.177.64 - - High
621 57.90.177.128 - - High
622 57.90.178.0 - - High
623 57.90.180.0 - - High
624 57.90.184.0 - - High
625 62.3.28.0 - - High
626 62.4.114.0 - - High
627 62.67.16.216 - - High
628 62.68.91.0 - - High
629 62.68.93.0 - - High
630 62.106.92.0 - - High
631 62.121.64.0 - - High
632 62.133.45.0 - - High
633 62.140.26.0 - - High
634 62.140.26.128 - - High
635 62.140.26.192 - - High
636 62.140.26.208 - - High
637 62.140.26.224 - - High
638 62.140.27.0 - - High
639 62.140.27.64 - - High
640 62.140.27.96 - - High
641 62.140.27.112 - - High
642 62.140.27.124 - - High
643 62.140.27.128 - - High
644 62.179.154.0 - - High
645 62.179.160.50 - - High
646 62.179.160.58 - - High
647 62.186.77.64 - - High
648 62.186.102.224 - - High
649 62.187.218.0 - - High
650 62.216.64.0 - - High
651 62.217.39.181 - - High
652 62.217.192.0 - - High
653 62.217.208.0 - - High
654 62.217.212.0 - - High
655 62.217.213.0 - - High
656 62.217.213.128 - - High
657 62.217.213.144 - - High
658 62.217.213.147 - - High
659 62.217.213.148 - - High
660 62.217.213.152 - - High
661 62.217.213.160 - - High
662 62.217.213.192 - - High
663 62.217.214.0 - - High
664 62.217.216.0 - - High
665 62.217.224.0 - - High
666 62.231.64.0 62-231-64-0.rdsnet.ro - High
667 63.167.243.0 - - High
668 63.218.200.0 63-218-200-0.static.pccwglobal.net - High
669 63.218.200.32 - - High
670 63.218.200.36 - - High
671 63.218.200.40 - - High
672 63.218.200.44 - - High
673 63.218.200.48 - - High
674 63.218.200.52 - - High
675 63.218.200.56 - - High
676 63.218.200.64 - - High
677 63.218.200.70 ge0-0-1-9.var04.sof02.pccwbtn.net - High
678 63.218.200.72 - - High
679 63.218.200.80 - - High
680 63.218.200.96 - - High
681 63.218.200.128 - - High
682 64.43.64.0 - - High
683 64.43.66.0 - - High
684 64.43.68.0 mx1.lastponywoods.com - High
685 64.43.76.0 - - High
686 64.43.77.0 - - High
687 64.43.80.0 - - High
688 64.43.192.0 - - High
689 64.214.188.0 ns1648.ztomy.com - High
690 66.22.244.0 - - High
691 66.102.34.0 - - High
692 66.118.244.0 - - High
693 66.118.246.0 - - High
694 66.220.23.184 - - High
695 66.225.212.0 network - High
696 66.225.214.0 unknown.cachenetworks.com - High
697 69.4.94.48 48.94.4.69.in-addr.arpa - High
698 69.41.50.0 - - High
699 69.41.54.0 - - High
700 69.41.56.0 - - High
701 69.41.60.0 - - High
702 72.14.153.0 - - High
703 77.36.0.0 ip-77-36-0-0.gvm.ro - High
704 77.36.16.0 - - High
705 77.36.28.0 mx1.zirconiumalloy.com - High
706 77.36.32.0 mx1.seatonelights.com - High
707 77.36.48.0 mx1.celerybub.com - High
708 77.36.54.0 - - High
709 77.36.56.0 - - High
710 77.36.60.0 - - High
711 77.36.61.0 - - High
712 77.36.64.0 - - High
713 77.36.80.0 mx1.cartauntproducts.com - High
714 77.36.88.0 - - High
715 77.36.96.0 - - High
716 77.47.244.0 - - High
717 77.67.54.96 - - High
718 77.67.104.64 - - High
719 77.77.186.80 - - High
720 77.81.0.0 - - High
721 77.81.2.0 - - High
722 77.81.4.0 77.81.4.0.netromholding.ro - High
723 77.81.8.0 - - High
724 77.81.16.0 - - High
725 77.81.48.0 77.81.48.0.static.netlog.ro - High
726 77.81.64.0 - - High
727 77.81.66.0 - - High
728 77.81.68.0 - - High
729 77.81.72.0 - - High
730 77.81.74.0 - - High
731 77.81.87.0 - - High
732 77.81.88.0 - - High
733 77.81.92.0 - - High
734 77.81.97.0 unused.simoshop.ro - High
735 77.81.98.0 no-rdns.clues.ro - High
736 77.81.100.0 - - High
737 77.81.104.0 - - High
738 77.81.122.0 - - High
739 77.81.136.0 - - High
740 77.81.137.0 - - High
741 77.81.138.0 - - High
742 77.81.140.0 - - High
743 77.81.142.0 - - High
744 77.81.164.0 - - High
745 77.81.166.0 - - High
746 77.81.176.0 - - High
747 77.81.178.0 77.81.178.0.banat-net.ro - High
748 77.81.180.0 - - High
749 77.81.183.0 - - High
750 77.81.184.0 - - High
751 77.81.190.0 - - High
752 77.83.48.0 - - High
753 77.83.164.0 - - High
754 77.83.168.0 - - High
755 77.83.220.0 - - High
756 77.83.243.0 - - High
757 77.83.248.0 - - High
758 77.83.250.0 - - High
759 77.87.88.0 - - High
760 77.90.151.0 - - High
761 77.90.181.0 - - High
762 77.90.185.0 - - High
763 77.90.190.0 - - High
764 77.93.160.0 - - High
765 77.232.192.0 - - High
766 77.232.192.32 - - High
767 77.232.192.48 - - High
768 77.232.192.56 - - High
769 77.232.192.64 - - High
770 77.232.192.128 - - High
771 77.232.194.0 - - High
772 77.232.196.0 - - High
773 77.232.200.0 - - High
774 77.232.208.0 - - High
775 77.232.216.0 - - High
776 77.246.247.0 - - High
777 77.247.112.0 - - High
778 78.24.206.0 - - High
779 78.31.56.0 - - High
780 78.31.128.0 netcorr.com - High
781 78.31.164.0 - - High
782 78.96.0.0 - - High
783 78.108.217.0 - - High
784 78.138.2.0 - - High
785 78.140.68.0 - - High
786 79.110.21.0 - - High
787 79.110.23.0 - - High
788 79.110.26.0 - - High
789 79.110.52.0 - - High
790 79.110.53.56 - - High
791 79.110.54.80 - - High
792 79.112.0.0 79-112-0-000.iasi.fiberlink.ro - High
793 79.117.0.0 79-117-0-0.digimobil.es - High
794 79.118.0.0 79-118-0-0.rdsnet.ro - High
795 79.141.46.126 79.141.46.126.available.above.net - High
796 79.143.49.0 - - High
797 79.180.175.219 bzq-79-180-175-219.red.bezeqint.net - High
798 80.65.220.0 - - High
799 80.74.48.0 000-048-074-080.ip-addr.inexio.net - High
800 80.86.96.0 80-86-96.NET.iNES.RO - High
801 80.86.97.203 - - High
802 80.86.99.0 - - High
803 80.86.100.0 AuctionWatch-NET.iNES.RO - High
804 80.86.104.0 Dialup-Pool.iNES.RO - High
805 80.86.112.0 - - High
806 80.91.221.0 - - High
807 80.91.242.163 - - High
808 80.91.252.13 - - High
809 80.91.255.99 - - High
810 80.94.92.0 - - High
811 80.96.0.0 - - High
812 80.96.8.0 - - High
813 80.96.11.0 - - High
814 80.96.12.0 - - High
815 80.96.16.0 - - High
816 80.96.24.0 - - High
817 80.96.28.0 alfa.mediasat.ro - High
818 80.96.30.0 30-net.apnetwork.ro - High
819 80.96.32.0 - - High
820 80.96.40.0 - - High
821 80.96.46.0 - - High
822 80.96.48.0 - - High
823 80.96.52.0 80-96-52-0.rdsnet.ro - High
824 80.96.56.0 80-96-56-0.rdsnet.ro - High
825 80.96.64.0 subnet0-63.draculas.ro - High
826 80.96.96.0 - - High
827 80.96.100.0 - - High
828 80.96.104.0 ofdm-sg1-net3.dnttm.ro - High
829 80.96.112.0 - - High
830 80.96.128.0 - - High
831 80.96.144.0 - - High
832 80.96.152.0 gts.web365.ro - High
833 80.96.160.0 - - High
834 80.96.176.0 - - High
835 80.96.180.0 - - High
836 80.96.183.0 - - High
837 80.96.184.0 - - High
838 80.96.192.0 0.192.96.80.internio.net - High
839 80.96.224.0 - - High
840 80.96.240.0 - - High
841 80.96.248.0 - - High
842 80.96.250.0 - - High
843 80.96.251.0 - - High
844 80.96.251.4 - - High
845 80.96.251.6 - - High
846 80.96.251.8 - - High
847 80.96.251.16 - - High
848 80.96.251.32 - - High
849 80.96.251.64 - - High
850 80.96.251.128 - - High
851 80.96.252.0 - - High
852 80.97.0.0 - - High
853 80.97.32.0 - - High
854 80.97.43.0 - - High
855 80.97.48.0 - - High
856 80.97.60.0 - - High
857 80.97.64.0 - - High
858 80.97.98.0 - - High
859 80.97.100.0 - - High
860 80.97.104.0 - - High
861 80.97.112.0 - - High
862 80.97.128.0 - - High
863 80.208.254.0 - - High
864 80.209.254.0 - - High
865 80.231.72.0 - - High
866 80.231.208.0 if-be-5-100.ecore1.bu0-bucharest.as6453.net - High
867 80.231.208.32 - - High
868 80.231.208.38 ix-tengige-0-0-0-29-1-129.ecore1.bu0-bucharest.as6453.net - High
869 80.231.208.40 - - High
870 80.231.208.48 - - High
871 80.231.208.64 - - High
872 80.231.208.128 - - High
873 80.231.209.0 - - High
874 80.231.245.5 - - High
875 80.239.246.48 - - High
876 80.239.251.20 - - High
877 80.247.129.0 - - High
878 80.248.224.140 - - High
879 81.2.149.116 - - High
880 81.12.128.0 - - High
881 81.16.128.0 - - High
882 81.18.64.0 - - High
883 81.22.144.0 81-22-144-0.next-gen.ro - High
884 81.24.16.0 ip4-81-24-16-0.euroweb.ro - High
885 81.26.156.0 - - High
886 81.26.158.0 - - High
887 81.89.0.0 - - High
888 81.161.0.0 - - High
889 81.161.8.0 - - High
890 81.161.12.0 - - High
891 81.161.48.0 - - High
892 81.161.59.0 - - High
893 81.180.0.0 - - High
894 81.180.80.0 - - High
895 81.180.86.0 - - High
896 81.180.88.0 - - High
897 81.180.96.0 - - High
898 81.180.100.0 - - High
899 81.180.104.0 - - High
900 81.180.112.0 - - High
901 81.180.128.0 - - High
902 81.180.160.0 - - High
903 81.180.168.0 - - High
904 81.180.172.0 - - High
905 81.180.176.0 - - High
906 81.180.192.0 - - High
907 81.180.224.0 alfa.mediasat.ro - High
908 81.180.230.0 - - High
909 81.180.232.0 - - High
910 81.180.240.0 - - High
911 81.180.248.0 - - High
912 81.180.250.0 - - High
913 81.180.252.0 - - High
914 81.181.0.0 - - High
915 81.181.8.0 - - High
916 81.181.12.0 - - High
917 81.181.16.0 - - High
918 81.181.24.0 subnet0-63.24.181.81.in-addr.arpa - High
919 81.181.28.0 - - High
920 81.181.32.0 - - High
921 81.181.64.0 - - High
922 81.181.70.0 - - High
923 81.181.74.0 - - High
924 81.181.76.0 - - High
925 81.181.80.0 - - High
926 81.181.96.0 - - High
927 81.181.112.0 - - High
928 81.181.128.0 urusag-net.WaveNET.Ro - High
929 81.196.0.0 static-81-196-0-0.rdsnet.ro - High
930 81.196.16.0 81-196-16-0.rdsnet.ro - High
931 81.196.20.0 81-196-20-0.rdsnet.ro - High
932 81.196.21.0 81-196-21-0.rdsnet.ro - High
933 81.196.21.64 81-196-21-64.rdsnet.ro - High
934 81.196.21.96 81-196-21-96.rdsnet.ro - High
935 81.196.21.102 81-196-21-102.rdsnet.ro - High
936 81.196.21.104 81-196-21-104.rdsnet.ro - High
937 81.196.21.112 81-196-21-112.rdsnet.ro - High
938 81.196.21.128 81-196-21-128.rdsnet.ro - High
939 81.196.22.0 81-196-22-0.rdsnet.ro - High
940 81.196.24.0 81-196-24-0.rdsnet.ro - High
941 81.196.32.0 net-81.196.32.0-15.rdsnet.ro - High
942 81.196.64.0 static-81-196-64-0.rdsnet.ro - High
943 81.196.128.0 - - High
944 81.196.160.0 - - High
945 81.196.176.0 - - High
946 81.196.184.0 81-196-184-0.rdsnet.ro - High
947 81.196.186.0 81-196-186-0.rdsnet.ro - High
948 81.196.188.0 - - High
949 81.196.192.0 - - High
950 82.76.0.0 82-76-0-0.rdsnet.ro - High
951 82.102.30.138 - - High
952 82.102.30.142 - - High
953 82.102.31.136 - - High
954 82.137.0.0 82-137-0-0.rdsnet.ro - High
955 82.208.128.0 - - High
956 82.210.128.0 - - High
957 83.97.20.0 0.20.97.83.ro.ovo.sc - High
958 83.97.21.213 vlan2903.pe1.buc1.ro.m247.com - High
959 83.97.22.0 - - High
960 83.103.128.0 - - High
961 83.143.246.13 coats.ecotend.net - High
962 83.143.246.177 ten.askthepigeon.com - High
963 83.143.246.178 eleven.askthepigeon.com - High
964 83.143.246.217 - - High
965 83.143.246.218 - - High
966 83.150.236.0 route.microhost.pl - High
967 83.150.238.0 - - High
968 83.166.192.0 - - High
969 83.172.61.0 - - High
970 83.217.231.0 - - High
971 83.217.231.64 - - High
972 83.217.231.96 - - High
973 83.217.231.112 - - High
974 83.217.231.124 - - High
975 83.217.231.128 - - High
976 83.246.0.0 - - High
977 84.1.102.0 - - High
978 84.1.105.0 - - High
979 84.1.105.120 - - High
980 84.1.113.0 - - High
981 84.1.159.0 - - High
982 84.1.226.0 - - High
983 84.2.24.0 - - High
984 84.2.24.2 - - High
985 84.2.50.0 - - High
986 84.2.52.0 - - High
987 84.22.148.0 - - High
988 84.22.150.0 - - High
989 84.39.113.224 - - High
990 84.39.115.80 mx1.happyhappydancer.com - High
991 84.39.117.16 host16.quitequip.us - High
992 84.39.117.176 natus176.nickembew.com - High
993 84.41.113.0 - - High
994 84.47.132.0 - - High
995 84.47.146.0 - - High
996 84.47.154.0 - - High
997 84.47.166.0 - - High
998 84.47.179.0 - - High
999 84.47.184.0 - - High
1000 84.47.189.0 - - High
1001 84.54.34.0 - - High
1002 84.116.141.72 - - High
1003 84.116.141.80 - - High
1004 84.116.141.112 - - High
1005 84.116.141.128 - - High
1006 84.116.186.0 - - High
1007 84.116.187.0 - - High
1008 84.116.187.128 - - High
1009 84.116.187.132 - - High
1010 84.116.187.135 - - High
1011 84.116.187.136 - - High
1012 84.116.187.144 - - High
1013 84.116.187.160 - - High
1014 84.116.187.192 - - High
1015 84.116.216.0 - - High
1016 84.116.224.0 - - High
1017 84.116.226.0 - - High
1018 84.117.0.0 - - High
1019 84.232.128.0 84-232-128-0.dynamic.brasov.rdsnet.ro - High
1020 84.233.230.0 - - High
1021 84.234.96.0 - - High
1022 84.239.0.0 - - High
1023 84.239.16.0 - - High
1024 84.239.19.0 - - High
1025 84.239.20.0 - - High
1026 84.239.24.0 - - High
1027 84.239.32.0 - - High
1028 84.239.40.0 - - High
1029 84.239.44.0 - - High
1030 84.239.46.0 - - High
1031 84.239.47.0 - - High
1032 ... ... ... ...

There are 4126 more IOC items available. Please use our online service to access the data.

TTP - Tactics, Techniques, Procedures

Tactics, techniques, and procedures (TTP) summarize the suspected MITRE ATT&CK techniques used by Romania Unknown. This data is unique as it uses our predictive model for actor profiling.

ID Technique Weakness Description Confidence
1 T1006 CWE-21, CWE-22, CWE-23, CWE-36, CWE-37 Pathname Traversal High
2 T1040 CWE-319 Authentication Bypass by Capture-replay High
3 T1055 CWE-74 Injection High
4 T1059 CWE-88, CWE-94 Cross Site Scripting High
5 ... ... ... ...

There are 18 more TTP items available. Please use our online service to access the data.

IOA - Indicator of Attack

These indicators of attack (IOA) list the potential fragments used for technical activities like reconnaissance, exploitation, privilege escalation, and exfiltration by Romania Unknown. This data is unique as it uses our predictive model for actor profiling.

ID Type Indicator Confidence
1 File //WEB-INF Medium
2 File /?ajax-request=jnews High
3 File /?p=products Medium
4 File /about.php Medium
5 File /admin.php/accessory/filesdel.html High
6 File /admin.php/update/getFile.html High
7 File /admin/?page=user/manage High
8 File /admin/add-new.php High
9 File /admin/budget/manage_budget.php High
10 File /admin/cashadvance_row.php High
11 File /admin/doctors.php High
12 File /admin/edit_subject.php High
13 File /admin/inquiries/view_inquiry.php High
14 File /admin/maintenance/view_designation.php High
15 File /admin/products/manage_product.php High
16 File /admin/report/index.php High
17 File /admin/userprofile.php High
18 File /alphaware/summary.php High
19 File /api/ Low
20 File /api/admin/store/product/list High
21 File /api/stl/actions/search High
22 File /api/v2/cli/commands High
23 File /apply.cgi Medium
24 File /APR/login.php High
25 File /boat/login.php High
26 File /cgi-bin Medium
27 File /cgi-bin/wapopen High
28 File /cgi-bin/wlogin.cgi High
29 File /classes/Master.php?f=delete_service High
30 File /classes/Master.php?f=save_course High
31 File /debug/pprof Medium
32 File /dosen/data Medium
33 File /E-mobile/App/System/File/downfile.php High
34 File /edoc/doctor/patient.php High
35 File /feeds/post/publish High
36 File /forum/away.php High
37 File /inc/jquery/uploadify/uploadify.php High
38 File /inc/topBarNav.php High
39 File /index.php?app=main&func=passport&action=login High
40 File /index.php?page=category_list High
41 File /jurusan/data High
42 File /kelasdosen/data High
43 File /messageboard/view.php High
44 File /modules/projects/vw_files.php High
45 File /Moosikay/order.php High
46 File /opac/Actions.php?a=login High
47 File /osm/REGISTER.cmd High
48 File /PreviewHandler.ashx High
49 File /public/launchNewWindow.jsp High
50 File /reservation/add_message.php High
51 File /reviewer/system/system/admins/manage/users/user-update.php High
52 File /reviewer_0/admins/assessments/pretest/questions-view.php High
53 File /servlet/webacc High
54 File /spip.php Medium
55 File /textpattern/index.php High
56 File /user/updatePwd High
57 File /webroot/inc/utility_all.php High
58 File /wireless/security.asp High
59 File /wp-admin/admin-ajax.php High
60 File 20review.asp Medium
61 File a-forms.php Medium
62 File account.asp Medium
63 File AcquisiAction.class.php High
64 File activenews_view.asp High
65 File adclick.php Medium
66 File additem.asp Medium
67 File admin.a6mambocredits.php High
68 File admin.cropcanvas.php High
69 File admin.joomlaradiov5.php High
70 File admin.php Medium
71 File admin.php/index/upload because app/common/service/UploadService.php High
72 File admin.remository.php High
73 File admin/?page=students/view_student High
74 ... ... ...

There are 650 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.

References

The following list contains external sources which discuss the actor and the associated activities:

Literature

The following articles explain our unique predictive cyber threat intelligence:

License

(c) 1997-2023 by vuldb.com. All data on this page is shared under the license CC BY-NC-SA 4.0. Questions? Check the FAQ, read the documentation or contact us!