cyber_threat_intelligence/actors/Sliver
2023-08-01 08:06:09 +02:00
..
README.md Update August 2023 2023-08-01 08:06:09 +02:00

Sliver - Cyber Threat Intelligence

These indicators were reported, collected, and generated during the VulDB CTI analysis of the actor known as Sliver. The activity monitoring correlates data from social media, forums, chat rooms, and darknet markets. It helps to determine associated actors, specific activities, expected intentions, emerging research, and ongoing attacks. Our unique predictive model uses big data to forecast activities and their characteristics.

Live data and more analysis capabilities are available at https://vuldb.com/?actor.sliver

Countries

These countries are directly (e.g. origin of attacks) or indirectly (e.g. access by proxy) associated with Sliver:

There are 22 more country items available. Please use our online service to access the data.

IOC - Indicator of Compromise

These indicators of compromise (IOC) indicate associated network resources which are known to be part of research and attack activities of Sliver.

ID IP address Hostname Campaign Confidence
1 1.13.17.105 - - High
2 1.13.174.161 - - High
3 1.13.180.253 - - High
4 3.8.115.155 ec2-3-8-115-155.eu-west-2.compute.amazonaws.com - Medium
5 3.18.103.195 ec2-3-18-103-195.us-east-2.compute.amazonaws.com - Medium
6 3.68.73.20 ec2-3-68-73-20.eu-central-1.compute.amazonaws.com - Medium
7 3.70.227.81 ec2-3-70-227-81.eu-central-1.compute.amazonaws.com - Medium
8 3.80.71.248 ec2-3-80-71-248.compute-1.amazonaws.com - Medium
9 3.82.226.95 ec2-3-82-226-95.compute-1.amazonaws.com - Medium
10 3.85.22.130 ec2-3-85-22-130.compute-1.amazonaws.com - Medium
11 3.92.41.116 ec2-3-92-41-116.compute-1.amazonaws.com - Medium
12 3.93.154.104 ec2-3-93-154-104.compute-1.amazonaws.com - Medium
13 3.101.117.8 ec2-3-101-117-8.us-west-1.compute.amazonaws.com - Medium
14 3.104.54.39 ec2-3-104-54-39.ap-southeast-2.compute.amazonaws.com - Medium
15 3.128.135.199 ec2-3-128-135-199.us-east-2.compute.amazonaws.com - Medium
16 3.130.73.232 ec2-3-130-73-232.us-east-2.compute.amazonaws.com - Medium
17 3.134.102.71 ec2-3-134-102-71.us-east-2.compute.amazonaws.com - Medium
18 3.142.79.130 ec2-3-142-79-130.us-east-2.compute.amazonaws.com - Medium
19 3.235.153.136 ec2-3-235-153-136.compute-1.amazonaws.com - Medium
20 3.237.92.13 ec2-3-237-92-13.compute-1.amazonaws.com - Medium
21 3.238.195.247 ec2-3-238-195-247.compute-1.amazonaws.com - Medium
22 4.240.86.147 - - High
23 5.75.238.234 static.234.238.75.5.clients.your-server.de - High
24 5.178.2.76 - - High
25 5.188.34.63 monting10136.example.com - High
26 5.199.168.209 - - High
27 5.199.173.106 - - High
28 5.199.173.134 - - High
29 5.199.174.230 - - High
30 5.252.176.26 5-252-176-26.mivocloud.com - High
31 5.255.114.206 - - High
32 5.255.120.28 - - High
33 8.212.148.49 - - High
34 8.217.54.75 - - High
35 8.218.149.214 - - High
36 8.218.200.114 - - High
37 8.218.204.19 - - High
38 8.219.200.180 - - High
39 13.48.204.226 ec2-13-48-204-226.eu-north-1.compute.amazonaws.com - Medium
40 13.49.46.31 ec2-13-49-46-31.eu-north-1.compute.amazonaws.com - Medium
41 13.56.236.146 ec2-13-56-236-146.us-west-1.compute.amazonaws.com - Medium
42 13.115.21.133 ec2-13-115-21-133.ap-northeast-1.compute.amazonaws.com - Medium
43 13.229.251.52 ec2-13-229-251-52.ap-southeast-1.compute.amazonaws.com - Medium
44 13.236.149.120 ec2-13-236-149-120.ap-southeast-2.compute.amazonaws.com - Medium
45 13.238.218.206 ec2-13-238-218-206.ap-southeast-2.compute.amazonaws.com - Medium
46 14.1.29.189 - - High
47 18.140.228.104 ec2-18-140-228-104.ap-southeast-1.compute.amazonaws.com - Medium
48 18.159.62.29 ec2-18-159-62-29.eu-central-1.compute.amazonaws.com - Medium
49 18.163.80.92 ec2-18-163-80-92.ap-east-1.compute.amazonaws.com - Medium
50 18.234.7.23 ec2-18-234-7-23.compute-1.amazonaws.com - Medium
51 20.1.134.133 - - High
52 20.58.167.202 - - High
53 20.61.4.19 - - High
54 20.118.135.66 - - High
55 20.123.75.93 - - High
56 20.227.28.202 - - High
57 20.248.225.130 - - High
58 23.19.227.106 - - High
59 23.81.246.193 - - High
60 23.82.141.146 - - High
61 23.83.127.233 - - High
62 23.94.131.51 beikeet.com - High
63 23.94.200.202 ju7-ry.insulin-pumpers.org - High
64 23.95.44.80 23-95-44-80-host.colocrossing.com - High
65 23.105.193.194 cs.hax0x.win - High
66 23.224.135.138 - - High
67 23.224.135.139 - - High
68 23.224.135.140 - - High
69 23.224.135.141 - - High
70 23.224.135.142 - - High
71 23.234.199.141 141-199-234-23-dedicated.multacom.com - High
72 23.239.30.17 23-239-30-17.ip.linodeusercontent.com - High
73 31.41.44.19 huotovich.maks.example.com - High
74 34.105.151.117 117.151.105.34.bc.googleusercontent.com - Medium
75 34.136.159.101 101.159.136.34.bc.googleusercontent.com - Medium
76 34.150.49.203 203.49.150.34.bc.googleusercontent.com - Medium
77 34.162.188.150 150.188.162.34.bc.googleusercontent.com - Medium
78 34.171.81.60 60.81.171.34.bc.googleusercontent.com - Medium
79 34.176.0.227 227.0.176.34.bc.googleusercontent.com - Medium
80 34.201.98.138 ec2-34-201-98-138.compute-1.amazonaws.com - Medium
81 34.212.32.244 ec2-34-212-32-244.us-west-2.compute.amazonaws.com - Medium
82 34.221.238.130 ec2-34-221-238-130.us-west-2.compute.amazonaws.com - Medium
83 35.72.242.198 ec2-35-72-242-198.ap-northeast-1.compute.amazonaws.com - Medium
84 35.167.111.43 ec2-35-167-111-43.us-west-2.compute.amazonaws.com - Medium
85 35.180.5.225 ec2-35-180-5-225.eu-west-3.compute.amazonaws.com - Medium
86 35.180.135.137 ec2-35-180-135-137.eu-west-3.compute.amazonaws.com - Medium
87 35.225.60.206 206.60.225.35.bc.googleusercontent.com - Medium
88 35.236.117.76 76.117.236.35.bc.googleusercontent.com - Medium
89 35.240.171.140 140.171.240.35.bc.googleusercontent.com - Medium
90 37.10.71.215 pewna-kamagra.pl - High
91 37.27.17.204 static.204.17.27.37.clients.your-server.de - High
92 37.28.157.7 d157007.artnet.gda.pl - High
93 37.48.120.35 - - High
94 37.120.238.184 - - High
95 37.187.123.146 ns332345.ip-37-187-123.eu - High
96 37.235.49.25 ns2.test-ipv6.is - High
97 38.55.24.35 - - High
98 38.55.97.95 - - High
99 39.98.48.67 - - High
100 42.194.137.196 - - High
101 43.133.22.89 - - High
102 43.137.3.222 - - High
103 43.137.17.156 - - High
104 43.138.196.138 - - High
105 43.142.109.133 - - High
106 43.153.101.130 - - High
107 43.154.223.31 - - High
108 43.156.59.135 - - High
109 43.207.147.229 ec2-43-207-147-229.ap-northeast-1.compute.amazonaws.com - Medium
110 43.248.136.99 - - High
111 44.202.249.7 ec2-44-202-249-7.compute-1.amazonaws.com - Medium
112 44.211.101.170 ec2-44-211-101-170.compute-1.amazonaws.com - Medium
113 45.8.146.160 vm1125144.stark-industries.solutions - High
114 45.8.157.45 super-links777.com - High
115 45.9.148.64 - - High
116 45.9.148.212 - - High
117 45.9.148.252 - - High
118 45.9.150.109 - - High
119 45.9.150.132 - - High
120 45.14.224.102 hosted-by.spectraip.net - High
121 45.32.233.220 45.32.233.220.vultrusercontent.com - High
122 45.56.113.227 45-56-113-227.ip.linodeusercontent.com - High
123 45.56.114.203 45-56-114-203.ip.linodeusercontent.com - High
124 45.61.136.196 - - High
125 45.61.137.59 - - High
126 ... ... ... ...

There are 500 more IOC items available. Please use our online service to access the data.

TTP - Tactics, Techniques, Procedures

Tactics, techniques, and procedures (TTP) summarize the suspected MITRE ATT&CK techniques used by Sliver. This data is unique as it uses our predictive model for actor profiling.

ID Technique Weakness Description Confidence
1 T1006 CWE-21, CWE-22, CWE-23 Pathname Traversal High
2 T1040 CWE-294, CWE-319 Authentication Bypass by Capture-replay High
3 T1055 CWE-74 Injection High
4 T1059 CWE-88, CWE-94 Cross Site Scripting High
5 T1059.007 CWE-79, CWE-80 Cross Site Scripting High
6 ... ... ... ...

There are 18 more TTP items available. Please use our online service to access the data.

IOA - Indicator of Attack

These indicators of attack (IOA) list the potential fragments used for technical activities like reconnaissance, exploitation, privilege escalation, and exfiltration by Sliver. This data is unique as it uses our predictive model for actor profiling.

ID Type Indicator Confidence
1 File //WEB-INF Medium
2 File /about.php Medium
3 File /admin.php/update/getFile.html High
4 File /admin/cashadvance_row.php High
5 File /admin/maintenance/view_designation.php High
6 File /admin/sys_sql_query.php High
7 File /admin/userprofile.php High
8 File /api/baskets/{name} High
9 File /APR/login.php High
10 File /cgi-bin/wapopen High
11 File /College/admin/teacher.php High
12 File /company/store High
13 File /Controller/Ajaxfileupload.ashx High
14 File /Controls/Generic/EBMK/Handlers/EStatements/DownloadEStatement.ashx High
15 File /dcim/rack-roles/ High
16 File /en/blog-comment-4 High
17 File /feeds/post/publish High
18 File /forms/doLogin High
19 File /forum/away.php High
20 File /goform/aspForm High
21 File /h/ Low
22 File /inc/jquery/uploadify/uploadify.php High
23 File /inc/topBarNav.php High
24 File /index.php Medium
25 File /index.php?app=main&func=passport&action=login High
26 File /index.php?page=category_list High
27 File /jobinfo/ Medium
28 File /kelas/data Medium
29 File /Moosikay/order.php High
30 File /opac/Actions.php?a=login High
31 File /opt/zimbra/jetty/webapps/zimbra/public High
32 File /PreviewHandler.ashx High
33 File /public/launchNewWindow.jsp High
34 File /recipe-result High
35 File /reservation/add_message.php High
36 File /rom-0 Low
37 File /Service/ImageStationDataService.asmx High
38 File /ServletAPI/accounts/login High
39 File /student/bookdetails.php High
40 File /uploads/exam_question/ High
41 File /user/profile High
42 File /user/ticket/create High
43 File /user/updatePwd High
44 File /var/lib/docker/<remapping> High
45 File /wp-admin/admin-ajax.php High
46 File /wp-content/plugins/woocommerce/templates/emails/plain/ High
47 File a-forms.php Medium
48 File acloudCosAction.php.SQL High
49 File activenews_view.asp High
50 File ActiveServices.java High
51 ... ... ...

There are 444 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.

References

The following list contains external sources which discuss the actor and the associated activities:

Literature

The following articles explain our unique predictive cyber threat intelligence:

License

(c) 1997-2023 by vuldb.com. All data on this page is shared under the license CC BY-NC-SA 4.0. Questions? Check the FAQ, read the documentation or contact us!