cyber_threat_intelligence/actors/Vietnam Unknown
2023-06-06 10:26:07 +02:00
..
README.md Update June 2023 2023-06-06 10:26:07 +02:00

Vietnam Unknown - Cyber Threat Intelligence

These indicators were reported, collected, and generated during the VulDB CTI analysis of the actor known as Vietnam Unknown. The activity monitoring correlates data from social media, forums, chat rooms, and darknet markets. It helps to determine associated actors, specific activities, expected intentions, emerging research, and ongoing attacks. Our unique predictive model uses big data to forecast activities and their characteristics.

Live data and more analysis capabilities are available at https://vuldb.com/?actor.vietnam_unknown

Countries

These countries are directly (e.g. origin of attacks) or indirectly (e.g. access by proxy) associated with Vietnam Unknown:

There are 11 more country items available. Please use our online service to access the data.

IOC - Indicator of Compromise

These indicators of compromise (IOC) indicate associated network resources which are known to be part of research and attack activities of Vietnam Unknown.

ID IP address Hostname Campaign Confidence
1 1.52.0.0 - - High
2 2.56.16.0 - - High
3 2.59.0.0 - - High
4 5.62.61.212 r-212-61-62-5.consumer-pool.prcdn.net - High
5 5.62.63.200 r-200-63-62-5.consumer-pool.prcdn.net - High
6 5.189.202.128 esxi1.prod.slkz - High
7 14.0.16.0 - - High
8 14.160.0.0 static.vnpt.vn - High
9 14.224.0.0 static.vnpt.vn - High
10 17.81.39.0 - - High
11 17.81.60.0 - - High
12 17.81.145.0 - - High
13 17.81.162.0 - - High
14 17.92.240.0 - - High
15 20.134.144.0 - - High
16 20.134.208.0 - - High
17 20.134.243.0 - - High
18 20.139.144.0 - - High
19 23.50.12.0 a23-50-12-0.deploy.static.akamaitechnologies.com - High
20 23.53.208.0 a23-53-208-0.deploy.static.akamaitechnologies.com - High
21 23.60.70.0 a23-60-70-0.deploy.static.akamaitechnologies.com - High
22 23.61.254.0 a23-61-254-0.deploy.static.akamaitechnologies.com - High
23 23.79.96.0 a23-79-96-0.deploy.static.akamaitechnologies.com - High
24 23.91.108.0 - - High
25 23.194.136.0 a23-194-136-0.deploy.static.akamaitechnologies.com - High
26 23.248.172.0 - - High
27 27.0.12.0 - - High
28 27.0.240.0 - - High
29 27.2.0.0 - - High
30 27.64.0.0 localhost - High
31 27.118.16.0 - - High
32 27.124.19.0 - - High
33 27.124.48.0 - - High
34 34.98.238.0 0.238.98.34.bc.googleusercontent.com - Medium
35 34.98.254.0 0.254.98.34.bc.googleusercontent.com - Medium
36 34.103.14.0 0.14.103.34.bc.googleusercontent.com - Medium
37 42.1.64.0 - - High
38 42.96.0.0 - - High
39 42.112.0.0 - - High
40 42.114.0.0 - - High
41 42.115.128.0 - - High
42 42.116.0.0 - - High
43 43.239.148.0 - - High
44 43.239.184.0 - - High
45 43.239.220.0 - - High
46 43.239.224.0 - - High
47 45.10.215.0 - - High
48 45.12.70.242 75-on-coward.globalhilive.com - High
49 45.12.71.242 - - High
50 45.95.128.0 - - High
51 45.117.76.0 - - High
52 45.117.80.0 - - High
53 45.117.156.0 45-117-156-0.bestcloudone.com - High
54 45.117.160.0 - - High
55 45.117.176.0 - - High
56 45.118.136.0 - - High
57 45.118.144.0 - - High
58 45.119.76.0 - - High
59 45.119.80.0 - - High
60 45.119.108.0 - - High
61 45.119.212.0 - - High
62 45.119.216.0 - - High
63 45.119.240.0 - - High
64 45.120.224.0 - - High
65 45.121.24.0 - - High
66 45.121.152.0 - - High
67 45.121.160.0 - - High
68 45.122.220.0 - - High
69 45.122.232.0 static.cmcti.vn - High
70 45.122.240.0 static.cmcti.vn - High
71 45.123.96.0 static-ptr.ehost.vn - High
72 45.124.84.0 - - High
73 45.124.88.0 - - High
74 45.125.200.0 - - High
75 45.125.208.0 - - High
76 45.125.236.0 - - High
77 45.126.92.0 - - High
78 45.126.96.0 - - High
79 45.127.252.0 - - High
80 45.140.65.0 - - High
81 45.150.61.0 - - High
82 45.152.225.0 - - High
83 45.154.161.0 - - High
84 45.251.112.0 - - High
85 45.252.240.0 - - High
86 45.252.248.0 - - High
87 45.254.32.0 - - High
88 46.36.200.211 - - High
89 46.36.200.212 - - High
90 47.89.102.0 - - High
91 49.156.52.0 - - High
92 49.213.64.0 - - High
93 49.236.208.0 - - High
94 49.246.128.0 pool-33.gds.vn - High
95 49.246.192.0 pool-97.gds.vn - High
96 57.72.68.0 - - High
97 57.93.80.0 - - High
98 58.84.0.0 - - High
99 58.186.0.0 - - High
100 59.152.47.192 - - High
101 59.153.212.0 - - High
102 59.153.216.0 - - High
103 59.153.224.0 - - High
104 61.11.224.0 - - High
105 61.14.232.0 no-ptr.123host.vn - High
106 61.28.224.0 - - High
107 63.222.104.0 - - High
108 68.234.45.0 host-68-234-45-0.static.sprious.com - High
109 101.36.102.0 - - High
110 101.53.0.0 - - High
111 101.96.12.0 - - High
112 101.96.64.0 - - High
113 101.99.0.0 static.cmcti.vn - High
114 103.1.200.0 - - High
115 103.1.208.0 - - High
116 103.1.236.0 - - High
117 103.2.220.0 - - High
118 103.2.224.0 - - High
119 103.3.244.0 - - High
120 103.3.248.0 - - High
121 103.4.128.0 - - High
122 103.5.30.0 - - High
123 103.5.204.0 - - High
124 103.5.208.0 - - High
125 103.7.36.0 - - High
126 103.7.40.0 - - High
127 103.7.172.0 - - High
128 103.7.174.0 - - High
129 103.7.177.0 static.duytan.edu.vn - High
130 103.7.196.0 - - High
131 103.8.13.0 - - High
132 103.9.0.0 - - High
133 103.9.76.0 - - High
134 103.9.80.0 - - High
135 103.9.156.0 - - High
136 103.9.196.0 static.cmcti.vn - High
137 103.9.200.0 - - High
138 103.9.208.0 - - High
139 103.10.44.0 - - High
140 103.10.88.0 - - High
141 103.10.212.0 - - High
142 103.11.172.0 - - High
143 103.12.104.0 - - High
144 103.13.76.0 - - High
145 103.15.48.0 - - High
146 103.16.0.0 - - High
147 103.17.88.0 - - High
148 103.17.197.0 - - High
149 103.17.236.0 - - High
150 103.18.4.0 - - High
151 103.18.176.0 - - High
152 103.19.96.0 - - High
153 103.19.164.0 - - High
154 103.19.220.0 - - High
155 103.20.144.0 - - High
156 103.21.120.0 - - High
157 103.21.148.0 - - High
158 103.23.144.0 - - High
159 103.23.156.0 - - High
160 103.24.244.0 - - High
161 103.26.252.0 103-26-252-xxx.pvi.com.vn - High
162 103.27.60.0 - - High
163 103.27.64.0 - - High
164 103.27.229.128 - - High
165 103.27.231.0 - - High
166 103.27.236.0 - - High
167 103.28.32.0 - - High
168 103.28.136.0 - - High
169 103.28.172.0 - - High
170 103.30.36.0 ip.bmsc.vn - High
171 103.31.120.0 - - High
172 103.35.64.0 - - High
173 103.37.28.0 - - High
174 103.37.32.0 - - High
175 103.38.136.0 - - High
176 103.39.92.0 - - High
177 103.39.96.0 - - High
178 103.42.56.0 ip.vnptcorp.com - High
179 103.45.228.0 - - High
180 103.45.232.0 - - High
181 ... ... ... ...

There are 719 more IOC items available. Please use our online service to access the data.

TTP - Tactics, Techniques, Procedures

Tactics, techniques, and procedures (TTP) summarize the suspected MITRE ATT&CK techniques used by Vietnam Unknown. This data is unique as it uses our predictive model for actor profiling.

ID Technique Weakness Description Confidence
1 T1006 CWE-21, CWE-22, CWE-23, CWE-25, CWE-29, CWE-36, CWE-37 Pathname Traversal High
2 T1040 CWE-319 Authentication Bypass by Capture-replay High
3 T1055 CWE-74 Injection High
4 T1059 CWE-88, CWE-94, CWE-1321 Cross Site Scripting High
5 T1059.007 CWE-79, CWE-80 Cross Site Scripting High
6 ... ... ... ...

There are 18 more TTP items available. Please use our online service to access the data.

IOA - Indicator of Attack

These indicators of attack (IOA) list the potential fragments used for technical activities like reconnaissance, exploitation, privilege escalation, and exfiltration by Vietnam Unknown. This data is unique as it uses our predictive model for actor profiling.

ID Type Indicator Confidence
1 File //proc/kcore Medium
2 File //WEB-INF Medium
3 File /about.php Medium
4 File /action/wirelessConnect High
5 File /admin.php/update/getFile.html High
6 File /admin/assign/assign.php High
7 File /admin/contacts/organizations/edit/2 High
8 File /admin/curriculum/view_curriculum.php High
9 File /admin/departments/view_department.php High
10 File /admin/service.php High
11 File /admin/user/manage_user.php High
12 File /admin/user/uploadImg High
13 File /api/user/password/sent-reset-email High
14 File /Application/Admin/Controller/ConfigController.class.php High
15 File /bin/login Medium
16 File /bsms_ci/index.php High
17 File /bsms_ci/index.php/user/edit_user/ High
18 File /cas/logout Medium
19 File /cgi-bin/upload_vpntar High
20 File /cgi-bin/wlogin.cgi High
21 File /classes/Master.php High
22 File /classes/Master.php?f=delete_item High
23 File /config/getuser High
24 File /Content/Template/root/reverse-shell.aspx High
25 File /debug/pprof Medium
26 File /E-mobile/App/System/File/downfile.php High
27 File /Electron/download High
28 File /feeds/post/publish High
29 File /forms/doLogin High
30 File /forum/away.php High
31 File /hrm/controller/employee.php High
32 File /hrm/employeeadd.php High
33 File /hrm/employeeview.php High
34 File /inc/jquery/uploadify/uploadify.php High
35 File /index.php?app=main&func=passport&action=login High
36 File /index.php?page=category_list High
37 File /login/index.php High
38 File /menu.html Medium
39 File /mims/login.php High
40 File /Moosikay/order.php High
41 File /opac/Actions.php?a=login High
42 File /out.php Medium
43 File /PreviewHandler.ashx High
44 File /proxy Low
45 File /reservation/add_message.php High
46 File /reviewer/system/system/admins/manage/users/user-update.php High
47 ... ... ...

There are 404 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.

References

The following list contains external sources which discuss the actor and the associated activities:

Literature

The following articles explain our unique predictive cyber threat intelligence:

License

(c) 1997-2023 by vuldb.com. All data on this page is shared under the license CC BY-NC-SA 4.0. Questions? Check the FAQ, read the documentation or contact us!