cyber_threat_intelligence/actors/Republic of Korea Unknown
2023-03-14 21:25:30 +01:00
..
README.md Update March 2023 2023-03-14 21:25:30 +01:00

Republic of Korea Unknown - Cyber Threat Intelligence

These indicators were reported, collected, and generated during the VulDB CTI analysis of the actor known as Republic of Korea Unknown. The activity monitoring correlates data from social media, forums, chat rooms, and darknet markets. It helps to determine associated actors, specific activities, expected intentions, emerging research, and ongoing attacks. Our unique predictive model uses big data to forecast activities and their characteristics.

Live data and more analysis capabilities are available at https://vuldb.com/?actor.republic_of_korea_unknown

Countries

These countries are directly (e.g. origin of attacks) or indirectly (e.g. access by proxy) associated with Republic of Korea Unknown:

There are 21 more country items available. Please use our online service to access the data.

IOC - Indicator of Compromise

These indicators of compromise (IOC) indicate associated network resources which are known to be part of research and attack activities of Republic of Korea Unknown.

ID IP address Hostname Campaign Confidence
1 1.11.0.0 - - High
2 1.16.0.0 - - High
3 1.18.116.0 - - High
4 1.18.120.0 - - High
5 1.18.128.0 - - High
6 1.19.0.0 - - High
7 1.32.216.0 - - High
8 1.32.220.0 - - High
9 1.32.222.0 - - High
10 1.96.0.0 - - High
11 1.176.0.0 - - High
12 1.201.0.0 - - High
13 1.208.0.0 - - High
14 1.224.0.0 - - High
15 2.57.255.0 - - High
16 2.59.153.0 - - High
17 3.5.140.0 - - High
18 3.5.144.0 - - High
19 3.34.0.0 ec2-3-34-0-0.ap-northeast-2.compute.amazonaws.com - Medium
20 3.34.128.0 ec2-3-34-128-0.ap-northeast-2.compute.amazonaws.com - Medium
21 3.34.192.0 ec2-3-34-192-0.ap-northeast-2.compute.amazonaws.com - Medium
22 3.34.224.0 ec2-3-34-224-0.ap-northeast-2.compute.amazonaws.com - Medium
23 3.34.229.0 ec2-3-34-229-0.ap-northeast-2.compute.amazonaws.com - Medium
24 3.34.230.0 ec2-3-34-230-0.ap-northeast-2.compute.amazonaws.com - Medium
25 3.34.232.0 ec2-3-34-232-0.ap-northeast-2.compute.amazonaws.com - Medium
26 3.34.240.0 ec2-3-34-240-0.ap-northeast-2.compute.amazonaws.com - Medium
27 3.35.0.0 ec2-3-35-0-0.ap-northeast-2.compute.amazonaws.com - Medium
28 3.36.0.0 ec2-3-36-0-0.ap-northeast-2.compute.amazonaws.com - Medium
29 3.36.128.0 ec2-3-36-128-0.ap-northeast-2.compute.amazonaws.com - Medium
30 3.36.192.0 ec2-3-36-192-0.ap-northeast-2.compute.amazonaws.com - Medium
31 3.36.200.0 ec2-3-36-200-0.ap-northeast-2.compute.amazonaws.com - Medium
32 3.36.203.0 ec2-3-36-203-0.ap-northeast-2.compute.amazonaws.com - Medium
33 3.36.204.0 ec2-3-36-204-0.ap-northeast-2.compute.amazonaws.com - Medium
34 3.36.208.0 ec2-3-36-208-0.ap-northeast-2.compute.amazonaws.com - Medium
35 3.36.224.0 ec2-3-36-224-0.ap-northeast-2.compute.amazonaws.com - Medium
36 3.37.0.0 ec2-3-37-0-0.ap-northeast-2.compute.amazonaws.com - Medium
37 3.38.0.0 ec2-3-38-0-0.ap-northeast-2.compute.amazonaws.com - Medium
38 8.38.149.0 - - High
39 13.33.188.0 server-13-33-188-0.icn55.r.cloudfront.net - High
40 13.104.47.0 - - High
41 13.104.56.0 - - High
42 13.104.60.0 - - High
43 13.104.62.0 - - High
44 13.105.20.0 - - High
45 13.106.90.0 - - High
46 13.106.92.0 - - High
47 13.106.224.0 - - High
48 13.107.209.0 - - High
49 13.124.0.0 ec2-13-124-0-0.ap-northeast-2.compute.amazonaws.com - Medium
50 13.209.0.0 ec2-13-209-0-0.ap-northeast-2.compute.amazonaws.com - Medium
51 13.209.2.0 ec2-13-209-2-0.ap-northeast-2.compute.amazonaws.com - Medium
52 13.209.4.0 ec2-13-209-4-0.ap-northeast-2.compute.amazonaws.com - Medium
53 13.209.8.0 ec2-13-209-8-0.ap-northeast-2.compute.amazonaws.com - Medium
54 13.209.16.0 ec2-13-209-16-0.ap-northeast-2.compute.amazonaws.com - Medium
55 13.209.32.0 ec2-13-209-32-0.ap-northeast-2.compute.amazonaws.com - Medium
56 13.209.64.0 ec2-13-209-64-0.ap-northeast-2.compute.amazonaws.com - Medium
57 13.209.128.0 ec2-13-209-128-0.ap-northeast-2.compute.amazonaws.com - Medium
58 13.225.105.0 server-13-225-105-0.icn54.r.cloudfront.net - High
59 13.225.106.0 server-13-225-106-0.icn54.r.cloudfront.net - High
60 13.225.108.0 server-13-225-108-0.icn54.r.cloudfront.net - High
61 13.225.112.0 server-13-225-112-0.icn54.r.cloudfront.net - High
62 13.225.128.0 server-13-225-128-0.icn54.r.cloudfront.net - High
63 13.225.136.0 server-13-225-136-0.icn54.r.cloudfront.net - High
64 14.0.32.0 - - High
65 14.0.64.0 - - High
66 14.4.0.0 - - High
67 14.32.0.0 - - High
68 14.64.0.0 - - High
69 14.128.48.0 - - High
70 14.128.51.0 - - High
71 14.128.52.0 - - High
72 14.128.54.0 - - High
73 14.128.128.0 - - High
74 14.129.0.0 - - High
75 14.138.0.0 - - High
76 14.192.80.0 - - High
77 14.206.0.0 - - High
78 15.164.0.0 ec2-15-164-0-0.ap-northeast-2.compute.amazonaws.com - Medium
79 15.164.128.0 ec2-15-164-128-0.ap-northeast-2.compute.amazonaws.com - Medium
80 15.164.192.0 ec2-15-164-192-0.ap-northeast-2.compute.amazonaws.com - Medium
81 15.164.224.0 ec2-15-164-224-0.ap-northeast-2.compute.amazonaws.com - Medium
82 15.164.240.0 ec2-15-164-240-0.ap-northeast-2.compute.amazonaws.com - Medium
83 15.164.242.0 ec2-15-164-242-0.ap-northeast-2.compute.amazonaws.com - Medium
84 15.164.244.0 ec2-15-164-244-0.ap-northeast-2.compute.amazonaws.com - Medium
85 15.164.248.0 ec2-15-164-248-0.ap-northeast-2.compute.amazonaws.com - Medium
86 15.165.0.0 ec2-15-165-0-0.ap-northeast-2.compute.amazonaws.com - Medium
87 15.177.76.0 - - High
88 15.193.9.0 ec2-15-193-9-0.ap-northeast-2.compute.amazonaws.com - Medium
89 15.230.60.0 - - High
90 15.230.81.0 - - High
91 15.230.196.0 - - High
92 15.248.36.0 - - High
93 17.91.200.0 - - High
94 17.92.0.0 - - High
95 17.92.8.0 - - High
96 17.253.114.0 - - High
97 20.39.168.0 - - High
98 20.39.184.0 - - High
99 20.39.192.0 - - High
100 20.41.64.0 - - High
101 20.44.24.0 - - High
102 20.47.46.0 - - High
103 20.47.90.0 - - High
104 20.60.16.0 - - High
105 20.60.200.0 - - High
106 20.135.26.0 - - High
107 20.135.30.0 - - High
108 20.135.108.0 - - High
109 20.135.112.0 - - High
110 20.150.4.0 - - High
111 20.150.14.0 - - High
112 20.157.137.0 - - High
113 20.157.140.0 - - High
114 20.190.148.0 - - High
115 20.190.179.0 - - High
116 20.190.180.0 - - High
117 20.194.0.0 - - High
118 20.194.64.0 - - High
119 20.194.80.0 - - High
120 20.194.96.0 - - High
121 20.196.64.0 - - High
122 20.196.128.0 - - High
123 20.200.128.0 - - High
124 20.202.40.0 - - High
125 23.12.224.0 a23-12-224-0.deploy.static.akamaitechnologies.com - High
126 23.15.13.0 a23-15-13-0.deploy.static.akamaitechnologies.com - High
127 23.32.56.0 a23-32-56-0.deploy.static.akamaitechnologies.com - High
128 23.33.120.0 a23-33-120-0.deploy.static.akamaitechnologies.com - High
129 23.33.144.0 a23-33-144-0.deploy.static.akamaitechnologies.com - High
130 23.35.218.0 a23-35-218-0.deploy.static.akamaitechnologies.com - High
131 23.35.220.0 a23-35-220-0.deploy.static.akamaitechnologies.com - High
132 23.40.44.0 a23-40-44-0.deploy.static.akamaitechnologies.com - High
133 23.43.0.0 a23-43-0-0.deploy.static.akamaitechnologies.com - High
134 23.43.165.0 a23-43-165-0.deploy.static.akamaitechnologies.com - High
135 23.44.173.0 a23-44-173-0.deploy.static.akamaitechnologies.com - High
136 23.46.22.0 a23-46-22-0.deploy.static.akamaitechnologies.com - High
137 23.49.48.0 a23-49-48-0.deploy.static.akamaitechnologies.com - High
138 23.49.144.0 a23-49-144-0.deploy.static.akamaitechnologies.com - High
139 23.50.0.0 a23-50-0-0.deploy.static.akamaitechnologies.com - High
140 23.51.28.0 a23-51-28-0.deploy.static.akamaitechnologies.com - High
141 23.53.2.0 a23-53-2-0.deploy.static.akamaitechnologies.com - High
142 23.53.32.0 a23-53-32-0.deploy.static.akamaitechnologies.com - High
143 23.53.36.0 a23-53-36-0.deploy.static.akamaitechnologies.com - High
144 23.53.224.0 a23-53-224-0.deploy.static.akamaitechnologies.com - High
145 23.53.228.0 a23-53-228-0.deploy.static.akamaitechnologies.com - High
146 23.58.88.0 a23-58-88-0.deploy.static.akamaitechnologies.com - High
147 23.59.72.0 a23-59-72-0.deploy.static.akamaitechnologies.com - High
148 23.59.151.0 a23-59-151-0.deploy.static.akamaitechnologies.com - High
149 23.61.64.0 a23-61-64-0.deploy.static.akamaitechnologies.com - High
150 23.62.183.0 a23-62-183-0.deploy.static.akamaitechnologies.com - High
151 23.62.232.0 a23-62-232-0.deploy.static.akamaitechnologies.com - High
152 23.65.48.0 a23-65-48-0.deploy.static.akamaitechnologies.com - High
153 23.65.188.0 a23-65-188-0.deploy.static.akamaitechnologies.com - High
154 23.67.53.0 a23-67-53-0.deploy.static.akamaitechnologies.com - High
155 23.74.16.0 a23-74-16-0.deploy.static.akamaitechnologies.com - High
156 23.76.153.0 a23-76-153-0.deploy.static.akamaitechnologies.com - High
157 23.79.245.0 a23-79-245-0.deploy.static.akamaitechnologies.com - High
158 23.194.214.0 a23-194-214-0.deploy.static.akamaitechnologies.com - High
159 23.195.106.0 a23-195-106-0.deploy.static.akamaitechnologies.com - High
160 23.197.54.0 a23-197-54-0.deploy.static.akamaitechnologies.com - High
161 23.197.160.0 a23-197-160-0.deploy.static.akamaitechnologies.com - High
162 23.200.75.0 a23-200-75-0.deploy.static.akamaitechnologies.com - High
163 23.201.35.0 a23-201-35-0.deploy.static.akamaitechnologies.com - High
164 23.201.36.0 a23-201-36-0.deploy.static.akamaitechnologies.com - High
165 23.203.175.0 a23-203-175-0.deploy.static.akamaitechnologies.com - High
166 23.204.116.0 a23-204-116-0.deploy.static.akamaitechnologies.com - High
167 23.206.175.0 a23-206-175-0.deploy.static.akamaitechnologies.com - High
168 23.207.200.0 lo0.r01.border101.den01.fab.netarch.akamai.com - High
169 23.211.117.0 a23-211-117-0.deploy.static.akamaitechnologies.com - High
170 23.212.12.0 a23-212-12-0.deploy.static.akamaitechnologies.com - High
171 23.213.13.0 a23-213-13-0.deploy.static.akamaitechnologies.com - High
172 23.216.159.0 a23-216-159-0.deploy.static.akamaitechnologies.com - High
173 23.238.168.0 - - High
174 23.248.160.0 - - High
175 23.251.224.0 - - High
176 27.0.236.0 - - High
177 27.1.0.0 - - High
178 27.35.0.0 - - High
179 27.96.128.0 - - High
180 27.100.128.0 - - High
181 27.101.0.0 - - High
182 27.102.0.0 - - High
183 27.111.96.0 - - High
184 27.112.128.0 - - High
185 27.113.0.0 - - High
186 27.115.128.0 - - High
187 27.116.64.0 - - High
188 27.116.128.0 - - High
189 27.117.0.0 - - High
190 27.118.64.0 - - High
191 27.118.128.0 - - High
192 27.119.0.0 - - High
193 27.120.0.0 - - High
194 27.122.128.0 - - High
195 27.124.8.0 - - High
196 27.124.128.0 - - High
197 27.125.0.0 - - High
198 27.126.0.0 - - High
199 27.160.0.0 - - High
200 27.176.0.0 - - High
201 27.232.0.0 - - High
202 27.255.64.0 - - High
203 31.13.76.0 - - High
204 34.64.0.0 - - High
205 34.64.2.0 - - High
206 34.64.64.0 0.64.64.34.bc.googleusercontent.com - Medium
207 34.64.128.0 0.128.64.34.bc.googleusercontent.com - Medium
208 34.98.164.0 0.164.98.34.bc.googleusercontent.com - Medium
209 34.98.174.0 0.174.98.34.bc.googleusercontent.com - Medium
210 35.216.0.0 0.0.216.35.bc.googleusercontent.com - Medium
211 36.38.0.0 - - High
212 37.252.244.0 - - High
213 39.4.0.0 - - High
214 39.16.0.0 - - High
215 39.109.91.0 - - High
216 39.112.0.0 - - High
217 40.66.92.0 - - High
218 40.69.232.0 - - High
219 40.79.220.0 - - High
220 40.80.32.0 - - High
221 40.80.168.0 koreasouth03.rnm.core.windows.net - High
222 40.80.224.0 - - High
223 40.82.128.0 - - High
224 40.89.192.0 - - High
225 40.92.52.0 - - High
226 40.92.84.0 - - High
227 40.92.242.0 - - High
228 40.92.254.0 - - High
229 40.94.32.0 - - High
230 40.94.233.0 - - High
231 40.94.234.0 - - High
232 40.94.241.0 - - High
233 40.94.242.0 - - High
234 40.94.244.0 - - High
235 40.94.246.0 - - High
236 40.94.254.0 - - High
237 40.95.53.0 - - High
238 40.95.83.0 - - High
239 40.95.242.0 - - High
240 40.95.254.0 - - High
241 40.96.17.0 - - High
242 40.96.47.0 - - High
243 40.99.11.0 - - High
244 40.99.12.0 - - High
245 40.100.20.0 - - High
246 40.100.44.0 - - High
247 40.100.48.0 - - High
248 40.107.128.0 mail-eopbgr1280000.outbound.protection.outlook.com - High
249 40.107.132.0 mail-eopbgr1320000.outbound.protection.outlook.com - High
250 40.107.226.0 - - High
251 40.107.230.0 - - High
252 40.107.233.0 - - High
253 40.107.255.0 - - High
254 40.108.153.0 - - High
255 40.108.156.0 - - High
256 40.126.20.0 - - High
257 40.126.51.0 - - High
258 40.126.52.0 - - High
259 42.8.0.0 - - High
260 42.16.0.0 - - High
261 42.32.0.0 - - High
262 42.82.0.0 - - High
263 43.128.129.0 - - High
264 43.128.130.0 - - High
265 43.128.132.0 - - High
266 43.128.136.0 - - High
267 43.128.144.0 - - High
268 43.128.152.0 - - High
269 43.128.156.0 - - High
270 43.131.224.0 - - High
271 43.133.64.0 - - High
272 43.133.224.0 - - High
273 43.133.240.0 - - High
274 43.200.0.0 ec2-43-200-0-0.ap-northeast-2.compute.amazonaws.com - Medium
275 43.224.28.0 - - High
276 43.224.104.0 - - High
277 43.226.231.0 - - High
278 43.227.112.0 - - High
279 43.227.120.0 - - High
280 43.228.160.0 - - High
281 43.229.0.0 - - High
282 43.230.0.0 - - High
283 43.230.76.0 - - High
284 43.230.80.0 - - High
285 43.230.216.0 - - High
286 43.240.236.0 - - High
287 43.241.44.0 - - High
288 43.241.104.0 - - High
289 43.242.112.0 - - High
290 43.243.188.0 - - High
291 43.243.216.0 - - High
292 43.246.152.0 - - High
293 43.246.180.0 - - High
294 43.247.104.0 - - High
295 43.247.192.0 - - High
296 43.249.45.0 - - High
297 43.250.152.0 - - High
298 43.251.28.0 - - High
299 43.251.68.0 - - High
300 43.251.71.0 - - High
301 43.251.120.0 - - High
302 43.254.244.0 - - High
303 43.255.248.0 - - High
304 45.13.57.0 - - High
305 45.43.40.0 - - High
306 45.64.140.0 - - High
307 45.64.144.0 - - High
308 45.64.152.0 - - High
309 45.64.172.0 - - High
310 45.67.97.0 - - High
311 45.86.235.0 - - High
312 45.91.225.0 - - High
313 45.93.64.0 - - High
314 45.93.67.0 - - High
315 45.94.152.0 - - High
316 45.112.88.0 - - High
317 45.112.96.0 - - High
318 45.112.112.0 - - High
319 45.112.152.0 - - High
320 45.112.160.0 - - High
321 45.112.168.0 - - High
322 45.113.34.0 - - High
323 45.113.44.0 - - High
324 45.113.48.0 - - High
325 45.114.104.0 - - High
326 45.114.128.0 - - High
327 45.114.131.0 - - High
328 45.115.25.0 - - High
329 45.115.152.0 - - High
330 45.117.12.0 - - High
331 45.119.144.0 - - High
332 45.120.64.0 - - High
333 45.120.76.0 - - High
334 45.120.78.0 - - High
335 45.120.200.0 - - High
336 45.121.164.0 - - High
337 45.125.232.0 - - High
338 45.126.148.0 - - High
339 45.130.137.0 - - High
340 45.133.194.0 - - High
341 45.138.209.0 - - High
342 45.141.136.0 - - High
343 45.141.138.0 - - High
344 45.142.153.0 - - High
345 45.144.136.0 - - High
346 45.144.138.0 - - High
347 45.150.172.0 - - High
348 45.150.174.0 - - High
349 45.154.12.0 - - High
350 45.154.157.0 - - High
351 45.154.158.0 - - High
352 45.156.117.0 45.156.117.0.static.quadranet.com - High
353 45.195.2.0 - - High
354 45.195.86.0 - - High
355 45.195.206.0 - - High
356 45.248.72.0 - - High
357 45.249.64.0 - - High
358 45.249.160.0 - - High
359 45.250.204.0 - - High
360 45.250.208.0 - - High
361 45.250.220.0 - - High
362 45.254.252.0 - - High
363 46.8.114.0 - - High
364 47.89.122.0 - - High
365 47.246.29.0 - - High
366 47.246.59.0 - - High
367 49.1.0.0 - - High
368 49.8.0.0 - - High
369 49.16.0.0 - - High
370 49.50.0.0 - - High
371 49.50.16.0 - - High
372 49.50.32.0 - - High
373 49.50.128.0 - - High
374 49.56.0.0 - - High
375 49.128.192.0 - - High
376 49.142.0.0 - - High
377 49.143.0.0 - - High
378 49.143.128.0 - - High
379 49.143.192.0 - - High
380 49.160.0.0 - - High
381 49.236.64.0 - - High
382 49.236.128.0 - - High
383 49.238.64.0 - - High
384 49.238.128.0 - - High
385 49.239.128.0 - - High
386 49.246.0.0 - - High
387 49.247.0.0 - - High
388 49.254.0.0 - - High
389 51.162.188.0 - - High
390 52.46.53.0 server-52-46-53-0.icn55.r.cloudfront.net - High
391 52.78.0.0 ec2-52-78-0-0.ap-northeast-2.compute.amazonaws.com - Medium
392 52.84.85.0 server-52-84-85-0.icn54.r.cloudfront.net - High
393 52.84.166.0 server-52-84-166-0.icn54.r.cloudfront.net - High
394 52.84.252.0 server-52-84-252-0.icn55.r.cloudfront.net - High
395 ... ... ... ...

There are 1578 more IOC items available. Please use our online service to access the data.

TTP - Tactics, Techniques, Procedures

Tactics, techniques, and procedures (TTP) summarize the suspected MITRE ATT&CK techniques used by Republic of Korea Unknown. This data is unique as it uses our predictive model for actor profiling.

ID Technique Weakness Description Confidence
1 T1006 CWE-21, CWE-22 Pathname Traversal High
2 T1040 CWE-294 Authentication Bypass by Capture-replay High
3 T1055 CWE-74 Injection High
4 T1059 CWE-88, CWE-94, CWE-1321 Cross Site Scripting High
5 T1059.007 CWE-79, CWE-80 Cross Site Scripting High
6 ... ... ... ...

There are 21 more TTP items available. Please use our online service to access the data.

IOA - Indicator of Attack

These indicators of attack (IOA) list the potential fragments used for technical activities like reconnaissance, exploitation, privilege escalation, and exfiltration by Republic of Korea Unknown. This data is unique as it uses our predictive model for actor profiling.

ID Type Indicator Confidence
1 File $GIT_DIR/objects High
2 File .github/workflows/combine-prs.yml High
3 File /admin/admin_manage/delete High
4 File /admin/api/admin/articles/ High
5 File /admin/edit.php High
6 File /admin/fst_upload.inc.php High
7 File /admin/main/mod-blog High
8 File /admin/options High
9 File /adms/admin/?page=vehicles/sell_vehicle High
10 File /adms/admin/?page=vehicles/view_transaction High
11 File /advanced/adv_dns.xgi High
12 File /alarm_pi/alarmService.php High
13 File /api/ Low
14 File /api/v1/attack/token High
15 File /backup.pl Medium
16 File /bin/httpd Medium
17 File /browse.PROJECTKEY High
18 File /cgi-bin/luci/api/wireless High
19 File /cgi-bin/supervisor/adcommand.cgi High
20 File /cgi-bin/supervisor/CloudSetup.cgi High
21 File /cmscp/ext/collect/fetch_url.do High
22 File /crmeb/app/admin/controller/store/CopyTaobao.php High
23 File /debug/pprof Medium
24 File /dev/block/mmcblk0rpmb High
25 File /DocSystem/Repos/getReposAllUsers.do High
26 File /env Low
27 File /face-recognition-php/facepay-master/camera.php High
28 File /forms/doLogin High
29 File /fos/admin/ajax.php?action=login High
30 File /fos/admin/index.php?page=menu High
31 File /home/masterConsole High
32 File /home/sendBroadcast High
33 File /hrm/employeeadd.php High
34 File /hrm/employeeview.php High
35 File /jsoa/hntdCustomDesktopActionContent High
36 File /login/index.php High
37 File /lookin/info Medium
38 File /mygym/admin/index.php?view_exercises High
39 File /orrs/admin/?page=user/manage_user High
40 File /out.php Medium
41 File /php-opos/index.php High
42 File /plugin/getList High
43 File /proxy Low
44 File /Redcock-Farm/farm/category.php High
45 File /reports/rwservlet High
46 File /resources//../ High
47 ... ... ...

There are 409 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.

References

The following list contains external sources which discuss the actor and the associated activities:

Literature

The following articles explain our unique predictive cyber threat intelligence:

License

(c) 1997-2023 by vuldb.com. All data on this page is shared under the license CC BY-NC-SA 4.0. Questions? Check the FAQ, read the documentation or contact us!