cyber_threat_intelligence/actors/Croatia Unknown/README.md
2023-01-13 23:50:29 +01:00

8.6 KiB

Croatia Unknown - Cyber Threat Intelligence

These indicators were reported, collected, and generated during the VulDB CTI analysis of the actor known as Croatia Unknown. The activity monitoring correlates data from social media, forums, chat rooms, and darknet markets. It helps to determine associated actors, specific activities, expected intentions, emerging research, and ongoing attacks. Our unique predictive model uses big data to forecast activities and their characteristics.

Live data and more analysis capabilities are available at https://vuldb.com/?actor.croatia_unknown

Countries

These countries are directly (e.g. origin of attacks) or indirectly (e.g. access by proxy) associated with Croatia Unknown:

IOC - Indicator of Compromise

These indicators of compromise (IOC) indicate associated network resources which are known to be part of research and attack activities of Croatia Unknown.

ID IP address Hostname Campaign Confidence
1 2.57.172.0 - - High
2 2.58.32.0 - - High
3 2.58.48.0 start.softnet.si - High
4 5.39.128.0 - - High
5 5.43.160.0 5-43-160-0.dsl.optinet.hr - High
6 5.62.61.228 r-228-61-62-5.consumer-pool.prcdn.net - High
7 5.62.63.224 r-224-63-62-5.consumer-pool.prcdn.net - High
8 5.175.186.200 - - High
9 5.180.216.0 - - High
10 5.188.10.0 - - High
11 5.231.9.0 - - High
12 5.231.77.0 - - High
13 8.39.6.0 - - High
14 31.45.128.0 srv-31-45-128-0.static.a1.hr - High
15 31.147.0.0 vipnet0.mobile.carnet.hr - High
16 31.216.192.0 - - High
17 31.217.0.0 - - High
18 34.99.142.0 0.142.99.34.bc.googleusercontent.com - Medium
19 34.99.214.0 0.214.99.34.bc.googleusercontent.com - Medium
20 34.103.158.0 0.158.103.34.bc.googleusercontent.com - Medium
21 36.255.92.0 36-255-92-0.cheapserviceswiki.com - High
22 37.0.128.0 m37-0-128-0.cust.tele2.hr - High
23 37.0.192.0 m37-0-192-0.cust.tele2.hr - High
24 37.48.232.0 - - High
25 37.60.128.0 - - High
26 37.205.96.0 - - High
27 37.244.128.0 srv-37-244-128-0.static.a1.hr - High
28 43.113.227.0 - - High
29 44.170.0.0 - - High
30 45.12.70.99 inflects.yourbandinc.com - High
31 45.12.71.99 - - High
32 45.85.120.0 - - High
33 45.87.24.0 - - High
34 45.95.168.0 maxko-hosting.com - High
35 45.136.188.0 - - High
36 46.31.136.0 - - High
37 46.163.0.0 - - High
38 46.163.51.0 - - High
39 46.163.53.0 - - High
40 46.163.58.0 - - High
41 46.174.136.0 - - High
42 46.174.138.0 - - High
43 46.188.128.0 - - High
44 46.229.240.0 - - High
45 46.229.248.0 - - High
46 46.229.252.0 46-229-252-0-dsl.novi-net.net - High
47 46.234.64.0 - - High
48 57.90.64.0 - - High
49 63.170.203.144 - - High
50 77.216.0.0 m77-216-0-0.cust.tele2.hr - High
51 77.219.32.0 m77-219-32-0.cust.tele2.hr - High
52 77.219.64.0 m77-219-64-0.cust.tele2.hr - High
53 77.219.128.0 m77-219-128-0.cust.tele2.hr - High
54 77.237.96.0 srv-77-237-96-0.static.a1.hr - High
55 78.0.0.0 78-0-0-0.adsl.net.t-com.hr - High
56 78.134.128.0 78.134.128.0-dsl.net.metronet.hr - High
57 80.80.48.0 - - High
58 80.253.162.0 - - High
59 80.253.164.0 - - High
60 80.253.168.0 - - High
61 82.132.0.0 - - High
62 82.193.192.0 - - High
63 82.214.76.0 c82-214-76-0.loc.akton.net - High
64 82.214.78.0 c82-214-78-0.loc.akton.net - High
65 82.214.96.0 c82-214-96-0.loc.akton.net - High
66 83.131.0.0 - - High
67 83.139.64.0 - - High
68 83.176.32.0 m83-176-32-0.cust.tele2.hr - High
69 83.176.64.0 m83-176-64-0.cust.tele2.hr - High
70 83.176.128.0 m83-176-128-0.cust.tele2.hr - High
71 83.177.0.0 m83-177-0-0.cust.tele2.hr - High
72 83.178.0.0 - - High
73 83.178.104.0 m83-178-104-0.cust.tele2.hr - High
74 83.178.112.0 m83-178-112-0.cust.tele2.hr - High
75 83.178.234.0 m83-178-234-0.cust.tele2.hr - High
76 83.178.236.0 m83-178-236-0.cust.tele2.hr - High
77 ... ... ... ...

There are 306 more IOC items available. Please use our online service to access the data.

TTP - Tactics, Techniques, Procedures

Tactics, techniques, and procedures (TTP) summarize the suspected MITRE ATT&CK techniques used by Croatia Unknown. This data is unique as it uses our predictive model for actor profiling.

ID Technique Weakness Description Confidence
1 T1068 CWE-269 Execution with Unnecessary Privileges High
2 T1202 CWE-78 Command Injection High

References

The following list contains external sources which discuss the actor and the associated activities:

Literature

The following articles explain our unique predictive cyber threat intelligence:

License

(c) 1997-2023 by vuldb.com. All data on this page is shared under the license CC BY-NC-SA 4.0. Questions? Check the FAQ, read the documentation or contact us!