cyber_threat_intelligence/actors/Taiwan Unknown/README.md
2023-01-13 23:50:29 +01:00

21 KiB

Taiwan Unknown - Cyber Threat Intelligence

These indicators were reported, collected, and generated during the VulDB CTI analysis of the actor known as Taiwan Unknown. The activity monitoring correlates data from social media, forums, chat rooms, and darknet markets. It helps to determine associated actors, specific activities, expected intentions, emerging research, and ongoing attacks. Our unique predictive model uses big data to forecast activities and their characteristics.

Live data and more analysis capabilities are available at https://vuldb.com/?actor.taiwan_unknown

Countries

These countries are directly (e.g. origin of attacks) or indirectly (e.g. access by proxy) associated with Taiwan Unknown:

There are 18 more country items available. Please use our online service to access the data.

IOC - Indicator of Compromise

These indicators of compromise (IOC) indicate associated network resources which are known to be part of research and attack activities of Taiwan Unknown.

ID IP address Hostname Campaign Confidence
1 1.32.194.0 - - High
2 1.32.197.0 - - High
3 1.32.202.0 - - High
4 1.32.203.0 - - High
5 1.32.204.0 - - High
6 1.34.0.0 1-34-0-0.hinet-ip.hinet.net - High
7 1.160.0.0 1-160-0-0.dynamic-ip.hinet.net - High
8 1.200.0.0 - - High
9 2.58.240.0 - - High
10 8.39.126.0 - - High
11 14.0.56.0 - - High
12 17.91.120.0 - - High
13 17.91.176.0 - - High
14 17.92.208.0 - - High
15 17.253.116.0 - - High
16 23.210.215.4 a23-210-215-4.deploy.static.akamaitechnologies.com - High
17 23.210.215.12 a23-210-215-12.deploy.static.akamaitechnologies.com - High
18 23.210.215.20 a23-210-215-20.deploy.static.akamaitechnologies.com - High
19 23.210.215.28 a23-210-215-28.deploy.static.akamaitechnologies.com - High
20 23.210.215.36 a23-210-215-36.deploy.static.akamaitechnologies.com - High
21 23.210.215.44 a23-210-215-44.deploy.static.akamaitechnologies.com - High
22 23.210.215.102 a23-210-215-102.deploy.static.akamaitechnologies.com - High
23 23.210.215.108 a23-210-215-108.deploy.static.akamaitechnologies.com - High
24 23.210.215.116 a23-210-215-116.deploy.static.akamaitechnologies.com - High
25 23.210.215.124 a23-210-215-124.deploy.static.akamaitechnologies.com - High
26 23.210.215.132 a23-210-215-132.deploy.static.akamaitechnologies.com - High
27 23.210.215.140 a23-210-215-140.deploy.static.akamaitechnologies.com - High
28 23.236.103.0 - - High
29 23.236.104.0 - - High
30 23.248.176.0 - - High
31 27.0.152.0 - - High
32 27.51.0.0 27-51-0-0.adsl.fetnet.net - High
33 27.52.0.0 27-52-0-0.adsl.fetnet.net - High
34 27.96.224.0 27-96-224-0.veetime.com - High
35 27.100.19.0 - - High
36 27.100.64.0 0-64-100-27.tinp.net.tw - High
37 27.105.0.0 27-105-0-0-adsl-TPE.dynamic.so-net.net.tw - High
38 27.123.200.0 unknown.yahoo.com - High
39 27.124.13.0 - - High
40 27.124.14.0 - - High
41 27.147.0.0 - - High
42 27.240.0.0 27-240-0-0.adsl.fetnet.net - High
43 31.187.65.192 - - High
44 34.80.144.29 29.144.80.34.bc.googleusercontent.com - Medium
45 34.80.249.113 113.249.80.34.bc.googleusercontent.com - Medium
46 34.98.152.0 0.152.98.34.bc.googleusercontent.com - Medium
47 35.194.149.95 95.149.194.35.bc.googleusercontent.com - Medium
48 35.201.247.218 218.247.201.35.bc.googleusercontent.com - Medium
49 35.203.226.0 0.226.203.35.bc.googleusercontent.com - Medium
50 36.224.0.0 36-224-0-0.dynamic-ip.hinet.net - High
51 36.255.96.0 - - High
52 37.252.243.0 - - High
53 39.1.0.0 39-1-0-0-adsl-KHH.dynamic.so-net.net.tw - High
54 39.8.0.0 39-8-0-0.adsl.fetnet.net - High
55 42.0.64.0 - - High
56 42.64.0.0 42-64-0-0.emome-ip.hinet.net - High
57 43.224.20.0 - - High
58 43.224.248.0 - - High
59 43.226.232.0 - - High
60 43.227.24.0 - - High
61 43.240.24.0 - - High
62 43.240.44.0 - - High
63 43.240.104.0 - - High
64 43.240.152.0 - - High
65 43.241.32.0 - - High
66 43.241.160.0 - - High
67 43.243.252.0 - - High
68 43.245.223.0 - - High
69 43.246.188.0 - - High
70 43.246.216.0 - - High
71 43.248.16.0 - - High
72 43.250.44.0 - - High
73 43.251.56.0 - - High
74 43.251.182.118 - - High
75 43.254.16.0 43-254-16-0.static.ip.net.tw - High
76 43.254.60.0 - - High
77 43.255.12.0 - - High
78 43.255.88.0 - - High
79 43.255.180.0 - - High
80 45.10.214.0 - - High
81 45.12.70.229 outposts.globalhilive.com - High
82 45.12.71.229 - - High
83 45.40.216.0 - - High
84 45.41.147.0 - - High
85 45.43.36.0 - - High
86 45.64.28.0 - - High
87 45.64.32.0 - - High
88 45.64.74.0 - - High
89 45.64.228.0 - - High
90 45.64.232.0 - - High
91 45.66.156.0 0.156-66-45.rdns.scalabledns.com - High
92 45.82.155.0 - - High
93 45.113.156.0 - - High
94 45.120.201.0 - - High
95 45.121.48.0 - - High
96 45.121.180.0 - - High
97 45.127.218.0 - - High
98 45.129.77.0 - - High
99 45.129.78.0 - - High
100 45.133.181.64 - - High
101 45.249.105.0 - - High
102 45.254.255.0 - - High
103 49.128.80.0 - - High
104 49.128.112.0 - - High
105 49.158.0.0 49-158-0-0.dynamic.elinx.com.tw - High
106 49.213.128.0 0-128-213-49.tinp.net.tw - High
107 49.214.0.0 - - High
108 49.216.0.0 - - High
109 57.73.160.0 - - High
110 58.86.0.0 - - High
111 58.99.0.0 - - High
112 58.114.0.0 host-58-114-0-0.dynamic.kbtelecom.net - High
113 59.102.128.0 - - High
114 59.104.0.0 - - High
115 59.112.0.0 59-112-0-0.dynamic-ip.hinet.net - High
116 60.198.0.0 60-198-0-0.dynamic.tfn.net.tw - High
117 60.244.0.0 - - High
118 60.245.0.0 - - High
119 60.248.0.0 60-248-0-0.hinet-ip.hinet.net - High
120 61.14.133.80 ip-61-14-133-80.asianetcom.net - High
121 61.20.0.0 61-20-0-0.adsl.fetnet.net - High
122 61.30.0.0 - - High
123 61.56.0.0 - - High
124 61.64.0.0 - - High
125 61.70.0.0 - - High
126 61.216.0.0 61-216-0-0.hinet-ip.hinet.net - High
127 61.224.0.0 61-224-0-0.dynamic-ip.hinet.net - High
128 61.247.160.0 static-ip-0-160-247-61.rev.dyxnet.com - High
129 63.218.17.32 63-218-17-32.static.pccwglobal.net - High
130 63.222.54.144 63-222-54-144.static.pccwglobal.net - High
131 64.64.121.208 - - High
132 66.249.82.198 google-proxy-66-249-82-198.google.com - High
133 72.14.230.40 - - High
134 72.14.231.40 - - High
135 74.120.120.0 74.120.120.0.as1030.net - High
136 74.125.41.0 - - High
137 80.245.108.0 - - High
138 85.14.204.160 58.41.402.061.static.rdns-uclo.net - High
139 85.190.226.0 - - High
140 85.217.216.0 - - High
141 89.163.181.128 98.361.181.821.static.rdns-uclo.net - High
142 89.163.183.128 - - High
143 101.0.128.0 - - High
144 101.3.0.0 - - High
145 101.8.0.0 - - High
146 101.79.144.0 - - High
147 101.79.155.0 - - High
148 101.79.156.0 - - High
149 101.79.159.0 - - High
150 101.101.101.0 - - High
151 101.102.103.0 - - High
152 101.136.0.0 101-136-0-0.mobile.dynamic.aptg.com.tw - High
153 101.251.95.0 - - High
154 103.1.220.0 103-1-220-0.static.ip.net.tw - High
155 103.2.216.0 - - High
156 103.3.192.0 - - High
157 103.4.28.0 - - High
158 103.4.104.0 - - High
159 103.5.32.0 - - High
160 103.5.44.0 - - High
161 103.5.100.0 - - High
162 103.8.104.0 - - High
163 103.9.116.0 - - High
164 103.10.4.0 - - High
165 103.10.204.0 - - High
166 103.11.37.0 - - High
167 103.16.240.0 - - High
168 103.17.8.0 103-17-8-0.static.ip.net.tw - High
169 103.17.95.0 - - High
170 103.17.240.0 - - High
171 103.18.128.0 103-18-128-0.ip.mwsrv.com - High
172 103.20.40.0 - - High
173 103.20.176.0 - - High
174 103.21.60.0 - - High
175 103.21.196.0 - - High
176 103.22.156.0 - - High
177 103.22.212.0 - - High
178 103.23.108.0 ip-103-23-108-0.static.pixnet.tw - High
179 103.24.100.0 - - High
180 103.25.232.0 - - High
181 103.28.200.0 - - High
182 103.30.44.0 - - High
183 103.30.128.0 - - High
184 103.31.196.0 - - High
185 103.35.204.0 - - High
186 103.36.116.0 - - High
187 103.37.36.0 - - High
188 103.38.146.0 - - High
189 103.39.40.0 - - High
190 103.42.112.0 - - High
191 103.42.144.0 - - High
192 103.43.48.0 - - High
193 103.46.144.0 - - High
194 103.46.188.0 - - High
195 103.49.133.0 - - High
196 103.51.140.0 - - High
197 ... ... ... ...

There are 784 more IOC items available. Please use our online service to access the data.

TTP - Tactics, Techniques, Procedures

Tactics, techniques, and procedures (TTP) summarize the suspected MITRE ATT&CK techniques used by Taiwan Unknown. This data is unique as it uses our predictive model for actor profiling.

ID Technique Weakness Description Confidence
1 T1006 CWE-21, CWE-22 Pathname Traversal High
2 T1040 CWE-294 Authentication Bypass by Capture-replay High
3 T1055 CWE-74 Injection High
4 T1059 CWE-94, CWE-1321 Cross Site Scripting High
5 T1059.007 CWE-79, CWE-80 Cross Site Scripting High
6 ... ... ... ...

There are 20 more TTP items available. Please use our online service to access the data.

IOA - Indicator of Attack

These indicators of attack (IOA) list the potential fragments used for technical activities like reconnaissance, exploitation, privilege escalation, and exfiltration by Taiwan Unknown. This data is unique as it uses our predictive model for actor profiling.

ID Type Indicator Confidence
1 File .github/workflows/combine-prs.yml High
2 File .htaccess Medium
3 File /Admin/add-student.php High
4 File /admin/api/admin/articles/ High
5 File /admin/conferences/list/ High
6 File /admin/edit_admin_details.php?id=admin High
7 File /admin/generalsettings.php High
8 File /Admin/login.php High
9 File /admin/payment.php High
10 File /admin/reports.php High
11 File /admin/showbad.php High
12 File /apilog.php Medium
13 File /cgi-bin/wlogin.cgi High
14 File /connectors/index.php High
15 File /DocSystem/Repos/getReposAllUsers.do High
16 File /face-recognition-php/facepay-master/camera.php High
17 File /forum/away.php High
18 File /hrm/employeeadd.php High
19 File /hrm/employeeview.php High
20 File /index.php Medium
21 File /Items/*/RemoteImages/Download High
22 File /items/view_item.php High
23 File /jsoa/hntdCustomDesktopActionContent High
24 File /lookin/info Medium
25 File /MagickCore/image.c High
26 File /manager/index.php High
27 File /medical/inventories.php High
28 File /modules/profile/index.php High
29 File /modules/projects/vw_files.php High
30 File /modules/public/calendar.php High
31 File /newsDia.php Medium
32 File /out.php Medium
33 File /proxy Low
34 File /public/launchNewWindow.jsp High
35 File /Redcock-Farm/farm/category.php High
36 File /reports/rwservlet High
37 File /sacco_shield/manage_user.php High
38 File /spip.php Medium
39 File /sqlitemanager/main.php?dbsel=-1%20or%2072%20=%2072 High
40 File /staff/bookdetails.php High
41 File /TeleoptiWFM/Administration/GetOneTenant High
42 File /user/update_booking.php High
43 File /WEB-INF/web.xml High
44 File /Wedding-Management-PHP/admin/photos_add.php High
45 File /wordpress/wp-admin/options-general.php High
46 File /wp-content/plugins/woocommerce/templates/emails/plain/ High
47 File /_vti_pvt/access.cnf High
48 File AbstractScheduleJob.java High
49 File actionphp/download.File.php High
50 File AdClass.php Medium
51 File adclick.php Medium
52 File addtocart.asp High
53 File admin.php Medium
54 File admin/conf_users_edit.php High
55 File admin/panels/entry/admin.entry.list.php High
56 ... ... ...

There are 484 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.

References

The following list contains external sources which discuss the actor and the associated activities:

Literature

The following articles explain our unique predictive cyber threat intelligence:

License

(c) 1997-2023 by vuldb.com. All data on this page is shared under the license CC BY-NC-SA 4.0. Questions? Check the FAQ, read the documentation or contact us!