cyber_threat_intelligence/actors/Cambodia Unknown/README.md

15 KiB

Cambodia Unknown - Cyber Threat Intelligence

These indicators were reported, collected, and generated during the VulDB CTI analysis of the actor known as Cambodia Unknown. The activity monitoring correlates data from social media, forums, chat rooms, and darknet markets. It helps to determine associated actors, specific activities, expected intentions, emerging research, and ongoing attacks. Our unique predictive model uses big data to forecast activities and their characteristics.

Live data and more analysis capabilities are available at https://vuldb.com/?actor.cambodia_unknown

Countries

These countries are directly (e.g. origin of attacks) or indirectly (e.g. access by proxy) associated with Cambodia Unknown:

There are 3 more country items available. Please use our online service to access the data.

IOC - Indicator of Compromise

These indicators of compromise (IOC) indicate associated network resources which are known to be part of research and attack activities of Cambodia Unknown.

ID IP address Hostname Campaign Confidence
1 1.32.201.169 - - High
2 1.32.201.170 - - High
3 1.32.206.0 - - High
4 1.32.243.64 smtp-5.outwatchesky.org - High
5 1.32.252.0 - - High
6 5.28.32.0 - - High
7 5.62.60.64 r-64-60-62-5.consumer-pool.prcdn.net - High
8 5.62.62.64 r-64-62-62-5.consumer-pool.prcdn.net - High
9 27.34.178.0 - - High
10 27.34.178.64 - - High
11 27.34.181.0 - - High
12 27.34.183.0 - - High
13 27.34.186.0 - - High
14 27.34.186.2 - - High
15 27.34.187.0 - - High
16 27.34.187.32 - - High
17 27.34.189.0 - - High
18 27.50.56.0 - - High
19 27.96.84.0 - - High
20 27.109.112.0 - - High
21 27.111.8.0 - - High
22 27.116.60.0 - - High
23 27.124.15.0 - - High
24 27.124.33.0 - - High
25 27.124.34.0 - - High
26 27.124.35.0 - - High
27 27.124.36.0 - - High
28 27.124.40.0 - - High
29 27.124.51.0 - - High
30 27.124.52.0 - - High
31 27.124.57.0 - - High
32 27.124.57.16 - - High
33 27.124.57.24 - - High
34 27.124.57.32 - - High
35 27.124.57.40 - - High
36 27.124.57.50 - - High
37 27.124.57.52 - - High
38 27.124.57.56 - - High
39 27.124.57.64 - - High
40 27.124.57.128 - - High
41 27.124.60.16 - - High
42 27.254.112.0 - - High
43 34.98.224.0 0.224.98.34.bc.googleusercontent.com - Medium
44 34.98.240.0 0.240.98.34.bc.googleusercontent.com - Medium
45 34.103.0.0 0.0.103.34.bc.googleusercontent.com - Medium
46 36.37.128.0 metfone.com.kh - High
47 36.37.192.0 - - High
48 36.37.224.0 - - High
49 36.37.240.0 - - High
50 36.37.248.0 - - High
51 36.37.252.0 - - High
52 36.37.252.16 - - High
53 36.37.252.24 - - High
54 36.37.252.28 - - High
55 36.37.252.30 - - High
56 36.37.252.32 - - High
57 36.37.252.64 - - High
58 36.37.252.128 - - High
59 36.37.253.0 - - High
60 36.37.254.0 - - High
61 36.255.144.0 - - High
62 38.54.4.0 - - High
63 38.54.93.0 - - High
64 42.115.0.0 - - High
65 42.115.0.34 - - High
66 43.129.36.175 - - High
67 43.129.41.169 - - High
68 43.226.12.0 - - High
69 43.226.22.0 - - High
70 43.230.60.0 - - High
71 43.230.192.0 - - High
72 43.231.64.0 - - High
73 43.231.220.0 iZxeQl5zBqI.IC849Y21.ayApslN-TlHo.iNFO - High
74 43.245.32.0 - - High
75 43.245.200.0 - - High
76 43.245.216.0 - - High
77 43.247.1.0 - - High
78 43.250.228.0 - - High
79 43.252.16.0 - - High
80 43.252.16.128 - - High
81 43.252.17.0 - - High
82 43.252.18.0 - - High
83 43.252.80.0 - - High
84 43.255.112.0 - - High
85 45.12.70.118 device-despite.yourbandinc.com - High
86 45.12.71.118 - - High
87 45.59.146.0 - - High
88 45.62.164.0 - - High
89 45.64.124.0 - - High
90 45.112.44.0 - - High
91 45.114.160.0 - - High
92 45.115.80.0 - - High
93 45.115.180.0 - - High
94 45.115.208.0 - - High
95 45.118.76.0 - - High
96 45.119.132.0 - - High
97 45.119.135.0 - - High
98 45.121.236.0 akctv.com - High
99 45.127.152.0 - - High
100 45.133.168.0 - - High
101 45.201.128.0 - - High
102 45.201.192.0 - - High
103 45.201.208.0 - - High
104 45.201.212.0 - - High
105 45.250.236.0 - - High
106 45.253.246.0 - - High
107 46.244.29.64 - - High
108 49.156.0.0 - - High
109 49.156.32.0 - - High
110 57.72.80.0 - - High
111 57.92.80.0 - - High
112 58.97.192.0 - - High
113 58.97.208.0 - - High
114 58.97.216.0 - - High
115 58.97.218.0 - - High
116 58.97.220.0 - - High
117 58.97.224.0 - - High
118 61.29.252.192 - - High
119 61.29.254.0 - - High
120 64.64.121.64 - - High
121 66.102.33.0 - - High
122 81.161.239.0 - - High
123 83.172.62.0 - - High
124 85.209.176.0 - - High
125 87.247.160.0 - - High
126 88.209.207.0 - - High
127 93.114.14.0 - - High
128 96.9.64.0 - - High
129 102.129.157.0 - - High
130 102.129.232.0 - - High
131 102.165.57.0 - - High
132 102.165.58.0 - - High
133 103.5.124.0 - - High
134 103.5.230.0 - - High
135 103.6.8.0 - - High
136 103.7.24.0 ppp-103.7.24.0.revip.NTT.COM.KH - High
137 103.7.144.0 - - High
138 103.8.20.0 - - High
139 103.9.188.0 - - High
140 103.11.216.0 - - High
141 103.12.160.0 - - High
142 103.14.11.122 sun-mx960-transit-intl-103-14-11-122.symphony.net.th - High
143 103.14.248.0 - - High
144 103.16.60.0 - - High
145 ... ... ... ...

There are 574 more IOC items available. Please use our online service to access the data.

TTP - Tactics, Techniques, Procedures

Tactics, techniques, and procedures (TTP) summarize the suspected MITRE ATT&CK techniques used by Cambodia Unknown. This data is unique as it uses our predictive model for actor profiling.

ID Technique Weakness Description Confidence
1 T1006 CWE-22 Path Traversal High
2 T1040 CWE-294 Authentication Bypass by Capture-replay High
3 T1055 CWE-74 Injection High
4 ... ... ... ...

There are 11 more TTP items available. Please use our online service to access the data.

IOA - Indicator of Attack

These indicators of attack (IOA) list the potential fragments used for technical activities like reconnaissance, exploitation, privilege escalation, and exfiltration by Cambodia Unknown. This data is unique as it uses our predictive model for actor profiling.

ID Type Indicator Confidence
1 File /admin/AddNewCity/Add_City High
2 File /admin/subnets/ripe-query.php High
3 File /food/admin/all_users.php High
4 File /forum/away.php High
5 File /index.php/client/message/message_read/xxxxxxxx[random-msg-hash] High
6 File /log/download.php High
7 File /mkshop/Men/profile.php High
8 File /modules/profile/index.php High
9 File /netflow/servlet/CReportPDFServlet High
10 File /nova/bin/console High
11 File /oauth/idp/.well-known/openid-configuration High
12 File /out.php Medium
13 File /spip.php Medium
14 File /uncpath/ Medium
15 File /usr/bin/pkexec High
16 File adclick.php Medium
17 File add-testimonial.php High
18 File addentry.php Medium
19 File add_edit_user.asp High
20 File admin.php Medium
21 ... ... ...

There are 169 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.

References

The following list contains external sources which discuss the actor and the associated activities:

Literature

The following articles explain our unique predictive cyber threat intelligence:

License

(c) 1997-2024 by vuldb.com. All data on this page is shared under the license CC BY-NC-SA 4.0. Questions? Check the FAQ, read the documentation or contact us!