cyber_threat_intelligence/actors/Chile Unknown/README.md

33 KiB

Chile Unknown - Cyber Threat Intelligence

These indicators were reported, collected, and generated during the VulDB CTI analysis of the actor known as Chile Unknown. The activity monitoring correlates data from social media, forums, chat rooms, and darknet markets. It helps to determine associated actors, specific activities, expected intentions, emerging research, and ongoing attacks. Our unique predictive model uses big data to forecast activities and their characteristics.

Live data and more analysis capabilities are available at https://vuldb.com/?actor.chile_unknown

Countries

These countries are directly (e.g. origin of attacks) or indirectly (e.g. access by proxy) associated with Chile Unknown:

There are 13 more country items available. Please use our online service to access the data.

IOC - Indicator of Compromise

These indicators of compromise (IOC) indicate associated network resources which are known to be part of research and attack activities of Chile Unknown.

ID IP address Hostname Campaign Confidence
1 2.18.236.0 a2-18-236-0.deploy.static.akamaitechnologies.com - High
2 2.19.252.0 a2-19-252-0.deploy.static.akamaitechnologies.com - High
3 2.22.148.0 a2-22-148-0.deploy.static.akamaitechnologies.com - High
4 2.23.178.0 a2-23-178-0.deploy.static.akamaitechnologies.com - High
5 2.23.187.0 lo0.r01.border.scl01.sdn.netarch.akamai.com - High
6 2.57.28.0 - - High
7 5.8.45.128 - - High
8 5.62.56.52 r-52-56-62-5.consumer-pool.prcdn.net - High
9 5.62.58.52 r-52-58-62-5.consumer-pool.prcdn.net - High
10 8.14.204.0 - - High
11 8.36.218.0 - - High
12 8.51.2.0 - - High
13 8.51.5.0 - - High
14 8.51.7.0 - - High
15 8.51.45.0 - - High
16 8.51.46.0 - - High
17 8.241.245.0 - - High
18 8.241.249.0 - - High
19 8.241.251.0 - - High
20 8.241.254.0 - - High
21 8.242.200.0 host-8-242-200-0.centurylink.cl - High
22 8.243.139.80 8-243-139-80.gblx.net.ar - High
23 8.243.176.0 - - High
24 13.104.141.65 - - High
25 13.104.141.129 - - High
26 13.104.185.32 - - High
27 13.227.181.0 server-13-227-181-0.scl50.r.cloudfront.net - High
28 13.227.182.0 server-13-227-182-0.scl50.r.cloudfront.net - High
29 13.227.192.0 server-13-227-192-0.scl50.r.cloudfront.net - High
30 13.227.196.0 server-13-227-196-0.scl50.r.cloudfront.net - High
31 13.227.200.0 server-13-227-200-0.scl50.r.cloudfront.net - High
32 13.248.104.32 - - High
33 13.248.104.64 - - High
34 17.43.132.0 - - High
35 17.45.140.0 - - High
36 17.45.142.0 - - High
37 17.45.170.114 - - High
38 19.50.58.20 - - High
39 20.20.32.64 - - High
40 20.20.32.128 - - High
41 20.201.132.0 - - High
42 20.201.134.0 - - High
43 23.2.64.0 a23-2-64-0.deploy.static.akamaitechnologies.com - High
44 23.3.240.0 a23-3-240-0.deploy.static.akamaitechnologies.com - High
45 23.6.0.0 a23-6-0-0.deploy.static.akamaitechnologies.com - High
46 23.12.112.0 a23-12-112-0.deploy.static.akamaitechnologies.com - High
47 23.14.64.0 a23-14-64-0.deploy.static.akamaitechnologies.com - High
48 23.14.87.0 a23-14-87-0.deploy.static.akamaitechnologies.com - High
49 23.15.184.0 a23-15-184-0.deploy.static.akamaitechnologies.com - High
50 23.15.192.0 a23-15-192-0.deploy.static.akamaitechnologies.com - High
51 23.41.11.0 a23-41-11-0.deploy.static.akamaitechnologies.com - High
52 23.41.144.0 a23-41-144-0.deploy.static.akamaitechnologies.com - High
53 23.44.231.0 a23-44-231-0.deploy.static.akamaitechnologies.com - High
54 23.45.136.0 a23-45-136-0.deploy.static.akamaitechnologies.com - High
55 23.51.144.0 a23-51-144-0.deploy.static.akamaitechnologies.com - High
56 23.56.214.0 a23-56-214-0.deploy.static.akamaitechnologies.com - High
57 23.56.216.0 a23-56-216-0.deploy.static.akamaitechnologies.com - High
58 23.59.24.0 a23-59-24-0.deploy.static.akamaitechnologies.com - High
59 23.59.228.0 a23-59-228-0.deploy.static.akamaitechnologies.com - High
60 23.60.14.0 a23-60-14-0.deploy.static.akamaitechnologies.com - High
61 23.60.100.0 a23-60-100-0.deploy.static.akamaitechnologies.com - High
62 23.62.52.0 a23-62-52-0.deploy.static.akamaitechnologies.com - High
63 23.72.251.0 a23-72-251-0.deploy.static.akamaitechnologies.com - High
64 23.78.224.0 a23-78-224-0.deploy.static.akamaitechnologies.com - High
65 23.195.99.0 a23-195-99-0.deploy.static.akamaitechnologies.com - High
66 23.204.95.0 a23-204-95-0.deploy.static.akamaitechnologies.com - High
67 23.213.29.0 a23-213-29-0.deploy.static.akamaitechnologies.com - High
68 23.213.30.0 a23-213-30-0.deploy.static.akamaitechnologies.com - High
69 23.213.206.0 a23-213-206-0.deploy.static.akamaitechnologies.com - High
70 23.219.44.0 a23-219-44-0.deploy.static.akamaitechnologies.com - High
71 23.219.148.0 a23-219-148-0.deploy.static.akamaitechnologies.com - High
72 23.222.237.0 a23-222-237-0.deploy.static.akamaitechnologies.com - High
73 23.222.238.0 a23-222-238-0.deploy.static.akamaitechnologies.com - High
74 24.239.163.0 - - High
75 31.169.121.0 - - High
76 32.59.28.0 - - High
77 32.59.29.0 - - High
78 32.59.68.0 - - High
79 32.59.96.0 - - High
80 32.59.98.0 - - High
81 32.115.37.22 - - High
82 32.118.88.2 - - High
83 32.118.88.18 - - High
84 32.118.88.26 - - High
85 32.118.88.210 - - High
86 34.100.20.0 0.20.100.34.bc.googleusercontent.com - Medium
87 34.100.54.0 0.54.100.34.bc.googleusercontent.com - Medium
88 34.104.50.0 0.50.104.34.bc.googleusercontent.com - Medium
89 34.127.178.0 0.178.127.34.bc.googleusercontent.com - Medium
90 34.127.199.32 - - High
91 34.127.199.64 - - High
92 34.176.0.0 0.0.176.34.bc.googleusercontent.com - Medium
93 35.203.244.96 96.244.203.35.gae.googleusercontent.com - Medium
94 35.203.244.128 128.244.203.35.gae.googleusercontent.com - Medium
95 37.139.70.0 - - High
96 37.143.128.0 - - High
97 37.235.52.0 - - High
98 37.252.251.0 - - High
99 38.7.192.0 - - High
100 38.9.192.0 - - High
101 38.9.200.0 - - High
102 38.9.205.0 - - High
103 38.9.206.0 - - High
104 38.9.208.0 - - High
105 38.9.212.0 - - High
106 38.9.215.0 - - High
107 38.9.216.0 - - High
108 38.9.220.0 - - High
109 38.9.223.0 - - High
110 38.41.176.0 - - High
111 38.43.78.0 - - High
112 38.54.46.0 - - High
113 38.87.223.0 - - High
114 38.131.8.0 - - High
115 40.90.64.47 - - High
116 40.90.64.68 - - High
117 40.96.14.144 - - High
118 40.96.24.160 - - High
119 40.96.56.96 - - High
120 40.97.14.64 - - High
121 40.97.14.128 - - High
122 40.102.32.0 - - High
123 43.249.73.0 - - High
124 44.31.61.0 - - High
125 45.4.0.0 - - High
126 45.4.168.0 - - High
127 45.5.120.0 - - High
128 45.7.92.0 - - High
129 45.7.228.0 - - High
130 45.8.207.0 - - High
131 45.12.70.46 deep.get-eye.com - High
132 45.12.71.46 - - High
133 45.57.60.0 - - High
134 45.65.160.0 dynamic-45-65-160-0.conectamais.net.br - High
135 45.65.240.0 - - High
136 45.68.16.0 - - High
137 45.71.8.0 - - High
138 45.71.44.0 - - High
139 45.82.103.0 - - High
140 45.87.10.0 - - High
141 45.160.4.0 - - High
142 45.160.12.0 - - High
143 45.160.72.0 - - High
144 45.160.188.0 - - High
145 45.160.212.0 - - High
146 45.161.44.0 - - High
147 45.161.108.0 - - High
148 45.161.112.0 - - High
149 45.161.188.0 - - High
150 45.162.132.0 - - High
151 45.162.184.0 - - High
152 45.162.192.0 - - High
153 45.162.208.0 - - High
154 45.165.40.0 - - High
155 45.165.168.0 - - High
156 45.166.72.0 - - High
157 45.166.144.0 - - High
158 45.167.24.0 - - High
159 45.167.192.0 - - High
160 45.168.68.0 - - High
161 45.169.54.0 - - High
162 45.169.148.0 - - High
163 45.169.163.0 wifired.cl - High
164 45.170.36.0 - - High
165 45.170.100.0 - - High
166 45.170.135.0 - - High
167 45.171.48.0 - - High
168 45.171.220.0 - - High
169 45.172.136.0 - - High
170 45.173.120.0 - - High
171 45.173.128.0 - - High
172 45.174.104.0 - - High
173 45.174.204.0 - - High
174 45.175.21.0 - - High
175 45.176.116.0 - - High
176 45.176.164.0 - - High
177 45.176.192.0 - - High
178 45.177.96.0 - - High
179 45.178.132.0 - - High
180 45.178.187.0 - - High
181 45.180.24.0 - - High
182 45.180.68.0 - - High
183 45.180.172.0 - - High
184 45.181.78.0 - - High
185 45.181.120.0 - - High
186 45.182.116.0 - - High
187 45.183.179.0 - - High
188 45.184.84.0 - - High
189 45.186.148.0 static-0.148.186.45.wipluschile.cl - High
190 45.190.16.0 - - High
191 45.191.0.0 0.0.191.45.host.as64114.com - High
192 45.191.48.0 - - High
193 45.191.100.0 - - High
194 45.194.30.0 - - High
195 45.199.158.0 - - High
196 45.224.120.0 - - High
197 45.225.43.0 - - High
198 45.225.80.0 - - High
199 45.225.92.0 - - High
200 45.225.112.0 - - High
201 45.225.132.0 - - High
202 45.225.184.0 - - High
203 45.225.204.0 undefined.hostname.localhost - High
204 45.226.168.0 0.168.226.45.ip.static.grupoz.cl - High
205 45.227.60.0 - - High
206 45.227.62.0 - - High
207 45.227.64.0 45-227-64-0.sigmainternet.com.br - High
208 45.227.131.0 - - High
209 45.227.132.0 - - High
210 45.227.176.0 - - High
211 45.228.208.0 - - High
212 45.229.136.0 - - High
213 45.229.137.0 - - High
214 45.229.188.0 - - High
215 45.229.247.0 - - High
216 45.230.21.0 - - High
217 45.230.22.0 - - High
218 45.230.36.0 - - High
219 45.230.48.0 - - High
220 45.231.48.0 - - High
221 45.232.32.0 - - High
222 45.232.92.0 - - High
223 45.232.120.0 - - High
224 45.232.176.0 - - High
225 45.232.208.0 - - High
226 45.234.156.0 m10a.fidelizador.org - High
227 45.234.224.0 - - High
228 45.235.36.0 - - High
229 45.236.88.0 - - High
230 45.236.124.0 - - High
231 45.236.128.0 - - High
232 45.236.164.0 - - High
233 45.236.174.0 - - High
234 45.236.184.0 - - High
235 45.237.132.0 - - High
236 45.237.136.0 - - High
237 45.238.20.0 - - High
238 45.238.60.0 - - High
239 45.238.152.0 host0.45.238.152.dynamic.melsat.cl - High
240 45.238.176.0 - - High
241 45.238.177.0 - - High
242 45.238.179.0 - - High
243 45.239.28.0 - - High
244 45.239.48.0 - - High
245 45.239.96.0 - - High
246 45.239.108.0 - - High
247 45.239.112.0 - - High
248 45.239.120.0 - - High
249 45.239.208.0 - - High
250 45.239.216.0 - - High
251 45.250.252.0 - - High
252 50.85.123.32 - - High
253 52.97.0.32 - - High
254 52.97.2.64 - - High
255 52.97.2.128 - - High
256 52.97.3.0 - - High
257 52.97.3.128 - - High
258 52.97.3.160 - - High
259 52.97.21.128 - - High
260 52.97.23.128 - - High
261 52.97.23.192 - - High
262 52.97.23.224 - - High
263 52.97.24.0 - - High
264 52.97.25.48 - - High
265 52.97.25.192 - - High
266 52.97.26.0 - - High
267 52.97.26.144 - - High
268 52.97.26.224 - - High
269 52.97.28.0 - - High
270 52.97.29.0 - - High
271 52.97.29.64 - - High
272 52.97.30.112 - - High
273 52.97.31.0 - - High
274 52.97.31.144 - - High
275 52.97.31.192 - - High
276 52.97.33.104 - - High
277 52.97.34.16 - - High
278 52.97.34.32 - - High
279 52.97.34.64 - - High
280 52.97.34.80 - - High
281 52.97.36.232 - - High
282 52.97.36.240 - - High
283 52.97.37.0 - - High
284 52.97.38.0 - - High
285 52.97.38.32 - - High
286 52.97.38.200 - - High
287 52.97.38.208 - - High
288 52.97.38.224 - - High
289 52.97.39.0 - - High
290 52.97.39.128 - - High
291 52.97.39.160 - - High
292 52.97.39.176 - - High
293 52.97.40.8 - - High
294 52.97.40.16 - - High
295 52.97.40.32 - - High
296 52.97.40.64 - - High
297 52.97.40.128 - - High
298 52.97.41.0 - - High
299 52.97.41.64 - - High
300 52.97.42.112 - - High
301 52.97.42.128 - - High
302 52.97.43.0 - - High
303 52.97.43.184 - - High
304 52.97.43.192 - - High
305 52.97.44.0 - - High
306 52.97.44.248 - - High
307 52.97.45.0 - - High
308 52.97.45.64 - - High
309 52.107.245.32 - - High
310 52.108.114.0 - - High
311 52.120.53.237 - - High
312 52.123.245.32 - - High
313 57.74.160.0 - - High
314 57.97.72.0 - - High
315 62.44.42.0 - - High
316 63.222.130.0 - - High
317 64.76.96.0 64-76-96-0.static.gblx.cl - High
318 64.76.136.0 - - High
319 64.76.140.0 - - High
320 64.76.142.0 - - High
321 64.76.142.128 - - High
322 64.76.142.144 - - High
323 64.76.142.152 - - High
324 64.76.142.160 - - High
325 64.76.142.192 - - High
326 64.76.143.0 - - High
327 64.76.144.0 - - High
328 64.76.160.0 64-76-160-0.static.gblx.cl - High
329 64.76.176.0 - - High
330 64.76.180.0 64-76-180-0.static.gblx.cl - High
331 64.116.8.12 0.lo0.GW4.GIA1.ALTER.NET - High
332 64.116.8.29 0.lo0.GW3.GIA1.ALTER.NET - High
333 64.116.8.30 0.lo0.BR1.GIA1.ALTER.NET - High
334 64.116.16.84 - - High
335 64.116.16.88 - - High
336 64.116.16.112 - - High
337 64.116.16.130 vrf180.GIA1.ALTER.NET - High
338 64.116.16.146 - - High
339 64.116.16.200 - - High
340 64.116.32.140 0.lo0.XT3.GIA1.ALTER.NET - High
341 64.116.40.28 - - High
342 64.116.41.80 - - High
343 64.116.41.92 - - High
344 64.116.41.96 - - High
345 64.116.192.0 - - High
346 64.116.192.64 - - High
347 64.116.192.96 - - High
348 64.116.192.112 - - High
349 64.116.192.124 - - High
350 64.116.192.128 - - High
351 64.116.193.0 - - High
352 64.116.194.0 - - High
353 64.116.195.0 - - High
354 64.116.196.0 - - High
355 64.116.199.0 - - High
356 64.116.200.0 - - High
357 64.116.208.0 - - High
358 64.116.210.0 - - High
359 ... ... ... ...

There are 1431 more IOC items available. Please use our online service to access the data.

TTP - Tactics, Techniques, Procedures

Tactics, techniques, and procedures (TTP) summarize the suspected MITRE ATT&CK techniques used by Chile Unknown. This data is unique as it uses our predictive model for actor profiling.

ID Technique Weakness Description Confidence
1 T1006 CWE-21, CWE-22, CWE-23, CWE-24, CWE-25 Pathname Traversal High
2 T1040 CWE-319 Authentication Bypass by Capture-replay High
3 T1055 CWE-74 Injection High
4 T1059 CWE-94, CWE-1321 Cross Site Scripting High
5 T1059.007 CWE-79, CWE-80 Cross Site Scripting High
6 T1068 CWE-250, CWE-264, CWE-269, CWE-284 J2EE Misconfiguration: Weak Access Permissions for EJB Methods High
7 ... ... ... ...

There are 23 more TTP items available. Please use our online service to access the data.

IOA - Indicator of Attack

These indicators of attack (IOA) list the potential fragments used for technical activities like reconnaissance, exploitation, privilege escalation, and exfiltration by Chile Unknown. This data is unique as it uses our predictive model for actor profiling.

ID Type Indicator Confidence
1 File %SYSTEMDRIVE%\node_modules\.bin\wmic.exe High
2 File /.env Low
3 File /admin/pages/edit_chicken.php High
4 File /admin/pages/student-print.php High
5 File /admin_route/inc_service_credits.php High
6 File /api/v4/teams//channels/deleted High
7 File /app/Http/Controllers/ImageController.php High
8 File /application/index/controller/Icon.php High
9 File /b2b-supermarket/shopping-cart High
10 File /cgi-bin/cstecgi.cgi High
11 File /change-language/de_DE High
12 File /debug/pprof Medium
13 File /devinfo Medium
14 File /dist/index.js High
15 File /Forms/oadmin_1 High
16 File /forum/away.php High
17 File /goform/formSysCmd High
18 File /hosts/firewall/ip High
19 File /index.php/ccm/system/file/upload High
20 File /Interface/DevManage/VM.php High
21 File /log/decodmail.php High
22 File /main/doctype.php High
23 File /nagiosxi/admin/banner_message-ajaxhelper.php High
24 File /oauth/idp/.well-known/openid-configuration High
25 File /one_church/churchprofile.php High
26 File /php/ping.php High
27 File /register.do Medium
28 File /s/index.php?action=statistics High
29 File /skyboxview-softwareupdate/services/CollectorSoftwareUpdate High
30 File /spip.php Medium
31 File /st_reg.php Medium
32 File /supplier.php High
33 File /system/role/list High
34 File /system/traceLog/page High
35 File /TMS/admin/setting/mail/createorupdate High
36 File /upload/ueditorConfig?action=config High
37 File /user/index/findpass?do=4 High
38 File /var/log/nginx High
39 File /view-pass-detail.php High
40 ... ... ...

There are 344 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.

References

The following list contains external sources which discuss the actor and the associated activities:

Literature

The following articles explain our unique predictive cyber threat intelligence:

License

(c) 1997-2024 by vuldb.com. All data on this page is shared under the license CC BY-NC-SA 4.0. Questions? Check the FAQ, read the documentation or contact us!