AMOS Analysis

IOB - Indicator of Behavior (1000)

Timeline

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Lang

en134
zh94
ru90
fr84
pl84

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Country

fr84
pl84
es84
ru82
ar82

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Actors

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Activities

Interest

Timeline

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Type

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Vendor

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Product

Tenda W15E8
MailCleaner6
Tenda i216
Microsoft Windows4
Kashipara Online Furniture Shopping Ecommerce Webs ...4

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Vulnerabilities

#VulnerabilityBaseTemp0dayTodayExpRemEPSSCTICVE
1Apryse WebViewer PDF Document cross site scripting3.53.2$0-$5k$0-$5kProof-of-ConceptOfficial Fix0.000450.00CVE-2024-4327
2MailCleaner Email os command injection9.89.3$0-$5k$0-$5kProof-of-ConceptOfficial Fix0.000460.00CVE-2024-3191
3osCommerce all-products cross site scripting4.33.9$0-$5k$0-$5kProof-of-ConceptNot Defined0.000650.07CVE-2024-4348
4MailCleaner Admin Interface cross site scripting6.56.3$0-$5k$0-$5kProof-of-ConceptOfficial Fix0.000450.00CVE-2024-3192
5SourceCodester Pisay Online E-Learning System controller.php unrestricted upload7.36.6$0-$5k$0-$5kProof-of-ConceptNot Defined0.000450.04CVE-2024-4349
6MailCleaner Admin Endpoints os command injection8.88.3$0-$5k$0-$5kProof-of-ConceptOfficial Fix0.000460.04CVE-2024-3193
7BloomPixel Max Addons Pro for Bricks Plugin authorization6.56.4$0-$5k$0-$5kNot DefinedNot Defined0.000430.08CVE-2024-32951
8Extend Themes Teluro Plugin cross-site request forgery4.34.2$0-$5k$0-$5kNot DefinedNot Defined0.000430.00CVE-2024-33688
9Apache HTTP Server mod_lua Multipart Parser r:parsebody out-of-bounds write8.58.4$25k-$100k$5k-$25kNot DefinedOfficial Fix0.088080.03CVE-2021-44790
10Elementor ImageBox Plugin cross site scripting3.53.4$0-$5k$0-$5kNot DefinedNot Defined0.000450.08CVE-2024-3074
11Dell Wyse Proprietary OS Telemetry Dashboard information disclosure4.74.7$0-$5k$0-$5kNot DefinedNot Defined0.000430.00CVE-2024-28963
12Apache Parquet Parquet-MR denial of service3.53.4$0-$5k$0-$5kNot DefinedOfficial Fix0.000890.00CVE-2021-41561
13Foliovision FV Flowplayer Video Player Plugin server-side request forgery5.65.5$0-$5k$0-$5kNot DefinedNot Defined0.000430.00CVE-2024-32955
14Dell Repository Manager API Module improper authorization8.38.1$5k-$25k$0-$5kNot DefinedOfficial Fix0.000430.04CVE-2024-28976
15Jegstudio Financio Plugin cross-site request forgery4.34.2$0-$5k$0-$5kNot DefinedNot Defined0.000430.00CVE-2024-33690
16ThemeNcode Fan Page Widget by Plugin cross site scripting4.14.1$0-$5k$0-$5kNot DefinedNot Defined0.000430.00CVE-2024-33695
17Pavex Embed Google Photos Album Plugin server-side request forgery5.65.5$0-$5k$0-$5kNot DefinedNot Defined0.000430.08CVE-2024-32775
18Apple Mac OS X Server Wiki Server sql injection5.34.6$5k-$25k$0-$5kUnprovenOfficial Fix0.003390.76CVE-2015-5911
19AnnounceKit Plugin cross site scripting2.42.4$0-$5k$0-$5kNot DefinedNot Defined0.000450.04CVE-2024-3023
20Repute Infosystems ARMember Plugin authorization7.87.7$0-$5k$0-$5kNot DefinedNot Defined0.000430.07CVE-2024-32948

IOC - Indicator of Compromise (42)

These indicators of compromise highlight associated network ressources which are known to be part of research and attack activities.

IDIP addressHostnameActorCampaignsIdentifiedTypeConfidence
15.42.64.45AMOS01/31/2024verifiedHigh
25.42.64.83AMOS04/15/2024verifiedHigh
35.42.65.55AMOS12/07/2023verifiedHigh
45.42.65.102AMOS04/15/2024verifiedHigh
55.42.65.106AMOS04/15/2024verifiedHigh
65.42.65.107AMOS02/04/2024verifiedHigh
75.42.65.108AMOS01/17/2024verifiedHigh
85.42.66.22AMOS04/15/2024verifiedHigh
95.42.67.1AMOS04/15/2024verifiedHigh
10X.XXX.XX.Xxxxxxxxx-xxxxxx.xxxx.xxxxxxxXxxx12/23/2023verifiedHigh
11X.XXX.XXX.XXXXxxx05/12/2024verifiedHigh
12XX.XX.XXX.XXXxxxxxxxxx.xxxxxxx.xxx.xxXxxx04/15/2024verifiedHigh
13XX.XX.XXX.XXXxxxxxxxxx.xxxxxxx.xxx.xxXxxx04/15/2024verifiedHigh
14XX.XXX.XX.XXxxx-xx-xxx-xx-xx.xxxxx-xxxx.xxXxxx08/15/2023verifiedHigh
15XX.XXX.XXX.XXXxxx05/07/2024verifiedHigh
16XX.XXX.XXX.X.Xxxx04/10/2024verifiedHigh
17XX.XXX.XXX.XXXxxx-xxxxxx.xxxx.xxxxxxxXxxx01/08/2024verifiedHigh
18XX.XXX.XXX.XXXxxx04/15/2024verifiedHigh
19XX.XXX.XXX.XXXxxxxxxx.xxx.xxxxxx-xxxxxx.xxxxXxxx04/15/2024verifiedHigh
20XX.XXX.XXX.XXXxxxxxxxxxx-xxxx-xxxxxx.xxxx.xxxxxxxXxxx01/18/2024verifiedHigh
21XXX.XX.XX.XXXXxxx10/29/2023verifiedHigh
22XXX.XX.XXX.XXxxxxxx.xx.xxx.xx.xxx.xxxxxxx.xxxx-xxxxxx.xxXxxx04/15/2024verifiedHigh
23XXX.XX.XX.XXXxxxx.xxxxxxxxxxxx.xxxXxxx10/15/2023verifiedHigh
24XXX.XX.XXX.XXXXxxx10/29/2023verifiedHigh
25XXX.XXX.XX.XXXXxxx09/18/2023verifiedHigh
26XXX.XXX.XXX.XXXxxx12/17/2023verifiedHigh
27XXX.XXX.XXX.XXXXxxx03/10/2024verifiedHigh
28XXX.XXX.XXX.XXXXxxx12/07/2023verifiedHigh
29XXX.XXX.XXX.XXXxxx12/15/2023verifiedHigh
30XXX.XXX.XXX.XXXXxxx09/29/2023verifiedHigh
31XXX.XXX.XXX.Xxxxxxxxxxxxxx.xxxx.xxXxxx05/14/2024verifiedHigh
32XXX.XXX.XXX.XXXXxxx05/14/2024verifiedHigh
33XXX.XXX.X.XXXxxxxxxx.xxx.xxxxxx-xxxxxx.xxxxXxxx04/15/2024verifiedHigh
34XXX.XXX.XXX.XXXxxx05/13/2024verifiedHigh
35XXX.XXX.XXX.XXXXxxx05/01/2024verifiedHigh
36XXX.XXX.XXX.XXXXxxx05/07/2024verifiedHigh
37XXX.XXX.XXX.XXXXxxx03/19/2024verifiedHigh
38XXX.XXX.XXX.XXXXxxx03/19/2024verifiedHigh
39XXX.XXX.XXX.XXXXxxx04/17/2024verifiedHigh
40XXX.XXX.XXX.XXXXxxx03/19/2024verifiedHigh
41XXX.XX.XX.XXXxxx11/16/2023verifiedHigh
42XXX.XXX.XXX.XXXXxxx10/21/2023verifiedHigh

TTP - Tactics, Techniques, Procedures (14)

Tactics, techniques, and procedures summarize the suspected MITRE ATT&CK techniques used. This data is unique as it uses our predictive model for actor profiling.

IOA - Indicator of Attack (74)

These indicators of attack list the potential fragments used for technical activities like reconnaissance, exploitation, privilege escalation, and exfiltration. This data is unique as it uses our predictive model for actor profiling.

IDClassIndicatorTypeConfidence
1File/catalog/all-productspredictiveHigh
2File/changePasswordpredictiveHigh
3File/Employee/changepassword.phppredictiveHigh
4File/goform/addIpMacBindpredictiveHigh
5File/goform/DelDhcpRulepredictiveHigh
6File/goform/delIpMacBindpredictiveHigh
7File/goform/DelPortMappingpredictiveHigh
8File/goform/modifyDhcpRulepredictiveHigh
9File/goform/modifyIpMacBindpredictiveHigh
10File/goform/setBlackRulepredictiveHigh
11File/xxxxxx/xxxxxxxxxxpredictiveHigh
12File/xxxxxx/xxxxxxxxxpredictiveHigh
13File/xxxxxx/xxxxxxxxxxxxxxxxpredictiveHigh
14File/xxxxxx/xxxxxxxxxxxxxxpredictiveHigh
15File/xxxxxx/xxxxxxxxxxxxxpredictiveHigh
16File/xxxxxx/xxxxxxxxxxxpredictiveHigh
17File/xxxxxx/xxxxxxxxxx.xxxpredictiveHigh
18File/xxxxxxxxxxx.xxx/xxxxxxxxpredictiveHigh
19File/xxxxxxxx/xxxx_xxxxxxx.xxxpredictiveHigh
20File/xxx/xxxxxxx/xxxpredictiveHigh
21File/xxxxxx-xxxxxx-xxxxxxx-xxxxxx/xxxxx/xxxxx.xxx?xxxx=xxxxxx_xxxxpredictiveHigh
22File/xxxx/xxxxxx_xxxxx_xxxxx_xxxxxx_xxxx.xxxpredictiveHigh
23File/xxxx/xxxxxxx xxxxxx/xxx/xxx_xxxx_xxxxxx.xxxpredictiveHigh
24File/xxxx/xxxx_xxxxxxxx.xxxpredictiveHigh
25File/xxxx/xxxxxxx_xxxxxxxxxx_xxxxxxxx.xxxpredictiveHigh
26File/xxxx/xxxxxxx_xxxx_xxxx_xxxxxx_xxxxx.xxxpredictiveHigh
27Filexxxxx/xxxxxxx/xxxxxxxxxxxxx.xxpredictiveHigh
28Filexxxxxxxxxxxx.xxxpredictiveHigh
29Filexxxxxxxxxxxxxxxxxxx.xxxpredictiveHigh
30Filexxxxxxx/xxxxxxxx.xxxpredictiveHigh
31Filexx/xxxxxx/xxxxxxxxxxpredictiveHigh
32Filexxxxx.xxxpredictiveMedium
33Filexxxxxx_xxxx.xxxpredictiveHigh
34Filexxxxxxxx.xxxpredictiveMedium
35Filexxxxxxxx.xxxpredictiveMedium
36Filexxxxxxxx.xxxpredictiveMedium
37Filexxxxxxxxxxxxxxx.xxxpredictiveHigh
38Filexxxxxxx_xxxxxxxx.xxxpredictiveHigh
39Argumentxxxxx_xxxxxpredictiveMedium
40ArgumentxxxxxxxxxxxxxpredictiveHigh
41ArgumentxxxpredictiveLow
42ArgumentxxxxxxxxxpredictiveMedium
43ArgumentxxxxxxxxxxxxpredictiveMedium
44ArgumentxxxxxxxxxxpredictiveMedium
45ArgumentxxxxxxxpredictiveLow
46Argumentxxxxx_xxxpredictiveMedium
47ArgumentxxxxpredictiveLow
48ArgumentxxxxxxxxxxxxxxxxxxxxxxpredictiveHigh
49Argumentxx/xxxxpredictiveLow
50ArgumentxxxxxpredictiveLow
51ArgumentxxxxxxxpredictiveLow
52ArgumentxxpredictiveLow
53ArgumentxxpredictiveLow
54ArgumentxxxxxxxxxxxxxxpredictiveHigh
55ArgumentxxxxxxxxxxxxxpredictiveHigh
56Argumentxxxxxxxxxxxxxxx/xxxxxxxxxxxxxxx/xxxxxxxxxxxxxxxx/xxxxxxxxxxxxxxxxxxxpredictiveHigh
57ArgumentxxxxxxxxxxpredictiveMedium
58ArgumentxxxxxxxxxxxxpredictiveMedium
59Argumentxx_xxxxxx_xxxxxxxxxxxxpredictiveHigh
60ArgumentxxxxpredictiveLow
61ArgumentxxxxpredictiveLow
62ArgumentxxxxxxxxxxxxxxxxpredictiveHigh
63Argumentxxxxxxx_xxxxxxx_xxxxx_xxxxx_xxxxxpredictiveHigh
64ArgumentxxxxxxpredictiveLow
65ArgumentxxxxxxxxpredictiveMedium
66ArgumentxxxxxxxxxxxxxxxxxxpredictiveHigh
67Argumentxxxxxxxxxx/xxxxxxxx/xxxxxxx/xxxxxxxxxxpredictiveHigh
68ArgumentxxxxxxxxxpredictiveMedium
69ArgumentxxxxxxxxxxxxxxxxpredictiveHigh
70ArgumentxxxxpredictiveLow
71ArgumentxxxxxxxxxxpredictiveMedium
72Argumentxxxxxx_xxxxxxxx/xxxxxx_xxxxxxxx/xxxxxxxxxx_xxxxxxxxpredictiveHigh
73ArgumentxxxxpredictiveLow
74Argumentxxxx/xxxxx/xxx/xxxx/xxxxxx/xxxxxxpredictiveHigh

References (14)

The following list contains external sources which discuss the actor and the associated activities:

Samples (11)

The following list contains associated samples:

Are you interested in using VulDB?

Download the whitepaper to learn more about our service!