APT1 Analysis

IOB - Indicator of Behavior (82)

Timeline

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Lang

en62
zh16
sv2
ko2

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Country

cn32
us26
il14
gb2

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Actors

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Activities

Interest

Timeline

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Type

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Vendor

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Product

Google Android10
Juniper IVE OS4
DeDeCMS4
Cisco Identity Services Engine2
Fortinet FortiOS2

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Vulnerabilities

#VulnerabilityBaseTemp0dayTodayExpRemEPSSCTICVE
1Micrium uC-HTTP HTTP Request heap-based overflow8.78.7$1k-$2k$2k-$5kNot DefinedNot Defined0.004640.00CVE-2022-24942
2Sangfor Sundray WLAN Controller SSH Service hard-coded credentials9.89.7$2k-$5k$0-$1kNot DefinedWorkaround0.012180.03CVE-2019-9160
3ZZZCMS zzzphp File Upload unrestricted upload7.47.4$1k-$2k$0-$1kNot DefinedNot Defined0.000900.00CVE-2019-16720
4Cisco RV340/RV340W/RV345/RV345P SSL VPN input validation8.58.2$10k-$25k$0-$1kNot DefinedOfficial Fix0.002660.02CVE-2020-3357
5Microsoft Internet Explorer Scripting Engine JScript.dll memory corruption7.17.0$25k-$50k$10k-$25kHighOfficial Fix0.093480.00CVE-2018-8653
6thttpd WebService information disclosure5.35.0$2k-$5k$0-$1kProof-of-ConceptNot Defined0.000000.00
7Babel Traverse incomplete blacklist7.87.7$0-$1k$0-$1kNot DefinedOfficial Fix0.000600.00CVE-2023-45133
8HP Business Availability Center cross-site request forgery6.36.3$10k-$25k$1k-$2kNot DefinedNot Defined0.001390.00CVE-2012-3256
9Hikvision Intercom Broadcasting System ping.php os command injection7.57.3$1k-$2k$0-$1kProof-of-ConceptOfficial Fix0.901600.00CVE-2023-6895
10Google Android Integer Overflow fdt.c fdt_next_tag out-of-bounds write5.45.3$10k-$25k$2k-$5kNot DefinedOfficial Fix0.000430.00CVE-2023-21065
11Google Android p2p_iface.cpp out-of-bounds3.33.3$5k-$10k$0-$1kNot DefinedOfficial Fix0.000420.00CVE-2023-21011
12Google Android HWC2.cpp setPowerMode out-of-bounds4.03.9$10k-$25k$1k-$2kNot DefinedOfficial Fix0.000420.00CVE-2023-21031
13Google Android dhd_msgbuf.c dhd_prot_ioctcmplt_process out-of-bounds write5.45.3$10k-$25k$2k-$5kNot DefinedOfficial Fix0.000420.00CVE-2023-21071
14Google Android Debug Policy Local Privilege Escalation6.56.4$10k-$25k$2k-$5kNot DefinedOfficial Fix0.000420.00CVE-2023-21068
15Google Android WifiManager.java addNetwork resource consumption6.05.9$25k-$50k$5k-$10kNot DefinedOfficial Fix0.000420.03CVE-2023-21033
16Google Android simdata.cpp ParseWithAuthType out-of-bounds4.54.4$5k-$10k$0-$1kNot DefinedOfficial Fix0.000420.00CVE-2023-21063
17Mozilla Firefox Notification unknown vulnerability5.45.2$25k-$50k$5k-$10kNot DefinedOfficial Fix0.000650.00CVE-2023-28159
18Google Android ufdt_convert.c _ufdt_output_node_to_fdt out-of-bounds3.33.3$5k-$10k$0-$1kNot DefinedOfficial Fix0.000420.00CVE-2023-21032
19Google Android ih264e_process.c ih264e_init_proc_ctxt out-of-bounds4.44.3$10k-$25k$1k-$2kNot DefinedOfficial Fix0.000420.00CVE-2023-21019

Campaigns (2)

These are the campaigns that can be associated with the actor:

IOC - Indicator of Compromise (75)

These indicators of compromise highlight associated network ressources which are known to be part of research and attack activities.

IDIP addressHostnameActorCampaignsIdentifiedTypeConfidence
123.236.62.147147.62.236.23.bc.googleusercontent.comAPT106/05/2021verifiedMedium
227.102.112.179APT1Oceansalt12/11/2020verifiedHigh
358.246.0.0APT1Mandiant12/13/2020verifiedHigh
458.247.0.0APT1Mandiant12/13/2020verifiedHigh
567.222.16.131host.dnsweb.orgAPT106/05/2021verifiedHigh
6100.42.216.230tfs2480.sipnav.inAPT112/11/2020verifiedHigh
7101.80.0.0APT1Mandiant02/25/2022verifiedHigh
8101.81.0.0APT1Mandiant02/25/2022verifiedHigh
9101.82.0.0APT1Mandiant02/25/2022verifiedHigh
10101.83.0.0APT1Mandiant02/25/2022verifiedHigh
11101.84.0.0APT1Mandiant02/25/2022verifiedHigh
12101.85.0.0APT1Mandiant02/25/2022verifiedHigh
13101.86.0.0APT1Mandiant02/25/2022verifiedHigh
14101.87.0.0APT1Mandiant02/25/2022verifiedHigh
15101.88.0.0APT1Mandiant02/25/2022verifiedHigh
16XXX.XX.X.XXxxxXxxxxxxx02/25/2022verifiedHigh
17XXX.XX.X.XXxxxXxxxxxxx02/25/2022verifiedHigh
18XXX.XX.X.XXxxxXxxxxxxx02/25/2022verifiedHigh
19XXX.XX.X.XXxxxXxxxxxxx02/25/2022verifiedHigh
20XXX.XX.X.XXxxxXxxxxxxx02/25/2022verifiedHigh
21XXX.XX.X.XXxxxXxxxxxxx02/25/2022verifiedHigh
22XXX.XX.X.XXxxxXxxxxxxx02/25/2022verifiedHigh
23XXX.XX.XXX.XXXXxxx06/05/2021verifiedHigh
24XXX.XX.XX.XXXxxx06/05/2021verifiedHigh
25XXX.XX.X.XXxxxXxxxxxxx02/25/2022verifiedHigh
26XXX.XX.X.XXxxxXxxxxxxx02/25/2022verifiedHigh
27XXX.XX.X.XXxxxXxxxxxxx02/25/2022verifiedHigh
28XXX.XX.X.XXxxxXxxxxxxx02/25/2022verifiedHigh
29XXX.XX.X.XXxxxXxxxxxxx02/25/2022verifiedHigh
30XXX.XX.X.XXxxxXxxxxxxx02/25/2022verifiedHigh
31XXX.XX.X.XXxxxXxxxxxxx02/25/2022verifiedHigh
32XXX.XX.X.XXxxxXxxxxxxx02/25/2022verifiedHigh
33XXX.XX.X.XXxxxXxxxxxxx02/25/2022verifiedHigh
34XXX.XX.X.XXxxxXxxxxxxx02/25/2022verifiedHigh
35XXX.XX.X.XXxxxXxxxxxxx02/25/2022verifiedHigh
36XXX.XX.X.XXxxxXxxxxxxx02/25/2022verifiedHigh
37XXX.XX.X.XXxxxXxxxxxxx02/25/2022verifiedHigh
38XXX.XX.X.XXxxxXxxxxxxx02/25/2022verifiedHigh
39XXX.XX.X.XXxxxXxxxxxxx02/25/2022verifiedHigh
40XXX.XX.X.XXxxxXxxxxxxx02/25/2022verifiedHigh
41XXX.XX.X.XXxxxXxxxxxxx02/25/2022verifiedHigh
42XXX.XX.X.XXxxxXxxxxxxx02/25/2022verifiedHigh
43XXX.XXX.X.XXxxxXxxxxxxx02/25/2022verifiedHigh
44XXX.XXX.X.XXxxxXxxxxxxx02/25/2022verifiedHigh
45XXX.XXX.X.XXxxxXxxxxxxx02/25/2022verifiedHigh
46XXX.XXX.X.XXxxxXxxxxxxx02/25/2022verifiedHigh
47XXX.XXX.X.XXxxxXxxxxxxx02/25/2022verifiedHigh
48XXX.XXX.X.XXxxxXxxxxxxx02/25/2022verifiedHigh
49XXX.XXX.X.XXxxxXxxxxxxx02/25/2022verifiedHigh
50XXX.XXX.X.XXxxxXxxxxxxx02/25/2022verifiedHigh
51XXX.XXX.X.XXxxxXxxxxxxx02/25/2022verifiedHigh
52XXX.XXX.X.XXxxxXxxxxxxx02/25/2022verifiedHigh
53XXX.XXX.X.XXxxxXxxxxxxx02/25/2022verifiedHigh
54XXX.XXX.X.XXxxxXxxxxxxx02/25/2022verifiedHigh
55XXX.XXX.X.XXxxxXxxxxxxx02/25/2022verifiedHigh
56XXX.XXX.X.XXxxxXxxxxxxx02/25/2022verifiedHigh
57XXX.XXX.X.XXxxxXxxxxxxx02/25/2022verifiedHigh
58XXX.XXX.X.XXxxxXxxxxxxx02/25/2022verifiedHigh
59XXX.XXX.X.XXxxxXxxxxxxx02/25/2022verifiedHigh
60XXX.XX.X.XXxxxXxxxxxxx02/25/2022verifiedHigh
61XXX.XX.XXX.XXxxxx.xx-xxx-xx-xxx.xxxXxxxXxxxxxxxx12/11/2020verifiedHigh
62XXX.XX.XXX.XXxx-xxx-xx-xxx-xx.xxxx.xxxxxxxxx.xxxXxxxXxxxxxxxx12/11/2020verifiedHigh
63XXX.XXX.XXX.XXXXxxxXxxxxxxxx12/11/2020verifiedHigh
64XXX.XX.X.Xx.x.xx.xxx.xxxxx.xx.xx.xxxxxxx.xxxxxxx.xxx.xxXxxxXxxxxxxx02/25/2022verifiedHigh
65XXX.XX.X.Xx.x.xx.xxx.xxxxx.xx.xx.xxxxxxx.xxxxxxx.xxx.xxXxxxXxxxxxxx02/25/2022verifiedHigh
66XXX.XX.X.XXxxxXxxxxxxx02/25/2022verifiedHigh
67XXX.XX.X.Xx.x.xx.xxx.xxxxx.xx.xx.xxxxxxx.xxxxxxx.xxx.xxXxxxXxxxxxxx02/25/2022verifiedHigh
68XXX.XX.X.XXxxxXxxxxxxx02/25/2022verifiedHigh
69XXX.XX.X.XXxxxXxxxxxxx02/25/2022verifiedHigh
70XXX.XX.X.Xx.x.xx.xxx.xxxxx.xx.xx.xxxxxxx.xxxxxxx.xxx.xxXxxxXxxxxxxx02/25/2022verifiedHigh
71XXX.XX.X.Xx.x.xx.xxx.xxxxx.xx.xx.xxxxxxx.xxxxxxx.xxx.xxXxxxXxxxxxxx02/25/2022verifiedHigh
72XXX.XX.X.XXxxxXxxxxxxx02/25/2022verifiedHigh
73XXX.XX.X.XXxxxXxxxxxxx02/25/2022verifiedHigh
74XXX.XXX.X.XXxxxXxxxxxxx12/13/2020verifiedHigh
75XXX.XXX.X.XXxxxXxxxxxxx12/13/2020verifiedHigh

TTP - Tactics, Techniques, Procedures (12)

Tactics, techniques, and procedures summarize the suspected MITRE ATT&CK techniques used. This data is unique as it uses our predictive model for actor profiling.

IOA - Indicator of Attack (39)

These indicators of attack list the potential fragments used for technical activities like reconnaissance, exploitation, privilege escalation, and exfiltration. This data is unique as it uses our predictive model for actor profiling.

IDClassIndicatorTypeConfidence
1File/api/uploadpredictiveMedium
2File/php/ping.phppredictiveHigh
3File/public/plugins/predictiveHigh
4File/systemrw/predictiveMedium
5Fileadm/boardgroup_form_update.phppredictiveHigh
6Filexxxxx/xxxxxxx/xxxxxxxxxxpredictiveHigh
7Filexxxxxxx.xpredictiveMedium
8Filexxx_xxxxxx.xpredictiveMedium
9Filexxx.xpredictiveLow
10Filexxxx.xxxpredictiveMedium
11Filexxxxxx_xxxxxxx.xpredictiveHigh
12Filexxxxx_xx.xxxxpredictiveHigh
13Filexxx_xxxxx_xxx.xxxpredictiveHigh
14Filexxxxxxx.xxxpredictiveMedium
15Filexxx_xxxxx.xxxpredictiveHigh
16Filexxxxxxx/xxxxxxx/xxx/xxxxxxxxxx.xxx?xxxxxxxx=xxxx&xxxxxx=xxxxxxxxxxpredictiveHigh
17Filexxxx/xxxxxx.xxxpredictiveHigh
18Filexxx.xpredictiveLow
19Filexxxxxxx.xxxpredictiveMedium
20Filexxxx_xxxxxxx.xpredictiveHigh
21Filexxxxxxx/xxxxxxx/xxxxxx/xxxxxx_xxxxxx_xxxx.xxxpredictiveHigh
22Filexxxxxxxxxxx.xxxxpredictiveHigh
23Filexx-xxxxxxxx/xxxxx.xxxpredictiveHigh
24Filexx/xxxxxx.xxxpredictiveHigh
25Library/xxx/xxx/xxx/xxxx/xxxxxxxxxx/xxxxx/xxxxxxxxxx.xxxpredictiveHigh
26Libraryxxxxxxx.xxxpredictiveMedium
27Argumentxxxxx_xxpredictiveMedium
28ArgumentxxxxxxxxxxxpredictiveMedium
29Argumentxx_x~xxpredictiveLow
30ArgumentxxxxxpredictiveLow
31Argumentxxxxxxxx[xx]predictiveMedium
32Argumentxxxxx_xxxxpredictiveMedium
33ArgumentxxxxxxxxpredictiveMedium
34ArgumentxxxxxxxxpredictiveMedium
35ArgumentxxxxpredictiveLow
36Input Valuexxxx.xxx::$xxxxpredictiveHigh
37Input Valuexxxxxxx -xxxpredictiveMedium
38Network Portxxx/xxxxpredictiveMedium
39Network Portxxx/xxxxxpredictiveMedium

References (5)

The following list contains external sources which discuss the actor and the associated activities:

Do you need the next level of professionalism?

Upgrade your account now!