ObserverStealer Analysis

IOB - Indicator of Behavior (155)

Timeline

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Lang

en132
ru14
it4
zh2
pl2

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Country

us132
it2

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Actors

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Activities

Interest

Timeline

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Type

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Vendor

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Product

Reality Medias Phpizabi2
WordPress2
Francisco Burzi PHP-Nuke2
PHP Scripts Mall Multi Language Olx Clone Script2
RealFaviconGenerator Favicon Plugin2

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Vulnerabilities

#VulnerabilityBaseTemp0dayTodayExpRemEPSSCTICVE
1Indexu suggest_category.php cross site scripting3.53.5$0-$5k$0-$5kNot DefinedNot Defined0.000000.06
2Citrix NetScaler ADC/NetScaler Gateway OpenID openid-configuration ns_aaa_oauthrp_send_openid_config CitrixBleed memory corruption8.38.2$25k-$100k$0-$5kHighOfficial Fix0.966680.04CVE-2023-4966
3Joomla CMS com_easyblog sql injection6.36.1$5k-$25k$5k-$25kNot DefinedNot Defined0.000000.37
4TikiWiki tiki-register.php input validation7.36.6$0-$5k$0-$5kProof-of-ConceptOfficial Fix0.010758.76CVE-2006-6168
5DZCP deV!L`z Clanportal config.php code injection7.36.6$0-$5k$0-$5kProof-of-ConceptOfficial Fix0.009430.49CVE-2010-0966
6PHP Link Directory Administration Page index.html cross site scripting4.34.3$0-$5k$0-$5kNot DefinedNot Defined0.003740.25CVE-2007-0529
7PHPizabi index.php path traversal6.55.7$0-$5k$0-$5kUnprovenUnavailable0.008260.12CVE-2008-3723
8SPIP spip.php cross site scripting3.53.4$0-$5k$0-$5kNot DefinedOfficial Fix0.001320.46CVE-2022-28959
9RealFaviconGenerator Favicon Plugin class-favicon-by-realfavicongenerator-admin.php install_new_favicon cross-site request forgery5.85.7$0-$5k$0-$5kNot DefinedOfficial Fix0.002360.18CVE-2015-10116
10Intelliants eSyndiCat suggest-category.php cross site scripting4.34.3$0-$5k$0-$5kNot DefinedNot Defined0.002570.04CVE-2010-4504
11LogicBoard CMS away.php redirect6.36.1$0-$5k$0-$5kNot DefinedUnavailable0.000001.84
12PHP Scripts Mall Multi Language Olx Clone Script cross site scripting5.24.7$0-$5k$0-$5kProof-of-ConceptNot Defined0.001150.02CVE-2018-6845
13DZCP Witze Addon index.php sql injection7.37.3$0-$5k$0-$5kHighUnavailable0.002610.05CVE-2012-5000
14Storytlr cross site scripting4.34.3$0-$5k$0-$5kNot DefinedNot Defined0.001340.09CVE-2014-100037
15YaBB cross site scripting3.53.4$0-$5k$0-$5kNot DefinedOfficial Fix0.001720.04CVE-2005-4426
16YaBB yabb.pl cross site scripting4.34.1$0-$5k$0-$5kProof-of-ConceptNot Defined0.012400.04CVE-2004-2402
17Reality Medias Phpizabi File Upload image.php access control10.09.4$0-$5k$0-$5kProof-of-ConceptNot Defined0.018940.08CVE-2008-0805
18Adobe ColdFusion Authentication credentials management5.65.4$0-$5k$0-$5kHighOfficial Fix0.861850.00CVE-2013-0625
19TCL 30Z/10 access control5.35.3$0-$5k$0-$5kNot DefinedNot Defined0.000430.05CVE-2023-38295
20git-ecosystem git-credential-manager permission assignment5.35.3$0-$5k$0-$5kNot DefinedOfficial Fix0.000430.00CVE-2024-32478

IOC - Indicator of Compromise (4)

These indicators of compromise highlight associated network ressources which are known to be part of research and attack activities.

TTP - Tactics, Techniques, Procedures (10)

Tactics, techniques, and procedures summarize the suspected MITRE ATT&CK techniques used. This data is unique as it uses our predictive model for actor profiling.

IOA - Indicator of Attack (46)

These indicators of attack list the potential fragments used for technical activities like reconnaissance, exploitation, privilege escalation, and exfiltration. This data is unique as it uses our predictive model for actor profiling.

IDClassIndicatorTypeConfidence
1File/forum/away.phppredictiveHigh
2File/oauth/idp/.well-known/openid-configurationpredictiveHigh
3File/settings/accountpredictiveHigh
4File/spip.phppredictiveMedium
5File/userLogin.asppredictiveHigh
6Fileadmin.php3predictiveMedium
7Filexxxxx/xxxxx-xxxxxxx-xx-xxxxxxxxxxxxxxxxxxxx-xxxxx.xxxpredictiveHigh
8Filexxx_xxxxxxxxx.xxxpredictiveHigh
9Filexxxxx.xxxpredictiveMedium
10Filexxxxx.xxxpredictiveMedium
11Filexxx/xxxxxx.xxxpredictiveHigh
12Filexxx/xxxxxxxxxxx/xxxxxxx.xxxpredictiveHigh
13Filexxxxx.xxxxpredictiveMedium
14Filexxxxx.xxxpredictiveMedium
15Filexxxxx.xxx/xxxxxxxxx_xxxx/xxx_xxxxxxx_xxxxxxxxxx/predictiveHigh
16Filexxxxxxxxxxxxx.xxxpredictiveHigh
17Filexxxxx/xxxxx.xxxpredictiveHigh
18Filexxx_xxxx.xxxpredictiveMedium
19Filexxxxxxxx/xxxxx/xxxxxxxx?xxxxxxxxpredictiveHigh
20Filexxxxxxxxxx_xxxxx.xxxxxxpredictiveHigh
21Filexxxxxxx-xxxxxxxx.xxxpredictiveHigh
22Filexxxxxxx-xxxxxxx.xxxpredictiveHigh
23Filexxxxxxx_xxxxxxxx.xxxpredictiveHigh
24Filexxxx-xxxxx.xxxpredictiveHigh
25Filexxxx-xxxxxxxx.xxxpredictiveHigh
26Filexxxxx/xx_xxxx.xpredictiveHigh
27Filexx-xxxxxxxx/xxxxx-xx-xxxxxx-xxxxxx.xxxpredictiveHigh
28Filexxxxxx.xxxpredictiveMedium
29Filexxxx.xxpredictiveLow
30Filexxxxxxxxxxxx.xxxpredictiveHigh
31Argumentxxx/xxxpredictiveLow
32ArgumentxxxxxxxxpredictiveMedium
33ArgumentxxxxxpredictiveLow
34ArgumentxxxxxxxpredictiveLow
35ArgumentxxxxxxxpredictiveLow
36ArgumentxxxxxpredictiveLow
37Argumentxxxxx_xxxpredictiveMedium
38ArgumentxxxxpredictiveLow
39ArgumentxxxxxxxxpredictiveMedium
40Argumentxxxxxx_xxxpredictiveMedium
41ArgumentxxpredictiveLow
42Argumentxxxxxxx_xxpredictiveMedium
43Argumentxx_xxxxpredictiveLow
44ArgumentxxxxxxpredictiveLow
45ArgumentxxxxxpredictiveLow
46Input Valuexxxxxxxxxxxxxxxxxxxxxxxxxxxx+xxxxx+xxxxxx+x,x,xxxx,xxx,x,x+xxxx+xxx_xxxxx+xxxxx+xx=x--+predictiveHigh

References (3)

The following list contains external sources which discuss the actor and the associated activities:

Do you need the next level of professionalism?

Upgrade your account now!