UAC-0010 Analysis

IOB - Indicator of Behavior (12)

Timeline

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Lang

en12

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Country

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Actors

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Activities

Interest

Timeline

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Type

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Vendor

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Product

Apache HTTP Server2
Better Search Replace Plugin2
Redis Hyperloglog Data Structure2
PHP2
Fortra GoAnywhere MFT2

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Vulnerabilities

IOC - Indicator of Compromise (171)

These indicators of compromise highlight associated network ressources which are known to be part of research and attack activities.

IDIP addressHostnameActorCampaignsIdentifiedTypeConfidence
15.44.42.130uaeser-1672132036.4server.ioUAC-001003/20/2024verifiedHigh
25.44.42.137uaeser-1672132036.4server.ioUAC-001003/20/2024verifiedHigh
35.44.42.144UAC-001003/20/2024verifiedHigh
45.44.42.145UAC-001003/20/2024verifiedHigh
55.44.42.1894vps-ae-01.ip-ptr.techUAC-001003/20/2024verifiedHigh
65.44.42.198uaetest.ip-ptr.techUAC-001003/20/2024verifiedHigh
75.44.42.203UAC-001003/20/2024verifiedHigh
85.44.42.204hostera-ae.ip-ptr.techUAC-001003/20/2024verifiedHigh
924.199.102.96UAC-001003/20/2024verifiedHigh
1024.199.106.158UAC-001003/20/2024verifiedHigh
1131.129.22.88kfgb-kz-mail.ip-ptr.techUAC-001003/20/2024verifiedHigh
1231.129.22.89pt01.ip-ptr.techUAC-001003/20/2024verifiedHigh
1331.129.22.94portugaliya.ip-ptr.techUAC-001003/20/2024verifiedHigh
1431.129.22.95portugaliya.ip-ptr.techUAC-001003/20/2024verifiedHigh
1531.129.22.98pr-2.ip-ptr.techUAC-001003/20/2024verifiedHigh
1631.129.22.99pt-11-sep-1.ip-ptr.techUAC-001003/20/2024verifiedHigh
1731.129.22.100v408sktl0uv.servera.infoUAC-001003/20/2024verifiedHigh
1831.129.22.101UAC-001003/20/2024verifiedHigh
1931.129.22.102ptser-1671619506.4server.ioUAC-001003/20/2024verifiedHigh
2031.129.22.105UAC-001003/20/2024verifiedHigh
2145.61.138.226UAC-001010/10/2022verifiedHigh
2245.61.139.22UAC-001010/10/2022verifiedHigh
2345.77.196.21145.77.196.211.vultrusercontent.comUAC-001010/10/2022verifiedHigh
2445.77.237.25245.77.237.252.vultrusercontent.comUAC-001010/10/2022verifiedHigh
2545.82.13.55new-98.ip-ptr.techUAC-001003/20/2024verifiedHigh
2645.82.13.604s-4-tg-1706753462.ip-ptr.techUAC-001003/20/2024verifiedHigh
2745.82.13.864s-4-tg-1699346951.ip-ptr.techUAC-001003/20/2024verifiedHigh
2845.95.232.102900dsw2.ip-ptr.techUAC-001003/20/2024verifiedHigh
2945.95.232.147ch-27_nov__2.ip-ptr.techUAC-001003/20/2024verifiedHigh
3045.95.232.151cisco-18-alma.msk.hostUAC-001003/20/2024verifiedHigh
3145.95.233.145fr-w8mchcwusxpkaym2.ip-ptr.techUAC-001003/20/2024verifiedHigh
3245.95.233.161alihanfranc.ip-ptr.techUAC-001003/20/2024verifiedHigh
3345.95.233.163fr-30-oct_2.ip-ptr.techUAC-001003/20/2024verifiedHigh
3446.29.234.95lvser.ip-ptr.techUAC-001003/20/2024verifiedHigh
3546.29.234.99litvatazestar.ip-ptr.techUAC-001003/20/2024verifiedHigh
36XX.XX.XXX.XXXxxxxxxx.xx-xxx.xxxxXxx-xxxx03/20/2024verifiedHigh
37XX.XX.XX.XXXxx.xx.xx.xxx.xxxxxxxxxxxxxxxx.xxxXxx-xxxx07/21/2022verifiedHigh
38XX.XX.XXX.XXxx.xx.xxx.xx.xxxxxxxxxxxxxxxx.xxxXxx-xxxx10/10/2022verifiedHigh
39XX.XXX.XXX.XXXxx-xxx-xxx-xxx.xx.xxxxxxxxxxxxxxxxx.xxxXxx-xxxx07/21/2022verifiedHigh
40XX.XXX.XXX.XXXxxxxxxx.xxxxxxxxxxxxx.xxxXxx-xxxx03/20/2024verifiedHigh
41XX.XXX.XXX.XXXXxx-xxxx03/20/2024verifiedHigh
42XX.XX.XXX.XXXxx.xx.xxx.xxx.xxxxxxxxxxxxxxxx.xxxXxx-xxxx10/10/2022verifiedHigh
43XX.XXX.XXX.XXxxxxxxxx.xxxxxx-xx-xxxxxx.xxXxx-xxxx03/20/2024verifiedHigh
44XX.XXX.XXX.XXXxxxxxxxx.xxxxxx-xx-xxxxxx.xxXxx-xxxx03/20/2024verifiedHigh
45XX.XXX.XXX.XXXxxxxxxxx.xxxxxx-xx-xxxxxx.xxXxx-xxxx03/20/2024verifiedHigh
46XX.XXX.XXX.XXxxxx-xx-xxx-xxx-xx.xxxxxx-xx-xxxxxx.xxXxx-xxxx03/20/2024verifiedHigh
47XX.XXX.XXX.XXXxxxxxxxx.xxxxxx-xx-xxxxxx.xxXxx-xxxx03/20/2024verifiedHigh
48XX.XXX.XXX.XXXxxxx.xx-xxx.xxxxXxx-xxxx03/20/2024verifiedHigh
49XX.XXX.XXX.XXXxxxxxx.xx-xxx.xxxxXxx-xxxx03/20/2024verifiedHigh
50XX.XXX.XXX.XXXxxx_xx_x_x.xx-xxx.xxxxXxx-xxxx03/20/2024verifiedHigh
51XX.XX.XXX.XXXxxxxx-xxxxxxxxxx.xxxxxxx.xxXxx-xxxx03/20/2024verifiedHigh
52XX.XXX.XXX.XXXxx-xxxx03/20/2024verifiedHigh
53XX.XXX.XXX.XXxxxxxxx-xxxxxxx.xx-xxx.xxxxXxx-xxxx03/20/2024verifiedHigh
54XX.XX.XXX.XXXXxx-xxxx03/20/2024verifiedHigh
55XX.XX.XXX.XXxxxxxxxxxx.xx-xxx.xxxxXxx-xxxx03/20/2024verifiedHigh
56XX.XX.XXX.XXxx-xxxx.xx-xxx.xxxxXxx-xxxx03/20/2024verifiedHigh
57XX.XX.XXX.XXXxxx-x-x_x.xx-xxx.xxxxXxx-xxxx03/20/2024verifiedHigh
58XX.XXX.XX.XXxx_xxxx.xx-xxx.xxxxXxx-xxxx03/20/2024verifiedHigh
59XX.XXX.XX.XXXxxxxx.xxxXxx-xxxx03/20/2024verifiedHigh
60XX.XXX.XX.XXXxxx.xx-xxx.xxxxXxx-xxxx03/20/2024verifiedHigh
61XX.XXX.XX.XXXxxxxx.xx-xxx.xxxxXxx-xxxx03/20/2024verifiedHigh
62XX.XXX.XX.XXXxxxxx.xx-xxx.xxxxXxx-xxxx03/20/2024verifiedHigh
63XX.XXX.XX.XXXxxxx_x.xx-xxx.xxxxXxx-xxxx03/20/2024verifiedHigh
64XX.XXX.XX.XXXxxxx_xx.xx-xxx.xxxxXxx-xxxx03/20/2024verifiedHigh
65XX.XXX.XX.XXXxxxxxx.xx-xxx.xxxxXxx-xxxx03/20/2024verifiedHigh
66XX.XXX.XX.XXXxx-x.xx-xxx.xxxxXxx-xxxx03/20/2024verifiedHigh
67XX.XXX.XX.XXXxx-x.xx-xxx.xxxxXxx-xxxx03/20/2024verifiedHigh
68XX.XXX.XXX.XXXxxxxxxxx.xxxxxx-xx-xxxxxx.xxXxx-xxxx03/20/2024verifiedHigh
69XX.XX.XXX.XXXxxxxxxxx.xxxxxxx.xxXxx-xxxx07/21/2022verifiedHigh
70XXX.XXX.XXX.XXXxx-xxxx03/20/2024verifiedHigh
71XXX.XXX.XX.XXxxxxxxxx.xxxxxx-xx-xxxxxx.xxXxx-xxxx03/20/2024verifiedHigh
72XXX.XXX.XXX.XXXXxx-xxxx03/20/2024verifiedHigh
73XXX.XXX.XX.XXXxxxxxxx.xxxx-xx-xxxxxXxx-xxxx03/20/2024verifiedHigh
74XXX.XXX.XXX.XXXXxx-xxxx10/10/2022verifiedHigh
75XXX.XX.XXX.XXXXxx-xxxx10/10/2022verifiedHigh
76XXX.XX.XXX.XXxxxxxxx.xx-xxx.xxxxXxx-xxxx03/20/2024verifiedHigh
77XXX.XX.XXX.XXXxxxxxxxxxx.xx-xxx.xxxxXxx-xxxx03/20/2024verifiedHigh
78XXX.XX.XXX.XXXxxxxxxxx.xx-xxx.xxxxXxx-xxxx03/20/2024verifiedHigh
79XXX.XX.XXX.XXXxxxxxxxx.xx-xxx.xxxxXxx-xxxx03/20/2024verifiedHigh
80XXX.XX.XXX.XXXxxxxxxxxxx.xx-xxx.xxxxXxx-xxxx03/20/2024verifiedHigh
81XXX.XXX.XX.XXXxx-xxxx03/20/2024verifiedHigh
82XXX.XXX.XXX.XXXxx-xxxx03/20/2024verifiedHigh
83XXX.XXX.XX.XXXxxx.xxx.xx.xxx.xxxxxxxxxxxxxxxx.xxxXxx-xxxx10/10/2022verifiedHigh
84XXX.XXX.XXX.XXXxx-xxxx03/20/2024verifiedHigh
85XXX.XXX.XXX.XXXXxx-xxxx03/20/2024verifiedHigh
86XXX.XXX.XXX.XXXXxx-xxxx03/20/2024verifiedHigh
87XXX.XXX.XXX.XXXXxx-xxxx03/20/2024verifiedHigh
88XXX.XXX.XX.XXxxx.xxx.xx.xx.xxxxxxxxxxxxxxxx.xxxXxx-xxxx07/21/2022verifiedHigh
89XXX.XXX.XXX.XXXXxx-xxxx03/20/2024verifiedHigh
90XXX.XXX.XX.XXXXxx-xxxx10/10/2022verifiedHigh
91XXX.XXX.XX.XXXxx-xxxx10/10/2022verifiedHigh
92XXX.XXX.XX.XXXXxx-xxxx03/20/2024verifiedHigh
93XXX.XXX.XX.XXXxx-xxxx03/20/2024verifiedHigh
94XXX.XX.XX.XXXXxx-xxxx03/20/2024verifiedHigh
95XXX.XX.XX.XXXXxx-xxxx03/20/2024verifiedHigh
96XXX.XXX.XXX.XXXxxxxxxx.xxxxxxxxxxxxx.xxxXxx-xxxx03/20/2024verifiedHigh
97XXX.XXX.XXX.XXXXxx-xxxx03/20/2024verifiedHigh
98XXX.XXX.XXX.XXXXxx-xxxx03/20/2024verifiedHigh
99XXX.XX.XXX.XXXxx-xxxx03/20/2024verifiedHigh
100XXX.XXX.XX.XXXXxx-xxxx03/20/2024verifiedHigh
101XXX.XXX.XX.XXXXxx-xxxx10/10/2022verifiedHigh
102XXX.XXX.XX.XXXXxx-xxxx03/20/2024verifiedHigh
103XXX.XX.XXX.XXXxx-xxxx10/10/2022verifiedHigh
104XXX.XXX.XX.XXXxxxxxxx.xxxxxxxxxxxxx.xxxXxx-xxxx03/20/2024verifiedHigh
105XXX.XX.XXX.XXXxxxxxxxxxxxxx.xx-xxx.xxxxXxx-xxxx03/20/2024verifiedHigh
106XXX.XX.XXX.XXXxxxx.xxxxxx.xxXxx-xxxx03/20/2024verifiedHigh
107XXX.XX.XXX.XXXxxxx.xxxxxx.xxXxx-xxxx03/20/2024verifiedHigh
108XXX.XX.XXX.XXXxxxxxx.xx-xxx.xxxxXxx-xxxx03/20/2024verifiedHigh
109XXX.XX.XXX.XXXXxx-xxxx03/20/2024verifiedHigh
110XXX.XX.XXX.XXXXxx-xxxx03/20/2024verifiedHigh
111XXX.XX.XXX.XXXxxxxxxxx.xxXxx-xxxx03/20/2024verifiedHigh
112XXX.XX.XXX.XXXxxxxxxxx.xxXxx-xxxx03/20/2024verifiedHigh
113XXX.XX.XXX.XXXXxx-xxxx03/20/2024verifiedHigh
114XXX.XX.XXX.XXXXxx-xxxx03/20/2024verifiedHigh
115XXX.XX.XXX.XXXXxx-xxxx03/20/2024verifiedHigh
116XXX.XX.XXX.XXxx-x.xx-xxx.xxxxXxx-xxxx03/20/2024verifiedHigh
117XXX.XX.XXX.XXxxxxxxxxxx.xx-xxx.xxxxXxx-xxxx03/20/2024verifiedHigh
118XXX.XX.XXX.XXxxx_xxx_xx.xx-xxx.xxxxXxx-xxxx03/20/2024verifiedHigh
119XXX.XX.XXX.XXxxxxx.xx-xxx.xxxxXxx-xxxx03/20/2024verifiedHigh
120XXX.XX.XXX.XXxxxxxxxx.xx-xxx.xxxxXxx-xxxx03/20/2024verifiedHigh
121XXX.XX.XXX.XXxxxxxxxx.xx-xxx.xxxxXxx-xxxx03/20/2024verifiedHigh
122XXX.XXX.XXX.XXXXxx-xxxx03/20/2024verifiedHigh
123XXX.XXX.XXX.XXXXxx-xxxx03/20/2024verifiedHigh
124XXX.XXX.XXX.XXXXxx-xxxx03/20/2024verifiedHigh
125XXX.XXX.XXX.XXXxxxxxxxxx.xx-xxx.xxxxXxx-xxxx03/20/2024verifiedHigh
126XXX.XXX.XXX.XXXxxxxxxxxx.xx-xxx.xxxxXxx-xxxx03/20/2024verifiedHigh
127XXX.XXX.XXX.XXXxx-xx.xx-xxx.xxxxXxx-xxxx03/20/2024verifiedHigh
128XXX.XXX.XXX.XXXxxxxx_xxxxx.xx-xxx.xxxxXxx-xxxx03/20/2024verifiedHigh
129XXX.XXX.XXX.XXXxxxxxxxxx.xx-xxx.xxxxXxx-xxxx03/20/2024verifiedHigh
130XXX.XXX.XXX.XXXxxxxxxxxx.xx-xxx.xxxxXxx-xxxx03/20/2024verifiedHigh
131XXX.XXX.XXX.XXXxxxxxxxxxxx.xxxxxxx.xxxxXxx-xxxx03/20/2024verifiedHigh
132XXX.XX.XXX.XXXxx-xxxx03/20/2024verifiedHigh
133XXX.XX.XXX.XXXxx-xxxx03/20/2024verifiedHigh
134XXX.XX.XXX.XXXxx-xxxx03/20/2024verifiedHigh
135XXX.XX.XXX.XXXxx-xxxx03/20/2024verifiedHigh
136XXX.XX.XXX.XXXXxx-xxxx03/20/2024verifiedHigh
137XXX.XX.XXX.XXXXxx-xxxx03/20/2024verifiedHigh
138XXX.XX.XXX.XXXXxx-xxxx03/20/2024verifiedHigh
139XXX.XXX.XXX.XXXXxx-xxxx03/20/2024verifiedHigh
140XXX.XXX.XXX.XXXXxx-xxxx10/10/2022verifiedHigh
141XXX.XX.XXX.XXxxx-xxxxx-xxxxxx.xxxxxxx-xxx.xxxxXxx-xxxx03/20/2024verifiedHigh
142XXX.XX.XXX.XXXxxx-xxxxx-xxxxxx.xxxxxxx-xxx.xxxxXxx-xxxx03/20/2024verifiedHigh
143XXX.XX.XXX.XXXxxx-xxxxx-xxxxxx.xxxxxxx-xxx.xxxxXxx-xxxx03/20/2024verifiedHigh
144XXX.XXX.XXX.XXXxx-xxxx03/20/2024verifiedHigh
145XXX.XXX.XXX.XXXxx-xxxx03/20/2024verifiedHigh
146XXX.XXX.XXX.XXXxx-xxxx03/20/2024verifiedHigh
147XXX.XXX.XXX.XXXxx-xxxx03/20/2024verifiedHigh
148XXX.XX.XXX.XXxxxxxx.xxxxxxxxxxxxxxxxxx.xxxXxx-xxxx07/21/2022verifiedHigh
149XXX.XX.XXX.XXXxxx-xx-xxx-xxx.xxxxxxxx.xxxxxxxxxxxx.xxXxx-xxxx07/21/2022verifiedHigh
150XXX.XX.XX.XXxxxx-xxx-xx-xxxxxx.xx-xxx.xxxxXxx-xxxx03/20/2024verifiedHigh
151XXX.XX.XX.XXXxxxxxxxx.xx-xxx.xxxxXxx-xxxx03/20/2024verifiedHigh
152XXX.XX.XX.XXXxxxxxxx.xx-xxx.xxxxXxx-xxxx03/20/2024verifiedHigh
153XXX.XX.XX.XXXXxx-xxxx03/20/2024verifiedHigh
154XXX.XX.XX.XXXXxx-xxxx03/20/2024verifiedHigh
155XXX.XX.XX.XXXXxx-xxxx03/20/2024verifiedHigh
156XXX.XX.XXX.XXXxx-xxxx03/20/2024verifiedHigh
157XXX.XXX.XXX.XXxxx-xxx-xxx-xx.xxxxxxxxx.xxxXxx-xxxx10/10/2022verifiedHigh
158XXX.XXX.XXX.XXXxxxxxxxxxx.xxxxxxxxxxxxxxx.xxxXxx-xxxx07/21/2022verifiedHigh
159XXX.XXX.XXX.XXxxx-xxx-xxx-xx.xxxxxxxxx.xxxXxx-xxxx03/20/2024verifiedHigh
160XXX.XXX.XX.XXxxxx-xxxx_xxxx.xx-xxx.xxxxXxx-xxxx03/20/2024verifiedHigh
161XXX.XXX.XX.XXxxxxxxxx.xx-xxx.xxxxXxx-xxxx03/20/2024verifiedHigh
162XXX.XXX.XX.XXxx_xxxxx_x.xx-xxx.xxxxXxx-xxxx03/20/2024verifiedHigh
163XXX.XXX.XX.XXxxxxxx.xx-xxx.xxxxXxx-xxxx03/20/2024verifiedHigh
164XXX.XX.XXX.XXxxxxx.xx-xxx.xxxxXxx-xxxx03/20/2024verifiedHigh
165XXX.XX.XXX.XXXxx-xxxx03/20/2024verifiedHigh
166XXX.XX.XXX.XXxxxxxxxx-xxxx-xx.xx-xxx.xxxxXxx-xxxx03/20/2024verifiedHigh
167XXX.XX.XXX.XXxxxxx.xx-xxx.xxxxXxx-xxxx03/20/2024verifiedHigh
168XXX.XX.XXX.XXxxxxxxxxxxxx.xx-xxx.xxxxXxx-xxxx03/20/2024verifiedHigh
169XXX.XXX.XXX.XXXxxx.xxx.xxx.xxx.xxxxxxxxxxxxxxxx.xxxXxx-xxxx07/21/2022verifiedHigh
170XXX.XX.XXX.XXxxx-xxxxx-xxxxxx.xxxxxxx-xxx.xxxxXxx-xxxx03/20/2024verifiedHigh
171XXX.XX.XXX.XXXxxxxxx-xxxx.xxxxxxx-xxx.xxxxXxx-xxxx03/20/2024verifiedHigh

TTP - Tactics, Techniques, Procedures (3)

Tactics, techniques, and procedures summarize the suspected MITRE ATT&CK techniques used. This data is unique as it uses our predictive model for actor profiling.

IDTechniqueClassVulnerabilitiesAccess VectorTypeConfidence
1T1059CAPEC-242CWE-94Argument InjectionpredictiveHigh
2TXXXX.XXXCAPEC-18CWE-XXXxxxx Xxxx XxxxxxxxxpredictiveHigh
3TXXXXCAPEC-108CWE-XXXxx XxxxxxxxxpredictiveHigh

IOA - Indicator of Attack (5)

These indicators of attack list the potential fragments used for technical activities like reconnaissance, exploitation, privilege escalation, and exfiltration. This data is unique as it uses our predictive model for actor profiling.

IDClassIndicatorTypeConfidence
1File/admin/students.phppredictiveHigh
2File/admin/theme-edit.phppredictiveHigh
3Filexxx/xxx/xxx_xxxx.xpredictiveHigh
4Filexxxx_xxxxxxx.xxxpredictiveHigh
5Argumentxxx.xxxx$xxxxxxpredictiveHigh

References (7)

The following list contains external sources which discuss the actor and the associated activities:

Interested in the pricing of exploits?

See the underground prices here!