UAC-0050 Analysis

IOB - Indicator of Behavior (1000)

Timeline

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Lang

ru96
en92
pl90
es84
ja84

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Country

ru96
pl90
es84
ar82
sv80

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Actors

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Activities

Interest

Timeline

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Type

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Vendor

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Product

Tenda W15E12
Tenda i218
MailCleaner8
Dell Repository Manager4
Kashipara Online Furniture Shopping Ecommerce Webs ...4

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Vulnerabilities

#VulnerabilityBaseTemp0dayTodayExpRemEPSSCTICVE
1Apryse WebViewer PDF Document cross site scripting3.53.2$0-$5k$0-$5kProof-of-ConceptOfficial Fix0.000450.08CVE-2024-4327
2MailCleaner Email os command injection9.89.3$0-$5k$0-$5kProof-of-ConceptOfficial Fix0.000460.07CVE-2024-3191
3osCommerce all-products cross site scripting4.33.9$0-$5k$0-$5kProof-of-ConceptNot Defined0.000650.20CVE-2024-4348
4MailCleaner Admin Interface cross site scripting6.56.3$0-$5k$0-$5kProof-of-ConceptOfficial Fix0.000450.07CVE-2024-3192
5SourceCodester Pisay Online E-Learning System controller.php unrestricted upload7.36.6$0-$5k$0-$5kProof-of-ConceptNot Defined0.000450.12CVE-2024-4349
6MailCleaner Admin Endpoints os command injection8.88.3$0-$5k$0-$5kProof-of-ConceptOfficial Fix0.000460.04CVE-2024-3193
7BloomPixel Max Addons Pro for Bricks Plugin authorization6.56.4$0-$5k$0-$5kNot DefinedNot Defined0.000430.08CVE-2024-32951
8Extend Themes Teluro Plugin cross-site request forgery4.34.2$0-$5k$0-$5kNot DefinedNot Defined0.000430.00CVE-2024-33688
9Apache HTTP Server mod_lua Multipart Parser r:parsebody out-of-bounds write8.58.4$25k-$100k$5k-$25kNot DefinedOfficial Fix0.088080.00CVE-2021-44790
10Elementor ImageBox Plugin cross site scripting3.53.4$0-$5k$0-$5kNot DefinedNot Defined0.000450.08CVE-2024-3074
11Dell Wyse Proprietary OS Telemetry Dashboard information disclosure4.74.7$0-$5k$0-$5kNot DefinedNot Defined0.000430.03CVE-2024-28963
12Apache Parquet Parquet-MR denial of service3.53.4$0-$5k$0-$5kNot DefinedOfficial Fix0.000890.00CVE-2021-41561
13Pavex Embed Google Photos Album Plugin server-side request forgery5.65.5$0-$5k$0-$5kNot DefinedNot Defined0.000430.08CVE-2024-32775
14Foliovision FV Flowplayer Video Player Plugin server-side request forgery5.65.5$0-$5k$0-$5kNot DefinedNot Defined0.000430.00CVE-2024-32955
15Tenda i21 formQosManageDouble_auto stack-based overflow8.88.5$0-$5k$0-$5kNot DefinedNot Defined0.000450.07CVE-2024-4246
16Dell Repository Manager API Module improper authorization8.38.1$5k-$25k$0-$5kNot DefinedOfficial Fix0.000430.00CVE-2024-28976
17Jegstudio Financio Plugin cross-site request forgery4.34.2$0-$5k$0-$5kNot DefinedNot Defined0.000430.00CVE-2024-33690
18ThemeNcode Fan Page Widget by Plugin cross site scripting4.14.1$0-$5k$0-$5kNot DefinedNot Defined0.000430.00CVE-2024-33695
19AnnounceKit Plugin cross site scripting2.42.4$0-$5k$0-$5kNot DefinedNot Defined0.000450.04CVE-2024-3023
20Repute Infosystems ARMember Plugin authorization7.87.7$0-$5k$0-$5kNot DefinedNot Defined0.000430.07CVE-2024-32948

Campaigns (1)

These are the campaigns that can be associated with the actor:

  • Remcos

IOC - Indicator of Compromise (97)

These indicators of compromise highlight associated network ressources which are known to be part of research and attack activities.

IDIP addressHostnameActorCampaignsIdentifiedTypeConfidence
15.42.92.30hosted-by.saltu-cloud.proUAC-005003/20/2024verifiedHigh
25.42.92.31hosted-by.saltu-cloud.proUAC-005003/20/2024verifiedHigh
35.42.92.32hosted-by.yeezyhost.netUAC-005003/20/2024verifiedHigh
45.42.92.37hosted-by.yeezyhost.netUAC-005003/20/2024verifiedHigh
55.42.92.44hosted-by.yeezyhost.netUAC-005003/20/2024verifiedHigh
645.10.245.245UAC-005003/20/2024verifiedHigh
745.87.154.153net-group.netUAC-005003/20/2024verifiedHigh
845.87.155.41trustvs.comUAC-005003/20/2024verifiedHigh
946.249.58.40yufrt.g5.housinglandshares.infoUAC-0050Remcos01/08/2024verifiedHigh
1077.105.132.70UAC-005003/20/2024verifiedHigh
1177.105.132.124UAC-005003/20/2024verifiedHigh
1279.137.205.201awesome-dime.aeza.networkUAC-005003/20/2024verifiedHigh
1380.78.254.2880-78-254-28.cloudvps.regruhosting.ruUAC-005003/20/2024verifiedHigh
1481.19.149.130mx20lb.world4you.comUAC-005003/20/2024verifiedHigh
1589.23.98.22UAC-005003/20/2024verifiedHigh
1694.131.99.56vm2202770.stark-industries.solutionsUAC-005003/20/2024verifiedHigh
1794.131.99.89vm2030942.stark-industries.solutionsUAC-005003/20/2024verifiedHigh
1894.131.99.153vm2051611.stark-industries.solutionsUAC-005003/20/2024verifiedHigh
1994.131.99.156swiss.vpsUAC-005003/20/2024verifiedHigh
2094.131.102.115.UAC-005003/20/2024verifiedHigh
21XX.XXX.XXX.XXXxxxxxxxxx.xxxxx-xxxxxxxxxx.xxxxxxxxxXxx-xxxx03/20/2024verifiedHigh
22XX.XXX.XXX.XXXxxxxxxxxx.xxxxx-xxxxxxxxxx.xxxxxxxxxXxx-xxxx03/20/2024verifiedHigh
23XX.XXX.XXX.XXX.Xxx-xxxx03/20/2024verifiedHigh
24XX.XXX.XXX.XXXxxxxxxxxx.xxxxx-xxxxxxxxxx.xxxxxxxxxXxx-xxxx03/20/2024verifiedHigh
25XX.XXX.XX.XXXxxxxxxxxx.xxxxx-xxxxxxxxxx.xxxxxxxxxXxx-xxxx03/20/2024verifiedHigh
26XX.XXX.XX.XXXXxx-xxxx03/20/2024verifiedHigh
27XX.XXX.XX.XXXXxx-xxxx03/20/2024verifiedHigh
28XX.XXX.XX.XXxxxxxxxxx.xxxxxxxx.xxxxxxxxxXxx-xxxx03/20/2024verifiedHigh
29XX.XXX.XX.XXxxxxxxxxx.xxxxxxxx.xxxxxxxxxXxx-xxxx03/20/2024verifiedHigh
30XX.XXX.XX.XXxxxxxxxxx.xxxxxxxx.xxxxxxxxxXxx-xxxx03/20/2024verifiedHigh
31XX.XXX.XX.XXxxxxxxxxx.xxxxxxxx.xxxxxxxxxXxx-xxxx03/20/2024verifiedHigh
32XX.XXX.XX.XXxxxxxxxxx.xxxxxxxx.xxxxxxxxxXxx-xxxx03/20/2024verifiedHigh
33XX.XXX.XX.XXxxxxxxxxx.xxxxxxxx.xxxxxxxxxXxx-xxxx03/20/2024verifiedHigh
34XX.XXX.XX.XXXxxxxxxxxx.xxxxxxxx.xxxxxxxxxXxx-xxxx03/20/2024verifiedHigh
35XX.XXX.XX.XXXxxxxxxxxx.xxxxxxxx.xxxxxxxxxXxx-xxxx03/20/2024verifiedHigh
36XXX.XX.XX.XXxxxxxxx.xxxxx.xxXxx-xxxx03/20/2024verifiedHigh
37XXX.XX.XX.XXxxxxxxx.xxxxx.xxXxx-xxxx03/20/2024verifiedHigh
38XXX.XX.XX.XXXxxxxxxx.xxxxx.xxXxx-xxxx03/20/2024verifiedHigh
39XXX.XX.XX.XXXxxxxxxx.xxxxx.xxXxx-xxxx03/20/2024verifiedHigh
40XXX.XX.XX.XXXxxxxxxx.xxxxx.xxXxx-xxxx03/20/2024verifiedHigh
41XXX.XX.XX.XXXxxxxxxx.xxxxx.xxXxx-xxxx03/20/2024verifiedHigh
42XXX.XX.XX.XXXxxxxxxx.xxxxx.xxXxx-xxxx03/20/2024verifiedHigh
43XXX.XX.XX.XXXxxxxxxx.xxxxx.xxXxx-xxxx03/20/2024verifiedHigh
44XXX.XX.XX.XXXxxxxxxx.xxxxx.xxXxx-xxxx03/20/2024verifiedHigh
45XXX.XX.XX.XXXxxxxxxx.xxxxx.xxXxx-xxxx03/20/2024verifiedHigh
46XXX.XX.XX.XXXxxx.xxxxxxx.xxxxXxx-xxxx03/20/2024verifiedHigh
47XXX.XX.XX.XXxxxxxxx.xxxxx.xxXxx-xxxx03/20/2024verifiedHigh
48XXX.XX.XX.XXXxxxxxxx.xxxxx.xxXxx-xxxx03/20/2024verifiedHigh
49XXX.XX.XX.XXXxxxxxxx.xxxxx.xxXxx-xxxx03/20/2024verifiedHigh
50XXX.XX.XX.XXXxxxxxxx.xxxxx.xxXxx-xxxx03/20/2024verifiedHigh
51XXX.XX.XX.XXXxxxxxxx.xxxxx.xxXxx-xxxx03/20/2024verifiedHigh
52XXX.XX.XX.XXXxxxxxxx.xxxxx.xxXxx-xxxx03/20/2024verifiedHigh
53XXX.XX.XX.XXXxxxxxxx.xxxxx.xxXxx-xxxx03/20/2024verifiedHigh
54XXX.XX.XX.XXXxxxxxxx.xxxxx.xxXxx-xxxx03/20/2024verifiedHigh
55XXX.XX.XX.XXXxxxxxxx.xxxxx.xxXxx-xxxx03/20/2024verifiedHigh
56XXX.XX.XX.XXXxxxxxxx.xxxxx.xxXxx-xxxx03/20/2024verifiedHigh
57XXX.XX.XX.XXXxxxxxxx.xxxxx.xxXxx-xxxx03/20/2024verifiedHigh
58XXX.XX.XX.XXXxxxxxxx.xxxxx.xxXxx-xxxx03/20/2024verifiedHigh
59XXX.XX.XX.XXXxxxxxxx.xxxxx.xxXxx-xxxx03/20/2024verifiedHigh
60XXX.XX.XX.XXXxxxxxxx.xxxxx.xxXxx-xxxx03/20/2024verifiedHigh
61XXX.XX.XX.XXXxxxxxxx.xxxxx.xxXxx-xxxx03/20/2024verifiedHigh
62XXX.XXX.XXX.XXXxxxxxx-xx.xxxxxxxxx.xxxXxx-xxxx03/20/2024verifiedHigh
63XXX.XXX.XXX.XXXxxxxxx-xx.xxxxxxxxx.xxxXxx-xxxx03/20/2024verifiedHigh
64XXX.XXX.XXX.XXXxxxxxx-xx.xxxxxxxxx.xxxXxx-xxxx03/20/2024verifiedHigh
65XXX.XXX.XXX.XXXxxxxxx-xx.xxxxxxxxx.xxxXxx-xxxx03/20/2024verifiedHigh
66XXX.XXX.XXX.XXXxxxxxx-xx.xxxxxxxxx.xxxXxx-xxxx03/20/2024verifiedHigh
67XXX.XX.XXX.XXxxxxxxx.xxxxx.xxXxx-xxxx03/20/2024verifiedHigh
68XXX.XX.XXX.XXxxxxxxx.xxxxx.xxXxx-xxxx03/20/2024verifiedHigh
69XXX.XX.XXX.XXxxxx.xxxxxxxx.xxxxXxx-xxxx03/20/2024verifiedHigh
70XXX.XX.XXX.XXXxxxxxxx.xxxxx.xxXxx-xxxx03/20/2024verifiedHigh
71XXX.XX.XXX.XXXxxxxxxx.xxxxx.xxXxx-xxxx03/20/2024verifiedHigh
72XXX.XX.XXX.XXXxxxxxxx.xxxxx.xxXxx-xxxx03/20/2024verifiedHigh
73XXX.XX.XXX.XXXxxxxxxxxxx.xxxXxx-xxxx03/20/2024verifiedHigh
74XXX.XX.XXX.XXXxxxxxxx.xxxxx.xxXxx-xxxx03/20/2024verifiedHigh
75XXX.XX.XX.XXXxx-xxxx03/20/2024verifiedHigh
76XXX.XX.XX.XXXxx-xxxx03/20/2024verifiedHigh
77XXX.XX.XXX.XXxxxxxxxxx.xxxxx-xxxxxxxxxx.xxxxxxxxxXxx-xxxx03/20/2024verifiedHigh
78XXX.XX.XXX.XXXxxxxxxxx.xxxxxxxXxx-xxxx03/20/2024verifiedHigh
79XXX.XX.XXX.XXXXxx-xxxx03/20/2024verifiedHigh
80XXX.XX.XXX.XXXxxxxxxxxx.xxxxx-xxxxxxxxxx.xxxxxxxxxXxx-xxxx03/20/2024verifiedHigh
81XXX.XX.XXX.XXxxxxxxxxx.xxxxx-xxxxxxxxxx.xxxxxxxxxXxx-xxxx03/20/2024verifiedHigh
82XXX.XX.XXX.XXXxxxx-xxxx.xxxxxxxx.xxxXxx-xxxx03/20/2024verifiedHigh
83XXX.XX.XXX.XXXxxx.xxxxxx.xxXxx-xxxx03/20/2024verifiedHigh
84XXX.XX.XXX.XXXxxxxxxxxxxxxxxxxx.xxXxx-xxxx03/20/2024verifiedHigh
85XXX.XX.XXX.XXXxxxxxxxxx.xxxxx-xxxxxxxxxx.xxxxxxxxxXxx-xxxx03/20/2024verifiedHigh
86XXX.XX.XXX.XXXxxxxxxxxx.xxxxx-xxxxxxxxxx.xxxxxxxxxXxx-xxxx03/20/2024verifiedHigh
87XXX.XX.XXX.XXXxxxxx.xxxxxxxxxxxXxx-xxxx03/20/2024verifiedHigh
88XXX.XX.XXX.XXXxxxxx.xxxXxx-xxxx03/20/2024verifiedHigh
89XXX.XX.XXX.XXXXxx-xxxx03/20/2024verifiedHigh
90XXX.XX.XXX.XXXxxxxxxxxx.xxxXxx-xxxx03/20/2024verifiedHigh
91XXX.XX.XXX.XXXxxxxxxxxx.xxxxx-xxxxxxxxxx.xxxxxxxxxXxx-xxxx03/20/2024verifiedHigh
92XXX.XX.XXX.XXXxx-xxxx03/20/2024verifiedHigh
93XXX.XX.XXX.XXXxx-xxxx03/20/2024verifiedHigh
94XXX.XX.XXX.XXXXxx-xxxx03/20/2024verifiedHigh
95XXX.XXX.XXX.XXxxxxxxx.xxxxxx.xxxXxx-xxxx03/20/2024verifiedHigh
96XXX.XX.XX.XXXXxx-xxxxXxxxxx01/08/2024verifiedHigh
97XXX.XXX.XXX.XXXXxx-xxxx03/20/2024verifiedHigh

TTP - Tactics, Techniques, Procedures (13)

Tactics, techniques, and procedures summarize the suspected MITRE ATT&CK techniques used. This data is unique as it uses our predictive model for actor profiling.

IOA - Indicator of Attack (66)

These indicators of attack list the potential fragments used for technical activities like reconnaissance, exploitation, privilege escalation, and exfiltration. This data is unique as it uses our predictive model for actor profiling.

IDClassIndicatorTypeConfidence
1File/catalog/all-productspredictiveHigh
2File/changePasswordpredictiveHigh
3File/goform/addIpMacBindpredictiveHigh
4File/goform/DelDhcpRulepredictiveHigh
5File/goform/delIpMacBindpredictiveHigh
6File/goform/DelPortMappingpredictiveHigh
7File/goform/modifyDhcpRulepredictiveHigh
8File/goform/modifyIpMacBindpredictiveHigh
9File/xxxxxx/xxxxxxxxxxxxpredictiveHigh
10File/xxxxxx/xxxxxxxxxxpredictiveHigh
11File/xxxxxx/xxxxxxxxxpredictiveHigh
12File/xxxxxx/xxxxxxxxxxxxxxxxpredictiveHigh
13File/xxxxxx/xxxxxxxxxxxxxxpredictiveHigh
14File/xxxxxx/xxxxxxxxxxxxxxxxxxpredictiveHigh
15File/xxxxxx/xxxxxxxxxxxxxxpredictiveHigh
16File/xxxxxx/xxxxxxxxxxxxxpredictiveHigh
17File/xxxxxx/xxxxxxxxxxxxxxxxxxxpredictiveHigh
18File/xxxxxx/xxxxxxxxxxxpredictiveHigh
19File/xxxxxx/xxxxxxxxxx.xxxpredictiveHigh
20File/xxxxxxxxxxx.xxx/xxxxxxxxpredictiveHigh
21File/xxx/xxxxxxx/xxxpredictiveHigh
22File/xxxx/xxxxxxx xxxxxx/xxx/xxx_xxxx_xxxxxx.xxxpredictiveHigh
23Filexxxxx/xxxxxxx/xxxxxxxxxxxxx.xxpredictiveHigh
24Filexxxxx.xxxpredictiveMedium
25Filexxxxxxxxxxxx.xxxpredictiveHigh
26Filexxxxxxxxxxxxxxxxxxx.xxxpredictiveHigh
27Filexxxxxxx/xxxxxxxx.xxxpredictiveHigh
28Filexx/xxxxxx/xxxxxxxxxxpredictiveHigh
29Filexxxxx-xxxxxx-xxxxxx.xxxxpredictiveHigh
30Filexxxxx.xxxpredictiveMedium
31Filexxxxxxxx.xxxpredictiveMedium
32Filexxxxxxxx.xxxpredictiveMedium
33Filexxxxxxxx.xxxpredictiveMedium
34Filexxxx-xxxxxxxx.xxxpredictiveHigh
35Argumentxxxxx_xxxxxpredictiveMedium
36ArgumentxxxxxxxxxxxxxpredictiveHigh
37ArgumentxxxpredictiveLow
38ArgumentxxxxxxxxxpredictiveMedium
39ArgumentxxxxxxxxxxxxpredictiveMedium
40ArgumentxxxxxxxxxxpredictiveMedium
41ArgumentxxxxxxxpredictiveLow
42ArgumentxxxxpredictiveLow
43ArgumentxxxxxxxxxxxxxxxxxxxxxxpredictiveHigh
44Argumentxx/xxxxpredictiveLow
45ArgumentxxpredictiveLow
46ArgumentxxpredictiveLow
47ArgumentxxxxxxxxxxxxxxpredictiveHigh
48ArgumentxxxxxxxxxxxxxpredictiveHigh
49Argumentxxxxxxxxxxxxxxx/xxxxxxxxxxxxxxx/xxxxxxxxxxxxxxxx/xxxxxxxxxxxxxxxxxxxpredictiveHigh
50ArgumentxxxxpredictiveLow
51ArgumentxxxxxxxxxxpredictiveMedium
52ArgumentxxxxxxxxxxxxpredictiveMedium
53ArgumentxxxxpredictiveLow
54ArgumentxxxxxxxxxxxxxxxxpredictiveHigh
55Argumentxxxxxxx_xxxxxxx_xxxxx_xxxxx_xxxxxpredictiveHigh
56ArgumentxxxxxxpredictiveLow
57ArgumentxxxxxxxxpredictiveMedium
58ArgumentxxxxxxxxxxxxxxxxxxpredictiveHigh
59ArgumentxxxxxxxxxxpredictiveMedium
60ArgumentxxxxxxxxpredictiveMedium
61Argumentxxxxxxxxxx/xxxxxxxx/xxxxxxx/xxxxxxxxxxpredictiveHigh
62ArgumentxxxxxxxxxpredictiveMedium
63ArgumentxxxxxxxxxxxxxxxxpredictiveHigh
64ArgumentxxxxpredictiveLow
65ArgumentxxxxxxxxxxpredictiveMedium
66Argumentxxxx/xxxxx/xxx/xxxx/xxxxxx/xxxxxxpredictiveHigh

References (9)

The following list contains external sources which discuss the actor and the associated activities:

Want to stay up to date on a daily basis?

Enable the mail alert feature now!