WikiLoader Analysis

IOB - Indicator of Behavior (32)

Timeline

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Lang

pl32

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Country

us32

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Actors

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Activities

Interest

Timeline

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Type

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Vendor

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Product

Cisco RV01610
Cisco RV04210
Cisco RV042G10
Cisco RV08210
Cisco RV32010

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Vulnerabilities

#VulnerabilityBaseTemp0dayTodayExpRemEPSSCTICVE
1Cisco RV016/RV042/RV042G/RV082/RV320/RV325 Web-based Management Interface stack-based overflow7.26.9$5k-$25k$0-$5kNot DefinedOfficial Fix0.002210.00CVE-2021-1348
2Cisco IOS XR/NX-OS IPv6 Access Control List access control6.96.6$25k-$100k$5k-$25kNot DefinedOfficial Fix0.001290.00CVE-2021-1389
3Redwood Report2Web signIn.do cross site scripting4.84.8$0-$5k$0-$5kNot DefinedNot Defined0.001160.00CVE-2021-26710
4Electric Coin Company Zcashd Time Offset information disclosure4.44.2$0-$5k$0-$5kNot DefinedOfficial Fix0.000840.00CVE-2020-8807
5Linux Kernel VSOCK af_vsock.c race condition6.05.7$5k-$25k$0-$5kProof-of-ConceptOfficial Fix0.000420.03CVE-2021-26708
6Redwood Report2Web default.htm injection5.85.8$0-$5k$0-$5kNot DefinedNot Defined0.001580.00CVE-2021-26711
7typora cross site scripting4.84.8$0-$5k$0-$5kNot DefinedNot Defined0.001290.00CVE-2020-18737
8IBM PowerHA Discovery information disclosure4.74.7$0-$5k$0-$5kNot DefinedNot Defined0.000420.00CVE-2020-4832
9Gitea denial of service5.95.9$0-$5k$0-$5kNot DefinedNot Defined0.002170.00CVE-2021-3382
10Psyprax Firebird Database access control7.26.8$0-$5k$0-$5kNot DefinedOfficial Fix0.000650.00CVE-2020-10552
11Psyprax Lockscreen PPScreen.ini permission5.95.7$0-$5k$0-$5kNot DefinedOfficial Fix0.000420.00CVE-2020-10553
12Psyprax Password inadequate encryption5.35.1$0-$5k$0-$5kNot DefinedOfficial Fix0.001680.00CVE-2020-10554
13Zulip Desktop shell.openItem Privilege Escalation8.07.7$0-$5k$0-$5kNot DefinedOfficial Fix0.006500.00CVE-2020-10857
14Cisco RV016/RV042/RV042G/RV082/RV320/RV325 Web-based Management Interface stack-based overflow7.26.9$5k-$25k$0-$5kNot DefinedOfficial Fix0.002210.00CVE-2021-1319
15Cisco RV016/RV042/RV042G/RV082/RV320/RV325 Web-based Management Interface stack-based overflow7.26.9$5k-$25k$0-$5kNot DefinedOfficial Fix0.002210.00CVE-2021-1320
16Cisco RV016/RV042/RV042G/RV082/RV320/RV325 Web-based Management Interface stack-based overflow7.26.9$5k-$25k$0-$5kNot DefinedOfficial Fix0.002210.00CVE-2021-1321
17Cisco RV016/RV042/RV042G/RV082/RV320/RV325 Web-based Management Interface stack-based overflow7.26.9$5k-$25k$0-$5kNot DefinedOfficial Fix0.002210.00CVE-2021-1338
18Cisco RV016/RV042/RV042G/RV082/RV320/RV325 Web-based Management Interface stack-based overflow7.26.9$5k-$25k$0-$5kNot DefinedOfficial Fix0.002210.00CVE-2021-1340
19Cisco RV016/RV042/RV042G/RV082/RV320/RV325 Web-based Management Interface stack-based overflow7.26.9$5k-$25k$0-$5kNot DefinedOfficial Fix0.002210.00CVE-2021-1344
20Cisco RV016/RV042/RV042G/RV082/RV320/RV325 Web-based Management Interface stack-based overflow7.26.9$5k-$25k$0-$5kNot DefinedOfficial Fix0.002210.00CVE-2021-1345

IOC - Indicator of Compromise (1)

These indicators of compromise highlight associated network ressources which are known to be part of research and attack activities.

IDIP addressHostnameActorCampaignsIdentifiedTypeConfidence
154.146.113.169ec2-54-146-113-169.compute-1.amazonaws.comWikiLoader02/13/2024verifiedMedium

TTP - Tactics, Techniques, Procedures (10)

Tactics, techniques, and procedures summarize the suspected MITRE ATT&CK techniques used. This data is unique as it uses our predictive model for actor profiling.

IOA - Indicator of Attack (9)

These indicators of attack list the potential fragments used for technical activities like reconnaissance, exploitation, privilege escalation, and exfiltration. This data is unique as it uses our predictive model for actor profiling.

IDClassIndicatorTypeConfidence
1File%PROGRAMDATA%\Psyprax32\PPScreen.inipredictiveHigh
2FileAuth/Manager.phppredictiveHigh
3Filexxxx/xxxxxx_xxxx/xxxxxxx/xxxxxxx.xxxpredictiveHigh
4Filexxx/xxx_xxxxx/xx_xxxxx.xpredictiveHigh
5Filexxxxxx.xxpredictiveMedium
6Filexxxxxxxxxx.xxxpredictiveHigh
7ArgumentxxxxpredictiveLow
8ArgumentxxxxpredictiveLow
9ArgumentxxxxpredictiveLow

References (2)

The following list contains external sources which discuss the actor and the associated activities:

Do you need the next level of professionalism?

Upgrade your account now!