Balada Analysis

IOB - Indicator of Behavior (235)

Timeline

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Lang

en182
zh42
pl6
ru4
de2

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Country

la210
us14
gb4
vn4
jp4

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Actors

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Activities

Interest

Timeline

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Type

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Vendor

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Product

Microsoft Windows6
ZoneMinder4
CodeIgniter4
Revive Adserver4
WordPress4

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Vulnerabilities

#VulnerabilityBaseTemp0dayTodayExpRemEPSSCTICVE
1TikiWiki tiki-register.php input validation7.36.6$0-$5k$0-$5kProof-of-ConceptOfficial Fix0.010758.81CVE-2006-6168
2Tiki Admin Password tiki-login.php improper authentication8.07.7$0-$5k$0-$5kNot DefinedOfficial Fix0.009362.48CVE-2020-15906
3LogicBoard CMS away.php redirect6.36.1$0-$5k$0-$5kNot DefinedUnavailable0.000001.77
4DZCP deV!L`z Clanportal config.php code injection7.36.6$0-$5k$0-$5kProof-of-ConceptOfficial Fix0.009430.46CVE-2010-0966
5nginx request smuggling6.96.9$0-$5k$0-$5kNot DefinedNot Defined0.002411.68CVE-2020-12440
6Drupal Sanitization API cross site scripting3.53.4$0-$5k$0-$5kNot DefinedOfficial Fix0.000560.04CVE-2020-13672
7LiteSpeed Cache Plugin Shortcode cross site scripting3.53.4$0-$5k$0-$5kNot DefinedNot Defined0.000510.00CVE-2023-4372
8WebTitan Appliance Extensions Persistent cross site scripting3.53.4$0-$5k$0-$5kNot DefinedNot Defined0.000000.00
9ipTIME NAS-I Bulletin Manage unrestricted upload7.17.1$0-$5k$0-$5kNot DefinedNot Defined0.009880.05CVE-2020-7847
10request-baskets API Request {name} server-side request forgery6.46.4$0-$5k$0-$5kNot DefinedNot Defined0.081090.05CVE-2023-27163
11PHP phpinfo cross site scripting4.33.9$5k-$25k$0-$5kProof-of-ConceptOfficial Fix0.019600.05CVE-2007-1287
12Microsoft Windows Scripting Engine Remote Code Execution5.95.1$25k-$100k$5k-$25kUnprovenOfficial Fix0.377400.00CVE-2021-34480
13DevExpress ASP.NET Web Forms ASPxHttpHandlerModule DXR.axd resource injection4.34.2$0-$5k$0-$5kNot DefinedNot Defined0.002050.18CVE-2022-41479
14Basilix Webmail login.php3 command injection7.37.0$0-$5k$0-$5kNot DefinedOfficial Fix0.000000.07
15JoomlaTune Com Jcomments admin.jcomments.php cross site scripting4.34.1$0-$5k$0-$5kProof-of-ConceptNot Defined0.004890.00CVE-2010-5048
16Microsoft Office Remote Code Execution7.06.1$5k-$25k$0-$5kUnprovenOfficial Fix0.001990.00CVE-2023-21735
17Alt-N MDaemon Worldclient injection4.94.7$5k-$25k$0-$5kNot DefinedOfficial Fix0.000900.04CVE-2021-27182
18CouchCMS mysql2i.func.php Path information disclosure3.33.3$0-$5k$0-$5kNot DefinedNot Defined0.002410.02CVE-2019-1010042
19Esri ArcGIS Server sql injection8.18.0$0-$5k$0-$5kNot DefinedOfficial Fix0.001230.05CVE-2021-29114
20Appleple A-Blog CMS path traversal4.34.3$0-$5k$0-$5kNot DefinedNot Defined0.000430.03CVE-2024-27279

IOC - Indicator of Compromise (7)

These indicators of compromise highlight associated network ressources which are known to be part of research and attack activities.

TTP - Tactics, Techniques, Procedures (19)

Tactics, techniques, and procedures summarize the suspected MITRE ATT&CK techniques used. This data is unique as it uses our predictive model for actor profiling.

IOA - Indicator of Attack (123)

These indicators of attack list the potential fragments used for technical activities like reconnaissance, exploitation, privilege escalation, and exfiltration. This data is unique as it uses our predictive model for actor profiling.

IDClassIndicatorTypeConfidence
1File/admin/dl_sendmail.phppredictiveHigh
2File/adminPage/conf/reloadpredictiveHigh
3File/api/baskets/{name}predictiveHigh
4File/api/v2/cli/commandspredictiveHigh
5File/Device/Device/GetDeviceInfoList?deviceCode=&searchField=&deviceState=predictiveHigh
6File/DXR.axdpredictiveMedium
7File/forum/away.phppredictiveHigh
8File/mfsNotice/pagepredictiveHigh
9File/novel/bookSetting/listpredictiveHigh
10File/novel/userFeedback/listpredictiveHigh
11File/owa/auth/logon.aspxpredictiveHigh
12File/spip.phppredictiveMedium
13File/x_portal_assemble_surface/jaxrs/portal/list?v=8.2.3-4-43f4fe3predictiveHigh
14File/zm/index.phppredictiveHigh
15Filexxxxxxx.xxxpredictiveMedium
16Filexxxxx.xxxxxxxxx.xxxpredictiveHigh
17Filexxxxxxxxxxx/xxxxxxx/xxxxx/xxxxx/xxxxxxxxx/xxxxxxxx.xxxpredictiveHigh
18Filexxxxx.xxxpredictiveMedium
19Filexxxx/xxxxxxxxxxxx.xxxpredictiveHigh
20Filexxxx.xxxpredictiveMedium
21Filexx_xxxx_xx_xxxx_xxxx.xxxpredictiveHigh
22Filexxxx_xxxxxxx.xxxpredictiveHigh
23Filexxxxx.xxxpredictiveMedium
24Filexxxxxxxxxx/xxxxxxxxxxxx/xxxxxxxxxxxx/xxxxxxxxxxxxx/xxxxxxxxxxxxxxxxxx/xxxx_xxxxx.xxxxpredictiveHigh
25Filexxxxx-xxxxxxx.xxxpredictiveHigh
26Filexxxxxxxxxx/xxx_xxxxxxxxxx/xxxxxxx/xxxxxxxxxx.xxxpredictiveHigh
27Filexxxxxxxxxx\xxxx.xxxpredictiveHigh
28Filexxxxxxxxxxx.xxxpredictiveHigh
29Filexxxx/xxxxxxxxxxxxxxx.xxxpredictiveHigh
30Filexxxx-xxxxxx.xxxpredictiveHigh
31Filexxxxxxxxxxx.xxxxx.xxxpredictiveHigh
32Filexxxx.xxxpredictiveMedium
33Filexxxxx_xxxx.xxxpredictiveHigh
34Filexxxxxxxxxx\xxxxxx\xxxxxxxxxxxxx.xxxpredictiveHigh
35Filexxx/xxxxxx.xxxpredictiveHigh
36Filexxxxxxxx/xxxxxxx/xxxxxxx.xxxx.xxxpredictiveHigh
37Filexxxxx.xxxxpredictiveMedium
38Filexxxxx.xxxpredictiveMedium
39Filexxxxx.xxx/xxxxxx.xxx/xxxxxxxxxxxxx.xxx/xxxxxxxx.xxxpredictiveHigh
40Filexxxxx.xxx?x=xxxx&x=xxxx&x=xx_xxx_xxxxxxpredictiveHigh
41Filexxxxx.xxx?x=xxxx&x=xxxxxxx&x=xxxpredictiveHigh
42Filexxxx_xxxxxxx.xxxpredictiveHigh
43Filexxxxx.xxxxpredictiveMedium
44Filexxxxx.xxxpredictiveMedium
45Filexxxx.xxxxpredictiveMedium
46Filexx_xxxx.xpredictiveMedium
47Filexxx/xxxx/xxxx_xxxxxxxxx.xpredictiveHigh
48Filexxxxxxx_xxxx.xxxpredictiveHigh
49Filexxxxxxxxxxxxxxxxx.xxxpredictiveHigh
50Filexxxxxxx.xxxpredictiveMedium
51Filexxxxxxx/xxxxxxx/xxx/xxxxxxxxxx.xxx?xxxxxxxx=xxxx&xxxxxx=xxxxxxxxxxpredictiveHigh
52Filexxxx_xxxx_xxxxxx.xxxpredictiveHigh
53Filexxxx_xxxxx.xxxxpredictiveHigh
54Filexxxxxxxxxx_xxxx.xxxpredictiveHigh
55Filexxx/xxxx/xxxxpredictiveHigh
56Filexxxxxx\xxxxxxxx\xx_xxxxx_xxxxxxx.xxxpredictiveHigh
57Filexxxxxxx.xxx.xx.xxxxxxxxxxx.xxxpredictiveHigh
58Filexxxxxxxxx/xxxxxxxx.xxxpredictiveHigh
59Filexxxx_xxxxxx.xxpredictiveHigh
60Filexxxx-xxxxx.xxxpredictiveHigh
61Filexxxx-xxxxxxxx.xxxpredictiveHigh
62Filexx.xxxpredictiveLow
63Filexxxxxx_xxxxx.xxxpredictiveHigh
64Filexxxxxx.xxxpredictiveMedium
65Filexxxxxxx-xxxxx.xxxpredictiveHigh
66Filexxxx_xxxxx.xxxpredictiveHigh
67Filexxxx/xxx/xxxx-xxxxx.xxxpredictiveHigh
68Filexxxx.xxxpredictiveMedium
69Filexx-xxxxx-xxxxxx.xxxpredictiveHigh
70Filexxx/xxxxxxxx/xxxxxxxx.xxxpredictiveHigh
71Filexxxx.xxxpredictiveMedium
72File~/xxx/xxxx-xxxxxxxxx.xxxpredictiveHigh
73File~/xxxxxxxx/xxxxx-xx-xxxxxxxxxx-xxxxxxxxx.xxxpredictiveHigh
74Libraryxxxxxxx/xxx.xxx.xxx.xxxpredictiveHigh
75Argumentxxx_xxxpredictiveLow
76ArgumentxxxxpredictiveLow
77ArgumentxxxxxxxxxpredictiveMedium
78ArgumentxxxxxxxxpredictiveMedium
79Argumentxxx_xxx_xx_xxx_xxxxxxxxxx_xpredictiveHigh
80Argumentxxxxx_xxxxpredictiveMedium
81Argumentxxxx_xxx_xxxxpredictiveHigh
82ArgumentxxxxxxxxxxpredictiveMedium
83ArgumentxxxpredictiveLow
84ArgumentxxxxxxxxxxxxxxxpredictiveHigh
85ArgumentxxxxpredictiveLow
86Argumentxxxxxxxxx_xxxxxxpredictiveHigh
87ArgumentxxxxxxxxxpredictiveMedium
88Argumentxx_xxxxxxxpredictiveMedium
89ArgumentxxxxpredictiveLow
90ArgumentxxxxxxxxpredictiveMedium
91ArgumentxxxxxpredictiveLow
92Argumentxxxxxx_xxxxxpredictiveMedium
93Argumentxx_xxpredictiveLow
94Argumentxxxxxxx[xxxxxxx]predictiveHigh
95ArgumentxxxxxxxpredictiveLow
96ArgumentxxxxxxpredictiveLow
97ArgumentxxxxxpredictiveLow
98ArgumentxxpredictiveLow
99ArgumentxxxpredictiveLow
100ArgumentxxxxpredictiveLow
101ArgumentxxxxpredictiveLow
102Argumentxxx xxxxxxxx/xxxxxxx xxxxxxxxpredictiveHigh
103ArgumentxxxxxxxxpredictiveMedium
104Argumentxxxxxx/xxxxx/xxxxpredictiveHigh
105ArgumentxxxxxxxpredictiveLow
106ArgumentxxxxpredictiveLow
107Argumentxxxxxx_xxxxxxpredictiveHigh
108Argumentxxxxxxxx_xxpredictiveMedium
109Argumentxxxxxx_xxxxxpredictiveMedium
110Argumentxxxx_xxxxpredictiveMedium
111ArgumentxxxxpredictiveLow
112ArgumentxxxxxxpredictiveLow
113ArgumentxxxxxxxpredictiveLow
114ArgumentxxxpredictiveLow
115ArgumentxxxxxpredictiveLow
116Argumentxx_xxxxxxxxpredictiveMedium
117ArgumentxxxpredictiveLow
118ArgumentxxxxxxxxpredictiveMedium
119Argument_xxx_xxxxxxxxxxx_predictiveHigh
120Input Valuexxxxxxxxx' xxx 'x'='xpredictiveHigh
121Input ValuexxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxpredictiveHigh
122Pattern|xx xx xx xx|predictiveHigh
123Network PortxxxxxpredictiveLow

References (2)

The following list contains external sources which discuss the actor and the associated activities:

Might our Artificial Intelligence support you?

Check our Alexa App!