Clop Analysis

IOB - Indicator of Behavior (1000)

Timeline

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Lang

en114
zh98
ja94
pl92
de86

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Country

pl92
de86
ru84
it82
fr78

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Actors

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Activities

Interest

Timeline

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Type

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Vendor

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Product

Tenda W15E10
MailCleaner8
Tenda TX96
Tenda i214
GOG Galaxy4

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Vulnerabilities

#VulnerabilityBaseTemp0dayTodayExpRemEPSSCTICVE
1Apryse WebViewer PDF Document cross site scripting3.53.2$0-$5k$0-$5kProof-of-ConceptOfficial Fix0.000450.08CVE-2024-4327
2MailCleaner Email os command injection9.89.3$0-$5k$0-$5kProof-of-ConceptOfficial Fix0.000460.07CVE-2024-3191
3osCommerce all-products cross site scripting4.33.9$0-$5k$0-$5kProof-of-ConceptNot Defined0.000650.21CVE-2024-4348
4MailCleaner Admin Interface cross site scripting6.56.3$0-$5k$0-$5kProof-of-ConceptOfficial Fix0.000450.04CVE-2024-3192
5SourceCodester Pisay Online E-Learning System controller.php unrestricted upload7.36.6$0-$5k$0-$5kProof-of-ConceptNot Defined0.000450.13CVE-2024-4349
6MailCleaner Admin Endpoints os command injection8.88.3$0-$5k$0-$5kProof-of-ConceptOfficial Fix0.000460.04CVE-2024-3193
7BloomPixel Max Addons Pro for Bricks Plugin authorization6.56.4$0-$5k$0-$5kNot DefinedNot Defined0.000430.08CVE-2024-32951
8Extend Themes Teluro Plugin cross-site request forgery4.34.2$0-$5k$0-$5kNot DefinedNot Defined0.000430.00CVE-2024-33688
9Apache HTTP Server mod_lua Multipart Parser r:parsebody out-of-bounds write8.58.4$25k-$100k$5k-$25kNot DefinedOfficial Fix0.088080.00CVE-2021-44790
10Elementor ImageBox Plugin cross site scripting3.53.4$0-$5k$0-$5kNot DefinedNot Defined0.000450.08CVE-2024-3074
11Dell Wyse Proprietary OS Telemetry Dashboard information disclosure4.74.7$0-$5k$0-$5kNot DefinedNot Defined0.000430.03CVE-2024-28963
12Apache Parquet Parquet-MR denial of service3.53.4$0-$5k$0-$5kNot DefinedOfficial Fix0.000890.00CVE-2021-41561
13Pavex Embed Google Photos Album Plugin server-side request forgery5.65.5$0-$5k$0-$5kNot DefinedNot Defined0.000430.08CVE-2024-32775
14Foliovision FV Flowplayer Video Player Plugin server-side request forgery5.65.5$0-$5k$0-$5kNot DefinedNot Defined0.000430.00CVE-2024-32955
15Tenda i21 formQosManageDouble_auto stack-based overflow8.88.5$0-$5k$0-$5kNot DefinedNot Defined0.000450.07CVE-2024-4246
16Dell Repository Manager API Module improper authorization8.38.1$5k-$25k$0-$5kNot DefinedOfficial Fix0.000430.00CVE-2024-28976
17Jegstudio Financio Plugin cross-site request forgery4.34.2$0-$5k$0-$5kNot DefinedNot Defined0.000430.00CVE-2024-33690
18ThemeNcode Fan Page Widget by Plugin cross site scripting4.14.1$0-$5k$0-$5kNot DefinedNot Defined0.000430.00CVE-2024-33695
19AnnounceKit Plugin cross site scripting2.42.4$0-$5k$0-$5kNot DefinedNot Defined0.000450.04CVE-2024-3023
20Repute Infosystems ARMember Plugin authorization7.87.7$0-$5k$0-$5kNot DefinedNot Defined0.000430.07CVE-2024-32948

Campaigns (2)

These are the campaigns that can be associated with the actor:

IOC - Indicator of Compromise (137)

These indicators of compromise highlight associated network ressources which are known to be part of research and attack activities.

IDIP addressHostnameActorCampaignsIdentifiedTypeConfidence
13.29.17.1ec2-3-29-17-1.me-central-1.compute.amazonaws.comClop12/04/2019verifiedMedium
23.101.53.11ec2-3-101-53-11.us-west-1.compute.amazonaws.comClopFortra GoAnywhere10/27/2023verifiedMedium
35.34.178.28s41.friendhosting.netClopFortra GoAnywhere10/27/2023verifiedHigh
45.34.178.30dedic-hghdgsjhdgjhgdj67tyu687uy-1209043.hosted-by-itldc.comClopFortra GoAnywhere10/27/2023verifiedHigh
55.34.178.31free.dsClopFortra GoAnywhere10/27/2023verifiedHigh
65.34.180.48mail.tube-plant.comClopFortra GoAnywhere10/27/2023verifiedHigh
75.34.180.205bkp-vm-ams.layer6.netClopCVE-2023-3436210/27/2023verifiedHigh
85.62.43.184r-184-43-62-5.consumer-pool.prcdn.netClop10/29/2023verifiedHigh
95.149.248.68ClopCVE-2023-3436210/27/2023verifiedHigh
105.149.250.74verizon.comClopCVE-2023-3436210/27/2023verifiedHigh
115.149.250.92digiable.netClopCVE-2023-3436210/27/2023verifiedHigh
125.188.86.114ClopCVE-2023-3436210/27/2023verifiedHigh
135.188.86.250ClopCVE-2023-3436210/27/2023verifiedHigh
145.188.87.27ClopCVE-2023-3436210/27/2023verifiedHigh
155.188.87.194ClopCVE-2023-3436210/27/2023verifiedHigh
165.188.87.226ClopCVE-2023-3436210/27/2023verifiedHigh
175.252.23.116vm1120066.stark-industries.solutionsClopCVE-2023-3436210/27/2023verifiedHigh
185.252.25.88free.dsClopCVE-2023-3436210/27/2023verifiedHigh
195.252.189.0Clop04/02/2024verifiedHigh
205.252.190.0Clop04/02/2024verifiedHigh
215.252.191.0Clop04/02/2024verifiedHigh
2215.235.13.184gollum.utwb.netClopFortra GoAnywhere10/27/2023verifiedHigh
2315.235.83.73web0.meritusedu.caClopFortra GoAnywhere10/27/2023verifiedHigh
2420.47.120.195ClopFortra GoAnywhere10/27/2023verifiedHigh
2524.3.132.168c-24-3-132-168.hsd1.pa.comcast.netClopFortra GoAnywhere10/27/2023verifiedHigh
2644.206.3.111ec2-44-206-3-111.compute-1.amazonaws.comClopFortra GoAnywhere10/27/2023verifiedMedium
2745.56.165.248nordns.crowncloud.netClopCVE-2023-3436210/27/2023verifiedHigh
2845.227.253.6hosting-by.directwebhost.orgClopCVE-2023-3436210/27/2023verifiedHigh
29XX.XXX.XXX.XXxxxxxxx-xx.xxxxxxxxxxxxx.xxxXxxxXxx-xxxx-xxxxx10/27/2023verifiedHigh
30XX.XXX.XXX.XXxxxxxxx-xx.xxxxxxxxxxxxx.xxxXxxxXxx-xxxx-xxxxx10/27/2023verifiedHigh
31XX.XXX.XXX.XXXxxxxxxx-xx.xxxxxxxxxxxxx.xxxXxxxXxx-xxxx-xxxxx10/27/2023verifiedHigh
32XX.XXX.XXX.XXXxxxxxxx-xx.xxxxxxxxxxxxx.xxxXxxxXxx-xxxx-xxxxx10/27/2023verifiedHigh
33XX.XX.XXX.XXxxxxxxxx.xx-xx-xx-xxx.xxxXxxxXxxxxx Xxxxxxxxxx10/27/2023verifiedHigh
34XX.XXX.XXX.XXXxxx-xx-xxx-xxx-xxx.xx-xxxx-x.xxxxxxx.xxxxxxxxx.xxxXxxxXxxxxx Xxxxxxxxxx10/27/2023verifiedMedium
35XX.XXX.XX.XXxx-xxx-xx-xx.xxxxxx-xx-xxxxxxxxxxx.xxxXxxxXxx-xxxx-xxxxx10/27/2023verifiedHigh
36XX.XXX.XX.XXxxxxxx.x-xxx.xxxXxxxXxx-xxxx-xxxxx10/27/2023verifiedHigh
37XX.XXX.XX.XXXxxxxxx-xxxx.xxxxxxxx.xxxXxxxXxx-xxxx-xxxxx10/27/2023verifiedHigh
38XX.XX.XX.XXXxxxx.xxxxxxxx.xxxXxxxXxx-xxxx-xxxxx10/27/2023verifiedHigh
39XX.XX.XX.XXXxxxx-xxxxxx.xxxxxxx.xxxXxxxXxx-xxxx-xxxxx10/27/2023verifiedHigh
40XX.XX.XX.XXXXxxxXxx-xxxx-xxxxx10/27/2023verifiedHigh
41XX.XXX.XXX.XXXxxx-xx-xxx-xxx-xxx.xxxxxxx-x.xxxxxxxxx.xxxXxxxXxxxxx Xxxxxxxxxx10/27/2023verifiedMedium
42XX.XXX.XXX.Xx-xx-xxx-xxx-x.xxxx.xx.xxxxxxx.xxxXxxxXxxxxx Xxxxxxxxxx10/27/2023verifiedHigh
43XX.XX.XXX.XXxxxxxxxx.xxxxxxxxxxxxxxx.xxxXxxxXxxxxx Xxxxxxxxxx10/27/2023verifiedHigh
44XX.XXX.XXX.XXXxxxXxx-xxxx-xxxxx10/27/2023verifiedHigh
45XX.XXX.XXX.XXxxxxxxxxxx.xxxxxxxxxxxxxxxxx.xxxXxxxXxx-xxxx-xxxxx10/27/2023verifiedHigh
46XX.XXX.XXX.XXXXxxxXxxxxx Xxxxxxxxxx10/27/2023verifiedHigh
47XX.XX.XXX.XXxxxxxxxxx.xxxxxxxx.xxxxxxxxxXxxx10/29/2023verifiedHigh
48XX.XX.XXX.XXxxxxxxxxx.xxxxxxxx.xxxxxxxxxXxxx10/29/2023verifiedHigh
49XX.XX.XXX.XXxxxxxxxxx.xxxxxxxx.xxxxxxxxxXxxx10/29/2023verifiedHigh
50XX.XX.XXX.XXxxxxxxxxx.xxxxxxxx.xxxxxxxxxXxxx10/29/2023verifiedHigh
51XX.XX.XX.XXXxxxxx-x_xxxx-xx-xx-xx-xxx.xxx.xxxxxx.xxxXxxxXxxxxx Xxxxxxxxxx10/27/2023verifiedHigh
52XX.XXX.XXX.XXXxxxxx-xxxxxxxxxxxxxx-xxxxxxx.xxxxxx-xx-xxxxx.xxxXxxxXxxxxx Xxxxxxxxxx10/27/2023verifiedHigh
53XX.XXX.XXX.XXXxxx.xxxxxxxxxxxxx.xxxXxxxXxxxxx Xxxxxxxxxx10/27/2023verifiedHigh
54XX.XXX.XX.XXXxxxXxx-xxxx-xxxxx10/27/2023verifiedHigh
55XX.XXX.XX.XXXxxxxxxxx.xxxxXxxxXxx-xxxx-xxxxx10/27/2023verifiedHigh
56XX.XX.XX.XXXXxxx10/29/2023verifiedHigh
57XX.XX.XXX.XXXxx-xx-xxx-xxx.xxxxxx-xx-xxxxxxxxxxx.xxxXxxxXxx-xxxx-xxxxx10/27/2023verifiedHigh
58XX.XX.XXX.XXXxx-xx-xxx-xxx.xxxxxx-xx-xxxxxxxxxxx.xxxXxxxXxx-xxxx-xxxxx10/27/2023verifiedHigh
59XX.XXX.X.XXxxxxxxx.xxxxxxxxxx.xxxxxxxXxxxXxx-xxxx-xxxxx10/27/2023verifiedHigh
60XX.XXX.XXX.XXxxxxxxxxx.xxxxxxxxx.xxxXxxxXxxxxx Xxxxxxxxxx10/27/2023verifiedHigh
61XX.XXX.XXX.XXxxxxxxxxx.xxxxxxxxx.xxxXxxxXxx-xxxx-xxxxx10/27/2023verifiedHigh
62XX.XXX.XX.XXXxx.xxx.xx.xxx.xxxxxxxxx-xxxXxxxXxx-xxxx-xxxxx10/27/2023verifiedHigh
63XX.XXX.XX.XXXXxxx10/29/2023verifiedHigh
64XX.XXX.XX.XXXXxxxXxxxxx Xxxxxxxxxx10/27/2023verifiedHigh
65XX.XXX.XXX.XXXxx-xxx-xxx-xxx.xxxxxx-xx-xxxxxxxxxxx.xxxXxxxXxx-xxxx-xxxxx10/27/2023verifiedHigh
66XX.XXX.XXX.XXXxxxxxxxxx.xxxx.x-xxxxxxxxx.xxXxxx10/29/2023verifiedHigh
67XX.XXX.X.XXxxxx-xxx.xxxxxxxxxx.xxxXxxx10/29/2023verifiedHigh
68XX.XXX.X.XXXxxxx-xxxxxx.xxxxxxxxxxx.xxxXxxx10/29/2023verifiedHigh
69XX.XX.XXX.XXXxx.xx.xxx.xxx.xxxxxx.xxxxxxxxx.xxxXxxxXxxxxx Xxxxxxxxxx10/27/2023verifiedHigh
70XX.XXX.XXX.XXXxxxx-xx-xxx-xxx-xxx.xxxxxx.xxxx.xxxxxxx.xxxXxxx10/29/2023verifiedHigh
71XXX.XX.XXX.XXxxx-xxx-xx-xxx-xx.xx-xxxx-x.xxxxxxx.xxxxxxxxx.xxxXxxxXxxxxx Xxxxxxxxxx10/27/2023verifiedMedium
72XXX.XXX.XXX.XXXxxxxxxxxxxxxx.xxxXxxxXxx-xxxx-xxxxx10/27/2023verifiedHigh
73XXX.XXX.XX.XXXxxxxxxx.xxxxxxxxx.xx.xxxXxxxXxxxxx Xxxxxxxxxx10/27/2023verifiedHigh
74XXX.XX.XXX.XXXxxxx.xxxxxxx.xxXxxxXxxxxx Xxxxxxxxxx10/27/2023verifiedHigh
75XXX.XX.XXX.XXXXxxx10/29/2023verifiedHigh
76XXX.XXX.XX.XXXXxxx04/02/2024verifiedHigh
77XXX.XX.XX.XXXXxxx04/02/2024verifiedHigh
78XXX.XX.XXX.XXXxxxxxxxx.xx-xxx-xx-xxx.xxxXxxxXxxxxx Xxxxxxxxxx10/27/2023verifiedHigh
79XXX.X.XX.XXXXxxxXxx-xxxx-xxxxx10/27/2023verifiedHigh
80XXX.X.XX.XXXXxxxXxx-xxxx-xxxxx10/27/2023verifiedHigh
81XXX.X.XX.XXXXxxxXxx-xxxx-xxxxx10/27/2023verifiedHigh
82XXX.XXX.XXX.XXXxxxxxxxxx.xx-xxx-xxx-xxx.xxxXxxxXxx-xxxx-xxxxx10/27/2023verifiedHigh
83XXX.XXX.XXX.XXXxxxxxxxxx.xx-xxx-xxx-xxx.xxxXxxxXxxxxx Xxxxxxxxxx10/27/2023verifiedHigh
84XXX.XX.XXX.XXxxx-xx-xxx.xx-xxx.xxxx.xxXxxx10/29/2023verifiedHigh
85XXX.XX.XXX.XXXXxxxXxxxxx Xxxxxxxxxx10/27/2023verifiedHigh
86XXX.XXX.XXX.XXXXxxx10/29/2023verifiedHigh
87XXX.XXX.XX.XXxxxxxxxxx.xxxXxxxXxx-xxxx-xxxxx10/27/2023verifiedHigh
88XXX.XXX.XX.X.XxxxXxx-xxxx-xxxxx10/27/2023verifiedHigh
89XXX.XX.XX.XXXxxxXxxxxx Xxxxxxxxxx10/27/2023verifiedHigh
90XXX.XX.XXX.XXXXxxx04/02/2024verifiedHigh
91XXX.XXX.XX.XXXXxxx04/02/2024verifiedHigh
92XXX.XX.XXX.XXXxxx04/02/2024verifiedHigh
93XXX.XXX.XXX.XXXxxxx.xxxxxxxxxxxxx.xxxXxxxXxxxxx Xxxxxxxxxx10/27/2023verifiedHigh
94XXX.XX.XX.XXXXxxx10/29/2023verifiedHigh
95XXX.XX.XXX.XXXXxxxXxx-xxxx-xxxxx10/27/2023verifiedHigh
96XXX.XX.XXX.XXXxxx10/29/2023verifiedHigh
97XXX.XX.XX.XXXxxxxxx.xxxxx.xxxXxxxXxxxxx Xxxxxxxxxx10/27/2023verifiedHigh
98XXX.XX.XX.XXXxxxxxx.xxxxxxxxxxxxxxx.xxXxxxXxxxxx Xxxxxxxxxx10/27/2023verifiedHigh
99XXX.XX.XX.XXXxxxxx.xxxxxxxxxxx.xxxXxxxXxxxxx Xxxxxxxxxx10/27/2023verifiedHigh
100XXX.XX.XXX.XXXXxxxXxxxxx Xxxxxxxxxx10/27/2023verifiedHigh
101XXX.XXX.XXX.XXxxxxxxxxxxxx.xxxXxxxXxx-xxxx-xxxxx10/27/2023verifiedHigh
102XXX.XXX.XXX.XXxxxxxxxxx.xxxXxxxXxx-xxxx-xxxxx10/27/2023verifiedHigh
103XXX.XXX.XXX.XXXXxxxXxxxxx Xxxxxxxxxx10/27/2023verifiedHigh
104XXX.XXX.XXX.XXXXxxxXxx-xxxx-xxxxx10/27/2023verifiedHigh
105XXX.XXX.XX.Xxxxxxxxxx.xxxXxxxXxxxxx Xxxxxxxxxx10/27/2023verifiedHigh
106XXX.XXX.XX.XXXxxxXxx-xxxx-xxxxx10/27/2023verifiedHigh
107XXX.XXX.XXX.XXxxxxxxxx.xxxxxxxxxxxxxxx.xxxXxxxXxx-xxxx-xxxxx10/27/2023verifiedHigh
108XXX.XXX.XXX.XXXxxx.xxx.xxx.xxx.xxxxxxxxx-xxxXxxxXxx-xxxx-xxxxx10/27/2023verifiedHigh
109XXX.XXX.XXX.XXXxxx.xxx.xxx.xxx.xxxxxxxxx-xxxXxxxXxx-xxxx-xxxxx10/27/2023verifiedHigh
110XXX.XXX.XXX.XXxx-xxxx.xxxxxxxxxxxxx.xxxXxxxXxx-xxxx-xxxxx10/27/2023verifiedHigh
111XXX.XXX.XXX.XXXxx-xxxx.xxxxxxxxxxxxx.xxxXxxxXxx-xxxx-xxxxx10/27/2023verifiedHigh
112XXX.XXX.XX.XXXxxx-xxx-xx-xxx.xxxxxx-xx-xxxxxxxxxxx.xxxXxxxXxx-xxxx-xxxxx10/27/2023verifiedHigh
113XXX.XXX.XX.XXXxxx-xxx-xx-xxx.xxxxxx-xx-xxxxxxxxxxx.xxxXxxxXxx-xxxx-xxxxx10/27/2023verifiedHigh
114XXX.XXX.X.XXXxxx-xxx-xxx-x-xxx-xxx.xxxx-xxxxxxxxx.xxx.xxXxxx10/29/2023verifiedHigh
115XXX.XXX.XX.XXXxxxxxxxxxxxxx.xxxxxxxx.xxxXxxxXxx-xxxx-xxxxx10/27/2023verifiedHigh
116XXX.XXX.XX.XXxxxxxxxx-xxxxxx-xxx-xx-xx.xxxxxxxxxxxxx.xxxXxxx10/29/2023verifiedHigh
117XXX.XX.XXX.XXXx.xxx-xxxx.xxxxxxxxxxxxx.xxXxxxXxxxxx Xxxxxxxxxx10/27/2023verifiedHigh
118XXX.XXX.XXX.XXXxxx-xxx-xxx.-xxx.xxxxx.xxxXxxx10/29/2023verifiedHigh
119XXX.XX.XX.XXXxxxxxxxx.xxxxxxxxxxxxxxx.xxxXxxxXxxxxx Xxxxxxxxxx10/27/2023verifiedHigh
120XXX.XXX.XXX.XXxxx.xxx.xxx.xx.xxxxxxxxx-xxxXxxxXxx-xxxx-xxxxx10/27/2023verifiedHigh
121XXX.XX.XX.Xxxxxx.xxxxxxx.xxXxxxXxx-xxxx-xxxxx10/27/2023verifiedHigh
122XXX.XX.XX.XXXXxxxXxx-xxxx-xxxxx10/27/2023verifiedHigh
123XXX.XX.XX.XXXXxxxXxx-xxxx-xxxxx10/27/2023verifiedHigh
124XXX.XX.XX.XXXXxxx10/29/2023verifiedHigh
125XXX.XX.XX.XXXxxx-xx-xx-xxx-xxxx.xxxxxxxxxxxx.xxxXxxxXxx-xxxx-xxxxx10/27/2023verifiedHigh
126XXX.XX.XX.XXXxxxxxxxxx.xx-xxx-xx-xx.xxxXxxxXxx-xxxx-xxxxx10/27/2023verifiedHigh
127XXX.XX.XXX.XXXxxxxxx-xxx-xx-xxx-xxx.xxxx.xxxxx.xxxXxxx10/29/2023verifiedHigh
128XXX.XXX.XXX.XXXxxxXxxxxx Xxxxxxxxxx10/27/2023verifiedHigh
129XXX.XXX.XXX.XXXXxxxXxx-xxxx-xxxxx10/27/2023verifiedHigh
130XXX.XXX.XXX.XXxx-xxx-xxx-xxx.xxxxxx.xxxxxxx.xxxx.xxxXxxxXxxxxx Xxxxxxxxxx10/27/2023verifiedHigh
131XXX.XXX.X.XXXxxxXxx-xxxx-xxxxx10/27/2023verifiedHigh
132XXX.XXX.XXX.XXXxxxxx.xxxxxxxxxxxx.xxxXxxxXxx-xxxx-xxxxx10/27/2023verifiedHigh
133XXX.XXX.XX.XXXxxxXxxxxx Xxxxxxxxxx10/27/2023verifiedHigh
134XXX.XXX.XXX.XXXXxxxXxx-xxxx-xxxxx10/27/2023verifiedHigh
135XXX.XXX.XXX.XXXxxxXxxxxx Xxxxxxxxxx10/27/2023verifiedHigh
136XXX.XXX.XXX.XXxx-xxx-xxx-xxx.xxxxxx.xxxxxxx.xxxx.xxxXxxxXxxxxx Xxxxxxxxxx10/27/2023verifiedHigh
137XXX.XXX.XXX.XXXXxxx10/29/2023verifiedHigh

TTP - Tactics, Techniques, Procedures (14)

Tactics, techniques, and procedures summarize the suspected MITRE ATT&CK techniques used. This data is unique as it uses our predictive model for actor profiling.

IOA - Indicator of Attack (66)

These indicators of attack list the potential fragments used for technical activities like reconnaissance, exploitation, privilege escalation, and exfiltration. This data is unique as it uses our predictive model for actor profiling.

IDClassIndicatorTypeConfidence
1File/catalog/all-productspredictiveHigh
2File/changePasswordpredictiveHigh
3File/goform/addIpMacBindpredictiveHigh
4File/goform/DelDhcpRulepredictiveHigh
5File/goform/delIpMacBindpredictiveHigh
6File/goform/DelPortMappingpredictiveHigh
7File/goform/modifyDhcpRulepredictiveHigh
8File/goform/modifyIpMacBindpredictiveHigh
9File/xxxxxx/xxxxxxxxxxxxpredictiveHigh
10File/xxxxxx/xxxxxxxxxxpredictiveHigh
11File/xxxxxx/xxxxxxxxxpredictiveHigh
12File/xxxxxx/xxxxxxxxxxxxxxxxpredictiveHigh
13File/xxxxxx/xxxxxxxxxxxxxxpredictiveHigh
14File/xxxxxx/xxxxxxxxxxxxxxxxxxpredictiveHigh
15File/xxxxxx/xxxxxxxxxxxxxxpredictiveHigh
16File/xxxxxx/xxxxxxxxxxxxxpredictiveHigh
17File/xxxxxx/xxxxxxxxxxxxxxxxxxxpredictiveHigh
18File/xxxxxx/xxxxxxxxxxxpredictiveHigh
19File/xxxxxx/xxxxxxxxxx.xxxpredictiveHigh
20File/xxxxxxxxxxx.xxx/xxxxxxxxpredictiveHigh
21File/xxx/xxxxxxx/xxxpredictiveHigh
22File/xxxx/xxxxxxx xxxxxx/xxx/xxx_xxxx_xxxxxx.xxxpredictiveHigh
23Filexxxxx/xxxxxxx/xxxxxxxxxxxxx.xxpredictiveHigh
24Filexxxxx.xxxpredictiveMedium
25Filexxxxxxxxxxxx.xxxpredictiveHigh
26Filexxxxxxxxxxxxxxxxxxx.xxxpredictiveHigh
27Filexxxxxxx/xxxxxxxx.xxxpredictiveHigh
28Filexx/xxxxxx/xxxxxxxxxxpredictiveHigh
29Filexxxxx-xxxxxx-xxxxxx.xxxxpredictiveHigh
30Filexxxxx.xxxpredictiveMedium
31Filexxxxxxxx.xxxpredictiveMedium
32Filexxxxxxxx.xxxpredictiveMedium
33Filexxxxxxxx.xxxpredictiveMedium
34Filexxxx-xxxxxxxx.xxxpredictiveHigh
35Argumentxxxxx_xxxxxpredictiveMedium
36ArgumentxxxxxxxxxxxxxpredictiveHigh
37ArgumentxxxpredictiveLow
38ArgumentxxxxxxxxxpredictiveMedium
39ArgumentxxxxxxxxxxxxpredictiveMedium
40ArgumentxxxxxxxxxxpredictiveMedium
41ArgumentxxxxxxxpredictiveLow
42ArgumentxxxxpredictiveLow
43ArgumentxxxxxxxxxxxxxxxxxxxxxxpredictiveHigh
44Argumentxx/xxxxpredictiveLow
45ArgumentxxpredictiveLow
46ArgumentxxpredictiveLow
47ArgumentxxxxxxxxxxxxxxpredictiveHigh
48ArgumentxxxxxxxxxxxxxpredictiveHigh
49Argumentxxxxxxxxxxxxxxx/xxxxxxxxxxxxxxx/xxxxxxxxxxxxxxxx/xxxxxxxxxxxxxxxxxxxpredictiveHigh
50ArgumentxxxxpredictiveLow
51ArgumentxxxxxxxxxxpredictiveMedium
52ArgumentxxxxxxxxxxxxpredictiveMedium
53ArgumentxxxxpredictiveLow
54ArgumentxxxxxxxxxxxxxxxxpredictiveHigh
55Argumentxxxxxxx_xxxxxxx_xxxxx_xxxxx_xxxxxpredictiveHigh
56ArgumentxxxxxxpredictiveLow
57ArgumentxxxxxxxxpredictiveMedium
58ArgumentxxxxxxxxxxxxxxxxxxpredictiveHigh
59ArgumentxxxxxxxxxxpredictiveMedium
60ArgumentxxxxxxxxpredictiveMedium
61Argumentxxxxxxxxxx/xxxxxxxx/xxxxxxx/xxxxxxxxxxpredictiveHigh
62ArgumentxxxxxxxxxpredictiveMedium
63ArgumentxxxxxxxxxxxxxxxxpredictiveHigh
64ArgumentxxxxpredictiveLow
65ArgumentxxxxxxxxxxpredictiveMedium
66Argumentxxxx/xxxxx/xxx/xxxx/xxxxxx/xxxxxxpredictiveHigh

References (5)

The following list contains external sources which discuss the actor and the associated activities:

Do you want to use VulDB in your project?

Use the official API to access entries easily!