KrBanker Analysis
IOB - Indicator of Behavior (1)
Activities
Campaigns (1)
These are the campaigns that can be associated with the actor:
- KaiXin/NEWSPOT
IOC - Indicator of Compromise (5)
These indicators of compromise highlight associated network ressources which are known to be part of research and attack activities.
ID | IP address | Hostname | Actor | Campaigns | Identified | Type | Confidence |
---|---|---|---|---|---|---|---|
1 | 23.107.204.38 | KRBanker | KaiXin/NEWSPOT | 08/30/2021 | verified | High | |
2 | XX.XXX.XX.XX | Xxxxxxxx | 04/26/2024 | verified | High | ||
3 | XX.XXX.XX.X | Xxxxxxxx | 04/26/2024 | verified | High | ||
4 | XX.XXX.XXX.XXX | Xxxxxxxx | 03/09/2024 | verified | High | ||
5 | XXX.XXX.XXX.XX | Xxxxxxxx | 04/27/2024 | verified | High |
TTP - Tactics, Techniques, Procedures (1)
Tactics, techniques, and procedures summarize the suspected MITRE ATT&CK techniques used. This data is unique as it uses our predictive model for actor profiling.
ID | Technique | Class | Vulnerabilities | Access Vector | Type | Confidence |
---|---|---|---|---|---|---|
1 | T1006 | CAPEC-126 | CWE-22 | Path Traversal | predictive | High |
References (6)
The following list contains external sources which discuss the actor and the associated activities:
- https://github.com/vuldb/cyber_threat_intelligence/tree/main/actors/KrBanker
- xxxxx://xxxxxxxxx.xxxxx.xx
- xxxxx://xxxx.xx/xxxxxx-xxxxxxxxxx
- xxxxx://xxxx.xx/xxxxxx-xxxxxxxxxx
- xxxxx://xxxx.xx/xxxxxx-xxxxxxxxxx
- xxxxx://xxxxxx.xxxxxxxxxxxxxxxx.xxx/xxxxxx-xxxxxxxx-xxxxxxx-xxxxx-xxxxx-xxxxxxx-xxxxxx-xxx-xxxxxxx-xxxx-x/