JanelaRAT Analysis

IOB - Indicator of Behavior (1000)

Timeline

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Lang

en920
de18
zh14
ru14
es8

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Country

us982
cn14
ir2
br2

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Actors

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Activities

Interest

Timeline

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Type

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Vendor

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Product

Pearlinger Products6
Microsoft Windows4
Vmware Workspace ONE Access4
Linux Kernel4
PHPWind4

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Vulnerabilities

#VulnerabilityBaseTemp0dayTodayExpRemEPSSCTICVE
1LogicBoard CMS away.php redirect6.36.1$0-$5k$0-$5kNot DefinedUnavailable0.000006.55
2DZCP deV!L`z Clanportal config.php code injection7.36.6$0-$5k$0-$5kProof-of-ConceptOfficial Fix0.009430.83CVE-2010-0966
3FLDS redir.php sql injection7.37.3$0-$5k$0-$5kHighUnavailable0.002030.07CVE-2008-5928
4Tiki Admin Password tiki-login.php improper authentication8.07.7$0-$5k$0-$5kNot DefinedOfficial Fix0.009363.50CVE-2020-15906
5My Link Trader out.php sql injection6.35.7$0-$5k$0-$5kProof-of-ConceptNot Defined0.000000.11
6Bitrix Site Manager redirect.php link following5.34.7$0-$5k$0-$5kUnprovenUnavailable0.001130.03CVE-2008-2052
7PHP phpinfo cross site scripting4.33.9$5k-$25k$0-$5kProof-of-ConceptOfficial Fix0.019600.00CVE-2007-1287
8SAS Web Report Studio javascript: URL logonAndRender.do cross site scripting3.53.4$0-$5k$0-$5kNot DefinedNot Defined0.000890.00CVE-2022-25256
9Vunet VU Web Visitor Analyst redir.asp sql injection7.37.1$0-$5k$0-$5kHighWorkaround0.001190.03CVE-2010-2338
10Serendipity exit.php privileges management6.36.0$0-$5k$0-$5kProof-of-ConceptNot Defined0.000000.22
11OpenX adclick.php redirect5.34.7$0-$5k$0-$5kUnprovenUnavailable0.004400.83CVE-2014-2230
12Lars Ellingsen Guestserver guestbook.cgi cross site scripting4.34.3$0-$5k$0-$5kNot DefinedNot Defined0.001690.07CVE-2005-4222
13Microsoft Windows Roaming Security Rights Management Services Remote Code Execution8.17.4$100k and more$5k-$25kUnprovenOfficial Fix0.008500.06CVE-2022-21974
14GetSimpleCMS index.php redirect6.66.6$0-$5k$0-$5kNot DefinedNot Defined0.001230.00CVE-2019-9915
15vBulletin redirector.php6.66.6$0-$5k$0-$5kNot DefinedNot Defined0.001060.11CVE-2018-6200
16Atlassian Jira Service Management Server/Data Center InsightDefaultCustomFieldConfig.jspa cross site scripting3.53.4$0-$5k$0-$5kNot DefinedOfficial Fix0.000540.00CVE-2021-43943
17PHPWind goto.php redirect6.36.3$0-$5k$0-$5kNot DefinedNot Defined0.003480.22CVE-2015-4134
18Openads adclick.php Remote Code Execution7.36.9$0-$5k$0-$5kProof-of-ConceptNot Defined0.018710.43CVE-2007-2046
19Atlassian JIRA Server/Data Center Thread Contention/CPU Monitoring Service ViewInstrumentation.jspa cross-site request forgery4.34.1$0-$5k$0-$5kNot DefinedOfficial Fix0.000740.00CVE-2021-43953
20Microsoft Windows Ancillary Function Driver for WinSock Privilege Escalation8.17.4$100k and more$5k-$25kUnprovenOfficial Fix0.000430.02CVE-2022-24507

IOC - Indicator of Compromise (12)

These indicators of compromise highlight associated network ressources which are known to be part of research and attack activities.

TTP - Tactics, Techniques, Procedures (18)

Tactics, techniques, and procedures summarize the suspected MITRE ATT&CK techniques used. This data is unique as it uses our predictive model for actor profiling.

IOA - Indicator of Attack (301)

These indicators of attack list the potential fragments used for technical activities like reconnaissance, exploitation, privilege escalation, and exfiltration. This data is unique as it uses our predictive model for actor profiling.

IDClassIndicatorTypeConfidence
1File/admin/general.cgipredictiveHigh
2File/Admin/login.phppredictiveHigh
3File/admin/reminders/manage_reminder.phppredictiveHigh
4File/API/infopredictiveMedium
5File/CCMAdmin/serverlist.asppredictiveHigh
6File/cgi/get_param.cgipredictiveHigh
7File/csms/admin/inquiries/view_details.phppredictiveHigh
8File/cstecgi.cgipredictiveMedium
9File/files.md5predictiveMedium
10File/forum/away.phppredictiveHigh
11File/home/searchpredictiveMedium
12File/hrm/employeeview.phppredictiveHigh
13File/include/chart_generator.phppredictiveHigh
14File/index.php?menu=asterisk_clipredictiveHigh
15File/librarian/bookdetails.phppredictiveHigh
16File/loginpredictiveLow
17File/messageboard/view.phppredictiveHigh
18File/oauth/idp/.well-known/openid-configurationpredictiveHigh
19File/one_church/userregister.phppredictiveHigh
20File/out.phppredictiveMedium
21File/owa/auth/logon.aspxpredictiveHigh
22File/SAP_Information_System/controllers/add_admin.phppredictiveHigh
23File/SASWebReportStudio/logonAndRender.dopredictiveHigh
24File/secure/admin/InsightDefaultCustomFieldConfig.jspapredictiveHigh
25File/secure/admin/ViewInstrumentation.jspapredictiveHigh
26File/SVFE2/pages/feegroups/country_group.jsfpredictiveHigh
27File/SystemMng.ashxpredictiveHigh
28File/textpattern/index.phppredictiveHigh
29File/upfile.cgipredictiveMedium
30File/v2/quantum/save-data-upload-big-filepredictiveHigh
31File/wordpress/wp-admin/admin.phppredictiveHigh
32File4.edu.phppredictiveMedium
33FileAccountManagerService.javapredictiveHigh
34Fileaccount_footer.phppredictiveHigh
35Fileadclick.phppredictiveMedium
36Fileaddlink.phppredictiveMedium
37Filexxx_xxxx_xxx.xxxpredictiveHigh
38Filexxx_xxxx_xxxx.xxxpredictiveHigh
39Filexxxxx.xxxxxxxxxx.xxxpredictiveHigh
40Filexxxxx.xxxxxxxxx.xxxpredictiveHigh
41Filexxxxx/xxxxxxxxxxx.xxxpredictiveHigh
42Filexxxxx/xxxx_xxxxxxxx.xxxpredictiveHigh
43Filexxxxx/xxxxx.xxxpredictiveHigh
44Filexxxxx/xxxxxxxxxxxxx.xxxpredictiveHigh
45Filexxxxxxxxxxxxxxxx.xxxpredictiveHigh
46Filexxxxxxxxxxx.xxxpredictiveHigh
47Filexxxxxxxxxxx.xxxpredictiveHigh
48Filexxxx_xxxx_xxxxxxxx.xxxpredictiveHigh
49Filexx_xxxxxxxxxx.xxxpredictiveHigh
50Filexxx/xxxxxx/xxxx_xxxxxx.xxxpredictiveHigh
51Filexxxxxxxxxxxxxx.xxxpredictiveHigh
52Filexxxxxxxx.xxxxxxx.xxxpredictiveHigh
53Filexx_xxxxx_xxxxx.xxxpredictiveHigh
54Filexx_xxxx.xxxpredictiveMedium
55Filexxx_xxxxxxxxx.xxxpredictiveHigh
56Filex:\xxxxpredictiveLow
57Filexxxxxx/xxxxx/xxxxx.xxxpredictiveHigh
58Filexxxx_xxxxxxx.xxxpredictiveHigh
59Filexxxxxxxx.xxxpredictiveMedium
60Filexxxxxxxx.xxxpredictiveMedium
61Filexxx-xxx/xxxxxxxxxxxx.xxxpredictiveHigh
62Filexxx-xxx/xxx/xxxxxxxx_xxx.xxxpredictiveHigh
63Filexxxxxxxxxxx.xxxpredictiveHigh
64Filexxxxx.xxxxx.xxxpredictiveHigh
65Filexxxxx/xxxxx_xxxxxx.xxxpredictiveHigh
66Filexxxxxxxxxx_xxxxx.xxxpredictiveHigh
67Filexxxxx_xx_xxxxxxxxx.xxxpredictiveHigh
68Filexxxxx_xxxx.xxxpredictiveHigh
69Filexxxxx.xxxpredictiveMedium
70Filexxx.xxx?xxx=xxxxx_xxxxpredictiveHigh
71Filexxxx/xxxxxxxx.xxpredictiveHigh
72Filexxxxxxxx_xxxxxxxxxxxxxxxxx.xxxpredictiveHigh
73Filexxxxxxx.xxxpredictiveMedium
74Filexxxxxxxxxx.xxxpredictiveHigh
75Filexxxxxxxxxxxxxxxxxxx.xxpredictiveHigh
76Filexxxxxxxxx.xxxpredictiveHigh
77Filexxxxxxx.xxxpredictiveMedium
78Filexxxxxx.xxxpredictiveMedium
79Filexxxxxx.xxxpredictiveMedium
80Filexxxxxxxx.xxxpredictiveMedium
81Filexxxxxxxxxx-xxxxxxxxxxxxx.xxxpredictiveHigh
82Filexxxxxxx/xxxxx/xxxxx.xpredictiveHigh
83Filexxxxx.xxxpredictiveMedium
84Filexxxxx.xxxpredictiveMedium
85Filexxxx.xxxpredictiveMedium
86Filexxxxxxxx.xxxpredictiveMedium
87Filexxxxxxxx.xxxpredictiveMedium
88Filexxxxxxxxx.xxxpredictiveHigh
89Filexxxxxx.xxxxpredictiveMedium
90Filexxxx.xxxpredictiveMedium
91Filexxxx.xxxpredictiveMedium
92Filexxxxxxxxx.xxxpredictiveHigh
93Filexxxxxxxxx.xxpredictiveMedium
94Filexxxxxxxxxx.xxxpredictiveHigh
95Filexxxxx_xxxxxx.xxxpredictiveHigh
96Filexxxxxxxxx.xxxpredictiveHigh
97Filexxx/xxxxxxxx.xxxpredictiveHigh
98Filexxx/xxxxxx.xxxpredictiveHigh
99Filexxx/xxxxxxxxxxx/xxxxxxx.xxxpredictiveHigh
100Filexxx/xxxxxxx/xxxxxxxxxxxx.xxxpredictiveHigh
101Filexxxxxxx.xxxpredictiveMedium
102Filexxxxxxx/xxxx.xxxpredictiveHigh
103Filexxxxxxxx/xxxx.xxxpredictiveHigh
104Filexxxxx.xxxpredictiveMedium
105Filexxxx.xxxxpredictiveMedium
106Filexxxxxxxxxxxxx.xxxpredictiveHigh
107Filexxxxxxxx/xxxxxxxx_xxxxxxx_xxxxxx/xxxxx.xxxpredictiveHigh
108Filexxxx_xxxx.xxxpredictiveHigh
109Filexxx_xxxxxxxxx.xxxpredictiveHigh
110Filexxx.xxxxpredictiveMedium
111Filexxxxxx/xxxxxx/xxxxxx-xx.xpredictiveHigh
112Filexxxxxx.xxxpredictiveMedium
113Filexxxxx.xxxxpredictiveMedium
114Filexxxxx.xxxpredictiveMedium
115Filexxxxx.xxxxpredictiveMedium
116Filexxxxx_xxxxxxx.xxxpredictiveHigh
117Filexxx_xxxxxxxx.xxxpredictiveHigh
118Filexxx/xxxx_xxx.xxxpredictiveHigh
119Filexxxxxxx.xxxpredictiveMedium
120Filexxxxxxx/xxx.xxxpredictiveHigh
121Filexxx/xxxxxxxxx/xx_xxx_xxxxxx.xpredictiveHigh
122Filexxx.xxxpredictiveLow
123Filexxxxxx_xx.xxxpredictiveHigh
124Filexxx/xxxxx.xxxxpredictiveHigh
125Filex-xxxx.xxxpredictiveMedium
126Filexxxx.xxxxxxxxx.xxxpredictiveHigh
127Filexxxxxxxxx.xxx.xxxpredictiveHigh
128Filexxxxxx.xxxpredictiveMedium
129Filexxxx.xxxpredictiveMedium
130Filexxxx.xxxpredictiveMedium
131Filexxxxxxxxx/xxxxxxxxxxxxxx.xxxxpredictiveHigh
132Filexxx.xxxxx.xxxpredictiveHigh
133Filexxxxx.xxxpredictiveMedium
134Filexxxxx.xxxpredictiveMedium
135Filexxxxxxxx.xxxpredictiveMedium
136Filexxxxxxxxxx.xxxpredictiveHigh
137Filexxxxxxxx.xxxpredictiveMedium
138Filexxxxxxxx.xxxpredictiveMedium
139Filexxxxxxxx_xxxx.xxxpredictiveHigh
140Filexxxxxxxxxxxx_xxxxxxxx.xxx.xxxpredictiveHigh
141Filexxxxxx.xxxpredictiveMedium
142Filexxxxxxxx.xpredictiveMedium
143Filexx_xxxx.xpredictiveMedium
144Filexxxx_xxxx_xxxxxx.xxxpredictiveHigh
145Filexxxxxx.xxxpredictiveMedium
146Filexxxxxx.xxxpredictiveMedium
147Filexxxx/xxxxxxx/xxxxxxxxxxxxx_xxx.xxxpredictiveHigh
148Filexxxxxx.xxxxpredictiveMedium
149Filexxxxxxxx-xxxxxx_xxxxx.xxxpredictiveHigh
150Filexxxx.xxxpredictiveMedium
151Filexxxx_xxxxxxx_xxxxxxxx.xxxpredictiveHigh
152Filexxxxxxxx.xxx/xxxxxx.xxx/xxxxxxxx.xxxpredictiveHigh
153Filexxxxxxxxxxx.xxxpredictiveHigh
154Filexxx/xxx/xxxxxxx/xxxx.xxxpredictiveHigh
155Filexxxxx_xxxxx.xxxpredictiveHigh
156Filexxxx-xxxxx.xxxpredictiveHigh
157Filexxxx-xxxxxxxx.xxxpredictiveHigh
158Filexxxxx.xxpredictiveMedium
159Filexxxxx.xxxpredictiveMedium
160Filexxxxxx.xxxpredictiveMedium
161Filexxxx.xxxpredictiveMedium
162Filexxxxx-xxxxxxxx-xxxxx-xxxxxxxxxxx-xxx-xxxxx.xxxpredictiveHigh
163Filexxxxx.xxxxpredictiveMedium
164Filexxxx.xxxpredictiveMedium
165Filexxxxxxxxx.xxxxpredictiveHigh
166Filexxxxxxx/xxxxxxxxx/xxxxxxxxxxxx.xxxpredictiveHigh
167Filexxxxxxx.xxxpredictiveMedium
168Filexx-xxxxx/xxxxx.xxxpredictiveHigh
169Filexx.xxxpredictiveLow
170Filexxxxxxxxxxxx.xxxpredictiveHigh
171File~/xxxxx-xxxxx.xxxpredictiveHigh
172File~/xxxxxxxx-xxxxxxxx.xxxpredictiveHigh
173Libraryxxxxxx[xxxxxx_xxxxpredictiveHigh
174Libraryxxxxxx.xxxxxxxxx.xxxxxxx.xxxxx_xxxxx.xxxpredictiveHigh
175Libraryxxxx/xxxxxxx/xxxx/xxxxxxxxx/xxxxx.xxxpredictiveHigh
176Library~/xxx/xxxxx-xxxxxxxx-xxxxxxxxxx.xxxpredictiveHigh
177Argument$_xxxxxxpredictiveMedium
178Argumentxxx_xxxxpredictiveMedium
179Argumentxx_xxpredictiveLow
180ArgumentxxxxxxpredictiveLow
181ArgumentxxpredictiveLow
182Argumentxxx_xxpredictiveLow
183ArgumentxxpredictiveLow
184ArgumentxxpredictiveLow
185ArgumentxxxxxxxxpredictiveMedium
186ArgumentxxxxxxxxpredictiveMedium
187ArgumentxxxxxpredictiveLow
188ArgumentxxxxpredictiveLow
189Argumentxxxx_xxx_xxxxpredictiveHigh
190ArgumentxxxpredictiveLow
191ArgumentxxxxxxxxpredictiveMedium
192ArgumentxxxxxxxxxxpredictiveMedium
193Argumentxxxxxxxx_xxxxpredictiveHigh
194Argumentxxx_xxpredictiveLow
195Argumentxx_xxxxxxpredictiveMedium
196ArgumentxxxxpredictiveLow
197Argumentxxxx_xxpredictiveLow
198ArgumentxxxxxxxpredictiveLow
199ArgumentxxxxxxxxxxpredictiveMedium
200Argumentxxxxxx[xxxxxx_xxxx]predictiveHigh
201Argumentxxxx_xxpredictiveLow
202ArgumentxxxxxxxxxxxxpredictiveMedium
203ArgumentxxxpredictiveLow
204ArgumentxxxxxxxxpredictiveMedium
205ArgumentxxxxxpredictiveLow
206ArgumentxxxxpredictiveLow
207Argumentxxxxx_xxxx_xxxxpredictiveHigh
208Argumentxxxxxxx=xxxxxxxxpredictiveHigh
209ArgumentxxxxpredictiveLow
210ArgumentxxxxxxxpredictiveLow
211Argumentxxxxxxx_xxxxxxxpredictiveHigh
212Argumentxxxxxxxxxxxxxx[xxxxxxxxxxxxxxxxxx]predictiveHigh
213ArgumentxxxxxxxxpredictiveMedium
214ArgumentxxxxpredictiveLow
215ArgumentxxpredictiveLow
216Argumentxx/xx_xxxxxx_xxxx/xx_xxxx_xxxxxxpredictiveHigh
217ArgumentxxxxxxxxxpredictiveMedium
218Argumentxx_xxxxxpredictiveMedium
219ArgumentxxxxxpredictiveLow
220Argumentxxxxx_xxxxpredictiveMedium
221ArgumentxxxxxxpredictiveLow
222Argumentxxxx_xxpredictiveLow
223ArgumentxxxxpredictiveLow
224Argumentxxxxxxxx_xxxpredictiveMedium
225Argumentxxx_xxxpredictiveLow
226ArgumentxxxxxxxpredictiveLow
227ArgumentxxxpredictiveLow
228ArgumentxxxxpredictiveLow
229ArgumentxxxxxxxpredictiveLow
230Argumentxxx_xxxx_xxxxpredictiveHigh
231ArgumentxxxxxxxxxxpredictiveMedium
232ArgumentxxxpredictiveLow
233Argumentxx_xxxxpredictiveLow
234Argumentxxx/xxxxxxxxxpredictiveHigh
235Argumentxxxxxxxxx_xxxxxxxx_xxxxpredictiveHigh
236ArgumentxxxxxpredictiveLow
237Argumentxxxxxxx_xxxxpredictiveMedium
238ArgumentxxxxpredictiveLow
239Argumentxxxx/xxxxxxxx/xxx/xxx/xxxxxxxx/xxxxxxxpredictiveHigh
240Argumentxxxxxxx_xxpredictiveMedium
241Argumentxxxxxx xxxxxxpredictiveHigh
242ArgumentxxxxxxxxxxxxpredictiveMedium
243ArgumentxxxxpredictiveLow
244Argumentxxx_xxx[]predictiveMedium
245ArgumentxxxxxxxxpredictiveMedium
246Argumentxxxx_xx_xx_xxxpredictiveHigh
247ArgumentxxxxxxxpredictiveLow
248ArgumentxxxxxxxxxxxxxpredictiveHigh
249ArgumentxxxxxxxxxpredictiveMedium
250Argumentxxxxx_xxxx_xxxxpredictiveHigh
251ArgumentxxxxxxxxxxxxpredictiveMedium
252ArgumentxxxxxpredictiveLow
253ArgumentxxxxxxxpredictiveLow
254ArgumentxxxxpredictiveLow
255Argumentxx_xxxxpredictiveLow
256Argumentxx_xxxxpredictiveLow
257ArgumentxxxxxxpredictiveLow
258ArgumentxxxxxpredictiveLow
259ArgumentxxxxxxxxpredictiveMedium
260ArgumentxxxxxxxxxxpredictiveMedium
261ArgumentxxxxxpredictiveLow
262Argumentxxxxxxx_xxpredictiveMedium
263ArgumentxxxxxxxxxxpredictiveMedium
264Argumentxxxxxx_xxxxxxx_xxxxxxxxx_xxxx/xxxxxx_xxxxxxx_xxxxxxx_xxxxpredictiveHigh
265ArgumentxxxpredictiveLow
266ArgumentxxxxxxpredictiveLow
267Argumentxxxxxx_xxxxxxpredictiveHigh
268ArgumentxxxpredictiveLow
269Argumentxxxxxx_xxxpredictiveMedium
270Argumentxxxx_xxxxpredictiveMedium
271ArgumentxxxxxxxpredictiveLow
272Argumentxxxxxx_xxpredictiveMedium
273Argumentxxxxxxx_xxpredictiveMedium
274ArgumentxxxxxxpredictiveLow
275Argumentxx_xxxxx_xxxx_xxxxpredictiveHigh
276ArgumentxxpredictiveLow
277ArgumentxxxxxxxxxpredictiveMedium
278ArgumentxxxxxxxpredictiveLow
279ArgumentxxxxxxxxxxpredictiveMedium
280Argumentx_xxpredictiveLow
281ArgumentxxxxxpredictiveLow
282Argumentxxxxxxxxxx_xxpredictiveHigh
283ArgumentxxxxxxxxxxxpredictiveMedium
284ArgumentxxxxpredictiveLow
285Argumentxxxx_xxpredictiveLow
286ArgumentxxxpredictiveLow
287ArgumentxxxpredictiveLow
288Argumentxxxx.xxxxxpredictiveMedium
289Argumentxxxxxxxx:x_xxxx/xxxxxxxx:x_xxxx/xxxxxxxx:x_xxxxpredictiveHigh
290ArgumentxxxxxxpredictiveLow
291ArgumentxxxxxxxxpredictiveMedium
292Argumentxxxx_xxpredictiveLow
293Argumentxx_xxxxpredictiveLow
294Input Value' xxx (xxxxxx xxxx xxxx (xxxxxx(xxxxx(x)))xxxx)-- xxxxpredictiveHigh
295Input Value..predictiveLow
296Input ValuexxpredictiveLow
297Input Valuex%xxxxxxx%xxxxxxxx%xxx,xxxxxx_xx%xxxxxx,xx_xxxxxxx,xxxxxxxx%xx,x,x,x,x,x,x,x,xx,xx,xx,xx,xx,xx,xx,xx,xx%xxxxxx%xxxxxxxxxx%xxxxxxx%xxxx%xxxpredictiveHigh
298Input Value<xxx%xxxxx='xxxx://xxx.xxxx.xx/xxxx.xxx'%xxxxxxx='xxxxxx:%xxxxx%xxxxxxx%xxxxxxx;'>predictiveHigh
299Input Value\xxx../../../../xxx/xxxxxxpredictiveHigh
300Patternxxxxxxx-xxxx|xx| xxxx/xxxxpredictiveHigh
301Patternxxxx /xpredictiveLow

References (6)

The following list contains external sources which discuss the actor and the associated activities:

Do you want to use VulDB in your project?

Use the official API to access entries easily!