Nexus Analysis

IOB - Indicator of Behavior (620)

Timeline

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Lang

en512
ru34
de14
es12
ja10

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Country

us516
de104

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Actors

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Activities

Interest

Timeline

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Type

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Vendor

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Product

PHP6
SourceCodester Online Food Ordering System4
IsolSoft Support Center4
Revive Adserver4
Esoftpro Online Guestbook Pro4

The data in this chart does not reflect real data. It is dummy data, distorted and not usable in any way. You need an additional purchase to unlock this view to get access to more details of real data.

Vulnerabilities

#VulnerabilityBaseTemp0dayTodayExpRemEPSSCTICVE
1Lars Ellingsen Guestserver guestbook.cgi cross site scripting4.34.3$0-$5k$0-$5kNot DefinedNot Defined0.001690.06CVE-2005-4222
2Matt Wright Matt Wright Guestbook guestbook.pl cross site scripting4.34.1$0-$5k$0-$5kProof-of-ConceptUnavailable0.009910.05CVE-2006-1697
3PHP phpinfo cross site scripting4.33.9$5k-$25k$0-$5kProof-of-ConceptOfficial Fix0.019600.03CVE-2007-1287
4PHP Link Directory Administration Page index.html cross site scripting4.34.3$0-$5k$0-$5kNot DefinedNot Defined0.003740.15CVE-2007-0529
5SPIP spip.php cross site scripting3.53.4$0-$5k$0-$5kNot DefinedOfficial Fix0.001320.59CVE-2022-28959
6Joomla CMS com_easyblog sql injection6.36.1$5k-$25k$5k-$25kNot DefinedNot Defined0.000000.62
7Void Contact Form 7 Widget for Elementor Page Builder Plugin void_cf7_opt_in_user_data_track cross-site request forgery4.34.2$0-$5k$0-$5kNot DefinedNot Defined0.000630.00CVE-2022-47166
8DZCP deV!L`z Clanportal config.php code injection7.36.6$0-$5k$0-$5kProof-of-ConceptOfficial Fix0.009430.35CVE-2010-0966
9SourceCodester Online Flight Booking Management System POST Parameter review_search.php sql injection7.57.3$0-$5k$0-$5kProof-of-ConceptNot Defined0.001340.03CVE-2023-0283
10Responsive Menus Configuration Setting responsive_menus.module responsive_menus_admin_form_submit cross site scripting3.23.2$0-$5k$0-$5kNot DefinedOfficial Fix0.001270.06CVE-2018-25085
11TikiWiki tiki-register.php input validation7.36.6$0-$5k$0-$5kProof-of-ConceptOfficial Fix0.010757.56CVE-2006-6168
12Intelliants eSyndiCat suggest-category.php cross site scripting4.34.3$0-$5k$0-$5kNot DefinedNot Defined0.002570.04CVE-2010-4504
13MGB OpenSource Guestbook email.php sql injection7.37.3$0-$5k$0-$5kHighUnavailable0.013020.62CVE-2007-0354
14Phorum register.php sql injection7.37.0$0-$5k$0-$5kNot DefinedOfficial Fix0.001830.04CVE-2004-2110
15WordPress AdServe adclick.php sql injection7.36.6$0-$5k$0-$5kProof-of-ConceptOfficial Fix0.000730.20CVE-2008-0507
16Esoftpro Online Guestbook Pro ogp_show.php cross site scripting4.34.3$0-$5k$0-$5kNot DefinedNot Defined0.001340.03CVE-2009-2447
17OpenX adclick.php redirect5.34.7$0-$5k$0-$5kUnprovenUnavailable0.004400.23CVE-2014-2230
18MilliScripts register.php cross site scripting4.34.1$0-$5k$0-$5kProof-of-ConceptNot Defined0.005180.04CVE-2005-4161
19DZCP deV!L`z Clanportal browser.php information disclosure5.35.0$0-$5k$0-$5kProof-of-ConceptNot Defined0.027330.71CVE-2007-1167
20E-topbiz Viral DX 1 adclick.php sql injection7.37.3$0-$5k$0-$5kHighUnavailable0.000870.09CVE-2008-2867

IOC - Indicator of Compromise (13)

These indicators of compromise highlight associated network ressources which are known to be part of research and attack activities.

IDIP addressHostnameActorCampaignsIdentifiedTypeConfidence
15.161.23.233static.233.23.161.5.clients.your-server.deNexus04/27/2023verifiedHigh
25.161.97.57static.57.97.161.5.clients.your-server.deNexus04/02/2024verifiedHigh
35.161.201.122static.122.201.161.5.clients.your-server.deNexus03/07/2023verifiedHigh
4XX.XX.XX.XXXXxxxx04/27/2023verifiedHigh
5XX.XX.XX.XXXXxxxx03/07/2023verifiedHigh
6XX.XXX.XXX.XXXxxxx04/27/2023verifiedHigh
7XX.XXX.XX.XXXXxxxx04/27/2023verifiedHigh
8XX.XXX.XX.XXXXxxxx04/27/2023verifiedHigh
9XX.XXX.XX.XXXXxxxx04/27/2023verifiedHigh
10XXX.XX.XX.XXXxxxx03/30/2023verifiedHigh
11XXX.XX.XX.XXXxxxx03/30/2023verifiedHigh
12XXX.XX.XXX.XXXxxxx04/27/2023verifiedHigh
13XXX.XX.XXX.XXXxxxx04/27/2023verifiedHigh

TTP - Tactics, Techniques, Procedures (19)

Tactics, techniques, and procedures summarize the suspected MITRE ATT&CK techniques used. This data is unique as it uses our predictive model for actor profiling.

IOA - Indicator of Attack (228)

These indicators of attack list the potential fragments used for technical activities like reconnaissance, exploitation, privilege escalation, and exfiltration. This data is unique as it uses our predictive model for actor profiling.

IDClassIndicatorTypeConfidence
1File/acms/admin/cargo_types/manage_cargo_type.phppredictiveHigh
2File/admin/?page=user/manage_user&id=3predictiveHigh
3File/admin/ajax/avatar.phppredictiveHigh
4File/admin/employee_edit.phppredictiveHigh
5File/admin/fields/manage_field.phppredictiveHigh
6File/admin/optionspredictiveHigh
7File/admin/pages/yearlevel.phppredictiveHigh
8File/admin/show.phppredictiveHigh
9File/be/erpc.phppredictiveMedium
10File/bin/shpredictiveLow
11File/cgi-bin/system_mgr.cgipredictiveHigh
12File/cgi-bin/vitogate.cgipredictiveHigh
13File/ebics-server/ebics.aspxpredictiveHigh
14File/forum/away.phppredictiveHigh
15File/front/admin/tenancyDetail.phppredictiveHigh
16File/horde/util/go.phppredictiveHigh
17File/importexport.phppredictiveHigh
18File/mgmt/tm/util/bashpredictiveHigh
19File/my_photo_gallery/image.phppredictiveHigh
20File/oews/classes/Master.php?f=update_cartpredictiveHigh
21File/patient/doctors.phppredictiveHigh
22File/php-fusion/infusions/shoutbox_panel/shoutbox_archive.phppredictiveHigh
23File/phpinventory/editcategory.phppredictiveHigh
24File/phpinventory/edituser.phppredictiveHigh
25File/schedules/view_schedule.phppredictiveHigh
26File/Service/ImageStationDataService.asmxpredictiveHigh
27File/spip.phppredictiveMedium
28File/uncpath/predictiveMedium
29File/useratte/inc/userattea.phppredictiveHigh
30File/var/log/cronpredictiveHigh
31File/xxxx/xxxxxxx_xxxx_xxxx_xxxxxx_xxxxx.xxxpredictiveHigh
32File/xx/xxxxx/xxxxxxx.xxxpredictiveHigh
33File/xx-xxxxx/xxxxx-xxxx.xxxpredictiveHigh
34Filexxx/xxx.xxxpredictiveMedium
35Filexxxxxxx.xxxpredictiveMedium
36Filexxxxxx/xxxxxxx/xxx/xxx-xxxxx.xxpredictiveHigh
37Filexxxxx.xxxpredictiveMedium
38Filexxxxx.xxxxpredictiveMedium
39Filexxxxx/xxxxxxxxxxxxx.xxxpredictiveHigh
40Filexxxxx/xxx.xxxpredictiveHigh
41Filexxxxx/xxxxx-xxxxxxx-xx-xxxxxxxxxxxxxxxxxxxx-xxxxx.xxxpredictiveHigh
42Filexxxxx/xxxxx.xxx?xx=xxxxxx&xxxxxx=xxxx_xxxxxpredictiveHigh
43Filexxxxx_xxxxx.xxxpredictiveHigh
44Filexxx.xxxpredictiveLow
45Filexxxxxxxxxxxxx.xxxpredictiveHigh
46Filexxxxxxx.xxpredictiveMedium
47Filexxxxxxx.xxpredictiveMedium
48Filexxxx_xxxxxxxxxxx.xxxpredictiveHigh
49Filexxxxxx.xxxpredictiveMedium
50Filexxxx.xxxpredictiveMedium
51Filexxxxxx_xxxxxx.xxxpredictiveHigh
52Filexxxxxx-xxxxxx-xx.xxxpredictiveHigh
53Filex:\xxxxxxx xxxxx\xxxxxx xxxxx\xxx\xxxxxxx.xxxpredictiveHigh
54Filexxxxxxxx.xxxpredictiveMedium
55Filexxx-xxx/xxxxxxx.xxpredictiveHigh
56Filexxxxx.xxxpredictiveMedium
57Filexxxxx-xxxxxxx.xxxpredictiveHigh
58Filexxxxxxxx-xxx.xxxpredictiveHigh
59Filexxxxxx-xxxxx.xxxpredictiveHigh
60Filexxxxxxxxx.xxxpredictiveHigh
61Filexxxx.xxxpredictiveMedium
62Filexxxxx/xxxx/xxxxxxxxpredictiveHigh
63Filexxxxxxxxx.xxxpredictiveHigh
64Filexxxxxxxx.xxx.xxxpredictiveHigh
65Filexxxxx.xxxpredictiveMedium
66Filexxxxxxxx/xxx-xxxx.xxxpredictiveHigh
67Filexxxxxxxxxxxxxxxx/xxxxxxxxxxxxxx.xxpredictiveHigh
68Filexxxx.xxxpredictiveMedium
69Filexxx/xxxx/xxx/xxxxx_xxxx.xpredictiveHigh
70Filexxx/xxxx/xxxx.xpredictiveHigh
71Filexxxxxxxx.xxxpredictiveMedium
72Filexxxxxxxxxxxx_xxxx.xxxpredictiveHigh
73Filexxxxxx/xxxxxxxxx?xx=xxx_xxx.xxxpredictiveHigh
74Filexxxxxxxxx.xxxpredictiveHigh
75Filexxxxxxxxx.xxpredictiveMedium
76Filexxxx.xxxpredictiveMedium
77Filexxxxxxxxxxxxxx.xxxpredictiveHigh
78Filexxx/xxxxxx.xxxpredictiveHigh
79Filexxx/xxxxxxxxxxx/xxxxxxx.xxxpredictiveHigh
80Filexxxxxxx.xxxpredictiveMedium
81Filexxxxxxx/xxxxxxx/xxxxxx.xxx.xxxpredictiveHigh
82Filexxxxxxx_xxxxx.xxxpredictiveHigh
83Filexxxxx.xxxxpredictiveMedium
84Filexxxxx.xxxpredictiveMedium
85Filexxxxxxxxxxxxx.xxxpredictiveHigh
86Filexxx.xxxpredictiveLow
87Filexxxxxxxx.xxx.xxxpredictiveHigh
88Filexxxxxxx.xxxpredictiveMedium
89Filexxxx.xxxxpredictiveMedium
90Filexxxxxxxxxxx.xxxpredictiveHigh
91Filexxxxxxx/xxx_xxxxxxxx.xxxpredictiveHigh
92Filexxx_xxxxxxxx.xxxpredictiveHigh
93Filexxxxxxxx.xxxxxxxxxxxxxxxxxxx.xxxxxxxxxxxxxxxxxxpredictiveHigh
94Filexxxxxxxxx.xpredictiveMedium
95Filexxxxxxxxx.xxxpredictiveHigh
96Filexxx_xxxx.xxxpredictiveMedium
97Filexxxxxx_xxxxxx.xxxpredictiveHigh
98Filexxxx.xxxpredictiveMedium
99Filexxxxxxxxxxxxxxx.xxxpredictiveHigh
100Filexxxxxxxxx.xxx.xxxpredictiveHigh
101Filexxxxxxx_xxxxxx_xxx.xxxxpredictiveHigh
102Filexxxxxxx/xxxxxxx/xx_xxxxxxxxx/xxxxxxxx/xxxxxxxx.xxxpredictiveHigh
103Filexxxxx_xxxxxx.xxxpredictiveHigh
104Filexxxxx.xxxpredictiveMedium
105Filexxxxx.xxxpredictiveMedium
106Filexxxx.xxxpredictiveMedium
107Filexxxxx.xxxpredictiveMedium
108Filexxxxx_xxxx_xxxx_xxxx.xxxpredictiveHigh
109Filexxxxxxxx.xxxpredictiveMedium
110Filexxxxxxxx_xxxxxx.xxxpredictiveHigh
111Filexxxxxxxxxx_xxxxx.xxxxxxpredictiveHigh
112Filexxxxxx_xxxxxx.xxxpredictiveHigh
113Filexxxxx-xxxxxx-xx.xxxpredictiveHigh
114Filexxxxxx_xxx_xxxxxx.xxxpredictiveHigh
115Filexxxx.xxxpredictiveMedium
116Filexxxxxxxx.xxxpredictiveMedium
117Filexxxxxxxx.xxx/xxxxxx.xxx/xxxxxxxx.xxxpredictiveHigh
118Filexxxxxxx/xxxxxx.xxxpredictiveHigh
119Filexxxxx.xxxpredictiveMedium
120Filexxxxxxxxx.xxxpredictiveHigh
121Filexxxxxxx-xxxxxxxx.xxxpredictiveHigh
122Filexxxxxxx-xxxxxxx.xxxpredictiveHigh
123Filexxxxxxxxxxxxxxxxxxxxx.xxxpredictiveHigh
124Filexxxxxxxxx/xxxxx/xxxx/xxx_xxxxxxx/xxxxxxx/xxxxxxx.xxxpredictiveHigh
125Filexxxx-xxxxx.xxxpredictiveHigh
126Filexxxx-xxxxxxxx.xxxpredictiveHigh
127Filexxxx/xxx/xxxx-xxxxx.xxxpredictiveHigh
128Filexxxx.xpredictiveLow
129Filexxxxxx.xxxpredictiveMedium
130Filexxxxxxxxx.xxxpredictiveHigh
131Filexx-xxxxxxxx/xxxxx-xx-xxxxxx-xxxxxx.xxxpredictiveHigh
132Filexxx/xxxxxxxx/xxxxxxxx.xxxpredictiveHigh
133File~/xxxxxxx/xxxxxxx/xxxxxxxxxxxx.xxxpredictiveHigh
134File~/xxxxxxxx/xxxxxxx/xxxxx-xxxx-xxxxxxx.xxxpredictiveHigh
135Libraryxxxxxx.xxxpredictiveMedium
136Libraryxxxxxxxxxxxxxxxx.xxxpredictiveHigh
137Libraryxxx/xxxx/xxxxxxx/xxxxxxxx_xxxxxxx/xxxxxxxx.xxpredictiveHigh
138Libraryxxxxxxxxx/xxx-xxxxxx/xxxxxxxx.xxxpredictiveHigh
139Libraryxxxxxxxxx.x.x.xxx.xxxpredictiveHigh
140Libraryxxxxxxxxx.xxxpredictiveHigh
141Libraryxxxxxxxxxxx.xxxpredictiveHigh
142Libraryxxxxxxxx.xxxpredictiveMedium
143Libraryxxxxxxxxxxxx.xxxpredictiveHigh
144Libraryxxxxxxxx.xxxpredictiveMedium
145Argumentxx_xxxx_xxxxpredictiveMedium
146Argumentxxx/xxxpredictiveLow
147ArgumentxxxxxpredictiveLow
148Argumentxxxxxxx_xxpredictiveMedium
149ArgumentxxxxxxxxxpredictiveMedium
150ArgumentxxxxxxxxpredictiveMedium
151ArgumentxxxxxxxxpredictiveMedium
152Argumentxxxx_xxxpredictiveMedium
153Argumentxxxxx_xxxpredictiveMedium
154Argumentxxxx_xxxxpredictiveMedium
155Argumentxxx_xxxpredictiveLow
156Argumentxxxx_xxpredictiveLow
157ArgumentxxxpredictiveLow
158ArgumentxxxxxxxxpredictiveMedium
159ArgumentxxxxxxxxxxpredictiveMedium
160ArgumentxxxpredictiveLow
161ArgumentxxxxxxpredictiveLow
162ArgumentxxxxxxxxxxpredictiveMedium
163Argumentxxxxxx[xxxx]predictiveMedium
164ArgumentxxxxxxxxpredictiveMedium
165ArgumentxxxxxxxxxxxpredictiveMedium
166ArgumentxxxxpredictiveLow
167ArgumentxxxxxxxpredictiveLow
168ArgumentxxxxxxxxxxpredictiveMedium
169ArgumentxxxxxpredictiveLow
170ArgumentxxxxxpredictiveLow
171Argumentxx_xxxxx_xxpredictiveMedium
172ArgumentxxxxpredictiveLow
173ArgumentxxxxxpredictiveLow
174ArgumentxxxxxxpredictiveLow
175ArgumentxxxxxxxxpredictiveMedium
176ArgumentxxxxxpredictiveLow
177Argumentxxxx/xxxxpredictiveMedium
178Argumentxxxx_xxxxxpredictiveMedium
179Argumentxxxx_xxxxxxxpredictiveMedium
180ArgumentxxpredictiveLow
181ArgumentxxpredictiveLow
182ArgumentxxxpredictiveLow
183ArgumentxxxxxpredictiveLow
184Argumentxxx_xxxpredictiveLow
185Argumentxxxxx.xxx?xxxxxx=xxx_xxxxxxx/xxxx=xxxxxxx/xx=x/xxxxxxxx=xxxxxpredictiveHigh
186Argumentxxxxxxx_xxxxpredictiveMedium
187ArgumentxxxxpredictiveLow
188Argumentxxxxx_xxxpredictiveMedium
189ArgumentxxxxpredictiveLow
190Argumentxxxxxxxxxxxxx/xxxxxxxxxxxxxpredictiveHigh
191Argumentxxx_xxpredictiveLow
192Argumentxxxxxxxxx_xxxxxxxx_xxxxpredictiveHigh
193ArgumentxxxpredictiveLow
194Argumentxxxxxxx_xxpredictiveMedium
195Argumentxxxxxxxxx/xxxxxxxxxxxpredictiveHigh
196ArgumentxxxxxxpredictiveLow
197Argumentxxxxxx_xxxxxx[xxxxxx_xxxx]predictiveHigh
198ArgumentxxpredictiveLow
199ArgumentxxxxxxpredictiveLow
200ArgumentxxxxxxxxxpredictiveMedium
201Argumentxxxxxxx_xxxpredictiveMedium
202Argumentxxxxxxxx_xxxxxpredictiveHigh
203ArgumentxxxxpredictiveLow
204ArgumentxxxxxxxpredictiveLow
205ArgumentxxxxxxpredictiveLow
206ArgumentxxxxxxxxpredictiveMedium
207ArgumentxxxxxxpredictiveLow
208Argumentxxxxxx_xxxxxxpredictiveHigh
209ArgumentxxxxxxpredictiveLow
210ArgumentxxxxpredictiveLow
211ArgumentxxxpredictiveLow
212ArgumentxxxxxxxxxxpredictiveMedium
213ArgumentxxxxxxpredictiveLow
214ArgumentxxxpredictiveLow
215ArgumentxxxxxpredictiveLow
216ArgumentxxxxxxxxxpredictiveMedium
217ArgumentxxxpredictiveLow
218ArgumentxxxxxpredictiveLow
219Argumentxxxx xxxxx/xxxxxxxpredictiveHigh
220Argument_xxxxx_xxxxxxx_xxxxxxxxx_xxxxxxx-xxxpredictiveHigh
221Input Value"><xxxxxx>xxxxxx(x)</xxxxxx>predictiveHigh
222Input Value%xxpredictiveLow
223Input Value-xx%xxxxxxx%xxxxx%xxxxxxxx%xxx,@@xxxxxxx,x,x,x,x,x,x--predictiveHigh
224Input Valuex xxxxx xxx xxxxxx xxxx,xxxx,xxxx,xxxx,xxxxxx(xxxxxxxxxxxx,xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx,xxxxxxxxxxxx)--predictiveHigh
225Input Valuexxxxx"><xxxxxx>xxxxx('xxx')</xxxxxx>predictiveHigh
226Input Value\xxx../../../../xxx/xxxxxxpredictiveHigh
227Network Portxxx/xxxpredictiveLow
228Network Portxxx/xxxxpredictiveMedium

References (4)

The following list contains external sources which discuss the actor and the associated activities:

Do you know our Splunk app?

Download it now for free!