Suspected Chinese Threat Actors Exploiting FortiOS Vulnerability (CVE-2022-42475) | Mandiant
Tags
Common Information
Type | Value |
---|---|
UUID | 87ed5770-3923-466e-91a4-cc36b5bdce93 |
Fingerprint | b7f9bc11cc3195c0 |
Analysis status | DONE |
Considered CTI value | 2 |
Text language | |
Published | Jan. 19, 2023, midnight |
Added to db | Nov. 6, 2023, 6:52 p.m. |
Last updated | Nov. 17, 2024, 6:54 p.m. |
Headline | Suspected Chinese Threat Actors Exploiting FortiOS Vulnerability (CVE-2022-42475) |
Title | Suspected Chinese Threat Actors Exploiting FortiOS Vulnerability (CVE-2022-42475) | Mandiant |
Detected Hints/Tags/Attributes | 88/2/19 |
Source URLs
URL Provider
RSS Feed
Details | Id | Enabled | Feed title | Url | Added to db |
---|---|---|---|---|---|
Details | 330 | ✔ | Threat Intelligence | https://www.mandiant.com/resources/blog/rss.xml | 2024-08-30 22:08 |
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | CVE | 90 | cve-2022-42475 |
|
Details | CVE | 3 | cve-2022-49475 |
|
Details | Domain | 2 | libips.so |
|
Details | Domain | 6 | libiptcp.so |
|
Details | Domain | 6 | libgif.so |
|
Details | File | 1 | utsname.sys |
|
Details | File | 1 | pkginfo.json |
|
Details | md5 | 3 | 3191cb2e06e9a30792309813793f78b6 |
|
Details | md5 | 3 | 12e28c14bb7f7b9513a02e5857592ad7 |
|
Details | md5 | 3 | 54bbea35b095ddfe9740df97b693627b |
|
Details | sha256 | 2 | 3da407c1a30d810aaff9a04dfc1ef5861062ebdf0e6d0f6823ca682ca08c37da |
|
Details | sha256 | 2 | 0184e3d3dd8f4778d192d07e2caf44211141a570d45bb47a87894c68ebebeabb |
|
Details | sha256 | 2 | 61aae0e18c41ec4f610676680d26f6c6e1d4d5aa4e5092e40915fe806b679cd4 |
|
Details | IPv4 | 2 | 139.180.128.142 |
|
Details | IPv4 | 1441 | 127.0.0.1 |
|
Details | IPv4 | 1 | 192.168.120.206 |
|
Details | MITRE ATT&CK Techniques | 48 | T1480 |
|
Details | MITRE ATT&CK Techniques | 11 | T1562.006 |
|
Details | Threat Actor Identifier - APT | 41 | APT5 |