Suspected Chinese Threat Actors Exploiting FortiOS Vulnerability (CVE-2022-42475) | Mandiant
Common Information
Type Value
UUID 87ed5770-3923-466e-91a4-cc36b5bdce93
Fingerprint b7f9bc11cc3195c0
Analysis status DONE
Considered CTI value 2
Text language
Published Jan. 19, 2023, midnight
Added to db Nov. 6, 2023, 6:52 p.m.
Last updated Nov. 17, 2024, 6:54 p.m.
Headline Suspected Chinese Threat Actors Exploiting FortiOS Vulnerability (CVE-2022-42475)
Title Suspected Chinese Threat Actors Exploiting FortiOS Vulnerability (CVE-2022-42475) | Mandiant
Detected Hints/Tags/Attributes 88/2/19
RSS Feed
Details Id Enabled Feed title Url Added to db
Details 330 Threat Intelligence https://www.mandiant.com/resources/blog/rss.xml 2024-08-30 22:08
Attributes
Details Type #Events CTI Value
Details CVE 90
cve-2022-42475
Details CVE 3
cve-2022-49475
Details Domain 2
libips.so
Details Domain 6
libiptcp.so
Details Domain 6
libgif.so
Details File 1
utsname.sys
Details File 1
pkginfo.json
Details md5 3
3191cb2e06e9a30792309813793f78b6
Details md5 3
12e28c14bb7f7b9513a02e5857592ad7
Details md5 3
54bbea35b095ddfe9740df97b693627b
Details sha256 2
3da407c1a30d810aaff9a04dfc1ef5861062ebdf0e6d0f6823ca682ca08c37da
Details sha256 2
0184e3d3dd8f4778d192d07e2caf44211141a570d45bb47a87894c68ebebeabb
Details sha256 2
61aae0e18c41ec4f610676680d26f6c6e1d4d5aa4e5092e40915fe806b679cd4
Details IPv4 2
139.180.128.142
Details IPv4 1441
127.0.0.1
Details IPv4 1
192.168.120.206
Details MITRE ATT&CK Techniques 48
T1480
Details MITRE ATT&CK Techniques 11
T1562.006
Details Threat Actor Identifier - APT 41
APT5