Security Updates
Multiple Vulnerabilities in HPE Aruba Networking Products
Several vulnerabilities in HPE Aruba Mobility Conductors, Controllers, and WLAN/SD-WAN Gateways running AOS could allow authenticated attackers to execute arbitrary code on affected systems.
Vulnerability Details:
CVE: • CVE-2024-42501: Path traversal vulnerability in AOS (CVSS 7.2) allowing code execution.
• CVE-2024-42502: Remote command execution via AOS CLI (CVSS 7.2).
• CVE-2024-42503: Command injection in Lua package of AOS CLI (CVSS 7.2).
Affected Versions: • AOS-10.6.x.x (10.6.0.2 and below)
• AOS-8.12.x.x (8.12.0.1 and below)
• AOS-8.10.x.x (8.10.0.13 and below)
Fixed Versions: Update to AOS-10.7.x.x (10.7.0.0+), AOS-10.6.x.x (10.6.0.3+), AOS-8.12.x.x (8.12.0.2+), or AOS-8.10.x.x (8.10.0.14+).
References
• https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04709en_us&docLocale
Multiple Vulnerabilities in HPE Aruba Networking Products
Several vulnerabilities in HPE Aruba Mobility Conductors, Controllers, and WLAN/SD-WAN Gateways running AOS could allow authenticated attackers to execute arbitrary code on affected systems.
Vulnerability Details:
CVE: • CVE-2024-42501: Path traversal vulnerability in AOS (CVSS 7.2) allowing code execution.
• CVE-2024-42502: Remote command execution via AOS CLI (CVSS 7.2).
• CVE-2024-42503: Command injection in Lua package of AOS CLI (CVSS 7.2).
Affected Versions: • AOS-10.6.x.x (10.6.0.2 and below)
• AOS-8.12.x.x (8.12.0.1 and below)
• AOS-8.10.x.x (8.10.0.13 and below)
Fixed Versions: Update to AOS-10.7.x.x (10.7.0.0+), AOS-10.6.x.x (10.6.0.3+), AOS-8.12.x.x (8.12.0.2+), or AOS-8.10.x.x (8.10.0.14+).
References
• https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04709en_us&docLocale
Security Updates
Critical Vulnerability in Ivanti Cloud Appliance
Ivanti has issued a security advisory for a critical vulnerability (CVE-2024-8963) in its Cloud Services Appliance (CSA), version 4.6, which is being actively exploited. This path traversal vulnerability allows remote unauthenticated attackers to access restricted functionality and potentially execute arbitrary commands when combined with CVE-2024-8190.
Vulnerability Details:
CVE: CVE-2024-8963: Path traversal vulnerability in CSA 4.6 (CVSS 9.4 Critical). Exploitation could bypass admin authentication and lead to command execution.
Affected Products: CSA 4.6 (all versions before Patch 519)
Fixed Version: CSA 4.6 Patch 519 or CSA 5.0 (recommended)
Recommendations: Update to CSA 4.6 Patch 519 or upgrade to CSA 5.0 to mitigate this critical risk.
References
• https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-CSA-4-6-Cloud-Services-Appliance-CVE-2024-8963?language=en_US
Critical Vulnerability in Ivanti Cloud Appliance
Ivanti has issued a security advisory for a critical vulnerability (CVE-2024-8963) in its Cloud Services Appliance (CSA), version 4.6, which is being actively exploited. This path traversal vulnerability allows remote unauthenticated attackers to access restricted functionality and potentially execute arbitrary commands when combined with CVE-2024-8190.
Vulnerability Details:
CVE: CVE-2024-8963: Path traversal vulnerability in CSA 4.6 (CVSS 9.4 Critical). Exploitation could bypass admin authentication and lead to command execution.
Affected Products: CSA 4.6 (all versions before Patch 519)
Fixed Version: CSA 4.6 Patch 519 or CSA 5.0 (recommended)
Recommendations: Update to CSA 4.6 Patch 519 or upgrade to CSA 5.0 to mitigate this critical risk.
References
• https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-CSA-4-6-Cloud-Services-Appliance-CVE-2024-8963?language=en_US
Security Updates
Earth Baxia Threat Campaign
Earth Baxia, a sophisticated threat actor group, has been targeting government organizations and critical sectors in the Asia-Pacific (APAC) region. The group employs spear-phishing and exploits the GeoServer vulnerability (CVE-2024-36401) to deploy customized malware, including a modified version of Cobalt Strike and a new backdoor named EAGLEDOOR.
Details:
Attack Details: • Spear-Phishing: Tailored phishing emails with malicious attachments to gain initial access.
• CVE-2024-36401: Exploits GeoServer to execute arbitrary commands, enabling malicious payload delivery.
Malware: • Cobalt Strike Modifications: Altered to evade detection through internal signature and configuration changes.
• EAGLEDOOR Backdoor: Uses DNS, HTTP, TCP, and Telegram for data exfiltration and command-and-control, with system information gathering and payload delivery capabilities.
Indicators of Compromise (IOCs): Earth Baxia Threat Campaign IOC.csv
Recommendations: • Patch systems, especially GeoServer, to prevent CVE-2024-36401 exploitation.
References
• https://www.trendmicro.com/en_us/research/24/i/earth-baxia-spear-phishing-and-geoserver-exploit.html
Earth Baxia Threat Campaign
Earth Baxia, a sophisticated threat actor group, has been targeting government organizations and critical sectors in the Asia-Pacific (APAC) region. The group employs spear-phishing and exploits the GeoServer vulnerability (CVE-2024-36401) to deploy customized malware, including a modified version of Cobalt Strike and a new backdoor named EAGLEDOOR.
Details:
Attack Details: • Spear-Phishing: Tailored phishing emails with malicious attachments to gain initial access.
• CVE-2024-36401: Exploits GeoServer to execute arbitrary commands, enabling malicious payload delivery.
Malware: • Cobalt Strike Modifications: Altered to evade detection through internal signature and configuration changes.
• EAGLEDOOR Backdoor: Uses DNS, HTTP, TCP, and Telegram for data exfiltration and command-and-control, with system information gathering and payload delivery capabilities.
Indicators of Compromise (IOCs): Earth Baxia Threat Campaign IOC.csv
Recommendations: • Patch systems, especially GeoServer, to prevent CVE-2024-36401 exploitation.
References
• https://www.trendmicro.com/en_us/research/24/i/earth-baxia-spear-phishing-and-geoserver-exploit.html
Trend Micro
Earth Baxia Uses Spear-Phishing and GeoServer Exploit to Target APAC
Security Updates
High Severity Vulnerability in Keycloak
A high-severity vulnerability (CVE-2024-8698) has been identified in Keycloak's SAML signature validation process, allowing attackers to bypass authentication and potentially escalate privileges.
Vulnerability Details:
CVE: CVE-2024-8698
CVSS Score: 7.7 (High)
Affected Version: Keycloak versions up to and including 25.0.5
Fixed Version: Keycloak version 25.0.6
References
• https://nvd.nist.gov/vuln/detail/CVE-2024-8698
High Severity Vulnerability in Keycloak
A high-severity vulnerability (CVE-2024-8698) has been identified in Keycloak's SAML signature validation process, allowing attackers to bypass authentication and potentially escalate privileges.
Vulnerability Details:
CVE: CVE-2024-8698
CVSS Score: 7.7 (High)
Affected Version: Keycloak versions up to and including 25.0.5
Fixed Version: Keycloak version 25.0.6
References
• https://nvd.nist.gov/vuln/detail/CVE-2024-8698
Security Updates
Critical Vulnerability in Acronis Backup Plugins
A critical vulnerability (CVE-2024-8767) has been identified in Acronis Backup plugins for cPanel & WHM, Plesk, and DirectAdmin. This flaw could allow attackers to gain unauthorized access to sensitive information and execute malicious commands.
Vulnerability Details:
CVE: CVE-2024-8767
Severity: Critical (CVSS 9.9)
Impact: Improper permissions in the plugins can be exploited for data exfiltration and unauthorized command execution.
Affected Versions: • Acronis Backup plugin for cPanel & WHM (Linux) before build 619
• Acronis Backup extension for Plesk (Linux) before build 555
• Acronis Backup plugin for DirectAdmin (Linux) before build 147
Fixed Versions: • Update to Acronis Backup plugin version 1.8.0 (or later) for cPanel & WHM and Plesk.
• Update to Acronis Backup plugin version 1.2.0 (or later) for DirectAdmin.
References
• https://security-advisory.acronis.com/advisories/SEC-4976
Critical Vulnerability in Acronis Backup Plugins
A critical vulnerability (CVE-2024-8767) has been identified in Acronis Backup plugins for cPanel & WHM, Plesk, and DirectAdmin. This flaw could allow attackers to gain unauthorized access to sensitive information and execute malicious commands.
Vulnerability Details:
CVE: CVE-2024-8767
Severity: Critical (CVSS 9.9)
Impact: Improper permissions in the plugins can be exploited for data exfiltration and unauthorized command execution.
Affected Versions: • Acronis Backup plugin for cPanel & WHM (Linux) before build 619
• Acronis Backup extension for Plesk (Linux) before build 555
• Acronis Backup plugin for DirectAdmin (Linux) before build 147
Fixed Versions: • Update to Acronis Backup plugin version 1.8.0 (or later) for cPanel & WHM and Plesk.
• Update to Acronis Backup plugin version 1.2.0 (or later) for DirectAdmin.
References
• https://security-advisory.acronis.com/advisories/SEC-4976
Acronis
Acronis Advisory Database - Acronis
Acronis Advisory Database. Find information about the latest security advisories and updates for Acronis products.
Security Updates
Microsoft Edge Browser
Microsoft has released security updates to patch multiple vulnerabilities in the Edge browser, which could allow attackers to execute arbitrary code or trick users into interacting with malicious content.
Vulnerability Details:
CVE: • CVE-2024-43489 & CVE-2024-43496: Remote Code Execution vulnerabilities in Microsoft Edge (Chromium-based).
• CVE-2024-38221: Spoofing vulnerability in Microsoft Edge (Chromium-based).
Fixed Version: • Microsoft Edge Stable Channel (Version 129.0.2792.52)
• Microsoft Edge Extended Stable Channel (Version 128.0.2739.90)
Recommendations: Update Microsoft Edge to the latest version immediately.
References
• https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnotes-security
Microsoft Edge Browser
Microsoft has released security updates to patch multiple vulnerabilities in the Edge browser, which could allow attackers to execute arbitrary code or trick users into interacting with malicious content.
Vulnerability Details:
CVE: • CVE-2024-43489 & CVE-2024-43496: Remote Code Execution vulnerabilities in Microsoft Edge (Chromium-based).
• CVE-2024-38221: Spoofing vulnerability in Microsoft Edge (Chromium-based).
Fixed Version: • Microsoft Edge Stable Channel (Version 129.0.2792.52)
• Microsoft Edge Extended Stable Channel (Version 128.0.2739.90)
Recommendations: Update Microsoft Edge to the latest version immediately.
References
• https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnotes-security
Docs
Release notes for Microsoft Edge Security Updates
Security Updates
UNC1860 Targeting Government and Telecommunications Sectors
UNC1860, an advanced Iranian threat actor, is targeting government and telecommunications sectors in the Middle East, using sophisticated tooling and passive backdoors to maintain persistent access to high-priority networks.
Details:
Tactics, Techniques, and Procedures (TTPs): • Initial Access: Exploitation of vulnerable servers (e.g., SharePoint CVE-2019-0604) with web shells and malware (STAYSHANTE, SASHEYAWAY).
• Persistence: Use of passive implants (TEMPLEDOOR, SPARKLOAD) and legitimate software repurposing.
• Privilege Escalation: Custom utilities like TEMPLELOCK for event log manipulation.
• Defense Evasion: Custom Base64 and XOR encryption, HTTPS-encrypted traffic.
• Lateral Movement: Network scanning and credential exploitation.
• Command and Control (C&C): Use of TEMPLEPLAY and VIROGREEN for remote access and obfuscation of traffic.
Collaboration: UNC1860 is known to work with other Iranian threat actors, such as APT34, to enhance operations across compromised networks.
Indicators of Compromise (IOCs):
73fb0fe5cd96a14a4f85639223aec6a8
85427a8a47c4162b48d8dfb37440665d
a500561c0b374816972094c2aa90da2a
a65ee1a82975ee4c8d4e70219e1bfff5
ce537dd649a391e52c27a3f88a0a8912
e67687b4443f58d2b0a465e3af3caffe
b34883fb1630db43e06a38cebfa0bce2
46804472541ed61cc904cd14be18fe1d
4de802f7e61cb8c820a02e042b58b215
929b12bc9f9e5f8e854de1d46ebf40d9
f0dfb7bf01c0412891da8fa2702f4c7b
b219672bcd60ce9a81b900217b3b5864
fc90907e70f18c7f6a6b9d9599b6f97c
d1e45afbfd3424612b4a4218cc7357ef
da0085a97c38ead734885e5cced1847f
490590bfdeeedf44b3ae306409bb0d03
e86e885e6c96ac72482741d8696c17fb
ca3f0d25f7da0e8cde8e1f367451c77a
7b2fa099d51fa3885766f6d60d768748
6626dbe74acd15d06ff6900071ef240c
a3ea0d13848a104c28d035a9d518acc2
bd6464f12bb6f7f02b6ffebb363d8e5f
f89be788e4adf665acf1a8ef8fcaa133
f292e61774c267c3787fdfcace50ea7b
c11a4e4a2d484513f79bd127a0387b0c
14e54ff4805840e656efb8cd38de4751
3d5d05f230ae702c04098de512d93d48
a038975255d3dda636d86ccd307f7838
31f2369d2e38c78f5b3f2035dba07c08
c21eefc65cda49f17ddd1d243a7bffb5
c8fa0ce3ae6a13af640607ea606c55f9
2cece71e107d12ffd74b2fb24bf339a6
fa1c6f7a5e02374b9d33de2578cb3399
1e896f026246872b2feb4f8e3e093815
57c916da83cc634af22bde0ad44d0db3
07db3058e32fe5f36823dc7092cd7d5b
3dd829fb27353622eff34be1eabb8f18
1e6679cd25d1bb127a0bec665adcf21e
2e803d28809be2a0216f25126efde37b
2398a83f10329a107801d3d23d06f7cb
1176381da7dea356f3377a59a6f0e799
41f4732ed369f2224a422752860b0bc5
4029bc4a06638bb9ac4b8528523b72f6
126bc1c30fba27f8bf67dce4892b1e8c
0c9ff0db00f04fd4c6a9160bffd85a1d
a7693e399602eb79db537c5022dd1e01
d9719f6738dbfaa21be7f184512fe074
17b27e6aa0ab6501f11bb4d2e0f829ff
4dd6250eb2d368f500949952eb013964
69fd67c115349abb4a313230a1692642
7f5f5f290910d256e6b012f898c88bf3
c90ec587e3333dabb647ebc182673460
efe8043e1b4214640c5f7b5ddf737653
a90236e4962620949b720f647a91f101
b26d54b7da7b2bf600104f69da4ea00f
d87ca3f830b8b53fde358bb64900f6af
c50ae2c4b76f0d5724ec240568c78c4f
57cd8e220465aa8030755d4009d0117c
4b2c78bb2c439998cff0cc097a14b942
4abcf21b63781a53bbc1aa17bd8d2cbc
67560e05383e38b2fcc30df84f0792ad095d5594838087076b214d849cde9542
1146b1f38e420936b7c5f6b22212f3aa93515f3738c861f499ed1047865549cb
b65bcba449d74e4395421aeb4012c9e509acb5e8153ff3dc9f01fd97a5cc2711
ac7b01e01de0dc289cd649aa5072243f2036bd8d2d0152b6d9874c2ccaaf1e5d
c0dc609e6fc8801bb902d14910c3ffd69d6bd5a26389836446dc4c23565ddcc7
ffb6acd2715dd988fe3c3fdbd7d45159f8e5b529eea506a856109a8696e93a80
596b2a90c1590eaf704295a2d95aae5d2fec136e9613e059fd37de4b02fd03bb
6f0a38c9eb9171cd323b0f599b74ee571620bc3f34aa07435e7c5822663de605
3269de107e436a75a8308377709dc49b4893cfd137a3fc5b92d0f0590af4cb12
a2598161e1efff623de6128ad8aafba9da0300b6f86e8c951e616bd19f0a572b
da450c639c9a50377233c0f195c3f6162beb253f320ed57d5c9bb9c7f0e83999
786298c0d98aaf35777738a43a41546c6c8b1972b9bd601fb6cccf2c8f539ae4
159eecbba87a7397a5b84a21c289ae66ec776a3fd3b41bf11549fb621afebc0a
1c57b1ed990a8946e86d69da2a047fa15525d883b86e93cb6444a4065dbad362
9117bd328e37be121fb497596a2d0619a0eaca44752a1854523b8af46a5b0ceb
UNC1860 Targeting Government and Telecommunications Sectors
UNC1860, an advanced Iranian threat actor, is targeting government and telecommunications sectors in the Middle East, using sophisticated tooling and passive backdoors to maintain persistent access to high-priority networks.
Details:
Tactics, Techniques, and Procedures (TTPs): • Initial Access: Exploitation of vulnerable servers (e.g., SharePoint CVE-2019-0604) with web shells and malware (STAYSHANTE, SASHEYAWAY).
• Persistence: Use of passive implants (TEMPLEDOOR, SPARKLOAD) and legitimate software repurposing.
• Privilege Escalation: Custom utilities like TEMPLELOCK for event log manipulation.
• Defense Evasion: Custom Base64 and XOR encryption, HTTPS-encrypted traffic.
• Lateral Movement: Network scanning and credential exploitation.
• Command and Control (C&C): Use of TEMPLEPLAY and VIROGREEN for remote access and obfuscation of traffic.
Collaboration: UNC1860 is known to work with other Iranian threat actors, such as APT34, to enhance operations across compromised networks.
Indicators of Compromise (IOCs):
73fb0fe5cd96a14a4f85639223aec6a8
85427a8a47c4162b48d8dfb37440665d
a500561c0b374816972094c2aa90da2a
a65ee1a82975ee4c8d4e70219e1bfff5
ce537dd649a391e52c27a3f88a0a8912
e67687b4443f58d2b0a465e3af3caffe
b34883fb1630db43e06a38cebfa0bce2
46804472541ed61cc904cd14be18fe1d
4de802f7e61cb8c820a02e042b58b215
929b12bc9f9e5f8e854de1d46ebf40d9
f0dfb7bf01c0412891da8fa2702f4c7b
b219672bcd60ce9a81b900217b3b5864
fc90907e70f18c7f6a6b9d9599b6f97c
d1e45afbfd3424612b4a4218cc7357ef
da0085a97c38ead734885e5cced1847f
490590bfdeeedf44b3ae306409bb0d03
e86e885e6c96ac72482741d8696c17fb
ca3f0d25f7da0e8cde8e1f367451c77a
7b2fa099d51fa3885766f6d60d768748
6626dbe74acd15d06ff6900071ef240c
a3ea0d13848a104c28d035a9d518acc2
bd6464f12bb6f7f02b6ffebb363d8e5f
f89be788e4adf665acf1a8ef8fcaa133
f292e61774c267c3787fdfcace50ea7b
c11a4e4a2d484513f79bd127a0387b0c
14e54ff4805840e656efb8cd38de4751
3d5d05f230ae702c04098de512d93d48
a038975255d3dda636d86ccd307f7838
31f2369d2e38c78f5b3f2035dba07c08
c21eefc65cda49f17ddd1d243a7bffb5
c8fa0ce3ae6a13af640607ea606c55f9
2cece71e107d12ffd74b2fb24bf339a6
fa1c6f7a5e02374b9d33de2578cb3399
1e896f026246872b2feb4f8e3e093815
57c916da83cc634af22bde0ad44d0db3
07db3058e32fe5f36823dc7092cd7d5b
3dd829fb27353622eff34be1eabb8f18
1e6679cd25d1bb127a0bec665adcf21e
2e803d28809be2a0216f25126efde37b
2398a83f10329a107801d3d23d06f7cb
1176381da7dea356f3377a59a6f0e799
41f4732ed369f2224a422752860b0bc5
4029bc4a06638bb9ac4b8528523b72f6
126bc1c30fba27f8bf67dce4892b1e8c
0c9ff0db00f04fd4c6a9160bffd85a1d
a7693e399602eb79db537c5022dd1e01
d9719f6738dbfaa21be7f184512fe074
17b27e6aa0ab6501f11bb4d2e0f829ff
4dd6250eb2d368f500949952eb013964
69fd67c115349abb4a313230a1692642
7f5f5f290910d256e6b012f898c88bf3
c90ec587e3333dabb647ebc182673460
efe8043e1b4214640c5f7b5ddf737653
a90236e4962620949b720f647a91f101
b26d54b7da7b2bf600104f69da4ea00f
d87ca3f830b8b53fde358bb64900f6af
c50ae2c4b76f0d5724ec240568c78c4f
57cd8e220465aa8030755d4009d0117c
4b2c78bb2c439998cff0cc097a14b942
4abcf21b63781a53bbc1aa17bd8d2cbc
67560e05383e38b2fcc30df84f0792ad095d5594838087076b214d849cde9542
1146b1f38e420936b7c5f6b22212f3aa93515f3738c861f499ed1047865549cb
b65bcba449d74e4395421aeb4012c9e509acb5e8153ff3dc9f01fd97a5cc2711
ac7b01e01de0dc289cd649aa5072243f2036bd8d2d0152b6d9874c2ccaaf1e5d
c0dc609e6fc8801bb902d14910c3ffd69d6bd5a26389836446dc4c23565ddcc7
ffb6acd2715dd988fe3c3fdbd7d45159f8e5b529eea506a856109a8696e93a80
596b2a90c1590eaf704295a2d95aae5d2fec136e9613e059fd37de4b02fd03bb
6f0a38c9eb9171cd323b0f599b74ee571620bc3f34aa07435e7c5822663de605
3269de107e436a75a8308377709dc49b4893cfd137a3fc5b92d0f0590af4cb12
a2598161e1efff623de6128ad8aafba9da0300b6f86e8c951e616bd19f0a572b
da450c639c9a50377233c0f195c3f6162beb253f320ed57d5c9bb9c7f0e83999
786298c0d98aaf35777738a43a41546c6c8b1972b9bd601fb6cccf2c8f539ae4
159eecbba87a7397a5b84a21c289ae66ec776a3fd3b41bf11549fb621afebc0a
1c57b1ed990a8946e86d69da2a047fa15525d883b86e93cb6444a4065dbad362
9117bd328e37be121fb497596a2d0619a0eaca44752a1854523b8af46a5b0ceb
fa2c5fa2814d4db288bf8733edc4f1a78cd2c72cde90f42cf5b14162ac648042
c3fa9432243e1a2ab1991ab4c07a19392038e6a8e817e5fea0232c4caabbb950
e984b40c4c6909813ed9f0ea5de8f4f7cac40f0e8b9fb5041f4a568e307e5712
9483f5eb9133c353cef636ef9fcc29e2c7bf658881574211ee142c93c523efaf
ba3efa7d61e79cf62eeb0c65e803a6353f3012a89e0d910c2292801da43c8a93
23a9abed7c4a76a5cacf1e984ecf3cce91c3c1bbf4424c4b2ee141b4154c3703
e416fc85dbeefdff0f172b406c2f1fcdb90a895fa99c4eb66bcbe5c159f07b82
f42ebd85c4d0ab6573a856049ac9c892c037a0ec8f39e54153dd439616883390
71106875c37bf5b92ef25c7bc1d607ae349aa85bbb2e92a39165a8a8f8f6eb0e
5cb88ec4eca35c41dbf32218c0f031e75e4c24a17cabe9eea2aa06efa5982967
e579a55f5415f891095a7488e2dd250da7f2ccadc27c3d1280f13fea4263a97b
58cb1ef132fbdd1855f75c2886666275d1bb75a9fb3fed88d05feee4230afd32
1786916c1e3b16ce654497861fe43bb595ea0f0fa0fad4cd62f3edc82f9a27d4
e1ad173e49eee1194f2a55afa681cef7c3b8f6c26572f474dec7a42e9f0cdc9d
daa362f070ba121b9a2fa3567abc345edcde33c54cabefa71dd2faad78c10c33
359d826ff025c5e4971d90be0d7dfebe10fc125f6dcaa2f0e9869e9f6bec4432
0969f7f5556e3babd7050308a29fa2987dce01b3c94959724c9cd49bce052d80
a375f98aa21377ed0c59b4c7121ac93763157e39d8235fb5ce77f88dee0e2ee4
a650a90c1b505989b7e81bfb310d7e2013a380ab26f99622de158c58b1d0fbbf
3875ed58c0d42e05c83843b32ed33d6ba5e94e18ffe8fb1bf34fd7dedf3f82a7
6f938caeefa0aea3b8301e07bf918a49408cd319187d05ac519b20a00f460469
8578bff36e3b02cc71495b647db88c67c3c5ca710b5a2bd539148550595d0330
59463257c3f2425109fd097f814b6468663df947de8178c8cd7b7c5e94d3375c
2097320e71990865f04b9484858d279875cf5c66a5f6d12c819a34e2385da838
e26fbbeea2e152b3769126714c52112d04c4f2310461fb842bf2532e7903ce51
c5b4542d61af74cf7454d7f1c8d96218d709de38f94ccfa7c16b15f726dc08c0
90b3f7fefe8e11b8eacaba09a3c14ed6aa66a4c8d798440d912d0a663917a265
ce59bbe3ef7e16423718de50639d2278eab9c1f08f998677ba6fbd36695f316a
f4639c63fb01875946a4272c3515f005d558823311d0ee4c34896c2b66122596
36b61f94bdfc86e736a4ee30718e0b1ee1c07279db079d48d3fe78b1578dbf03
2538767f13218503bccf31fccb74e7531994b69a36a3780b53ba5020d938af20
b66919a18322aa4ce2ad47d149b7fe38063cd3cfa2e4062cd1a01ad6b3e47651
ed3745f82c7873adca16833b718e20090ac6a8c74e7004b854af29ef1551de75
f6c316e2385f2694d47e936b0ac4bc9b55e279d530dd5e805f0d963cb47c3c0d
8fdd00243ba68cadd175af0cbaf860218e08f42e715a998d6183d7c7462a3b5b
8e4f7a19b09e118ebda79726bf17e9d37ff4b66f4143762dd97ca80340388963
7a1fee8d879bc16e63d05c79c5419bd19ee308c54831d7ee196cfa8281498a06
ff51aa6cad655ddd99a525b78419cd746453fb2adcb689ba34ca3ab6e78b1347
1485c0ed3e875cbdfc6786a5bd26d18ea9d31727deb8df290a1c00c780419a4e
e17510e9fad082426920e6e6d94df7c1314ecc3ab041aa8e19d18140f5a0cc21
fe14edf4db2a9838f15aaf24a5837ffc5c901313d6fd2fe60d15401154e44406
eafb31f3ab90246d099e58f5fb950f58effa583f1e3caabc451dfabaf0d200e1
269d7faed3a01b5ff9181df32e3fdbf7f7f193cc53e4f28aa21290343e69f3cd
a052413e65e025cbefdddff6eeae91161de17ffec16d3a741dd9b7c33d392435
7495c1ea421063845eb8f4599a1c17c105f700ca0671ca874c5aa5aef3764c1c
References
• https://cloud.google.com/blog/topics/threat-intelligence/unc1860-iran-middle-eastern-networks/
c3fa9432243e1a2ab1991ab4c07a19392038e6a8e817e5fea0232c4caabbb950
e984b40c4c6909813ed9f0ea5de8f4f7cac40f0e8b9fb5041f4a568e307e5712
9483f5eb9133c353cef636ef9fcc29e2c7bf658881574211ee142c93c523efaf
ba3efa7d61e79cf62eeb0c65e803a6353f3012a89e0d910c2292801da43c8a93
23a9abed7c4a76a5cacf1e984ecf3cce91c3c1bbf4424c4b2ee141b4154c3703
e416fc85dbeefdff0f172b406c2f1fcdb90a895fa99c4eb66bcbe5c159f07b82
f42ebd85c4d0ab6573a856049ac9c892c037a0ec8f39e54153dd439616883390
71106875c37bf5b92ef25c7bc1d607ae349aa85bbb2e92a39165a8a8f8f6eb0e
5cb88ec4eca35c41dbf32218c0f031e75e4c24a17cabe9eea2aa06efa5982967
e579a55f5415f891095a7488e2dd250da7f2ccadc27c3d1280f13fea4263a97b
58cb1ef132fbdd1855f75c2886666275d1bb75a9fb3fed88d05feee4230afd32
1786916c1e3b16ce654497861fe43bb595ea0f0fa0fad4cd62f3edc82f9a27d4
e1ad173e49eee1194f2a55afa681cef7c3b8f6c26572f474dec7a42e9f0cdc9d
daa362f070ba121b9a2fa3567abc345edcde33c54cabefa71dd2faad78c10c33
359d826ff025c5e4971d90be0d7dfebe10fc125f6dcaa2f0e9869e9f6bec4432
0969f7f5556e3babd7050308a29fa2987dce01b3c94959724c9cd49bce052d80
a375f98aa21377ed0c59b4c7121ac93763157e39d8235fb5ce77f88dee0e2ee4
a650a90c1b505989b7e81bfb310d7e2013a380ab26f99622de158c58b1d0fbbf
3875ed58c0d42e05c83843b32ed33d6ba5e94e18ffe8fb1bf34fd7dedf3f82a7
6f938caeefa0aea3b8301e07bf918a49408cd319187d05ac519b20a00f460469
8578bff36e3b02cc71495b647db88c67c3c5ca710b5a2bd539148550595d0330
59463257c3f2425109fd097f814b6468663df947de8178c8cd7b7c5e94d3375c
2097320e71990865f04b9484858d279875cf5c66a5f6d12c819a34e2385da838
e26fbbeea2e152b3769126714c52112d04c4f2310461fb842bf2532e7903ce51
c5b4542d61af74cf7454d7f1c8d96218d709de38f94ccfa7c16b15f726dc08c0
90b3f7fefe8e11b8eacaba09a3c14ed6aa66a4c8d798440d912d0a663917a265
ce59bbe3ef7e16423718de50639d2278eab9c1f08f998677ba6fbd36695f316a
f4639c63fb01875946a4272c3515f005d558823311d0ee4c34896c2b66122596
36b61f94bdfc86e736a4ee30718e0b1ee1c07279db079d48d3fe78b1578dbf03
2538767f13218503bccf31fccb74e7531994b69a36a3780b53ba5020d938af20
b66919a18322aa4ce2ad47d149b7fe38063cd3cfa2e4062cd1a01ad6b3e47651
ed3745f82c7873adca16833b718e20090ac6a8c74e7004b854af29ef1551de75
f6c316e2385f2694d47e936b0ac4bc9b55e279d530dd5e805f0d963cb47c3c0d
8fdd00243ba68cadd175af0cbaf860218e08f42e715a998d6183d7c7462a3b5b
8e4f7a19b09e118ebda79726bf17e9d37ff4b66f4143762dd97ca80340388963
7a1fee8d879bc16e63d05c79c5419bd19ee308c54831d7ee196cfa8281498a06
ff51aa6cad655ddd99a525b78419cd746453fb2adcb689ba34ca3ab6e78b1347
1485c0ed3e875cbdfc6786a5bd26d18ea9d31727deb8df290a1c00c780419a4e
e17510e9fad082426920e6e6d94df7c1314ecc3ab041aa8e19d18140f5a0cc21
fe14edf4db2a9838f15aaf24a5837ffc5c901313d6fd2fe60d15401154e44406
eafb31f3ab90246d099e58f5fb950f58effa583f1e3caabc451dfabaf0d200e1
269d7faed3a01b5ff9181df32e3fdbf7f7f193cc53e4f28aa21290343e69f3cd
a052413e65e025cbefdddff6eeae91161de17ffec16d3a741dd9b7c33d392435
7495c1ea421063845eb8f4599a1c17c105f700ca0671ca874c5aa5aef3764c1c
References
• https://cloud.google.com/blog/topics/threat-intelligence/unc1860-iran-middle-eastern-networks/
Google Cloud Blog
UNC1860 and the Temple of Oats: Iran’s Hidden Hand in Middle Eastern Networks | Google Cloud Blog
UNC1860 is an Iranian state-sponsored threat actor with specialized tooling and passive backdoors.
👍1
کارگاه سه ساعته مانیتورینگ امنیت SOC
آخرین مهلت ثبت نام :2 آبان
حداکثر تعداد شرکت کننده 10 نفر
هزینه کارگاه 800 هزارتومان
جهت دریافت شرایط دایرکت دهید : ID telegram :@parra198
آخرین مهلت ثبت نام :2 آبان
حداکثر تعداد شرکت کننده 10 نفر
هزینه کارگاه 800 هزارتومان
جهت دریافت شرایط دایرکت دهید : ID telegram :@parra198
خبر هک شدن بلو بانک و فروش اطلاعات توسط گروه هکری به قیمت ۵۰ هزار دلار،واقعا این حد از پابلیک شدن دیتای کاربران خیلی ناراحت کننده هست،توی هک اسنپ فود خیلی جالب بود که باگ هایی که قبلا وجود داشت هنوز رفع نشده بود و براشون اصلا مهم نیست دیتای کاربران پابلیک بشه یا نه و کلا اهمیتی به این قضیه نمیدن 🤦♀
105 Windows SIEM Use Cases
1.Failed Login Attempts - Event ID: 4625
2.Account Lockouts - Event ID: 4740
3.Successful Login Outside Business Hours - Event ID: 4624
4.New User Creation - Event ID: 4720
5.Privileged Account Usage - Event ID: 4672
6.User Account Changes - Event IDs: 4722, 4723, 4724, 4725, 4726
7.Logon from Unusual Locations - Event ID: 4624 (with geolocation analysis)
8.Password Changes - Event ID: 4723 (change attempt), 4724 (successful reset)
9.Group Membership Changes - Event IDs: 4727, 4731, 4735, 4737
10.Suspicious Logon Patterns - Event ID: 4624 (anomalous logons)
11.Excessive Logon Failures - Event ID: 4625
12.Disabled Account Activity - Event ID: 4725
13.Dormant Account Usage - Event ID: 4624 (rarely used accounts)
14.Service Account Activity - Event IDs: 4624, 4672
15.RDP Access Monitoring - Event ID: 4624 (with RDP-specific filtering)
16.Lateral Movement Detection - Event ID: 4648 (network logons)
17.File and Folder Access - Event ID: 4663
18.Unauthorised File Sharing - Event IDs: 5140, 5145
19.Registry Changes - Event IDs: 4657
20.Application Installation and Removal - Event IDs: 11707, 1033
21.USB Device Usage - Event IDs: 20001, 20003 (from Device Management logs)
22.Windows Firewall Changes - Event IDs: 4946, 4947, 4950, 4951
23.Scheduled Task Creation - Event ID: 4698
24.Process Execution Monitoring - Event ID: 4688
25.System Restart or Shutdown - Event IDs: 6005, 6006, 1074
26.Event Log Clearing - Event ID: 1102
27.Malware Execution or Indicators - Event IDs: 4688, 1116 (from Windows Defender)
28.Active Directory Changes - Event IDs: 5136, 5141
29.Shadow Copy Deletion - Event ID: 524 (with VSSAdmin logs)
30.Network Configuration Changes - Event IDs: 4254, 4255, 10400
31.Execution of Suspicious Scripts - Event ID: 4688 (process creation with script interpreter)
32.Service Installation or Modification - Event ID: 4697
33.Clearing of Audit Logs - Event ID: 1102
34.Software Restriction Policy Violation - Event ID: 865
35.Excessive Account Enumeration - Event IDs: 4625, 4776
36.Attempt to Access Sensitive Files - Event ID: 4663
37.Unusual Process Injection - Event ID: 4688 (with EDR or Sysmon data)
38.Driver Installation - Event IDs: 7045 (Service Control Manager)
39.Modification of Scheduled Tasks - Event ID: 4699
40.Unauthorised GPO Changes - Event ID: 5136
41.Suspicious PowerShell Activity - Event ID: 4104 (from PowerShell logs)
42.Unusual Network Connections - Event ID: 5156 (network filtering platform)
43.Unauthorised Access to Shared Files - Event ID: 5145
44.DNS Query for Malicious Domains - Event ID: 5158 (DNS logs required)
45.LDAP Search Abuse - Event ID: 4662
46.Process Termination Monitoring - Event ID: 4689
47.Failed Attempts to Start a Service - Event ID: 7041
48.Audit Policy Changes - Event IDs: 4719, 1102
49.Time Change Monitoring - Event IDs: 4616, 520
50.BitLocker Encryption Key Changes - Event ID: 5379
51. Windows Defender Threat Detections - Event ID: 1116
52. SMB Session Monitoring - Event ID: 5140
53. Account Expiry Notification - Event ID: 4725
54. Locked File Deletion Attempts - Event ID: 4660
55. Abnormal CPU Usage by Process - Event ID: 4688 (with additional monitoring tools)
56. Security Group Deletion - Event ID: 4730
57. System Privileges Escalation Attempts - Event ID: 4673
58. Account Delegation Changes - Event ID: 4765
59. Printer Configuration Changes - Event IDs: 307, 805
60. IP Address Configuration Changes - Event IDs: 4200, 4201
61. Network Share Permission Changes - Event ID: 5141
62. Removable Device Access - Event IDs: 20001, 20003
63. Unusual WMI Activity - Event ID: 4688 (with WMI filters)
64. Firewall Rules Deleted - Event IDs: 4946, 4947
65. Suspicious COM Object Access - Event ID: 4688 (Sysmon Event ID 10)
66. Changes to Registry Autoruns - Event ID: 4657
67. Unusual Service Startup Parameters - Event ID: 4697
1.Failed Login Attempts - Event ID: 4625
2.Account Lockouts - Event ID: 4740
3.Successful Login Outside Business Hours - Event ID: 4624
4.New User Creation - Event ID: 4720
5.Privileged Account Usage - Event ID: 4672
6.User Account Changes - Event IDs: 4722, 4723, 4724, 4725, 4726
7.Logon from Unusual Locations - Event ID: 4624 (with geolocation analysis)
8.Password Changes - Event ID: 4723 (change attempt), 4724 (successful reset)
9.Group Membership Changes - Event IDs: 4727, 4731, 4735, 4737
10.Suspicious Logon Patterns - Event ID: 4624 (anomalous logons)
11.Excessive Logon Failures - Event ID: 4625
12.Disabled Account Activity - Event ID: 4725
13.Dormant Account Usage - Event ID: 4624 (rarely used accounts)
14.Service Account Activity - Event IDs: 4624, 4672
15.RDP Access Monitoring - Event ID: 4624 (with RDP-specific filtering)
16.Lateral Movement Detection - Event ID: 4648 (network logons)
17.File and Folder Access - Event ID: 4663
18.Unauthorised File Sharing - Event IDs: 5140, 5145
19.Registry Changes - Event IDs: 4657
20.Application Installation and Removal - Event IDs: 11707, 1033
21.USB Device Usage - Event IDs: 20001, 20003 (from Device Management logs)
22.Windows Firewall Changes - Event IDs: 4946, 4947, 4950, 4951
23.Scheduled Task Creation - Event ID: 4698
24.Process Execution Monitoring - Event ID: 4688
25.System Restart or Shutdown - Event IDs: 6005, 6006, 1074
26.Event Log Clearing - Event ID: 1102
27.Malware Execution or Indicators - Event IDs: 4688, 1116 (from Windows Defender)
28.Active Directory Changes - Event IDs: 5136, 5141
29.Shadow Copy Deletion - Event ID: 524 (with VSSAdmin logs)
30.Network Configuration Changes - Event IDs: 4254, 4255, 10400
31.Execution of Suspicious Scripts - Event ID: 4688 (process creation with script interpreter)
32.Service Installation or Modification - Event ID: 4697
33.Clearing of Audit Logs - Event ID: 1102
34.Software Restriction Policy Violation - Event ID: 865
35.Excessive Account Enumeration - Event IDs: 4625, 4776
36.Attempt to Access Sensitive Files - Event ID: 4663
37.Unusual Process Injection - Event ID: 4688 (with EDR or Sysmon data)
38.Driver Installation - Event IDs: 7045 (Service Control Manager)
39.Modification of Scheduled Tasks - Event ID: 4699
40.Unauthorised GPO Changes - Event ID: 5136
41.Suspicious PowerShell Activity - Event ID: 4104 (from PowerShell logs)
42.Unusual Network Connections - Event ID: 5156 (network filtering platform)
43.Unauthorised Access to Shared Files - Event ID: 5145
44.DNS Query for Malicious Domains - Event ID: 5158 (DNS logs required)
45.LDAP Search Abuse - Event ID: 4662
46.Process Termination Monitoring - Event ID: 4689
47.Failed Attempts to Start a Service - Event ID: 7041
48.Audit Policy Changes - Event IDs: 4719, 1102
49.Time Change Monitoring - Event IDs: 4616, 520
50.BitLocker Encryption Key Changes - Event ID: 5379
51. Windows Defender Threat Detections - Event ID: 1116
52. SMB Session Monitoring - Event ID: 5140
53. Account Expiry Notification - Event ID: 4725
54. Locked File Deletion Attempts - Event ID: 4660
55. Abnormal CPU Usage by Process - Event ID: 4688 (with additional monitoring tools)
56. Security Group Deletion - Event ID: 4730
57. System Privileges Escalation Attempts - Event ID: 4673
58. Account Delegation Changes - Event ID: 4765
59. Printer Configuration Changes - Event IDs: 307, 805
60. IP Address Configuration Changes - Event IDs: 4200, 4201
61. Network Share Permission Changes - Event ID: 5141
62. Removable Device Access - Event IDs: 20001, 20003
63. Unusual WMI Activity - Event ID: 4688 (with WMI filters)
64. Firewall Rules Deleted - Event IDs: 4946, 4947
65. Suspicious COM Object Access - Event ID: 4688 (Sysmon Event ID 10)
66. Changes to Registry Autoruns - Event ID: 4657
67. Unusual Service Startup Parameters - Event ID: 4697
🔥1
68. Unauthorised Software Use - Event IDs: 4688, 1033
69. Shared Drive Mounting by Remote Host - Event ID: 5140
70. Unauthorised Access to Admin Shares - Event ID: 5145
71. Abnormal Usage of Built-in Administrator Account - Event ID: 4624
72. Modification of System Files - Event ID: 4663
73. Changes to Critical Windows Services - Event ID: 7040
74. Failed Attempt to Modify Group Policy Object - Event ID: 5136
75. Suspicious Account Activity on Domain Controller - Event IDs: 4624, 4672
76. Abuse of Debugging Privileges - Event ID: 4673
77. Firewall Port Scanning Detection - Event IDs: 5156, 5157
78. Unauthorised RDP Session Termination - Event ID: 4634
79. Data Exfiltration via USB Devices - Event IDs: 20001, 20004
80. Mass File Deletion - Event ID: 4660
81. Execution of Suspicious Binary - Event ID: 4688
82. Changes to Time Synchronisation Settings - Event ID: 4616
83. Unusual Account Unlock Activity - Event ID: 4767
84. Suspicious PowerShell Encoding Activity - Event ID: 4104
85. Disabled Audit Logs - Event ID: 4719
86. Sensitive File Permission Changes - Event ID: 4670
87. Abuse of Kerberos Ticket Granting - Event ID: 4768
88. Duplicate IP Address Detection - Event IDs: 4199, 4198
89. Suspicious Account Removal - Event ID: 4726
90. Changes to Audit Policy Subcategories - Event ID: 4715
91. Clearing Security Group Memberships - Event ID: 4735
92. Failed Certificate Validation - Event ID: 4797
93. Unauthorised Driver Updates - Event IDs: 7045, 20001
94. Exploitation of Windows Task Scheduler - Event ID: 4698
95. Unauthorised Usage of Remote Shells - Event ID: 4104
96. Unexpected Device Installation - Event IDs: 20003, 7045
97. Suspicious Token Privilege Escalation - Event ID: 4673
98. Misuse of NTLM Authentication - Event IDs: 4776, 4624
99. Suspicious Registry Key Changes - Event ID: 4657
100. Detection of Golden Ticket Attacks - Event IDs: 4769, 4770
101. Excessive Lockout Attempts on a Single Account - Event ID: 4740
102. Unusual File Copy Activity - Event ID: 4663
103. Changes to Network Policies - Event ID: 4907
104. Suspicious Process Command Line Arguments - Event ID: 4688
105. Unauthorised File Decryption Attempts - Event ID: 4672
69. Shared Drive Mounting by Remote Host - Event ID: 5140
70. Unauthorised Access to Admin Shares - Event ID: 5145
71. Abnormal Usage of Built-in Administrator Account - Event ID: 4624
72. Modification of System Files - Event ID: 4663
73. Changes to Critical Windows Services - Event ID: 7040
74. Failed Attempt to Modify Group Policy Object - Event ID: 5136
75. Suspicious Account Activity on Domain Controller - Event IDs: 4624, 4672
76. Abuse of Debugging Privileges - Event ID: 4673
77. Firewall Port Scanning Detection - Event IDs: 5156, 5157
78. Unauthorised RDP Session Termination - Event ID: 4634
79. Data Exfiltration via USB Devices - Event IDs: 20001, 20004
80. Mass File Deletion - Event ID: 4660
81. Execution of Suspicious Binary - Event ID: 4688
82. Changes to Time Synchronisation Settings - Event ID: 4616
83. Unusual Account Unlock Activity - Event ID: 4767
84. Suspicious PowerShell Encoding Activity - Event ID: 4104
85. Disabled Audit Logs - Event ID: 4719
86. Sensitive File Permission Changes - Event ID: 4670
87. Abuse of Kerberos Ticket Granting - Event ID: 4768
88. Duplicate IP Address Detection - Event IDs: 4199, 4198
89. Suspicious Account Removal - Event ID: 4726
90. Changes to Audit Policy Subcategories - Event ID: 4715
91. Clearing Security Group Memberships - Event ID: 4735
92. Failed Certificate Validation - Event ID: 4797
93. Unauthorised Driver Updates - Event IDs: 7045, 20001
94. Exploitation of Windows Task Scheduler - Event ID: 4698
95. Unauthorised Usage of Remote Shells - Event ID: 4104
96. Unexpected Device Installation - Event IDs: 20003, 7045
97. Suspicious Token Privilege Escalation - Event ID: 4673
98. Misuse of NTLM Authentication - Event IDs: 4776, 4624
99. Suspicious Registry Key Changes - Event ID: 4657
100. Detection of Golden Ticket Attacks - Event IDs: 4769, 4770
101. Excessive Lockout Attempts on a Single Account - Event ID: 4740
102. Unusual File Copy Activity - Event ID: 4663
103. Changes to Network Policies - Event ID: 4907
104. Suspicious Process Command Line Arguments - Event ID: 4688
105. Unauthorised File Decryption Attempts - Event ID: 4672
👍2