امنیت سایبری SOC
327 subscribers
160 photos
10 videos
169 files
212 links
Information about soc , cyber security defence and cyber security news
Download Telegram
خبر هک شدن بلو بانک و فروش اطلاعات توسط گروه هکری به قیمت ۵۰ هزار دلار،واقعا این حد از پابلیک شدن دیتای کاربران خیلی ناراحت کننده هست،توی هک اسنپ فود خیلی جالب بود که باگ هایی که قبلا وجود داشت هنوز رفع نشده بود و براشون اصلا مهم نیست دیتای کاربران پابلیک بشه یا نه و کلا اهمیتی به این قضیه نمیدن 🤦‍♀
105 Windows SIEM Use Cases

1.Failed Login Attempts - Event ID: 4625
2.Account Lockouts - Event ID: 4740
3.Successful Login Outside Business Hours - Event ID: 4624
4.New User Creation - Event ID: 4720
5.Privileged Account Usage - Event ID: 4672
6.User Account Changes - Event IDs: 4722, 4723, 4724, 4725, 4726
7.Logon from Unusual Locations - Event ID: 4624 (with geolocation analysis)
8.Password Changes - Event ID: 4723 (change attempt), 4724 (successful reset)
9.Group Membership Changes - Event IDs: 4727, 4731, 4735, 4737
10.Suspicious Logon Patterns - Event ID: 4624 (anomalous logons)
11.Excessive Logon Failures - Event ID: 4625
12.Disabled Account Activity - Event ID: 4725
13.Dormant Account Usage - Event ID: 4624 (rarely used accounts)
14.Service Account Activity - Event IDs: 4624, 4672
15.RDP Access Monitoring - Event ID: 4624 (with RDP-specific filtering)
16.Lateral Movement Detection - Event ID: 4648 (network logons)
17.File and Folder Access - Event ID: 4663
18.Unauthorised File Sharing - Event IDs: 5140, 5145
19.Registry Changes - Event IDs: 4657
20.Application Installation and Removal - Event IDs: 11707, 1033
21.USB Device Usage - Event IDs: 20001, 20003 (from Device Management logs)
22.Windows Firewall Changes - Event IDs: 4946, 4947, 4950, 4951
23.Scheduled Task Creation - Event ID: 4698
24.Process Execution Monitoring - Event ID: 4688
25.System Restart or Shutdown - Event IDs: 6005, 6006, 1074
26.Event Log Clearing - Event ID: 1102
27.Malware Execution or Indicators - Event IDs: 4688, 1116 (from Windows Defender)
28.Active Directory Changes - Event IDs: 5136, 5141
29.Shadow Copy Deletion - Event ID: 524 (with VSSAdmin logs)
30.Network Configuration Changes - Event IDs: 4254, 4255, 10400
31.Execution of Suspicious Scripts - Event ID: 4688 (process creation with script interpreter)
32.Service Installation or Modification - Event ID: 4697
33.Clearing of Audit Logs - Event ID: 1102
34.Software Restriction Policy Violation - Event ID: 865
35.Excessive Account Enumeration - Event IDs: 4625, 4776
36.Attempt to Access Sensitive Files - Event ID: 4663
37.Unusual Process Injection - Event ID: 4688 (with EDR or Sysmon data)
38.Driver Installation - Event IDs: 7045 (Service Control Manager)
39.Modification of Scheduled Tasks - Event ID: 4699
40.Unauthorised GPO Changes - Event ID: 5136
41.Suspicious PowerShell Activity - Event ID: 4104 (from PowerShell logs)
42.Unusual Network Connections - Event ID: 5156 (network filtering platform)
43.Unauthorised Access to Shared Files - Event ID: 5145
44.DNS Query for Malicious Domains - Event ID: 5158 (DNS logs required)
45.LDAP Search Abuse - Event ID: 4662
46.Process Termination Monitoring - Event ID: 4689
47.Failed Attempts to Start a Service - Event ID: 7041
48.Audit Policy Changes - Event IDs: 4719, 1102
49.Time Change Monitoring - Event IDs: 4616, 520
50.BitLocker Encryption Key Changes - Event ID: 5379
51. Windows Defender Threat Detections - Event ID: 1116
52. SMB Session Monitoring - Event ID: 5140
53. Account Expiry Notification - Event ID: 4725
54. Locked File Deletion Attempts - Event ID: 4660
55. Abnormal CPU Usage by Process - Event ID: 4688 (with additional monitoring tools)
56. Security Group Deletion - Event ID: 4730
57. System Privileges Escalation Attempts - Event ID: 4673
58. Account Delegation Changes - Event ID: 4765
59. Printer Configuration Changes - Event IDs: 307, 805
60. IP Address Configuration Changes - Event IDs: 4200, 4201
61. Network Share Permission Changes - Event ID: 5141
62. Removable Device Access - Event IDs: 20001, 20003
63. Unusual WMI Activity - Event ID: 4688 (with WMI filters)
64. Firewall Rules Deleted - Event IDs: 4946, 4947
65. Suspicious COM Object Access - Event ID: 4688 (Sysmon Event ID 10)
66. Changes to Registry Autoruns - Event ID: 4657
67. Unusual Service Startup Parameters - Event ID: 4697
🔥1
68. Unauthorised Software Use - Event IDs: 4688, 1033
69. Shared Drive Mounting by Remote Host - Event ID: 5140
70. Unauthorised Access to Admin Shares - Event ID: 5145
71. Abnormal Usage of Built-in Administrator Account - Event ID: 4624
72. Modification of System Files - Event ID: 4663
73. Changes to Critical Windows Services - Event ID: 7040
74. Failed Attempt to Modify Group Policy Object - Event ID: 5136
75. Suspicious Account Activity on Domain Controller - Event IDs: 4624, 4672
76. Abuse of Debugging Privileges - Event ID: 4673
77. Firewall Port Scanning Detection - Event IDs: 5156, 5157
78. Unauthorised RDP Session Termination - Event ID: 4634
79. Data Exfiltration via USB Devices - Event IDs: 20001, 20004
80. Mass File Deletion - Event ID: 4660
81. Execution of Suspicious Binary - Event ID: 4688
82. Changes to Time Synchronisation Settings - Event ID: 4616
83. Unusual Account Unlock Activity - Event ID: 4767
84. Suspicious PowerShell Encoding Activity - Event ID: 4104
85. Disabled Audit Logs - Event ID: 4719
86. Sensitive File Permission Changes - Event ID: 4670
87. Abuse of Kerberos Ticket Granting - Event ID: 4768
88. Duplicate IP Address Detection - Event IDs: 4199, 4198
89. Suspicious Account Removal - Event ID: 4726
90. Changes to Audit Policy Subcategories - Event ID: 4715
91. Clearing Security Group Memberships - Event ID: 4735
92. Failed Certificate Validation - Event ID: 4797
93. Unauthorised Driver Updates - Event IDs: 7045, 20001
94. Exploitation of Windows Task Scheduler - Event ID: 4698
95. Unauthorised Usage of Remote Shells - Event ID: 4104
96. Unexpected Device Installation - Event IDs: 20003, 7045
97. Suspicious Token Privilege Escalation - Event ID: 4673
98. Misuse of NTLM Authentication - Event IDs: 4776, 4624
99. Suspicious Registry Key Changes - Event ID: 4657
100. Detection of Golden Ticket Attacks - Event IDs: 4769, 4770
101. Excessive Lockout Attempts on a Single Account - Event ID: 4740
102. Unusual File Copy Activity - Event ID: 4663
103. Changes to Network Policies - Event ID: 4907
104. Suspicious Process Command Line Arguments - Event ID: 4688
105. Unauthorised File Decryption Attempts - Event ID: 4672
👍2
Researchers analyzed a malicious Android sample created using Spynote RAT, targeting high-value assets in Southern Asia, which, likely deployed by an unknown threat actor, aims to compromise sensitive information.The app was in the menu after the installation was over
Emerging Threat: Sneaky Log and Sneaky 2FA
Sneaky Log, operating as a Phishing-as-a-Service (PhaaS) platform, distributes the Sneaky 2FA phishing kit targeting Microsoft 365 accounts to bypass MFA using Adversary-in-the-Middle (AiTM) tactics. The kit, hosted on compromised WordPress sites and attacker-controlled domains, uses anti-bot measures like Cloudflare Turnstile and anti-analysis techniques, including obfuscated code and junk data, to evade detection. Phishing URLs prefill victim details via email parameters, while malicious QR codes redirect users to fake Microsoft login pages. Sold for $200/month through Telegram bots (@SneakyLog_bot, @SneakySupport_bot), payments are processed via multiple cryptocurrencies. Users are advised to verify email and QR code authenticity
BadPilot Campaign: Sandworm Subgroup (Seashell Blizzard)
A state-sponsored APT44/Sandworm subgroup has been targeting energy, oil & gas, telecom, and government entities across 15+ countries since 2021. The group exploits known vulnerabilities in internet-facing systems, such as Microsoft Exchange (CVE-2021-34473), Zimbra Collaboration (CVE-2022-41352), OpenFire (CVE-2023-32315), JetBrains TeamCity (CVE-2023-42793), Microsoft Outlook (CVE-2023-23397), ConnectWise ScreenConnect (CVE-2024-1709), and Fortinet FortiClient EMS (CVE-2023-48788). Post-exploitation, they establish persistence using tools like Atera Agent, Splashtop Remote Services, LocalOlive web shell, Kalambur RDP backdoor, and ShadowLink (a TOR-based utility). To mitigate these threats, organizations are advised to promptly apply security patches
کمپین BadPilot: زیرگروه Sandworm (Seashell Blizzard)
یک زیرگروه APT44/Sandworm با حمایت دولتی از سال 2021 انرژی، نفت و گاز، مخابرات و نهادهای دولتی را در بیش از 15 کشور هدف قرار داده است. این گروه از آسیب‌پذیری‌های شناخته شده در سیستم‌های روبه‌روی اینترنت، مانند Microsoft Exchange (CVE-2021-34473)، Zimbra Open-2302C (CVE-2021-34473)، Zimbra Open-2352C (Open-2021-34473)، و Zimbra-2352C (Open-2021-34473)، و سازمان‌های دولتی در بیش از 15 کشور استفاده می‌کند. (CVE-2023-32315)، JetBrains TeamCity (CVE-2023-42793)، Microsoft Outlook (CVE-2023-23397)، ConnectWise ScreenConnect (CVE-2024-1709)، و Fortinet FortiClient EMS (CVE-22028) پس از بهره برداری، آنها با استفاده از ابزارهایی مانند Atera Agent، Splashtop Remote Services، پوسته وب LocalOlive، درب پشتی Kalambur RDP و ShadowLink (یک ابزار مبتنی بر TOR) پایداری ایجاد می کنند. برای کاهش این تهدیدات، به سازمان ها توصیه می شود که به سرعت وصله های امنیتی را اعمال کنند
ShadowLink :
یک ابزار هک است که توسط گروه تهدید سایبری Seashell Blizzard (معروف به Sandworm) استفاده می‌شود. این ابزار به‌عنوان یک بایگانی RAR خوداستخراج‌شونده (SFX) با نام defender.exe توزیع می‌شود که به‌طور جعلی به‌عنوان Microsoft Defender نمایش داده می‌شود. پس از اجرا، ShadowLink سرویس‌های مخفی TOR را بر روی دستگاه قربانی نصب می‌کند و آن را به یک سرور شبکه TOR با دامنه .onion منحصربه‌فرد تبدیل می‌کند. این اقدام به مهاجمان امکان می‌دهد تا از طریق شبکه TOR به دستگاه قربانی متصل شده و ترافیک را به سرویس Remote Desktop Protocol (RDP) دستگاه هدایت کنند. این روش به آن‌ها اجازه می‌دهد تا از مکانیزم‌های حفاظتی شبکه عبور کرده و به منابع داخلی دسترسی پیدا کنند.

شاخص‌های نفوذ (IOCs) مرتبط با ShadowLink:

نام فایل مخرب: defender.exe
مسیر نصب: C:\Users\Public\Defender\Defender\defender.exe
پورت مورد استفاده: پورت 3389 (پورت پیش‌فرض RDP)
دستور نصب نمونه:

C:\Users\Public\Defender\Defender\defender.exe --service install -options -f C:\Users\Public\Defender\Data\Defender\def

توصیه‌های امنیتی:

بررسی دقیق دستگاه‌های مشکوک: دستگاه‌های آلوده را به‌طور کامل برای شناسایی بدافزارها و نشانه‌های حرکت جانبی بررسی کنید.
به‌روزرسانی امنیتی: به‌روزرسانی‌های امنیتی را به‌موقع اعمال کنید، به‌ویژه برای آسیب‌پذیری‌های شناخته‌شده.
اجرای اصل حداقل دسترسی: دسترسی‌های ادمین را محدود کرده و از حساب‌های کاربری با دسترسی گسترده خودداری کنید.
تقسیم‌بندی شبکه: شبکه را به بخش‌های کوچکتر تقسیم کنید تا از گسترش بدافزار جلوگیری شود.
استفاده از مرورگرهای امن: از مرورگرهایی مانند Microsoft Edge با قابلیت SmartScreen برای شناسایی و مسدود کردن وب‌سایت‌های مخرب استفاده کنید.
غیرفعال کردن اجرای اسکریپت‌های غیرضروری: اجرای محتوای اجرایی دانلودشده را با غیرفعال کردن JavaScript یا VBScript محدود کنید.

با اجرای این اقدامات، می‌توانید از نفوذ و سوءاستفاده از ابزارهایی مانند ShadowLink جلوگیری کرده و امنیت شبکه خود را تقویت کنید.
نرم‌افزار Atera Agent یک ابزار قانونی برای نظارت و مدیریت از راه دور (RMM) است که توسط ارائه‌دهندگان خدمات مدیریت‌شده (MSP) و تیم‌های فناوری اطلاعات استفاده می‌شود. با این حال، مهاجمان سایبری، به‌ویژه گروه تهدید ایرانی موسوم به MuddyWater، از این نرم‌افزار برای دسترسی غیرمجاز به سیستم‌ها سوءاستفاده کرده‌اند.

شاخص‌های نفوذ (IOCs) مرتبط با سوءاستفاده از Atera Agent:

فرستنده‌های ایمیل فیشینگ: مهاجمان از حساب‌های ایمیل هک‌شده یا جعلی برای ارسال ایمیل‌های فیشینگ استفاده می‌کنند.

موضوعات ایمیل: موضوعاتی مانند "תלושי השכר" (فیش‌های حقوقی) یا "תלוש שכר לחודש 02/2024" (فیش حقوقی برای ماه 02/2024)

نام پیوست‌های PDF مخرب: "תלוש השכר .pdf" (فیش حقوقی)

لینک‌های دانلود مخرب: لینک‌هایی که به فایل‌های میزبانی‌شده در سرویس‌های اشتراک‌گذاری فایل مانند Egnyte، Onehub، Sync و TeraBox اشاره دارند.

هش‌های SHA256 فایل‌های مخرب: هش‌های مرتبط با فایل‌های ZIP و MSI که برای نصب Atera Agent استفاده می‌شوند.
LocalOlive
یک وب‌ شل است که توسط زیرگروهی از گروه تهدید سایبری Seashell Blizzard معروف به Sandworm استفاده می‌شود. این وب‌شل به‌عنوان ابزار اصلی برای فرماندهی و کنترل (C2) و استقرار ابزارهای اضافی در زیرساخت‌های به خطر افتاده به کار می‌رود. LocalOlive معمولاً پس از بهره‌برداری از آسیب‌پذیری‌های موجود در سیستم‌های متصل به اینترنت، به‌ویژه در زیرساخت‌های محیط‌های کوچک اداری/خانگی (SOHO) و شبکه‌های سازمانی، مستقر می‌شود. این وب‌شل به مهاجمان امکان می‌دهد تا به‌طور مداوم به سیستم‌های هدف دسترسی داشته باشند و فعالیت‌های مخرب خود را ادامه دهند.
شاخص‌های نفوذ (IOCs) مرتبط با LocalOlive:
نام فایل‌های مشکوک: فایل‌هایی با نام‌های غیرمعمول یا ناشناخته در دایرکتوری‌های وب سرور، مانند localolive.aspx یا localolive.php.
مسیرهای نصب غیرمعمول: وجود فایل‌های اجرایی در مسیرهایی که معمولاً برای فایل‌های سیستمی یا برنامه‌های قانونی استفاده نمی‌شوند، مانند C:\Users\Public\Libraries\ یا /var/tmp/.
ارتباطات شبکه‌ای غیرمجاز: ترافیک شبکه‌ای به یا از آدرس‌های IP ناشناخته یا مشکوک، به‌ویژه در پورت‌های غیرمعمول.
تغییرات در پیکربندی سرور: تغییرات غیرمجاز در فایل‌های پیکربندی وب سرور، مانند web.config یا .htaccess.
حساب‌های کاربری جدید یا ناشناخته: ایجاد حساب‌های کاربری با امتیازات بالا بدون اطلاع یا مجوز مدیر سیستم.
Fake Etsy Invoice Scam – Phishing for Credit Card Details
Threat Actors using phishing emails disguised as fake invoices from Etsy support. The emails contain PDF attachments. Victims are redirected to a spoofed Etsy support page, where they are tricked into entering credit card details under the pretense of identity verification. The scam relies on urgent language, fake Etsy URLs
Recommendation: Verify sender addresses, avoid clicking links in emails, manually navigate to Etsy.com, and report suspicious emails to Etsy support.Indicators of Compromise (IOCs) for Fake Etsy Invoice Scam – Phishing for Credit Card Details
1. Email Indicators (Phishing Emails)

Sender Addresses:
support@etsy-invoice[.]com
billing@etsy-support[.]net
help@etsy-payments[.]org
service@etsy-security[.]info
Spoofed addresses resembling official Etsy domains

Email Subjects:
"Your Etsy Invoice is Overdue – Immediate Action Required"
"Verify Your Payment Information to Continue Selling on Etsy"
"Etsy Support: Billing Issue Detected"

Email Content Characteristics:
Urgent Language (e.g., "Failure to update your payment info will result in account suspension.")
Fake Etsy Logos & Branding
Poor Grammar & Spelling Mistakes

2. Malicious Attachments

File Types:
.pdf (Fake Invoice PDFs)
.html (Redirect pages)
.zip (Potential malware loaders)

Example Malicious File Names:
Etsy_Invoice_238791.pdf
Etsy-Billing-Verification.html
Etsy_Payment_Confirmation.pdf

3. Phishing URLs (Spoofed Etsy Pages)

Fake Domains & Lookalikes:
etsy-support[.]com/login
etsy-invoice[.]net/payment
secure-etsy[.]org/billing-update
etsy-verification[.]info

Redirection Techniques:
URL shorteners (e.g., bit[.]ly, tinyurl[.]com)
Base64-encoded redirect URLs
HTML meta refresh or JavaScript-based redirections

4. IP Addresses (Hosting Malicious Sites)

Example IPs (May Change Over Time):
192.99.146[.]32
185.156.73[.]91
82.102.26[.]18
👍1