CTT Report Hub
3.43K subscribers
9.97K photos
6 videos
67 files
13.6K links
Threat Intelligence Report Hub
Download Telegram
#ParsedReport
08-06-2022

Unknown APT group has targeted Russia repeatedly since Ukraine invasion

https://blog.malwarebytes.com/threat-intelligence/2022/05/unknown-apt-group-has-targeted-russia-repeatedly-since-ukraine-invasion

Actors/Campaigns:
Shell_crew
Pirate_panda
Lazarus

Threats:
Log4shell_vuln (tags: malware, phishing)
Ollvm_tool
Bogus_control_technique
Sakula_rat
Trickbot
Bazarbackdoor

Industry:
Media, Telco, Government

Geo:
Saudi, Chinese, Ukraine, Russia, Russian

TTPs:
Tactics: 1
Technics: 0

IOCs:
File: 9
Path: 2
Domain: 4
IP: 5
Hash: 48

Functions Names: 8

Links:
https://github.com/wolfSSL/wolfssl
https://github.com/obfuscator-llvm/obfuscator/wiki/Bogus-Control-Flow
https://github.com/obfuscator-llvm/obfuscator
https://github.com/wolfSSL/wolfssl/blob/c9ae021427fd21f1a91e4020bf50bb3573c15abe/src/x509.c#L4539
https://github.com/zephyrproject-rtos/zephyr/blob/main/subsys/net/lib/http/http\_parser.c
#ParsedReport
08-06-2022

Attackers Exploit MSDT Follina Bug to Drop RAT, Infostealer

https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/follina-msdt-exploit-malware

Threats:
Follina_vuln (tags: trojan, stealer, rat, malware)
Asyncrat_rat (tags: malware)

CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...

IOCs:
File: 3
Hash: 3
#ParsedReport
08-06-2022

List of available regions. Crypto stealing campaign spread via fake cracked software

https://blog.avast.com/fakecrack-campaign

Actors/Campaigns:
Axiom

Threats:
Fakecrack
Blackseo_technique
Clipboard_changer_technique

Industry:
E-commerce, Financial

Geo:
Indonesia, India, France, Brazil, Japanese

TTPs:
Tactics: 1
Technics: 0

IOCs:
Domain: 20
File: 2
Registry: 1
Hash: 8
IP: 7

Functions Names: 1
#ParsedReport
08-06-2022

Mars Stealer malware analysis. Mars Stealer targets

https://seguranca-informatica.pt/mars-stealer-malware-analysis/?utm_source=rss&utm_medium=rss&utm_campaign=mars-stealer-malware-analysis

Threats:
Mars_stealer (tags: phishing, malware, trojan, stealer)
Oski_stealer (tags: malware)

Industry:
Financial, Iot

Geo:
Portuguese

IOCs:
File: 4

Functions Names: 1

Links:
https://github.com/sirpedrotavares/SI-LAB-malware/blob/master/mars\_stealer\_decryptor
#ParsedReport
08-06-2022

MakeMoney malvertising campaign adds fake update template

https://blog.malwarebytes.com/threat-intelligence/2022/06/makemoney-malvertising-campaign-adds-fake-update-template

Actors/Campaigns:
Makemoney (tags: malware, stealer)

Threats:
Socgholish_loader (tags: malware)
Rig_tool
Rigek_tool
Kpot_stealer
Redline_stealer

Geo:
Russia

IOCs:
Domain: 134
IP: 8
Hash: 1

Functions Names: 1
#ParsedReport
09-06-2022

Aoqin Dragon \| Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years

https://www.sentinelone.com/labs/aoqin-dragon-newly-discovered-chinese-linked-apt-has-been-quietly-spying-on-organizations-for-10-years

Actors/Campaigns:
Aoqin_dragon (tags: backdoor, dns, dropper, rat, malware, phishing, trojan)

Threats:
Dll_hijacking_technique (tags: malware)
Themida_packer_tool (tags: backdoor)
Mongall (tags: rat, backdoor, malware)
Heyoka (tags: rat, malware, backdoor, dns)
Beacon (tags: backdoor)
Watering_hole_technique

Industry:
Government, Education, Telco, Aerospace

Geo:
Vietnamese, China, Cambodia, Singapore, Myanmars, Apac, Asia, Australia, Chinese, Vietnam, Malaysia

CVEs:
CVE-2014-6332 [Vulners]
Vulners: Score: 9.3, CVSS: 9.3,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.3
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2, r2, -)
- microsoft windows 7 (-)
- microsoft windows vista (-)
- microsoft windows rt (-)
- microsoft windows rt 8.1 (-)
have more...
CVE-2012-0158 [Vulners]
Vulners: Score: 9.3, CVSS: 7.5,
Vulners: Exploitation: True
X-Force: Risk: 9.3
X-Force: Patch: Official fix
Soft:
- microsoft office (2010, 2010, 2003, 2007, 2007)
- microsoft office web components (2003)
- microsoft sql server (2000, 2008, 2008, 2005, 2008, 2008, 2008, 2000, 2005, 2008, 2008, 2005, 2005, 2008, 2008)
- microsoft biztalk server (2002)
- microsoft commerce server (2002, 2007, 2009, 2009)
have more...
CVE-2010-3333 [Vulners]
Vulners: Score: 9.3, CVSS: 9.1,
Vulners: Exploitation: True
X-Force: Risk: 9.3
X-Force: Patch: Official fix
Soft:
- microsoft office (xp, 2008, 2011, 2010, 2004, 2003, 2007)
- microsoft open xml file format converter (*)


TTPs:
Tactics: 8
Technics: 15

IOCs:
Path: 11
File: 9
Hash: 155
IP: 8
Domain: 81

Links:
https://github.com/SentineLabs/aoqin\_dragon
#ParsedReport
09-06-2022

Operation () Tejas: A dying elephant curled up in the Kunlun Mountains

https://mp-weixin-qq-com.translate.goog/s/8j_rHA7gdMxY1_X8alj8Zg?_x_tr_sl=zh-CN&_x_tr_tl=en&_x_tr_hl=en

Actors/Campaigns:
Manling_flower
Sidewinder
Manlinghua
Maya_elephant
Diamondback

Threats:
Raindrop_tool
Opendir

Industry:
Financial

Geo:
China, Asia, Bangladesh

CVEs:
CVE-2018-0798 [Vulners]
Vulners: Score: 9.3, CVSS: 9.3,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2010, 2016, 2016, 2007, 2013)
- microsoft word (2013, 2016, 2007, 2010, 2013)
- microsoft office compatibility pack (-)


IOCs:
Hash: 22
File: 1
Path: 2
#ParsedReport
09-06-2022

Symbiote Deep-Dive: Analysis of a New, Nearly-Impossible-to-Detect Linux Threat

https://www.intezer.com/blog/research/new-linux-threat-symbiote

Actors/Campaigns:
Equation

Threats:
Symbiote (tags: scan, malware, rootkit, rat, dns, backdoor)
Ebury (tags: malware)

Industry:
Financial

Geo:
Brazil, America, Brazilian

TTPs:

IOCs:
File: 5
IP: 1
Domain: 9
Hash: 5

Functions Names: 4

Links:
https://github.com/iagox86/dnscat2
#ParsedReport
09-06-2022

Shark's Carnival APT-C-55 Kimsuky Organization's Recent BabyShark Component Disclosure

https://mp-weixin-qq-com.translate.goog/s/ZV8AOTd7YGUgCTTTZtTktQ?_x_tr_sl=zh-CN&_x_tr_tl=en&_x_tr_hl=en

Actors/Campaigns:
Kimsuky (tags: malware, rat)
Axiom

Threats:
Shark (tags: malware, rat)
Babyshark (tags: malware, rat)
Nuclear
Gold_dragon

Industry:
Government

Geo:
Korean

IOCs:
Url: 3
Domain: 2
Hash: 3
File: 2

Functions Names: 1
#ParsedReport
09-06-2022

Killnet: The Hactivist Group That Started A Global Cyber War

https://www.digitalshadows.com/blog-and-research/killnet-the-hactivist-group-that-started-a-global-cyber-war

Actors/Campaigns:
Killnet (tags: botnet, ddos, rat)
It_army
Ddosgung
Sakurajima
Kratos
Zarya

Threats:
Phoenix_keylogger
Mirai
Dns_amplification_technique

Industry:
Financial, Government

Geo:
Russian, Russia, Ukraine, Lithuania, Poland, Romanian, Estonia, Latvia, Italian, Germany, German, Italy, Romania

Functions Names: 1
#ParsedReport
09-06-2022

LockBit 2.0: How This RaaS Operates and How to Protect Against It

https://unit42.paloaltonetworks.com/lockbit-2-ransomware

Actors/Campaigns:
Darkside

Threats:
Lockbit (tags: stealer, rat, malware, spyware, ddos, ransomware, vpn, dns, scan, proxy, phishing)
Babuk
Revil
Conti
Blackcat
Avaddon
Suncrypt
Blackbyte
Cobalt_strike
Metasploit_tool
Proxyshell_vuln
Psexec_tool
Wevtutil_tool
Mimikatz
Minidump_tool
Grabchrome_tool
Grabrff_tool
Netscan_tool
Adfind_tool
Pchunter_tool
Beacon
Megasync_tool
Stealbit

Industry:
Healthcare, Education, Retail, Financial

Geo:
Latam, Russian, Japan, Japac, Germany, Apac, Italy, America, Emea

CVEs:
CVE-2021-20028 [Vulners]
Vulners: Score: 7.5, CVSS: 4.4,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Unavailable
Soft:
- sonicwall sma 210 firmware (<9.0.0.10)
- sonicwall sma 410 firmware (<9.0.0.10)
- sonicwall sma 500v firmware (<9.0.0.10)

CVE-2021-34523 [Vulners]
Vulners: Score: 7.5, CVSS: 6.4,
Vulners: Exploitation: True
X-Force: Risk: 9
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2013, 2016, 2016, 2019, 2019)

CVE-2020-0787 [Vulners]
Vulners: Score: 7.2, CVSS: 5.1,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (-, 1607, 1709, 1803, 1809, 1903, 1909)
- microsoft windows 7 (-)
- microsoft windows 8.1 (-)
- microsoft windows rt 8.1 (-)
- microsoft windows server 2008 (-, r2, r2)
have more...
CVE-2021-34473 [Vulners]
Vulners: Score: 10.0, CVSS: 6.4,
Vulners: Exploitation: True
X-Force: Risk: 9.1
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2013, 2016, 2016, 2019, 2019)


TTPs:
Tactics: 10
Technics: 27
#ParsedReport
09-06-2022

Andariel Group, active only in Korea, for the past two years

https://www-ahnlab-com.translate.goog/kr/site/securityinfo/secunews/secuNewsView.do?seq=31890&menu_dist=2&cmd=scrap&_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp

Actors/Campaigns:
Lazarus (tags: malware, phishing, ransomware, keylogger)

Threats:
Gh0st_rat
Rifdoor
Phandoor
Tiger_downloader
Watering_hole_technique
Nukesped_rat
Tiger_rat

Geo:
Korea

IOCs:
File: 10

Functions Names: 1
Оппааа! Кто-то небезопасно выкладывает куски кода )
#ParsedReport
09-06-2022

eSentire Threat Intelligence Malware Analysis: Purple Fox

https://www.esentire.com/blog/esentire-threat-intelligence-malware-analysis-purple-fox

Threats:
Purplefox (tags: malware, rat, rootkit, proxy, dns, scan, phishing)
Rig_tool (tags: malware)
Lolbin
Hot_potato_technique
Tater_exploit

Geo:
Chinese, Africa, Apac, America, Emea

CVEs:
CVE-2018-8120 [Vulners]
Vulners: Score: 7.2, CVSS: 7.3,
Vulners: Exploitation: True
X-Force: Risk: 7
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2, -, r2)
- microsoft windows 7 (-)

CVE-2021-1675 [Vulners]
Vulners: Score: 9.3, CVSS: 3.2,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2, -)
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 20h2, 21h1, 1809, 1909, 2004)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
have more...
CVE-2015-1701 [Vulners]
Vulners: Score: 7.2, CVSS: 7.1,
Vulners: Exploitation: True
X-Force: Risk: 6.8
X-Force: Patch: Official fix
Soft:
- microsoft windows vista (*)
- microsoft windows 2003 server (*)
- microsoft windows server 2008 (-)
- microsoft windows 7 (le-, le-)

CVE-2020-0674 [Vulners]
Vulners: Score: 7.6, CVSS: 6.2,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Workaround
Soft:
- microsoft internet explorer (9, 10, 11)

CVE-2019-0808 [Vulners]
Vulners: Score: 7.2, CVSS: 6.2,
Vulners: Exploitation: True
X-Force: Risk: 7
X-Force: Patch: Official fix
Soft:
- microsoft windows 7 (sp1)
- microsoft windows server 2008 (r2, r2, -)


IOCs:
File: 10
Registry: 4
Path: 21
IP: 39
Domain: 1
Hash: 6
Url: 1

YARA: Found

Links:
https://github.com/Kevin-Robertson/Tater
https://github.com/k8gege/K8tools
#ParsedReport
10-06-2022

Lyceum .NET DNSBackdoor. Key Features of this attack:

https://www.zscaler.com/blogs/security-research/lyceum-net-dns-backdoor

Actors/Campaigns:
Siamesekitten (tags: dns, backdoor, malware)

Threats:
Dnsbackdoor (tags: dns, backdoor, malware)

Industry:
Energy, Telco

Geo:
Iran, Iranian

TTPs:
Tactics: 1
Technics: 7

IOCs:
File: 5
Url: 5
Hash: 2
Domain: 1
IP: 2

Functions Names: 6
#ParsedReport
10-06-2022

Bumblebee Loader Linked to Conti and Used In Quantum Locker Attacks

https://www.kroll.com/en/insights/publications/cyber/bumblebee-loader-linked-conti-used-in-quantum-locker-attacks

Actors/Campaigns:
Exotic_lily
Ta578
Ta579

Threats:
Quantum_locker (tags: spam, phishing, trojan, malware, ransomware)
Bumblebee (tags: spam, phishing, trojan, malware, ransomware)
Conti (tags: spam, phishing, trojan, malware, ransomware)
Cobalt_strike
Emotet
Icedid
Ryuk
Gozi
Meterpreter_tool
Sliver_tool
Bazarbackdoor

Industry:
Healthcare

CVEs:
CVE-2021-40444 [Vulners]
Vulners: Score: 6.8, CVSS: 2.1,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2, -)
- microsoft windows 10 (1607, -, 1809, 1909, 2004, 20h2, 21h1)
- microsoft windows server 2016 (-, 2004, 20h2)
- microsoft windows rt 8.1 (-)
- microsoft windows server 2012 (-, -)
have more...

Links:
https://github.com/LordNoteworthy/al-khaser/tree/06d4a89e9ecc3e49e4d2df67fe0b2d6faf04166e