CTT Report Hub
3.43K subscribers
9.97K photos
6 videos
67 files
13.6K links
Threat Intelligence Report Hub
Download Telegram
#ParsedReport
08-06-2022

Mars Stealer malware analysis. Mars Stealer targets

https://seguranca-informatica.pt/mars-stealer-malware-analysis/?utm_source=rss&utm_medium=rss&utm_campaign=mars-stealer-malware-analysis

Threats:
Mars_stealer (tags: phishing, malware, trojan, stealer)
Oski_stealer (tags: malware)

Industry:
Financial, Iot

Geo:
Portuguese

IOCs:
File: 4

Functions Names: 1

Links:
https://github.com/sirpedrotavares/SI-LAB-malware/blob/master/mars\_stealer\_decryptor
#ParsedReport
08-06-2022

MakeMoney malvertising campaign adds fake update template

https://blog.malwarebytes.com/threat-intelligence/2022/06/makemoney-malvertising-campaign-adds-fake-update-template

Actors/Campaigns:
Makemoney (tags: malware, stealer)

Threats:
Socgholish_loader (tags: malware)
Rig_tool
Rigek_tool
Kpot_stealer
Redline_stealer

Geo:
Russia

IOCs:
Domain: 134
IP: 8
Hash: 1

Functions Names: 1
#ParsedReport
09-06-2022

Aoqin Dragon \| Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years

https://www.sentinelone.com/labs/aoqin-dragon-newly-discovered-chinese-linked-apt-has-been-quietly-spying-on-organizations-for-10-years

Actors/Campaigns:
Aoqin_dragon (tags: backdoor, dns, dropper, rat, malware, phishing, trojan)

Threats:
Dll_hijacking_technique (tags: malware)
Themida_packer_tool (tags: backdoor)
Mongall (tags: rat, backdoor, malware)
Heyoka (tags: rat, malware, backdoor, dns)
Beacon (tags: backdoor)
Watering_hole_technique

Industry:
Government, Education, Telco, Aerospace

Geo:
Vietnamese, China, Cambodia, Singapore, Myanmars, Apac, Asia, Australia, Chinese, Vietnam, Malaysia

CVEs:
CVE-2014-6332 [Vulners]
Vulners: Score: 9.3, CVSS: 9.3,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.3
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2, r2, -)
- microsoft windows 7 (-)
- microsoft windows vista (-)
- microsoft windows rt (-)
- microsoft windows rt 8.1 (-)
have more...
CVE-2012-0158 [Vulners]
Vulners: Score: 9.3, CVSS: 7.5,
Vulners: Exploitation: True
X-Force: Risk: 9.3
X-Force: Patch: Official fix
Soft:
- microsoft office (2010, 2010, 2003, 2007, 2007)
- microsoft office web components (2003)
- microsoft sql server (2000, 2008, 2008, 2005, 2008, 2008, 2008, 2000, 2005, 2008, 2008, 2005, 2005, 2008, 2008)
- microsoft biztalk server (2002)
- microsoft commerce server (2002, 2007, 2009, 2009)
have more...
CVE-2010-3333 [Vulners]
Vulners: Score: 9.3, CVSS: 9.1,
Vulners: Exploitation: True
X-Force: Risk: 9.3
X-Force: Patch: Official fix
Soft:
- microsoft office (xp, 2008, 2011, 2010, 2004, 2003, 2007)
- microsoft open xml file format converter (*)


TTPs:
Tactics: 8
Technics: 15

IOCs:
Path: 11
File: 9
Hash: 155
IP: 8
Domain: 81

Links:
https://github.com/SentineLabs/aoqin\_dragon
#ParsedReport
09-06-2022

Operation () Tejas: A dying elephant curled up in the Kunlun Mountains

https://mp-weixin-qq-com.translate.goog/s/8j_rHA7gdMxY1_X8alj8Zg?_x_tr_sl=zh-CN&_x_tr_tl=en&_x_tr_hl=en

Actors/Campaigns:
Manling_flower
Sidewinder
Manlinghua
Maya_elephant
Diamondback

Threats:
Raindrop_tool
Opendir

Industry:
Financial

Geo:
China, Asia, Bangladesh

CVEs:
CVE-2018-0798 [Vulners]
Vulners: Score: 9.3, CVSS: 9.3,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2010, 2016, 2016, 2007, 2013)
- microsoft word (2013, 2016, 2007, 2010, 2013)
- microsoft office compatibility pack (-)


IOCs:
Hash: 22
File: 1
Path: 2
#ParsedReport
09-06-2022

Symbiote Deep-Dive: Analysis of a New, Nearly-Impossible-to-Detect Linux Threat

https://www.intezer.com/blog/research/new-linux-threat-symbiote

Actors/Campaigns:
Equation

Threats:
Symbiote (tags: scan, malware, rootkit, rat, dns, backdoor)
Ebury (tags: malware)

Industry:
Financial

Geo:
Brazil, America, Brazilian

TTPs:

IOCs:
File: 5
IP: 1
Domain: 9
Hash: 5

Functions Names: 4

Links:
https://github.com/iagox86/dnscat2
#ParsedReport
09-06-2022

Shark's Carnival APT-C-55 Kimsuky Organization's Recent BabyShark Component Disclosure

https://mp-weixin-qq-com.translate.goog/s/ZV8AOTd7YGUgCTTTZtTktQ?_x_tr_sl=zh-CN&_x_tr_tl=en&_x_tr_hl=en

Actors/Campaigns:
Kimsuky (tags: malware, rat)
Axiom

Threats:
Shark (tags: malware, rat)
Babyshark (tags: malware, rat)
Nuclear
Gold_dragon

Industry:
Government

Geo:
Korean

IOCs:
Url: 3
Domain: 2
Hash: 3
File: 2

Functions Names: 1
#ParsedReport
09-06-2022

Killnet: The Hactivist Group That Started A Global Cyber War

https://www.digitalshadows.com/blog-and-research/killnet-the-hactivist-group-that-started-a-global-cyber-war

Actors/Campaigns:
Killnet (tags: botnet, ddos, rat)
It_army
Ddosgung
Sakurajima
Kratos
Zarya

Threats:
Phoenix_keylogger
Mirai
Dns_amplification_technique

Industry:
Financial, Government

Geo:
Russian, Russia, Ukraine, Lithuania, Poland, Romanian, Estonia, Latvia, Italian, Germany, German, Italy, Romania

Functions Names: 1
#ParsedReport
09-06-2022

LockBit 2.0: How This RaaS Operates and How to Protect Against It

https://unit42.paloaltonetworks.com/lockbit-2-ransomware

Actors/Campaigns:
Darkside

Threats:
Lockbit (tags: stealer, rat, malware, spyware, ddos, ransomware, vpn, dns, scan, proxy, phishing)
Babuk
Revil
Conti
Blackcat
Avaddon
Suncrypt
Blackbyte
Cobalt_strike
Metasploit_tool
Proxyshell_vuln
Psexec_tool
Wevtutil_tool
Mimikatz
Minidump_tool
Grabchrome_tool
Grabrff_tool
Netscan_tool
Adfind_tool
Pchunter_tool
Beacon
Megasync_tool
Stealbit

Industry:
Healthcare, Education, Retail, Financial

Geo:
Latam, Russian, Japan, Japac, Germany, Apac, Italy, America, Emea

CVEs:
CVE-2021-20028 [Vulners]
Vulners: Score: 7.5, CVSS: 4.4,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Unavailable
Soft:
- sonicwall sma 210 firmware (<9.0.0.10)
- sonicwall sma 410 firmware (<9.0.0.10)
- sonicwall sma 500v firmware (<9.0.0.10)

CVE-2021-34523 [Vulners]
Vulners: Score: 7.5, CVSS: 6.4,
Vulners: Exploitation: True
X-Force: Risk: 9
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2013, 2016, 2016, 2019, 2019)

CVE-2020-0787 [Vulners]
Vulners: Score: 7.2, CVSS: 5.1,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (-, 1607, 1709, 1803, 1809, 1903, 1909)
- microsoft windows 7 (-)
- microsoft windows 8.1 (-)
- microsoft windows rt 8.1 (-)
- microsoft windows server 2008 (-, r2, r2)
have more...
CVE-2021-34473 [Vulners]
Vulners: Score: 10.0, CVSS: 6.4,
Vulners: Exploitation: True
X-Force: Risk: 9.1
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2013, 2016, 2016, 2019, 2019)


TTPs:
Tactics: 10
Technics: 27
#ParsedReport
09-06-2022

Andariel Group, active only in Korea, for the past two years

https://www-ahnlab-com.translate.goog/kr/site/securityinfo/secunews/secuNewsView.do?seq=31890&menu_dist=2&cmd=scrap&_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp

Actors/Campaigns:
Lazarus (tags: malware, phishing, ransomware, keylogger)

Threats:
Gh0st_rat
Rifdoor
Phandoor
Tiger_downloader
Watering_hole_technique
Nukesped_rat
Tiger_rat

Geo:
Korea

IOCs:
File: 10

Functions Names: 1
Оппааа! Кто-то небезопасно выкладывает куски кода )
#ParsedReport
09-06-2022

eSentire Threat Intelligence Malware Analysis: Purple Fox

https://www.esentire.com/blog/esentire-threat-intelligence-malware-analysis-purple-fox

Threats:
Purplefox (tags: malware, rat, rootkit, proxy, dns, scan, phishing)
Rig_tool (tags: malware)
Lolbin
Hot_potato_technique
Tater_exploit

Geo:
Chinese, Africa, Apac, America, Emea

CVEs:
CVE-2018-8120 [Vulners]
Vulners: Score: 7.2, CVSS: 7.3,
Vulners: Exploitation: True
X-Force: Risk: 7
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2, -, r2)
- microsoft windows 7 (-)

CVE-2021-1675 [Vulners]
Vulners: Score: 9.3, CVSS: 3.2,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2, -)
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 20h2, 21h1, 1809, 1909, 2004)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
have more...
CVE-2015-1701 [Vulners]
Vulners: Score: 7.2, CVSS: 7.1,
Vulners: Exploitation: True
X-Force: Risk: 6.8
X-Force: Patch: Official fix
Soft:
- microsoft windows vista (*)
- microsoft windows 2003 server (*)
- microsoft windows server 2008 (-)
- microsoft windows 7 (le-, le-)

CVE-2020-0674 [Vulners]
Vulners: Score: 7.6, CVSS: 6.2,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Workaround
Soft:
- microsoft internet explorer (9, 10, 11)

CVE-2019-0808 [Vulners]
Vulners: Score: 7.2, CVSS: 6.2,
Vulners: Exploitation: True
X-Force: Risk: 7
X-Force: Patch: Official fix
Soft:
- microsoft windows 7 (sp1)
- microsoft windows server 2008 (r2, r2, -)


IOCs:
File: 10
Registry: 4
Path: 21
IP: 39
Domain: 1
Hash: 6
Url: 1

YARA: Found

Links:
https://github.com/Kevin-Robertson/Tater
https://github.com/k8gege/K8tools
#ParsedReport
10-06-2022

Lyceum .NET DNSBackdoor. Key Features of this attack:

https://www.zscaler.com/blogs/security-research/lyceum-net-dns-backdoor

Actors/Campaigns:
Siamesekitten (tags: dns, backdoor, malware)

Threats:
Dnsbackdoor (tags: dns, backdoor, malware)

Industry:
Energy, Telco

Geo:
Iran, Iranian

TTPs:
Tactics: 1
Technics: 7

IOCs:
File: 5
Url: 5
Hash: 2
Domain: 1
IP: 2

Functions Names: 6
#ParsedReport
10-06-2022

Bumblebee Loader Linked to Conti and Used In Quantum Locker Attacks

https://www.kroll.com/en/insights/publications/cyber/bumblebee-loader-linked-conti-used-in-quantum-locker-attacks

Actors/Campaigns:
Exotic_lily
Ta578
Ta579

Threats:
Quantum_locker (tags: spam, phishing, trojan, malware, ransomware)
Bumblebee (tags: spam, phishing, trojan, malware, ransomware)
Conti (tags: spam, phishing, trojan, malware, ransomware)
Cobalt_strike
Emotet
Icedid
Ryuk
Gozi
Meterpreter_tool
Sliver_tool
Bazarbackdoor

Industry:
Healthcare

CVEs:
CVE-2021-40444 [Vulners]
Vulners: Score: 6.8, CVSS: 2.1,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2, -)
- microsoft windows 10 (1607, -, 1809, 1909, 2004, 20h2, 21h1)
- microsoft windows server 2016 (-, 2004, 20h2)
- microsoft windows rt 8.1 (-)
- microsoft windows server 2012 (-, -)
have more...

Links:
https://github.com/LordNoteworthy/al-khaser/tree/06d4a89e9ecc3e49e4d2df67fe0b2d6faf04166e
#ParsedReport
10-06-2022

Back From the Dead, Emotet Returns in 2022

https://www.deepinstinct.com/blog/emotet-malware-returns-in-2022

Actors/Campaigns:
Wizard_spider (tags: malware)

Threats:
Emotet (tags: malware, botnet, rat, phishing, trojan, ransomware)
Conti
Ryuk
Trickbot (tags: malware)
Qakbot
Chaos (tags: phishing, malware)

Industry:
Financial

Geo:
Japanese, Netherlands

CVEs:
CVE-2017-11882 [Vulners]
Vulners: Score: 9.3, CVSS: 8.3,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2013, 2010, 2016, 2007)
#ParsedReport
10-06-2022

SANS ISC: InfoSec Handlers Diary Blog - SANS Internet Storm Center SANS Site Network Current Site SANS Internet Storm Center Other SANS Sites Help Graduate Degree Programs Security Training Security Certification Security Awareness Training Penetration Testing Industrial Control Systems Cyber Defense Foundations DFIR Software Security Government OnSite Training InfoSec Handlers Diary Blog

https://isc.sans.edu/diary/rss/28728

Actors/Campaigns:
Ta570 (tags: spam, malware)

Threats:
Qakbot (tags: spam, malware)
Follina_vuln (tags: spam, malware)

Industry:
Government

CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...

IOCs:
File: 59
Hash: 49
Path: 1
Url: 4