#ParsedReport
08-06-2022
Follina vulnerability (CVE-2022-30190) attack in 'antibacterial film proposal'
https://asec-ahnlab-com.translate.goog/ko/35013/?_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Threats:
Follina_vuln (tags: malware)
CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...
IOCs:
File: 10
Url: 6
Path: 2
Hash: 5
08-06-2022
Follina vulnerability (CVE-2022-30190) attack in 'antibacterial film proposal'
https://asec-ahnlab-com.translate.goog/ko/35013/?_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Threats:
Follina_vuln (tags: malware)
CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...
IOCs:
File: 10
Url: 6
Path: 2
Hash: 5
ASEC BLOG
'항균필름제안서' 내용의 Follina 취약점(CVE-2022-30190) 공격 - ASEC BLOG
지난 5월 31일, ASEC 분석팀에서는 본 블로그를 통해 MS 오피스 문서파일에 대한 제로데이 취약점인 Follina 에 대해 신속하게 소개한 바 있다. 아직 해당 취약점에 대한 패치가 제공되지 않아 사용자 주의가 요구되는 상황이다. 주의! MS 오피스 제로데이 취약점 Follina (CVE-2022-30190) 안랩은 해당 취약점 이용한 공격시도에 대해 파일진단, 행위진단 관점에서 탐지 룰을 배포한 상황이며, 다양한 자사 제품군(V3, MDS, EDR)에서…
#ParsedReport
08-06-2022
Mars Stealer malware analysis. Mars Stealer targets
https://seguranca-informatica.pt/mars-stealer-malware-analysis/?utm_source=rss&utm_medium=rss&utm_campaign=mars-stealer-malware-analysis
Threats:
Mars_stealer (tags: phishing, malware, trojan, stealer)
Oski_stealer (tags: malware)
Industry:
Financial, Iot
Geo:
Portuguese
IOCs:
File: 4
Functions Names: 1
Links:
08-06-2022
Mars Stealer malware analysis. Mars Stealer targets
https://seguranca-informatica.pt/mars-stealer-malware-analysis/?utm_source=rss&utm_medium=rss&utm_campaign=mars-stealer-malware-analysis
Threats:
Mars_stealer (tags: phishing, malware, trojan, stealer)
Oski_stealer (tags: malware)
Industry:
Financial, Iot
Geo:
Portuguese
IOCs:
File: 4
Functions Names: 1
Links:
https://github.com/sirpedrotavares/SI-LAB-malware/blob/master/mars\_stealer\_decryptor#ParsedReport
08-06-2022
MakeMoney malvertising campaign adds fake update template
https://blog.malwarebytes.com/threat-intelligence/2022/06/makemoney-malvertising-campaign-adds-fake-update-template
Actors/Campaigns:
Makemoney (tags: malware, stealer)
Threats:
Socgholish_loader (tags: malware)
Rig_tool
Rigek_tool
Kpot_stealer
Redline_stealer
Geo:
Russia
IOCs:
Domain: 134
IP: 8
Hash: 1
Functions Names: 1
08-06-2022
MakeMoney malvertising campaign adds fake update template
https://blog.malwarebytes.com/threat-intelligence/2022/06/makemoney-malvertising-campaign-adds-fake-update-template
Actors/Campaigns:
Makemoney (tags: malware, stealer)
Threats:
Socgholish_loader (tags: malware)
Rig_tool
Rigek_tool
Kpot_stealer
Redline_stealer
Geo:
Russia
IOCs:
Domain: 134
IP: 8
Hash: 1
Functions Names: 1
Malwarebytes
MakeMoney malvertising campaign adds fake update template
We catch up with some old acquaintances that just aren't ready to hang up the towel just yet.
#ParsedReport
09-06-2022
Aoqin Dragon \| Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years
https://www.sentinelone.com/labs/aoqin-dragon-newly-discovered-chinese-linked-apt-has-been-quietly-spying-on-organizations-for-10-years
Actors/Campaigns:
Aoqin_dragon (tags: backdoor, dns, dropper, rat, malware, phishing, trojan)
Threats:
Dll_hijacking_technique (tags: malware)
Themida_packer_tool (tags: backdoor)
Mongall (tags: rat, backdoor, malware)
Heyoka (tags: rat, malware, backdoor, dns)
Beacon (tags: backdoor)
Watering_hole_technique
Industry:
Government, Education, Telco, Aerospace
Geo:
Vietnamese, China, Cambodia, Singapore, Myanmars, Apac, Asia, Australia, Chinese, Vietnam, Malaysia
CVEs:
CVE-2014-6332 [Vulners]
Vulners: Score: 9.3, CVSS: 9.3,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.3
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2, r2, -)
- microsoft windows 7 (-)
- microsoft windows vista (-)
- microsoft windows rt (-)
- microsoft windows rt 8.1 (-)
have more...
CVE-2012-0158 [Vulners]
Vulners: Score: 9.3, CVSS: 7.5,
Vulners: Exploitation: True
X-Force: Risk: 9.3
X-Force: Patch: Official fix
Soft:
- microsoft office (2010, 2010, 2003, 2007, 2007)
- microsoft office web components (2003)
- microsoft sql server (2000, 2008, 2008, 2005, 2008, 2008, 2008, 2000, 2005, 2008, 2008, 2005, 2005, 2008, 2008)
- microsoft biztalk server (2002)
- microsoft commerce server (2002, 2007, 2009, 2009)
have more...
CVE-2010-3333 [Vulners]
Vulners: Score: 9.3, CVSS: 9.1,
Vulners: Exploitation: True
X-Force: Risk: 9.3
X-Force: Patch: Official fix
Soft:
- microsoft office (xp, 2008, 2011, 2010, 2004, 2003, 2007)
- microsoft open xml file format converter (*)
TTPs:
Tactics: 8
Technics: 15
IOCs:
Path: 11
File: 9
Hash: 155
IP: 8
Domain: 81
Links:
09-06-2022
Aoqin Dragon \| Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years
https://www.sentinelone.com/labs/aoqin-dragon-newly-discovered-chinese-linked-apt-has-been-quietly-spying-on-organizations-for-10-years
Actors/Campaigns:
Aoqin_dragon (tags: backdoor, dns, dropper, rat, malware, phishing, trojan)
Threats:
Dll_hijacking_technique (tags: malware)
Themida_packer_tool (tags: backdoor)
Mongall (tags: rat, backdoor, malware)
Heyoka (tags: rat, malware, backdoor, dns)
Beacon (tags: backdoor)
Watering_hole_technique
Industry:
Government, Education, Telco, Aerospace
Geo:
Vietnamese, China, Cambodia, Singapore, Myanmars, Apac, Asia, Australia, Chinese, Vietnam, Malaysia
CVEs:
CVE-2014-6332 [Vulners]
Vulners: Score: 9.3, CVSS: 9.3,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.3
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2, r2, -)
- microsoft windows 7 (-)
- microsoft windows vista (-)
- microsoft windows rt (-)
- microsoft windows rt 8.1 (-)
have more...
CVE-2012-0158 [Vulners]
Vulners: Score: 9.3, CVSS: 7.5,
Vulners: Exploitation: True
X-Force: Risk: 9.3
X-Force: Patch: Official fix
Soft:
- microsoft office (2010, 2010, 2003, 2007, 2007)
- microsoft office web components (2003)
- microsoft sql server (2000, 2008, 2008, 2005, 2008, 2008, 2008, 2000, 2005, 2008, 2008, 2005, 2005, 2008, 2008)
- microsoft biztalk server (2002)
- microsoft commerce server (2002, 2007, 2009, 2009)
have more...
CVE-2010-3333 [Vulners]
Vulners: Score: 9.3, CVSS: 9.1,
Vulners: Exploitation: True
X-Force: Risk: 9.3
X-Force: Patch: Official fix
Soft:
- microsoft office (xp, 2008, 2011, 2010, 2004, 2003, 2007)
- microsoft open xml file format converter (*)
TTPs:
Tactics: 8
Technics: 15
IOCs:
Path: 11
File: 9
Hash: 155
IP: 8
Domain: 81
Links:
https://github.com/SentineLabs/aoqin\_dragonSentinelOne
Aoqin Dragon | Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years
Targeting organizations in SE Asia and Australia, Aoqin Dragon uses pornographic-themed lures and custom backdoors to conduct espionage operations.
#ParsedReport
09-06-2022
Operation () Tejas: A dying elephant curled up in the Kunlun Mountains
https://mp-weixin-qq-com.translate.goog/s/8j_rHA7gdMxY1_X8alj8Zg?_x_tr_sl=zh-CN&_x_tr_tl=en&_x_tr_hl=en
Actors/Campaigns:
Manling_flower
Sidewinder
Manlinghua
Maya_elephant
Diamondback
Threats:
Raindrop_tool
Opendir
Industry:
Financial
Geo:
China, Asia, Bangladesh
CVEs:
CVE-2018-0798 [Vulners]
Vulners: Score: 9.3, CVSS: 9.3,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2010, 2016, 2016, 2007, 2013)
- microsoft word (2013, 2016, 2007, 2010, 2013)
- microsoft office compatibility pack (-)
IOCs:
Hash: 22
File: 1
Path: 2
09-06-2022
Operation () Tejas: A dying elephant curled up in the Kunlun Mountains
https://mp-weixin-qq-com.translate.goog/s/8j_rHA7gdMxY1_X8alj8Zg?_x_tr_sl=zh-CN&_x_tr_tl=en&_x_tr_hl=en
Actors/Campaigns:
Manling_flower
Sidewinder
Manlinghua
Maya_elephant
Diamondback
Threats:
Raindrop_tool
Opendir
Industry:
Financial
Geo:
China, Asia, Bangladesh
CVEs:
CVE-2018-0798 [Vulners]
Vulners: Score: 9.3, CVSS: 9.3,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2010, 2016, 2016, 2007, 2013)
- microsoft word (2013, 2016, 2007, 2010, 2013)
- microsoft office compatibility pack (-)
IOCs:
Hash: 22
File: 1
Path: 2
微信公众平台
Operation(काराकोरम) Tejas:蜷居在昆仑山脉的残喘枯象
奇安信威胁情报中心发现蔓灵花团伙(APT-Q-37)在四月份最新的攻击活动中使用了新的攻击手法和样本,除此之外文末还会对摩耶象(APT-Q-41)近期的钓鱼活动和响尾蛇(APT-Q-39)今年以来的基础设施进行分享。
#ParsedReport
09-06-2022
Symbiote Deep-Dive: Analysis of a New, Nearly-Impossible-to-Detect Linux Threat
https://www.intezer.com/blog/research/new-linux-threat-symbiote
Actors/Campaigns:
Equation
Threats:
Symbiote (tags: scan, malware, rootkit, rat, dns, backdoor)
Ebury (tags: malware)
Industry:
Financial
Geo:
Brazil, America, Brazilian
TTPs:
IOCs:
File: 5
IP: 1
Domain: 9
Hash: 5
Functions Names: 4
Links:
09-06-2022
Symbiote Deep-Dive: Analysis of a New, Nearly-Impossible-to-Detect Linux Threat
https://www.intezer.com/blog/research/new-linux-threat-symbiote
Actors/Campaigns:
Equation
Threats:
Symbiote (tags: scan, malware, rootkit, rat, dns, backdoor)
Ebury (tags: malware)
Industry:
Financial
Geo:
Brazil, America, Brazilian
TTPs:
IOCs:
File: 5
IP: 1
Domain: 9
Hash: 5
Functions Names: 4
Links:
https://github.com/iagox86/dnscat2Intezer
Symbiote: A New, Nearly-Impossible-to-Detect Linux Threat
Symbiote is a new Linux® malware we discovered that acts in a parasitic nature, infecting other running processes to inflict damage on machines.
#ParsedReport
09-06-2022
Shark's Carnival APT-C-55 Kimsuky Organization's Recent BabyShark Component Disclosure
https://mp-weixin-qq-com.translate.goog/s/ZV8AOTd7YGUgCTTTZtTktQ?_x_tr_sl=zh-CN&_x_tr_tl=en&_x_tr_hl=en
Actors/Campaigns:
Kimsuky (tags: malware, rat)
Axiom
Threats:
Shark (tags: malware, rat)
Babyshark (tags: malware, rat)
Nuclear
Gold_dragon
Industry:
Government
Geo:
Korean
IOCs:
Url: 3
Domain: 2
Hash: 3
File: 2
Functions Names: 1
09-06-2022
Shark's Carnival APT-C-55 Kimsuky Organization's Recent BabyShark Component Disclosure
https://mp-weixin-qq-com.translate.goog/s/ZV8AOTd7YGUgCTTTZtTktQ?_x_tr_sl=zh-CN&_x_tr_tl=en&_x_tr_hl=en
Actors/Campaigns:
Kimsuky (tags: malware, rat)
Axiom
Threats:
Shark (tags: malware, rat)
Babyshark (tags: malware, rat)
Nuclear
Gold_dragon
Industry:
Government
Geo:
Korean
IOCs:
Url: 3
Domain: 2
Hash: 3
File: 2
Functions Names: 1
微信公众平台
鲨鱼的狂欢 — APT-C-55 Kimsuky组织近期BabyShark组件披露
2022年上半年,360高级威胁研究院发现了来自Kimsuky组织该组件的多起攻击活动,该组件会针对特定用户进行定向攻击活动,隐蔽性强,并通过对多个地址访问请求增强其溯源难度
#ParsedReport
09-06-2022
ASEC Weekly Malware Statistics ( 20220530 \~ 20220605 )
https://asec-ahnlab-com.translate.goog/ko/35144/?_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Threats:
Formbook (tags: spam, malware, stealer)
Agent_tesla
Azorult
Lokibot_stealer
Avemaria_rat
Redline_stealer (tags: malware)
Beamwinhttp_loader
Industry:
Transport, Financial
IOCs:
File: 35
Url: 20
Domain: 8
IP: 12
Email: 4
09-06-2022
ASEC Weekly Malware Statistics ( 20220530 \~ 20220605 )
https://asec-ahnlab-com.translate.goog/ko/35144/?_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Threats:
Formbook (tags: spam, malware, stealer)
Agent_tesla
Azorult
Lokibot_stealer
Avemaria_rat
Redline_stealer (tags: malware)
Beamwinhttp_loader
Industry:
Transport, Financial
IOCs:
File: 35
Url: 20
Domain: 8
IP: 12
Email: 4
ASEC BLOG
ASEC 주간 악성코드 통계 ( 20220530 ~ 20220605 ) - ASEC BLOG
ASEC 분석팀에서는 ASEC 자동 분석 시스템 RAPIT 을 활용하여 알려진 악성코드들에 대한 분류 및 대응을 진행하고 있다. 본 포스팅에서는 2022년 5월 30일 월요일부터 6월 5일 일요일까지 한 주간 수집된 악성코드의 통계를 정리한다. 대분류 상으로는 인포스틸러가 89.9%로 1위를 차지하였으며, 그 다음으로는 RAT (Remote Administration Tool) 악성코드가 8.5%, 랜섬웨어, 다운로더, 뱅킹 악성코드가 각각 0.5%로…
#ParsedReport
09-06-2022
Killnet: The Hactivist Group That Started A Global Cyber War
https://www.digitalshadows.com/blog-and-research/killnet-the-hactivist-group-that-started-a-global-cyber-war
Actors/Campaigns:
Killnet (tags: botnet, ddos, rat)
It_army
Ddosgung
Sakurajima
Kratos
Zarya
Threats:
Phoenix_keylogger
Mirai
Dns_amplification_technique
Industry:
Financial, Government
Geo:
Russian, Russia, Ukraine, Lithuania, Poland, Romanian, Estonia, Latvia, Italian, Germany, German, Italy, Romania
Functions Names: 1
09-06-2022
Killnet: The Hactivist Group That Started A Global Cyber War
https://www.digitalshadows.com/blog-and-research/killnet-the-hactivist-group-that-started-a-global-cyber-war
Actors/Campaigns:
Killnet (tags: botnet, ddos, rat)
It_army
Ddosgung
Sakurajima
Kratos
Zarya
Threats:
Phoenix_keylogger
Mirai
Dns_amplification_technique
Industry:
Financial, Government
Geo:
Russian, Russia, Ukraine, Lithuania, Poland, Romanian, Estonia, Latvia, Italian, Germany, German, Italy, Romania
Functions Names: 1
Digital Shadows
Killnet: The Hactivist Group That Started A Global Cyber War
We have observed an explosion in the number of distributed denial-of-service (DDoS), defacement, and data-leakage attack
#ParsedReport
09-06-2022
LockBit 2.0: How This RaaS Operates and How to Protect Against It
https://unit42.paloaltonetworks.com/lockbit-2-ransomware
Actors/Campaigns:
Darkside
Threats:
Lockbit (tags: stealer, rat, malware, spyware, ddos, ransomware, vpn, dns, scan, proxy, phishing)
Babuk
Revil
Conti
Blackcat
Avaddon
Suncrypt
Blackbyte
Cobalt_strike
Metasploit_tool
Proxyshell_vuln
Psexec_tool
Wevtutil_tool
Mimikatz
Minidump_tool
Grabchrome_tool
Grabrff_tool
Netscan_tool
Adfind_tool
Pchunter_tool
Beacon
Megasync_tool
Stealbit
Industry:
Healthcare, Education, Retail, Financial
Geo:
Latam, Russian, Japan, Japac, Germany, Apac, Italy, America, Emea
CVEs:
CVE-2021-20028 [Vulners]
Vulners: Score: 7.5, CVSS: 4.4,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Unavailable
Soft:
- sonicwall sma 210 firmware (<9.0.0.10)
- sonicwall sma 410 firmware (<9.0.0.10)
- sonicwall sma 500v firmware (<9.0.0.10)
CVE-2021-34523 [Vulners]
Vulners: Score: 7.5, CVSS: 6.4,
Vulners: Exploitation: True
X-Force: Risk: 9
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2013, 2016, 2016, 2019, 2019)
CVE-2020-0787 [Vulners]
Vulners: Score: 7.2, CVSS: 5.1,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (-, 1607, 1709, 1803, 1809, 1903, 1909)
- microsoft windows 7 (-)
- microsoft windows 8.1 (-)
- microsoft windows rt 8.1 (-)
- microsoft windows server 2008 (-, r2, r2)
have more...
CVE-2021-34473 [Vulners]
Vulners: Score: 10.0, CVSS: 6.4,
Vulners: Exploitation: True
X-Force: Risk: 9.1
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2013, 2016, 2016, 2019, 2019)
TTPs:
Tactics: 10
Technics: 27
09-06-2022
LockBit 2.0: How This RaaS Operates and How to Protect Against It
https://unit42.paloaltonetworks.com/lockbit-2-ransomware
Actors/Campaigns:
Darkside
Threats:
Lockbit (tags: stealer, rat, malware, spyware, ddos, ransomware, vpn, dns, scan, proxy, phishing)
Babuk
Revil
Conti
Blackcat
Avaddon
Suncrypt
Blackbyte
Cobalt_strike
Metasploit_tool
Proxyshell_vuln
Psexec_tool
Wevtutil_tool
Mimikatz
Minidump_tool
Grabchrome_tool
Grabrff_tool
Netscan_tool
Adfind_tool
Pchunter_tool
Beacon
Megasync_tool
Stealbit
Industry:
Healthcare, Education, Retail, Financial
Geo:
Latam, Russian, Japan, Japac, Germany, Apac, Italy, America, Emea
CVEs:
CVE-2021-20028 [Vulners]
Vulners: Score: 7.5, CVSS: 4.4,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Unavailable
Soft:
- sonicwall sma 210 firmware (<9.0.0.10)
- sonicwall sma 410 firmware (<9.0.0.10)
- sonicwall sma 500v firmware (<9.0.0.10)
CVE-2021-34523 [Vulners]
Vulners: Score: 7.5, CVSS: 6.4,
Vulners: Exploitation: True
X-Force: Risk: 9
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2013, 2016, 2016, 2019, 2019)
CVE-2020-0787 [Vulners]
Vulners: Score: 7.2, CVSS: 5.1,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (-, 1607, 1709, 1803, 1809, 1903, 1909)
- microsoft windows 7 (-)
- microsoft windows 8.1 (-)
- microsoft windows rt 8.1 (-)
- microsoft windows server 2008 (-, r2, r2)
have more...
CVE-2021-34473 [Vulners]
Vulners: Score: 10.0, CVSS: 6.4,
Vulners: Exploitation: True
X-Force: Risk: 9.1
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2013, 2016, 2016, 2019, 2019)
TTPs:
Tactics: 10
Technics: 27
Unit 42
LockBit 2.0: How This RaaS Operates and How to Protect Against It
LockBit 2.0 has so far been this year's most active ransomware gang on double-extortion leak sites. Learn about their tactics.
#ParsedReport
09-06-2022
Andariel Group, active only in Korea, for the past two years
https://www-ahnlab-com.translate.goog/kr/site/securityinfo/secunews/secuNewsView.do?seq=31890&menu_dist=2&cmd=scrap&_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Actors/Campaigns:
Lazarus (tags: malware, phishing, ransomware, keylogger)
Threats:
Gh0st_rat
Rifdoor
Phandoor
Tiger_downloader
Watering_hole_technique
Nukesped_rat
Tiger_rat
Geo:
Korea
IOCs:
File: 10
Functions Names: 1
09-06-2022
Andariel Group, active only in Korea, for the past two years
https://www-ahnlab-com.translate.goog/kr/site/securityinfo/secunews/secuNewsView.do?seq=31890&menu_dist=2&cmd=scrap&_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Actors/Campaigns:
Lazarus (tags: malware, phishing, ransomware, keylogger)
Threats:
Gh0st_rat
Rifdoor
Phandoor
Tiger_downloader
Watering_hole_technique
Nukesped_rat
Tiger_rat
Geo:
Korea
IOCs:
File: 10
Functions Names: 1
www-ahnlab-com.translate.goog
보안 이슈 | AhnLab
안랩이 최신 IT 및 보안 이슈를 알기 쉽게 풀어드립니다.
#ParsedReport
09-06-2022
eSentire Threat Intelligence Malware Analysis: Purple Fox
https://www.esentire.com/blog/esentire-threat-intelligence-malware-analysis-purple-fox
Threats:
Purplefox (tags: malware, rat, rootkit, proxy, dns, scan, phishing)
Rig_tool (tags: malware)
Lolbin
Hot_potato_technique
Tater_exploit
Geo:
Chinese, Africa, Apac, America, Emea
CVEs:
CVE-2018-8120 [Vulners]
Vulners: Score: 7.2, CVSS: 7.3,
Vulners: Exploitation: True
X-Force: Risk: 7
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2, -, r2)
- microsoft windows 7 (-)
CVE-2021-1675 [Vulners]
Vulners: Score: 9.3, CVSS: 3.2,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2, -)
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 20h2, 21h1, 1809, 1909, 2004)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
have more...
CVE-2015-1701 [Vulners]
Vulners: Score: 7.2, CVSS: 7.1,
Vulners: Exploitation: True
X-Force: Risk: 6.8
X-Force: Patch: Official fix
Soft:
- microsoft windows vista (*)
- microsoft windows 2003 server (*)
- microsoft windows server 2008 (-)
- microsoft windows 7 (le-, le-)
CVE-2020-0674 [Vulners]
Vulners: Score: 7.6, CVSS: 6.2,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Workaround
Soft:
- microsoft internet explorer (9, 10, 11)
CVE-2019-0808 [Vulners]
Vulners: Score: 7.2, CVSS: 6.2,
Vulners: Exploitation: True
X-Force: Risk: 7
X-Force: Patch: Official fix
Soft:
- microsoft windows 7 (sp1)
- microsoft windows server 2008 (r2, r2, -)
IOCs:
File: 10
Registry: 4
Path: 21
IP: 39
Domain: 1
Hash: 6
Url: 1
YARA: Found
Links:
09-06-2022
eSentire Threat Intelligence Malware Analysis: Purple Fox
https://www.esentire.com/blog/esentire-threat-intelligence-malware-analysis-purple-fox
Threats:
Purplefox (tags: malware, rat, rootkit, proxy, dns, scan, phishing)
Rig_tool (tags: malware)
Lolbin
Hot_potato_technique
Tater_exploit
Geo:
Chinese, Africa, Apac, America, Emea
CVEs:
CVE-2018-8120 [Vulners]
Vulners: Score: 7.2, CVSS: 7.3,
Vulners: Exploitation: True
X-Force: Risk: 7
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2, -, r2)
- microsoft windows 7 (-)
CVE-2021-1675 [Vulners]
Vulners: Score: 9.3, CVSS: 3.2,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2, -)
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 20h2, 21h1, 1809, 1909, 2004)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
have more...
CVE-2015-1701 [Vulners]
Vulners: Score: 7.2, CVSS: 7.1,
Vulners: Exploitation: True
X-Force: Risk: 6.8
X-Force: Patch: Official fix
Soft:
- microsoft windows vista (*)
- microsoft windows 2003 server (*)
- microsoft windows server 2008 (-)
- microsoft windows 7 (le-, le-)
CVE-2020-0674 [Vulners]
Vulners: Score: 7.6, CVSS: 6.2,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Workaround
Soft:
- microsoft internet explorer (9, 10, 11)
CVE-2019-0808 [Vulners]
Vulners: Score: 7.2, CVSS: 6.2,
Vulners: Exploitation: True
X-Force: Risk: 7
X-Force: Patch: Official fix
Soft:
- microsoft windows 7 (sp1)
- microsoft windows server 2008 (r2, r2, -)
IOCs:
File: 10
Registry: 4
Path: 21
IP: 39
Domain: 1
Hash: 6
Url: 1
YARA: Found
Links:
https://github.com/Kevin-Robertson/Taterhttps://github.com/k8gege/K8toolseSentire
eSentire Threat Intelligence Malware Analysis: Purple Fox
Dive deeper into the technical details gathered during eSentire’s Threat Response Unit (TRU) team’s research and threat analysis of the Purple Fox malware.
#ParsedReport
10-06-2022
Lyceum .NET DNSBackdoor. Key Features of this attack:
https://www.zscaler.com/blogs/security-research/lyceum-net-dns-backdoor
Actors/Campaigns:
Siamesekitten (tags: dns, backdoor, malware)
Threats:
Dnsbackdoor (tags: dns, backdoor, malware)
Industry:
Energy, Telco
Geo:
Iran, Iranian
TTPs:
Tactics: 1
Technics: 7
IOCs:
File: 5
Url: 5
Hash: 2
Domain: 1
IP: 2
Functions Names: 6
10-06-2022
Lyceum .NET DNSBackdoor. Key Features of this attack:
https://www.zscaler.com/blogs/security-research/lyceum-net-dns-backdoor
Actors/Campaigns:
Siamesekitten (tags: dns, backdoor, malware)
Threats:
Dnsbackdoor (tags: dns, backdoor, malware)
Industry:
Energy, Telco
Geo:
Iran, Iranian
TTPs:
Tactics: 1
Technics: 7
IOCs:
File: 5
Url: 5
Hash: 2
Domain: 1
IP: 2
Functions Names: 6
Zscaler
Lyceum .NET DNS Backdoor | Zscaler
The Lyceum APT group is targeting Middle East organizations with DNS hijacking attack using a new .NET-based malware.
#ParsedReport
10-06-2022
Bumblebee Loader Linked to Conti and Used In Quantum Locker Attacks
https://www.kroll.com/en/insights/publications/cyber/bumblebee-loader-linked-conti-used-in-quantum-locker-attacks
Actors/Campaigns:
Exotic_lily
Ta578
Ta579
Threats:
Quantum_locker (tags: spam, phishing, trojan, malware, ransomware)
Bumblebee (tags: spam, phishing, trojan, malware, ransomware)
Conti (tags: spam, phishing, trojan, malware, ransomware)
Cobalt_strike
Emotet
Icedid
Ryuk
Gozi
Meterpreter_tool
Sliver_tool
Bazarbackdoor
Industry:
Healthcare
CVEs:
CVE-2021-40444 [Vulners]
Vulners: Score: 6.8, CVSS: 2.1,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2, -)
- microsoft windows 10 (1607, -, 1809, 1909, 2004, 20h2, 21h1)
- microsoft windows server 2016 (-, 2004, 20h2)
- microsoft windows rt 8.1 (-)
- microsoft windows server 2012 (-, -)
have more...
Links:
10-06-2022
Bumblebee Loader Linked to Conti and Used In Quantum Locker Attacks
https://www.kroll.com/en/insights/publications/cyber/bumblebee-loader-linked-conti-used-in-quantum-locker-attacks
Actors/Campaigns:
Exotic_lily
Ta578
Ta579
Threats:
Quantum_locker (tags: spam, phishing, trojan, malware, ransomware)
Bumblebee (tags: spam, phishing, trojan, malware, ransomware)
Conti (tags: spam, phishing, trojan, malware, ransomware)
Cobalt_strike
Emotet
Icedid
Ryuk
Gozi
Meterpreter_tool
Sliver_tool
Bazarbackdoor
Industry:
Healthcare
CVEs:
CVE-2021-40444 [Vulners]
Vulners: Score: 6.8, CVSS: 2.1,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2, -)
- microsoft windows 10 (1607, -, 1809, 1909, 2004, 20h2, 21h1)
- microsoft windows server 2016 (-, 2004, 20h2)
- microsoft windows rt 8.1 (-)
- microsoft windows server 2012 (-, -)
have more...
Links:
https://github.com/LordNoteworthy/al-khaser/tree/06d4a89e9ecc3e49e4d2df67fe0b2d6faf04166eKroll
Bumblebee Loader Linked to Conti and Used In Quantum Locker Attacks | Kroll
Kroll has recently observed a new malware strain called “Bumblebee” operating as a loader, delivered via phishing email, in order to deploy additional payloads for use in ransomware operations. Read more.
#ParsedReport
10-06-2022
Smilodon Credit Card Skimming Malware Shifts to WordPress
https://blog.sucuri.net/2022/06/smilodon-credit-card-skimming-malware-shifts-to-wordpress.html
Actors/Campaigns:
Magecart (tags: malware)
Threats:
Megalodon (tags: malware, rat, backdoor)
Industry:
E-commerce, Financial
IOCs:
Domain: 3
Functions Names: 1
10-06-2022
Smilodon Credit Card Skimming Malware Shifts to WordPress
https://blog.sucuri.net/2022/06/smilodon-credit-card-skimming-malware-shifts-to-wordpress.html
Actors/Campaigns:
Magecart (tags: malware)
Threats:
Megalodon (tags: malware, rat, backdoor)
Industry:
E-commerce, Financial
IOCs:
Domain: 3
Functions Names: 1
Sucuri Blog
Smilodon Credit Card Skimming Malware Shifts to WordPress
WordPress’ massive market share has come with an unsurprising side effect: As more and more site admins turn to popular plugins like WooCommerce to turn…
#ParsedReport
10-06-2022
BAT (//)
https://asec-ahnlab-com.translate.goog/ko/35189/?_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Actors/Campaigns:
Kimsuky
IOCs:
File: 6
Hash: 13
10-06-2022
BAT (//)
https://asec-ahnlab-com.translate.goog/ko/35189/?_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Actors/Campaigns:
Kimsuky
IOCs:
File: 6
Hash: 13
ASEC BLOG
활발하게 유포 중인 BAT 스크립트 포함한 악성 한글문서 (북한/국방/방송) - ASEC BLOG
ASEC 분석팀은 한글 문서의 정상 기능(OLE 개체 연결 삽입)을 악용하는 APT 문서가 최근 활발하게 유포 중임을 확인하였다. 지난 3월 3일 소개한 “20대 대통령선거 선상투표 보도자료 가장한 악성 한글문서 유포” 사례 이후로 공격자는 국방, 대북, 방송 관계자들을 대상으로 지속적으로 악성 한글 문서를 유포하고있다. 악성 한글 문서의 동작 방식은 한글 문서 안에 삽입된 OLE 개체(배치파일)가 실행되고, 이후 파워쉘을 통해 쉘코드를 정상 프로세스에…
#ParsedReport
10-06-2022
Back From the Dead, Emotet Returns in 2022
https://www.deepinstinct.com/blog/emotet-malware-returns-in-2022
Actors/Campaigns:
Wizard_spider (tags: malware)
Threats:
Emotet (tags: malware, botnet, rat, phishing, trojan, ransomware)
Conti
Ryuk
Trickbot (tags: malware)
Qakbot
Chaos (tags: phishing, malware)
Industry:
Financial
Geo:
Japanese, Netherlands
CVEs:
CVE-2017-11882 [Vulners]
Vulners: Score: 9.3, CVSS: 8.3,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2013, 2010, 2016, 2007)
10-06-2022
Back From the Dead, Emotet Returns in 2022
https://www.deepinstinct.com/blog/emotet-malware-returns-in-2022
Actors/Campaigns:
Wizard_spider (tags: malware)
Threats:
Emotet (tags: malware, botnet, rat, phishing, trojan, ransomware)
Conti
Ryuk
Trickbot (tags: malware)
Qakbot
Chaos (tags: phishing, malware)
Industry:
Financial
Geo:
Japanese, Netherlands
CVEs:
CVE-2017-11882 [Vulners]
Vulners: Score: 9.3, CVSS: 8.3,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2013, 2010, 2016, 2007)
Deep Instinct
Emotet Malware Returns in 2022 | Deep Instinct
Emotet malware has returned with a vengeance in 2022. How dangerous are new emotet variants? Learn more about the newest Emotet threats & how Deep Instinct can help.
#ParsedReport
10-06-2022
SANS ISC: InfoSec Handlers Diary Blog - SANS Internet Storm Center SANS Site Network Current Site SANS Internet Storm Center Other SANS Sites Help Graduate Degree Programs Security Training Security Certification Security Awareness Training Penetration Testing Industrial Control Systems Cyber Defense Foundations DFIR Software Security Government OnSite Training InfoSec Handlers Diary Blog
https://isc.sans.edu/diary/rss/28728
Actors/Campaigns:
Ta570 (tags: spam, malware)
Threats:
Qakbot (tags: spam, malware)
Follina_vuln (tags: spam, malware)
Industry:
Government
CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...
IOCs:
File: 59
Hash: 49
Path: 1
Url: 4
10-06-2022
SANS ISC: InfoSec Handlers Diary Blog - SANS Internet Storm Center SANS Site Network Current Site SANS Internet Storm Center Other SANS Sites Help Graduate Degree Programs Security Training Security Certification Security Awareness Training Penetration Testing Industrial Control Systems Cyber Defense Foundations DFIR Software Security Government OnSite Training InfoSec Handlers Diary Blog
https://isc.sans.edu/diary/rss/28728
Actors/Campaigns:
Ta570 (tags: spam, malware)
Threats:
Qakbot (tags: spam, malware)
Follina_vuln (tags: spam, malware)
Industry:
Government
CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...
IOCs:
File: 59
Hash: 49
Path: 1
Url: 4
SANS Internet Storm Center
InfoSec Handlers Diary Blog - SANS Internet Storm Center
Internet Storm Center Diary 2022-09-13, Author: Johannes Ullrich
#ParsedReport
10-06-2022
Phishing Campaigns featuring Ursnif Trojan on the Rise
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/phishing-campaigns-featuring-ursnif-trojan/?&web_view=true
Threats:
Gozi (tags: spam, rat, trojan, phishing, malware)
Dexter
Emotet
Hancitor
Ficker_stealer
TTPs:
Tactics: 3
Technics: 4
IOCs:
File: 4
Url: 1
Hash: 2
Functions Names: 2
10-06-2022
Phishing Campaigns featuring Ursnif Trojan on the Rise
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/phishing-campaigns-featuring-ursnif-trojan/?&web_view=true
Threats:
Gozi (tags: spam, rat, trojan, phishing, malware)
Dexter
Emotet
Hancitor
Ficker_stealer
TTPs:
Tactics: 3
Technics: 4
IOCs:
File: 4
Url: 1
Hash: 2
Functions Names: 2
McAfee Blog
Phishing Campaigns featuring Ursnif Trojan on the Rise | McAfee Blog
Authored by Jyothi Naveen and Kiran Raj McAfee Labs have been observing a spike in phishing campaigns that utilize Microsoft office macro capabilities.
#ParsedReport
10-06-2022
Instagram credentials Stealers: Free Followers or Free Likes
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/instagram-credentials-stealers-free-followers-or-free-likes
Threats:
Dexter
Emotet
Hancitor
Ficker_stealer
Geo:
Turkey, Portuguese
IOCs:
Hash: 2
10-06-2022
Instagram credentials Stealers: Free Followers or Free Likes
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/instagram-credentials-stealers-free-followers-or-free-likes
Threats:
Dexter
Emotet
Hancitor
Ficker_stealer
Geo:
Turkey, Portuguese
IOCs:
Hash: 2
McAfee Blog
Instagram credentials Stealers: Free Followers or Free Likes | McAfee Blog
Authored by Dexter Shin Instagram has become a platform with over a billion monthly active users. Many of Instagram's users are looking to increase their