#ParsedReport
10-06-2022
BAT (//)
https://asec-ahnlab-com.translate.goog/ko/35189/?_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Actors/Campaigns:
Kimsuky
IOCs:
File: 6
Hash: 13
10-06-2022
BAT (//)
https://asec-ahnlab-com.translate.goog/ko/35189/?_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Actors/Campaigns:
Kimsuky
IOCs:
File: 6
Hash: 13
ASEC BLOG
활발하게 유포 중인 BAT 스크립트 포함한 악성 한글문서 (북한/국방/방송) - ASEC BLOG
ASEC 분석팀은 한글 문서의 정상 기능(OLE 개체 연결 삽입)을 악용하는 APT 문서가 최근 활발하게 유포 중임을 확인하였다. 지난 3월 3일 소개한 “20대 대통령선거 선상투표 보도자료 가장한 악성 한글문서 유포” 사례 이후로 공격자는 국방, 대북, 방송 관계자들을 대상으로 지속적으로 악성 한글 문서를 유포하고있다. 악성 한글 문서의 동작 방식은 한글 문서 안에 삽입된 OLE 개체(배치파일)가 실행되고, 이후 파워쉘을 통해 쉘코드를 정상 프로세스에…
#ParsedReport
10-06-2022
Back From the Dead, Emotet Returns in 2022
https://www.deepinstinct.com/blog/emotet-malware-returns-in-2022
Actors/Campaigns:
Wizard_spider (tags: malware)
Threats:
Emotet (tags: malware, botnet, rat, phishing, trojan, ransomware)
Conti
Ryuk
Trickbot (tags: malware)
Qakbot
Chaos (tags: phishing, malware)
Industry:
Financial
Geo:
Japanese, Netherlands
CVEs:
CVE-2017-11882 [Vulners]
Vulners: Score: 9.3, CVSS: 8.3,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2013, 2010, 2016, 2007)
10-06-2022
Back From the Dead, Emotet Returns in 2022
https://www.deepinstinct.com/blog/emotet-malware-returns-in-2022
Actors/Campaigns:
Wizard_spider (tags: malware)
Threats:
Emotet (tags: malware, botnet, rat, phishing, trojan, ransomware)
Conti
Ryuk
Trickbot (tags: malware)
Qakbot
Chaos (tags: phishing, malware)
Industry:
Financial
Geo:
Japanese, Netherlands
CVEs:
CVE-2017-11882 [Vulners]
Vulners: Score: 9.3, CVSS: 8.3,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2013, 2010, 2016, 2007)
Deep Instinct
Emotet Malware Returns in 2022 | Deep Instinct
Emotet malware has returned with a vengeance in 2022. How dangerous are new emotet variants? Learn more about the newest Emotet threats & how Deep Instinct can help.
#ParsedReport
10-06-2022
SANS ISC: InfoSec Handlers Diary Blog - SANS Internet Storm Center SANS Site Network Current Site SANS Internet Storm Center Other SANS Sites Help Graduate Degree Programs Security Training Security Certification Security Awareness Training Penetration Testing Industrial Control Systems Cyber Defense Foundations DFIR Software Security Government OnSite Training InfoSec Handlers Diary Blog
https://isc.sans.edu/diary/rss/28728
Actors/Campaigns:
Ta570 (tags: spam, malware)
Threats:
Qakbot (tags: spam, malware)
Follina_vuln (tags: spam, malware)
Industry:
Government
CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...
IOCs:
File: 59
Hash: 49
Path: 1
Url: 4
10-06-2022
SANS ISC: InfoSec Handlers Diary Blog - SANS Internet Storm Center SANS Site Network Current Site SANS Internet Storm Center Other SANS Sites Help Graduate Degree Programs Security Training Security Certification Security Awareness Training Penetration Testing Industrial Control Systems Cyber Defense Foundations DFIR Software Security Government OnSite Training InfoSec Handlers Diary Blog
https://isc.sans.edu/diary/rss/28728
Actors/Campaigns:
Ta570 (tags: spam, malware)
Threats:
Qakbot (tags: spam, malware)
Follina_vuln (tags: spam, malware)
Industry:
Government
CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...
IOCs:
File: 59
Hash: 49
Path: 1
Url: 4
SANS Internet Storm Center
InfoSec Handlers Diary Blog - SANS Internet Storm Center
Internet Storm Center Diary 2022-09-13, Author: Johannes Ullrich
#ParsedReport
10-06-2022
Phishing Campaigns featuring Ursnif Trojan on the Rise
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/phishing-campaigns-featuring-ursnif-trojan/?&web_view=true
Threats:
Gozi (tags: spam, rat, trojan, phishing, malware)
Dexter
Emotet
Hancitor
Ficker_stealer
TTPs:
Tactics: 3
Technics: 4
IOCs:
File: 4
Url: 1
Hash: 2
Functions Names: 2
10-06-2022
Phishing Campaigns featuring Ursnif Trojan on the Rise
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/phishing-campaigns-featuring-ursnif-trojan/?&web_view=true
Threats:
Gozi (tags: spam, rat, trojan, phishing, malware)
Dexter
Emotet
Hancitor
Ficker_stealer
TTPs:
Tactics: 3
Technics: 4
IOCs:
File: 4
Url: 1
Hash: 2
Functions Names: 2
McAfee Blog
Phishing Campaigns featuring Ursnif Trojan on the Rise | McAfee Blog
Authored by Jyothi Naveen and Kiran Raj McAfee Labs have been observing a spike in phishing campaigns that utilize Microsoft office macro capabilities.
#ParsedReport
10-06-2022
Instagram credentials Stealers: Free Followers or Free Likes
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/instagram-credentials-stealers-free-followers-or-free-likes
Threats:
Dexter
Emotet
Hancitor
Ficker_stealer
Geo:
Turkey, Portuguese
IOCs:
Hash: 2
10-06-2022
Instagram credentials Stealers: Free Followers or Free Likes
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/instagram-credentials-stealers-free-followers-or-free-likes
Threats:
Dexter
Emotet
Hancitor
Ficker_stealer
Geo:
Turkey, Portuguese
IOCs:
Hash: 2
McAfee Blog
Instagram credentials Stealers: Free Followers or Free Likes | McAfee Blog
Authored by Dexter Shin Instagram has become a platform with over a billion monthly active users. Many of Instagram's users are looking to increase their
#ParsedReport
10-06-2022
Instagram credentials Stealer: Disguised as Mod App
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/instagram-credentials-stealer-disguised-as-mod-app
Threats:
Dexter (tags: stealer)
Emotet
Hancitor
Ficker_stealer
IOCs:
Email: 1
Hash: 1
10-06-2022
Instagram credentials Stealer: Disguised as Mod App
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/instagram-credentials-stealer-disguised-as-mod-app
Threats:
Dexter (tags: stealer)
Emotet
Hancitor
Ficker_stealer
IOCs:
Email: 1
Hash: 1
McAfee Blog
Instagram credentials Stealer: Disguised as Mod App | McAfee Blog
Authored by Dexter Shin McAfee’s Mobile Research Team introduced a new Android malware targeting Instagram users who want to increase their followers or
#ParsedReport
10-06-2022
Yashma Ransomware Report
https://www.cyfirma.com/outofband/yashma-ransomware-report
Threats:
Yashma (tags: ddos, malware, ransomware, spam, phishing, rat)
Chaos (tags: ransomware)
Geo:
Turkey, Azerbaijan
TTPs:
Tactics: 6
Technics: 12
IOCs:
File: 2
Hash: 1
10-06-2022
Yashma Ransomware Report
https://www.cyfirma.com/outofband/yashma-ransomware-report
Threats:
Yashma (tags: ddos, malware, ransomware, spam, phishing, rat)
Chaos (tags: ransomware)
Geo:
Turkey, Azerbaijan
TTPs:
Tactics: 6
Technics: 12
IOCs:
File: 2
Hash: 1
CYFIRMA
Yashma Ransomware Report - CYFIRMA
Yashma Ransomware Report Executive Summary: Yashma is a new ransomware seen in the wild since May 2022. This ransomware is...
#technique
PACMAN is a new attack technique demonstrated against Apple M1 processor chipsets that could be used to hack macOS systems.
https://securityaffairs.co/wordpress/132154/hacking/pacman-attack-apple-m1-cpus.html
PACMAN is a new attack technique demonstrated against Apple M1 processor chipsets that could be used to hack macOS systems.
https://securityaffairs.co/wordpress/132154/hacking/pacman-attack-apple-m1-cpus.html
Security Affairs
PACMAN, a new attack technique against Apple M1 CPUs
PACMAN is a new attack technique demonstrated against Apple M1 processor chipsets that could be used to hack macOS systems.
#ParsedReport
12-06-2022
Confluence servers hacked to deploy AvosLocker, Cerber2021 ransomware
https://www.bleepingcomputer.com/news/security/confluence-servers-hacked-to-deploy-avoslocker-cerber2021-ransomware
Threats:
Avoslocker (tags: scan, ransomware, cryptomining, malware, botnet, rat)
Cerberimposter (tags: ransomware, botnet, cryptomining, malware, scan, rat)
Cerber (tags: ransomware)
Geo:
Australia
CVEs:
CVE-2022-26134 [Vulners]
Vulners: Score: Unknown, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
CVE-2021-26084 [Vulners]
Vulners: Score: 7.5, CVSS: 7.3,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- atlassian confluence server (<7.12.5, <7.4.11, <7.11.6, <6.13.23)
- atlassian confluence data center (<7.12.5, <7.11.6, <7.4.11, <6.13.23)
12-06-2022
Confluence servers hacked to deploy AvosLocker, Cerber2021 ransomware
https://www.bleepingcomputer.com/news/security/confluence-servers-hacked-to-deploy-avoslocker-cerber2021-ransomware
Threats:
Avoslocker (tags: scan, ransomware, cryptomining, malware, botnet, rat)
Cerberimposter (tags: ransomware, botnet, cryptomining, malware, scan, rat)
Cerber (tags: ransomware)
Geo:
Australia
CVEs:
CVE-2022-26134 [Vulners]
Vulners: Score: Unknown, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
CVE-2021-26084 [Vulners]
Vulners: Score: 7.5, CVSS: 7.3,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- atlassian confluence server (<7.12.5, <7.4.11, <7.11.6, <6.13.23)
- atlassian confluence data center (<7.12.5, <7.11.6, <7.4.11, <6.13.23)
BleepingComputer
Confluence servers hacked to deploy AvosLocker, Cerber2021 ransomware
Ransomware gangs are now targeting a recently patched and actively exploited remote code execution (RCE) vulnerability affecting Atlassian Confluence Server and Data Center instances for initial access to corporate networks.
#ParsedReport
12-06-2022
Exposing HelloXD Ransomware and x4k
https://unit42.paloaltonetworks.com/helloxd-ransomware
Actors/Campaigns:
Lapsus (tags: ransomware)
Threats:
Helloxd (tags: malware, backdoor, ddos, dns, ransomware, rat)
Babuk (tags: ransomware)
Microbackdoor (tags: ransomware)
Cobalt_strike (tags: ransomware)
Beacon (tags: ransomware)
Lockbit (tags: malware, ransomware)
Industry:
Financial
Geo:
Apac, Emea, Japan, America, Russia, Russian
TTPs:
Tactics: 1
Technics: 0
IOCs:
IP: 7
File: 3
Hash: 59
Email: 1
Domain: 56
Links:
12-06-2022
Exposing HelloXD Ransomware and x4k
https://unit42.paloaltonetworks.com/helloxd-ransomware
Actors/Campaigns:
Lapsus (tags: ransomware)
Threats:
Helloxd (tags: malware, backdoor, ddos, dns, ransomware, rat)
Babuk (tags: ransomware)
Microbackdoor (tags: ransomware)
Cobalt_strike (tags: ransomware)
Beacon (tags: ransomware)
Lockbit (tags: malware, ransomware)
Industry:
Financial
Geo:
Apac, Emea, Japan, America, Russia, Russian
TTPs:
Tactics: 1
Technics: 0
IOCs:
IP: 7
File: 3
Hash: 59
Email: 1
Domain: 56
Links:
https://github.com/l4ckyguyhttps://github.com/byt3bl33d3r/OffensiveNim/blob/master/src/self\_delete\_bin.nimhttps://github.com/l4cky-controlhttps://github.com/x4kmehttps://github.com/vbdaga/Rabbit-CipherUnit 42
Exposing HelloXD Ransomware and x4k
HelloXD is a ransomware family in its initial stages – but already seeking to impact organizations. We analyze samples and hunt for attribution.
#ParsedReport
12-06-2022
Smilodon Credit Card Skimming Malware Shifts to WordPress
https://blog.sucuri.net/2022/06/smilodon-credit-card-skimming-malware-shifts-to-wordpress.html
Actors/Campaigns:
Magecart (tags: malware)
Threats:
Megalodon (tags: rat, backdoor, malware)
Industry:
E-commerce, Financial
IOCs:
Domain: 3
Functions Names: 1
12-06-2022
Smilodon Credit Card Skimming Malware Shifts to WordPress
https://blog.sucuri.net/2022/06/smilodon-credit-card-skimming-malware-shifts-to-wordpress.html
Actors/Campaigns:
Magecart (tags: malware)
Threats:
Megalodon (tags: rat, backdoor, malware)
Industry:
E-commerce, Financial
IOCs:
Domain: 3
Functions Names: 1
Sucuri Blog
Smilodon Credit Card Skimming Malware Shifts to WordPress
WordPress’ massive market share has come with an unsurprising side effect: As more and more site admins turn to popular plugins like WooCommerce to turn…
#ParsedReport
13-06-2022
Hydra Android Malware Distributed Via Play Store. Fake Document Manager App Downloading Hydra Banking Trojan
https://blog.cyble.com/2022/06/13/hydra-android-malware-distributed-via-play-store
Threats:
Hydra (tags: malware, trojan, phishing, proxy)
Industry:
Financial
Geo:
Colombia
TTPs:
Tactics: 6
Technics: 2
IOCs:
Url: 6
File: 2
Hash: 2
13-06-2022
Hydra Android Malware Distributed Via Play Store. Fake Document Manager App Downloading Hydra Banking Trojan
https://blog.cyble.com/2022/06/13/hydra-android-malware-distributed-via-play-store
Threats:
Hydra (tags: malware, trojan, phishing, proxy)
Industry:
Financial
Geo:
Colombia
TTPs:
Tactics: 6
Technics: 2
IOCs:
Url: 6
File: 2
Hash: 2
Cyble
Cyble - Fake Document Manager App Downloading Hydra Banking Trojan
Cyble analyzes a resurfaced version of Hydra malware distributed via a fake Document Manager app on the Play Store.
#ParsedReport
13-06-2022
Technical Analysis of PureCrypter: A Fully-Functional Loader Distributing Remote Access Trojans and Information Stealers. Key points
https://www.zscaler.com/blogs/security-research/technical-analysis-purecrypter
Threats:
Purecrypter (tags: ransomware, malware, stealer, rat)
Binder
Agent_tesla
Arkei_stealer
Asyncrat_rat
Azorult
Dcrat_rat
Nanocore_rat
Redline_stealer
Remcos_rat
Snake_keylogger
Avemaria_rat
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 57
File: 13
Url: 17
Registry: 4
Path: 1
Functions Names: 4
13-06-2022
Technical Analysis of PureCrypter: A Fully-Functional Loader Distributing Remote Access Trojans and Information Stealers. Key points
https://www.zscaler.com/blogs/security-research/technical-analysis-purecrypter
Threats:
Purecrypter (tags: ransomware, malware, stealer, rat)
Binder
Agent_tesla
Arkei_stealer
Asyncrat_rat
Azorult
Dcrat_rat
Nanocore_rat
Redline_stealer
Remcos_rat
Snake_keylogger
Avemaria_rat
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 57
File: 13
Url: 17
Registry: 4
Path: 1
Functions Names: 4
Zscaler
Technical Analysis of PureCrypter | Zscaler Blog
Technical Analysis of PureCrypter: A Fully-Functional Loader Distributing Remote Access Trojans and Information Stealers
#ParsedReport
13-06-2022
Industroyer: A cyberweapon that brought down a power grid
https://www.welivesecurity.com/2022/06/13/industroyer-cyber-weapon-brought-down-power-grid
Actors/Campaigns:
Sandworm (tags: malware)
Threats:
Crashoverride (tags: malware, rat)
Blackout
Industry:
Petroleum, Energy, Healthcare
Geo:
Ukrainian, Ukraine
13-06-2022
Industroyer: A cyberweapon that brought down a power grid
https://www.welivesecurity.com/2022/06/13/industroyer-cyber-weapon-brought-down-power-grid
Actors/Campaigns:
Sandworm (tags: malware)
Threats:
Crashoverride (tags: malware, rat)
Blackout
Industry:
Petroleum, Energy, Healthcare
Geo:
Ukrainian, Ukraine
WeLiveSecurity
Industroyer: A cyber‑weapon that brought down a power grid
It's been five years since ESET researchers released their analysis of the first ever malware that was designed specifically to attack power grids.
#ParsedReport
13-06-2022
GALLIUM Expands Targeting Across Telecommunications, Government and Finance Sectors With New PingPull Tool
https://unit42.paloaltonetworks.com/pingpull-gallium
Actors/Campaigns:
Gallium (tags: dns, trojan, backdoor, malware, rat)
Soft_cell
Threats:
Pingpull (tags: proxy, dns, trojan, backdoor, malware, rat)
Timestomp_tool (tags: malware)
Beacon (tags: malware)
Industry:
Government, Financial, Telco
Geo:
Apac, Asia, Australia, Japanese, Russia, America, Emea, Afghanistan, Mozambique, Malaysia, Philippines, Australian, Cambodia, Vietnam, Belgium, Japan, Africa, Chinese
IOCs:
File: 5
IP: 130
Hash: 8
Domain: 13
13-06-2022
GALLIUM Expands Targeting Across Telecommunications, Government and Finance Sectors With New PingPull Tool
https://unit42.paloaltonetworks.com/pingpull-gallium
Actors/Campaigns:
Gallium (tags: dns, trojan, backdoor, malware, rat)
Soft_cell
Threats:
Pingpull (tags: proxy, dns, trojan, backdoor, malware, rat)
Timestomp_tool (tags: malware)
Beacon (tags: malware)
Industry:
Government, Financial, Telco
Geo:
Apac, Asia, Australia, Japanese, Russia, America, Emea, Afghanistan, Mozambique, Malaysia, Philippines, Australian, Cambodia, Vietnam, Belgium, Japan, Africa, Chinese
IOCs:
File: 5
IP: 130
Hash: 8
Domain: 13
Unit 42
GALLIUM Expands Targeting Across Telecommunications, Government and Finance Sectors With New PingPull Tool
A new, difficult-to-detect remote access trojan named PingPull is being used by GALLIUM, an advanced persistent threat (APT) group.
#ParsedReport
13-06-2022
Linux Threat Hunting: Syslogk a kernel rootkit found under development in the wild. Introduction
https://decoded.avast.io/davidalvarez/linux-threat-hunting-syslogk-a-kernel-rootkit-found-under-development-in-the-wild/?utm_source=rss&utm_medium=rss&utm_campaign=linux-threat-hunting-syslogk-a-kernel-rootkit-found-under-development-in-the-wild
Threats:
Syslogk_rootkit (tags: backdoor, rootkit, malware, rat, trojan, scan)
Adoreng_rootkit (tags: rootkit)
Rekoobe_rootkit (tags: rootkit, backdoor, malware, rat)
Netstat_tool
IOCs:
File: 1
Hash: 71
Functions Names: 2
Links:
13-06-2022
Linux Threat Hunting: Syslogk a kernel rootkit found under development in the wild. Introduction
https://decoded.avast.io/davidalvarez/linux-threat-hunting-syslogk-a-kernel-rootkit-found-under-development-in-the-wild/?utm_source=rss&utm_medium=rss&utm_campaign=linux-threat-hunting-syslogk-a-kernel-rootkit-found-under-development-in-the-wild
Threats:
Syslogk_rootkit (tags: backdoor, rootkit, malware, rat, trojan, scan)
Adoreng_rootkit (tags: rootkit)
Rekoobe_rootkit (tags: rootkit, backdoor, malware, rat)
Netstat_tool
IOCs:
File: 1
Hash: 71
Functions Names: 2
Links:
https://github.com/yaoyumeng/adore-ng/blob/master/adore-ng.c#L178
https://github.com/yaoyumeng/adore-ng/blob/master/adore-ng.c#L193
https://github.com/yaoyumeng/adore-ng/blob/522c80a2dc043c2d523256472becc88c90d66337/adore-ng.c#L835
https://github.com/ksaravan910/FileCloakingRootkit/blob/master/rootkit.c#L81
https://github.com/avast/ioc/tree/master/SyslogkRootkit
https://github.com/milabs/kmod\_hooking/blob/master/module-init.c#L237
https://github.com/vmt/udis86
https://github.com/creaktive/tsh/blob/master/tshd.c#L693
https://github.com/yaoyumeng/adore-ng/blob/master/adore-ng.c#L688
https://github.com/avast/ioc/blob/master/SyslogkRootkit/Research%20Tools/magic\_packet\_start\_rekoobe.py
https://github.com/ksaravan910/FileCloakingRootkit/blob/master/rootkit.c#L64
https://github.com/avast/ioc/blob/master/SyslogkRootkit/Research%20Tools/cert.pem
https://github.com/avast/ioc/blob/master/SyslogkRootkit/Research%20Tools/unhide\_rootkit.c
https://github.com/avast/ioc/blob/master/SyslogkRootkit/Research%20Tools/magic\_packet\_kill\_rekoobe.py
https://github.com/avast/ioc/blob/master/SyslogkRootkit/Research%20Tools/remove\_syslogk\_from\_memory.sh
https://github.com/torvalds/linux/blob/master/include/linux/fs.h#L956
https://github.com/yaoyumeng/adore-ng/blob/master/adore-ng.c#L697
https://github.com/yaoyumeng/adore-ng/blob/master/adore-ng.c#L300
https://github.com/yaoyumeng/adore-ng/blob/522c80a2dc043c2d523256472becc88c90d66337/adore-ng.c#L662
https://github.com/avast/ioc/blob/master/SyslogkRootkit/Research%20Tools/rekoobe\_backdoor\_client.py
https://github.com/yaoyumeng/adore-ng
https://github.com/torvalds/linux/blob/master/net/ipv4/tcp\_ipv4.c#L2695
https://github.com/torvalds/linux/blob/master/include/linux/fs.h#L939Gendigital
Linux Threat Hunting: ‘Syslogk’ a kernel rootkit found under development in the wild
Syslogk Rootkit Revealed: Analysis
#ParsedReport
13-06-2022
BumbleBee: a new trendy loader for Initial Access Brokers. Technical Analysis
https://blog.sekoia.io/bumblebee-a-new-trendy-loader-for-initial-access-brokers
Actors/Campaigns:
Darkhalo
Threats:
Bumblebee (tags: malware, ransomware, botnet)
Cobalt_strike
Meterpreter_tool
Conti
Lockbit
Avoslocker
Diavol
Sliver_tool
Icedid
Redline_stealer
Bazarbackdoor
Qakbot
Trickbot
IOCs:
File: 1
IP: 38
Hash: 17
YARA: Found
Links:
13-06-2022
BumbleBee: a new trendy loader for Initial Access Brokers. Technical Analysis
https://blog.sekoia.io/bumblebee-a-new-trendy-loader-for-initial-access-brokers
Actors/Campaigns:
Darkhalo
Threats:
Bumblebee (tags: malware, ransomware, botnet)
Cobalt_strike
Meterpreter_tool
Conti
Lockbit
Avoslocker
Diavol
Sliver_tool
Icedid
Redline_stealer
Bazarbackdoor
Qakbot
Trickbot
IOCs:
File: 1
IP: 38
Hash: 17
YARA: Found
Links:
https://github.com/LordNoteworthy/al-khaserSekoia.io Blog
BumbleBee: a new trendy loader for Initial Access Brokers
BumbleBee is a new malicious loader that is being used by several IABs to gain an initial foothold within victims' networks
#ParsedReport
13-06-2022
How SeaFlower installs backdoors in iOS/Android web3 wallets to steal your seed phrase. What is SeaFlower?
https://blog.confiant.com/how-seaflower-%E8%97%8F%E6%B5%B7%E8%8A%B1-installs-backdoors-in-ios-android-web3-wallets-to-steal-your-seed-phrase-d25f0ccdffce
Actors/Campaigns:
Seaflower (tags: proxy, malware, backdoor)
Lazarus
Threats:
Sara
Geo:
Tibetan, Chinese
IOCs:
Domain: 6
Url: 1
File: 10
Email: 1
Hash: 5
Functions Names: 2
Links:
13-06-2022
How SeaFlower installs backdoors in iOS/Android web3 wallets to steal your seed phrase. What is SeaFlower?
https://blog.confiant.com/how-seaflower-%E8%97%8F%E6%B5%B7%E8%8A%B1-installs-backdoors-in-ios-android-web3-wallets-to-steal-your-seed-phrase-d25f0ccdffce
Actors/Campaigns:
Seaflower (tags: proxy, malware, backdoor)
Lazarus
Threats:
Sara
Geo:
Tibetan, Chinese
IOCs:
Domain: 6
Url: 1
File: 10
Email: 1
Hash: 5
Functions Names: 2
Links:
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x06c-Reverse-Engineering-and-Tampering.mdhttps://github.com/facebook/react-native/blob/main/React/Base/RCTJavaScriptLoader.hhttps://github.com/AloneMonkeyhttps://github.com/AloneMonkey/MonkeyDev-Xcode-Templateshttps://github.com/AloneMonkey/MonkeyDev-Xcode-Templates/blob/master/MonkeyAppLibrary.xctemplate/Trace/OCMethodTrace.hhttps://github.com/omxcodechttps://github.com/xialun/RSAClassMedium
How SeaFlower 藏海花 installs backdoors in iOS/Android web3 wallets to steal your seed phrase
During the course of our work at Confiant, we see malicious activity on a daily basis. What matters the most for us is the ability to:
#ParsedReport
13-06-2022
Taking down the IP2Scam tech support campaign
https://blog.malwarebytes.com/threat-intelligence/2022/06/taking-down-the-ip2scam-tech-support-campaign
IOCs:
Url: 1
Domain: 19
Links:
13-06-2022
Taking down the IP2Scam tech support campaign
https://blog.malwarebytes.com/threat-intelligence/2022/06/taking-down-the-ip2scam-tech-support-campaign
IOCs:
Url: 1
Domain: 19
Links:
https://github.com/MBThreatIntel/TSS/blob/master/choopa\_IP2Scam.csvhttps://github.com/MBThreatIntel/TSS/blob/master/digital\_ocean\_IP2Scam.csvMalwarebytes
Taking down the IP2Scam tech support campaign
Online YARA-сканнер файлов от abuse
https://abuse.ch/blog/introducing-yaraify/
https://abuse.ch/blog/introducing-yaraify/
abuse.ch
abuse.ch | Introducing YARAify
abuse.ch blog post: Introducting YARAIfy
CTT Report Hub pinned «Online YARA-сканнер файлов от abuse https://abuse.ch/blog/introducing-yaraify/»