CTT Report Hub
3.43K subscribers
9.96K photos
6 videos
67 files
13.6K links
Threat Intelligence Report Hub
Download Telegram
#ParsedReport
13-06-2022

Hydra Android Malware Distributed Via Play Store. Fake Document Manager App Downloading Hydra Banking Trojan

https://blog.cyble.com/2022/06/13/hydra-android-malware-distributed-via-play-store

Threats:
Hydra (tags: malware, trojan, phishing, proxy)

Industry:
Financial

Geo:
Colombia

TTPs:
Tactics: 6
Technics: 2

IOCs:
Url: 6
File: 2
Hash: 2
#ParsedReport
13-06-2022

Technical Analysis of PureCrypter: A Fully-Functional Loader Distributing Remote Access Trojans and Information Stealers. Key points

https://www.zscaler.com/blogs/security-research/technical-analysis-purecrypter

Threats:
Purecrypter (tags: ransomware, malware, stealer, rat)
Binder
Agent_tesla
Arkei_stealer
Asyncrat_rat
Azorult
Dcrat_rat
Nanocore_rat
Redline_stealer
Remcos_rat
Snake_keylogger
Avemaria_rat

TTPs:
Tactics: 1
Technics: 0

IOCs:
Hash: 57
File: 13
Url: 17
Registry: 4
Path: 1

Functions Names: 4
#ParsedReport
13-06-2022

GALLIUM Expands Targeting Across Telecommunications, Government and Finance Sectors With New PingPull Tool

https://unit42.paloaltonetworks.com/pingpull-gallium

Actors/Campaigns:
Gallium (tags: dns, trojan, backdoor, malware, rat)
Soft_cell

Threats:
Pingpull (tags: proxy, dns, trojan, backdoor, malware, rat)
Timestomp_tool (tags: malware)
Beacon (tags: malware)

Industry:
Government, Financial, Telco

Geo:
Apac, Asia, Australia, Japanese, Russia, America, Emea, Afghanistan, Mozambique, Malaysia, Philippines, Australian, Cambodia, Vietnam, Belgium, Japan, Africa, Chinese

IOCs:
File: 5
IP: 130
Hash: 8
Domain: 13
#ParsedReport
13-06-2022

Linux Threat Hunting: Syslogk a kernel rootkit found under development in the wild. Introduction

https://decoded.avast.io/davidalvarez/linux-threat-hunting-syslogk-a-kernel-rootkit-found-under-development-in-the-wild/?utm_source=rss&utm_medium=rss&utm_campaign=linux-threat-hunting-syslogk-a-kernel-rootkit-found-under-development-in-the-wild

Threats:
Syslogk_rootkit (tags: backdoor, rootkit, malware, rat, trojan, scan)
Adoreng_rootkit (tags: rootkit)
Rekoobe_rootkit (tags: rootkit, backdoor, malware, rat)
Netstat_tool

IOCs:
File: 1
Hash: 71

Functions Names: 2

Links:
https://github.com/yaoyumeng/adore-ng/blob/master/adore-ng.c#L178
https://github.com/yaoyumeng/adore-ng/blob/master/adore-ng.c#L193
https://github.com/yaoyumeng/adore-ng/blob/522c80a2dc043c2d523256472becc88c90d66337/adore-ng.c#L835
https://github.com/ksaravan910/FileCloakingRootkit/blob/master/rootkit.c#L81
https://github.com/avast/ioc/tree/master/SyslogkRootkit
https://github.com/milabs/kmod\_hooking/blob/master/module-init.c#L237
https://github.com/vmt/udis86
https://github.com/creaktive/tsh/blob/master/tshd.c#L693
https://github.com/yaoyumeng/adore-ng/blob/master/adore-ng.c#L688
https://github.com/avast/ioc/blob/master/SyslogkRootkit/Research%20Tools/magic\_packet\_start\_rekoobe.py
https://github.com/ksaravan910/FileCloakingRootkit/blob/master/rootkit.c#L64
https://github.com/avast/ioc/blob/master/SyslogkRootkit/Research%20Tools/cert.pem
https://github.com/avast/ioc/blob/master/SyslogkRootkit/Research%20Tools/unhide\_rootkit.c
https://github.com/avast/ioc/blob/master/SyslogkRootkit/Research%20Tools/magic\_packet\_kill\_rekoobe.py
https://github.com/avast/ioc/blob/master/SyslogkRootkit/Research%20Tools/remove\_syslogk\_from\_memory.sh
https://github.com/torvalds/linux/blob/master/include/linux/fs.h#L956
https://github.com/yaoyumeng/adore-ng/blob/master/adore-ng.c#L697
https://github.com/yaoyumeng/adore-ng/blob/master/adore-ng.c#L300
https://github.com/yaoyumeng/adore-ng/blob/522c80a2dc043c2d523256472becc88c90d66337/adore-ng.c#L662
https://github.com/avast/ioc/blob/master/SyslogkRootkit/Research%20Tools/rekoobe\_backdoor\_client.py
https://github.com/yaoyumeng/adore-ng
https://github.com/torvalds/linux/blob/master/net/ipv4/tcp\_ipv4.c#L2695
https://github.com/torvalds/linux/blob/master/include/linux/fs.h#L939
#ParsedReport
13-06-2022

BumbleBee: a new trendy loader for Initial Access Brokers. Technical Analysis

https://blog.sekoia.io/bumblebee-a-new-trendy-loader-for-initial-access-brokers

Actors/Campaigns:
Darkhalo

Threats:
Bumblebee (tags: malware, ransomware, botnet)
Cobalt_strike
Meterpreter_tool
Conti
Lockbit
Avoslocker
Diavol
Sliver_tool
Icedid
Redline_stealer
Bazarbackdoor
Qakbot
Trickbot

IOCs:
File: 1
IP: 38
Hash: 17

YARA: Found

Links:
https://github.com/LordNoteworthy/al-khaser
#ParsedReport
13-06-2022

How SeaFlower installs backdoors in iOS/Android web3 wallets to steal your seed phrase. What is SeaFlower?

https://blog.confiant.com/how-seaflower-%E8%97%8F%E6%B5%B7%E8%8A%B1-installs-backdoors-in-ios-android-web3-wallets-to-steal-your-seed-phrase-d25f0ccdffce

Actors/Campaigns:
Seaflower (tags: proxy, malware, backdoor)
Lazarus

Threats:
Sara

Geo:
Tibetan, Chinese

IOCs:
Domain: 6
Url: 1
File: 10
Email: 1
Hash: 5

Functions Names: 2

Links:
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x06c-Reverse-Engineering-and-Tampering.md
https://github.com/facebook/react-native/blob/main/React/Base/RCTJavaScriptLoader.h
https://github.com/AloneMonkey
https://github.com/AloneMonkey/MonkeyDev-Xcode-Templates
https://github.com/AloneMonkey/MonkeyDev-Xcode-Templates/blob/master/MonkeyAppLibrary.xctemplate/Trace/OCMethodTrace.h
https://github.com/omxcodec
https://github.com/xialun/RSAClass
#ParsedReport
13-06-2022

Taking down the IP2Scam tech support campaign

https://blog.malwarebytes.com/threat-intelligence/2022/06/taking-down-the-ip2scam-tech-support-campaign

IOCs:
Url: 1
Domain: 19

Links:
https://github.com/MBThreatIntel/TSS/blob/master/choopa\_IP2Scam.csv
https://github.com/MBThreatIntel/TSS/blob/master/digital\_ocean\_IP2Scam.csv
CTT Report Hub pinned «Online YARA-сканнер файлов от abuse https://abuse.ch/blog/introducing-yaraify/»
#ParsedReport
14-06-2022

ASEC Weekly Malware Statistics (May 30th, 2022 June 5th, 2022)

https://asec.ahnlab.com/en/35190

Threats:
Formbook (tags: spam, malware, stealer, rat)
Agent_tesla
Lokibot_stealer
Avemaria_rat
Redline_stealer
Beamwinhttp_loader

Industry:
Transport, Financial

IOCs:
File: 35
Url: 20
Domain: 8
IP: 12
Email: 4
#ParsedReport
14-06-2022

CHM Malware Types with Anti-Sandbox Technique and Targeting Companies

https://asec.ahnlab.com/en/35268

Threats:
Dll_hijacking_technique (tags: malware)
Revbshell (tags: malware)
Akdoor (tags: malware)
Trojan/win.generic.c5025270 (tags: malware)
Dropper/win.agent.c5028107 (tags: malware)

Geo:
Korea

IOCs:
File: 3
Hash: 5
#ParsedReport
14-06-2022

The many lives of BlackCat ransomware

https://www.microsoft.com/security/blog/2022/06/13/the-many-lives-of-blackcat-ransomware

Actors/Campaigns:
Fin12 (tags: ransomware)
Dev-0504 (tags: ransomware)
Blackmatter (tags: ransomware)

Threats:
Blackcat (tags: ransomware, dns, malware)
Ryuk (tags: ransomware)
Conti (tags: ransomware)
Revil (tags: ransomware)
Psexec_tool (tags: ransomware)
Wevtutil_tool
Mimikatz (tags: ransomware)
Adrecon
Screenconnect_tool
Megasync_tool
Rubeus_tool (tags: ransomware)
Lockbit (tags: ransomware)

Industry:
Financial

Geo:
Asia, Americas, Africa

TTPs:
Tactics: 2
Technics: 0

IOCs:
File: 17
Registry: 1
Path: 4
#ParsedReport
14-06-2022

Taking down the IP2Scam tech support campaign

https://blog.malwarebytes.com/threat-intelligence/2022/06/taking-down-the-ip2scam-tech-support-campaign

IOCs:
Url: 1
Domain: 19

Links:
https://github.com/MBThreatIntel/TSS/blob/master/digital\_ocean\_IP2Scam.csv
https://github.com/MBThreatIntel/TSS/blob/master/choopa\_IP2Scam.csv
#ParsedReport
15-06-2022

Follina Vulnerability (CVE-2022-30190) Attack Using Antimicrobial Film Request File

https://asec.ahnlab.com/en/35343

Threats:
Follina_vuln (tags: backdoor, malware, rat)
Cobalt_strike

Geo:
Korean

CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...

IOCs:
File: 9
Url: 6
Path: 2
Hash: 5
#ParsedReport
15-06-2022

Research Paper \| Emulating Phineas Phisher Attacks in Modern EDR Environments

https://www.sentinelone.com/blog/research-paper-emulating-phineas-phisher-attacks-in-modern-edr-environments

Threats:
Cobalt_strike (tags: rat, phishing)
Meterpreter_tool
Empire_loader
Vortex (tags: rat)
Beacon (tags: rat)
Winrm_tool
Ryuk (tags: ransomware)
Ragnarlocker (tags: ransomware)
Babuk (tags: ransomware)

Industry:
Government, Financial

TTPs:
Tactics: 2
Technics: 0
#ParsedReport
15-06-2022

Telerik UI exploitation leads to cryptominer, Cobalt Strike infections

https://news.sophos.com/en-us/2022/06/15/telerik-ui-exploitation-leads-to-cryptominer-cobalt-strike-infections

Threats:
Cobalt_strike (tags: rat, cryptomining, malware, dropper, ransomware)
Xmrig_miner
Beacon
Netwalker
Metasploit_tool
Log4shell_vuln
Mimikatz
Nmap_tool

Geo:
Czech

CVEs:
CVE-2017-1137 [Vulners]
Vulners: Score: 6.8, CVSS: 4.6,
Vulners: Exploitation: Unknown
X-Force: Risk: 5.9
X-Force: Patch: Official fix
Soft:
- ibm websphere application server (8.5, 8.5.5, 8.0)

CVE-2017-11317 [Vulners]
Vulners: Score: 7.5, CVSS: 6.2,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- telerik ui for asp.net ajax (2017.2.503, 2017.2.621, le2016.3.1027)

CVE-2017-11357 [Vulners]
Vulners: Score: 7.5, CVSS: 6.9,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- telerik ui for asp.net ajax (le2017.2.621)

CVE-2021-44228 [Vulners]
Vulners: Score: 9.3, CVSS: 4.0,
Vulners: Exploitation: True
X-Force: Risk: 10
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, <2.15.0, <2.3.1, <2.12.2)
- siemens sppa-t3000 ses3000 firmware (*)
- siemens logo\! soft comfort (*)
- siemens spectrum power 4 (4.70, 4.70, <4.70, 4.70)
- siemens siveillance control pro (*)
have more...
CVE-2019-18935 [Vulners]
Vulners: Score: 7.5, CVSS: 6.1,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- telerik ui for asp.net ajax (<2019.3.1023)


IOCs:
File: 11
Path: 3
Registry: 1
Url: 2
Coin: 2
Hash: 9
IP: 1

Links:
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/telerik\_rau\_deserialization.rb
https://github.com/noperator/CVE-2019-18935
https://github.com/ThanHuuTuan/Telerik\_CVE-2019-18935
https://github.com/bao7uo/RAU\_crypto
https://github.com/sophoslabs/IoCs/blob/master/Troj-Miner-AED.csv
https://github.com/ohpe/juicy-potato