CTT Report Hub
3.43K subscribers
9.96K photos
6 videos
67 files
13.6K links
Threat Intelligence Report Hub
Download Telegram
#ParsedReport
13-06-2022

GALLIUM Expands Targeting Across Telecommunications, Government and Finance Sectors With New PingPull Tool

https://unit42.paloaltonetworks.com/pingpull-gallium

Actors/Campaigns:
Gallium (tags: dns, trojan, backdoor, malware, rat)
Soft_cell

Threats:
Pingpull (tags: proxy, dns, trojan, backdoor, malware, rat)
Timestomp_tool (tags: malware)
Beacon (tags: malware)

Industry:
Government, Financial, Telco

Geo:
Apac, Asia, Australia, Japanese, Russia, America, Emea, Afghanistan, Mozambique, Malaysia, Philippines, Australian, Cambodia, Vietnam, Belgium, Japan, Africa, Chinese

IOCs:
File: 5
IP: 130
Hash: 8
Domain: 13
#ParsedReport
13-06-2022

Linux Threat Hunting: Syslogk a kernel rootkit found under development in the wild. Introduction

https://decoded.avast.io/davidalvarez/linux-threat-hunting-syslogk-a-kernel-rootkit-found-under-development-in-the-wild/?utm_source=rss&utm_medium=rss&utm_campaign=linux-threat-hunting-syslogk-a-kernel-rootkit-found-under-development-in-the-wild

Threats:
Syslogk_rootkit (tags: backdoor, rootkit, malware, rat, trojan, scan)
Adoreng_rootkit (tags: rootkit)
Rekoobe_rootkit (tags: rootkit, backdoor, malware, rat)
Netstat_tool

IOCs:
File: 1
Hash: 71

Functions Names: 2

Links:
https://github.com/yaoyumeng/adore-ng/blob/master/adore-ng.c#L178
https://github.com/yaoyumeng/adore-ng/blob/master/adore-ng.c#L193
https://github.com/yaoyumeng/adore-ng/blob/522c80a2dc043c2d523256472becc88c90d66337/adore-ng.c#L835
https://github.com/ksaravan910/FileCloakingRootkit/blob/master/rootkit.c#L81
https://github.com/avast/ioc/tree/master/SyslogkRootkit
https://github.com/milabs/kmod\_hooking/blob/master/module-init.c#L237
https://github.com/vmt/udis86
https://github.com/creaktive/tsh/blob/master/tshd.c#L693
https://github.com/yaoyumeng/adore-ng/blob/master/adore-ng.c#L688
https://github.com/avast/ioc/blob/master/SyslogkRootkit/Research%20Tools/magic\_packet\_start\_rekoobe.py
https://github.com/ksaravan910/FileCloakingRootkit/blob/master/rootkit.c#L64
https://github.com/avast/ioc/blob/master/SyslogkRootkit/Research%20Tools/cert.pem
https://github.com/avast/ioc/blob/master/SyslogkRootkit/Research%20Tools/unhide\_rootkit.c
https://github.com/avast/ioc/blob/master/SyslogkRootkit/Research%20Tools/magic\_packet\_kill\_rekoobe.py
https://github.com/avast/ioc/blob/master/SyslogkRootkit/Research%20Tools/remove\_syslogk\_from\_memory.sh
https://github.com/torvalds/linux/blob/master/include/linux/fs.h#L956
https://github.com/yaoyumeng/adore-ng/blob/master/adore-ng.c#L697
https://github.com/yaoyumeng/adore-ng/blob/master/adore-ng.c#L300
https://github.com/yaoyumeng/adore-ng/blob/522c80a2dc043c2d523256472becc88c90d66337/adore-ng.c#L662
https://github.com/avast/ioc/blob/master/SyslogkRootkit/Research%20Tools/rekoobe\_backdoor\_client.py
https://github.com/yaoyumeng/adore-ng
https://github.com/torvalds/linux/blob/master/net/ipv4/tcp\_ipv4.c#L2695
https://github.com/torvalds/linux/blob/master/include/linux/fs.h#L939
#ParsedReport
13-06-2022

BumbleBee: a new trendy loader for Initial Access Brokers. Technical Analysis

https://blog.sekoia.io/bumblebee-a-new-trendy-loader-for-initial-access-brokers

Actors/Campaigns:
Darkhalo

Threats:
Bumblebee (tags: malware, ransomware, botnet)
Cobalt_strike
Meterpreter_tool
Conti
Lockbit
Avoslocker
Diavol
Sliver_tool
Icedid
Redline_stealer
Bazarbackdoor
Qakbot
Trickbot

IOCs:
File: 1
IP: 38
Hash: 17

YARA: Found

Links:
https://github.com/LordNoteworthy/al-khaser
#ParsedReport
13-06-2022

How SeaFlower installs backdoors in iOS/Android web3 wallets to steal your seed phrase. What is SeaFlower?

https://blog.confiant.com/how-seaflower-%E8%97%8F%E6%B5%B7%E8%8A%B1-installs-backdoors-in-ios-android-web3-wallets-to-steal-your-seed-phrase-d25f0ccdffce

Actors/Campaigns:
Seaflower (tags: proxy, malware, backdoor)
Lazarus

Threats:
Sara

Geo:
Tibetan, Chinese

IOCs:
Domain: 6
Url: 1
File: 10
Email: 1
Hash: 5

Functions Names: 2

Links:
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x06c-Reverse-Engineering-and-Tampering.md
https://github.com/facebook/react-native/blob/main/React/Base/RCTJavaScriptLoader.h
https://github.com/AloneMonkey
https://github.com/AloneMonkey/MonkeyDev-Xcode-Templates
https://github.com/AloneMonkey/MonkeyDev-Xcode-Templates/blob/master/MonkeyAppLibrary.xctemplate/Trace/OCMethodTrace.h
https://github.com/omxcodec
https://github.com/xialun/RSAClass
#ParsedReport
13-06-2022

Taking down the IP2Scam tech support campaign

https://blog.malwarebytes.com/threat-intelligence/2022/06/taking-down-the-ip2scam-tech-support-campaign

IOCs:
Url: 1
Domain: 19

Links:
https://github.com/MBThreatIntel/TSS/blob/master/choopa\_IP2Scam.csv
https://github.com/MBThreatIntel/TSS/blob/master/digital\_ocean\_IP2Scam.csv
CTT Report Hub pinned «Online YARA-сканнер файлов от abuse https://abuse.ch/blog/introducing-yaraify/»
#ParsedReport
14-06-2022

ASEC Weekly Malware Statistics (May 30th, 2022 June 5th, 2022)

https://asec.ahnlab.com/en/35190

Threats:
Formbook (tags: spam, malware, stealer, rat)
Agent_tesla
Lokibot_stealer
Avemaria_rat
Redline_stealer
Beamwinhttp_loader

Industry:
Transport, Financial

IOCs:
File: 35
Url: 20
Domain: 8
IP: 12
Email: 4
#ParsedReport
14-06-2022

CHM Malware Types with Anti-Sandbox Technique and Targeting Companies

https://asec.ahnlab.com/en/35268

Threats:
Dll_hijacking_technique (tags: malware)
Revbshell (tags: malware)
Akdoor (tags: malware)
Trojan/win.generic.c5025270 (tags: malware)
Dropper/win.agent.c5028107 (tags: malware)

Geo:
Korea

IOCs:
File: 3
Hash: 5
#ParsedReport
14-06-2022

The many lives of BlackCat ransomware

https://www.microsoft.com/security/blog/2022/06/13/the-many-lives-of-blackcat-ransomware

Actors/Campaigns:
Fin12 (tags: ransomware)
Dev-0504 (tags: ransomware)
Blackmatter (tags: ransomware)

Threats:
Blackcat (tags: ransomware, dns, malware)
Ryuk (tags: ransomware)
Conti (tags: ransomware)
Revil (tags: ransomware)
Psexec_tool (tags: ransomware)
Wevtutil_tool
Mimikatz (tags: ransomware)
Adrecon
Screenconnect_tool
Megasync_tool
Rubeus_tool (tags: ransomware)
Lockbit (tags: ransomware)

Industry:
Financial

Geo:
Asia, Americas, Africa

TTPs:
Tactics: 2
Technics: 0

IOCs:
File: 17
Registry: 1
Path: 4
#ParsedReport
14-06-2022

Taking down the IP2Scam tech support campaign

https://blog.malwarebytes.com/threat-intelligence/2022/06/taking-down-the-ip2scam-tech-support-campaign

IOCs:
Url: 1
Domain: 19

Links:
https://github.com/MBThreatIntel/TSS/blob/master/digital\_ocean\_IP2Scam.csv
https://github.com/MBThreatIntel/TSS/blob/master/choopa\_IP2Scam.csv
#ParsedReport
15-06-2022

Follina Vulnerability (CVE-2022-30190) Attack Using Antimicrobial Film Request File

https://asec.ahnlab.com/en/35343

Threats:
Follina_vuln (tags: backdoor, malware, rat)
Cobalt_strike

Geo:
Korean

CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...

IOCs:
File: 9
Url: 6
Path: 2
Hash: 5
#ParsedReport
15-06-2022

Research Paper \| Emulating Phineas Phisher Attacks in Modern EDR Environments

https://www.sentinelone.com/blog/research-paper-emulating-phineas-phisher-attacks-in-modern-edr-environments

Threats:
Cobalt_strike (tags: rat, phishing)
Meterpreter_tool
Empire_loader
Vortex (tags: rat)
Beacon (tags: rat)
Winrm_tool
Ryuk (tags: ransomware)
Ragnarlocker (tags: ransomware)
Babuk (tags: ransomware)

Industry:
Government, Financial

TTPs:
Tactics: 2
Technics: 0
#ParsedReport
15-06-2022

Telerik UI exploitation leads to cryptominer, Cobalt Strike infections

https://news.sophos.com/en-us/2022/06/15/telerik-ui-exploitation-leads-to-cryptominer-cobalt-strike-infections

Threats:
Cobalt_strike (tags: rat, cryptomining, malware, dropper, ransomware)
Xmrig_miner
Beacon
Netwalker
Metasploit_tool
Log4shell_vuln
Mimikatz
Nmap_tool

Geo:
Czech

CVEs:
CVE-2017-1137 [Vulners]
Vulners: Score: 6.8, CVSS: 4.6,
Vulners: Exploitation: Unknown
X-Force: Risk: 5.9
X-Force: Patch: Official fix
Soft:
- ibm websphere application server (8.5, 8.5.5, 8.0)

CVE-2017-11317 [Vulners]
Vulners: Score: 7.5, CVSS: 6.2,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- telerik ui for asp.net ajax (2017.2.503, 2017.2.621, le2016.3.1027)

CVE-2017-11357 [Vulners]
Vulners: Score: 7.5, CVSS: 6.9,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- telerik ui for asp.net ajax (le2017.2.621)

CVE-2021-44228 [Vulners]
Vulners: Score: 9.3, CVSS: 4.0,
Vulners: Exploitation: True
X-Force: Risk: 10
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, <2.15.0, <2.3.1, <2.12.2)
- siemens sppa-t3000 ses3000 firmware (*)
- siemens logo\! soft comfort (*)
- siemens spectrum power 4 (4.70, 4.70, <4.70, 4.70)
- siemens siveillance control pro (*)
have more...
CVE-2019-18935 [Vulners]
Vulners: Score: 7.5, CVSS: 6.1,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- telerik ui for asp.net ajax (<2019.3.1023)


IOCs:
File: 11
Path: 3
Registry: 1
Url: 2
Coin: 2
Hash: 9
IP: 1

Links:
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/telerik\_rau\_deserialization.rb
https://github.com/noperator/CVE-2019-18935
https://github.com/ThanHuuTuan/Telerik\_CVE-2019-18935
https://github.com/bao7uo/RAU\_crypto
https://github.com/sophoslabs/IoCs/blob/master/Troj-Miner-AED.csv
https://github.com/ohpe/juicy-potato
#ParsedReport
16-06-2022

How Emotet is changing tactics in response to Microsofts tightening of Office macro security

https://www.welivesecurity.com/2022/06/16/how-emotet-is-changing-tactics-microsoft-tightening-office-macro-security

Actors/Campaigns:
Axiom
Turla

Threats:
Emotet (tags: malware, ransomware, botnet, spam, backdoor, trojan, phishing)
Dridex
Gootkit
Icedid
Nymaim
Qakbot
Trickbot
Gozi
Zeus
Mailpassview
Webbrowserview
Cobalt_strike
Beacon
Lockdown (tags: malware)
Shadowpad
Gazer
Astaroth
Passview_tool
Gobot

Industry:
Financial

Geo:
Italy, Mexico, Ukraine, Japan

IOCs:
File: 4

Links:
https://github.com/nmantani/archiver-MOTW-support-comparison
#ParsedReport
16-06-2022

DriftingCloud: Zero-Day Sophos Firewall Exploitation and an Insidious Breach

https://www.volexity.com/blog/2022/06/15/driftingcloud-zero-day-sophos-firewall-exploitation-and-an-insidious-breach

Actors/Campaigns:
Driftingcloud (tags: vpn, malware, backdoor, rat, dns)

Threats:
Behinder
Sliver_tool
Pupy_rat

Geo:
China, Chinese, Asia

CVEs:
CVE-2021-4034 [Vulners]
Vulners: Score: 7.2, CVSS: 3.5,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- polkit project polkit (*)
- redhat enterprise linux desktop (7.0)
- redhat enterprise linux workstation (7.0)
- redhat enterprise linux for scientific computing (7.0)
- redhat enterprise linux server (7.0, 6.0)
have more...
CVE-2022-26134 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- atlassian confluence data center (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
- atlassian confluence server (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)

CVE-2022-1040 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- sophos sfos (le18.5.3)


IOCs:
File: 5
Url: 1
Domain: 4
IP: 8

Functions Names: 3

YARA: Found

Links:
https://github.com/gooogleapis/gooogleapis
https://github.com/Konloch/bytecode-viewer
https://github.com/epinna/weevely3/blob/master/bd/agents/obfpost\_php.tpl
https://github.com/cassanof/pantegana/blob/master/Makefile#L12
https://github.com/BishopFox/sliver
https://github.com/cassanof/pantegana
https://github.com/volexity/threat-intel/blob/main/2022/2022-06-15%20DriftingCloud%20-%20Zero-Day%20Sophos%20Firewall%20Exploitation%20and%20an%20Insidious%20Breach/indicators/indicators.csv
https://github.com/MountCloud/BehinderClientSource/blob/master/src/main/java/net/rebeyond/behinder/payload/java/SocksProxy.java
https://github.com/berdav/CVE-2021-4034
https://github.com/n1nj4sec/pupy
https://github.com/volexity/threat-intel/blob/main/2022/2022-06-15%20DriftingCloud%20-%20Zero-Day%20Sophos%20Firewall%20Exploitation%20and%20an%20Insidious%20Breach/indicators/yara.yar