#ParsedReport
13-06-2022
BumbleBee: a new trendy loader for Initial Access Brokers. Technical Analysis
https://blog.sekoia.io/bumblebee-a-new-trendy-loader-for-initial-access-brokers
Actors/Campaigns:
Darkhalo
Threats:
Bumblebee (tags: malware, ransomware, botnet)
Cobalt_strike
Meterpreter_tool
Conti
Lockbit
Avoslocker
Diavol
Sliver_tool
Icedid
Redline_stealer
Bazarbackdoor
Qakbot
Trickbot
IOCs:
File: 1
IP: 38
Hash: 17
YARA: Found
Links:
13-06-2022
BumbleBee: a new trendy loader for Initial Access Brokers. Technical Analysis
https://blog.sekoia.io/bumblebee-a-new-trendy-loader-for-initial-access-brokers
Actors/Campaigns:
Darkhalo
Threats:
Bumblebee (tags: malware, ransomware, botnet)
Cobalt_strike
Meterpreter_tool
Conti
Lockbit
Avoslocker
Diavol
Sliver_tool
Icedid
Redline_stealer
Bazarbackdoor
Qakbot
Trickbot
IOCs:
File: 1
IP: 38
Hash: 17
YARA: Found
Links:
https://github.com/LordNoteworthy/al-khaserSekoia.io Blog
BumbleBee: a new trendy loader for Initial Access Brokers
BumbleBee is a new malicious loader that is being used by several IABs to gain an initial foothold within victims' networks
#ParsedReport
13-06-2022
How SeaFlower installs backdoors in iOS/Android web3 wallets to steal your seed phrase. What is SeaFlower?
https://blog.confiant.com/how-seaflower-%E8%97%8F%E6%B5%B7%E8%8A%B1-installs-backdoors-in-ios-android-web3-wallets-to-steal-your-seed-phrase-d25f0ccdffce
Actors/Campaigns:
Seaflower (tags: proxy, malware, backdoor)
Lazarus
Threats:
Sara
Geo:
Tibetan, Chinese
IOCs:
Domain: 6
Url: 1
File: 10
Email: 1
Hash: 5
Functions Names: 2
Links:
13-06-2022
How SeaFlower installs backdoors in iOS/Android web3 wallets to steal your seed phrase. What is SeaFlower?
https://blog.confiant.com/how-seaflower-%E8%97%8F%E6%B5%B7%E8%8A%B1-installs-backdoors-in-ios-android-web3-wallets-to-steal-your-seed-phrase-d25f0ccdffce
Actors/Campaigns:
Seaflower (tags: proxy, malware, backdoor)
Lazarus
Threats:
Sara
Geo:
Tibetan, Chinese
IOCs:
Domain: 6
Url: 1
File: 10
Email: 1
Hash: 5
Functions Names: 2
Links:
https://github.com/OWASP/owasp-mstg/blob/master/Document/0x06c-Reverse-Engineering-and-Tampering.mdhttps://github.com/facebook/react-native/blob/main/React/Base/RCTJavaScriptLoader.hhttps://github.com/AloneMonkeyhttps://github.com/AloneMonkey/MonkeyDev-Xcode-Templateshttps://github.com/AloneMonkey/MonkeyDev-Xcode-Templates/blob/master/MonkeyAppLibrary.xctemplate/Trace/OCMethodTrace.hhttps://github.com/omxcodechttps://github.com/xialun/RSAClassMedium
How SeaFlower 藏海花 installs backdoors in iOS/Android web3 wallets to steal your seed phrase
During the course of our work at Confiant, we see malicious activity on a daily basis. What matters the most for us is the ability to:
#ParsedReport
13-06-2022
Taking down the IP2Scam tech support campaign
https://blog.malwarebytes.com/threat-intelligence/2022/06/taking-down-the-ip2scam-tech-support-campaign
IOCs:
Url: 1
Domain: 19
Links:
13-06-2022
Taking down the IP2Scam tech support campaign
https://blog.malwarebytes.com/threat-intelligence/2022/06/taking-down-the-ip2scam-tech-support-campaign
IOCs:
Url: 1
Domain: 19
Links:
https://github.com/MBThreatIntel/TSS/blob/master/choopa\_IP2Scam.csvhttps://github.com/MBThreatIntel/TSS/blob/master/digital\_ocean\_IP2Scam.csvMalwarebytes
Taking down the IP2Scam tech support campaign
Online YARA-сканнер файлов от abuse
https://abuse.ch/blog/introducing-yaraify/
https://abuse.ch/blog/introducing-yaraify/
abuse.ch
abuse.ch | Introducing YARAify
abuse.ch blog post: Introducting YARAIfy
CTT Report Hub pinned «Online YARA-сканнер файлов от abuse https://abuse.ch/blog/introducing-yaraify/»
#ParsedReport
14-06-2022
ASEC Weekly Malware Statistics (May 30th, 2022 June 5th, 2022)
https://asec.ahnlab.com/en/35190
Threats:
Formbook (tags: spam, malware, stealer, rat)
Agent_tesla
Lokibot_stealer
Avemaria_rat
Redline_stealer
Beamwinhttp_loader
Industry:
Transport, Financial
IOCs:
File: 35
Url: 20
Domain: 8
IP: 12
Email: 4
14-06-2022
ASEC Weekly Malware Statistics (May 30th, 2022 June 5th, 2022)
https://asec.ahnlab.com/en/35190
Threats:
Formbook (tags: spam, malware, stealer, rat)
Agent_tesla
Lokibot_stealer
Avemaria_rat
Redline_stealer
Beamwinhttp_loader
Industry:
Transport, Financial
IOCs:
File: 35
Url: 20
Domain: 8
IP: 12
Email: 4
ASEC BLOG
ASEC Weekly Malware Statistics (May 30th, 2022 - June 5th, 2022) - ASEC BLOG
The ASEC analysis team is using the ASEC automatic analysis system RAPIT to categorize and respond to known malware. This post will list weekly statistics collected from May 30th, 2022 (Monday) to June 5th, 2022 (Sunday). For the main category, info-stealer…
#ParsedReport
14-06-2022
CHM Malware Types with Anti-Sandbox Technique and Targeting Companies
https://asec.ahnlab.com/en/35268
Threats:
Dll_hijacking_technique (tags: malware)
Revbshell (tags: malware)
Akdoor (tags: malware)
Trojan/win.generic.c5025270 (tags: malware)
Dropper/win.agent.c5028107 (tags: malware)
Geo:
Korea
IOCs:
File: 3
Hash: 5
14-06-2022
CHM Malware Types with Anti-Sandbox Technique and Targeting Companies
https://asec.ahnlab.com/en/35268
Threats:
Dll_hijacking_technique (tags: malware)
Revbshell (tags: malware)
Akdoor (tags: malware)
Trojan/win.generic.c5025270 (tags: malware)
Dropper/win.agent.c5028107 (tags: malware)
Geo:
Korea
IOCs:
File: 3
Hash: 5
ASEC BLOG
CHM Malware Types with Anti-Sandbox Technique and Targeting Companies - ASEC BLOG
Among CHM strains that are recently being distributed in Korea, the ASEC analysis team has discovered those applied with the anti-sandbox technique and targeting companies. Both types were introduced in the ASEC blog in March and May. The type with the anti…
#ParsedReport
14-06-2022
Iranian Spear-Phishing Operation Targets Former Israeli and US High-Ranking Officials
https://research.checkpoint.com/2022/check-point-research-exposes-an-iranian-phishing-campaign-targeting-former-israeli-foreign-minister-former-us-ambassador-idf-general-and-defense-industry-executives
Actors/Campaigns:
Cleaver (tags: phishing)
Industry:
Petroleum
Geo:
Israel, Iran, American
IOCs:
Domain: 3
14-06-2022
Iranian Spear-Phishing Operation Targets Former Israeli and US High-Ranking Officials
https://research.checkpoint.com/2022/check-point-research-exposes-an-iranian-phishing-campaign-targeting-former-israeli-foreign-minister-former-us-ambassador-idf-general-and-defense-industry-executives
Actors/Campaigns:
Cleaver (tags: phishing)
Industry:
Petroleum
Geo:
Israel, Iran, American
IOCs:
Domain: 3
Check Point Research
Iranian Spear-Phishing Operation Targets Former Israeli and US High-Ranking Officials - Check Point Research
Introduction Check Point Research uncovers a recent Iranian-based spear-phishing operation aimed against former Israeli officials, high-ranking military personnel, research fellows in research institutions, think tanks, and against Israeli citizens. The attacks…
#ParsedReport
14-06-2022
Bringing Chaos into the world: Chaos Ransomware
https://labs.k7computing.com/index.php/bringing-chaos-into-the-world-chaos-ransomware
Threats:
Chaos (tags: ransomware)
Ryuk (tags: ransomware)
IOCs:
Hash: 2
Functions Names: 3
14-06-2022
Bringing Chaos into the world: Chaos Ransomware
https://labs.k7computing.com/index.php/bringing-chaos-into-the-world-chaos-ransomware
Threats:
Chaos (tags: ransomware)
Ryuk (tags: ransomware)
IOCs:
Hash: 2
Functions Names: 3
K7 Labs
Bringing Chaos into the world: Chaos Ransomware - K7 Labs
Recently, a new cracked version of Chaos Ransomware builder was leaked on several underground forums and telegram groups in the […]
#ParsedReport
14-06-2022
New Release: Industroyer2 Content Pack
https://www.nozominetworks.com/blog/new-release-industroyer2-content-pack
Actors/Campaigns:
Sandworm
Threats:
Crashoverride (tags: scan, malware)
Candywiper
Industry:
Ics
14-06-2022
New Release: Industroyer2 Content Pack
https://www.nozominetworks.com/blog/new-release-industroyer2-content-pack
Actors/Campaigns:
Sandworm
Threats:
Crashoverride (tags: scan, malware)
Candywiper
Industry:
Ics
Nozomi Networks
New Release: Industroyer2 Content Pack
Nozomi Networks has put together a content pack to help customers look for activity related to Industroyer2 in their network.
#ParsedReport
14-06-2022
The many lives of BlackCat ransomware
https://www.microsoft.com/security/blog/2022/06/13/the-many-lives-of-blackcat-ransomware
Actors/Campaigns:
Fin12 (tags: ransomware)
Dev-0504 (tags: ransomware)
Blackmatter (tags: ransomware)
Threats:
Blackcat (tags: ransomware, dns, malware)
Ryuk (tags: ransomware)
Conti (tags: ransomware)
Revil (tags: ransomware)
Psexec_tool (tags: ransomware)
Wevtutil_tool
Mimikatz (tags: ransomware)
Adrecon
Screenconnect_tool
Megasync_tool
Rubeus_tool (tags: ransomware)
Lockbit (tags: ransomware)
Industry:
Financial
Geo:
Asia, Americas, Africa
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 17
Registry: 1
Path: 4
14-06-2022
The many lives of BlackCat ransomware
https://www.microsoft.com/security/blog/2022/06/13/the-many-lives-of-blackcat-ransomware
Actors/Campaigns:
Fin12 (tags: ransomware)
Dev-0504 (tags: ransomware)
Blackmatter (tags: ransomware)
Threats:
Blackcat (tags: ransomware, dns, malware)
Ryuk (tags: ransomware)
Conti (tags: ransomware)
Revil (tags: ransomware)
Psexec_tool (tags: ransomware)
Wevtutil_tool
Mimikatz (tags: ransomware)
Adrecon
Screenconnect_tool
Megasync_tool
Rubeus_tool (tags: ransomware)
Lockbit (tags: ransomware)
Industry:
Financial
Geo:
Asia, Americas, Africa
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 17
Registry: 1
Path: 4
Microsoft News
The many lives of BlackCat ransomware
The use of an unconventional programming language, multiple target devices and possible entry points, and affiliation with prolific threat activity groups have made the BlackCat ransomware a prevalent threat and a prime example of the growing ransomware-as…
#ParsedReport
14-06-2022
Taking down the IP2Scam tech support campaign
https://blog.malwarebytes.com/threat-intelligence/2022/06/taking-down-the-ip2scam-tech-support-campaign
IOCs:
Url: 1
Domain: 19
Links:
14-06-2022
Taking down the IP2Scam tech support campaign
https://blog.malwarebytes.com/threat-intelligence/2022/06/taking-down-the-ip2scam-tech-support-campaign
IOCs:
Url: 1
Domain: 19
Links:
https://github.com/MBThreatIntel/TSS/blob/master/digital\_ocean\_IP2Scam.csvhttps://github.com/MBThreatIntel/TSS/blob/master/choopa\_IP2Scam.csvMalwarebytes
Taking down the IP2Scam tech support campaign
#ParsedReport
14-06-2022
Bumblebee malware is being distributed in Korea through email hijacking
https://asec-ahnlab-com.translate.goog/ko/35261/?_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Threats:
Bumblebee (tags: malware, dropper, trojan, phishing)
Cobalt_strike (tags: malware)
Dropper/win.dropperx-gen.c5154946 (tags: malware)
Geo:
Korea
IOCs:
File: 5
Path: 2
IP: 14
Hash: 5
14-06-2022
Bumblebee malware is being distributed in Korea through email hijacking
https://asec-ahnlab-com.translate.goog/ko/35261/?_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Threats:
Bumblebee (tags: malware, dropper, trojan, phishing)
Cobalt_strike (tags: malware)
Dropper/win.dropperx-gen.c5154946 (tags: malware)
Geo:
Korea
IOCs:
File: 5
Path: 2
IP: 14
Hash: 5
ASEC BLOG
이메일 하이재킹을 통해 Bumblebee 악성코드 국내 유포 중 - ASEC BLOG
ASEC 분석팀은 최근 다운로더 유형의 악성코드인 Bumblebee 가 다수 유포되고 있는 정황을 포착하였다. Bumblebee 다운로더는 피싱 메일을 통해 ISO 파일로 유포되고 있으며, ISO 파일은 바로가기 파일과 악성 dll 파일을 포함하고 있다. 추가로, 이메일 하이재킹을 통해 국내 사용자를 대상으로 유포되는 사례도 확인되었다. 아래는 Bumblebee 다운로더를 유포하는 피싱 메일이다. 해당 메일은 정상 메일을 가로채 악성 파일을 첨부하여 사용자에게…
#ParsedReport
15-06-2022
Follina Vulnerability (CVE-2022-30190) Attack Using Antimicrobial Film Request File
https://asec.ahnlab.com/en/35343
Threats:
Follina_vuln (tags: backdoor, malware, rat)
Cobalt_strike
Geo:
Korean
CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...
IOCs:
File: 9
Url: 6
Path: 2
Hash: 5
15-06-2022
Follina Vulnerability (CVE-2022-30190) Attack Using Antimicrobial Film Request File
https://asec.ahnlab.com/en/35343
Threats:
Follina_vuln (tags: backdoor, malware, rat)
Cobalt_strike
Geo:
Korean
CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...
IOCs:
File: 9
Url: 6
Path: 2
Hash: 5
ASEC BLOG
Follina Vulnerability (CVE-2022-30190) Attack Using 'Antimicrobial Film Request' File - ASEC BLOG
On June 7th, the ASEC analysis team swiftly uploaded a brief introduction of a zero-day vulnerability for Microsoft Office files (Follina). As the patch for the vulnerability is not distributed yet, users are advised to take caution. Caution! Microsoft Office…
#ParsedReport
15-06-2022
Research Paper \| Emulating Phineas Phisher Attacks in Modern EDR Environments
https://www.sentinelone.com/blog/research-paper-emulating-phineas-phisher-attacks-in-modern-edr-environments
Threats:
Cobalt_strike (tags: rat, phishing)
Meterpreter_tool
Empire_loader
Vortex (tags: rat)
Beacon (tags: rat)
Winrm_tool
Ryuk (tags: ransomware)
Ragnarlocker (tags: ransomware)
Babuk (tags: ransomware)
Industry:
Government, Financial
TTPs:
Tactics: 2
Technics: 0
15-06-2022
Research Paper \| Emulating Phineas Phisher Attacks in Modern EDR Environments
https://www.sentinelone.com/blog/research-paper-emulating-phineas-phisher-attacks-in-modern-edr-environments
Threats:
Cobalt_strike (tags: rat, phishing)
Meterpreter_tool
Empire_loader
Vortex (tags: rat)
Beacon (tags: rat)
Winrm_tool
Ryuk (tags: ransomware)
Ragnarlocker (tags: ransomware)
Babuk (tags: ransomware)
Industry:
Government, Financial
TTPs:
Tactics: 2
Technics: 0
SentinelOne
Research Paper | Emulating Phineas Phisher Attacks in Modern EDR Environments
How would a modern EDR fare in attacks such as those conducted by Phineas Phisher? This research aims to find out.
#ParsedReport
15-06-2022
Telerik UI exploitation leads to cryptominer, Cobalt Strike infections
https://news.sophos.com/en-us/2022/06/15/telerik-ui-exploitation-leads-to-cryptominer-cobalt-strike-infections
Threats:
Cobalt_strike (tags: rat, cryptomining, malware, dropper, ransomware)
Xmrig_miner
Beacon
Netwalker
Metasploit_tool
Log4shell_vuln
Mimikatz
Nmap_tool
Geo:
Czech
CVEs:
CVE-2017-1137 [Vulners]
Vulners: Score: 6.8, CVSS: 4.6,
Vulners: Exploitation: Unknown
X-Force: Risk: 5.9
X-Force: Patch: Official fix
Soft:
- ibm websphere application server (8.5, 8.5.5, 8.0)
CVE-2017-11317 [Vulners]
Vulners: Score: 7.5, CVSS: 6.2,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- telerik ui for asp.net ajax (2017.2.503, 2017.2.621, le2016.3.1027)
CVE-2017-11357 [Vulners]
Vulners: Score: 7.5, CVSS: 6.9,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- telerik ui for asp.net ajax (le2017.2.621)
CVE-2021-44228 [Vulners]
Vulners: Score: 9.3, CVSS: 4.0,
Vulners: Exploitation: True
X-Force: Risk: 10
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, <2.15.0, <2.3.1, <2.12.2)
- siemens sppa-t3000 ses3000 firmware (*)
- siemens logo\! soft comfort (*)
- siemens spectrum power 4 (4.70, 4.70, <4.70, 4.70)
- siemens siveillance control pro (*)
have more...
CVE-2019-18935 [Vulners]
Vulners: Score: 7.5, CVSS: 6.1,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- telerik ui for asp.net ajax (<2019.3.1023)
IOCs:
File: 11
Path: 3
Registry: 1
Url: 2
Coin: 2
Hash: 9
IP: 1
Links:
15-06-2022
Telerik UI exploitation leads to cryptominer, Cobalt Strike infections
https://news.sophos.com/en-us/2022/06/15/telerik-ui-exploitation-leads-to-cryptominer-cobalt-strike-infections
Threats:
Cobalt_strike (tags: rat, cryptomining, malware, dropper, ransomware)
Xmrig_miner
Beacon
Netwalker
Metasploit_tool
Log4shell_vuln
Mimikatz
Nmap_tool
Geo:
Czech
CVEs:
CVE-2017-1137 [Vulners]
Vulners: Score: 6.8, CVSS: 4.6,
Vulners: Exploitation: Unknown
X-Force: Risk: 5.9
X-Force: Patch: Official fix
Soft:
- ibm websphere application server (8.5, 8.5.5, 8.0)
CVE-2017-11317 [Vulners]
Vulners: Score: 7.5, CVSS: 6.2,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- telerik ui for asp.net ajax (2017.2.503, 2017.2.621, le2016.3.1027)
CVE-2017-11357 [Vulners]
Vulners: Score: 7.5, CVSS: 6.9,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- telerik ui for asp.net ajax (le2017.2.621)
CVE-2021-44228 [Vulners]
Vulners: Score: 9.3, CVSS: 4.0,
Vulners: Exploitation: True
X-Force: Risk: 10
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, <2.15.0, <2.3.1, <2.12.2)
- siemens sppa-t3000 ses3000 firmware (*)
- siemens logo\! soft comfort (*)
- siemens spectrum power 4 (4.70, 4.70, <4.70, 4.70)
- siemens siveillance control pro (*)
have more...
CVE-2019-18935 [Vulners]
Vulners: Score: 7.5, CVSS: 6.1,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- telerik ui for asp.net ajax (<2019.3.1023)
IOCs:
File: 11
Path: 3
Registry: 1
Url: 2
Coin: 2
Hash: 9
IP: 1
Links:
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/telerik\_rau\_deserialization.rbhttps://github.com/noperator/CVE-2019-18935https://github.com/ThanHuuTuan/Telerik\_CVE-2019-18935https://github.com/bao7uo/RAU\_cryptohttps://github.com/sophoslabs/IoCs/blob/master/Troj-Miner-AED.csvhttps://github.com/ohpe/juicy-potatoSophos
Telerik UI exploitation leads to cryptominer, Cobalt Strike infections
Attacker targets bugs in a popular web application graphical interface development tool
#ParsedReport
16-06-2022
New Qualys Research Report: Inside a Redline InfoStealer Campaign
https://blog.qualys.com/vulnerabilities-threat-research/2022/06/15/new-qualys-research-report-inside-a-redline-infostealer-campaign
Threats:
Redline_stealer (tags: malware, stealer)
Purecrypter (tags: stealer)
Exodus (tags: stealer)
16-06-2022
New Qualys Research Report: Inside a Redline InfoStealer Campaign
https://blog.qualys.com/vulnerabilities-threat-research/2022/06/15/new-qualys-research-report-inside-a-redline-infostealer-campaign
Threats:
Redline_stealer (tags: malware, stealer)
Purecrypter (tags: stealer)
Exodus (tags: stealer)
Qualys
New Qualys Research Report: Inside a Redline InfoStealer Campaign | Qualys
The Qualys Threat Research Team continues its efforts to identify and document previously unseen adversary activity to better understand their tactics, techniques, and procedures (TTPs) and defend…
#ParsedReport
16-06-2022
How Emotet is changing tactics in response to Microsofts tightening of Office macro security
https://www.welivesecurity.com/2022/06/16/how-emotet-is-changing-tactics-microsoft-tightening-office-macro-security
Actors/Campaigns:
Axiom
Turla
Threats:
Emotet (tags: malware, ransomware, botnet, spam, backdoor, trojan, phishing)
Dridex
Gootkit
Icedid
Nymaim
Qakbot
Trickbot
Gozi
Zeus
Mailpassview
Webbrowserview
Cobalt_strike
Beacon
Lockdown (tags: malware)
Shadowpad
Gazer
Astaroth
Passview_tool
Gobot
Industry:
Financial
Geo:
Italy, Mexico, Ukraine, Japan
IOCs:
File: 4
Links:
16-06-2022
How Emotet is changing tactics in response to Microsofts tightening of Office macro security
https://www.welivesecurity.com/2022/06/16/how-emotet-is-changing-tactics-microsoft-tightening-office-macro-security
Actors/Campaigns:
Axiom
Turla
Threats:
Emotet (tags: malware, ransomware, botnet, spam, backdoor, trojan, phishing)
Dridex
Gootkit
Icedid
Nymaim
Qakbot
Trickbot
Gozi
Zeus
Mailpassview
Webbrowserview
Cobalt_strike
Beacon
Lockdown (tags: malware)
Shadowpad
Gazer
Astaroth
Passview_tool
Gobot
Industry:
Financial
Geo:
Italy, Mexico, Ukraine, Japan
IOCs:
File: 4
Links:
https://github.com/nmantani/archiver-MOTW-support-comparisonWelivesecurity
How Emotet is changing tactics in response to Microsoft’s tightening of Office macro security
Emotet malware is back with ferocious vigor, according to ESET telemetry in the first four months of 2022. Will it survive the ever-tightening controls on macro-enabled documents?
#ParsedReport
16-06-2022
DriftingCloud: Zero-Day Sophos Firewall Exploitation and an Insidious Breach
https://www.volexity.com/blog/2022/06/15/driftingcloud-zero-day-sophos-firewall-exploitation-and-an-insidious-breach
Actors/Campaigns:
Driftingcloud (tags: vpn, malware, backdoor, rat, dns)
Threats:
Behinder
Sliver_tool
Pupy_rat
Geo:
China, Chinese, Asia
CVEs:
CVE-2021-4034 [Vulners]
Vulners: Score: 7.2, CVSS: 3.5,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- polkit project polkit (*)
- redhat enterprise linux desktop (7.0)
- redhat enterprise linux workstation (7.0)
- redhat enterprise linux for scientific computing (7.0)
- redhat enterprise linux server (7.0, 6.0)
have more...
CVE-2022-26134 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- atlassian confluence data center (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
- atlassian confluence server (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
CVE-2022-1040 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- sophos sfos (le18.5.3)
IOCs:
File: 5
Url: 1
Domain: 4
IP: 8
Functions Names: 3
YARA: Found
Links:
16-06-2022
DriftingCloud: Zero-Day Sophos Firewall Exploitation and an Insidious Breach
https://www.volexity.com/blog/2022/06/15/driftingcloud-zero-day-sophos-firewall-exploitation-and-an-insidious-breach
Actors/Campaigns:
Driftingcloud (tags: vpn, malware, backdoor, rat, dns)
Threats:
Behinder
Sliver_tool
Pupy_rat
Geo:
China, Chinese, Asia
CVEs:
CVE-2021-4034 [Vulners]
Vulners: Score: 7.2, CVSS: 3.5,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- polkit project polkit (*)
- redhat enterprise linux desktop (7.0)
- redhat enterprise linux workstation (7.0)
- redhat enterprise linux for scientific computing (7.0)
- redhat enterprise linux server (7.0, 6.0)
have more...
CVE-2022-26134 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- atlassian confluence data center (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
- atlassian confluence server (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
CVE-2022-1040 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- sophos sfos (le18.5.3)
IOCs:
File: 5
Url: 1
Domain: 4
IP: 8
Functions Names: 3
YARA: Found
Links:
https://github.com/gooogleapis/gooogleapishttps://github.com/Konloch/bytecode-viewerhttps://github.com/epinna/weevely3/blob/master/bd/agents/obfpost\_php.tplhttps://github.com/cassanof/pantegana/blob/master/Makefile#L12https://github.com/BishopFox/sliverhttps://github.com/cassanof/panteganahttps://github.com/volexity/threat-intel/blob/main/2022/2022-06-15%20DriftingCloud%20-%20Zero-Day%20Sophos%20Firewall%20Exploitation%20and%20an%20Insidious%20Breach/indicators/indicators.csvhttps://github.com/MountCloud/BehinderClientSource/blob/master/src/main/java/net/rebeyond/behinder/payload/java/SocksProxy.javahttps://github.com/berdav/CVE-2021-4034https://github.com/n1nj4sec/pupyhttps://github.com/volexity/threat-intel/blob/main/2022/2022-06-15%20DriftingCloud%20-%20Zero-Day%20Sophos%20Firewall%20Exploitation%20and%20an%20Insidious%20Breach/indicators/yara.yarVolexity
DriftingCloud: Zero-Day Sophos Firewall Exploitation and an Insidious Breach
Volexity frequently works with individuals and organizations heavily targeted by sophisticated, motivated, and well-equipped threat actors from around the world. Some of these individuals or organizations are attacked infrequently or […]
#ParsedReport
16-06-2022
Confluence exploits used to drop ransomware on vulnerable servers
https://news.sophos.com/en-us/2022/06/16/confluence-exploits-used-to-drop-ransomware-on-vulnerable-servers
Threats:
Cerber (tags: ransomware)
Log4shell_vuln (tags: ransomware)
Cobalt_strike (tags: ransomware)
Industry:
Financial
CVEs:
CVE-2022-26134 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- atlassian confluence data center (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
- atlassian confluence server (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
IOCs:
File: 1
Links:
16-06-2022
Confluence exploits used to drop ransomware on vulnerable servers
https://news.sophos.com/en-us/2022/06/16/confluence-exploits-used-to-drop-ransomware-on-vulnerable-servers
Threats:
Cerber (tags: ransomware)
Log4shell_vuln (tags: ransomware)
Cobalt_strike (tags: ransomware)
Industry:
Financial
CVEs:
CVE-2022-26134 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- atlassian confluence data center (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
- atlassian confluence server (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
IOCs:
File: 1
Links:
https://github.com/sophoslabs/IoCs/blob/master/CVE-2022-26134\_attacks.csvSophos News
Confluence exploits used to drop ransomware on vulnerable servers
Automated attacks are now widely exploiting the Atlassian vulnerability
#ParsedReport
16-06-2022
Panchans Mining Rig: New Golang Peer-to-Peer Botnet Says Hi!
https://www.akamai.com/blog/security/new-p2p-botnet-panchan
Threats:
Rig_tool (tags: botnet, malware, cryptomining)
Panchan_botnet
Cryptojacker
Xmrig_miner (tags: cryptomining)
Industry:
Financial, Telco, Education
Geo:
Asia, Japanese, Taiwan, Spain
TTPs:
Tactics: 1
Technics: 0
YARA: Found
Links:
16-06-2022
Panchans Mining Rig: New Golang Peer-to-Peer Botnet Says Hi!
https://www.akamai.com/blog/security/new-p2p-botnet-panchan
Threats:
Rig_tool (tags: botnet, malware, cryptomining)
Panchan_botnet
Cryptojacker
Xmrig_miner (tags: cryptomining)
Industry:
Financial, Telco, Education
Geo:
Asia, Japanese, Taiwan, Spain
TTPs:
Tactics: 1
Technics: 0
YARA: Found
Links:
https://github.com/akamai/akamai-security-research/tree/main/malware/panchanAkamai
Akamai Blog | Panchan’s Mining Rig: New Golang Peer-to-Peer Botnet Says “Hi!”
Akamai researchers have discovered a new P2P botnet targeting APJ. Read about it here.