#ParsedReport
14-06-2022
Bumblebee malware is being distributed in Korea through email hijacking
https://asec-ahnlab-com.translate.goog/ko/35261/?_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Threats:
Bumblebee (tags: malware, dropper, trojan, phishing)
Cobalt_strike (tags: malware)
Dropper/win.dropperx-gen.c5154946 (tags: malware)
Geo:
Korea
IOCs:
File: 5
Path: 2
IP: 14
Hash: 5
14-06-2022
Bumblebee malware is being distributed in Korea through email hijacking
https://asec-ahnlab-com.translate.goog/ko/35261/?_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Threats:
Bumblebee (tags: malware, dropper, trojan, phishing)
Cobalt_strike (tags: malware)
Dropper/win.dropperx-gen.c5154946 (tags: malware)
Geo:
Korea
IOCs:
File: 5
Path: 2
IP: 14
Hash: 5
ASEC BLOG
이메일 하이재킹을 통해 Bumblebee 악성코드 국내 유포 중 - ASEC BLOG
ASEC 분석팀은 최근 다운로더 유형의 악성코드인 Bumblebee 가 다수 유포되고 있는 정황을 포착하였다. Bumblebee 다운로더는 피싱 메일을 통해 ISO 파일로 유포되고 있으며, ISO 파일은 바로가기 파일과 악성 dll 파일을 포함하고 있다. 추가로, 이메일 하이재킹을 통해 국내 사용자를 대상으로 유포되는 사례도 확인되었다. 아래는 Bumblebee 다운로더를 유포하는 피싱 메일이다. 해당 메일은 정상 메일을 가로채 악성 파일을 첨부하여 사용자에게…
#ParsedReport
15-06-2022
Follina Vulnerability (CVE-2022-30190) Attack Using Antimicrobial Film Request File
https://asec.ahnlab.com/en/35343
Threats:
Follina_vuln (tags: backdoor, malware, rat)
Cobalt_strike
Geo:
Korean
CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...
IOCs:
File: 9
Url: 6
Path: 2
Hash: 5
15-06-2022
Follina Vulnerability (CVE-2022-30190) Attack Using Antimicrobial Film Request File
https://asec.ahnlab.com/en/35343
Threats:
Follina_vuln (tags: backdoor, malware, rat)
Cobalt_strike
Geo:
Korean
CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...
IOCs:
File: 9
Url: 6
Path: 2
Hash: 5
ASEC BLOG
Follina Vulnerability (CVE-2022-30190) Attack Using 'Antimicrobial Film Request' File - ASEC BLOG
On June 7th, the ASEC analysis team swiftly uploaded a brief introduction of a zero-day vulnerability for Microsoft Office files (Follina). As the patch for the vulnerability is not distributed yet, users are advised to take caution. Caution! Microsoft Office…
#ParsedReport
15-06-2022
Research Paper \| Emulating Phineas Phisher Attacks in Modern EDR Environments
https://www.sentinelone.com/blog/research-paper-emulating-phineas-phisher-attacks-in-modern-edr-environments
Threats:
Cobalt_strike (tags: rat, phishing)
Meterpreter_tool
Empire_loader
Vortex (tags: rat)
Beacon (tags: rat)
Winrm_tool
Ryuk (tags: ransomware)
Ragnarlocker (tags: ransomware)
Babuk (tags: ransomware)
Industry:
Government, Financial
TTPs:
Tactics: 2
Technics: 0
15-06-2022
Research Paper \| Emulating Phineas Phisher Attacks in Modern EDR Environments
https://www.sentinelone.com/blog/research-paper-emulating-phineas-phisher-attacks-in-modern-edr-environments
Threats:
Cobalt_strike (tags: rat, phishing)
Meterpreter_tool
Empire_loader
Vortex (tags: rat)
Beacon (tags: rat)
Winrm_tool
Ryuk (tags: ransomware)
Ragnarlocker (tags: ransomware)
Babuk (tags: ransomware)
Industry:
Government, Financial
TTPs:
Tactics: 2
Technics: 0
SentinelOne
Research Paper | Emulating Phineas Phisher Attacks in Modern EDR Environments
How would a modern EDR fare in attacks such as those conducted by Phineas Phisher? This research aims to find out.
#ParsedReport
15-06-2022
Telerik UI exploitation leads to cryptominer, Cobalt Strike infections
https://news.sophos.com/en-us/2022/06/15/telerik-ui-exploitation-leads-to-cryptominer-cobalt-strike-infections
Threats:
Cobalt_strike (tags: rat, cryptomining, malware, dropper, ransomware)
Xmrig_miner
Beacon
Netwalker
Metasploit_tool
Log4shell_vuln
Mimikatz
Nmap_tool
Geo:
Czech
CVEs:
CVE-2017-1137 [Vulners]
Vulners: Score: 6.8, CVSS: 4.6,
Vulners: Exploitation: Unknown
X-Force: Risk: 5.9
X-Force: Patch: Official fix
Soft:
- ibm websphere application server (8.5, 8.5.5, 8.0)
CVE-2017-11317 [Vulners]
Vulners: Score: 7.5, CVSS: 6.2,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- telerik ui for asp.net ajax (2017.2.503, 2017.2.621, le2016.3.1027)
CVE-2017-11357 [Vulners]
Vulners: Score: 7.5, CVSS: 6.9,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- telerik ui for asp.net ajax (le2017.2.621)
CVE-2021-44228 [Vulners]
Vulners: Score: 9.3, CVSS: 4.0,
Vulners: Exploitation: True
X-Force: Risk: 10
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, <2.15.0, <2.3.1, <2.12.2)
- siemens sppa-t3000 ses3000 firmware (*)
- siemens logo\! soft comfort (*)
- siemens spectrum power 4 (4.70, 4.70, <4.70, 4.70)
- siemens siveillance control pro (*)
have more...
CVE-2019-18935 [Vulners]
Vulners: Score: 7.5, CVSS: 6.1,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- telerik ui for asp.net ajax (<2019.3.1023)
IOCs:
File: 11
Path: 3
Registry: 1
Url: 2
Coin: 2
Hash: 9
IP: 1
Links:
15-06-2022
Telerik UI exploitation leads to cryptominer, Cobalt Strike infections
https://news.sophos.com/en-us/2022/06/15/telerik-ui-exploitation-leads-to-cryptominer-cobalt-strike-infections
Threats:
Cobalt_strike (tags: rat, cryptomining, malware, dropper, ransomware)
Xmrig_miner
Beacon
Netwalker
Metasploit_tool
Log4shell_vuln
Mimikatz
Nmap_tool
Geo:
Czech
CVEs:
CVE-2017-1137 [Vulners]
Vulners: Score: 6.8, CVSS: 4.6,
Vulners: Exploitation: Unknown
X-Force: Risk: 5.9
X-Force: Patch: Official fix
Soft:
- ibm websphere application server (8.5, 8.5.5, 8.0)
CVE-2017-11317 [Vulners]
Vulners: Score: 7.5, CVSS: 6.2,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- telerik ui for asp.net ajax (2017.2.503, 2017.2.621, le2016.3.1027)
CVE-2017-11357 [Vulners]
Vulners: Score: 7.5, CVSS: 6.9,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- telerik ui for asp.net ajax (le2017.2.621)
CVE-2021-44228 [Vulners]
Vulners: Score: 9.3, CVSS: 4.0,
Vulners: Exploitation: True
X-Force: Risk: 10
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, <2.15.0, <2.3.1, <2.12.2)
- siemens sppa-t3000 ses3000 firmware (*)
- siemens logo\! soft comfort (*)
- siemens spectrum power 4 (4.70, 4.70, <4.70, 4.70)
- siemens siveillance control pro (*)
have more...
CVE-2019-18935 [Vulners]
Vulners: Score: 7.5, CVSS: 6.1,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- telerik ui for asp.net ajax (<2019.3.1023)
IOCs:
File: 11
Path: 3
Registry: 1
Url: 2
Coin: 2
Hash: 9
IP: 1
Links:
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/telerik\_rau\_deserialization.rbhttps://github.com/noperator/CVE-2019-18935https://github.com/ThanHuuTuan/Telerik\_CVE-2019-18935https://github.com/bao7uo/RAU\_cryptohttps://github.com/sophoslabs/IoCs/blob/master/Troj-Miner-AED.csvhttps://github.com/ohpe/juicy-potatoSophos
Telerik UI exploitation leads to cryptominer, Cobalt Strike infections
Attacker targets bugs in a popular web application graphical interface development tool
#ParsedReport
16-06-2022
New Qualys Research Report: Inside a Redline InfoStealer Campaign
https://blog.qualys.com/vulnerabilities-threat-research/2022/06/15/new-qualys-research-report-inside-a-redline-infostealer-campaign
Threats:
Redline_stealer (tags: malware, stealer)
Purecrypter (tags: stealer)
Exodus (tags: stealer)
16-06-2022
New Qualys Research Report: Inside a Redline InfoStealer Campaign
https://blog.qualys.com/vulnerabilities-threat-research/2022/06/15/new-qualys-research-report-inside-a-redline-infostealer-campaign
Threats:
Redline_stealer (tags: malware, stealer)
Purecrypter (tags: stealer)
Exodus (tags: stealer)
Qualys
New Qualys Research Report: Inside a Redline InfoStealer Campaign | Qualys
The Qualys Threat Research Team continues its efforts to identify and document previously unseen adversary activity to better understand their tactics, techniques, and procedures (TTPs) and defend…
#ParsedReport
16-06-2022
How Emotet is changing tactics in response to Microsofts tightening of Office macro security
https://www.welivesecurity.com/2022/06/16/how-emotet-is-changing-tactics-microsoft-tightening-office-macro-security
Actors/Campaigns:
Axiom
Turla
Threats:
Emotet (tags: malware, ransomware, botnet, spam, backdoor, trojan, phishing)
Dridex
Gootkit
Icedid
Nymaim
Qakbot
Trickbot
Gozi
Zeus
Mailpassview
Webbrowserview
Cobalt_strike
Beacon
Lockdown (tags: malware)
Shadowpad
Gazer
Astaroth
Passview_tool
Gobot
Industry:
Financial
Geo:
Italy, Mexico, Ukraine, Japan
IOCs:
File: 4
Links:
16-06-2022
How Emotet is changing tactics in response to Microsofts tightening of Office macro security
https://www.welivesecurity.com/2022/06/16/how-emotet-is-changing-tactics-microsoft-tightening-office-macro-security
Actors/Campaigns:
Axiom
Turla
Threats:
Emotet (tags: malware, ransomware, botnet, spam, backdoor, trojan, phishing)
Dridex
Gootkit
Icedid
Nymaim
Qakbot
Trickbot
Gozi
Zeus
Mailpassview
Webbrowserview
Cobalt_strike
Beacon
Lockdown (tags: malware)
Shadowpad
Gazer
Astaroth
Passview_tool
Gobot
Industry:
Financial
Geo:
Italy, Mexico, Ukraine, Japan
IOCs:
File: 4
Links:
https://github.com/nmantani/archiver-MOTW-support-comparisonWelivesecurity
How Emotet is changing tactics in response to Microsoft’s tightening of Office macro security
Emotet malware is back with ferocious vigor, according to ESET telemetry in the first four months of 2022. Will it survive the ever-tightening controls on macro-enabled documents?
#ParsedReport
16-06-2022
DriftingCloud: Zero-Day Sophos Firewall Exploitation and an Insidious Breach
https://www.volexity.com/blog/2022/06/15/driftingcloud-zero-day-sophos-firewall-exploitation-and-an-insidious-breach
Actors/Campaigns:
Driftingcloud (tags: vpn, malware, backdoor, rat, dns)
Threats:
Behinder
Sliver_tool
Pupy_rat
Geo:
China, Chinese, Asia
CVEs:
CVE-2021-4034 [Vulners]
Vulners: Score: 7.2, CVSS: 3.5,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- polkit project polkit (*)
- redhat enterprise linux desktop (7.0)
- redhat enterprise linux workstation (7.0)
- redhat enterprise linux for scientific computing (7.0)
- redhat enterprise linux server (7.0, 6.0)
have more...
CVE-2022-26134 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- atlassian confluence data center (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
- atlassian confluence server (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
CVE-2022-1040 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- sophos sfos (le18.5.3)
IOCs:
File: 5
Url: 1
Domain: 4
IP: 8
Functions Names: 3
YARA: Found
Links:
16-06-2022
DriftingCloud: Zero-Day Sophos Firewall Exploitation and an Insidious Breach
https://www.volexity.com/blog/2022/06/15/driftingcloud-zero-day-sophos-firewall-exploitation-and-an-insidious-breach
Actors/Campaigns:
Driftingcloud (tags: vpn, malware, backdoor, rat, dns)
Threats:
Behinder
Sliver_tool
Pupy_rat
Geo:
China, Chinese, Asia
CVEs:
CVE-2021-4034 [Vulners]
Vulners: Score: 7.2, CVSS: 3.5,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- polkit project polkit (*)
- redhat enterprise linux desktop (7.0)
- redhat enterprise linux workstation (7.0)
- redhat enterprise linux for scientific computing (7.0)
- redhat enterprise linux server (7.0, 6.0)
have more...
CVE-2022-26134 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- atlassian confluence data center (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
- atlassian confluence server (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
CVE-2022-1040 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- sophos sfos (le18.5.3)
IOCs:
File: 5
Url: 1
Domain: 4
IP: 8
Functions Names: 3
YARA: Found
Links:
https://github.com/gooogleapis/gooogleapishttps://github.com/Konloch/bytecode-viewerhttps://github.com/epinna/weevely3/blob/master/bd/agents/obfpost\_php.tplhttps://github.com/cassanof/pantegana/blob/master/Makefile#L12https://github.com/BishopFox/sliverhttps://github.com/cassanof/panteganahttps://github.com/volexity/threat-intel/blob/main/2022/2022-06-15%20DriftingCloud%20-%20Zero-Day%20Sophos%20Firewall%20Exploitation%20and%20an%20Insidious%20Breach/indicators/indicators.csvhttps://github.com/MountCloud/BehinderClientSource/blob/master/src/main/java/net/rebeyond/behinder/payload/java/SocksProxy.javahttps://github.com/berdav/CVE-2021-4034https://github.com/n1nj4sec/pupyhttps://github.com/volexity/threat-intel/blob/main/2022/2022-06-15%20DriftingCloud%20-%20Zero-Day%20Sophos%20Firewall%20Exploitation%20and%20an%20Insidious%20Breach/indicators/yara.yarVolexity
DriftingCloud: Zero-Day Sophos Firewall Exploitation and an Insidious Breach
Volexity frequently works with individuals and organizations heavily targeted by sophisticated, motivated, and well-equipped threat actors from around the world. Some of these individuals or organizations are attacked infrequently or […]
#ParsedReport
16-06-2022
Confluence exploits used to drop ransomware on vulnerable servers
https://news.sophos.com/en-us/2022/06/16/confluence-exploits-used-to-drop-ransomware-on-vulnerable-servers
Threats:
Cerber (tags: ransomware)
Log4shell_vuln (tags: ransomware)
Cobalt_strike (tags: ransomware)
Industry:
Financial
CVEs:
CVE-2022-26134 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- atlassian confluence data center (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
- atlassian confluence server (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
IOCs:
File: 1
Links:
16-06-2022
Confluence exploits used to drop ransomware on vulnerable servers
https://news.sophos.com/en-us/2022/06/16/confluence-exploits-used-to-drop-ransomware-on-vulnerable-servers
Threats:
Cerber (tags: ransomware)
Log4shell_vuln (tags: ransomware)
Cobalt_strike (tags: ransomware)
Industry:
Financial
CVEs:
CVE-2022-26134 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- atlassian confluence data center (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
- atlassian confluence server (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
IOCs:
File: 1
Links:
https://github.com/sophoslabs/IoCs/blob/master/CVE-2022-26134\_attacks.csvSophos News
Confluence exploits used to drop ransomware on vulnerable servers
Automated attacks are now widely exploiting the Atlassian vulnerability
#ParsedReport
16-06-2022
Panchans Mining Rig: New Golang Peer-to-Peer Botnet Says Hi!
https://www.akamai.com/blog/security/new-p2p-botnet-panchan
Threats:
Rig_tool (tags: botnet, malware, cryptomining)
Panchan_botnet
Cryptojacker
Xmrig_miner (tags: cryptomining)
Industry:
Financial, Telco, Education
Geo:
Asia, Japanese, Taiwan, Spain
TTPs:
Tactics: 1
Technics: 0
YARA: Found
Links:
16-06-2022
Panchans Mining Rig: New Golang Peer-to-Peer Botnet Says Hi!
https://www.akamai.com/blog/security/new-p2p-botnet-panchan
Threats:
Rig_tool (tags: botnet, malware, cryptomining)
Panchan_botnet
Cryptojacker
Xmrig_miner (tags: cryptomining)
Industry:
Financial, Telco, Education
Geo:
Asia, Japanese, Taiwan, Spain
TTPs:
Tactics: 1
Technics: 0
YARA: Found
Links:
https://github.com/akamai/akamai-security-research/tree/main/malware/panchanAkamai
Akamai Blog | Panchan’s Mining Rig: New Golang Peer-to-Peer Botnet Says “Hi!”
Akamai researchers have discovered a new P2P botnet targeting APJ. Read about it here.
#ParsedReport
16-06-2022
F5 Labs Investigates MaliBot
https://www.f5.com/labs/articles/threat-intelligence/f5-labs-investigates-malibot
Threats:
Malibot (tags: trojan, malware, rat, phishing, stealer, ransomware, dns)
Flubot
Sharkbot
Industry:
Government, Iot, Education, E-commerce, Financial
Geo:
African, Spanish, Italian, Russia, Spain, Italy
IOCs:
Url: 6
Hash: 4
IP: 1
File: 7
Domain: 2
Functions Names: 1
16-06-2022
F5 Labs Investigates MaliBot
https://www.f5.com/labs/articles/threat-intelligence/f5-labs-investigates-malibot
Threats:
Malibot (tags: trojan, malware, rat, phishing, stealer, ransomware, dns)
Flubot
Sharkbot
Industry:
Government, Iot, Education, E-commerce, Financial
Geo:
African, Spanish, Italian, Russia, Spain, Italy
IOCs:
Url: 6
Hash: 4
IP: 1
File: 7
Domain: 2
Functions Names: 1
F5
F5 Labs Investigates MaliBot
We found a novel malware strain that is targeting financial sites in Italy and Spain... so far.
👍1
#ParsedReport
17-06-2022
Malicious HWP Files with BAT Scripts Being Distributed Actively (North Korea/National Defense/Broadcasting)
https://asec.ahnlab.com/en/35405
Actors/Campaigns:
Kimsuky (tags: malware)
Geo:
Korea, Asia
IOCs:
File: 11
Hash: 13
17-06-2022
Malicious HWP Files with BAT Scripts Being Distributed Actively (North Korea/National Defense/Broadcasting)
https://asec.ahnlab.com/en/35405
Actors/Campaigns:
Kimsuky (tags: malware)
Geo:
Korea, Asia
IOCs:
File: 11
Hash: 13
ASEC BLOG
Malicious HWP Files with BAT Scripts Being Distributed Actively (North Korea/National Defense/Broadcasting) - ASEC BLOG
The ASEC analysis team has discovered the active distribution of APT files that are exploiting a feature of HWP files (OLE object insertion) recently. After the case introduced in the post “Malicious HWP File Disguised as Press Release of 20th Presidential…
#ParsedReport
17-06-2022
ASEC Weekly Malware Statistics (June 6th, 2022 June 12th, 2022)
https://asec.ahnlab.com/en/35424
Threats:
Emotet (tags: malware)
Qakbot (tags: malware)
Trickbot (tags: malware)
Agent_tesla (tags: malware)
Formbook (tags: malware)
Lokibot_stealer (tags: malware)
Redline_stealer (tags: malware)
Beamwinhttp_loader (tags: malware)
Industry:
Transport, Financial
Geo:
Usa
IOCs:
Domain: 2
IP: 2
Email: 2
File: 30
Url: 43
17-06-2022
ASEC Weekly Malware Statistics (June 6th, 2022 June 12th, 2022)
https://asec.ahnlab.com/en/35424
Threats:
Emotet (tags: malware)
Qakbot (tags: malware)
Trickbot (tags: malware)
Agent_tesla (tags: malware)
Formbook (tags: malware)
Lokibot_stealer (tags: malware)
Redline_stealer (tags: malware)
Beamwinhttp_loader (tags: malware)
Industry:
Transport, Financial
Geo:
Usa
IOCs:
Domain: 2
IP: 2
Email: 2
File: 30
Url: 43
ASEC
ASEC Weekly Malware Statistics (June 6th, 2022 - June 12th, 2022) - ASEC
The ASEC analysis team is using the ASEC automatic analysis system RAPIT to categorize and respond to known malware. This post will list weekly statistics collected from June 6th, 2022 (Monday) to June 12th, 2022 (Sunday). For the main category, banking malware…
#ParsedReport
17-06-2022
Cerber2021 Ransomware Back in Action. Sophisticated Ransomware targeting Windows and Linux Users
https://blog.cyble.com/2022/06/17/cerber2021-ransomware-back-in-action
Threats:
Cerberimposter (tags: ransomware, malware, rat)
Cerber (tags: ransomware)
Gandcrab (tags: ransomware)
Samsam (tags: ransomware)
Blackrouter (tags: ransomware)
Industry:
Financial
CVEs:
CVE-2021-22205 [Vulners]
Vulners: Score: 7.5, CVSS: 5.6,
Vulners: Exploitation: True
X-Force: Risk: 9.9
X-Force: Patch: Official fix
Soft:
- gitlab (<13.8.8, <13.8.8, <13.9.6, <13.9.6, <13.10.3, <13.10.3)
CVE-2021-26084 [Vulners]
Vulners: Score: 7.5, CVSS: 7.3,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- atlassian confluence server (<7.12.5, <7.4.11, <7.11.6, <6.13.23)
- atlassian confluence data center (<7.12.5, <7.11.6, <7.4.11, <6.13.23)
CVE-2022-26134 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- atlassian confluence data center (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
- atlassian confluence server (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
TTPs:
Tactics: 4
Technics: 6
IOCs:
Url: 1
Hash: 3
Functions Names: 1
Links:
17-06-2022
Cerber2021 Ransomware Back in Action. Sophisticated Ransomware targeting Windows and Linux Users
https://blog.cyble.com/2022/06/17/cerber2021-ransomware-back-in-action
Threats:
Cerberimposter (tags: ransomware, malware, rat)
Cerber (tags: ransomware)
Gandcrab (tags: ransomware)
Samsam (tags: ransomware)
Blackrouter (tags: ransomware)
Industry:
Financial
CVEs:
CVE-2021-22205 [Vulners]
Vulners: Score: 7.5, CVSS: 5.6,
Vulners: Exploitation: True
X-Force: Risk: 9.9
X-Force: Patch: Official fix
Soft:
- gitlab (<13.8.8, <13.8.8, <13.9.6, <13.9.6, <13.10.3, <13.10.3)
CVE-2021-26084 [Vulners]
Vulners: Score: 7.5, CVSS: 7.3,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- atlassian confluence server (<7.12.5, <7.4.11, <7.11.6, <6.13.23)
- atlassian confluence data center (<7.12.5, <7.11.6, <7.4.11, <6.13.23)
CVE-2022-26134 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- atlassian confluence data center (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
- atlassian confluence server (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
TTPs:
Tactics: 4
Technics: 6
IOCs:
Url: 1
Hash: 3
Functions Names: 1
Links:
https://github.com/weidai11/cryptoppCyble
Cerber2021 Ransomware Back in Action
Cyble Research Labs analyzes Cerber2021 Ransomware - a potential rebrand of the popular Cerber Ransomware family.
#ParsedReport
17-06-2022
Lookout Uncovers Android Spyware Deployed in Kazakhstan
https://www.lookout.com/blog/hermit-spyware-discovery
Actors/Campaigns:
Memento (tags: rat)
Threats:
Hermit (tags: malware, spyware, rat, phishing)
Chrysaor
Finfisher
Industry:
Government, Telco, Financial
Geo:
Syria, Pakistan, Bangladesh, Chinese, Syrian, Berlin, Turkmenistan, Chile, Italy, Italian, German, Mongolia, Turkey, Kazakhstans, Kazakhstan, Myanmar, Vietnam
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 1
Url: 1
IP: 10
Domain: 17
Hash: 8
17-06-2022
Lookout Uncovers Android Spyware Deployed in Kazakhstan
https://www.lookout.com/blog/hermit-spyware-discovery
Actors/Campaigns:
Memento (tags: rat)
Threats:
Hermit (tags: malware, spyware, rat, phishing)
Chrysaor
Finfisher
Industry:
Government, Telco, Financial
Geo:
Syria, Pakistan, Bangladesh, Chinese, Syrian, Berlin, Turkmenistan, Chile, Italy, Italian, German, Mongolia, Turkey, Kazakhstans, Kazakhstan, Myanmar, Vietnam
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 1
Url: 1
IP: 10
Domain: 17
Hash: 8
Lookout
Lookout Uncovers Hermit Spyware Deployed in Kazakhstan | Threat Intel
Lookout researchers have uncovered enterprise-grade Android surveillanceware used by the government of Kazakhstan within its borders.
#ParsedReport
17-06-2022
Raccoon Stealer is Back with a New Version. Executive Summary
https://medium.com/s2wblog/raccoon-stealer-is-back-with-a-new-version-5f436e04b20d
Threats:
Raccoon_stealer (tags: cryptomining, malware, stealer, rat)
Redline_stealer
Fakecrack
Exodus
Vidar_stealer
Kpot_stealer
Geo:
Korean
IOCs:
Hash: 47
Domain: 1
File: 13
Coin: 3
Path: 5
IP: 1
Functions Names: 1
17-06-2022
Raccoon Stealer is Back with a New Version. Executive Summary
https://medium.com/s2wblog/raccoon-stealer-is-back-with-a-new-version-5f436e04b20d
Threats:
Raccoon_stealer (tags: cryptomining, malware, stealer, rat)
Redline_stealer
Fakecrack
Exodus
Vidar_stealer
Kpot_stealer
Geo:
Korean
IOCs:
Hash: 47
Domain: 1
File: 13
Coin: 3
Path: 5
IP: 1
Functions Names: 1
Medium
Raccoon Stealer is Back with a New Version
Author: S2W TALON
#ParsedReport
17-06-2022
'Dark Elephant': A Decade of Cyber Attacks
https://mp-weixin-qq-com.translate.goog/s/mC5D8kFaQA-cIcw2rlTgeA?_x_tr_sl=zh-CN&_x_tr_tl=en&_x_tr_hl=en
Actors/Campaigns:
Darkelephant
Modified_elephant
Threats:
Harpoon
Netwire_rat
Darkcomet_rat
Parallax_rat
Geo:
India, China, Pakistan
CVEs:
CVE-2012-0158 [Vulners]
Vulners: Score: 9.3, CVSS: 7.5,
Vulners: Exploitation: True
X-Force: Risk: 9.3
X-Force: Patch: Official fix
Soft:
- microsoft office (2010, 2010, 2003, 2007, 2007)
- microsoft office web components (2003)
- microsoft sql server (2000, 2008, 2008, 2005, 2008, 2008, 2008, 2000, 2005, 2008, 2008, 2005, 2005, 2008, 2008)
- microsoft biztalk server (2002)
- microsoft commerce server (2002, 2007, 2009, 2009)
have more...
IOCs:
File: 14
17-06-2022
'Dark Elephant': A Decade of Cyber Attacks
https://mp-weixin-qq-com.translate.goog/s/mC5D8kFaQA-cIcw2rlTgeA?_x_tr_sl=zh-CN&_x_tr_tl=en&_x_tr_hl=en
Actors/Campaigns:
Darkelephant
Modified_elephant
Threats:
Harpoon
Netwire_rat
Darkcomet_rat
Parallax_rat
Geo:
India, China, Pakistan
CVEs:
CVE-2012-0158 [Vulners]
Vulners: Score: 9.3, CVSS: 7.5,
Vulners: Exploitation: True
X-Force: Risk: 9.3
X-Force: Patch: Official fix
Soft:
- microsoft office (2010, 2010, 2003, 2007, 2007)
- microsoft office web components (2003)
- microsoft sql server (2000, 2008, 2008, 2005, 2008, 2008, 2008, 2000, 2005, 2008, 2008, 2005, 2005, 2008, 2008)
- microsoft biztalk server (2002)
- microsoft commerce server (2002, 2007, 2009, 2009)
have more...
IOCs:
File: 14
微信公众平台
“暗象”组织:潜藏十年的网络攻击
安天披露印度“暗象”组织针对我国及南亚国家的网络窃密活动。
#ParsedReport
17-06-2022
Sophisticated Phishing Toolkit Dubbed NakedPages for Sale on Cybercrime Forums
https://cloudsek.com/threatintelligence/sophisticated-phishing-toolkit-dubbed-nakedpages-for-sale-on-cybercrime-forums
Threats:
Nakedpages_tool
Industry:
E-commerce
Geo:
India
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 2
17-06-2022
Sophisticated Phishing Toolkit Dubbed NakedPages for Sale on Cybercrime Forums
https://cloudsek.com/threatintelligence/sophisticated-phishing-toolkit-dubbed-nakedpages-for-sale-on-cybercrime-forums
Threats:
Nakedpages_tool
Industry:
E-commerce
Geo:
India
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 2
Cloudsek
Sophisticated Phishing Toolkit Dubbed “NakedPages” for Sale on Cybercrime Forums | Threat Intelligence | CloudSEK
XVigil discovered a threat actor advertising a “battle-tested” reverse proxy/PHP phishing app called “NakedPages”, on a cybercrime forum.
#ParsedReport
17-06-2022
Latin American Governments Targeted By Ransomware
https://www.recordedfuture.com/latin-american-governments-targeted-by-ransomware
Actors/Campaigns:
Zirochka
Wazawaka
Threats:
Conti (tags: ransomware)
Blackcat (tags: ransomware)
Lockbit (tags: ransomware)
Blackbyte (tags: ransomware)
Industry:
Government, Ics, Healthcare, Education, E-commerce, Financial
Geo:
Latam, Brazilian, Colombia, Russian, Peru, Mexico, Ukraine, Russia, Panama, Brazil, Ecuador, Chile, America, Argentina, Uruguay, American
TTPs:
IOCs:
Domain: 10
YARA: Found
17-06-2022
Latin American Governments Targeted By Ransomware
https://www.recordedfuture.com/latin-american-governments-targeted-by-ransomware
Actors/Campaigns:
Zirochka
Wazawaka
Threats:
Conti (tags: ransomware)
Blackcat (tags: ransomware)
Lockbit (tags: ransomware)
Blackbyte (tags: ransomware)
Industry:
Government, Ics, Healthcare, Education, E-commerce, Financial
Geo:
Latam, Brazilian, Colombia, Russian, Peru, Mexico, Ukraine, Russia, Panama, Brazil, Ecuador, Chile, America, Argentina, Uruguay, American
TTPs:
IOCs:
Domain: 10
YARA: Found
Recordedfuture
Latin American Governments Targeted By Ransomware
Recent ransomware attacks against Latin American governments suggest a change of policy within Russian-speaking threat groups, and they will likely continue to target these government entities – and critical infrastructure within Latin America’s private sector…
#ParsedReport
17-06-2022
CoinEgg Scam Campaign Steals Victims Cryptocurrency and Data
https://cloudsek.com/threatintelligence/coinegg-scam-campaign-steals-victims-cryptocurrency-and-data/?utm_source=rss&utm_medium=rss&utm_campaign=coinegg-scam-campaign-steals-victims-cryptocurrency-and-data
Industry:
Financial
Geo:
Australia, France
CVEs:
CVE-2022-26134 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- atlassian confluence data center (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
- atlassian confluence server (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
TTPs:
Tactics: 1
Technics: 0
IOCs:
Url: 6
Domain: 2
IP: 2
17-06-2022
CoinEgg Scam Campaign Steals Victims Cryptocurrency and Data
https://cloudsek.com/threatintelligence/coinegg-scam-campaign-steals-victims-cryptocurrency-and-data/?utm_source=rss&utm_medium=rss&utm_campaign=coinegg-scam-campaign-steals-victims-cryptocurrency-and-data
Industry:
Financial
Geo:
Australia, France
CVEs:
CVE-2022-26134 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- atlassian confluence data center (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
- atlassian confluence server (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
TTPs:
Tactics: 1
Technics: 0
IOCs:
Url: 6
Domain: 2
IP: 2
Cloudsek
CoinEgg Scam Campaign Steals Victims’ Cryptocurrency and Data | Threat Intelligence | CloudSEK
CloudSEK researchers’ investigation discovered that the CoinEgg Scam/cryptocurrency scam was conducted by threat actors. We discovered an on-going malicious scheme involving multiple payment gateway domains and Android-based applications, used to lure unsuspecting…
#ParsedReport
17-06-2022
Anatomy of a Ransomware Attack
https://www.varonis.com/blog/anatomy-of-a-ransomware-attack
Threats:
Lockbit
Psexec_tool
Tightvnc_tool
Log4shell_vuln
Mimikatz
Passthehash_technique
TTPs:
Tactics: 12
Technics: 24
IOCs:
Domain: 1
IP: 8
17-06-2022
Anatomy of a Ransomware Attack
https://www.varonis.com/blog/anatomy-of-a-ransomware-attack
Threats:
Lockbit
Psexec_tool
Tightvnc_tool
Log4shell_vuln
Mimikatz
Passthehash_technique
TTPs:
Tactics: 12
Technics: 24
IOCs:
Domain: 1
IP: 8
Varonis
Anatomy of a LockBit Ransomware Attack
A detailed case study of the exact techniques and methods that threat actors used in a real-life ransomware attack.
👍1
#ParsedReport
17-06-2022
Resurgence of Voicemail-themed Phishing Attacks Targeting Key Industry Verticals in US.
https://www.zscaler.com/blogs/security-research/resurgence-voicemail-themed-phishing-attacks-targeting-key-industry
Industry:
Transport, Healthcare
Geo:
Japan
IOCs:
Hash: 1
File: 2
Domain: 10
17-06-2022
Resurgence of Voicemail-themed Phishing Attacks Targeting Key Industry Verticals in US.
https://www.zscaler.com/blogs/security-research/resurgence-voicemail-themed-phishing-attacks-targeting-key-industry
Industry:
Transport, Healthcare
Geo:
Japan
IOCs:
Hash: 1
File: 2
Domain: 10
Zscaler
Voicemail Phishing Continues to Target Key US Industries
Voicemail-themed credential phishing campaign targets key industry verticals in US to steal Office365 and Outlook credentials. Read more.