CTT Report Hub
3.43K subscribers
9.94K photos
6 videos
67 files
13.6K links
Threat Intelligence Report Hub
Download Telegram
#ParsedReport
20-06-2022

BRATA is evolving into an Advanced Persistent Threat

https://www.cleafy.com/cleafy-labs/brata-is-evolving-into-an-advanced-persistent-threat

Threats:
Brata (tags: fraud, keylogger, phishing, stealer, malware)
Anatsa
Sms_stealer (tags: malware, stealer)

Industry:
Financial

Geo:
Italy, Spain

IOCs:
File: 1
Hash: 2
IP: 2
Научил парсер выкусывать "мотивацию" из текста TI-отчета и вязать с группировкой :)
🔥3
#ParsedReport
21-06-2022

APT ToddyCat

https://securelist.com/toddycat/106799

Actors/Campaigns:
Toddycat
Ice_fog

Threats:
Chinachopper
Samurai (tags: malware, trojan, backdoor, dropper)
Proxylogon_exploit
Cobalt_strike (tags: trojan)
Funnydream

Industry:
Government

Geo:
Indonesia, Taiwan, Russia, Slovakia, Iran, Malaysia, Vietnam, Afghanistan, Uzbekistan, Thailand, Kyrgyzstan, Vietnamese, Asia, Pakistan, China, India

TTPs:
Tactics: 1
Technics: 0

IOCs:
File: 23
Path: 55
Registry: 1
Hash: 16
IP: 1
Domain: 1

Functions Names: 4

YARA: Found
#ParsedReport
21-06-2022

Russias APT28 uses fear of nuclear war to spread Follina docs in Ukraine

https://blog.malwarebytes.com/threat-intelligence/2022/06/russias-apt28-uses-fear-of-nuclear-war-to-spread-follina-docs-in-ukraine

Actors/Campaigns:
Fancy_bear (motivation: cyberespionage)

Threats:
Follina_vuln (tags: malware, stealer)

Industry:
Government

Geo:
Dubai, Russia, Ukraine, Russian

CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...

IOCs:
File: 10
Path: 2
Domain: 2
IP: 1
Hash: 2
Url: 2

Functions Names: 1
#ParsedReport
21-06-2022

New IceXLoader 3.0 Developers Warm Up to Nim

https://www.fortinet.com/blog/threat-research/new-icexloader-3-0-developers-warm-up-to-nim

Threats:
Icexloader (tags: malware, ransomware, trojan, stealer, scan, phishing, rat, dropper, cryptomining)
Bazarnimrod
Bazarbackdoor
Trickbot
Ice_ix
Zeus
Xmr_miner
Dcrat_rat

Industry:
Financial

TTPs:
Tactics: 2
Technics: 0

IOCs:
Path: 1
File: 2
Hash: 8
Url: 12

Functions Names: 1
#ParsedReport
21-06-2022

Matanbuchus: Malware-as-a-Service with Demonic Intentions

https://unit42.paloaltonetworks.com/matanbuchus-malware-as-a-service

Actors/Campaigns:
Belialdemon

Threats:
Triumph_loader

Industry:
Education, E-commerce

Geo:
Japanese, Austria, Belgium

IOCs:
File: 12
Url: 1
Hash: 3
Domain: 35
IP: 3
Path: 2

Functions Names: 2
#ParsedReport
21-06-2022

Avos ransomware group expands with new attack arsenal

http://blog.talosintelligence.com/2022/06/avoslocker-new-arsenal.html

Actors/Campaigns:
Avos (motivation: financiallymotivated)

Threats:
Avoslocker (tags: ransomware)
Cobalt_strike (tags: ransomware)
Sliver_tool (tags: ransomware)
Log4shell_vuln (tags: ransomware)
Lolbin
Darkcomet_rat
Mimikatz
Beacon

Geo:
Russian

CVEs:
CVE-2021-45105 [Vulners]
Vulners: Score: 4.3, CVSS: 5.4,
Vulners: Exploitation: True
X-Force: Risk: 7.5
X-Force: Patch: Official fix
Soft:
- apache log4j (<2.3.1, <2.12.3, le2.16.0)
- netapp cloud manager (-)
- debian debian linux (10.0, 11.0)
- sonicwall email security (le10.0.12)
- sonicwall network security manager (<3.0, <3.0)
have more...
CVE-2021-45046 [Vulners]
Vulners: Score: 5.1, CVSS: 3.2,
Vulners: Exploitation: True
X-Force: Risk: 9
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, <2.12.2, <2.16.0)
- intel audio development kit (-)
- intel computer vision annotation tool (-)
- intel datacenter manager (-)
- intel genomics kernel library (-)
have more...
CVE-2021-44228 [Vulners]
Vulners: Score: 9.3, CVSS: 4.0,
Vulners: Exploitation: True
X-Force: Risk: 10
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, <2.15.0, <2.3.1, <2.12.2)
- siemens sppa-t3000 ses3000 firmware (*)
- siemens logo\! soft comfort (*)
- siemens spectrum power 4 (4.70, 4.70, <4.70, 4.70)
- siemens siveillance control pro (*)
have more...
CVE-2021-44832 [Vulners]
Vulners: Score: 6.0, CVSS: 5.3,
Vulners: Exploitation: Unknown
X-Force: Risk: 6.6
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, 2.0, 2.0, <2.3.2, <2.12.4, <2.17.1)


IOCs:
File: 4
Path: 2
Url: 1
Hash: 14
IP: 2

Links:
https://github.com/BishopFox/sliver
#ParsedReport
21-06-2022

MuddyWaters light first-stager targetting Middle East

https://lab52.io/blog/muddywaters-light-first-stager-targetting-middle-east

Actors/Campaigns:
Muddywater

Industry:
Energy, Government

Geo:
Kazakhstan, Syria, Sudan, Israel, Africa, Armenia, Bahrain, Turkey, Argentina, Iran, Pakistan

IOCs:
File: 10
Hash: 13
IP: 3

Functions Names: 2
#ParsedReport
22-06-2022

Chinese actor takes aim, armed with Nim Language and Bizarro AES. Executive Summary

https://research.checkpoint.com/2022/chinese-actor-takes-aim-armed-with-nim-language-and-bizarro-aes

Actors/Campaigns:
Pirate_panda
Ta428

Threats:
Bizarro (tags: proxy, trojan, scan, malware, rat, backdoor, ransomware)
Yahoyah (tags: scan, backdoor, malware)
Zebrocy
Trickbot
Process_doppelganging_technique

Industry:
Financial

Geo:
Philippines, Taiwan, China, Chinese

TTPs:
Tactics: 1
Technics: 0

IOCs:
File: 4
Hash: 32
IP: 24
Domain: 2

Functions Names: 1

Links:
https://github.com/polymorf/findcrypt-yara
#ParsedReport
22-06-2022

CALISTO continues its credential harvesting campaign

https://blog.sekoia.io/calisto-continues-its-credential-harvesting-campaign

Actors/Campaigns:
Calisto
Coldriver
Fancy_bear

Threats:
Hades

Industry:
Ngo

Geo:
Ukrainian, Russian

IOCs:
Domain: 24

Links:
https://github.com/kgretzky/evilginx2
#ParsedReport
22-06-2022

From the Front Lines \| 3 New and Emerging Ransomware Threats Striking Businesses in 2022

https://www.sentinelone.com/blog/from-the-front-lines-3-new-and-emerging-ransomware-threats-striking-businesses-in-2022

Actors/Campaigns:
Lapsus
Mindware

Threats:
Zeon (tags: ransomware)
Helloxd (tags: ransomware, malware, rat)
Babuk (tags: ransomware, malware)
Conti (tags: ransomware)
Lockbit (tags: ransomware)
Blackcat (tags: ransomware)
Microbackdoor (tags: ransomware)
Sfile (tags: ransomware)

Industry:
Financial

TTPs:
Tactics: 1
Technics: 0

IOCs:
File: 8
IP: 1
Hash: 22

Links:
https://github.com/vbdaga/Rabbit-Cipher
https://github.com/dashingsoft/pyarmor