#ParsedReport
21-06-2022
New IceXLoader 3.0 Developers Warm Up to Nim
https://www.fortinet.com/blog/threat-research/new-icexloader-3-0-developers-warm-up-to-nim
Threats:
Icexloader (tags: malware, ransomware, trojan, stealer, scan, phishing, rat, dropper, cryptomining)
Bazarnimrod
Bazarbackdoor
Trickbot
Ice_ix
Zeus
Xmr_miner
Dcrat_rat
Industry:
Financial
TTPs:
Tactics: 2
Technics: 0
IOCs:
Path: 1
File: 2
Hash: 8
Url: 12
Functions Names: 1
21-06-2022
New IceXLoader 3.0 Developers Warm Up to Nim
https://www.fortinet.com/blog/threat-research/new-icexloader-3-0-developers-warm-up-to-nim
Threats:
Icexloader (tags: malware, ransomware, trojan, stealer, scan, phishing, rat, dropper, cryptomining)
Bazarnimrod
Bazarbackdoor
Trickbot
Ice_ix
Zeus
Xmr_miner
Dcrat_rat
Industry:
Financial
TTPs:
Tactics: 2
Technics: 0
IOCs:
Path: 1
File: 2
Hash: 8
Url: 12
Functions Names: 1
Fortinet Blog
New IceXLoader 3.0 – Developers Warm Up to Nim
FortiGuard Labs discovered version 3.0 of IceXLoader, a new malware loader. Read our blog for the technical details of how it behaves and the potential malware that it can deliver in an infected sy…
#ParsedReport
21-06-2022
Matanbuchus: Malware-as-a-Service with Demonic Intentions
https://unit42.paloaltonetworks.com/matanbuchus-malware-as-a-service
Actors/Campaigns:
Belialdemon
Threats:
Triumph_loader
Industry:
Education, E-commerce
Geo:
Japanese, Austria, Belgium
IOCs:
File: 12
Url: 1
Hash: 3
Domain: 35
IP: 3
Path: 2
Functions Names: 2
21-06-2022
Matanbuchus: Malware-as-a-Service with Demonic Intentions
https://unit42.paloaltonetworks.com/matanbuchus-malware-as-a-service
Actors/Campaigns:
Belialdemon
Threats:
Triumph_loader
Industry:
Education, E-commerce
Geo:
Japanese, Austria, Belgium
IOCs:
File: 12
Url: 1
Hash: 3
Domain: 35
IP: 3
Path: 2
Functions Names: 2
Unit 42
Matanbuchus: Malware-as-a-Service with Demonic Intentions
Matanbuchus Loader is a new malware-as-a-service created by a threat actor who references demonic themes in software and usernames.
#ParsedReport
21-06-2022
Avos ransomware group expands with new attack arsenal
http://blog.talosintelligence.com/2022/06/avoslocker-new-arsenal.html
Actors/Campaigns:
Avos (motivation: financiallymotivated)
Threats:
Avoslocker (tags: ransomware)
Cobalt_strike (tags: ransomware)
Sliver_tool (tags: ransomware)
Log4shell_vuln (tags: ransomware)
Lolbin
Darkcomet_rat
Mimikatz
Beacon
Geo:
Russian
CVEs:
CVE-2021-45105 [Vulners]
Vulners: Score: 4.3, CVSS: 5.4,
Vulners: Exploitation: True
X-Force: Risk: 7.5
X-Force: Patch: Official fix
Soft:
- apache log4j (<2.3.1, <2.12.3, le2.16.0)
- netapp cloud manager (-)
- debian debian linux (10.0, 11.0)
- sonicwall email security (le10.0.12)
- sonicwall network security manager (<3.0, <3.0)
have more...
CVE-2021-45046 [Vulners]
Vulners: Score: 5.1, CVSS: 3.2,
Vulners: Exploitation: True
X-Force: Risk: 9
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, <2.12.2, <2.16.0)
- intel audio development kit (-)
- intel computer vision annotation tool (-)
- intel datacenter manager (-)
- intel genomics kernel library (-)
have more...
CVE-2021-44228 [Vulners]
Vulners: Score: 9.3, CVSS: 4.0,
Vulners: Exploitation: True
X-Force: Risk: 10
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, <2.15.0, <2.3.1, <2.12.2)
- siemens sppa-t3000 ses3000 firmware (*)
- siemens logo\! soft comfort (*)
- siemens spectrum power 4 (4.70, 4.70, <4.70, 4.70)
- siemens siveillance control pro (*)
have more...
CVE-2021-44832 [Vulners]
Vulners: Score: 6.0, CVSS: 5.3,
Vulners: Exploitation: Unknown
X-Force: Risk: 6.6
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, 2.0, 2.0, <2.3.2, <2.12.4, <2.17.1)
IOCs:
File: 4
Path: 2
Url: 1
Hash: 14
IP: 2
Links:
21-06-2022
Avos ransomware group expands with new attack arsenal
http://blog.talosintelligence.com/2022/06/avoslocker-new-arsenal.html
Actors/Campaigns:
Avos (motivation: financiallymotivated)
Threats:
Avoslocker (tags: ransomware)
Cobalt_strike (tags: ransomware)
Sliver_tool (tags: ransomware)
Log4shell_vuln (tags: ransomware)
Lolbin
Darkcomet_rat
Mimikatz
Beacon
Geo:
Russian
CVEs:
CVE-2021-45105 [Vulners]
Vulners: Score: 4.3, CVSS: 5.4,
Vulners: Exploitation: True
X-Force: Risk: 7.5
X-Force: Patch: Official fix
Soft:
- apache log4j (<2.3.1, <2.12.3, le2.16.0)
- netapp cloud manager (-)
- debian debian linux (10.0, 11.0)
- sonicwall email security (le10.0.12)
- sonicwall network security manager (<3.0, <3.0)
have more...
CVE-2021-45046 [Vulners]
Vulners: Score: 5.1, CVSS: 3.2,
Vulners: Exploitation: True
X-Force: Risk: 9
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, <2.12.2, <2.16.0)
- intel audio development kit (-)
- intel computer vision annotation tool (-)
- intel datacenter manager (-)
- intel genomics kernel library (-)
have more...
CVE-2021-44228 [Vulners]
Vulners: Score: 9.3, CVSS: 4.0,
Vulners: Exploitation: True
X-Force: Risk: 10
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, <2.15.0, <2.3.1, <2.12.2)
- siemens sppa-t3000 ses3000 firmware (*)
- siemens logo\! soft comfort (*)
- siemens spectrum power 4 (4.70, 4.70, <4.70, 4.70)
- siemens siveillance control pro (*)
have more...
CVE-2021-44832 [Vulners]
Vulners: Score: 6.0, CVSS: 5.3,
Vulners: Exploitation: Unknown
X-Force: Risk: 6.6
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, 2.0, 2.0, <2.3.2, <2.12.4, <2.17.1)
IOCs:
File: 4
Path: 2
Url: 1
Hash: 14
IP: 2
Links:
https://github.com/BishopFox/sliverCisco Talos Blog
Avos ransomware group expands with new attack arsenal
By Flavio Costa,
* In a recent customer engagement, we observed a month-long AvosLocker campaign.
* The attackers utilized several different tools, including Cobalt Strike, Sliver and multiple commercial network scanners.
* The initial ingress point in…
* In a recent customer engagement, we observed a month-long AvosLocker campaign.
* The attackers utilized several different tools, including Cobalt Strike, Sliver and multiple commercial network scanners.
* The initial ingress point in…
#ParsedReport
21-06-2022
MuddyWaters light first-stager targetting Middle East
https://lab52.io/blog/muddywaters-light-first-stager-targetting-middle-east
Actors/Campaigns:
Muddywater
Industry:
Energy, Government
Geo:
Kazakhstan, Syria, Sudan, Israel, Africa, Armenia, Bahrain, Turkey, Argentina, Iran, Pakistan
IOCs:
File: 10
Hash: 13
IP: 3
Functions Names: 2
21-06-2022
MuddyWaters light first-stager targetting Middle East
https://lab52.io/blog/muddywaters-light-first-stager-targetting-middle-east
Actors/Campaigns:
Muddywater
Industry:
Energy, Government
Geo:
Kazakhstan, Syria, Sudan, Israel, Africa, Armenia, Bahrain, Turkey, Argentina, Iran, Pakistan
IOCs:
File: 10
Hash: 13
IP: 3
Functions Names: 2
#technique
https://blog.malwarebytes.com/exploits-and-vulnerabilities/2022/06/dfscoerce-a-new-ntlm-relay-attack-can-take-control-over-a-windows-domain/
https://blog.malwarebytes.com/exploits-and-vulnerabilities/2022/06/dfscoerce-a-new-ntlm-relay-attack-can-take-control-over-a-windows-domain/
Malwarebytes
DFSCoerce, a new NTLM relay attack, can take control over a Windows domain
A researcher has posted a PoC for yet another NTLM relay attack method dubbed DFSCoerce. It is high time to retire NTLM.
#ParsedReport
21-06-2022
Rise of LNK (Shortcut files) Malware
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/rise-of-lnk-shortcut-files-malware
Threats:
Emotet (tags: malware)
Qakbot (tags: malware)
Icedid (tags: malware)
Bazarbackdoor (tags: malware)
Findpos
Hancitor
Ficker_stealer
Dexter
IOCs:
File: 8
Path: 2
Url: 9
Hash: 3
21-06-2022
Rise of LNK (Shortcut files) Malware
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/rise-of-lnk-shortcut-files-malware
Threats:
Emotet (tags: malware)
Qakbot (tags: malware)
Icedid (tags: malware)
Bazarbackdoor (tags: malware)
Findpos
Hancitor
Ficker_stealer
Dexter
IOCs:
File: 8
Path: 2
Url: 9
Hash: 3
McAfee Blog
Rise of LNK (Shortcut files) Malware | McAfee Blog
An LNK file is a Windows Shortcut that serves as a pointer to open a file, folder, or application. LNK files are based on the Shell Link binary file format, which holds information used to access another data object. McAfee Labs has seen a rise in malware…
#ParsedReport
22-06-2022
Chinese actor takes aim, armed with Nim Language and Bizarro AES. Executive Summary
https://research.checkpoint.com/2022/chinese-actor-takes-aim-armed-with-nim-language-and-bizarro-aes
Actors/Campaigns:
Pirate_panda
Ta428
Threats:
Bizarro (tags: proxy, trojan, scan, malware, rat, backdoor, ransomware)
Yahoyah (tags: scan, backdoor, malware)
Zebrocy
Trickbot
Process_doppelganging_technique
Industry:
Financial
Geo:
Philippines, Taiwan, China, Chinese
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 4
Hash: 32
IP: 24
Domain: 2
Functions Names: 1
Links:
22-06-2022
Chinese actor takes aim, armed with Nim Language and Bizarro AES. Executive Summary
https://research.checkpoint.com/2022/chinese-actor-takes-aim-armed-with-nim-language-and-bizarro-aes
Actors/Campaigns:
Pirate_panda
Ta428
Threats:
Bizarro (tags: proxy, trojan, scan, malware, rat, backdoor, ransomware)
Yahoyah (tags: scan, backdoor, malware)
Zebrocy
Trickbot
Process_doppelganging_technique
Industry:
Financial
Geo:
Philippines, Taiwan, China, Chinese
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 4
Hash: 32
IP: 24
Domain: 2
Functions Names: 1
Links:
https://github.com/polymorf/findcrypt-yaraCheck Point Research
Chinese actor takes aim, armed with Nim Language and Bizarro AES - Check Point Research
Executive Summary In this article, Check Point Research shares findings on a group / activity cluster with ties to Tropic Trooper: The infection chain includes a previously undescribed loader (dubbed “Nimbda”) written in Nim language. This loader was observed…
#ParsedReport
22-06-2022
CALISTO continues its credential harvesting campaign
https://blog.sekoia.io/calisto-continues-its-credential-harvesting-campaign
Actors/Campaigns:
Calisto
Coldriver
Fancy_bear
Threats:
Hades
Industry:
Ngo
Geo:
Ukrainian, Russian
IOCs:
Domain: 24
Links:
22-06-2022
CALISTO continues its credential harvesting campaign
https://blog.sekoia.io/calisto-continues-its-credential-harvesting-campaign
Actors/Campaigns:
Calisto
Coldriver
Fancy_bear
Threats:
Hades
Industry:
Ngo
Geo:
Ukrainian, Russian
IOCs:
Domain: 24
Links:
https://github.com/kgretzky/evilginx2Sekoia.io Blog
CALISTO continues its credential harvesting campaign
March 30, 2022, Google TAG published several IOCs related to CALISTO - a Russia-nexus threat actor. Discover our analysis.
#ParsedReport
22-06-2022
From the Front Lines \| 3 New and Emerging Ransomware Threats Striking Businesses in 2022
https://www.sentinelone.com/blog/from-the-front-lines-3-new-and-emerging-ransomware-threats-striking-businesses-in-2022
Actors/Campaigns:
Lapsus
Mindware
Threats:
Zeon (tags: ransomware)
Helloxd (tags: ransomware, malware, rat)
Babuk (tags: ransomware, malware)
Conti (tags: ransomware)
Lockbit (tags: ransomware)
Blackcat (tags: ransomware)
Microbackdoor (tags: ransomware)
Sfile (tags: ransomware)
Industry:
Financial
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 8
IP: 1
Hash: 22
Links:
22-06-2022
From the Front Lines \| 3 New and Emerging Ransomware Threats Striking Businesses in 2022
https://www.sentinelone.com/blog/from-the-front-lines-3-new-and-emerging-ransomware-threats-striking-businesses-in-2022
Actors/Campaigns:
Lapsus
Mindware
Threats:
Zeon (tags: ransomware)
Helloxd (tags: ransomware, malware, rat)
Babuk (tags: ransomware, malware)
Conti (tags: ransomware)
Lockbit (tags: ransomware)
Blackcat (tags: ransomware)
Microbackdoor (tags: ransomware)
Sfile (tags: ransomware)
Industry:
Financial
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 8
IP: 1
Hash: 22
Links:
https://github.com/vbdaga/Rabbit-Cipherhttps://github.com/dashingsoft/pyarmorSentinelOne
From the Front Lines | 3 New and Emerging Ransomware Threats Striking Businesses in 2022
Crimeware continues to evolve at pace with threat actors both iterating on old source code and creating new ransomware families. Stay informed, stay safe.
#ParsedReport
22-06-2022
Improvised Modus Operandi for Targeting Indian Banking Customers via SMS Forwarding Malware
https://cloudsek.com/threatintelligence/improvised-modus-operandi-for-targeting-indian-banking-customers-via-sms-forwarding-malware/?utm_source=rss&utm_medium=rss&utm_campaign=improvised-modus-operandi-for-targeting-indian-banking-customers-via-sms-forwarding-malware
Industry:
Financial
Geo:
Indian, India
TTPs:
Tactics: 2
Technics: 0
IOCs:
Domain: 5
File: 2
IP: 1
Hash: 1
Url: 3
Functions Names: 3
22-06-2022
Improvised Modus Operandi for Targeting Indian Banking Customers via SMS Forwarding Malware
https://cloudsek.com/threatintelligence/improvised-modus-operandi-for-targeting-indian-banking-customers-via-sms-forwarding-malware/?utm_source=rss&utm_medium=rss&utm_campaign=improvised-modus-operandi-for-targeting-indian-banking-customers-via-sms-forwarding-malware
Industry:
Financial
Geo:
Indian, India
TTPs:
Tactics: 2
Technics: 0
IOCs:
Domain: 5
File: 2
IP: 1
Hash: 1
Url: 3
Functions Names: 3
CloudSEK - Digital Risk Management Enterprise | Artificial Intelligence based Cybersecurity
Improvised Modus Operandi for Targeting Indian Banking Customers via SMS Forwarding Malware - CloudSEK
CloudSEK team has uncovered a banking trojan (SMS Forwarding Malware, with improvised modus operandi, where the threat actor or a group of threat actors host a simple fake online complaint portal having the domains and target Indian banking customers.
#ParsedReport
22-06-2022
Cybercriminals Exploit Reverse Tunnel Services and URL Shorteners to Launch Large-Scale Phishing Campaigns
https://cloudsek.com/threatintelligence/cybercriminals-exploit-reverse-tunnel-services-and-url-shorteners-to-launch-large-scale-phishing-campaigns/?utm_source=rss&utm_medium=rss&utm_campaign=cybercriminals-exploit-reverse-tunnel-services-and-url-shorteners-to-launch-large-scale-phishing-campaigns
Industry:
Financial
Geo:
Indian
TTPs:
Tactics: 1
Technics: 0
IOCs:
Domain: 3
Url: 6
22-06-2022
Cybercriminals Exploit Reverse Tunnel Services and URL Shorteners to Launch Large-Scale Phishing Campaigns
https://cloudsek.com/threatintelligence/cybercriminals-exploit-reverse-tunnel-services-and-url-shorteners-to-launch-large-scale-phishing-campaigns/?utm_source=rss&utm_medium=rss&utm_campaign=cybercriminals-exploit-reverse-tunnel-services-and-url-shorteners-to-launch-large-scale-phishing-campaigns
Industry:
Financial
Geo:
Indian
TTPs:
Tactics: 1
Technics: 0
IOCs:
Domain: 3
Url: 6
#ParsedReport
22-06-2022
Quantum Software: LNK file-based builders growing in popularity. Possibly associated with Lazarus APT group
https://blog.cyble.com/2022/06/22/quantum-software-lnk-file-based-builders-growing-in-popularity
Actors/Campaigns:
Lazarus
Kimsuky
Threats:
Emotet
Bumblebee
Qakbot
Icedid
Lolbin
Dogwalk_vuln
TTPs:
Tactics: 3
Technics: 5
IOCs:
File: 2
Path: 1
Url: 1
Hash: 2
22-06-2022
Quantum Software: LNK file-based builders growing in popularity. Possibly associated with Lazarus APT group
https://blog.cyble.com/2022/06/22/quantum-software-lnk-file-based-builders-growing-in-popularity
Actors/Campaigns:
Lazarus
Kimsuky
Threats:
Emotet
Bumblebee
Qakbot
Icedid
Lolbin
Dogwalk_vuln
TTPs:
Tactics: 3
Technics: 5
IOCs:
File: 2
Path: 1
Url: 1
Hash: 2
Cyble
Quantum Software: LNK File Builders Gain Popularity
Cyble analyzes Quantum Software, a .lnk -based builder with possible links to the Lazarus APT Group.
#ParsedReport
22-06-2022
Distribution of LockBit ransomware through email impersonating copyright
https://asec-ahnlab-com.translate.goog/ko/35481/?_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Threats:
Lockbit (tags: phishing, malware, ransomware)
Malware/mdp.systemmanipulation.m1751 (tags: ransomware)
IOCs:
File: 14
Hash: 2
22-06-2022
Distribution of LockBit ransomware through email impersonating copyright
https://asec-ahnlab-com.translate.goog/ko/35481/?_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Threats:
Lockbit (tags: phishing, malware, ransomware)
Malware/mdp.systemmanipulation.m1751 (tags: ransomware)
IOCs:
File: 14
Hash: 2
ASEC BLOG
저작권 사칭 메일을 통한 LockBit 랜섬웨어 유포 - ASEC BLOG
ASEC 분석팀은 이전에 소개한 방식과 동일한 저작권법 위반의 내용으로 사칭한 피싱 메일을 통해 LockBit 랜섬웨어가 다시 유포되고 있음을 확인하였다. 지난 2월 유포되었던 피싱 메일(아래 링크 참고) 본문과 유사한 내용으로 작성되었으며 기존처럼 첨부된 파일명에 압축 파일의 비밀번호를 포함하여 유포하였다. 지원서 및 저작권 관련 메일로 LockBit 랜섬웨어 유포 중 [그림 2]와 같이 피싱 메일에 첨부된 압축 파일 내부에 추가 압축 파일이 존재하는…
#ParsedReport
22-06-2022
New information stealing malware, crack disguise is being distributed
https://asec-ahnlab-com.translate.goog/ko/35549/?_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Threats:
Cryptbot_stealer (tags: malware)
Redline_stealer (tags: malware)
Vidar_stealer (tags: malware)
Raccoon_stealer (tags: malware)
Recordbreaker_stealer (tags: malware)
Exodus (tags: malware)
Clipbanker (tags: malware)
Infostealer/win.recordstealer.r498039 (tags: malware)
Infostealer/win.recordstealer.r500009 (tags: malware)
Infostealer/win.passstealer.r496906 (tags: malware)
IOCs:
Url: 9
Coin: 9
Hash: 230
Domain: 26
22-06-2022
New information stealing malware, crack disguise is being distributed
https://asec-ahnlab-com.translate.goog/ko/35549/?_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Threats:
Cryptbot_stealer (tags: malware)
Redline_stealer (tags: malware)
Vidar_stealer (tags: malware)
Raccoon_stealer (tags: malware)
Recordbreaker_stealer (tags: malware)
Exodus (tags: malware)
Clipbanker (tags: malware)
Infostealer/win.recordstealer.r498039 (tags: malware)
Infostealer/win.recordstealer.r500009 (tags: malware)
Infostealer/win.passstealer.r496906 (tags: malware)
IOCs:
Url: 9
Coin: 9
Hash: 230
Domain: 26
ASEC BLOG
신종 정보탈취 악성코드, 크랙 위장 유포 중 - ASEC BLOG
ASEC 분석팀은 S/W 크랙 및 인스톨러로 위장하여 유포되는 다양한 악성코드를 소개한 바 있다. CryptBot, RedLine, Vidar 악성코드가 대표적이다. 최근 단일 악성코드 형태의 RedLine 악성코드가 자취를 감추고(드로퍼 유형으로는 유포 중) 신종 정보 탈취 악성코드가 활발히 유포 중이다. 5월 20일 경부터 본격적으로 유포되기 시작하였으며, 해외에서는 해당 악성코드를 “Recordbreaker Stealer”로 분류하고 있으며, Raccoon…
#ParsedReport
23-06-2022
Windows MSDT Zero-day Vulnerability DogWalk Detected by V3
https://asec.ahnlab.com/en/35681
Threats:
Dogwalk_vuln (tags: malware)
Follina_vuln
IOCs:
File: 1
Path: 1
23-06-2022
Windows MSDT Zero-day Vulnerability DogWalk Detected by V3
https://asec.ahnlab.com/en/35681
Threats:
Dogwalk_vuln (tags: malware)
Follina_vuln
IOCs:
File: 1
Path: 1
ASEC BLOG
Windows MSDT Zero-day Vulnerability 'DogWalk' Detected by V3 - ASEC BLOG
On June 8th, a new Windows Zero-day vulnerability named DogWalk was revealed by Hacker News (thehackernews.com). Similar to that of Follina vulnerability that targeted MS Office document files, this is a vulnerability that occurs from MSDT (Microsoft Support…
#ParsedReport
23-06-2022
Spyware vendor targets users in Italy and Kazakhstan
https://blog.google/threat-analysis-group/italian-spyware-vendor-targets-users-in-italy-and-kazakhstan
Threats:
Lightspeed_vuln
Sockpuppet_vuln
Timewaste_vuln
Avecesare_vuln
Clicked_vuln
Industry:
Telco, Government
Geo:
Italy, Kazakhstan
CVEs:
CVE-2020-9907 [Vulners]
Vulners: Score: 9.3, CVSS: 4.6,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- apple ipad os (<13.6)
- apple iphone os (<13.6)
- apple tvos (<13.4.8)
CVE-2021-30883 [Vulners]
Vulners: Score: 9.3, CVSS: 3.1,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- apple ipad os (<14.8.1, 15.0, 15.0.1)
- apple iphone os (<14.8.1, 15.0, 15.0.1)
- apple macos (<11.6.1, 12.0)
- apple tvos (<15.1)
- apple watchos (<8.1)
have more...
CVE-2020-3837 [Vulners]
Vulners: Score: 9.3, CVSS: 5.8,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- apple ipados (<13.3.1)
- apple iphone os (<13.3.1)
- apple mac os x (<10.15.3)
- apple tvos (<13.3.1)
- apple watchos (<6.1.2)
have more...
CVE-2018-4344 [Vulners]
Vulners: Score: 9.3, CVSS: 4.4,
Vulners: Exploitation: Unknown
X-Force: Risk: 8.4
X-Force: Patch: Official fix
Soft:
- apple iphone os (<12.0)
- apple mac os x (<10.14)
- apple tvos (<12)
- apple watchos (<5.0)
CVE-2021-30983 [Vulners]
Vulners: Score: 9.3, CVSS: 4.7,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- apple ipados (<15.2)
- apple iphone os (<15.2)
CVE-2019-8605 [Vulners]
Vulners: Score: 9.3, CVSS: 5.7,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- apple iphone os (<12.3)
- apple mac os x (<10.14.5)
- apple tvos (<12.3)
- apple watchos (<5.2.1)
IOCs:
Domain: 18
Hash: 9
IP: 4
23-06-2022
Spyware vendor targets users in Italy and Kazakhstan
https://blog.google/threat-analysis-group/italian-spyware-vendor-targets-users-in-italy-and-kazakhstan
Threats:
Lightspeed_vuln
Sockpuppet_vuln
Timewaste_vuln
Avecesare_vuln
Clicked_vuln
Industry:
Telco, Government
Geo:
Italy, Kazakhstan
CVEs:
CVE-2020-9907 [Vulners]
Vulners: Score: 9.3, CVSS: 4.6,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- apple ipad os (<13.6)
- apple iphone os (<13.6)
- apple tvos (<13.4.8)
CVE-2021-30883 [Vulners]
Vulners: Score: 9.3, CVSS: 3.1,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- apple ipad os (<14.8.1, 15.0, 15.0.1)
- apple iphone os (<14.8.1, 15.0, 15.0.1)
- apple macos (<11.6.1, 12.0)
- apple tvos (<15.1)
- apple watchos (<8.1)
have more...
CVE-2020-3837 [Vulners]
Vulners: Score: 9.3, CVSS: 5.8,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- apple ipados (<13.3.1)
- apple iphone os (<13.3.1)
- apple mac os x (<10.15.3)
- apple tvos (<13.3.1)
- apple watchos (<6.1.2)
have more...
CVE-2018-4344 [Vulners]
Vulners: Score: 9.3, CVSS: 4.4,
Vulners: Exploitation: Unknown
X-Force: Risk: 8.4
X-Force: Patch: Official fix
Soft:
- apple iphone os (<12.0)
- apple mac os x (<10.14)
- apple tvos (<12)
- apple watchos (<5.0)
CVE-2021-30983 [Vulners]
Vulners: Score: 9.3, CVSS: 4.7,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- apple ipados (<15.2)
- apple iphone os (<15.2)
CVE-2019-8605 [Vulners]
Vulners: Score: 9.3, CVSS: 5.7,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- apple iphone os (<12.3)
- apple mac os x (<10.14.5)
- apple tvos (<12.3)
- apple watchos (<5.2.1)
IOCs:
Domain: 18
Hash: 9
IP: 4
Google
Spyware vendor targets users in Italy and Kazakhstan
Today, alongside Google’s Project Zero, we are detailing capabilities provided by RCS Labs, an Italian vendor that uses a combination of tactics, including atypical drive-by downloads as initial infection vectors to target mobile users on both iOS and Android.
#ParsedReport
23-06-2022
Malicious Cyber Actors Continue to Exploit Log4Shell in VMware Horizon Systems
https://us-cert.cisa.gov/ncas/current-activity/2022/06/23/malicious-cyber-actors-continue-exploit-log4shell-vmware-horizon
Actors/Campaigns:
Karakurt
Threats:
Log4shell_vuln
Spring4shell
Geo:
China
CVEs:
CVE-2021-44228 [Vulners]
Vulners: Score: 9.3, CVSS: 4.0,
Vulners: Exploitation: True
X-Force: Risk: 10
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, <2.15.0, <2.3.1, <2.12.2)
- siemens sppa-t3000 ses3000 firmware (*)
- siemens logo\! soft comfort (*)
- siemens spectrum power 4 (4.70, 4.70, <4.70, 4.70)
- siemens siveillance control pro (*)
have more...
23-06-2022
Malicious Cyber Actors Continue to Exploit Log4Shell in VMware Horizon Systems
https://us-cert.cisa.gov/ncas/current-activity/2022/06/23/malicious-cyber-actors-continue-exploit-log4shell-vmware-horizon
Actors/Campaigns:
Karakurt
Threats:
Log4shell_vuln
Spring4shell
Geo:
China
CVEs:
CVE-2021-44228 [Vulners]
Vulners: Score: 9.3, CVSS: 4.0,
Vulners: Exploitation: True
X-Force: Risk: 10
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, <2.15.0, <2.3.1, <2.12.2)
- siemens sppa-t3000 ses3000 firmware (*)
- siemens logo\! soft comfort (*)
- siemens spectrum power 4 (4.70, 4.70, <4.70, 4.70)
- siemens siveillance control pro (*)
have more...
www.cisa.gov
Malicious Cyber Actors Continue to Exploit Log4Shell in VMware Horizon Systems | CISA
CISA and the United States Coast Guard Cyber Command (CGCYBER) have released a joint Cybersecurity Advisory (CSA) to warn network defenders that cyber threat actors, including state-sponsored advanced persistent threat (APT) actors, have continued to exploit…
#ParsedReport
24-06-2022
eSentire Threat Intelligence Malware Analysis: PINGPULL RAT
https://www.esentire.com/blog/esentire-threat-intelligence-malware-analysis-pingpull-rat
Threats:
Pingpull (tags: malware, backdoor, rat, scan)
Log4shell_vuln
Netstat_tool
Industry:
Government, Telco
Geo:
Russia, Apac, Asia, America, Emea, Africa, Vietnam
IOCs:
File: 9
Hash: 6
IP: 1
Domain: 8
Functions Names: 11
YARA: Found
24-06-2022
eSentire Threat Intelligence Malware Analysis: PINGPULL RAT
https://www.esentire.com/blog/esentire-threat-intelligence-malware-analysis-pingpull-rat
Threats:
Pingpull (tags: malware, backdoor, rat, scan)
Log4shell_vuln
Netstat_tool
Industry:
Government, Telco
Geo:
Russia, Apac, Asia, America, Emea, Africa, Vietnam
IOCs:
File: 9
Hash: 6
IP: 1
Domain: 8
Functions Names: 11
YARA: Found
eSentire
eSentire Threat Intelligence Malware Analysis: PINGPULL RAT
Dive deeper into the technical details gathered during eSentire’s Threat Response Unit (TRU) team’s research and threat analysis of the PINGPULL Remote Access Tool.
#ParsedReport
24-06-2022
LockBit Ransomware Disguised as Copyright Claim E-mail Being Distributed
https://asec.ahnlab.com/en/35822
Threats:
Lockbit (tags: ransomware, malware, phishing)
Malware/mdp.systemmanipulation.m1751 (tags: ransomware)
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 14
Hash: 2
24-06-2022
LockBit Ransomware Disguised as Copyright Claim E-mail Being Distributed
https://asec.ahnlab.com/en/35822
Threats:
Lockbit (tags: ransomware, malware, phishing)
Malware/mdp.systemmanipulation.m1751 (tags: ransomware)
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 14
Hash: 2
ASEC BLOG
LockBit Ransomware Disguised as Copyright Claim E-mail Being Distributed - ASEC BLOG
The ASEC analysis team has once again discovered the distribution of LockBit ransomware using phishing e-mail, and disguising itself as copyright claims e-mail which was introduced in the previous blog. The filename of the attachment in e-mail had password…
#ParsedReport
24-06-2022
Socgholish to Cobalt Strike in 10 Minutes
https://www.esentire.com/blog/socgholish-to-cobalt-strike-in-10-minutes
Threats:
Cobalt_strike (tags: malware, phishing)
Socgholish_loader (tags: malware, phishing)
Kerberoasting_technique
Gootkit
Solarmarker
Geo:
America, Emea, Africa, Apac
IOCs:
File: 7
Hash: 2
Domain: 3
24-06-2022
Socgholish to Cobalt Strike in 10 Minutes
https://www.esentire.com/blog/socgholish-to-cobalt-strike-in-10-minutes
Threats:
Cobalt_strike (tags: malware, phishing)
Socgholish_loader (tags: malware, phishing)
Kerberoasting_technique
Gootkit
Solarmarker
Geo:
America, Emea, Africa, Apac
IOCs:
File: 7
Hash: 2
Domain: 3
eSentire
Socgholish to Cobalt Strike in 10 Minutes
Learn about the Socgholish malware including what we found, how we found it and recommendations from our Threat Response Unit (TRU) to protect your business from this cyber threat.
#ParsedReport
24-06-2022
NightLion Worm Strikes Again. Worm targeting openly accessible Elasticsearch Servers
https://blog.cyble.com/2022/06/24/nightlion-worm-strikes-again
Geo:
China
24-06-2022
NightLion Worm Strikes Again. Worm targeting openly accessible Elasticsearch Servers
https://blog.cyble.com/2022/06/24/nightlion-worm-strikes-again
Geo:
China
Cyble
“NightLion” Worm Strikes Again
Cyble analyzes the resurfaced "NightLion", a worm that targets vulnerable, openly-accessible Elasticsearch Servers.