CTT Report Hub
3.43K subscribers
9.94K photos
6 videos
67 files
13.6K links
Threat Intelligence Report Hub
Download Telegram
#ParsedReport
21-06-2022

New IceXLoader 3.0 Developers Warm Up to Nim

https://www.fortinet.com/blog/threat-research/new-icexloader-3-0-developers-warm-up-to-nim

Threats:
Icexloader (tags: malware, ransomware, trojan, stealer, scan, phishing, rat, dropper, cryptomining)
Bazarnimrod
Bazarbackdoor
Trickbot
Ice_ix
Zeus
Xmr_miner
Dcrat_rat

Industry:
Financial

TTPs:
Tactics: 2
Technics: 0

IOCs:
Path: 1
File: 2
Hash: 8
Url: 12

Functions Names: 1
#ParsedReport
21-06-2022

Matanbuchus: Malware-as-a-Service with Demonic Intentions

https://unit42.paloaltonetworks.com/matanbuchus-malware-as-a-service

Actors/Campaigns:
Belialdemon

Threats:
Triumph_loader

Industry:
Education, E-commerce

Geo:
Japanese, Austria, Belgium

IOCs:
File: 12
Url: 1
Hash: 3
Domain: 35
IP: 3
Path: 2

Functions Names: 2
#ParsedReport
21-06-2022

Avos ransomware group expands with new attack arsenal

http://blog.talosintelligence.com/2022/06/avoslocker-new-arsenal.html

Actors/Campaigns:
Avos (motivation: financiallymotivated)

Threats:
Avoslocker (tags: ransomware)
Cobalt_strike (tags: ransomware)
Sliver_tool (tags: ransomware)
Log4shell_vuln (tags: ransomware)
Lolbin
Darkcomet_rat
Mimikatz
Beacon

Geo:
Russian

CVEs:
CVE-2021-45105 [Vulners]
Vulners: Score: 4.3, CVSS: 5.4,
Vulners: Exploitation: True
X-Force: Risk: 7.5
X-Force: Patch: Official fix
Soft:
- apache log4j (<2.3.1, <2.12.3, le2.16.0)
- netapp cloud manager (-)
- debian debian linux (10.0, 11.0)
- sonicwall email security (le10.0.12)
- sonicwall network security manager (<3.0, <3.0)
have more...
CVE-2021-45046 [Vulners]
Vulners: Score: 5.1, CVSS: 3.2,
Vulners: Exploitation: True
X-Force: Risk: 9
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, <2.12.2, <2.16.0)
- intel audio development kit (-)
- intel computer vision annotation tool (-)
- intel datacenter manager (-)
- intel genomics kernel library (-)
have more...
CVE-2021-44228 [Vulners]
Vulners: Score: 9.3, CVSS: 4.0,
Vulners: Exploitation: True
X-Force: Risk: 10
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, <2.15.0, <2.3.1, <2.12.2)
- siemens sppa-t3000 ses3000 firmware (*)
- siemens logo\! soft comfort (*)
- siemens spectrum power 4 (4.70, 4.70, <4.70, 4.70)
- siemens siveillance control pro (*)
have more...
CVE-2021-44832 [Vulners]
Vulners: Score: 6.0, CVSS: 5.3,
Vulners: Exploitation: Unknown
X-Force: Risk: 6.6
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, 2.0, 2.0, <2.3.2, <2.12.4, <2.17.1)


IOCs:
File: 4
Path: 2
Url: 1
Hash: 14
IP: 2

Links:
https://github.com/BishopFox/sliver
#ParsedReport
21-06-2022

MuddyWaters light first-stager targetting Middle East

https://lab52.io/blog/muddywaters-light-first-stager-targetting-middle-east

Actors/Campaigns:
Muddywater

Industry:
Energy, Government

Geo:
Kazakhstan, Syria, Sudan, Israel, Africa, Armenia, Bahrain, Turkey, Argentina, Iran, Pakistan

IOCs:
File: 10
Hash: 13
IP: 3

Functions Names: 2
#ParsedReport
22-06-2022

Chinese actor takes aim, armed with Nim Language and Bizarro AES. Executive Summary

https://research.checkpoint.com/2022/chinese-actor-takes-aim-armed-with-nim-language-and-bizarro-aes

Actors/Campaigns:
Pirate_panda
Ta428

Threats:
Bizarro (tags: proxy, trojan, scan, malware, rat, backdoor, ransomware)
Yahoyah (tags: scan, backdoor, malware)
Zebrocy
Trickbot
Process_doppelganging_technique

Industry:
Financial

Geo:
Philippines, Taiwan, China, Chinese

TTPs:
Tactics: 1
Technics: 0

IOCs:
File: 4
Hash: 32
IP: 24
Domain: 2

Functions Names: 1

Links:
https://github.com/polymorf/findcrypt-yara
#ParsedReport
22-06-2022

CALISTO continues its credential harvesting campaign

https://blog.sekoia.io/calisto-continues-its-credential-harvesting-campaign

Actors/Campaigns:
Calisto
Coldriver
Fancy_bear

Threats:
Hades

Industry:
Ngo

Geo:
Ukrainian, Russian

IOCs:
Domain: 24

Links:
https://github.com/kgretzky/evilginx2
#ParsedReport
22-06-2022

From the Front Lines \| 3 New and Emerging Ransomware Threats Striking Businesses in 2022

https://www.sentinelone.com/blog/from-the-front-lines-3-new-and-emerging-ransomware-threats-striking-businesses-in-2022

Actors/Campaigns:
Lapsus
Mindware

Threats:
Zeon (tags: ransomware)
Helloxd (tags: ransomware, malware, rat)
Babuk (tags: ransomware, malware)
Conti (tags: ransomware)
Lockbit (tags: ransomware)
Blackcat (tags: ransomware)
Microbackdoor (tags: ransomware)
Sfile (tags: ransomware)

Industry:
Financial

TTPs:
Tactics: 1
Technics: 0

IOCs:
File: 8
IP: 1
Hash: 22

Links:
https://github.com/vbdaga/Rabbit-Cipher
https://github.com/dashingsoft/pyarmor
#ParsedReport
22-06-2022

Quantum Software: LNK file-based builders growing in popularity. Possibly associated with Lazarus APT group

https://blog.cyble.com/2022/06/22/quantum-software-lnk-file-based-builders-growing-in-popularity

Actors/Campaigns:
Lazarus
Kimsuky

Threats:
Emotet
Bumblebee
Qakbot
Icedid
Lolbin
Dogwalk_vuln

TTPs:
Tactics: 3
Technics: 5

IOCs:
File: 2
Path: 1
Url: 1
Hash: 2
#ParsedReport
23-06-2022

Spyware vendor targets users in Italy and Kazakhstan

https://blog.google/threat-analysis-group/italian-spyware-vendor-targets-users-in-italy-and-kazakhstan

Threats:
Lightspeed_vuln
Sockpuppet_vuln
Timewaste_vuln
Avecesare_vuln
Clicked_vuln

Industry:
Telco, Government

Geo:
Italy, Kazakhstan

CVEs:
CVE-2020-9907 [Vulners]
Vulners: Score: 9.3, CVSS: 4.6,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- apple ipad os (<13.6)
- apple iphone os (<13.6)
- apple tvos (<13.4.8)

CVE-2021-30883 [Vulners]
Vulners: Score: 9.3, CVSS: 3.1,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- apple ipad os (<14.8.1, 15.0, 15.0.1)
- apple iphone os (<14.8.1, 15.0, 15.0.1)
- apple macos (<11.6.1, 12.0)
- apple tvos (<15.1)
- apple watchos (<8.1)
have more...
CVE-2020-3837 [Vulners]
Vulners: Score: 9.3, CVSS: 5.8,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- apple ipados (<13.3.1)
- apple iphone os (<13.3.1)
- apple mac os x (<10.15.3)
- apple tvos (<13.3.1)
- apple watchos (<6.1.2)
have more...
CVE-2018-4344 [Vulners]
Vulners: Score: 9.3, CVSS: 4.4,
Vulners: Exploitation: Unknown
X-Force: Risk: 8.4
X-Force: Patch: Official fix
Soft:
- apple iphone os (<12.0)
- apple mac os x (<10.14)
- apple tvos (<12)
- apple watchos (<5.0)

CVE-2021-30983 [Vulners]
Vulners: Score: 9.3, CVSS: 4.7,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- apple ipados (<15.2)
- apple iphone os (<15.2)

CVE-2019-8605 [Vulners]
Vulners: Score: 9.3, CVSS: 5.7,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- apple iphone os (<12.3)
- apple mac os x (<10.14.5)
- apple tvos (<12.3)
- apple watchos (<5.2.1)


IOCs:
Domain: 18
Hash: 9
IP: 4
#ParsedReport
23-06-2022

Malicious Cyber Actors Continue to Exploit Log4Shell in VMware Horizon Systems

https://us-cert.cisa.gov/ncas/current-activity/2022/06/23/malicious-cyber-actors-continue-exploit-log4shell-vmware-horizon

Actors/Campaigns:
Karakurt

Threats:
Log4shell_vuln
Spring4shell

Geo:
China

CVEs:
CVE-2021-44228 [Vulners]
Vulners: Score: 9.3, CVSS: 4.0,
Vulners: Exploitation: True
X-Force: Risk: 10
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, <2.15.0, <2.3.1, <2.12.2)
- siemens sppa-t3000 ses3000 firmware (*)
- siemens logo\! soft comfort (*)
- siemens spectrum power 4 (4.70, 4.70, <4.70, 4.70)
- siemens siveillance control pro (*)
have more...
#ParsedReport
24-06-2022

eSentire Threat Intelligence Malware Analysis: PINGPULL RAT

https://www.esentire.com/blog/esentire-threat-intelligence-malware-analysis-pingpull-rat

Threats:
Pingpull (tags: malware, backdoor, rat, scan)
Log4shell_vuln
Netstat_tool

Industry:
Government, Telco

Geo:
Russia, Apac, Asia, America, Emea, Africa, Vietnam

IOCs:
File: 9
Hash: 6
IP: 1
Domain: 8

Functions Names: 11

YARA: Found
#ParsedReport
24-06-2022

Socgholish to Cobalt Strike in 10 Minutes

https://www.esentire.com/blog/socgholish-to-cobalt-strike-in-10-minutes

Threats:
Cobalt_strike (tags: malware, phishing)
Socgholish_loader (tags: malware, phishing)
Kerberoasting_technique
Gootkit
Solarmarker

Geo:
America, Emea, Africa, Apac

IOCs:
File: 7
Hash: 2
Domain: 3