#ParsedReport
22-06-2022
New information stealing malware, crack disguise is being distributed
https://asec-ahnlab-com.translate.goog/ko/35549/?_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Threats:
Cryptbot_stealer (tags: malware)
Redline_stealer (tags: malware)
Vidar_stealer (tags: malware)
Raccoon_stealer (tags: malware)
Recordbreaker_stealer (tags: malware)
Exodus (tags: malware)
Clipbanker (tags: malware)
Infostealer/win.recordstealer.r498039 (tags: malware)
Infostealer/win.recordstealer.r500009 (tags: malware)
Infostealer/win.passstealer.r496906 (tags: malware)
IOCs:
Url: 9
Coin: 9
Hash: 230
Domain: 26
22-06-2022
New information stealing malware, crack disguise is being distributed
https://asec-ahnlab-com.translate.goog/ko/35549/?_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Threats:
Cryptbot_stealer (tags: malware)
Redline_stealer (tags: malware)
Vidar_stealer (tags: malware)
Raccoon_stealer (tags: malware)
Recordbreaker_stealer (tags: malware)
Exodus (tags: malware)
Clipbanker (tags: malware)
Infostealer/win.recordstealer.r498039 (tags: malware)
Infostealer/win.recordstealer.r500009 (tags: malware)
Infostealer/win.passstealer.r496906 (tags: malware)
IOCs:
Url: 9
Coin: 9
Hash: 230
Domain: 26
ASEC BLOG
신종 정보탈취 악성코드, 크랙 위장 유포 중 - ASEC BLOG
ASEC 분석팀은 S/W 크랙 및 인스톨러로 위장하여 유포되는 다양한 악성코드를 소개한 바 있다. CryptBot, RedLine, Vidar 악성코드가 대표적이다. 최근 단일 악성코드 형태의 RedLine 악성코드가 자취를 감추고(드로퍼 유형으로는 유포 중) 신종 정보 탈취 악성코드가 활발히 유포 중이다. 5월 20일 경부터 본격적으로 유포되기 시작하였으며, 해외에서는 해당 악성코드를 “Recordbreaker Stealer”로 분류하고 있으며, Raccoon…
#ParsedReport
23-06-2022
Windows MSDT Zero-day Vulnerability DogWalk Detected by V3
https://asec.ahnlab.com/en/35681
Threats:
Dogwalk_vuln (tags: malware)
Follina_vuln
IOCs:
File: 1
Path: 1
23-06-2022
Windows MSDT Zero-day Vulnerability DogWalk Detected by V3
https://asec.ahnlab.com/en/35681
Threats:
Dogwalk_vuln (tags: malware)
Follina_vuln
IOCs:
File: 1
Path: 1
ASEC BLOG
Windows MSDT Zero-day Vulnerability 'DogWalk' Detected by V3 - ASEC BLOG
On June 8th, a new Windows Zero-day vulnerability named DogWalk was revealed by Hacker News (thehackernews.com). Similar to that of Follina vulnerability that targeted MS Office document files, this is a vulnerability that occurs from MSDT (Microsoft Support…
#ParsedReport
23-06-2022
Spyware vendor targets users in Italy and Kazakhstan
https://blog.google/threat-analysis-group/italian-spyware-vendor-targets-users-in-italy-and-kazakhstan
Threats:
Lightspeed_vuln
Sockpuppet_vuln
Timewaste_vuln
Avecesare_vuln
Clicked_vuln
Industry:
Telco, Government
Geo:
Italy, Kazakhstan
CVEs:
CVE-2020-9907 [Vulners]
Vulners: Score: 9.3, CVSS: 4.6,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- apple ipad os (<13.6)
- apple iphone os (<13.6)
- apple tvos (<13.4.8)
CVE-2021-30883 [Vulners]
Vulners: Score: 9.3, CVSS: 3.1,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- apple ipad os (<14.8.1, 15.0, 15.0.1)
- apple iphone os (<14.8.1, 15.0, 15.0.1)
- apple macos (<11.6.1, 12.0)
- apple tvos (<15.1)
- apple watchos (<8.1)
have more...
CVE-2020-3837 [Vulners]
Vulners: Score: 9.3, CVSS: 5.8,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- apple ipados (<13.3.1)
- apple iphone os (<13.3.1)
- apple mac os x (<10.15.3)
- apple tvos (<13.3.1)
- apple watchos (<6.1.2)
have more...
CVE-2018-4344 [Vulners]
Vulners: Score: 9.3, CVSS: 4.4,
Vulners: Exploitation: Unknown
X-Force: Risk: 8.4
X-Force: Patch: Official fix
Soft:
- apple iphone os (<12.0)
- apple mac os x (<10.14)
- apple tvos (<12)
- apple watchos (<5.0)
CVE-2021-30983 [Vulners]
Vulners: Score: 9.3, CVSS: 4.7,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- apple ipados (<15.2)
- apple iphone os (<15.2)
CVE-2019-8605 [Vulners]
Vulners: Score: 9.3, CVSS: 5.7,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- apple iphone os (<12.3)
- apple mac os x (<10.14.5)
- apple tvos (<12.3)
- apple watchos (<5.2.1)
IOCs:
Domain: 18
Hash: 9
IP: 4
23-06-2022
Spyware vendor targets users in Italy and Kazakhstan
https://blog.google/threat-analysis-group/italian-spyware-vendor-targets-users-in-italy-and-kazakhstan
Threats:
Lightspeed_vuln
Sockpuppet_vuln
Timewaste_vuln
Avecesare_vuln
Clicked_vuln
Industry:
Telco, Government
Geo:
Italy, Kazakhstan
CVEs:
CVE-2020-9907 [Vulners]
Vulners: Score: 9.3, CVSS: 4.6,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- apple ipad os (<13.6)
- apple iphone os (<13.6)
- apple tvos (<13.4.8)
CVE-2021-30883 [Vulners]
Vulners: Score: 9.3, CVSS: 3.1,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- apple ipad os (<14.8.1, 15.0, 15.0.1)
- apple iphone os (<14.8.1, 15.0, 15.0.1)
- apple macos (<11.6.1, 12.0)
- apple tvos (<15.1)
- apple watchos (<8.1)
have more...
CVE-2020-3837 [Vulners]
Vulners: Score: 9.3, CVSS: 5.8,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- apple ipados (<13.3.1)
- apple iphone os (<13.3.1)
- apple mac os x (<10.15.3)
- apple tvos (<13.3.1)
- apple watchos (<6.1.2)
have more...
CVE-2018-4344 [Vulners]
Vulners: Score: 9.3, CVSS: 4.4,
Vulners: Exploitation: Unknown
X-Force: Risk: 8.4
X-Force: Patch: Official fix
Soft:
- apple iphone os (<12.0)
- apple mac os x (<10.14)
- apple tvos (<12)
- apple watchos (<5.0)
CVE-2021-30983 [Vulners]
Vulners: Score: 9.3, CVSS: 4.7,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- apple ipados (<15.2)
- apple iphone os (<15.2)
CVE-2019-8605 [Vulners]
Vulners: Score: 9.3, CVSS: 5.7,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- apple iphone os (<12.3)
- apple mac os x (<10.14.5)
- apple tvos (<12.3)
- apple watchos (<5.2.1)
IOCs:
Domain: 18
Hash: 9
IP: 4
Google
Spyware vendor targets users in Italy and Kazakhstan
Today, alongside Google’s Project Zero, we are detailing capabilities provided by RCS Labs, an Italian vendor that uses a combination of tactics, including atypical drive-by downloads as initial infection vectors to target mobile users on both iOS and Android.
#ParsedReport
23-06-2022
Malicious Cyber Actors Continue to Exploit Log4Shell in VMware Horizon Systems
https://us-cert.cisa.gov/ncas/current-activity/2022/06/23/malicious-cyber-actors-continue-exploit-log4shell-vmware-horizon
Actors/Campaigns:
Karakurt
Threats:
Log4shell_vuln
Spring4shell
Geo:
China
CVEs:
CVE-2021-44228 [Vulners]
Vulners: Score: 9.3, CVSS: 4.0,
Vulners: Exploitation: True
X-Force: Risk: 10
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, <2.15.0, <2.3.1, <2.12.2)
- siemens sppa-t3000 ses3000 firmware (*)
- siemens logo\! soft comfort (*)
- siemens spectrum power 4 (4.70, 4.70, <4.70, 4.70)
- siemens siveillance control pro (*)
have more...
23-06-2022
Malicious Cyber Actors Continue to Exploit Log4Shell in VMware Horizon Systems
https://us-cert.cisa.gov/ncas/current-activity/2022/06/23/malicious-cyber-actors-continue-exploit-log4shell-vmware-horizon
Actors/Campaigns:
Karakurt
Threats:
Log4shell_vuln
Spring4shell
Geo:
China
CVEs:
CVE-2021-44228 [Vulners]
Vulners: Score: 9.3, CVSS: 4.0,
Vulners: Exploitation: True
X-Force: Risk: 10
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, <2.15.0, <2.3.1, <2.12.2)
- siemens sppa-t3000 ses3000 firmware (*)
- siemens logo\! soft comfort (*)
- siemens spectrum power 4 (4.70, 4.70, <4.70, 4.70)
- siemens siveillance control pro (*)
have more...
www.cisa.gov
Malicious Cyber Actors Continue to Exploit Log4Shell in VMware Horizon Systems | CISA
CISA and the United States Coast Guard Cyber Command (CGCYBER) have released a joint Cybersecurity Advisory (CSA) to warn network defenders that cyber threat actors, including state-sponsored advanced persistent threat (APT) actors, have continued to exploit…
#ParsedReport
24-06-2022
eSentire Threat Intelligence Malware Analysis: PINGPULL RAT
https://www.esentire.com/blog/esentire-threat-intelligence-malware-analysis-pingpull-rat
Threats:
Pingpull (tags: malware, backdoor, rat, scan)
Log4shell_vuln
Netstat_tool
Industry:
Government, Telco
Geo:
Russia, Apac, Asia, America, Emea, Africa, Vietnam
IOCs:
File: 9
Hash: 6
IP: 1
Domain: 8
Functions Names: 11
YARA: Found
24-06-2022
eSentire Threat Intelligence Malware Analysis: PINGPULL RAT
https://www.esentire.com/blog/esentire-threat-intelligence-malware-analysis-pingpull-rat
Threats:
Pingpull (tags: malware, backdoor, rat, scan)
Log4shell_vuln
Netstat_tool
Industry:
Government, Telco
Geo:
Russia, Apac, Asia, America, Emea, Africa, Vietnam
IOCs:
File: 9
Hash: 6
IP: 1
Domain: 8
Functions Names: 11
YARA: Found
eSentire
eSentire Threat Intelligence Malware Analysis: PINGPULL RAT
Dive deeper into the technical details gathered during eSentire’s Threat Response Unit (TRU) team’s research and threat analysis of the PINGPULL Remote Access Tool.
#ParsedReport
24-06-2022
LockBit Ransomware Disguised as Copyright Claim E-mail Being Distributed
https://asec.ahnlab.com/en/35822
Threats:
Lockbit (tags: ransomware, malware, phishing)
Malware/mdp.systemmanipulation.m1751 (tags: ransomware)
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 14
Hash: 2
24-06-2022
LockBit Ransomware Disguised as Copyright Claim E-mail Being Distributed
https://asec.ahnlab.com/en/35822
Threats:
Lockbit (tags: ransomware, malware, phishing)
Malware/mdp.systemmanipulation.m1751 (tags: ransomware)
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 14
Hash: 2
ASEC BLOG
LockBit Ransomware Disguised as Copyright Claim E-mail Being Distributed - ASEC BLOG
The ASEC analysis team has once again discovered the distribution of LockBit ransomware using phishing e-mail, and disguising itself as copyright claims e-mail which was introduced in the previous blog. The filename of the attachment in e-mail had password…
#ParsedReport
24-06-2022
Socgholish to Cobalt Strike in 10 Minutes
https://www.esentire.com/blog/socgholish-to-cobalt-strike-in-10-minutes
Threats:
Cobalt_strike (tags: malware, phishing)
Socgholish_loader (tags: malware, phishing)
Kerberoasting_technique
Gootkit
Solarmarker
Geo:
America, Emea, Africa, Apac
IOCs:
File: 7
Hash: 2
Domain: 3
24-06-2022
Socgholish to Cobalt Strike in 10 Minutes
https://www.esentire.com/blog/socgholish-to-cobalt-strike-in-10-minutes
Threats:
Cobalt_strike (tags: malware, phishing)
Socgholish_loader (tags: malware, phishing)
Kerberoasting_technique
Gootkit
Solarmarker
Geo:
America, Emea, Africa, Apac
IOCs:
File: 7
Hash: 2
Domain: 3
eSentire
Socgholish to Cobalt Strike in 10 Minutes
Learn about the Socgholish malware including what we found, how we found it and recommendations from our Threat Response Unit (TRU) to protect your business from this cyber threat.
#ParsedReport
24-06-2022
NightLion Worm Strikes Again. Worm targeting openly accessible Elasticsearch Servers
https://blog.cyble.com/2022/06/24/nightlion-worm-strikes-again
Geo:
China
24-06-2022
NightLion Worm Strikes Again. Worm targeting openly accessible Elasticsearch Servers
https://blog.cyble.com/2022/06/24/nightlion-worm-strikes-again
Geo:
China
Cyble
“NightLion” Worm Strikes Again
Cyble analyzes the resurfaced "NightLion", a worm that targets vulnerable, openly-accessible Elasticsearch Servers.
#ParsedReport
24-06-2022
Malware Analysis Report (AR22-174B)
https://us-cert.cisa.gov/ncas/analysis-reports/ar22-174b
Threats:
Chapak (tags: malware)
Nukesped_rat (tags: malware)
Trojan/win.generic (tags: malware)
Trojan.win64.injector (tags: malware)
Trojan/win.pws (tags: malware)
IOCs:
Hash: 57
Email: 3
IP: 12
Functions Names: 1
24-06-2022
Malware Analysis Report (AR22-174B)
https://us-cert.cisa.gov/ncas/analysis-reports/ar22-174b
Threats:
Chapak (tags: malware)
Nukesped_rat (tags: malware)
Trojan/win.generic (tags: malware)
Trojan.win64.injector (tags: malware)
Trojan/win.pws (tags: malware)
IOCs:
Hash: 57
Email: 3
IP: 12
Functions Names: 1
www.cisa.gov
MAR-10382580-1.v1 – Unidentified RAT | CISA
Notification This report is provided "as is" for informational purposes only. The Department of Homeland Security (DHS) does not provide any warranties of any kind regarding any information contained herein. The DHS does not endorse any commercial product…
#ParsedReport
24-06-2022
Cybereason vs. Black Basta Ransomware
https://www.cybereason.com/blog/cybereason-vs.-black-basta-ransomware
Actors/Campaigns:
Blackmatter
Threats:
Blackbasta (tags: ransomware, malware, phishing)
Qakbot (tags: ransomware)
Megacortex (tags: ransomware)
Doppelpaymer (tags: ransomware)
Conti (tags: ransomware)
Egregor (tags: ransomware)
Psexec_tool (tags: ransomware)
Lockbit
Cheerscrypt
Ryuk
Revil
Eternal_petya
Industry:
Telco, Healthcare, Transport, Government, Financial
Geo:
Australia, Russian, Canada
TTPs:
Tactics: 3
Technics: 0
IOCs:
Domain: 2
Path: 1
File: 4
Hash: 16
Url: 2
24-06-2022
Cybereason vs. Black Basta Ransomware
https://www.cybereason.com/blog/cybereason-vs.-black-basta-ransomware
Actors/Campaigns:
Blackmatter
Threats:
Blackbasta (tags: ransomware, malware, phishing)
Qakbot (tags: ransomware)
Megacortex (tags: ransomware)
Doppelpaymer (tags: ransomware)
Conti (tags: ransomware)
Egregor (tags: ransomware)
Psexec_tool (tags: ransomware)
Lockbit
Cheerscrypt
Ryuk
Revil
Eternal_petya
Industry:
Telco, Healthcare, Transport, Government, Financial
Geo:
Australia, Russian, Canada
TTPs:
Tactics: 3
Technics: 0
IOCs:
Domain: 2
Path: 1
File: 4
Hash: 16
Url: 2
Cybereason
Cybereason vs. Black Basta Ransomware
In just two months, Black Basta has added nearly 50 victims to their list, making them one of the more prominent ransomware gangs. The attackers infiltrate and move laterally throughout the network in a fully-developed RansomOps attack. The Cybereason Nocturnus…
#ParsedReport
24-06-2022
Matanbuchus Loader Resurfaces. Malware Variant Delivering Cobalt Strike Beacons via Spam Campaigns
https://blog.cyble.com/2022/06/23/matanbuchus-loader-resurfaces
Actors/Campaigns:
Belialdemon
Threats:
Cobalt_strike (tags: malware, phishing, spam, rat)
Beacon (tags: rat, phishing, malware, spam)
TTPs:
Tactics: 4
Technics: 7
IOCs:
Path: 4
Url: 6
File: 5
Hash: 11
Functions Names: 7
24-06-2022
Matanbuchus Loader Resurfaces. Malware Variant Delivering Cobalt Strike Beacons via Spam Campaigns
https://blog.cyble.com/2022/06/23/matanbuchus-loader-resurfaces
Actors/Campaigns:
Belialdemon
Threats:
Cobalt_strike (tags: malware, phishing, spam, rat)
Beacon (tags: rat, phishing, malware, spam)
TTPs:
Tactics: 4
Technics: 7
IOCs:
Path: 4
Url: 6
File: 5
Hash: 11
Functions Names: 7
#ParsedReport
24-06-2022
ASEC Weekly Malware Statistics ( 20220613 \~ 20220619 )
https://asec-ahnlab-com.translate.goog/ko/35547/?_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Threats:
Agent_tesla (tags: malware)
Azorult (tags: malware)
Formbook (tags: malware)
Lokibot_stealer (tags: malware)
Avemaria_rat (tags: malware)
Emotet (tags: malware)
Qakbot (tags: malware)
Trickbot (tags: malware)
Smoker_loader (tags: malware)
Industry:
Transport, Financial
Geo:
Korea
IOCs:
Domain: 18
Email: 3
File: 21
Url: 23
24-06-2022
ASEC Weekly Malware Statistics ( 20220613 \~ 20220619 )
https://asec-ahnlab-com.translate.goog/ko/35547/?_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Threats:
Agent_tesla (tags: malware)
Azorult (tags: malware)
Formbook (tags: malware)
Lokibot_stealer (tags: malware)
Avemaria_rat (tags: malware)
Emotet (tags: malware)
Qakbot (tags: malware)
Trickbot (tags: malware)
Smoker_loader (tags: malware)
Industry:
Transport, Financial
Geo:
Korea
IOCs:
Domain: 18
Email: 3
File: 21
Url: 23
ASEC BLOG
ASEC 주간 악성코드 통계 ( 20220613 ~ 20220619 ) - ASEC BLOG
ASEC 분석팀에서는 ASEC 자동 분석 시스템 RAPIT 을 활용하여 알려진 악성코드들에 대한 분류 및 대응을 진행하고 있다. 본 포스팅에서는 2022년 6월 13일 월요일부터 6월 19일 일요일까지 한 주간 수집된 악성코드의 통계를 정리한다. 대분류 상으로는 인포스틸러가 63.8%로 1위를 차지하였으며, 그 다음으로는 백도어가 17.8%, 다운로더 8.9%, 뱅킹 악성코드7.5%, 랜섬웨어 1.9%로 집계되었다. Top 1 – AgentTesla 인포스틸러…
#ParsedReport
24-06-2022
Keona Clipper Leverages Telegram for Anonymity. Evasive Malware Targeting Cryptocurrency Users
https://blog.cyble.com/2022/06/22/keona-clipper-leverages-telegram-for-anonymity
Threats:
Beacon
Industry:
Financial
TTPs:
Tactics: 4
Technics: 5
IOCs:
Hash: 11
File: 2
Functions Names: 2
24-06-2022
Keona Clipper Leverages Telegram for Anonymity. Evasive Malware Targeting Cryptocurrency Users
https://blog.cyble.com/2022/06/22/keona-clipper-leverages-telegram-for-anonymity
Threats:
Beacon
Industry:
Financial
TTPs:
Tactics: 4
Technics: 5
IOCs:
Hash: 11
File: 2
Functions Names: 2
Cyble
Cyble - Keona Clipper Leverages Telegram For Anonymity
Cyble analyzes Keona Clipper - an evasive malware variant targeting crypto-wallets and cryptocurrency users.
#ParsedReport
24-06-2022
APT-C-56
https://mp-weixin-qq-com.translate.goog/s/YKSedzm7haO0vPttIqsUAQ?_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Threats:
Crimson_rat (tags: rat)
IOCs:
IP: 1
Hash: 5
24-06-2022
APT-C-56
https://mp-weixin-qq-com.translate.goog/s/YKSedzm7haO0vPttIqsUAQ?_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Threats:
Crimson_rat (tags: rat)
IOCs:
IP: 1
Hash: 5
微信公众平台
APT-C-56(透明部落)伪装印度国防部邮件攻击的跟踪简报
360高级威胁研究院近期捕获到了透明部落攻击印度国防部的文档,与此前类似的是,恶意文档最终仍释放CrimsonRAT
#ParsedReport
24-06-2022
Emotet SMB spreader overview
http://reversing.fun/posts/2022/06/20/emotet-smb-spreader.html
Threats:
Emotet
IOCs:
Hash: 1
Functions Names: 1
24-06-2022
Emotet SMB spreader overview
http://reversing.fun/posts/2022/06/20/emotet-smb-spreader.html
Threats:
Emotet
IOCs:
Hash: 1
Functions Names: 1
..
Emotet SMB spreader overview
Emotet is back in business and it’s revealing some new tricks. Not long ago, Emotet introduced a new module, the Google Chrome’s credit card grabber. More recently, the SMB spreader module has been brought back and is now, once again, part of the infection…
#ParsedReport
24-06-2022
BRONZE STARLIGHT Ransomware Operations Use HUI Loader
https://www.secureworks.com/research/bronze-starlight-ransomware-operations-use-hui-loader
Actors/Campaigns:
Bronze_starlight (motivation: cyber_espionage, financially_motivated, government_sponsored, cyber_criminal)
Stone_panda
A41apt
Gold_waterfall
Darkside
Blackmatter
Evil_corp
Sandworm (motivation: financially_motivated)
Cobalt_foxglove (motivation: financially_motivated)
Threats:
Hui_loader (tags: ransomware, malware, dns, scan, rat)
Nightsky (tags: ransomware)
Lockfile (tags: ransomware)
Atomsilo (tags: ransomware)
Rook (tags: ransomware)
Pandora (tags: ransomware)
Cobalt_strike (tags: ransomware)
Sodamaster
Plugx_rat
Quasar_rat
Beacon (tags: ransomware)
Meterpreter_tool (tags: ransomware)
Lockbit (tags: ransomware)
Babuk (tags: ransomware)
Proxyshell_vuln
Shadowpad
Hades
Wannacry
Eternal_petya
Pay2key
N3tw0rm
Talisman
Log4shell_vuln
Cerber
Petitpotam_vuln
Hajime
Industry:
Healthcare, Aerospace, Government, Education, Financial
Geo:
Israel, India, Lithuania, Chinese, Iranian, Asian, China, Japan, Asia, Brazil, Russian, Korea, Japanese, Indiabullamc, Americas, Indian, Kazakhstan
CVEs:
CVE-2021-40539 [Vulners]
Vulners: Score: 7.5, CVSS: 6.4,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- zohocorp manageengine adselfservice plus (4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 5.0, 5.0, 5.0, 5.0, 5.0, 5.0, 5.0, 5.0, 5.0, 5.0, 5.0, 5.0, 5.0.6, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.2, 5.2, 5.2, 5.2, 5.2, 5.2, 5.2, 5.2, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.4, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.6, 5.6, 5.6, 5.6, 5.6, 5.6, 5.6, 5.6, 5.7, 5.7, 5.7, 5.7, 5.7, 5.7, 5.7, 5.7, 5.7, 5.7, 5.7, 5.7, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 6.0, 6.0, 6.0, 6.0, 6.0, 6.0, 6.0, 6.0, 6.0, 6.0, 6.0, 6.0, 6.0, 6.1, 6.1, 6.1, 6.1, 6.1, 6.1, 6.1, 6.1, 6.1)
IOCs:
File: 8
Coin: 1
IP: 3
Hash: 22
Functions Names: 2
Links:
24-06-2022
BRONZE STARLIGHT Ransomware Operations Use HUI Loader
https://www.secureworks.com/research/bronze-starlight-ransomware-operations-use-hui-loader
Actors/Campaigns:
Bronze_starlight (motivation: cyber_espionage, financially_motivated, government_sponsored, cyber_criminal)
Stone_panda
A41apt
Gold_waterfall
Darkside
Blackmatter
Evil_corp
Sandworm (motivation: financially_motivated)
Cobalt_foxglove (motivation: financially_motivated)
Threats:
Hui_loader (tags: ransomware, malware, dns, scan, rat)
Nightsky (tags: ransomware)
Lockfile (tags: ransomware)
Atomsilo (tags: ransomware)
Rook (tags: ransomware)
Pandora (tags: ransomware)
Cobalt_strike (tags: ransomware)
Sodamaster
Plugx_rat
Quasar_rat
Beacon (tags: ransomware)
Meterpreter_tool (tags: ransomware)
Lockbit (tags: ransomware)
Babuk (tags: ransomware)
Proxyshell_vuln
Shadowpad
Hades
Wannacry
Eternal_petya
Pay2key
N3tw0rm
Talisman
Log4shell_vuln
Cerber
Petitpotam_vuln
Hajime
Industry:
Healthcare, Aerospace, Government, Education, Financial
Geo:
Israel, India, Lithuania, Chinese, Iranian, Asian, China, Japan, Asia, Brazil, Russian, Korea, Japanese, Indiabullamc, Americas, Indian, Kazakhstan
CVEs:
CVE-2021-40539 [Vulners]
Vulners: Score: 7.5, CVSS: 6.4,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- zohocorp manageengine adselfservice plus (4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 5.0, 5.0, 5.0, 5.0, 5.0, 5.0, 5.0, 5.0, 5.0, 5.0, 5.0, 5.0, 5.0.6, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.2, 5.2, 5.2, 5.2, 5.2, 5.2, 5.2, 5.2, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.4, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.6, 5.6, 5.6, 5.6, 5.6, 5.6, 5.6, 5.6, 5.7, 5.7, 5.7, 5.7, 5.7, 5.7, 5.7, 5.7, 5.7, 5.7, 5.7, 5.7, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 6.0, 6.0, 6.0, 6.0, 6.0, 6.0, 6.0, 6.0, 6.0, 6.0, 6.0, 6.0, 6.0, 6.1, 6.1, 6.1, 6.1, 6.1, 6.1, 6.1, 6.1, 6.1)
IOCs:
File: 8
Coin: 1
IP: 3
Hash: 22
Functions Names: 2
Links:
https://github.com/xx0hcd/Malleable-C2-Profiles/blob/master/normal/gotomeeting.profilehttps://github.com/hfiref0x/KDUhttps://github.com/rivitna/APT/blob/main/PlugX/PlugX\_XV/plugx\_xv\_versions.txtSecureworks
BRONZE STARLIGHT Ransomware Operations Use HUI Loader
#ParsedReport
24-06-2022
There Is More Than One Way to Sleep: Dive Deep Into the Implementations of API Hammering by Various Malware Families
https://unit42.paloaltonetworks.com/api-hammering-malware-families
Threats:
Bazarbackdoor (tags: malware)
Z_loader (tags: malware)
Geo:
Japanese
IOCs:
Hash: 2
Functions Names: 6
24-06-2022
There Is More Than One Way to Sleep: Dive Deep Into the Implementations of API Hammering by Various Malware Families
https://unit42.paloaltonetworks.com/api-hammering-malware-families
Threats:
Bazarbackdoor (tags: malware)
Z_loader (tags: malware)
Geo:
Japanese
IOCs:
Hash: 2
Functions Names: 6
Unit 42
There Is More Than One Way to Sleep: Dive Deep Into the Implementations of API Hammering by Various Malware Families
Learn about the unique implementations of API Hammering malware samples and how to mitigate them.
#ParsedReport
24-06-2022
Malware Analysis Report (AR22-174A)
https://us-cert.cisa.gov/ncas/analysis-reports/ar22-174a
Threats:
Xmrig_miner (tags: malware)
Trojan/win.generic (tags: malware)
Trojan.win64.injector (tags: malware)
Trojan/win.pws (tags: malware)
IOCs:
Hash: 32
Email: 3
IP: 1
24-06-2022
Malware Analysis Report (AR22-174A)
https://us-cert.cisa.gov/ncas/analysis-reports/ar22-174a
Threats:
Xmrig_miner (tags: malware)
Trojan/win.generic (tags: malware)
Trojan.win64.injector (tags: malware)
Trojan/win.pws (tags: malware)
IOCs:
Hash: 32
Email: 3
IP: 1
www.cisa.gov
MAR-10382254-1.v1 – XMRIG Cryptominer | CISA
Notification This report is provided "as is" for informational purposes only. The Department of Homeland Security (DHS) does not provide any warranties of any kind regarding any information contained herein. The DHS does not endorse any commercial product…
The IT Army of Ukraine
Structure, Tasking, and Ecosystem
https://css.ethz.ch/content/dam/ethz/special-interest/gess/cis/center-for-securities-studies/pdfs/Cyber-Reports-2022-06-IT-Army-of-Ukraine.pdf
Structure, Tasking, and Ecosystem
https://css.ethz.ch/content/dam/ethz/special-interest/gess/cis/center-for-securities-studies/pdfs/Cyber-Reports-2022-06-IT-Army-of-Ukraine.pdf
Backdoor via XFF
Mysterious Threat Actor Under Radar
https://secjoes-reports.s3.eu-central-1.amazonaws.com/Backdoor%2Bvia%2BXFF%2BMysterious%2BThreat%2BActor%2BUnder%2BRadar.pdf
Mysterious Threat Actor Under Radar
https://secjoes-reports.s3.eu-central-1.amazonaws.com/Backdoor%2Bvia%2BXFF%2BMysterious%2BThreat%2BActor%2BUnder%2BRadar.pdf
#ParsedReport
25-06-2022
Ryuk Ransomware: Breakdown and Prevention Tips
https://www.varonis.com/blog/ryuk-ransomware
Actors/Campaigns:
Wizard_spider
Lazarus (motivation: cyber_criminal)
Threats:
Ryuk (tags: trojan, dns, ransomware, phishing, malware, spam)
Hermes (tags: ransomware)
Trickbot (tags: malware, ransomware)
Industry:
Healthcare, Financial
Geo:
Japanese
YARA: Found
25-06-2022
Ryuk Ransomware: Breakdown and Prevention Tips
https://www.varonis.com/blog/ryuk-ransomware
Actors/Campaigns:
Wizard_spider
Lazarus (motivation: cyber_criminal)
Threats:
Ryuk (tags: trojan, dns, ransomware, phishing, malware, spam)
Hermes (tags: ransomware)
Trickbot (tags: malware, ransomware)
Industry:
Healthcare, Financial
Geo:
Japanese
YARA: Found
Varonis
Ryuk Ransomware: Breakdown and Prevention Tips
Ryuk ransomware targets large organizations and spreads with deadly speed. Learn about the strain and how to prevent your company from becoming a victim.