CTT Report Hub
3.43K subscribers
9.94K photos
6 videos
67 files
13.6K links
Threat Intelligence Report Hub
Download Telegram
#ParsedReport
23-06-2022

Spyware vendor targets users in Italy and Kazakhstan

https://blog.google/threat-analysis-group/italian-spyware-vendor-targets-users-in-italy-and-kazakhstan

Threats:
Lightspeed_vuln
Sockpuppet_vuln
Timewaste_vuln
Avecesare_vuln
Clicked_vuln

Industry:
Telco, Government

Geo:
Italy, Kazakhstan

CVEs:
CVE-2020-9907 [Vulners]
Vulners: Score: 9.3, CVSS: 4.6,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- apple ipad os (<13.6)
- apple iphone os (<13.6)
- apple tvos (<13.4.8)

CVE-2021-30883 [Vulners]
Vulners: Score: 9.3, CVSS: 3.1,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- apple ipad os (<14.8.1, 15.0, 15.0.1)
- apple iphone os (<14.8.1, 15.0, 15.0.1)
- apple macos (<11.6.1, 12.0)
- apple tvos (<15.1)
- apple watchos (<8.1)
have more...
CVE-2020-3837 [Vulners]
Vulners: Score: 9.3, CVSS: 5.8,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- apple ipados (<13.3.1)
- apple iphone os (<13.3.1)
- apple mac os x (<10.15.3)
- apple tvos (<13.3.1)
- apple watchos (<6.1.2)
have more...
CVE-2018-4344 [Vulners]
Vulners: Score: 9.3, CVSS: 4.4,
Vulners: Exploitation: Unknown
X-Force: Risk: 8.4
X-Force: Patch: Official fix
Soft:
- apple iphone os (<12.0)
- apple mac os x (<10.14)
- apple tvos (<12)
- apple watchos (<5.0)

CVE-2021-30983 [Vulners]
Vulners: Score: 9.3, CVSS: 4.7,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- apple ipados (<15.2)
- apple iphone os (<15.2)

CVE-2019-8605 [Vulners]
Vulners: Score: 9.3, CVSS: 5.7,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- apple iphone os (<12.3)
- apple mac os x (<10.14.5)
- apple tvos (<12.3)
- apple watchos (<5.2.1)


IOCs:
Domain: 18
Hash: 9
IP: 4
#ParsedReport
23-06-2022

Malicious Cyber Actors Continue to Exploit Log4Shell in VMware Horizon Systems

https://us-cert.cisa.gov/ncas/current-activity/2022/06/23/malicious-cyber-actors-continue-exploit-log4shell-vmware-horizon

Actors/Campaigns:
Karakurt

Threats:
Log4shell_vuln
Spring4shell

Geo:
China

CVEs:
CVE-2021-44228 [Vulners]
Vulners: Score: 9.3, CVSS: 4.0,
Vulners: Exploitation: True
X-Force: Risk: 10
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, <2.15.0, <2.3.1, <2.12.2)
- siemens sppa-t3000 ses3000 firmware (*)
- siemens logo\! soft comfort (*)
- siemens spectrum power 4 (4.70, 4.70, <4.70, 4.70)
- siemens siveillance control pro (*)
have more...
#ParsedReport
24-06-2022

eSentire Threat Intelligence Malware Analysis: PINGPULL RAT

https://www.esentire.com/blog/esentire-threat-intelligence-malware-analysis-pingpull-rat

Threats:
Pingpull (tags: malware, backdoor, rat, scan)
Log4shell_vuln
Netstat_tool

Industry:
Government, Telco

Geo:
Russia, Apac, Asia, America, Emea, Africa, Vietnam

IOCs:
File: 9
Hash: 6
IP: 1
Domain: 8

Functions Names: 11

YARA: Found
#ParsedReport
24-06-2022

Socgholish to Cobalt Strike in 10 Minutes

https://www.esentire.com/blog/socgholish-to-cobalt-strike-in-10-minutes

Threats:
Cobalt_strike (tags: malware, phishing)
Socgholish_loader (tags: malware, phishing)
Kerberoasting_technique
Gootkit
Solarmarker

Geo:
America, Emea, Africa, Apac

IOCs:
File: 7
Hash: 2
Domain: 3
#ParsedReport
24-06-2022

Cybereason vs. Black Basta Ransomware

https://www.cybereason.com/blog/cybereason-vs.-black-basta-ransomware

Actors/Campaigns:
Blackmatter

Threats:
Blackbasta (tags: ransomware, malware, phishing)
Qakbot (tags: ransomware)
Megacortex (tags: ransomware)
Doppelpaymer (tags: ransomware)
Conti (tags: ransomware)
Egregor (tags: ransomware)
Psexec_tool (tags: ransomware)
Lockbit
Cheerscrypt
Ryuk
Revil
Eternal_petya

Industry:
Telco, Healthcare, Transport, Government, Financial

Geo:
Australia, Russian, Canada

TTPs:
Tactics: 3
Technics: 0

IOCs:
Domain: 2
Path: 1
File: 4
Hash: 16
Url: 2
#ParsedReport
24-06-2022

Matanbuchus Loader Resurfaces. Malware Variant Delivering Cobalt Strike Beacons via Spam Campaigns

https://blog.cyble.com/2022/06/23/matanbuchus-loader-resurfaces

Actors/Campaigns:
Belialdemon

Threats:
Cobalt_strike (tags: malware, phishing, spam, rat)
Beacon (tags: rat, phishing, malware, spam)

TTPs:
Tactics: 4
Technics: 7

IOCs:
Path: 4
Url: 6
File: 5
Hash: 11

Functions Names: 7
#ParsedReport
24-06-2022

Keona Clipper Leverages Telegram for Anonymity. Evasive Malware Targeting Cryptocurrency Users

https://blog.cyble.com/2022/06/22/keona-clipper-leverages-telegram-for-anonymity

Threats:
Beacon

Industry:
Financial

TTPs:
Tactics: 4
Technics: 5

IOCs:
Hash: 11
File: 2

Functions Names: 2
#ParsedReport
24-06-2022

BRONZE STARLIGHT Ransomware Operations Use HUI Loader

https://www.secureworks.com/research/bronze-starlight-ransomware-operations-use-hui-loader

Actors/Campaigns:
Bronze_starlight (motivation: cyber_espionage, financially_motivated, government_sponsored, cyber_criminal)
Stone_panda
A41apt
Gold_waterfall
Darkside
Blackmatter
Evil_corp
Sandworm (motivation: financially_motivated)
Cobalt_foxglove (motivation: financially_motivated)

Threats:
Hui_loader (tags: ransomware, malware, dns, scan, rat)
Nightsky (tags: ransomware)
Lockfile (tags: ransomware)
Atomsilo (tags: ransomware)
Rook (tags: ransomware)
Pandora (tags: ransomware)
Cobalt_strike (tags: ransomware)
Sodamaster
Plugx_rat
Quasar_rat
Beacon (tags: ransomware)
Meterpreter_tool (tags: ransomware)
Lockbit (tags: ransomware)
Babuk (tags: ransomware)
Proxyshell_vuln
Shadowpad
Hades
Wannacry
Eternal_petya
Pay2key
N3tw0rm
Talisman
Log4shell_vuln
Cerber
Petitpotam_vuln
Hajime

Industry:
Healthcare, Aerospace, Government, Education, Financial

Geo:
Israel, India, Lithuania, Chinese, Iranian, Asian, China, Japan, Asia, Brazil, Russian, Korea, Japanese, Indiabullamc, Americas, Indian, Kazakhstan

CVEs:
CVE-2021-40539 [Vulners]
Vulners: Score: 7.5, CVSS: 6.4,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- zohocorp manageengine adselfservice plus (4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 5.0, 5.0, 5.0, 5.0, 5.0, 5.0, 5.0, 5.0, 5.0, 5.0, 5.0, 5.0, 5.0.6, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.2, 5.2, 5.2, 5.2, 5.2, 5.2, 5.2, 5.2, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.4, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.6, 5.6, 5.6, 5.6, 5.6, 5.6, 5.6, 5.6, 5.7, 5.7, 5.7, 5.7, 5.7, 5.7, 5.7, 5.7, 5.7, 5.7, 5.7, 5.7, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 6.0, 6.0, 6.0, 6.0, 6.0, 6.0, 6.0, 6.0, 6.0, 6.0, 6.0, 6.0, 6.0, 6.1, 6.1, 6.1, 6.1, 6.1, 6.1, 6.1, 6.1, 6.1)


IOCs:
File: 8
Coin: 1
IP: 3
Hash: 22

Functions Names: 2

Links:
https://github.com/xx0hcd/Malleable-C2-Profiles/blob/master/normal/gotomeeting.profile
https://github.com/hfiref0x/KDU
https://github.com/rivitna/APT/blob/main/PlugX/PlugX\_XV/plugx\_xv\_versions.txt
#ParsedReport
24-06-2022

There Is More Than One Way to Sleep: Dive Deep Into the Implementations of API Hammering by Various Malware Families

https://unit42.paloaltonetworks.com/api-hammering-malware-families

Threats:
Bazarbackdoor (tags: malware)
Z_loader (tags: malware)

Geo:
Japanese

IOCs:
Hash: 2

Functions Names: 6
#ParsedReport
25-06-2022

Ryuk Ransomware: Breakdown and Prevention Tips

https://www.varonis.com/blog/ryuk-ransomware

Actors/Campaigns:
Wizard_spider
Lazarus (motivation: cyber_criminal)

Threats:
Ryuk (tags: trojan, dns, ransomware, phishing, malware, spam)
Hermes (tags: ransomware)
Trickbot (tags: malware, ransomware)

Industry:
Healthcare, Financial

Geo:
Japanese

YARA: Found