CTT Report Hub
3.43K subscribers
9.94K photos
6 videos
67 files
13.6K links
Threat Intelligence Report Hub
Download Telegram
#ParsedReport
24-06-2022

eSentire Threat Intelligence Malware Analysis: PINGPULL RAT

https://www.esentire.com/blog/esentire-threat-intelligence-malware-analysis-pingpull-rat

Threats:
Pingpull (tags: malware, backdoor, rat, scan)
Log4shell_vuln
Netstat_tool

Industry:
Government, Telco

Geo:
Russia, Apac, Asia, America, Emea, Africa, Vietnam

IOCs:
File: 9
Hash: 6
IP: 1
Domain: 8

Functions Names: 11

YARA: Found
#ParsedReport
24-06-2022

Socgholish to Cobalt Strike in 10 Minutes

https://www.esentire.com/blog/socgholish-to-cobalt-strike-in-10-minutes

Threats:
Cobalt_strike (tags: malware, phishing)
Socgholish_loader (tags: malware, phishing)
Kerberoasting_technique
Gootkit
Solarmarker

Geo:
America, Emea, Africa, Apac

IOCs:
File: 7
Hash: 2
Domain: 3
#ParsedReport
24-06-2022

Cybereason vs. Black Basta Ransomware

https://www.cybereason.com/blog/cybereason-vs.-black-basta-ransomware

Actors/Campaigns:
Blackmatter

Threats:
Blackbasta (tags: ransomware, malware, phishing)
Qakbot (tags: ransomware)
Megacortex (tags: ransomware)
Doppelpaymer (tags: ransomware)
Conti (tags: ransomware)
Egregor (tags: ransomware)
Psexec_tool (tags: ransomware)
Lockbit
Cheerscrypt
Ryuk
Revil
Eternal_petya

Industry:
Telco, Healthcare, Transport, Government, Financial

Geo:
Australia, Russian, Canada

TTPs:
Tactics: 3
Technics: 0

IOCs:
Domain: 2
Path: 1
File: 4
Hash: 16
Url: 2
#ParsedReport
24-06-2022

Matanbuchus Loader Resurfaces. Malware Variant Delivering Cobalt Strike Beacons via Spam Campaigns

https://blog.cyble.com/2022/06/23/matanbuchus-loader-resurfaces

Actors/Campaigns:
Belialdemon

Threats:
Cobalt_strike (tags: malware, phishing, spam, rat)
Beacon (tags: rat, phishing, malware, spam)

TTPs:
Tactics: 4
Technics: 7

IOCs:
Path: 4
Url: 6
File: 5
Hash: 11

Functions Names: 7
#ParsedReport
24-06-2022

Keona Clipper Leverages Telegram for Anonymity. Evasive Malware Targeting Cryptocurrency Users

https://blog.cyble.com/2022/06/22/keona-clipper-leverages-telegram-for-anonymity

Threats:
Beacon

Industry:
Financial

TTPs:
Tactics: 4
Technics: 5

IOCs:
Hash: 11
File: 2

Functions Names: 2
#ParsedReport
24-06-2022

BRONZE STARLIGHT Ransomware Operations Use HUI Loader

https://www.secureworks.com/research/bronze-starlight-ransomware-operations-use-hui-loader

Actors/Campaigns:
Bronze_starlight (motivation: cyber_espionage, financially_motivated, government_sponsored, cyber_criminal)
Stone_panda
A41apt
Gold_waterfall
Darkside
Blackmatter
Evil_corp
Sandworm (motivation: financially_motivated)
Cobalt_foxglove (motivation: financially_motivated)

Threats:
Hui_loader (tags: ransomware, malware, dns, scan, rat)
Nightsky (tags: ransomware)
Lockfile (tags: ransomware)
Atomsilo (tags: ransomware)
Rook (tags: ransomware)
Pandora (tags: ransomware)
Cobalt_strike (tags: ransomware)
Sodamaster
Plugx_rat
Quasar_rat
Beacon (tags: ransomware)
Meterpreter_tool (tags: ransomware)
Lockbit (tags: ransomware)
Babuk (tags: ransomware)
Proxyshell_vuln
Shadowpad
Hades
Wannacry
Eternal_petya
Pay2key
N3tw0rm
Talisman
Log4shell_vuln
Cerber
Petitpotam_vuln
Hajime

Industry:
Healthcare, Aerospace, Government, Education, Financial

Geo:
Israel, India, Lithuania, Chinese, Iranian, Asian, China, Japan, Asia, Brazil, Russian, Korea, Japanese, Indiabullamc, Americas, Indian, Kazakhstan

CVEs:
CVE-2021-40539 [Vulners]
Vulners: Score: 7.5, CVSS: 6.4,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- zohocorp manageengine adselfservice plus (4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 5.0, 5.0, 5.0, 5.0, 5.0, 5.0, 5.0, 5.0, 5.0, 5.0, 5.0, 5.0, 5.0.6, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.2, 5.2, 5.2, 5.2, 5.2, 5.2, 5.2, 5.2, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.4, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.6, 5.6, 5.6, 5.6, 5.6, 5.6, 5.6, 5.6, 5.7, 5.7, 5.7, 5.7, 5.7, 5.7, 5.7, 5.7, 5.7, 5.7, 5.7, 5.7, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 6.0, 6.0, 6.0, 6.0, 6.0, 6.0, 6.0, 6.0, 6.0, 6.0, 6.0, 6.0, 6.0, 6.1, 6.1, 6.1, 6.1, 6.1, 6.1, 6.1, 6.1, 6.1)


IOCs:
File: 8
Coin: 1
IP: 3
Hash: 22

Functions Names: 2

Links:
https://github.com/xx0hcd/Malleable-C2-Profiles/blob/master/normal/gotomeeting.profile
https://github.com/hfiref0x/KDU
https://github.com/rivitna/APT/blob/main/PlugX/PlugX\_XV/plugx\_xv\_versions.txt
#ParsedReport
24-06-2022

There Is More Than One Way to Sleep: Dive Deep Into the Implementations of API Hammering by Various Malware Families

https://unit42.paloaltonetworks.com/api-hammering-malware-families

Threats:
Bazarbackdoor (tags: malware)
Z_loader (tags: malware)

Geo:
Japanese

IOCs:
Hash: 2

Functions Names: 6
#ParsedReport
25-06-2022

Ryuk Ransomware: Breakdown and Prevention Tips

https://www.varonis.com/blog/ryuk-ransomware

Actors/Campaigns:
Wizard_spider
Lazarus (motivation: cyber_criminal)

Threats:
Ryuk (tags: trojan, dns, ransomware, phishing, malware, spam)
Hermes (tags: ransomware)
Trickbot (tags: malware, ransomware)

Industry:
Healthcare, Financial

Geo:
Japanese

YARA: Found
#ParsedReport
25-06-2022

Cunning Kitten Threat group targeting people in the Middle East. related suggestion

https://www-freebuf-com.translate.goog/news/337241.html?_x_tr_sl=auto&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp

Actors/Campaigns:
Cunning_kitten (motivation: cyber_espionage, information_theft)

Threats:
Powershortshell

CVEs:
CVE-2021-40444 [Vulners]
Vulners: Score: 6.8, CVSS: 2.1,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2, -)
- microsoft windows 10 (1607, -, 1809, 1909, 2004, 20h2, 21h1)
- microsoft windows server 2016 (-, 2004, 20h2)
- microsoft windows rt 8.1 (-)
- microsoft windows server 2012 (-, -)
have more...
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...

IOCs:
Hash: 12
Url: 1
Path: 1
Domain: 1
#ParsedReport
26-06-2022

APT34 - Saitama Agent. IntroductionPermalink

https://x-junior.github.io/malware%20analysis/2022/06/24/Apt34.html

Actors/Campaigns:
Oilrig

Threats:
Saitama (tags: backdoor, malware, phishing)

Industry:
Government

Geo:
Jordan

IOCs:
File: 22
Hash: 18
Path: 2
Domain: 12
IP: 29

Functions Names: 6

YARA: Found

Links:
https://gist.github.com/monoxgas/1b36031c5593ebfed3229f4