CTT Report Hub
3.43K subscribers
9.93K photos
6 videos
67 files
13.6K links
Threat Intelligence Report Hub
Download Telegram
#ParsedReport
24-06-2022

BRONZE STARLIGHT Ransomware Operations Use HUI Loader

https://www.secureworks.com/research/bronze-starlight-ransomware-operations-use-hui-loader

Actors/Campaigns:
Bronze_starlight (motivation: cyber_espionage, financially_motivated, government_sponsored, cyber_criminal)
Stone_panda
A41apt
Gold_waterfall
Darkside
Blackmatter
Evil_corp
Sandworm (motivation: financially_motivated)
Cobalt_foxglove (motivation: financially_motivated)

Threats:
Hui_loader (tags: ransomware, malware, dns, scan, rat)
Nightsky (tags: ransomware)
Lockfile (tags: ransomware)
Atomsilo (tags: ransomware)
Rook (tags: ransomware)
Pandora (tags: ransomware)
Cobalt_strike (tags: ransomware)
Sodamaster
Plugx_rat
Quasar_rat
Beacon (tags: ransomware)
Meterpreter_tool (tags: ransomware)
Lockbit (tags: ransomware)
Babuk (tags: ransomware)
Proxyshell_vuln
Shadowpad
Hades
Wannacry
Eternal_petya
Pay2key
N3tw0rm
Talisman
Log4shell_vuln
Cerber
Petitpotam_vuln
Hajime

Industry:
Healthcare, Aerospace, Government, Education, Financial

Geo:
Israel, India, Lithuania, Chinese, Iranian, Asian, China, Japan, Asia, Brazil, Russian, Korea, Japanese, Indiabullamc, Americas, Indian, Kazakhstan

CVEs:
CVE-2021-40539 [Vulners]
Vulners: Score: 7.5, CVSS: 6.4,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- zohocorp manageengine adselfservice plus (4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 5.0, 5.0, 5.0, 5.0, 5.0, 5.0, 5.0, 5.0, 5.0, 5.0, 5.0, 5.0, 5.0.6, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.2, 5.2, 5.2, 5.2, 5.2, 5.2, 5.2, 5.2, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.4, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.6, 5.6, 5.6, 5.6, 5.6, 5.6, 5.6, 5.6, 5.7, 5.7, 5.7, 5.7, 5.7, 5.7, 5.7, 5.7, 5.7, 5.7, 5.7, 5.7, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 6.0, 6.0, 6.0, 6.0, 6.0, 6.0, 6.0, 6.0, 6.0, 6.0, 6.0, 6.0, 6.0, 6.1, 6.1, 6.1, 6.1, 6.1, 6.1, 6.1, 6.1, 6.1)


IOCs:
File: 8
Coin: 1
IP: 3
Hash: 22

Functions Names: 2

Links:
https://github.com/xx0hcd/Malleable-C2-Profiles/blob/master/normal/gotomeeting.profile
https://github.com/hfiref0x/KDU
https://github.com/rivitna/APT/blob/main/PlugX/PlugX\_XV/plugx\_xv\_versions.txt
#ParsedReport
24-06-2022

There Is More Than One Way to Sleep: Dive Deep Into the Implementations of API Hammering by Various Malware Families

https://unit42.paloaltonetworks.com/api-hammering-malware-families

Threats:
Bazarbackdoor (tags: malware)
Z_loader (tags: malware)

Geo:
Japanese

IOCs:
Hash: 2

Functions Names: 6
#ParsedReport
25-06-2022

Ryuk Ransomware: Breakdown and Prevention Tips

https://www.varonis.com/blog/ryuk-ransomware

Actors/Campaigns:
Wizard_spider
Lazarus (motivation: cyber_criminal)

Threats:
Ryuk (tags: trojan, dns, ransomware, phishing, malware, spam)
Hermes (tags: ransomware)
Trickbot (tags: malware, ransomware)

Industry:
Healthcare, Financial

Geo:
Japanese

YARA: Found
#ParsedReport
25-06-2022

Cunning Kitten Threat group targeting people in the Middle East. related suggestion

https://www-freebuf-com.translate.goog/news/337241.html?_x_tr_sl=auto&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp

Actors/Campaigns:
Cunning_kitten (motivation: cyber_espionage, information_theft)

Threats:
Powershortshell

CVEs:
CVE-2021-40444 [Vulners]
Vulners: Score: 6.8, CVSS: 2.1,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2, -)
- microsoft windows 10 (1607, -, 1809, 1909, 2004, 20h2, 21h1)
- microsoft windows server 2016 (-, 2004, 20h2)
- microsoft windows rt 8.1 (-)
- microsoft windows server 2012 (-, -)
have more...
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...

IOCs:
Hash: 12
Url: 1
Path: 1
Domain: 1
#ParsedReport
26-06-2022

APT34 - Saitama Agent. IntroductionPermalink

https://x-junior.github.io/malware%20analysis/2022/06/24/Apt34.html

Actors/Campaigns:
Oilrig

Threats:
Saitama (tags: backdoor, malware, phishing)

Industry:
Government

Geo:
Jordan

IOCs:
File: 22
Hash: 18
Path: 2
Domain: 12
IP: 29

Functions Names: 6

YARA: Found

Links:
https://gist.github.com/monoxgas/1b36031c5593ebfed3229f4
Bug Bounty программа для ренсовари... прикольно.
Forwarded from vx-underground
Lockbit ransomware group announced today Lockbit 3.0 is officially released with the message: "Make Ransomware Great Again!"

Additionally, Lockbit has launched their own Bug Bounty program paying for PII on high-profile individuals, web security exploits, and more...
#ParsedReport
27-06-2022

Stories from the SOC - Detecting internal reconnaissance

https://cybersecurity.att.com/blogs/security-essentials/stories-from-the-soc-detecting-internal-reconnaissance

Threats:
Wannacry
Winrm_tool
#ParsedReport
27-06-2022

Emotet: Still Abusing Microsoft Office Macros

https://www.netskope.com/blog/emotet-still-abusing-microsoft-office-macros

Threats:
Emotet (tags: malware, phishing, fraud, ransomware)
Goodwill
Jasmin
Follina_vuln

CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...

IOCs:
File: 6

YARA: Found

Links:
https://github.com/netskopeoss/NetskopeThreatLabsIOCs/tree/main/Emotet/2022-06-24
https://github.com/mrexodia/dumpulator
https://github.com/netskopeoss/NetskopeThreatLabsIOCs/blob/main/Emotet/2022-06-24/script/extract\_xls\_urls.py