#ParsedReport
24-06-2022
Emotet SMB spreader overview
http://reversing.fun/posts/2022/06/20/emotet-smb-spreader.html
Threats:
Emotet
IOCs:
Hash: 1
Functions Names: 1
24-06-2022
Emotet SMB spreader overview
http://reversing.fun/posts/2022/06/20/emotet-smb-spreader.html
Threats:
Emotet
IOCs:
Hash: 1
Functions Names: 1
..
Emotet SMB spreader overview
Emotet is back in business and it’s revealing some new tricks. Not long ago, Emotet introduced a new module, the Google Chrome’s credit card grabber. More recently, the SMB spreader module has been brought back and is now, once again, part of the infection…
#ParsedReport
24-06-2022
BRONZE STARLIGHT Ransomware Operations Use HUI Loader
https://www.secureworks.com/research/bronze-starlight-ransomware-operations-use-hui-loader
Actors/Campaigns:
Bronze_starlight (motivation: cyber_espionage, financially_motivated, government_sponsored, cyber_criminal)
Stone_panda
A41apt
Gold_waterfall
Darkside
Blackmatter
Evil_corp
Sandworm (motivation: financially_motivated)
Cobalt_foxglove (motivation: financially_motivated)
Threats:
Hui_loader (tags: ransomware, malware, dns, scan, rat)
Nightsky (tags: ransomware)
Lockfile (tags: ransomware)
Atomsilo (tags: ransomware)
Rook (tags: ransomware)
Pandora (tags: ransomware)
Cobalt_strike (tags: ransomware)
Sodamaster
Plugx_rat
Quasar_rat
Beacon (tags: ransomware)
Meterpreter_tool (tags: ransomware)
Lockbit (tags: ransomware)
Babuk (tags: ransomware)
Proxyshell_vuln
Shadowpad
Hades
Wannacry
Eternal_petya
Pay2key
N3tw0rm
Talisman
Log4shell_vuln
Cerber
Petitpotam_vuln
Hajime
Industry:
Healthcare, Aerospace, Government, Education, Financial
Geo:
Israel, India, Lithuania, Chinese, Iranian, Asian, China, Japan, Asia, Brazil, Russian, Korea, Japanese, Indiabullamc, Americas, Indian, Kazakhstan
CVEs:
CVE-2021-40539 [Vulners]
Vulners: Score: 7.5, CVSS: 6.4,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- zohocorp manageengine adselfservice plus (4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 5.0, 5.0, 5.0, 5.0, 5.0, 5.0, 5.0, 5.0, 5.0, 5.0, 5.0, 5.0, 5.0.6, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.2, 5.2, 5.2, 5.2, 5.2, 5.2, 5.2, 5.2, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.4, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.6, 5.6, 5.6, 5.6, 5.6, 5.6, 5.6, 5.6, 5.7, 5.7, 5.7, 5.7, 5.7, 5.7, 5.7, 5.7, 5.7, 5.7, 5.7, 5.7, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 6.0, 6.0, 6.0, 6.0, 6.0, 6.0, 6.0, 6.0, 6.0, 6.0, 6.0, 6.0, 6.0, 6.1, 6.1, 6.1, 6.1, 6.1, 6.1, 6.1, 6.1, 6.1)
IOCs:
File: 8
Coin: 1
IP: 3
Hash: 22
Functions Names: 2
Links:
24-06-2022
BRONZE STARLIGHT Ransomware Operations Use HUI Loader
https://www.secureworks.com/research/bronze-starlight-ransomware-operations-use-hui-loader
Actors/Campaigns:
Bronze_starlight (motivation: cyber_espionage, financially_motivated, government_sponsored, cyber_criminal)
Stone_panda
A41apt
Gold_waterfall
Darkside
Blackmatter
Evil_corp
Sandworm (motivation: financially_motivated)
Cobalt_foxglove (motivation: financially_motivated)
Threats:
Hui_loader (tags: ransomware, malware, dns, scan, rat)
Nightsky (tags: ransomware)
Lockfile (tags: ransomware)
Atomsilo (tags: ransomware)
Rook (tags: ransomware)
Pandora (tags: ransomware)
Cobalt_strike (tags: ransomware)
Sodamaster
Plugx_rat
Quasar_rat
Beacon (tags: ransomware)
Meterpreter_tool (tags: ransomware)
Lockbit (tags: ransomware)
Babuk (tags: ransomware)
Proxyshell_vuln
Shadowpad
Hades
Wannacry
Eternal_petya
Pay2key
N3tw0rm
Talisman
Log4shell_vuln
Cerber
Petitpotam_vuln
Hajime
Industry:
Healthcare, Aerospace, Government, Education, Financial
Geo:
Israel, India, Lithuania, Chinese, Iranian, Asian, China, Japan, Asia, Brazil, Russian, Korea, Japanese, Indiabullamc, Americas, Indian, Kazakhstan
CVEs:
CVE-2021-40539 [Vulners]
Vulners: Score: 7.5, CVSS: 6.4,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- zohocorp manageengine adselfservice plus (4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 4.5, 5.0, 5.0, 5.0, 5.0, 5.0, 5.0, 5.0, 5.0, 5.0, 5.0, 5.0, 5.0, 5.0.6, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.1, 5.2, 5.2, 5.2, 5.2, 5.2, 5.2, 5.2, 5.2, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.3, 5.4, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.5, 5.6, 5.6, 5.6, 5.6, 5.6, 5.6, 5.6, 5.6, 5.7, 5.7, 5.7, 5.7, 5.7, 5.7, 5.7, 5.7, 5.7, 5.7, 5.7, 5.7, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 5.8, 6.0, 6.0, 6.0, 6.0, 6.0, 6.0, 6.0, 6.0, 6.0, 6.0, 6.0, 6.0, 6.0, 6.1, 6.1, 6.1, 6.1, 6.1, 6.1, 6.1, 6.1, 6.1)
IOCs:
File: 8
Coin: 1
IP: 3
Hash: 22
Functions Names: 2
Links:
https://github.com/xx0hcd/Malleable-C2-Profiles/blob/master/normal/gotomeeting.profilehttps://github.com/hfiref0x/KDUhttps://github.com/rivitna/APT/blob/main/PlugX/PlugX\_XV/plugx\_xv\_versions.txtSecureworks
BRONZE STARLIGHT Ransomware Operations Use HUI Loader
#ParsedReport
24-06-2022
There Is More Than One Way to Sleep: Dive Deep Into the Implementations of API Hammering by Various Malware Families
https://unit42.paloaltonetworks.com/api-hammering-malware-families
Threats:
Bazarbackdoor (tags: malware)
Z_loader (tags: malware)
Geo:
Japanese
IOCs:
Hash: 2
Functions Names: 6
24-06-2022
There Is More Than One Way to Sleep: Dive Deep Into the Implementations of API Hammering by Various Malware Families
https://unit42.paloaltonetworks.com/api-hammering-malware-families
Threats:
Bazarbackdoor (tags: malware)
Z_loader (tags: malware)
Geo:
Japanese
IOCs:
Hash: 2
Functions Names: 6
Unit 42
There Is More Than One Way to Sleep: Dive Deep Into the Implementations of API Hammering by Various Malware Families
Learn about the unique implementations of API Hammering malware samples and how to mitigate them.
#ParsedReport
24-06-2022
Malware Analysis Report (AR22-174A)
https://us-cert.cisa.gov/ncas/analysis-reports/ar22-174a
Threats:
Xmrig_miner (tags: malware)
Trojan/win.generic (tags: malware)
Trojan.win64.injector (tags: malware)
Trojan/win.pws (tags: malware)
IOCs:
Hash: 32
Email: 3
IP: 1
24-06-2022
Malware Analysis Report (AR22-174A)
https://us-cert.cisa.gov/ncas/analysis-reports/ar22-174a
Threats:
Xmrig_miner (tags: malware)
Trojan/win.generic (tags: malware)
Trojan.win64.injector (tags: malware)
Trojan/win.pws (tags: malware)
IOCs:
Hash: 32
Email: 3
IP: 1
www.cisa.gov
MAR-10382254-1.v1 – XMRIG Cryptominer | CISA
Notification This report is provided "as is" for informational purposes only. The Department of Homeland Security (DHS) does not provide any warranties of any kind regarding any information contained herein. The DHS does not endorse any commercial product…
The IT Army of Ukraine
Structure, Tasking, and Ecosystem
https://css.ethz.ch/content/dam/ethz/special-interest/gess/cis/center-for-securities-studies/pdfs/Cyber-Reports-2022-06-IT-Army-of-Ukraine.pdf
Structure, Tasking, and Ecosystem
https://css.ethz.ch/content/dam/ethz/special-interest/gess/cis/center-for-securities-studies/pdfs/Cyber-Reports-2022-06-IT-Army-of-Ukraine.pdf
Backdoor via XFF
Mysterious Threat Actor Under Radar
https://secjoes-reports.s3.eu-central-1.amazonaws.com/Backdoor%2Bvia%2BXFF%2BMysterious%2BThreat%2BActor%2BUnder%2BRadar.pdf
Mysterious Threat Actor Under Radar
https://secjoes-reports.s3.eu-central-1.amazonaws.com/Backdoor%2Bvia%2BXFF%2BMysterious%2BThreat%2BActor%2BUnder%2BRadar.pdf
#ParsedReport
25-06-2022
Ryuk Ransomware: Breakdown and Prevention Tips
https://www.varonis.com/blog/ryuk-ransomware
Actors/Campaigns:
Wizard_spider
Lazarus (motivation: cyber_criminal)
Threats:
Ryuk (tags: trojan, dns, ransomware, phishing, malware, spam)
Hermes (tags: ransomware)
Trickbot (tags: malware, ransomware)
Industry:
Healthcare, Financial
Geo:
Japanese
YARA: Found
25-06-2022
Ryuk Ransomware: Breakdown and Prevention Tips
https://www.varonis.com/blog/ryuk-ransomware
Actors/Campaigns:
Wizard_spider
Lazarus (motivation: cyber_criminal)
Threats:
Ryuk (tags: trojan, dns, ransomware, phishing, malware, spam)
Hermes (tags: ransomware)
Trickbot (tags: malware, ransomware)
Industry:
Healthcare, Financial
Geo:
Japanese
YARA: Found
Varonis
Ryuk Ransomware: Breakdown and Prevention Tips
Ryuk ransomware targets large organizations and spreads with deadly speed. Learn about the strain and how to prevent your company from becoming a victim.
#ParsedReport
25-06-2022
Cunning Kitten Threat group targeting people in the Middle East. related suggestion
https://www-freebuf-com.translate.goog/news/337241.html?_x_tr_sl=auto&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Actors/Campaigns:
Cunning_kitten (motivation: cyber_espionage, information_theft)
Threats:
Powershortshell
CVEs:
CVE-2021-40444 [Vulners]
Vulners: Score: 6.8, CVSS: 2.1,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2, -)
- microsoft windows 10 (1607, -, 1809, 1909, 2004, 20h2, 21h1)
- microsoft windows server 2016 (-, 2004, 20h2)
- microsoft windows rt 8.1 (-)
- microsoft windows server 2012 (-, -)
have more...
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...
IOCs:
Hash: 12
Url: 1
Path: 1
Domain: 1
25-06-2022
Cunning Kitten Threat group targeting people in the Middle East. related suggestion
https://www-freebuf-com.translate.goog/news/337241.html?_x_tr_sl=auto&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Actors/Campaigns:
Cunning_kitten (motivation: cyber_espionage, information_theft)
Threats:
Powershortshell
CVEs:
CVE-2021-40444 [Vulners]
Vulners: Score: 6.8, CVSS: 2.1,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2, -)
- microsoft windows 10 (1607, -, 1809, 1909, 2004, 20h2, 21h1)
- microsoft windows server 2016 (-, 2004, 20h2)
- microsoft windows rt 8.1 (-)
- microsoft windows server 2012 (-, -)
have more...
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...
IOCs:
Hash: 12
Url: 1
Path: 1
Domain: 1
www-freebuf-com.translate.goog
Cunning Kitten–针对中东相关人士的威胁组织 - FreeBuf网络安全行业门户
Cunning Kitten的攻击目标聚焦于世界各地的使用波斯语的相关人士,选取相关人士关心的政治话题发起攻击。
#ParsedReport
26-06-2022
APT34 - Saitama Agent. IntroductionPermalink
https://x-junior.github.io/malware%20analysis/2022/06/24/Apt34.html
Actors/Campaigns:
Oilrig
Threats:
Saitama (tags: backdoor, malware, phishing)
Industry:
Government
Geo:
Jordan
IOCs:
File: 22
Hash: 18
Path: 2
Domain: 12
IP: 29
Functions Names: 6
YARA: Found
Links:
26-06-2022
APT34 - Saitama Agent. IntroductionPermalink
https://x-junior.github.io/malware%20analysis/2022/06/24/Apt34.html
Actors/Campaigns:
Oilrig
Threats:
Saitama (tags: backdoor, malware, phishing)
Industry:
Government
Geo:
Jordan
IOCs:
File: 22
Hash: 18
Path: 2
Domain: 12
IP: 29
Functions Names: 6
YARA: Found
Links:
https://gist.github.com/monoxgas/1b36031c5593ebfed3229f4XJunior
APT34 - Saitama Agent
Saitama abuses the DNS protocol for its C2 communications. This is stealthier than other communication methods. Also uses techniques such as compression and long random sleep times to disguise malicious traffic in between legitimate traffic.
#ParsedReport
26-06-2022
Deep Analysis of Snake Keylogger. IntroductionPermalink
https://x-junior.github.io/malware%20analysis/2022/06/24/Snakekeylogger.html
Threats:
Snake_keylogger (tags: keylogger, rat, malware)
Mars_stealer
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 16
Hash: 24
Path: 2
Registry: 1
Functions Names: 11
YARA: Found
26-06-2022
Deep Analysis of Snake Keylogger. IntroductionPermalink
https://x-junior.github.io/malware%20analysis/2022/06/24/Snakekeylogger.html
Threats:
Snake_keylogger (tags: keylogger, rat, malware)
Mars_stealer
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 16
Hash: 24
Path: 2
Registry: 1
Functions Names: 11
YARA: Found
XJunior
Deep Analysis of Snake Keylogger
Snake Keylogger is a malware developed using .NET. It’s focused on stealing sensitive information from a victim’s device, including saved credentials, the victim’s keystrokes, screenshots of the victim’s screen, and clipboard data.
#ParsedReport
26-06-2022
Sonatype Blog. Python packages upload your AWS keys, env vars, secrets to the web
https://blog.sonatype.com/python-packages-upload-your-aws-keys-env-vars-secrets-to-web
IOCs:
Url: 2
Domain: 1
26-06-2022
Sonatype Blog. Python packages upload your AWS keys, env vars, secrets to the web
https://blog.sonatype.com/python-packages-upload-your-aws-keys-env-vars-secrets-to-web
IOCs:
Url: 2
Domain: 1
Sonatype
Malicious Python Packages Exfiltrate AWS Keys and Secrets
Multiple Python packages caught by Sonatype were seen uploading secrets such as AWS keys and environment variables to a web endpoint.
Forwarded from vx-underground
Lockbit ransomware group announced today Lockbit 3.0 is officially released with the message: "Make Ransomware Great Again!"
Additionally, Lockbit has launched their own Bug Bounty program paying for PII on high-profile individuals, web security exploits, and more...
Additionally, Lockbit has launched their own Bug Bounty program paying for PII on high-profile individuals, web security exploits, and more...
#ParsedReport
27-06-2022
Stories from the SOC - Detecting internal reconnaissance
https://cybersecurity.att.com/blogs/security-essentials/stories-from-the-soc-detecting-internal-reconnaissance
Threats:
Wannacry
Winrm_tool
27-06-2022
Stories from the SOC - Detecting internal reconnaissance
https://cybersecurity.att.com/blogs/security-essentials/stories-from-the-soc-detecting-internal-reconnaissance
Threats:
Wannacry
Winrm_tool
#ParsedReport
27-06-2022
research report. Analysis of shadowy botnets spread through download sites
https://www-antiy-cn.translate.goog/research/notice&report/research_report/20220624.html?_x_tr_sl=auto&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Actors/Campaigns:
Hidden_shadow
Threats:
Eternalblue_vuln
Trojan/win64.childhavetrojan
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 14
Path: 1
File: 4
27-06-2022
research report. Analysis of shadowy botnets spread through download sites
https://www-antiy-cn.translate.goog/research/notice&report/research_report/20220624.html?_x_tr_sl=auto&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Actors/Campaigns:
Hidden_shadow
Threats:
Eternalblue_vuln
Trojan/win64.childhavetrojan
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 14
Path: 1
File: 4
www-antiy-cn.translate.goog
通过下载站传播的匿影僵尸网络分析
安天是引领威胁检测与防御能力发展的网络安全国家队,为客户构建端点防护、流量监测、边界防护、导流捕获、深度分析、应急处置的安全基石
#ParsedReport
27-06-2022
Emotet: Still Abusing Microsoft Office Macros
https://www.netskope.com/blog/emotet-still-abusing-microsoft-office-macros
Threats:
Emotet (tags: malware, phishing, fraud, ransomware)
Goodwill
Jasmin
Follina_vuln
CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...
IOCs:
File: 6
YARA: Found
Links:
27-06-2022
Emotet: Still Abusing Microsoft Office Macros
https://www.netskope.com/blog/emotet-still-abusing-microsoft-office-macros
Threats:
Emotet (tags: malware, phishing, fraud, ransomware)
Goodwill
Jasmin
Follina_vuln
CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...
IOCs:
File: 6
YARA: Found
Links:
https://github.com/netskopeoss/NetskopeThreatLabsIOCs/tree/main/Emotet/2022-06-24https://github.com/mrexodia/dumpulatorhttps://github.com/netskopeoss/NetskopeThreatLabsIOCs/blob/main/Emotet/2022-06-24/script/extract\_xls\_urls.pyNetskope
Emotet: Still Abusing Microsoft Office Macros
Summary In April 2022, Netskope Threat Labs analyzed an Emotet campaign that was using LNK files instead of Microsoft Office documents, likely as a
#ParsedReport
27-06-2022
ASEC Weekly Malware Statistics ( 20220620 \~ 20220626 )
https://asec-ahnlab-com.translate.goog/ko/35940/?_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Threats:
Agent_tesla (tags: malware)
Azorult (tags: malware)
Cloudeye (tags: malware)
Formbook (tags: malware)
Remcos_rat (tags: malware)
Nanocore_rat (tags: malware)
Emotet (tags: malware)
Qakbot (tags: malware)
Trickbot (tags: malware)
Industry:
Financial
Geo:
Asian, Korea
IOCs:
Domain: 4
IP: 4
Email: 6
File: 22
Url: 27
27-06-2022
ASEC Weekly Malware Statistics ( 20220620 \~ 20220626 )
https://asec-ahnlab-com.translate.goog/ko/35940/?_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Threats:
Agent_tesla (tags: malware)
Azorult (tags: malware)
Cloudeye (tags: malware)
Formbook (tags: malware)
Remcos_rat (tags: malware)
Nanocore_rat (tags: malware)
Emotet (tags: malware)
Qakbot (tags: malware)
Trickbot (tags: malware)
Industry:
Financial
Geo:
Asian, Korea
IOCs:
Domain: 4
IP: 4
Email: 6
File: 22
Url: 27
ASEC BLOG
ASEC 주간 악성코드 통계 ( 20220620 ~ 20220626 ) - ASEC BLOG
ASEC 분석팀에서는 ASEC 자동 분석 시스템 RAPIT 을 활용하여 알려진 악성코드들에 대한 분류 및 대응을 진행하고 있다. 본 포스팅에서는 2022년 6월 20일 월요일부터 6월 26일 일요일까지 한 주간 수집된 악성코드의 통계를 정리한다. 대분류 상으로는 인포스틸러가 53.8%로 1위를 차지하였으며, 그 다음으로는 다운로더가 25.1%, 백도어 14.8%, 뱅킹 악성코드4.9%, 랜섬웨어 1.3%로 집계되었다. Top 1 – AgentTesla…