#ParsedReport
25-06-2022
Ryuk Ransomware: Breakdown and Prevention Tips
https://www.varonis.com/blog/ryuk-ransomware
Actors/Campaigns:
Wizard_spider
Lazarus (motivation: cyber_criminal)
Threats:
Ryuk (tags: trojan, dns, ransomware, phishing, malware, spam)
Hermes (tags: ransomware)
Trickbot (tags: malware, ransomware)
Industry:
Healthcare, Financial
Geo:
Japanese
YARA: Found
25-06-2022
Ryuk Ransomware: Breakdown and Prevention Tips
https://www.varonis.com/blog/ryuk-ransomware
Actors/Campaigns:
Wizard_spider
Lazarus (motivation: cyber_criminal)
Threats:
Ryuk (tags: trojan, dns, ransomware, phishing, malware, spam)
Hermes (tags: ransomware)
Trickbot (tags: malware, ransomware)
Industry:
Healthcare, Financial
Geo:
Japanese
YARA: Found
Varonis
Ryuk Ransomware: Breakdown and Prevention Tips
Ryuk ransomware targets large organizations and spreads with deadly speed. Learn about the strain and how to prevent your company from becoming a victim.
#ParsedReport
25-06-2022
Cunning Kitten Threat group targeting people in the Middle East. related suggestion
https://www-freebuf-com.translate.goog/news/337241.html?_x_tr_sl=auto&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Actors/Campaigns:
Cunning_kitten (motivation: cyber_espionage, information_theft)
Threats:
Powershortshell
CVEs:
CVE-2021-40444 [Vulners]
Vulners: Score: 6.8, CVSS: 2.1,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2, -)
- microsoft windows 10 (1607, -, 1809, 1909, 2004, 20h2, 21h1)
- microsoft windows server 2016 (-, 2004, 20h2)
- microsoft windows rt 8.1 (-)
- microsoft windows server 2012 (-, -)
have more...
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...
IOCs:
Hash: 12
Url: 1
Path: 1
Domain: 1
25-06-2022
Cunning Kitten Threat group targeting people in the Middle East. related suggestion
https://www-freebuf-com.translate.goog/news/337241.html?_x_tr_sl=auto&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Actors/Campaigns:
Cunning_kitten (motivation: cyber_espionage, information_theft)
Threats:
Powershortshell
CVEs:
CVE-2021-40444 [Vulners]
Vulners: Score: 6.8, CVSS: 2.1,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2, -)
- microsoft windows 10 (1607, -, 1809, 1909, 2004, 20h2, 21h1)
- microsoft windows server 2016 (-, 2004, 20h2)
- microsoft windows rt 8.1 (-)
- microsoft windows server 2012 (-, -)
have more...
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...
IOCs:
Hash: 12
Url: 1
Path: 1
Domain: 1
www-freebuf-com.translate.goog
Cunning Kitten–针对中东相关人士的威胁组织 - FreeBuf网络安全行业门户
Cunning Kitten的攻击目标聚焦于世界各地的使用波斯语的相关人士,选取相关人士关心的政治话题发起攻击。
#ParsedReport
26-06-2022
APT34 - Saitama Agent. IntroductionPermalink
https://x-junior.github.io/malware%20analysis/2022/06/24/Apt34.html
Actors/Campaigns:
Oilrig
Threats:
Saitama (tags: backdoor, malware, phishing)
Industry:
Government
Geo:
Jordan
IOCs:
File: 22
Hash: 18
Path: 2
Domain: 12
IP: 29
Functions Names: 6
YARA: Found
Links:
26-06-2022
APT34 - Saitama Agent. IntroductionPermalink
https://x-junior.github.io/malware%20analysis/2022/06/24/Apt34.html
Actors/Campaigns:
Oilrig
Threats:
Saitama (tags: backdoor, malware, phishing)
Industry:
Government
Geo:
Jordan
IOCs:
File: 22
Hash: 18
Path: 2
Domain: 12
IP: 29
Functions Names: 6
YARA: Found
Links:
https://gist.github.com/monoxgas/1b36031c5593ebfed3229f4XJunior
APT34 - Saitama Agent
Saitama abuses the DNS protocol for its C2 communications. This is stealthier than other communication methods. Also uses techniques such as compression and long random sleep times to disguise malicious traffic in between legitimate traffic.
#ParsedReport
26-06-2022
Deep Analysis of Snake Keylogger. IntroductionPermalink
https://x-junior.github.io/malware%20analysis/2022/06/24/Snakekeylogger.html
Threats:
Snake_keylogger (tags: keylogger, rat, malware)
Mars_stealer
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 16
Hash: 24
Path: 2
Registry: 1
Functions Names: 11
YARA: Found
26-06-2022
Deep Analysis of Snake Keylogger. IntroductionPermalink
https://x-junior.github.io/malware%20analysis/2022/06/24/Snakekeylogger.html
Threats:
Snake_keylogger (tags: keylogger, rat, malware)
Mars_stealer
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 16
Hash: 24
Path: 2
Registry: 1
Functions Names: 11
YARA: Found
XJunior
Deep Analysis of Snake Keylogger
Snake Keylogger is a malware developed using .NET. It’s focused on stealing sensitive information from a victim’s device, including saved credentials, the victim’s keystrokes, screenshots of the victim’s screen, and clipboard data.
#ParsedReport
26-06-2022
Sonatype Blog. Python packages upload your AWS keys, env vars, secrets to the web
https://blog.sonatype.com/python-packages-upload-your-aws-keys-env-vars-secrets-to-web
IOCs:
Url: 2
Domain: 1
26-06-2022
Sonatype Blog. Python packages upload your AWS keys, env vars, secrets to the web
https://blog.sonatype.com/python-packages-upload-your-aws-keys-env-vars-secrets-to-web
IOCs:
Url: 2
Domain: 1
Sonatype
Malicious Python Packages Exfiltrate AWS Keys and Secrets
Multiple Python packages caught by Sonatype were seen uploading secrets such as AWS keys and environment variables to a web endpoint.
Forwarded from vx-underground
Lockbit ransomware group announced today Lockbit 3.0 is officially released with the message: "Make Ransomware Great Again!"
Additionally, Lockbit has launched their own Bug Bounty program paying for PII on high-profile individuals, web security exploits, and more...
Additionally, Lockbit has launched their own Bug Bounty program paying for PII on high-profile individuals, web security exploits, and more...
#ParsedReport
27-06-2022
Stories from the SOC - Detecting internal reconnaissance
https://cybersecurity.att.com/blogs/security-essentials/stories-from-the-soc-detecting-internal-reconnaissance
Threats:
Wannacry
Winrm_tool
27-06-2022
Stories from the SOC - Detecting internal reconnaissance
https://cybersecurity.att.com/blogs/security-essentials/stories-from-the-soc-detecting-internal-reconnaissance
Threats:
Wannacry
Winrm_tool
#ParsedReport
27-06-2022
research report. Analysis of shadowy botnets spread through download sites
https://www-antiy-cn.translate.goog/research/notice&report/research_report/20220624.html?_x_tr_sl=auto&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Actors/Campaigns:
Hidden_shadow
Threats:
Eternalblue_vuln
Trojan/win64.childhavetrojan
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 14
Path: 1
File: 4
27-06-2022
research report. Analysis of shadowy botnets spread through download sites
https://www-antiy-cn.translate.goog/research/notice&report/research_report/20220624.html?_x_tr_sl=auto&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Actors/Campaigns:
Hidden_shadow
Threats:
Eternalblue_vuln
Trojan/win64.childhavetrojan
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 14
Path: 1
File: 4
www-antiy-cn.translate.goog
通过下载站传播的匿影僵尸网络分析
安天是引领威胁检测与防御能力发展的网络安全国家队,为客户构建端点防护、流量监测、边界防护、导流捕获、深度分析、应急处置的安全基石
#ParsedReport
27-06-2022
Emotet: Still Abusing Microsoft Office Macros
https://www.netskope.com/blog/emotet-still-abusing-microsoft-office-macros
Threats:
Emotet (tags: malware, phishing, fraud, ransomware)
Goodwill
Jasmin
Follina_vuln
CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...
IOCs:
File: 6
YARA: Found
Links:
27-06-2022
Emotet: Still Abusing Microsoft Office Macros
https://www.netskope.com/blog/emotet-still-abusing-microsoft-office-macros
Threats:
Emotet (tags: malware, phishing, fraud, ransomware)
Goodwill
Jasmin
Follina_vuln
CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...
IOCs:
File: 6
YARA: Found
Links:
https://github.com/netskopeoss/NetskopeThreatLabsIOCs/tree/main/Emotet/2022-06-24https://github.com/mrexodia/dumpulatorhttps://github.com/netskopeoss/NetskopeThreatLabsIOCs/blob/main/Emotet/2022-06-24/script/extract\_xls\_urls.pyNetskope
Emotet: Still Abusing Microsoft Office Macros
Summary In April 2022, Netskope Threat Labs analyzed an Emotet campaign that was using LNK files instead of Microsoft Office documents, likely as a
#ParsedReport
27-06-2022
ASEC Weekly Malware Statistics ( 20220620 \~ 20220626 )
https://asec-ahnlab-com.translate.goog/ko/35940/?_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Threats:
Agent_tesla (tags: malware)
Azorult (tags: malware)
Cloudeye (tags: malware)
Formbook (tags: malware)
Remcos_rat (tags: malware)
Nanocore_rat (tags: malware)
Emotet (tags: malware)
Qakbot (tags: malware)
Trickbot (tags: malware)
Industry:
Financial
Geo:
Asian, Korea
IOCs:
Domain: 4
IP: 4
Email: 6
File: 22
Url: 27
27-06-2022
ASEC Weekly Malware Statistics ( 20220620 \~ 20220626 )
https://asec-ahnlab-com.translate.goog/ko/35940/?_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Threats:
Agent_tesla (tags: malware)
Azorult (tags: malware)
Cloudeye (tags: malware)
Formbook (tags: malware)
Remcos_rat (tags: malware)
Nanocore_rat (tags: malware)
Emotet (tags: malware)
Qakbot (tags: malware)
Trickbot (tags: malware)
Industry:
Financial
Geo:
Asian, Korea
IOCs:
Domain: 4
IP: 4
Email: 6
File: 22
Url: 27
ASEC BLOG
ASEC 주간 악성코드 통계 ( 20220620 ~ 20220626 ) - ASEC BLOG
ASEC 분석팀에서는 ASEC 자동 분석 시스템 RAPIT 을 활용하여 알려진 악성코드들에 대한 분류 및 대응을 진행하고 있다. 본 포스팅에서는 2022년 6월 20일 월요일부터 6월 26일 일요일까지 한 주간 수집된 악성코드의 통계를 정리한다. 대분류 상으로는 인포스틸러가 53.8%로 1위를 차지하였으며, 그 다음으로는 다운로더가 25.1%, 백도어 14.8%, 뱅킹 악성코드4.9%, 랜섬웨어 1.3%로 집계되었다. Top 1 – AgentTesla…
#ParsedReport
27-06-2022
Return of the Evilnum APT with updated TTPs and newtargets.
https://www.zscaler.com/blogs/security-research/return-evilnum-apt-updated-ttps-and-new-targets
Actors/Campaigns:
Evilnum
Threats:
Beacon (tags: backdoor)
Industry:
Financial
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 22
Hash: 11
Domain: 36
Path: 5
IP: 1
Coin: 1
Functions Names: 1
27-06-2022
Return of the Evilnum APT with updated TTPs and newtargets.
https://www.zscaler.com/blogs/security-research/return-evilnum-apt-updated-ttps-and-new-targets
Actors/Campaigns:
Evilnum
Threats:
Beacon (tags: backdoor)
Industry:
Financial
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 22
Hash: 11
Domain: 36
Path: 5
IP: 1
Coin: 1
Functions Names: 1
Zscaler
Evilnum APT returns with updated TTPs and New Targets | Blog
ThreatLabz has identified several instances of targeted attacks by Evilnum APT group against organizations in UK and Europe since early 2022.
#ParsedReport
28-06-2022
New Info-stealer Disguised as Crack Being Distributed
https://asec.ahnlab.com/en/35981
Threats:
Cryptbot_stealer
Redline_stealer
Vidar_stealer
Recordbreaker_stealer
Raccoon_stealer
Clipbanker
Infostealer/win.recordstealer.r498039
Infostealer/win.recordstealer.r500009
Infostealer/win.passstealer.r496906
Geo:
Russian
IOCs:
Url: 9
Coin: 9
Hash: 230
Domain: 26
28-06-2022
New Info-stealer Disguised as Crack Being Distributed
https://asec.ahnlab.com/en/35981
Threats:
Cryptbot_stealer
Redline_stealer
Vidar_stealer
Recordbreaker_stealer
Raccoon_stealer
Clipbanker
Infostealer/win.recordstealer.r498039
Infostealer/win.recordstealer.r500009
Infostealer/win.passstealer.r496906
Geo:
Russian
IOCs:
Url: 9
Coin: 9
Hash: 230
Domain: 26
ASEC
New Info-stealer Disguised as Crack Being Distributed - ASEC
New Info-stealer Disguised as Crack Being Distributed ASEC
#ParsedReport
28-06-2022
ASEC Weekly Malware Statistics (June 13th, 2022 June 19th, 2022)
https://asec.ahnlab.com/en/35859
Threats:
Agent_tesla (tags: malware)
Formbook (tags: malware)
Clipboard_grabbing_technique (tags: malware)
Lokibot_stealer (tags: malware)
Emotet (tags: malware)
Qakbot (tags: malware)
Trickbot (tags: malware)
Smokeloader (tags: malware)
Industry:
Transport, Financial
IOCs:
Domain: 18
Email: 3
File: 21
Url: 22
28-06-2022
ASEC Weekly Malware Statistics (June 13th, 2022 June 19th, 2022)
https://asec.ahnlab.com/en/35859
Threats:
Agent_tesla (tags: malware)
Formbook (tags: malware)
Clipboard_grabbing_technique (tags: malware)
Lokibot_stealer (tags: malware)
Emotet (tags: malware)
Qakbot (tags: malware)
Trickbot (tags: malware)
Smokeloader (tags: malware)
Industry:
Transport, Financial
IOCs:
Domain: 18
Email: 3
File: 21
Url: 22
ASEC BLOG
ASEC Weekly Malware Statistics (June 13th, 2022 - June 19th, 2022) - ASEC BLOG
The ASEC analysis team is using the ASEC automatic analysis system RAPIT to categorize and respond to known malware. This post will list weekly statistics collected from June 13th, 2022 (Monday) to June 19th, 2022 (Sunday). For the main category, info-stealer…
#ParsedReport
28-06-2022
ZuoRAT Hijacks SOHO Routers to Silently Stalk Networks
https://blog.lumen.com/zuorat-hijacks-soho-routers-to-silently-stalk-networks/?utm_source=rss&utm_medium=rss&utm_campaign=zuorat-hijacks-soho-routers-to-silently-stalk-networks
Threats:
Zuo_rat
Cobalt_strike
Emotet
Konni
Mirai
Geo:
Chinese, Canada, China, American, Russian, America, Taiwan
CVEs:
CVE-2020-26879 [Vulners]
Vulners: Score: 10.0, CVSS: 2.7,
Vulners: Exploitation: Unknown
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- commscope ruckus vriot (le1.5.1.0.21)
CVE-2020-26878 [Vulners]
Vulners: Score: 9.0, CVSS: 6.1,
Vulners: Exploitation: Unknown
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- commscope ruckus vriot (le1.5.1.0.21)
IOCs:
Domain: 4
Url: 7
IP: 8
File: 4
Path: 2
Functions Names: 1
Links:
28-06-2022
ZuoRAT Hijacks SOHO Routers to Silently Stalk Networks
https://blog.lumen.com/zuorat-hijacks-soho-routers-to-silently-stalk-networks/?utm_source=rss&utm_medium=rss&utm_campaign=zuorat-hijacks-soho-routers-to-silently-stalk-networks
Threats:
Zuo_rat
Cobalt_strike
Emotet
Konni
Mirai
Geo:
Chinese, Canada, China, American, Russian, America, Taiwan
CVEs:
CVE-2020-26879 [Vulners]
Vulners: Score: 10.0, CVSS: 2.7,
Vulners: Exploitation: Unknown
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- commscope ruckus vriot (le1.5.1.0.21)
CVE-2020-26878 [Vulners]
Vulners: Score: 9.0, CVSS: 6.1,
Vulners: Exploitation: Unknown
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- commscope ruckus vriot (le1.5.1.0.21)
IOCs:
Domain: 4
Url: 7
IP: 8
File: 4
Path: 2
Functions Names: 1
Links:
https://github.com/jgamblin/Mirai-Source-Code
https://github.com/beyefendi/exploit/blob/main/ruckus151021.py
https://github.com/SolomonSklash/COM-Hijacking
https://github.com/blacklotuslabs/IOCs/blob/main/ZuoRAT\_IoCs.txtLumen Blog
ZuoRAT hijacks SOHO routers to silently stalk networks
Infected SOHO routers can compromise sensitive data. Discover the tactics used by threat actors to exploit home office networks.
#ParsedReport
28-06-2022
Attacks on industrial control systems using ShadowPad
https://ics-cert.kaspersky.com/publications/reports/2022/06/27/attacks-on-industrial-control-systems-using-shadowpad
Actors/Campaigns:
Hafnium
Red_delta
Threats:
Shadowpad (tags: proxy, rat, malware, backdoor)
Cobalt_strike
Plugx_rat (tags: backdoor)
Dll_hijacking_technique
Procdump_tool
Mimikatz
Nextnet_tool
Chinachopper
Industry:
Logistic, Telco, Transport, Ics
Geo:
Malaysia, Afghanistan, Pakistan, Chinese, China
CVEs:
CVE-2021-26855 [Vulners]
Vulners: Score: 7.5, CVSS: 6.4,
Vulners: Exploitation: True
X-Force: Risk: 9.1
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2016, 2016, 2013, 2016, 2016, 2013, 2016, 2019, 2013, 2016, 2016, 2016, 2016, 2016, 2016, 2016, 2019, 2019, 2019, 2019, 2019, 2019, 2019, 2019)
TTPs:
Tactics: 7
Technics: 22
IOCs:
File: 15
Path: 1
Domain: 12
Hash: 24
Url: 9
IP: 2
YARA: Found
28-06-2022
Attacks on industrial control systems using ShadowPad
https://ics-cert.kaspersky.com/publications/reports/2022/06/27/attacks-on-industrial-control-systems-using-shadowpad
Actors/Campaigns:
Hafnium
Red_delta
Threats:
Shadowpad (tags: proxy, rat, malware, backdoor)
Cobalt_strike
Plugx_rat (tags: backdoor)
Dll_hijacking_technique
Procdump_tool
Mimikatz
Nextnet_tool
Chinachopper
Industry:
Logistic, Telco, Transport, Ics
Geo:
Malaysia, Afghanistan, Pakistan, Chinese, China
CVEs:
CVE-2021-26855 [Vulners]
Vulners: Score: 7.5, CVSS: 6.4,
Vulners: Exploitation: True
X-Force: Risk: 9.1
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2016, 2016, 2013, 2016, 2016, 2013, 2016, 2019, 2013, 2016, 2016, 2016, 2016, 2016, 2016, 2016, 2019, 2019, 2019, 2019, 2019, 2019, 2019, 2019)
TTPs:
Tactics: 7
Technics: 22
IOCs:
File: 15
Path: 1
Domain: 12
Hash: 24
Url: 9
IP: 2
YARA: Found