CTT Report Hub
3.43K subscribers
9.93K photos
6 videos
67 files
13.6K links
Threat Intelligence Report Hub
Download Telegram
#ParsedReport
26-06-2022

APT34 - Saitama Agent. IntroductionPermalink

https://x-junior.github.io/malware%20analysis/2022/06/24/Apt34.html

Actors/Campaigns:
Oilrig

Threats:
Saitama (tags: backdoor, malware, phishing)

Industry:
Government

Geo:
Jordan

IOCs:
File: 22
Hash: 18
Path: 2
Domain: 12
IP: 29

Functions Names: 6

YARA: Found

Links:
https://gist.github.com/monoxgas/1b36031c5593ebfed3229f4
Bug Bounty программа для ренсовари... прикольно.
Forwarded from vx-underground
Lockbit ransomware group announced today Lockbit 3.0 is officially released with the message: "Make Ransomware Great Again!"

Additionally, Lockbit has launched their own Bug Bounty program paying for PII on high-profile individuals, web security exploits, and more...
#ParsedReport
27-06-2022

Stories from the SOC - Detecting internal reconnaissance

https://cybersecurity.att.com/blogs/security-essentials/stories-from-the-soc-detecting-internal-reconnaissance

Threats:
Wannacry
Winrm_tool
#ParsedReport
27-06-2022

Emotet: Still Abusing Microsoft Office Macros

https://www.netskope.com/blog/emotet-still-abusing-microsoft-office-macros

Threats:
Emotet (tags: malware, phishing, fraud, ransomware)
Goodwill
Jasmin
Follina_vuln

CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...

IOCs:
File: 6

YARA: Found

Links:
https://github.com/netskopeoss/NetskopeThreatLabsIOCs/tree/main/Emotet/2022-06-24
https://github.com/mrexodia/dumpulator
https://github.com/netskopeoss/NetskopeThreatLabsIOCs/blob/main/Emotet/2022-06-24/script/extract\_xls\_urls.py
#ParsedReport
27-06-2022

Return of the Evilnum APT with updated TTPs and newtargets.

https://www.zscaler.com/blogs/security-research/return-evilnum-apt-updated-ttps-and-new-targets

Actors/Campaigns:
Evilnum

Threats:
Beacon (tags: backdoor)

Industry:
Financial

TTPs:
Tactics: 1
Technics: 0

IOCs:
File: 22
Hash: 11
Domain: 36
Path: 5
IP: 1
Coin: 1

Functions Names: 1
#ParsedReport
28-06-2022

New Info-stealer Disguised as Crack Being Distributed

https://asec.ahnlab.com/en/35981

Threats:
Cryptbot_stealer
Redline_stealer
Vidar_stealer
Recordbreaker_stealer
Raccoon_stealer
Clipbanker
Infostealer/win.recordstealer.r498039
Infostealer/win.recordstealer.r500009
Infostealer/win.passstealer.r496906

Geo:
Russian

IOCs:
Url: 9
Coin: 9
Hash: 230
Domain: 26
#ParsedReport
28-06-2022

ASEC Weekly Malware Statistics (June 13th, 2022 June 19th, 2022)

https://asec.ahnlab.com/en/35859

Threats:
Agent_tesla (tags: malware)
Formbook (tags: malware)
Clipboard_grabbing_technique (tags: malware)
Lokibot_stealer (tags: malware)
Emotet (tags: malware)
Qakbot (tags: malware)
Trickbot (tags: malware)
Smokeloader (tags: malware)

Industry:
Transport, Financial

IOCs:
Domain: 18
Email: 3
File: 21
Url: 22
#ParsedReport
28-06-2022

ZuoRAT Hijacks SOHO Routers to Silently Stalk Networks

https://blog.lumen.com/zuorat-hijacks-soho-routers-to-silently-stalk-networks/?utm_source=rss&utm_medium=rss&utm_campaign=zuorat-hijacks-soho-routers-to-silently-stalk-networks

Threats:
Zuo_rat
Cobalt_strike
Emotet
Konni
Mirai

Geo:
Chinese, Canada, China, American, Russian, America, Taiwan

CVEs:
CVE-2020-26879 [Vulners]
Vulners: Score: 10.0, CVSS: 2.7,
Vulners: Exploitation: Unknown
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- commscope ruckus vriot (le1.5.1.0.21)

CVE-2020-26878 [Vulners]
Vulners: Score: 9.0, CVSS: 6.1,
Vulners: Exploitation: Unknown
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- commscope ruckus vriot (le1.5.1.0.21)


IOCs:
Domain: 4
Url: 7
IP: 8
File: 4
Path: 2

Functions Names: 1

Links:
https://github.com/jgamblin/Mirai-Source-Code
https://github.com/beyefendi/exploit/blob/main/ruckus151021.py
https://github.com/SolomonSklash/COM-Hijacking
https://github.com/blacklotuslabs/IOCs/blob/main/ZuoRAT\_IoCs.txt
#ParsedReport
28-06-2022

Attacks on industrial control systems using ShadowPad

https://ics-cert.kaspersky.com/publications/reports/2022/06/27/attacks-on-industrial-control-systems-using-shadowpad

Actors/Campaigns:
Hafnium
Red_delta

Threats:
Shadowpad (tags: proxy, rat, malware, backdoor)
Cobalt_strike
Plugx_rat (tags: backdoor)
Dll_hijacking_technique
Procdump_tool
Mimikatz
Nextnet_tool
Chinachopper

Industry:
Logistic, Telco, Transport, Ics

Geo:
Malaysia, Afghanistan, Pakistan, Chinese, China

CVEs:
CVE-2021-26855 [Vulners]
Vulners: Score: 7.5, CVSS: 6.4,
Vulners: Exploitation: True
X-Force: Risk: 9.1
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2016, 2016, 2013, 2016, 2016, 2013, 2016, 2019, 2013, 2016, 2016, 2016, 2016, 2016, 2016, 2016, 2019, 2019, 2019, 2019, 2019, 2019, 2019, 2019)


TTPs:
Tactics: 7
Technics: 22

IOCs:
File: 15
Path: 1
Domain: 12
Hash: 24
Url: 9
IP: 2

YARA: Found
#ParsedReport
28-06-2022

Revive: from spyware to Android banking trojan

https://www.cleafy.com/cleafy-labs/revive-from-spyware-to-android-banking-trojan

Threats:
Revive_rat (tags: spyware, trojan, keylogger, rat, fraud, malware, phishing)
Anatsa (tags: trojan, spyware)
Sharkbot
Teardroid
Oscorp

Industry:
Financial

Geo:
Francesco, Spanish

IOCs:
File: 1
Hash: 2
IP: 1
Domain: 2

Links:
https://github.com/ScRiPt1337/Teardroidv4\_api
https://github.com/ScRiPt1337/Teardroid-phprat
#ParsedReport
28-06-2022

Emotet: Still Abusing Microsoft Office Macros

https://www.netskope.com/blog/emotet-still-abusing-microsoft-office-macros

Threats:
Emotet (tags: ransomware, phishing, fraud, malware)
Goodwill
Jasmin
Follina_vuln

CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...

IOCs:
File: 6

YARA: Found

Links:
https://github.com/mrexodia/dumpulator
https://github.com/netskopeoss/NetskopeThreatLabsIOCs/tree/main/Emotet/2022-06-24
https://github.com/netskopeoss/NetskopeThreatLabsIOCs/blob/main/Emotet/2022-06-24/script/extract\_xls\_urls.py
#ParsedReport
28-06-2022

Bumblebee: New Loader Rapidly Assuming Central Position in Cyber-crime Ecosystem

https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/bumblebee-loader-cybercrime

Actors/Campaigns:
Wizard_spider

Threats:
Bumblebee (tags: backdoor, phishing, cryptomining, malware, rat, ransomware, trojan)
Conti (tags: malware, ransomware)
Mountlocker (tags: malware, ransomware)
Trickbot (tags: malware, ransomware)
Bazarbackdoor (tags: malware, ransomware)
Quantum_locker (tags: ransomware)
Cobalt_strike (tags: ransomware)
Metasploit_tool (tags: ransomware)
Adfind_tool (tags: phishing, rat, malware, ransomware)
Meterpreter_tool
Screenconnect_tool
Atera_tool
Avaddon
Ragnarlocker
Mimikatz
Lazagne
Netscan_tool
Ligolo
Procdump_tool
Diavol
Powersploit
Ryuk
Avoslocker
Empire_loader

Geo:
Canada

CVEs:
CVE-2021-34527 [Vulners]
Vulners: Score: 9.0, CVSS: 3.3,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2, -)
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 20h2, 21h1, 1809, 1909, 2004)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-, 20h2, 2004)
have more...

IOCs:
File: 16
IP: 6
Path: 2
Hash: 43
Domain: 1
Url: 6