#ParsedReport
04-07-2022
Advanced Phishing Scams Target Individuals & Businesses in the Middle East
https://cloudsek.com/threatintelligence/advanced-phishing-scams-target-individuals-businesses-in-the-middle-east/?utm_source=rss&utm_medium=rss&utm_campaign=advanced-phishing-scams-target-individuals-businesses-in-the-middle-east
Industry:
Financial, Education, Government, Petroleum
TTPs:
Tactics: 1
Technics: 0
IOCs:
Domain: 124
Email: 3
Url: 2
04-07-2022
Advanced Phishing Scams Target Individuals & Businesses in the Middle East
https://cloudsek.com/threatintelligence/advanced-phishing-scams-target-individuals-businesses-in-the-middle-east/?utm_source=rss&utm_medium=rss&utm_campaign=advanced-phishing-scams-target-individuals-businesses-in-the-middle-east
Industry:
Financial, Education, Government, Petroleum
TTPs:
Tactics: 1
Technics: 0
IOCs:
Domain: 124
Email: 3
Url: 2
CloudSEK - Digital Risk Management Enterprise | Artificial Intelligence based Cybersecurity
Advanced Phishing Scams campaign Target Individuals & Businesses in the Middle East
An ongoing Phishing Scams campaign is targeting various government as well as corporate entities in the Finance, Travel, Hospital, Legal, Oil and Gas, and Consultation industries. Domain exposed a full-fledged campaign, where the threat actors were impersonating…
#ParsedReport
04-07-2022
Threat Actor Claiming to have Compromised IBM & Stanford University Disclose Their TTPs
https://www.cloudsek.com/threatintelligence/threat-actor-claiming-to-have-compromised-ibm-stanford-university-disclose-their-ttps
Threats:
Log4shell_vuln
Industry:
Financial, Education, Government
Geo:
Ukraine, Thailand, Pakistan, Nepal, Slovakia, Kenya, Bhutan, Indonesia, Srilanka
TTPs:
Tactics: 1
Technics: 0
04-07-2022
Threat Actor Claiming to have Compromised IBM & Stanford University Disclose Their TTPs
https://www.cloudsek.com/threatintelligence/threat-actor-claiming-to-have-compromised-ibm-stanford-university-disclose-their-ttps
Threats:
Log4shell_vuln
Industry:
Financial, Education, Government
Geo:
Ukraine, Thailand, Pakistan, Nepal, Slovakia, Kenya, Bhutan, Indonesia, Srilanka
TTPs:
Tactics: 1
Technics: 0
Cloudsek
Threat Actor Claiming to have Compromised IBM & Stanford University Disclose Their TTPs | Threat Intelligence | CloudSEK
XVigil identified a post on an English-speaking cybercrime forum mentioning Jenkins as one of the TTPs used by a threat actor. This module has hidden desktop takeover capabilities to get clicks on ads.
#ParsedReport
04-07-2022
Two Copycats of LockBit Ransomware: SolidBit and CryptOn. Executive Summary
https://medium.com/s2wblog/two-copycats-of-lockbit-ransomware-solidbit-and-crypton-7257fb069b16
Threats:
Lockbit (tags: ransomware, stealer)
Yashma
Chaos
Prometheus
Revil
Blackguard_stealer
Industry:
Telco
Geo:
Netherlands
IOCs:
Hash: 5
04-07-2022
Two Copycats of LockBit Ransomware: SolidBit and CryptOn. Executive Summary
https://medium.com/s2wblog/two-copycats-of-lockbit-ransomware-solidbit-and-crypton-7257fb069b16
Threats:
Lockbit (tags: ransomware, stealer)
Yashma
Chaos
Prometheus
Revil
Blackguard_stealer
Industry:
Telco
Geo:
Netherlands
IOCs:
Hash: 5
Medium
Two Copycats of LockBit Ransomware: SolidBit and CryptOn
Author: S2W TALON
#ParsedReport
04-07-2022
GuLoader is distributing a quotation request as a disguised phishing email
https://asec-ahnlab-com.translate.goog/ko/36096/?_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Threats:
Cloudeye (tags: phishing, malware, stealer, ransomware, rat)
Agent_tesla (tags: phishing)
Formbook (tags: phishing)
Remcos_rat (tags: phishing)
Nanocore_rat (tags: phishing)
Industry:
Financial
Geo:
Korean
IOCs:
File: 5
Url: 1
Hash: 1
Functions Names: 1
04-07-2022
GuLoader is distributing a quotation request as a disguised phishing email
https://asec-ahnlab-com.translate.goog/ko/36096/?_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Threats:
Cloudeye (tags: phishing, malware, stealer, ransomware, rat)
Agent_tesla (tags: phishing)
Formbook (tags: phishing)
Remcos_rat (tags: phishing)
Nanocore_rat (tags: phishing)
Industry:
Financial
Geo:
Korean
IOCs:
File: 5
Url: 1
Hash: 1
Functions Names: 1
ASEC BLOG
견적의뢰서 위장 피싱 메일로 유포 중인 GuLoader - ASEC BLOG
ASEC 분석팀에서 해당 블로그에 매주 업데이트 중인 주간 Top5 악성코드 키워드에 GuLoader가 2년만에 다시 랭크되었다. GuLoader는 추가 악성코드를 다운로드하는 다운로더 형태의 악성코드이며 다운로드 주소로 구글 드라이브가 자주 사용되어 해당 이름으로 명명되었다. ASEC 분석팀에서는 이 유형의 악성코드가 올 2022년 2분기 동안 유포된 Downloader 형의 악성코드 중 가장 많은 비중을 차지하고 있는 것으로 파악했으며 아래와 같이…
#ParsedReport
05-07-2022
Hive ransomware gets upgrades in Rust. Recommended customer actions
https://www.microsoft.com/security/blog/2022/07/05/hive-ransomware-gets-upgrades-in-rust
Actors/Campaigns:
Fin12
Threats:
Hive (tags: ransomware, rat, malware)
Ransom:win64/hive
Ransom:win32/hive
Industry:
Education, Financial, Healthcare
Geo:
Korea
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 10
Hash: 9
Path: 1
Links:
05-07-2022
Hive ransomware gets upgrades in Rust. Recommended customer actions
https://www.microsoft.com/security/blog/2022/07/05/hive-ransomware-gets-upgrades-in-rust
Actors/Campaigns:
Fin12
Threats:
Hive (tags: ransomware, rat, malware)
Ransom:win64/hive
Ransom:win32/hive
Industry:
Education, Financial, Healthcare
Geo:
Korea
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 10
Hash: 9
Path: 1
Links:
https://github.com/Azure/Azure-Sentinel/blob/master/Hunting%20Queries/MultipleDataSources/BackupDeletion.yamlhttps://github.com/Azure/Azure-Sentinel/blob/master/Detections/MultipleDataSources/HiveRansomwareJuly2022.yamlhttps://github.com/Azure/Azure-Sentinel/blob/master/Detections/SecurityAlert/HiveRansomwareAVHits.yamlMicrosoft News
Hive ransomware gets upgrades in Rust
With its latest variant carrying several major upgrades, Hive proves it’s one of the fastest evolving ransomware payload, exemplifying the continuously changing ransomware ecosystem.
#ParsedReport
05-07-2022
JPCERT/CC Eyes
https://blogs.jpcert.or.jp/en/2022/07/vsingle.html
Actors/Campaigns:
Lazarus
Threats:
Vsingle (tags: malware)
Geo:
Usa
IOCs:
Hash: 3
05-07-2022
JPCERT/CC Eyes
https://blogs.jpcert.or.jp/en/2022/07/vsingle.html
Actors/Campaigns:
Lazarus
Threats:
Vsingle (tags: malware)
Geo:
Usa
IOCs:
Hash: 3
JPCERT/CC Eyes
VSingle malware that obtains C2 server information from GitHub - JPCERT/CC Eyes
Some types of malware use DGA, obfuscate...
#ParsedReport
05-07-2022
Your Guide to Top Infostealers in 2022
https://blog.morphisec.com/infostealer-comparison
Threats:
Mars_stealer (tags: stealer, malware)
Vidar_stealer
Oski_stealer
Raccoon_stealer (tags: stealer)
Redline_stealer (tags: stealer)
Blackguard_stealer (tags: stealer, malware, rat, vpn)
Stormkitty_stealer (tags: stealer)
44caliber_stealer (tags: stealer)
Jester_stealer (tags: stealer, malware, vpn)
Industry:
Financial, Chemical, Entertainment
Geo:
Ukraine, Ukrainian, Russian
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 9
Links:
05-07-2022
Your Guide to Top Infostealers in 2022
https://blog.morphisec.com/infostealer-comparison
Threats:
Mars_stealer (tags: stealer, malware)
Vidar_stealer
Oski_stealer
Raccoon_stealer (tags: stealer)
Redline_stealer (tags: stealer)
Blackguard_stealer (tags: stealer, malware, rat, vpn)
Stormkitty_stealer (tags: stealer)
44caliber_stealer (tags: stealer)
Jester_stealer (tags: stealer, malware, vpn)
Industry:
Financial, Chemical, Entertainment
Geo:
Ukraine, Ukrainian, Russian
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 9
Links:
https://github.com/swagkarna/StormKittyhttps://github.com/razexgod/44CALIBERMorphisec
Your Guide to Top Infostealers in 2022
An infostealer attack can be extremely damaging—and attacks are on the rise. Morphisec analyzes six of the top infostealers used in 2022.
#ParsedReport
05-07-2022
Lockbit 3.0 Ransomware group launches new version. Lockbit Black actively targeting BFSI Sector
https://blog.cyble.com/2022/07/05/lockbit-3-0-ransomware-group-launches-new-version
Threats:
Lockbit (tags: malware, ransomware)
Industry:
Financial
Geo:
Spanish, Chinese
TTPs:
Tactics: 4
Technics: 8
IOCs:
File: 4
Hash: 1
Functions Names: 3
05-07-2022
Lockbit 3.0 Ransomware group launches new version. Lockbit Black actively targeting BFSI Sector
https://blog.cyble.com/2022/07/05/lockbit-3-0-ransomware-group-launches-new-version
Threats:
Lockbit (tags: malware, ransomware)
Industry:
Financial
Geo:
Spanish, Chinese
TTPs:
Tactics: 4
Technics: 8
IOCs:
File: 4
Hash: 1
Functions Names: 3
Cyble
Cyble - Lockbit 3.0 - Ransomware Group Launches New Version
Cyble analyzes the return of Lockbit ransomware as Lockbit 3.0/"Lockbit Black" and how it has been actively targeting the BFSI sector.
#ParsedReport
05-07-2022
IconBurst: NPM software supply chain attack grabs data from apps, websites
https://blog.reversinglabs.com/blog/iconburst-npm-software-supply-chain-attack-grabs-data-from-apps-websites
Threats:
Woxruz_tool
Geo:
German
IOCs:
Url: 3
Hash: 62
Functions Names: 2
Links:
05-07-2022
IconBurst: NPM software supply chain attack grabs data from apps, websites
https://blog.reversinglabs.com/blog/iconburst-npm-software-supply-chain-attack-grabs-data-from-apps-websites
Threats:
Woxruz_tool
Geo:
German
IOCs:
Url: 3
Hash: 62
Functions Names: 2
Links:
https://github.com/ionic-team/ioniconshttps://github.com/javascript-obfuscator/javascript-obfuscatorhttps://github.com/relative/synchronyReversingLabs
RL Blog | ReversingLabs | ReversingLabs
RL Blog: AppSec & Supply Chain Security, Dev & DevSecOps, Threat Research, and Security Operations (SecOps)
#ParsedReport
06-07-2022
CuteBoi Detected Preparing a Large-Scale Crypto Mining Campaign on NPM Users. Details
https://checkmarx.com/blog/cuteboi-detected-preparing-a-large-scale-crypto-mining-campaign-on-npm-users
Actors/Campaigns:
Cuteboi
Red_lili
Threats:
Eazyminer
Xmrig_miner (tags: cryptomining)
IOCs:
Hash: 2
Links:
06-07-2022
CuteBoi Detected Preparing a Large-Scale Crypto Mining Campaign on NPM Users. Details
https://checkmarx.com/blog/cuteboi-detected-preparing-a-large-scale-crypto-mining-campaign-on-npm-users
Actors/Campaigns:
Cuteboi
Red_lili
Threats:
Eazyminer
Xmrig_miner (tags: cryptomining)
IOCs:
Hash: 2
Links:
https://github.com/checkmarx/cuteboiCheckmarx
“CuteBoi” Detected Preparing a Large-Scale Crypto Mining Campaign on NPM Users
Checkmarx SCS team detected over 1200 npm packages released to the registry by over a thousand different user accounts. This was done using automation which includes the ability to pass NPM 2FA challenge. This cluster of packages seems to be a part of an…
#ParsedReport
06-07-2022
North Korean State-Sponsored Cyber Actors Use Maui Ransomware to Target the Healthcare and Public Health Sector
https://us-cert.cisa.gov/ncas/current-activity/2022/07/06/north-korean-state-sponsored-cyber-actors-use-maui-ransomware
Threats:
Medusalocker
Log4shell_vuln
Spring4shell
Industry:
Healthcare
Geo:
Korea, Korean
06-07-2022
North Korean State-Sponsored Cyber Actors Use Maui Ransomware to Target the Healthcare and Public Health Sector
https://us-cert.cisa.gov/ncas/current-activity/2022/07/06/north-korean-state-sponsored-cyber-actors-use-maui-ransomware
Threats:
Medusalocker
Log4shell_vuln
Spring4shell
Industry:
Healthcare
Geo:
Korea, Korean
www.cisa.gov
North Korean State-Sponsored Cyber Actors Use Maui Ransomware to Target the Healthcare and Public Health Sector | CISA
CISA, the Federal Bureau of Investigation (FBI), and the Department of the Treasury (Treasury) have released a joint Cybersecurity Advisory (CSA), North Korean State-Sponsored Cyber Actors Use Maui Ransomware to Target the Healthcare and Public Health Sector…
#ParsedReport
06-07-2022
Flubot: the evolution of a notorious Android Banking Malware
https://research.nccgroup.com/2022/07/05/flubot-the-evolution-of-a-notorious-android-banking-malware
Threats:
Flubot (tags: rat, phishing, malware, botnet, dns)
Anatsa
Industry:
Financial, Transport
Geo:
Asia, Italy, Czech, Sweden, Belgium, Turkey, Thailand, Serbia, Poland, Romania, Spain, Austria, Greece, Croatia, Switzerland, Spanish, Slovakia, Bulgaria, German, Netherlands, Australia, Portugal, Singapore, Korea, Germany, Japan, Hungary
IOCs:
File: 3
Hash: 33
06-07-2022
Flubot: the evolution of a notorious Android Banking Malware
https://research.nccgroup.com/2022/07/05/flubot-the-evolution-of-a-notorious-android-banking-malware
Threats:
Flubot (tags: rat, phishing, malware, botnet, dns)
Anatsa
Industry:
Financial, Transport
Geo:
Asia, Italy, Czech, Sweden, Belgium, Turkey, Thailand, Serbia, Poland, Romania, Spain, Austria, Greece, Croatia, Switzerland, Spanish, Slovakia, Bulgaria, German, Netherlands, Australia, Portugal, Singapore, Korea, Germany, Japan, Hungary
IOCs:
File: 3
Hash: 33
NCC Group Research Blog
Flubot: the evolution of a notorious Android Banking Malware
Originally published June 29, 2022 on the Fox-IT blog Authored by Alberto Segura (main author) and Rolf Govers (co-author) Summary Flubot is an Android based malware that has been distributed in th…
#ParsedReport
06-07-2022
OrBit: New Undetected Linux Threat Uses Unique Hijack of Execution Flow
https://www.intezer.com/blog/incident-response/orbit-new-undetected-linux-threat
Actors/Campaigns:
Volatile_cedar
Threats:
Orbits_technique (tags: dropper, malware, backdoor)
Symbiote
Hiddenwasp
Hermeticwiper
Geo:
Israel
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 4
File: 1
Functions Names: 2
06-07-2022
OrBit: New Undetected Linux Threat Uses Unique Hijack of Execution Flow
https://www.intezer.com/blog/incident-response/orbit-new-undetected-linux-threat
Actors/Campaigns:
Volatile_cedar
Threats:
Orbits_technique (tags: dropper, malware, backdoor)
Symbiote
Hiddenwasp
Hermeticwiper
Geo:
Israel
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 4
File: 1
Functions Names: 2
Intezer
OrBit: New Undetected Linux Threat Uses Unique Hijack of Execution Flow
OrBit is a new Linux malware that hijacks the execution flow, evading and gaining persistence to get remote access and steal information.
#ParsedReport
06-07-2022
ALPHV Ransomware expands its Arsenal of Extortion techniques. Searchable Databases compound the risk of Supply Chain Attacks
https://blog.cyble.com/2022/07/06/alphv-ransomware-expands-its-arsenal-of-extortion-techniques
Actors/Campaigns:
Blackcat
Darkside
Blackmatter
Karakurt
06-07-2022
ALPHV Ransomware expands its Arsenal of Extortion techniques. Searchable Databases compound the risk of Supply Chain Attacks
https://blog.cyble.com/2022/07/06/alphv-ransomware-expands-its-arsenal-of-extortion-techniques
Actors/Campaigns:
Blackcat
Darkside
Blackmatter
Karakurt
Cyble
ALPHV Ransomware expands its Arsenal of Extortion techniques
Cyble analyzes ALPHV's updated TTPs and its possible links to other known ransomware groups like BlackMatter and DarkSide.
#ParsedReport
06-07-2022
ASEC Weekly Malware Statistics ( 20220627 \~ 20220703 )
https://asec-ahnlab-com.translate.goog/ko/36232/?_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Threats:
Agent_tesla (tags: malware)
Azorult (tags: malware)
Formbook (tags: malware)
Clipboard_grabbing_technique (tags: malware)
Emotet (tags: malware)
Qakbot (tags: malware)
Trickbot (tags: malware)
Cloudeye (tags: malware)
Remcos_rat (tags: malware)
Nanocore_rat (tags: malware)
Lokibot_stealer (tags: malware)
Avemaria_rat (tags: malware)
Industry:
Financial, Transport
Geo:
Korea
IOCs:
Domain: 1
IP: 3
Email: 6
File: 30
Url: 49
06-07-2022
ASEC Weekly Malware Statistics ( 20220627 \~ 20220703 )
https://asec-ahnlab-com.translate.goog/ko/36232/?_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Threats:
Agent_tesla (tags: malware)
Azorult (tags: malware)
Formbook (tags: malware)
Clipboard_grabbing_technique (tags: malware)
Emotet (tags: malware)
Qakbot (tags: malware)
Trickbot (tags: malware)
Cloudeye (tags: malware)
Remcos_rat (tags: malware)
Nanocore_rat (tags: malware)
Lokibot_stealer (tags: malware)
Avemaria_rat (tags: malware)
Industry:
Financial, Transport
Geo:
Korea
IOCs:
Domain: 1
IP: 3
Email: 6
File: 30
Url: 49
ASEC BLOG
ASEC 주간 악성코드 통계 ( 20220627 ~ 20220703 ) - ASEC BLOG
ASEC 분석팀에서는 ASEC 자동 분석 시스템 RAPIT 을 활용하여 알려진 악성코드들에 대한 분류 및 대응을 진행하고 있다. 본 포스팅에서는 2022년 6월 27일 월요일부터 7월 3일 일요일까지 한 주간 수집된 악성코드의 통계를 정리한다. 대분류 상으로는 인포스틸러가 48.0%로 1위를 차지하였으며, 그 다음으로는 뱅킹 악성코드가 26.5%, RAT 12.5%, 다운로더가 8.2%, 랜섬웨어 2.2%, 코인마이너 1.8%, 백도어가 0.7%로 집계되었다.…
#ParsedReport
06-07-2022
From the Front Lines \| New macOS covid Malware Masquerades as Apple, Wears Face of APT
https://www.sentinelone.com/blog/from-the-front-lines-new-macos-covid-malware-masquerades-as-apple-wears-face-of-apt
Actors/Campaigns:
Lazarus
Threats:
Dazzlespy (tags: malware)
Zuru (tags: malware)
Macma (tags: malware)
Gimmick (tags: malware)
Sliver_tool
Geo:
Korean
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 1
Url: 1
Hash: 5
IP: 1
Links:
06-07-2022
From the Front Lines \| New macOS covid Malware Masquerades as Apple, Wears Face of APT
https://www.sentinelone.com/blog/from-the-front-lines-new-macos-covid-malware-masquerades-as-apple-wears-face-of-apt
Actors/Campaigns:
Lazarus
Threats:
Dazzlespy (tags: malware)
Zuru (tags: malware)
Macma (tags: malware)
Gimmick (tags: malware)
Sliver_tool
Geo:
Korean
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 1
Url: 1
Hash: 5
IP: 1
Links:
https://github.com/BishopFox/sliverhttps://github.com/progrium/macdriverSentinelOne
From the Front Lines | New macOS ‘covid’ Malware Masquerades as Apple, Wears Face of APT
A fake VPN delivers a Sliver implant with a further malicious payload. APT or Red Team? The IoCs can look the same to defenders.
#ParsedReport
06-07-2022
Luna Moth: The Actors Behind the Recent False Subscription Scams
https://blog.sygnia.co/luna-moth-false-subscription-scams
Actors/Campaigns:
Luna_moth (motivation: information_theft)
Threats:
Atera_tool
Splashtop_tool
Syncro_tool
Sharpshares_tool
Industry:
Financial
TTPs:
Tactics: 2
Technics: 0
IOCs:
Email: 4
Domain: 88
IP: 46
Links:
06-07-2022
Luna Moth: The Actors Behind the Recent False Subscription Scams
https://blog.sygnia.co/luna-moth-false-subscription-scams
Actors/Campaigns:
Luna_moth (motivation: information_theft)
Threats:
Atera_tool
Splashtop_tool
Syncro_tool
Sharpshares_tool
Industry:
Financial
TTPs:
Tactics: 2
Technics: 0
IOCs:
Email: 4
Domain: 88
IP: 46
Links:
https://github.com/djhohnstein/SharpSharesblog.sygnia.co
Luna Moth: The Threat Actors Behind Recent False Subscription Scams
Sygnia’s team identified 'Luna Moth' ransom group. The threat actors resemble false subscription scammers, focusing on corporate data theft.
#ParsedReport
06-07-2022
research report. Analysis of Active Hezb Mining Trojans
https://www-antiy-cn.translate.goog/research/notice&report/research_report/20220705.html?_x_tr_sl=auto&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
CVEs:
CVE-2022-26134 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- atlassian confluence data center (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
- atlassian confluence server (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
CVE-2022-29464 [Vulners]
Vulners: Score: 10.0, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- wso2 api manager (le4.0.0)
- wso2 enterprise integrator (le6.6.0)
- wso2 identity server (le5.11.0)
- wso2 identity server analytics (5.4.0, 5.4.1, 5.5.0, 5.6.0)
- wso2 identity server as key manager (le5.10.0)
have more...
CVE-2021-4034 [Vulners]
Vulners: Score: 7.2, CVSS: 3.5,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- polkit project polkit (*)
- redhat enterprise linux desktop (7.0)
- redhat enterprise linux workstation (7.0)
- redhat enterprise linux for scientific computing (7.0)
- redhat enterprise linux server (7.0, 6.0)
have more...
IOCs:
File: 10
Url: 10
IP: 3
Coin: 1
Hash: 6
06-07-2022
research report. Analysis of Active Hezb Mining Trojans
https://www-antiy-cn.translate.goog/research/notice&report/research_report/20220705.html?_x_tr_sl=auto&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
CVEs:
CVE-2022-26134 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- atlassian confluence data center (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
- atlassian confluence server (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
CVE-2022-29464 [Vulners]
Vulners: Score: 10.0, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- wso2 api manager (le4.0.0)
- wso2 enterprise integrator (le6.6.0)
- wso2 identity server (le5.11.0)
- wso2 identity server analytics (5.4.0, 5.4.1, 5.5.0, 5.6.0)
- wso2 identity server as key manager (le5.10.0)
have more...
CVE-2021-4034 [Vulners]
Vulners: Score: 7.2, CVSS: 3.5,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- polkit project polkit (*)
- redhat enterprise linux desktop (7.0)
- redhat enterprise linux workstation (7.0)
- redhat enterprise linux for scientific computing (7.0)
- redhat enterprise linux server (7.0, 6.0)
have more...
IOCs:
File: 10
Url: 10
IP: 3
Coin: 1
Hash: 6
www-antiy-cn.translate.goog
活跃的Hezb挖矿木马分析
安天是引领威胁检测与防御能力发展的网络安全国家队,为客户构建端点防护、流量监测、边界防护、导流捕获、深度分析、应急处置的安全基石
#ParsedReport
07-07-2022
AsyncRAT Being Distributed to Vulnerable MySQL Servers
https://asec.ahnlab.com/en/36315
Threats:
Asyncrat_rat (tags: malware, spam, rat)
Cobalt_strike
Remcos_rat
Cringe_rat
Gh0st_rat
Metasploit_tool
Trojan/win32.rl_generic.c4239825
Trojan/win32.inject.c500093
IOCs:
File: 1
Hash: 2
Url: 1
IP: 3
07-07-2022
AsyncRAT Being Distributed to Vulnerable MySQL Servers
https://asec.ahnlab.com/en/36315
Threats:
Asyncrat_rat (tags: malware, spam, rat)
Cobalt_strike
Remcos_rat
Cringe_rat
Gh0st_rat
Metasploit_tool
Trojan/win32.rl_generic.c4239825
Trojan/win32.inject.c500093
IOCs:
File: 1
Hash: 2
Url: 1
IP: 3
ASEC BLOG
AsyncRAT Being Distributed to Unsecured MySQL Servers - ASEC BLOG
The ShadowServer foundation has recently released a report showing that there are about 3.6 million MySQL servers exposed to outside. Along with MS-SQL server, MySQL server is one of the main database servers that provides the feature of managing large amounts…
#ParsedReport
07-07-2022
ASEC Weekly Malware Statistics (June 27th, 2022 July 3rd, 2022)
https://asec.ahnlab.com/en/36294
Threats:
Agent_tesla (tags: malware)
Formbook (tags: malware)
Clipboard_grabbing_technique (tags: malware)
Emotet (tags: malware)
Qakbot (tags: malware)
Trickbot (tags: malware)
Cloudeye (tags: malware)
Remcos_rat (tags: malware)
Nanocore_rat (tags: malware)
Lokibot_stealer (tags: malware)
Industry:
Financial
IOCs:
Domain: 2
IP: 3
Email: 6
File: 30
Url: 48
07-07-2022
ASEC Weekly Malware Statistics (June 27th, 2022 July 3rd, 2022)
https://asec.ahnlab.com/en/36294
Threats:
Agent_tesla (tags: malware)
Formbook (tags: malware)
Clipboard_grabbing_technique (tags: malware)
Emotet (tags: malware)
Qakbot (tags: malware)
Trickbot (tags: malware)
Cloudeye (tags: malware)
Remcos_rat (tags: malware)
Nanocore_rat (tags: malware)
Lokibot_stealer (tags: malware)
Industry:
Financial
IOCs:
Domain: 2
IP: 3
Email: 6
File: 30
Url: 48
ASEC BLOG
ASEC Weekly Malware Statistics (June 27th, 2022 - July 3rd, 2022) - ASEC BLOG
The ASEC analysis team is using the ASEC automatic analysis system RAPIT to categorize and respond to known malware. This post will list weekly statistics collected from June 27th, 2022 (Monday) to July 3rd, 2022 (Sunday). For the main category, info-stealer…