CTT Report Hub
3.43K subscribers
9.91K photos
6 videos
67 files
13.6K links
Threat Intelligence Report Hub
Download Telegram
#ParsedReport
05-07-2022

Your Guide to Top Infostealers in 2022

https://blog.morphisec.com/infostealer-comparison

Threats:
Mars_stealer (tags: stealer, malware)
Vidar_stealer
Oski_stealer
Raccoon_stealer (tags: stealer)
Redline_stealer (tags: stealer)
Blackguard_stealer (tags: stealer, malware, rat, vpn)
Stormkitty_stealer (tags: stealer)
44caliber_stealer (tags: stealer)
Jester_stealer (tags: stealer, malware, vpn)

Industry:
Financial, Chemical, Entertainment

Geo:
Ukraine, Ukrainian, Russian

TTPs:
Tactics: 1
Technics: 0

IOCs:
File: 9

Links:
https://github.com/swagkarna/StormKitty
https://github.com/razexgod/44CALIBER
#ParsedReport
05-07-2022

Lockbit 3.0 Ransomware group launches new version. Lockbit Black actively targeting BFSI Sector

https://blog.cyble.com/2022/07/05/lockbit-3-0-ransomware-group-launches-new-version

Threats:
Lockbit (tags: malware, ransomware)

Industry:
Financial

Geo:
Spanish, Chinese

TTPs:
Tactics: 4
Technics: 8

IOCs:
File: 4
Hash: 1

Functions Names: 3
#ParsedReport
05-07-2022

IconBurst: NPM software supply chain attack grabs data from apps, websites

https://blog.reversinglabs.com/blog/iconburst-npm-software-supply-chain-attack-grabs-data-from-apps-websites

Threats:
Woxruz_tool

Geo:
German

IOCs:
Url: 3
Hash: 62

Functions Names: 2

Links:
https://github.com/ionic-team/ionicons
https://github.com/javascript-obfuscator/javascript-obfuscator
https://github.com/relative/synchrony
#ParsedReport
06-07-2022

Flubot: the evolution of a notorious Android Banking Malware

https://research.nccgroup.com/2022/07/05/flubot-the-evolution-of-a-notorious-android-banking-malware

Threats:
Flubot (tags: rat, phishing, malware, botnet, dns)
Anatsa

Industry:
Financial, Transport

Geo:
Asia, Italy, Czech, Sweden, Belgium, Turkey, Thailand, Serbia, Poland, Romania, Spain, Austria, Greece, Croatia, Switzerland, Spanish, Slovakia, Bulgaria, German, Netherlands, Australia, Portugal, Singapore, Korea, Germany, Japan, Hungary

IOCs:
File: 3
Hash: 33
#ParsedReport
06-07-2022

OrBit: New Undetected Linux Threat Uses Unique Hijack of Execution Flow

https://www.intezer.com/blog/incident-response/orbit-new-undetected-linux-threat

Actors/Campaigns:
Volatile_cedar

Threats:
Orbits_technique (tags: dropper, malware, backdoor)
Symbiote
Hiddenwasp
Hermeticwiper

Geo:
Israel

TTPs:
Tactics: 1
Technics: 0

IOCs:
Hash: 4
File: 1

Functions Names: 2
#ParsedReport
06-07-2022

From the Front Lines \| New macOS covid Malware Masquerades as Apple, Wears Face of APT

https://www.sentinelone.com/blog/from-the-front-lines-new-macos-covid-malware-masquerades-as-apple-wears-face-of-apt

Actors/Campaigns:
Lazarus

Threats:
Dazzlespy (tags: malware)
Zuru (tags: malware)
Macma (tags: malware)
Gimmick (tags: malware)
Sliver_tool

Geo:
Korean

TTPs:
Tactics: 1
Technics: 0

IOCs:
File: 1
Url: 1
Hash: 5
IP: 1

Links:
https://github.com/BishopFox/sliver
https://github.com/progrium/macdriver
#ParsedReport
06-07-2022

Luna Moth: The Actors Behind the Recent False Subscription Scams

https://blog.sygnia.co/luna-moth-false-subscription-scams

Actors/Campaigns:
Luna_moth (motivation: information_theft)

Threats:
Atera_tool
Splashtop_tool
Syncro_tool
Sharpshares_tool

Industry:
Financial

TTPs:
Tactics: 2
Technics: 0

IOCs:
Email: 4
Domain: 88
IP: 46

Links:
https://github.com/djhohnstein/SharpShares
#ParsedReport
06-07-2022

research report. Analysis of Active Hezb Mining Trojans

https://www-antiy-cn.translate.goog/research/notice&report/research_report/20220705.html?_x_tr_sl=auto&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp

CVEs:
CVE-2022-26134 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- atlassian confluence data center (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
- atlassian confluence server (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)

CVE-2022-29464 [Vulners]
Vulners: Score: 10.0, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- wso2 api manager (le4.0.0)
- wso2 enterprise integrator (le6.6.0)
- wso2 identity server (le5.11.0)
- wso2 identity server analytics (5.4.0, 5.4.1, 5.5.0, 5.6.0)
- wso2 identity server as key manager (le5.10.0)
have more...
CVE-2021-4034 [Vulners]
Vulners: Score: 7.2, CVSS: 3.5,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- polkit project polkit (*)
- redhat enterprise linux desktop (7.0)
- redhat enterprise linux workstation (7.0)
- redhat enterprise linux for scientific computing (7.0)
- redhat enterprise linux server (7.0, 6.0)
have more...

IOCs:
File: 10
Url: 10
IP: 3
Coin: 1
Hash: 6
#ParsedReport
07-07-2022

ASEC Weekly Malware Statistics (June 27th, 2022 July 3rd, 2022)

https://asec.ahnlab.com/en/36294

Threats:
Agent_tesla (tags: malware)
Formbook (tags: malware)
Clipboard_grabbing_technique (tags: malware)
Emotet (tags: malware)
Qakbot (tags: malware)
Trickbot (tags: malware)
Cloudeye (tags: malware)
Remcos_rat (tags: malware)
Nanocore_rat (tags: malware)
Lokibot_stealer (tags: malware)

Industry:
Financial

IOCs:
Domain: 2
IP: 3
Email: 6
File: 30
Url: 48
#ParsedReport
07-07-2022

Targets of Interest \| Russian Organizations Increasingly Under Attack By Chinese APTs

https://www.sentinelone.com/labs/targets-of-interest-russian-organizations-increasingly-under-attack-by-chinese-apts

Actors/Campaigns:
Red_delta
Scarab
Tonto_team

Threats:
Korlia (tags: malware)

Industry:
Telco, Government

Geo:
Russian, Russia, Chinese, Pakistan, Pakistani, Ukraines, Asia, Ukraine, Chinas

CVEs:
CVE-2018-0798 [Vulners]
Vulners: Score: 9.3, CVSS: 9.3,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2010, 2016, 2016, 2007, 2013)
- microsoft word (2013, 2016, 2007, 2010, 2013)
- microsoft office compatibility pack (-)


IOCs:
File: 3
Hash: 11
Domain: 4
IP: 2
#ParsedReport
07-07-2022

Unpacking Cloud-Based Cryptocurrency Miners That Abuse GitHub Actions and Azure Virtual Machines

https://www.trendmicro.com/en_us/research/22/g/unpacking-cloud-based-cryptocurrency-miners-that-abuse-github-ac.html

Threats:
Xmrig_miner (tags: cryptomining)

Industry:
E-commerce

IOCs:
File: 2
Coin: 7
Hash: 2

Links:
https://github.com/Hffffhujft/hahsy/blob/main/.github/workflows/main.yml
https://github.com/limoain14/Langs/blob/main/.github/workflows/main.yml
https://github.com/aldilariskhameilenia2018/mining22/blob/main/.github/workflows/blank.yml
https://github.com/nick-fields/retry
https://github.com/gesbul1989/VERUS/blob/main/.github/workflows/baru.yml
https://github.com/search?q=xmrig+extension%3Ayaml+extension%3Ayml+path%3A.github%2Fworkflows&type=Code
https://docs.github.com/en/actions/using-workflows/events-that-trigger-workflows#workflow\_dispatch
https://docs.github.com/en/actions/using-jobs/using-a-matrix-for-your-jobs
https://docs.github.com/en/actions/using-github-hosted-runners/about-github-hosted-runners
https://github.com/000h0/1hars/blob/circleci-project-setup/.github/workflows/main.yml
https://github.com/janjan1999/shiba/blob/main/.github/Workflows/KaptenCrypto.yml
https://github.com/wa2nderma1/StartNew/blob/main/.github/workflows/mulai1.yml
https://github.com/FixKRI1/miner/blob/main/.github/workflows/main.yml
https://github.com/wizman008/shiba/blob/main/.github/workflows/coins.yml
https://github.com/aldilariskhameilenia2018/mininggg/blob/main/.github/workflows/blank.yml
https://github.com/actions/checkout
https://github.com/jaknan/pg/blob/main/.github/workflows/main.yml
https://github.com/Olish420/nubatur/blob/main/.github/workflows/nubatur.yml
https://docs.github.com/en/actions/learn-github-actions/understanding-github-actions
https://github.com/dsdnklasmals/aaaaaaaaaaaaa/blob/main/.github/Workflows/KaptenCrypto.yml
https://github.com/Olish420/tron/blob/main/.github/workflows/tron.yml
https://github.com/jaknan/pg/actions
#ParsedReport
07-07-2022

Unprecedented Shift: The Trickbot Group is Systematically Attacking Ukraine

https://securityintelligence.com/posts/trickbot-group-systematically-attacking-ukraine

Actors/Campaigns:
Wizard_spider (motivation: cyber_criminal, financially_motivated, information_theft)
Ta578

Threats:
Trickbot (tags: malware, backdoor, phishing, ransomware, dropper, ddos, trojan)
Icedid (tags: malware, phishing, ransomware, dropper)
Cobalt_strike (tags: malware, phishing, ransomware, dropper, rat)
Meterpreter_tool (tags: phishing)
Bumblebee (tags: malware, ransomware, rat)
Conti
Ryuk
Diavol
Emotet
Tron
Bazarbackdoor
Anchor (tags: dropper)
Follina_vuln
Beacon
Putty_tool (tags: malware)

Industry:
Financial

Geo:
Ukraine, Ukraines, Belarus, Ukrainian, Russian, Russia

CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...

IOCs:
File: 10
Hash: 38
Url: 13
Domain: 3
Path: 4

Functions Names: 1
#ParsedReport
07-07-2022

Alert: Malicious campaign on behalf of the Tax and Customs Authority. Indicadores de Compromisso (IoCs)

https://seguranca-informatica.pt/alerta-campanha-maliciosa-em-nome-da-autoridade-tributaria-e-aduaneira/?utm_source=rss&utm_medium=rss&utm_campaign=alerta-campanha-maliciosa-em-nome-da-autoridade-tributaria-e-aduaneira

Industry:
Financial, Iot

Geo:
Portugal, Brasil, Portuguese

IOCs:
Url: 2
File: 2
#ParsedReport
06-07-2022

Brand-New HavanaCrypt Ransomware Poses as Google Software Update App, Uses Microsoft Hosting Service IP Address as C&C Server. Arrival

https://www.trendmicro.com/en_us/research/22/g/brand-new-havanacrypt-ransomware-poses-as-google-software-update.html

Threats:
Havanacrypt (tags: ransomware, malware, scan)

IOCs:
File: 8
IP: 1
Url: 3
Hash: 5

Links:
https://github.com/aramrami/KeePass-2.41/blob/master/KeePassLib/Cryptography/CryptoRandom.cs
https://github.com/DarkObb/DeObfuscar-Static
https://github.com/obfuscar/obfuscar
https://github.com/de4dot/de4dot