CTT Report Hub
3.43K subscribers
9.91K photos
6 videos
67 files
13.6K links
Threat Intelligence Report Hub
Download Telegram
#ParsedReport
07-07-2022

ASEC Weekly Malware Statistics (June 27th, 2022 July 3rd, 2022)

https://asec.ahnlab.com/en/36294

Threats:
Agent_tesla (tags: malware)
Formbook (tags: malware)
Clipboard_grabbing_technique (tags: malware)
Emotet (tags: malware)
Qakbot (tags: malware)
Trickbot (tags: malware)
Cloudeye (tags: malware)
Remcos_rat (tags: malware)
Nanocore_rat (tags: malware)
Lokibot_stealer (tags: malware)

Industry:
Financial

IOCs:
Domain: 2
IP: 3
Email: 6
File: 30
Url: 48
#ParsedReport
07-07-2022

Targets of Interest \| Russian Organizations Increasingly Under Attack By Chinese APTs

https://www.sentinelone.com/labs/targets-of-interest-russian-organizations-increasingly-under-attack-by-chinese-apts

Actors/Campaigns:
Red_delta
Scarab
Tonto_team

Threats:
Korlia (tags: malware)

Industry:
Telco, Government

Geo:
Russian, Russia, Chinese, Pakistan, Pakistani, Ukraines, Asia, Ukraine, Chinas

CVEs:
CVE-2018-0798 [Vulners]
Vulners: Score: 9.3, CVSS: 9.3,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2010, 2016, 2016, 2007, 2013)
- microsoft word (2013, 2016, 2007, 2010, 2013)
- microsoft office compatibility pack (-)


IOCs:
File: 3
Hash: 11
Domain: 4
IP: 2
#ParsedReport
07-07-2022

Unpacking Cloud-Based Cryptocurrency Miners That Abuse GitHub Actions and Azure Virtual Machines

https://www.trendmicro.com/en_us/research/22/g/unpacking-cloud-based-cryptocurrency-miners-that-abuse-github-ac.html

Threats:
Xmrig_miner (tags: cryptomining)

Industry:
E-commerce

IOCs:
File: 2
Coin: 7
Hash: 2

Links:
https://github.com/Hffffhujft/hahsy/blob/main/.github/workflows/main.yml
https://github.com/limoain14/Langs/blob/main/.github/workflows/main.yml
https://github.com/aldilariskhameilenia2018/mining22/blob/main/.github/workflows/blank.yml
https://github.com/nick-fields/retry
https://github.com/gesbul1989/VERUS/blob/main/.github/workflows/baru.yml
https://github.com/search?q=xmrig+extension%3Ayaml+extension%3Ayml+path%3A.github%2Fworkflows&type=Code
https://docs.github.com/en/actions/using-workflows/events-that-trigger-workflows#workflow\_dispatch
https://docs.github.com/en/actions/using-jobs/using-a-matrix-for-your-jobs
https://docs.github.com/en/actions/using-github-hosted-runners/about-github-hosted-runners
https://github.com/000h0/1hars/blob/circleci-project-setup/.github/workflows/main.yml
https://github.com/janjan1999/shiba/blob/main/.github/Workflows/KaptenCrypto.yml
https://github.com/wa2nderma1/StartNew/blob/main/.github/workflows/mulai1.yml
https://github.com/FixKRI1/miner/blob/main/.github/workflows/main.yml
https://github.com/wizman008/shiba/blob/main/.github/workflows/coins.yml
https://github.com/aldilariskhameilenia2018/mininggg/blob/main/.github/workflows/blank.yml
https://github.com/actions/checkout
https://github.com/jaknan/pg/blob/main/.github/workflows/main.yml
https://github.com/Olish420/nubatur/blob/main/.github/workflows/nubatur.yml
https://docs.github.com/en/actions/learn-github-actions/understanding-github-actions
https://github.com/dsdnklasmals/aaaaaaaaaaaaa/blob/main/.github/Workflows/KaptenCrypto.yml
https://github.com/Olish420/tron/blob/main/.github/workflows/tron.yml
https://github.com/jaknan/pg/actions
#ParsedReport
07-07-2022

Unprecedented Shift: The Trickbot Group is Systematically Attacking Ukraine

https://securityintelligence.com/posts/trickbot-group-systematically-attacking-ukraine

Actors/Campaigns:
Wizard_spider (motivation: cyber_criminal, financially_motivated, information_theft)
Ta578

Threats:
Trickbot (tags: malware, backdoor, phishing, ransomware, dropper, ddos, trojan)
Icedid (tags: malware, phishing, ransomware, dropper)
Cobalt_strike (tags: malware, phishing, ransomware, dropper, rat)
Meterpreter_tool (tags: phishing)
Bumblebee (tags: malware, ransomware, rat)
Conti
Ryuk
Diavol
Emotet
Tron
Bazarbackdoor
Anchor (tags: dropper)
Follina_vuln
Beacon
Putty_tool (tags: malware)

Industry:
Financial

Geo:
Ukraine, Ukraines, Belarus, Ukrainian, Russian, Russia

CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...

IOCs:
File: 10
Hash: 38
Url: 13
Domain: 3
Path: 4

Functions Names: 1
#ParsedReport
07-07-2022

Alert: Malicious campaign on behalf of the Tax and Customs Authority. Indicadores de Compromisso (IoCs)

https://seguranca-informatica.pt/alerta-campanha-maliciosa-em-nome-da-autoridade-tributaria-e-aduaneira/?utm_source=rss&utm_medium=rss&utm_campaign=alerta-campanha-maliciosa-em-nome-da-autoridade-tributaria-e-aduaneira

Industry:
Financial, Iot

Geo:
Portugal, Brasil, Portuguese

IOCs:
Url: 2
File: 2
#ParsedReport
06-07-2022

Brand-New HavanaCrypt Ransomware Poses as Google Software Update App, Uses Microsoft Hosting Service IP Address as C&C Server. Arrival

https://www.trendmicro.com/en_us/research/22/g/brand-new-havanacrypt-ransomware-poses-as-google-software-update.html

Threats:
Havanacrypt (tags: ransomware, malware, scan)

IOCs:
File: 8
IP: 1
Url: 3
Hash: 5

Links:
https://github.com/aramrami/KeePass-2.41/blob/master/KeePassLib/Cryptography/CryptoRandom.cs
https://github.com/DarkObb/DeObfuscar-Static
https://github.com/obfuscar/obfuscar
https://github.com/de4dot/de4dot
#ParsedReport
08-07-2022

Whatever floats your Boat Bitter APT continues to target Bangladesh

https://www.secuinfra.com/en/techtalk/whatever-floats-your-boat-bitter-apt-continues-to-target-bangladesh

Actors/Campaigns:
Bitter (motivation: cyber_espionage)

Threats:
Artradownloader
Zxxz_loader (tags: rat, dns, malware)
Procmon_tool
Cyberchef_tool
Bitter_rat (tags: rat)

Industry:
Transport, Maritime, Financial

Geo:
China, Bangladesh, Chinese, Indian, Asia, Pakistan

CVEs:
CVE-2021-1732 [Vulners]
Vulners: Score: 4.6, CVSS: 5.7,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (20h2, 1803, 1809, 1909, 2004)
- microsoft windows server 2016 (20h2, 1909, 2004)
- microsoft windows server 2019 (-)

CVE-2017-1182 [Vulners]
Vulners: Score: 5.4, CVSS: 4.5,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.5
X-Force: Patch: Official fix
Soft:
- ibm tivoli monitoring (6.2.2.9, 6.3.0.7, 6.2.3.5)

CVE-2018-0798 [Vulners]
Vulners: Score: 9.3, CVSS: 9.3,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2010, 2016, 2016, 2007, 2013)
- microsoft word (2013, 2016, 2007, 2010, 2013)
- microsoft office compatibility pack (-)

CVE-2021-28310 [Vulners]
Vulners: Score: 4.6, CVSS: 6.3,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (1803, 1809, 1909, 2004, 20h2)
- microsoft windows server 2019 (-)
- microsoft windows server 2016 (1909, 2004, 20h2)

CVE-2012-0158 [Vulners]
Vulners: Score: 9.3, CVSS: 7.5,
Vulners: Exploitation: True
X-Force: Risk: 9.3
X-Force: Patch: Official fix
Soft:
- microsoft office (2010, 2010, 2003, 2007, 2007)
- microsoft office web components (2003)
- microsoft sql server (2000, 2008, 2008, 2005, 2008, 2008, 2008, 2000, 2005, 2008, 2008, 2005, 2005, 2008, 2008)
- microsoft biztalk server (2002)
- microsoft commerce server (2002, 2007, 2009, 2009)
have more...

TTPs:
Tactics: 9
Technics: 11

IOCs:
Hash: 11
File: 7
Path: 2
Domain: 6
IP: 4
Url: 1

Functions Names: 2

YARA: Found
#ParsedReport
08-07-2022

Brute Ratel Utilized By Threat Actors In New Ransomware Operations

https://socradar.io/brute-ratel-utilized-by-threat-actors-in-new-ransomware-operations

Actors/Campaigns:
Duke

Threats:
Brc4_tool (tags: ransomware, rat, phishing, malware)
Checkmate (tags: ransomware)
Red_alert (tags: ransomware)
Raspberry_robin (tags: ransomware)
Cobalt_strike (tags: ransomware)
Beacon (tags: ransomware)
Conti
Bumblebee

Geo:
Russian

IOCs:
File: 6
IP: 43
Hash: 15
Domain: 1
#ParsedReport
08-07-2022

JPCERT/CC Eyes

https://blogs.jpcert.or.jp/en/2022/07/yamabot.html

Actors/Campaigns:
Lazarus

Threats:
Yamabot (tags: malware)
Vsingle (tags: malware)

Geo:
German, Usa, Japan

IOCs:
IP: 2
File: 1
Hash: 2

Links:
https://github.com/JPCERTCC/Lazarus-research/
#ParsedReport
08-07-2022

YourCyanide: An Investigation into The Frankenstein Ransomware that Sends Malware Laced Love Letters

https://cloudsek.com/yourcyanide-an-investigation-into-the-frankenstein-ransomware-that-sends-malware-laced-love-letters

Threats:
Yourcyanide (tags: malware, stealer, ransomware, phishing, dropper)
Gonnacope
Kekpop (tags: ransomware)

TTPs:
Tactics: 4
Technics: 0

IOCs:
File: 40
Path: 2
Hash: 12

Functions Names: 2
#ParsedReport
08-07-2022

NoMercy Stealer Adding New Features. New Stealer Rapidly Evolving into Clipper Malware

https://blog.cyble.com/2022/07/07/nomercy-stealer-adding-new-features

Geo:
Indian

TTPs:
Tactics: 5
Technics: 15

IOCs:
Url: 3
File: 3
IP: 1
Hash: 1

Functions Names: 4
#ParsedReport
08-07-2022

THREAT ANALYSIS REPORT: LockBit 2.0 - All Paths Lead to Ransom

https://www.cybereason.com/blog/threat-analysis-report-lockbit-2.0-all-paths-lead-to-ransom

Actors/Campaigns:
Volatile_cedar
Ember_bear

Threats:
Lockbit (tags: phishing, vpn, ransomware, proxy, scan, malware)
Megasync_tool
Magnitude
Mimikatz
Netscan_tool
Spoolfool_vuln
Psexec_tool (tags: ransomware)
Wevtutil_tool
Neshta
Revil
Winrm_tool

Industry:
Telco, Retail, Financial, Government

Geo:
Cyprus, Russia

CVEs:
CVE-2022-21999 [Vulners]
Vulners: Score: 4.6, CVSS: 6.0,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (-, 1607, -, 1607, 20h2, 20h2, 20h2, 21h1, 21h1, 21h1, 1809, 1809, 1809, 1909, 1909, 1909, 21h2, 21h2, 21h2)
- microsoft windows server 2008 (r2, -, -)
- microsoft windows server 2012 (r2, -)
- microsoft windows server 2016 (-)
- microsoft windows rt 8.1 (-)
have more...

TTPs:
Tactics: 5
Technics: 0

IOCs:
File: 22
Path: 6
Registry: 1
IP: 2
Domain: 1
Hash: 2

Functions Names: 1
#ParsedReport
08-07-2022

Vice Society: a discreet but steady double extortion ransomware group

https://blog.sekoia.io/vice-society-a-discreet-but-steady-double-extortion-ransomware-group

Actors/Campaigns:
Vice_society (motivation: cyber_criminal)

Threats:
Zeppelin (tags: ransomware)
Hellokitty (tags: ransomware)
Printnightmare_vuln
Vega_locker

Industry:
Healthcare, Government, Education

Geo:
Germany, France, Italy, America, Usa, Brazil, Spain

IOCs:
Email: 1
Hash: 7

YARA: Found

Links:
https://github.com/reversinglabs/reversinglabs-yara-rules/blob/develop/yara/ransomware/Win32.Ransomware.Zeppelin.yara
#ParsedReport
09-07-2022

From Follina to Rozena - Leveraging Discord to Distribute a Backdoor

https://www.fortinet.com/blog/threat-research/follina-rozena-leveraging-discord-to-distribute-a-backdoor

Threats:
Follina_vuln (tags: ransomware, backdoor, rat, malware)
Rozena (tags: backdoor, ransomware, rat, malware)
Metasploit_tool (tags: rat)

CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...

TTPs:
Tactics: 1
Technics: 0

IOCs:
Hash: 6
File: 12
Url: 1
Domain: 1

Functions Names: 1
#ParsedReport
09-07-2022

Koh: The Token Stealer. Motivation

https://posts.specterops.io/koh-the-token-stealer-41ca07a40ed6

Threats:
Koh_stealer (tags: stealer)
Cobalt_strike (tags: stealer)
Mimikatz
Psexec_tool

Geo:
Usa

IOCs:
File: 2

Functions Names: 15

Links:
https://github.com/GhostPack/Koh
https://github.com/GhostPack/Rubeus#example-credential-extraction
https://github.com/anthemtotheego/InlineExecute-Assembly
https://github.com/outflanknl/Dumpert
https://github.com/gentilkiwi/mimikatz
https://github.com/eladshamir/Internal-Monologue
https://github.com/PowerShellMafia/PowerSploit/blob/master/Exfiltration/Out-Minidump.ps1
https://github.com/GhostPack/Koh/issues
https://github.com/GhostPack/SharpDPAPI/
https://github.com/kyleavery/inject-assembly
https://github.com/GhostPack/Koh/blob/master/README.md#the-inline-shenanigans-bug
https://github.com/gentilkiwi/mimikatz/
https://github.com/b4rtik/ATPMiniDump
https://github.com/GhostPack/Rubeus