#ParsedReport
07-07-2022
Targets of Interest \| Russian Organizations Increasingly Under Attack By Chinese APTs
https://www.sentinelone.com/labs/targets-of-interest-russian-organizations-increasingly-under-attack-by-chinese-apts
Actors/Campaigns:
Red_delta
Scarab
Tonto_team
Threats:
Korlia (tags: malware)
Industry:
Telco, Government
Geo:
Russian, Russia, Chinese, Pakistan, Pakistani, Ukraines, Asia, Ukraine, Chinas
CVEs:
CVE-2018-0798 [Vulners]
Vulners: Score: 9.3, CVSS: 9.3,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2010, 2016, 2016, 2007, 2013)
- microsoft word (2013, 2016, 2007, 2010, 2013)
- microsoft office compatibility pack (-)
IOCs:
File: 3
Hash: 11
Domain: 4
IP: 2
07-07-2022
Targets of Interest \| Russian Organizations Increasingly Under Attack By Chinese APTs
https://www.sentinelone.com/labs/targets-of-interest-russian-organizations-increasingly-under-attack-by-chinese-apts
Actors/Campaigns:
Red_delta
Scarab
Tonto_team
Threats:
Korlia (tags: malware)
Industry:
Telco, Government
Geo:
Russian, Russia, Chinese, Pakistan, Pakistani, Ukraines, Asia, Ukraine, Chinas
CVEs:
CVE-2018-0798 [Vulners]
Vulners: Score: 9.3, CVSS: 9.3,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2010, 2016, 2016, 2007, 2013)
- microsoft word (2013, 2016, 2007, 2010, 2013)
- microsoft office compatibility pack (-)
IOCs:
File: 3
Hash: 11
Domain: 4
IP: 2
SentinelOne
Targets of Interest | Russian Organizations Increasingly Under Attack By Chinese APTs
Chinese-linked phishing campaign seeks to compromise Russian targets with custom malware designed for espionage.
#ParsedReport
07-07-2022
Unpacking Cloud-Based Cryptocurrency Miners That Abuse GitHub Actions and Azure Virtual Machines
https://www.trendmicro.com/en_us/research/22/g/unpacking-cloud-based-cryptocurrency-miners-that-abuse-github-ac.html
Threats:
Xmrig_miner (tags: cryptomining)
Industry:
E-commerce
IOCs:
File: 2
Coin: 7
Hash: 2
Links:
07-07-2022
Unpacking Cloud-Based Cryptocurrency Miners That Abuse GitHub Actions and Azure Virtual Machines
https://www.trendmicro.com/en_us/research/22/g/unpacking-cloud-based-cryptocurrency-miners-that-abuse-github-ac.html
Threats:
Xmrig_miner (tags: cryptomining)
Industry:
E-commerce
IOCs:
File: 2
Coin: 7
Hash: 2
Links:
https://github.com/Hffffhujft/hahsy/blob/main/.github/workflows/main.ymlhttps://github.com/limoain14/Langs/blob/main/.github/workflows/main.ymlhttps://github.com/aldilariskhameilenia2018/mining22/blob/main/.github/workflows/blank.ymlhttps://github.com/nick-fields/retryhttps://github.com/gesbul1989/VERUS/blob/main/.github/workflows/baru.ymlhttps://github.com/search?q=xmrig+extension%3Ayaml+extension%3Ayml+path%3A.github%2Fworkflows&type=Codehttps://docs.github.com/en/actions/using-workflows/events-that-trigger-workflows#workflow\_dispatchhttps://docs.github.com/en/actions/using-jobs/using-a-matrix-for-your-jobshttps://docs.github.com/en/actions/using-github-hosted-runners/about-github-hosted-runnershttps://github.com/000h0/1hars/blob/circleci-project-setup/.github/workflows/main.ymlhttps://github.com/janjan1999/shiba/blob/main/.github/Workflows/KaptenCrypto.ymlhttps://github.com/wa2nderma1/StartNew/blob/main/.github/workflows/mulai1.ymlhttps://github.com/FixKRI1/miner/blob/main/.github/workflows/main.ymlhttps://github.com/wizman008/shiba/blob/main/.github/workflows/coins.ymlhttps://github.com/aldilariskhameilenia2018/mininggg/blob/main/.github/workflows/blank.ymlhttps://github.com/actions/checkouthttps://github.com/jaknan/pg/blob/main/.github/workflows/main.ymlhttps://github.com/Olish420/nubatur/blob/main/.github/workflows/nubatur.ymlhttps://docs.github.com/en/actions/learn-github-actions/understanding-github-actionshttps://github.com/dsdnklasmals/aaaaaaaaaaaaa/blob/main/.github/Workflows/KaptenCrypto.ymlhttps://github.com/Olish420/tron/blob/main/.github/workflows/tron.ymlhttps://github.com/jaknan/pg/actionsTrend Micro
Unpacking Cloud-Based Cryptocurrency Miners That Abuse GitHub Actions and Azure Virtual Machines
We investigate cloud-based cryptocurrency miners that leverage GitHub Actions and Azure virtual machines, including the cloud infrastructure and vulnerabilities that malicious actors exploit for easy monetary gain.
#ParsedReport
07-07-2022
Unprecedented Shift: The Trickbot Group is Systematically Attacking Ukraine
https://securityintelligence.com/posts/trickbot-group-systematically-attacking-ukraine
Actors/Campaigns:
Wizard_spider (motivation: cyber_criminal, financially_motivated, information_theft)
Ta578
Threats:
Trickbot (tags: malware, backdoor, phishing, ransomware, dropper, ddos, trojan)
Icedid (tags: malware, phishing, ransomware, dropper)
Cobalt_strike (tags: malware, phishing, ransomware, dropper, rat)
Meterpreter_tool (tags: phishing)
Bumblebee (tags: malware, ransomware, rat)
Conti
Ryuk
Diavol
Emotet
Tron
Bazarbackdoor
Anchor (tags: dropper)
Follina_vuln
Beacon
Putty_tool (tags: malware)
Industry:
Financial
Geo:
Ukraine, Ukraines, Belarus, Ukrainian, Russian, Russia
CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...
IOCs:
File: 10
Hash: 38
Url: 13
Domain: 3
Path: 4
Functions Names: 1
07-07-2022
Unprecedented Shift: The Trickbot Group is Systematically Attacking Ukraine
https://securityintelligence.com/posts/trickbot-group-systematically-attacking-ukraine
Actors/Campaigns:
Wizard_spider (motivation: cyber_criminal, financially_motivated, information_theft)
Ta578
Threats:
Trickbot (tags: malware, backdoor, phishing, ransomware, dropper, ddos, trojan)
Icedid (tags: malware, phishing, ransomware, dropper)
Cobalt_strike (tags: malware, phishing, ransomware, dropper, rat)
Meterpreter_tool (tags: phishing)
Bumblebee (tags: malware, ransomware, rat)
Conti
Ryuk
Diavol
Emotet
Tron
Bazarbackdoor
Anchor (tags: dropper)
Follina_vuln
Beacon
Putty_tool (tags: malware)
Industry:
Financial
Geo:
Ukraine, Ukraines, Belarus, Ukrainian, Russian, Russia
CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...
IOCs:
File: 10
Hash: 38
Url: 13
Domain: 3
Path: 4
Functions Names: 1
Security Intelligence
Unprecedented Shift: The Trickbot Group is Systematically Attacking Ukraine
IBM Security X-Force uncovered evidence indicating that the Russia-based cybercriminal syndicate "Trickbot group" has been attacking Ukraine since the Russian invasion. Explore an in-depth analysis on six of ITG23's campaigns.
#ParsedReport
07-07-2022
Stormous Ransomware Group Runs Opinion Polls, Leaks Intellectual Property of Indian Companies
https://cloudsek.com/threatintelligence/stormous-ransomware-group-runs-opinion-polls-leaks-intellectual-property-of-indian-companies/?utm_source=rss&utm_medium=rss&utm_campaign=stormous-ransomware-group-runs-opinion-polls-leaks-intellectual-property-of-indian-companies
Actors/Campaigns:
Stormous (motivation: financially_motivated, hacktivism)
Threats:
Ekipa_rat (tags: ransomware)
Industry:
Financial, Telco, Education
Geo:
Russian, Indiacounty, India, Indian
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 19
IP: 10
Url: 4
07-07-2022
Stormous Ransomware Group Runs Opinion Polls, Leaks Intellectual Property of Indian Companies
https://cloudsek.com/threatintelligence/stormous-ransomware-group-runs-opinion-polls-leaks-intellectual-property-of-indian-companies/?utm_source=rss&utm_medium=rss&utm_campaign=stormous-ransomware-group-runs-opinion-polls-leaks-intellectual-property-of-indian-companies
Actors/Campaigns:
Stormous (motivation: financially_motivated, hacktivism)
Threats:
Ekipa_rat (tags: ransomware)
Industry:
Financial, Telco, Education
Geo:
Russian, Indiacounty, India, Indian
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 19
IP: 10
Url: 4
Cloudsek
Stormous Ransomware Group Runs Opinion Polls, Leaks Intellectual Property of Indian Companies | Threat Intelligence | CloudSEK
CloudSEK team has identified Stormous ransomware campaigns targeting multiple organizations globally. The threat group is financially motivated and their latest chain of attacks has been directed at Indian entities as well.
#ParsedReport
07-07-2022
Ekipa Remote Access Trojan Designed by Russian Hacktivists for Targeted Attacks. Executive Summary
https://cloudsek.com/threatintelligence/ekipa-remote-access-trojan-designed-by-russian-hacktivists-for-targeted-attacks/?utm_source=rss&utm_medium=rss&utm_campaign=ekipa-remote-access-trojan-designed-by-russian-hacktivists-for-targeted-attacks
Threats:
Ekipa_rat (tags: rat, trojan, malware)
Putty_tool
Geo:
Ukraine, Crimea, Russian, Russia
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 6
07-07-2022
Ekipa Remote Access Trojan Designed by Russian Hacktivists for Targeted Attacks. Executive Summary
https://cloudsek.com/threatintelligence/ekipa-remote-access-trojan-designed-by-russian-hacktivists-for-targeted-attacks/?utm_source=rss&utm_medium=rss&utm_campaign=ekipa-remote-access-trojan-designed-by-russian-hacktivists-for-targeted-attacks
Threats:
Ekipa_rat (tags: rat, trojan, malware)
Putty_tool
Geo:
Ukraine, Crimea, Russian, Russia
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 6
Cloudsek
Ekipa Remote Access Trojan Designed by Russian Hacktivists for “Targeted Attacks” | Threat Intelligence | CloudSEK
XVigil discovered a threat actor advertising a macro RAT (Remote Access Trojan) dubbed “Ekipa", created by Russian hacktivists.
#ParsedReport
07-07-2022
Alert: Malicious campaign on behalf of the Tax and Customs Authority. Indicadores de Compromisso (IoCs)
https://seguranca-informatica.pt/alerta-campanha-maliciosa-em-nome-da-autoridade-tributaria-e-aduaneira/?utm_source=rss&utm_medium=rss&utm_campaign=alerta-campanha-maliciosa-em-nome-da-autoridade-tributaria-e-aduaneira
Industry:
Financial, Iot
Geo:
Portugal, Brasil, Portuguese
IOCs:
Url: 2
File: 2
07-07-2022
Alert: Malicious campaign on behalf of the Tax and Customs Authority. Indicadores de Compromisso (IoCs)
https://seguranca-informatica.pt/alerta-campanha-maliciosa-em-nome-da-autoridade-tributaria-e-aduaneira/?utm_source=rss&utm_medium=rss&utm_campaign=alerta-campanha-maliciosa-em-nome-da-autoridade-tributaria-e-aduaneira
Industry:
Financial, Iot
Geo:
Portugal, Brasil, Portuguese
IOCs:
Url: 2
File: 2
#ParsedReport
06-07-2022
Brand-New HavanaCrypt Ransomware Poses as Google Software Update App, Uses Microsoft Hosting Service IP Address as C&C Server. Arrival
https://www.trendmicro.com/en_us/research/22/g/brand-new-havanacrypt-ransomware-poses-as-google-software-update.html
Threats:
Havanacrypt (tags: ransomware, malware, scan)
IOCs:
File: 8
IP: 1
Url: 3
Hash: 5
Links:
06-07-2022
Brand-New HavanaCrypt Ransomware Poses as Google Software Update App, Uses Microsoft Hosting Service IP Address as C&C Server. Arrival
https://www.trendmicro.com/en_us/research/22/g/brand-new-havanacrypt-ransomware-poses-as-google-software-update.html
Threats:
Havanacrypt (tags: ransomware, malware, scan)
IOCs:
File: 8
IP: 1
Url: 3
Hash: 5
Links:
https://github.com/aramrami/KeePass-2.41/blob/master/KeePassLib/Cryptography/CryptoRandom.cshttps://github.com/DarkObb/DeObfuscar-Statichttps://github.com/obfuscar/obfuscarhttps://github.com/de4dot/de4dotTrend Micro
Brand-New HavanaCrypt Ransomware Poses as Google Software Update App, Uses Microsoft Hosting Service IP Address as C&C Server
We recently found a new ransomware family, which we have dubbed as HavanaCrypt, that disguises itself as a Google Software Update application and uses a Microsoft web hosting service IP address as its command-and-control server to circumvent detection.
#ParsedReport
08-07-2022
Whatever floats your Boat Bitter APT continues to target Bangladesh
https://www.secuinfra.com/en/techtalk/whatever-floats-your-boat-bitter-apt-continues-to-target-bangladesh
Actors/Campaigns:
Bitter (motivation: cyber_espionage)
Threats:
Artradownloader
Zxxz_loader (tags: rat, dns, malware)
Procmon_tool
Cyberchef_tool
Bitter_rat (tags: rat)
Industry:
Transport, Maritime, Financial
Geo:
China, Bangladesh, Chinese, Indian, Asia, Pakistan
CVEs:
CVE-2021-1732 [Vulners]
Vulners: Score: 4.6, CVSS: 5.7,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (20h2, 1803, 1809, 1909, 2004)
- microsoft windows server 2016 (20h2, 1909, 2004)
- microsoft windows server 2019 (-)
CVE-2017-1182 [Vulners]
Vulners: Score: 5.4, CVSS: 4.5,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.5
X-Force: Patch: Official fix
Soft:
- ibm tivoli monitoring (6.2.2.9, 6.3.0.7, 6.2.3.5)
CVE-2018-0798 [Vulners]
Vulners: Score: 9.3, CVSS: 9.3,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2010, 2016, 2016, 2007, 2013)
- microsoft word (2013, 2016, 2007, 2010, 2013)
- microsoft office compatibility pack (-)
CVE-2021-28310 [Vulners]
Vulners: Score: 4.6, CVSS: 6.3,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (1803, 1809, 1909, 2004, 20h2)
- microsoft windows server 2019 (-)
- microsoft windows server 2016 (1909, 2004, 20h2)
CVE-2012-0158 [Vulners]
Vulners: Score: 9.3, CVSS: 7.5,
Vulners: Exploitation: True
X-Force: Risk: 9.3
X-Force: Patch: Official fix
Soft:
- microsoft office (2010, 2010, 2003, 2007, 2007)
- microsoft office web components (2003)
- microsoft sql server (2000, 2008, 2008, 2005, 2008, 2008, 2008, 2000, 2005, 2008, 2008, 2005, 2005, 2008, 2008)
- microsoft biztalk server (2002)
- microsoft commerce server (2002, 2007, 2009, 2009)
have more...
TTPs:
Tactics: 9
Technics: 11
IOCs:
Hash: 11
File: 7
Path: 2
Domain: 6
IP: 4
Url: 1
Functions Names: 2
YARA: Found
08-07-2022
Whatever floats your Boat Bitter APT continues to target Bangladesh
https://www.secuinfra.com/en/techtalk/whatever-floats-your-boat-bitter-apt-continues-to-target-bangladesh
Actors/Campaigns:
Bitter (motivation: cyber_espionage)
Threats:
Artradownloader
Zxxz_loader (tags: rat, dns, malware)
Procmon_tool
Cyberchef_tool
Bitter_rat (tags: rat)
Industry:
Transport, Maritime, Financial
Geo:
China, Bangladesh, Chinese, Indian, Asia, Pakistan
CVEs:
CVE-2021-1732 [Vulners]
Vulners: Score: 4.6, CVSS: 5.7,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (20h2, 1803, 1809, 1909, 2004)
- microsoft windows server 2016 (20h2, 1909, 2004)
- microsoft windows server 2019 (-)
CVE-2017-1182 [Vulners]
Vulners: Score: 5.4, CVSS: 4.5,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.5
X-Force: Patch: Official fix
Soft:
- ibm tivoli monitoring (6.2.2.9, 6.3.0.7, 6.2.3.5)
CVE-2018-0798 [Vulners]
Vulners: Score: 9.3, CVSS: 9.3,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2010, 2016, 2016, 2007, 2013)
- microsoft word (2013, 2016, 2007, 2010, 2013)
- microsoft office compatibility pack (-)
CVE-2021-28310 [Vulners]
Vulners: Score: 4.6, CVSS: 6.3,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (1803, 1809, 1909, 2004, 20h2)
- microsoft windows server 2019 (-)
- microsoft windows server 2016 (1909, 2004, 20h2)
CVE-2012-0158 [Vulners]
Vulners: Score: 9.3, CVSS: 7.5,
Vulners: Exploitation: True
X-Force: Risk: 9.3
X-Force: Patch: Official fix
Soft:
- microsoft office (2010, 2010, 2003, 2007, 2007)
- microsoft office web components (2003)
- microsoft sql server (2000, 2008, 2008, 2005, 2008, 2008, 2008, 2000, 2005, 2008, 2008, 2005, 2005, 2008, 2008)
- microsoft biztalk server (2002)
- microsoft commerce server (2002, 2007, 2009, 2009)
have more...
TTPs:
Tactics: 9
Technics: 11
IOCs:
Hash: 11
File: 7
Path: 2
Domain: 6
IP: 4
Url: 1
Functions Names: 2
YARA: Found
Secuinfra GmbH
Bitter APT continues to target Bangladesh | SECUINFRA Falcon Team
The SECUINFRA Falcon Team analyzed a recent attack conducted by the south-Asian Advanced Persistent Threat group „Bitter“.
#ParsedReport
08-07-2022
Brute Ratel Utilized By Threat Actors In New Ransomware Operations
https://socradar.io/brute-ratel-utilized-by-threat-actors-in-new-ransomware-operations
Actors/Campaigns:
Duke
Threats:
Brc4_tool (tags: ransomware, rat, phishing, malware)
Checkmate (tags: ransomware)
Red_alert (tags: ransomware)
Raspberry_robin (tags: ransomware)
Cobalt_strike (tags: ransomware)
Beacon (tags: ransomware)
Conti
Bumblebee
Geo:
Russian
IOCs:
File: 6
IP: 43
Hash: 15
Domain: 1
08-07-2022
Brute Ratel Utilized By Threat Actors In New Ransomware Operations
https://socradar.io/brute-ratel-utilized-by-threat-actors-in-new-ransomware-operations
Actors/Campaigns:
Duke
Threats:
Brc4_tool (tags: ransomware, rat, phishing, malware)
Checkmate (tags: ransomware)
Red_alert (tags: ransomware)
Raspberry_robin (tags: ransomware)
Cobalt_strike (tags: ransomware)
Beacon (tags: ransomware)
Conti
Bumblebee
Geo:
Russian
IOCs:
File: 6
IP: 43
Hash: 15
Domain: 1
SOCRadar® Cyber Intelligence Inc.
Brute Ratel Utilized By Threat Actors In New Ransomware Operations - SOCRadar® Cyber Intelligence Inc.
When Brute Ratel first appeared in the wild, almost no security solutions could detect it. To avoid being discovered by EDR and antivirus programs, hacking
#ParsedReport
08-07-2022
JPCERT/CC Eyes
https://blogs.jpcert.or.jp/en/2022/07/yamabot.html
Actors/Campaigns:
Lazarus
Threats:
Yamabot (tags: malware)
Vsingle (tags: malware)
Geo:
German, Usa, Japan
IOCs:
IP: 2
File: 1
Hash: 2
Links:
08-07-2022
JPCERT/CC Eyes
https://blogs.jpcert.or.jp/en/2022/07/yamabot.html
Actors/Campaigns:
Lazarus
Threats:
Yamabot (tags: malware)
Vsingle (tags: malware)
Geo:
German, Usa, Japan
IOCs:
IP: 2
File: 1
Hash: 2
Links:
https://github.com/JPCERTCC/Lazarus-research/JPCERT/CC Eyes
YamaBot Malware Used by Lazarus - JPCERT/CC Eyes
JPCERT/CC is continuously investigating ...
#ParsedReport
08-07-2022
ABCsoup: The Malicious Adware Extension with 350 Variants
https://blog.zimperium.com/abc-soup-the-malicious-adware-extension-with-350-variants
Geo:
Russian
IOCs:
File: 4
Hash: 136
Functions Names: 3
08-07-2022
ABCsoup: The Malicious Adware Extension with 350 Variants
https://blog.zimperium.com/abc-soup-the-malicious-adware-extension-with-350-variants
Geo:
Russian
IOCs:
File: 4
Hash: 136
Functions Names: 3
Zimperium
ABCsoup: The Malicious Adware Extension with 350 Variants - Zimperium
What can ABCsoup do? Recently Zimperium discovered and began monitoring the growth of a wide range of malicious browser extensions with the same extension
#ParsedReport
08-07-2022
YourCyanide: An Investigation into The Frankenstein Ransomware that Sends Malware Laced Love Letters
https://cloudsek.com/yourcyanide-an-investigation-into-the-frankenstein-ransomware-that-sends-malware-laced-love-letters
Threats:
Yourcyanide (tags: malware, stealer, ransomware, phishing, dropper)
Gonnacope
Kekpop (tags: ransomware)
TTPs:
Tactics: 4
Technics: 0
IOCs:
File: 40
Path: 2
Hash: 12
Functions Names: 2
08-07-2022
YourCyanide: An Investigation into The Frankenstein Ransomware that Sends Malware Laced Love Letters
https://cloudsek.com/yourcyanide-an-investigation-into-the-frankenstein-ransomware-that-sends-malware-laced-love-letters
Threats:
Yourcyanide (tags: malware, stealer, ransomware, phishing, dropper)
Gonnacope
Kekpop (tags: ransomware)
TTPs:
Tactics: 4
Technics: 0
IOCs:
File: 40
Path: 2
Hash: 12
Functions Names: 2
Cloudsek
YourCyanide: An Investigation into ‘The Frankenstein’ Ransomware that Sends Malware Laced Love Letters | CloudSEK
#ParsedReport
08-07-2022
THREAT ALERT: Raspberry Robin Worm Abuses Windows Installer and QNAP Devices
https://www.cybereason.com/blog/threat-alert-raspberry-robin-worm-abuses-windows-installer-and-qnap-devices
Threats:
Raspberry_robin (tags: rat, malware)
Lolbin
Industry:
Government
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 13
Hash: 1
Path: 1
Url: 2
Domain: 1
08-07-2022
THREAT ALERT: Raspberry Robin Worm Abuses Windows Installer and QNAP Devices
https://www.cybereason.com/blog/threat-alert-raspberry-robin-worm-abuses-windows-installer-and-qnap-devices
Threats:
Raspberry_robin (tags: rat, malware)
Lolbin
Industry:
Government
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 13
Hash: 1
Path: 1
Url: 2
Domain: 1
Cybereason
THREAT ALERT: Raspberry Robin Worm Abuses Windows Installer and QNAP Devices
Raspberry Robin involves a worm that spreads over USB devices or shared folders, leveraging compromised QNAP (Network Attached Storage or NAS) devices as stagers and an old but still effective method of using “LNK” shortcut files to lure its victims...
#ParsedReport
08-07-2022
NoMercy Stealer Adding New Features. New Stealer Rapidly Evolving into Clipper Malware
https://blog.cyble.com/2022/07/07/nomercy-stealer-adding-new-features
Geo:
Indian
TTPs:
Tactics: 5
Technics: 15
IOCs:
Url: 3
File: 3
IP: 1
Hash: 1
Functions Names: 4
08-07-2022
NoMercy Stealer Adding New Features. New Stealer Rapidly Evolving into Clipper Malware
https://blog.cyble.com/2022/07/07/nomercy-stealer-adding-new-features
Geo:
Indian
TTPs:
Tactics: 5
Technics: 15
IOCs:
Url: 3
File: 3
IP: 1
Hash: 1
Functions Names: 4
Cyble
NoMercy Stealer Adding New Features
Cyble analyzes NoMercy Stealer, a new information stealer evolving into Clipper Malware.
#ParsedReport
08-07-2022
THREAT ANALYSIS REPORT: LockBit 2.0 - All Paths Lead to Ransom
https://www.cybereason.com/blog/threat-analysis-report-lockbit-2.0-all-paths-lead-to-ransom
Actors/Campaigns:
Volatile_cedar
Ember_bear
Threats:
Lockbit (tags: phishing, vpn, ransomware, proxy, scan, malware)
Megasync_tool
Magnitude
Mimikatz
Netscan_tool
Spoolfool_vuln
Psexec_tool (tags: ransomware)
Wevtutil_tool
Neshta
Revil
Winrm_tool
Industry:
Telco, Retail, Financial, Government
Geo:
Cyprus, Russia
CVEs:
CVE-2022-21999 [Vulners]
Vulners: Score: 4.6, CVSS: 6.0,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (-, 1607, -, 1607, 20h2, 20h2, 20h2, 21h1, 21h1, 21h1, 1809, 1809, 1809, 1909, 1909, 1909, 21h2, 21h2, 21h2)
- microsoft windows server 2008 (r2, -, -)
- microsoft windows server 2012 (r2, -)
- microsoft windows server 2016 (-)
- microsoft windows rt 8.1 (-)
have more...
TTPs:
Tactics: 5
Technics: 0
IOCs:
File: 22
Path: 6
Registry: 1
IP: 2
Domain: 1
Hash: 2
Functions Names: 1
08-07-2022
THREAT ANALYSIS REPORT: LockBit 2.0 - All Paths Lead to Ransom
https://www.cybereason.com/blog/threat-analysis-report-lockbit-2.0-all-paths-lead-to-ransom
Actors/Campaigns:
Volatile_cedar
Ember_bear
Threats:
Lockbit (tags: phishing, vpn, ransomware, proxy, scan, malware)
Megasync_tool
Magnitude
Mimikatz
Netscan_tool
Spoolfool_vuln
Psexec_tool (tags: ransomware)
Wevtutil_tool
Neshta
Revil
Winrm_tool
Industry:
Telco, Retail, Financial, Government
Geo:
Cyprus, Russia
CVEs:
CVE-2022-21999 [Vulners]
Vulners: Score: 4.6, CVSS: 6.0,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (-, 1607, -, 1607, 20h2, 20h2, 20h2, 21h1, 21h1, 21h1, 1809, 1809, 1809, 1909, 1909, 1909, 21h2, 21h2, 21h2)
- microsoft windows server 2008 (r2, -, -)
- microsoft windows server 2012 (r2, -)
- microsoft windows server 2016 (-)
- microsoft windows rt 8.1 (-)
have more...
TTPs:
Tactics: 5
Technics: 0
IOCs:
File: 22
Path: 6
Registry: 1
IP: 2
Domain: 1
Hash: 2
Functions Names: 1
Cybereason
THREAT ANALYSIS REPORT: LockBit 2.0 - All Paths Lead to Ransom
LockBit 2.0 ransomware attackers are constantly evolving and making detection, investigation, and prevention more complex by disabling EDR and other security products and deleting the evidence to stifle forensics attempts...
#ParsedReport
08-07-2022
Vice Society: a discreet but steady double extortion ransomware group
https://blog.sekoia.io/vice-society-a-discreet-but-steady-double-extortion-ransomware-group
Actors/Campaigns:
Vice_society (motivation: cyber_criminal)
Threats:
Zeppelin (tags: ransomware)
Hellokitty (tags: ransomware)
Printnightmare_vuln
Vega_locker
Industry:
Healthcare, Government, Education
Geo:
Germany, France, Italy, America, Usa, Brazil, Spain
IOCs:
Email: 1
Hash: 7
YARA: Found
Links:
08-07-2022
Vice Society: a discreet but steady double extortion ransomware group
https://blog.sekoia.io/vice-society-a-discreet-but-steady-double-extortion-ransomware-group
Actors/Campaigns:
Vice_society (motivation: cyber_criminal)
Threats:
Zeppelin (tags: ransomware)
Hellokitty (tags: ransomware)
Printnightmare_vuln
Vega_locker
Industry:
Healthcare, Government, Education
Geo:
Germany, France, Italy, America, Usa, Brazil, Spain
IOCs:
Email: 1
Hash: 7
YARA: Found
Links:
https://github.com/reversinglabs/reversinglabs-yara-rules/blob/develop/yara/ransomware/Win32.Ransomware.Zeppelin.yaraSekoia.io Blog
Vice Society: a discreet but steady double extortion ransomware group
Vice Society is a little-known double extortion group. It showed a steady activity, encrypting and exfiltrating its victim’s data and threatening their victims to leak their information to pressure them into paying a ransom.
#ParsedReport
09-07-2022
Pseudo-APT-C-23 (Futao ) Organizational Equipment Threema Communication Case Attack Analysis
https://mp-weixin-qq-com.translate.goog/s/1uJaPS-nuGNI8lQ1-ZekIA?_x_tr_sl=ja&_x_tr_tl=en&_x_tr_hl=en&_x_tr_pto=wapp
Actors/Campaigns:
Aridviper
Threats:
Houdini_rat (tags: rat, dns)
Vamp
Njrat_rat
Industry:
Education
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 4
Hash: 21
IP: 1
09-07-2022
Pseudo-APT-C-23 (Futao ) Organizational Equipment Threema Communication Case Attack Analysis
https://mp-weixin-qq-com.translate.goog/s/1uJaPS-nuGNI8lQ1-ZekIA?_x_tr_sl=ja&_x_tr_tl=en&_x_tr_hl=en&_x_tr_pto=wapp
Actors/Campaigns:
Aridviper
Threats:
Houdini_rat (tags: rat, dns)
Vamp
Njrat_rat
Industry:
Education
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 4
Hash: 21
IP: 1
微信公众平台
疑似APT-C-23(双尾蝎)组织伪装Threema通讯软件攻击分析
以前的双尾蝎样本大多采用VC 版本、Delphi 版本,很少见到使用公开商业RAT组件进行攻击,此次发现的样本可能是该组织进攻方式的演变,也可能是双尾蝎组织内部出现的新的分支成员所采用的攻击手法
#ParsedReport
09-07-2022
From Follina to Rozena - Leveraging Discord to Distribute a Backdoor
https://www.fortinet.com/blog/threat-research/follina-rozena-leveraging-discord-to-distribute-a-backdoor
Threats:
Follina_vuln (tags: ransomware, backdoor, rat, malware)
Rozena (tags: backdoor, ransomware, rat, malware)
Metasploit_tool (tags: rat)
CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 6
File: 12
Url: 1
Domain: 1
Functions Names: 1
09-07-2022
From Follina to Rozena - Leveraging Discord to Distribute a Backdoor
https://www.fortinet.com/blog/threat-research/follina-rozena-leveraging-discord-to-distribute-a-backdoor
Threats:
Follina_vuln (tags: ransomware, backdoor, rat, malware)
Rozena (tags: backdoor, ransomware, rat, malware)
Metasploit_tool (tags: rat)
CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 6
File: 12
Url: 1
Domain: 1
Functions Names: 1
Fortinet Blog
From Follina to Rozena - Leveraging Discord to Distribute a Backdoor
FortiGuard Labs recently discovered a document that exploits CVE-2022-30190 (Follina) to trigger the download of the Rozena malware, capable of injecting a remote shell connection back to the attac…
#ParsedReport
09-07-2022
Koh: The Token Stealer. Motivation
https://posts.specterops.io/koh-the-token-stealer-41ca07a40ed6
Threats:
Koh_stealer (tags: stealer)
Cobalt_strike (tags: stealer)
Mimikatz
Psexec_tool
Geo:
Usa
IOCs:
File: 2
Functions Names: 15
Links:
09-07-2022
Koh: The Token Stealer. Motivation
https://posts.specterops.io/koh-the-token-stealer-41ca07a40ed6
Threats:
Koh_stealer (tags: stealer)
Cobalt_strike (tags: stealer)
Mimikatz
Psexec_tool
Geo:
Usa
IOCs:
File: 2
Functions Names: 15
Links:
https://github.com/GhostPack/Kohhttps://github.com/GhostPack/Rubeus#example-credential-extractionhttps://github.com/anthemtotheego/InlineExecute-Assemblyhttps://github.com/outflanknl/Dumperthttps://github.com/gentilkiwi/mimikatzhttps://github.com/eladshamir/Internal-Monologuehttps://github.com/PowerShellMafia/PowerSploit/blob/master/Exfiltration/Out-Minidump.ps1https://github.com/GhostPack/Koh/issueshttps://github.com/GhostPack/SharpDPAPI/https://github.com/kyleavery/inject-assemblyhttps://github.com/GhostPack/Koh/blob/master/README.md#the-inline-shenanigans-bughttps://github.com/gentilkiwi/mimikatz/https://github.com/b4rtik/ATPMiniDumphttps://github.com/GhostPack/RubeusMedium
Koh: The Token Stealer
Edit 07/13/22: After an awesome back and forth with Clément Notin and @SteveSyfuhs on Twitter on the effects of “TokenLeakDetectDelaySecs”…
#ParsedReport
09-07-2022
Magniber Ransomware, Changes in Injection Method
https://asec-ahnlab-com.translate.goog/ko/36276/?_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Threats:
Magniber (tags: malware, ransomware)
IOCs:
File: 5
Path: 1
Hash: 2
09-07-2022
Magniber Ransomware, Changes in Injection Method
https://asec-ahnlab-com.translate.goog/ko/36276/?_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Threats:
Magniber (tags: malware, ransomware)
IOCs:
File: 5
Path: 1
Hash: 2
ASEC BLOG
매그니베르(Magniber) 랜섬웨어, 인젝션 방식의 변화 - ASEC BLOG
ASEC 분석팀은 높은 유포건수를 보이는 매그니베르(Magniber) 랜섬웨어를 꾸준히 모니터링하고 있다. 매그니베르 랜섬웨어는 최근 몇년간 IE 취약점을 통해 유포되었지만, IE(Internet Explorer)의 지원 종료시기를 기점으로 IE 취약점 유포를 중단하였다. 그리고 최근 매그니베르 랜섬웨어는 Edge, Chrome 브라우저에서 Windows 설치 패키지 파일(.msi)로 유포되고 있다. Windows 설치 패키지 파일(.msi) 로 유포되는…