CTT Report Hub
3.43K subscribers
9.91K photos
6 videos
67 files
13.6K links
Threat Intelligence Report Hub
Download Telegram
#ParsedReport
09-07-2022

From Follina to Rozena - Leveraging Discord to Distribute a Backdoor

https://www.fortinet.com/blog/threat-research/follina-rozena-leveraging-discord-to-distribute-a-backdoor

Threats:
Follina_vuln (tags: ransomware, backdoor, rat, malware)
Rozena (tags: backdoor, ransomware, rat, malware)
Metasploit_tool (tags: rat)

CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...

TTPs:
Tactics: 1
Technics: 0

IOCs:
Hash: 6
File: 12
Url: 1
Domain: 1

Functions Names: 1
#ParsedReport
09-07-2022

Koh: The Token Stealer. Motivation

https://posts.specterops.io/koh-the-token-stealer-41ca07a40ed6

Threats:
Koh_stealer (tags: stealer)
Cobalt_strike (tags: stealer)
Mimikatz
Psexec_tool

Geo:
Usa

IOCs:
File: 2

Functions Names: 15

Links:
https://github.com/GhostPack/Koh
https://github.com/GhostPack/Rubeus#example-credential-extraction
https://github.com/anthemtotheego/InlineExecute-Assembly
https://github.com/outflanknl/Dumpert
https://github.com/gentilkiwi/mimikatz
https://github.com/eladshamir/Internal-Monologue
https://github.com/PowerShellMafia/PowerSploit/blob/master/Exfiltration/Out-Minidump.ps1
https://github.com/GhostPack/Koh/issues
https://github.com/GhostPack/SharpDPAPI/
https://github.com/kyleavery/inject-assembly
https://github.com/GhostPack/Koh/blob/master/README.md#the-inline-shenanigans-bug
https://github.com/gentilkiwi/mimikatz/
https://github.com/b4rtik/ATPMiniDump
https://github.com/GhostPack/Rubeus
#ParsedReport
10-07-2022

Anubis Networks is back with new C2 server. Fake domains hosted automatically on Cloudflare CDN

https://seguranca-informatica.pt/anubis-networks-is-back-with-new-c2-server/?utm_source=rss&utm_medium=rss&utm_campaign=anubis-networks-is-back-with-new-c2-server

Threats:
Anubis (tags: dns, malware, phishing)

Industry:
Education, Financial, Iot

Geo:
Brazilian, Portugal, Portuguese, Brazil

IOCs:
Email: 78
File: 2
#ParsedReport
10-07-2022

North Korean APT targets US healthcare sector with Maui ransomware

https://blog.malwarebytes.com/ransomware/2022/07/north-korean-apt-targets-us-healthcare-sector-with-maui-ransomware

Threats:
Mauicrypt (tags: ransomware, malware)
Conti (tags: ransomware)
Shione (tags: ransomware)

Industry:
Healthcare

Geo:
Korean

IOCs:
File: 1
#ParsedReport
11-07-2022

SELECT XMRig FROM SQLServer

https://thedfirreport.com/2022/07/11/select-xmrig-from-sqlserver

Threats:
Xmrig_miner (tags: cryptomining, rat, dropper, malware)
Thor
Cyberchef_tool

Geo:
Chinese

TTPs:
Tactics: 8
Technics: 14

IOCs:
File: 32
Path: 8
Domain: 3
Url: 1
Registry: 4
Coin: 1
Hash: 7
Email: 1

YARA: Found
SIGMA: Found

Links:
https://github.com/decoder-it/NetworkServiceExploit
#ParsedReport
11-07-2022

Meterpreter Distributed to Vulnerable Server of Korean Medical Institution

https://asec.ahnlab.com/en/36397

Threats:
Meterpreter_tool (tags: malware, scan, backdoor, ransomware)
Samsam
Smokeloader
Metasploit_tool
Malware/mdp.download.m1900

Industry:
Healthcare

Geo:
Korean

IOCs:
File: 9
Path: 5
Hash: 3
IP: 1
Url: 3

Links:
https://github.com/joaomatosf/jexboss
#ParsedReport
11-07-2022

Ransomware Spotlight: BlackByte

https://www.trendmicro.com/vinfo/us/security/news/ransomware-spotlight/ransomware-spotlight-blackbyte

Threats:
Blackbyte (tags: rat, phishing, malware, ransomware)
Ransomexx (tags: ransomware)
Avoslocker (tags: ransomware)
Clop (tags: ransomware)
Lockbit (tags: ransomware)
Conti (tags: ransomware)
Proxyshell_vuln (tags: malware)
Cobalt_strike (tags: malware)
Netscan_tool (tags: malware)
Chinachopper (tags: malware)

Industry:
Retail, Foodtech, Financial, Energy, Entertainment, Ics, Government, Healthcare, Transport

Geo:
Russia, America, Peru, American, China

TTPs:
Tactics: 3
Technics: 14

IOCs:
Domain: 2
File: 16
Path: 2
Registry: 2
Url: 2
Coin: 1
#ParsedReport
11-07-2022

GuLoader Disguised as Estimate Requests Being Distributed via Phishing Email

https://asec.ahnlab.com/en/36470

Threats:
Cloudeye (tags: stealer, phishing, rat, malware)
Formbook (tags: phishing)
Agent_tesla (tags: phishing)
Remcos_rat (tags: phishing)
Nanocore_rat (tags: phishing)

Geo:
Korean

IOCs:
File: 5
Url: 1
Hash: 1

Functions Names: 1
#ParsedReport
12-07-2022

From cookie theft to BEC: Attackers use AiTM phishing sites as entry point to further financial fraud

https://www.microsoft.com/security/blog/2022/07/12/from-cookie-theft-to-bec-attackers-use-aitm-phishing-sites-as-entry-point-to-further-financial-fraud

Threats:
Aitm_technique (tags: proxy, fraud, malware, scan, phishing, vpn)

Industry:
Financial, Telco, Government

TTPs:
Tactics: 1
Technics: 0

IOCs:
File: 1
Url: 2
Domain: 50

Links:
https://github.com/drk1wi/Modlishka
https://github.com/kgretzky/evilginx2
https://github.com/muraenateam/muraena
#ParsedReport
12-07-2022

OilRig Attack Graphs: Emulating the Iranian Threat Actors Global Campaigns

https://attackiq.com/2022/07/11/oilrig-attack-graphs-emulating-the-iranian-threat-actors-global-campaigns

Actors/Campaigns:
Oilrig

Threats:
Quadagent (tags: malware, dns, backdoor)
Disttrack
Bespoke (tags: phishing)
Tonedeaf (tags: phishing)
Longwatch (tags: phishing)
Valuevault (tags: phishing)
Pickpocket (tags: phishing)
Lazagne (tags: phishing)
Powerview

Industry:
Financial, Telco, Government, Energy

Geo:
Irans, Iranian

TTPs:

Links:
https://github.com/AlessandroZ/LaZagne
#ParsedReport
12-07-2022

ChromeLoader: New Stubborn Malware Campaign

https://unit42.paloaltonetworks.com/chromeloader-malware

Threats:
Chromeloader (tags: stealer, scan, malware, dropper)
Empire_loader

IOCs:
File: 16
Domain: 83
Hash: 173

Functions Names: 4

Links:
https://github.com/xephora/Threat-Remediation-Scripts/tree/main/Threat-Track/CS\_INSTALLER
#ParsedReport
12-07-2022

Dragon News Blog. An Analysis of Infrastructure linked to the Hagga Threat Actor

https://team-cymru.com/blog/2022/07/12/an-analysis-of-infrastructure-linked-to-the-hagga-threat-actor

Actors/Campaigns:
Aggaa

Threats:
Agent_tesla
Mana_tool
Revenge_rat
Azorult
Lokibot_stealer
Formbook
Beacon

Industry:
Telco

Geo:
Vietnam, Pakistan

IOCs:
IP: 18
Domain: 3
File: 1
Url: 1

Functions Names: 1