CTT Report Hub
3.43K subscribers
9.91K photos
6 videos
67 files
13.6K links
Threat Intelligence Report Hub
Download Telegram
#ParsedReport
11-07-2022

SELECT XMRig FROM SQLServer

https://thedfirreport.com/2022/07/11/select-xmrig-from-sqlserver

Threats:
Xmrig_miner (tags: cryptomining, rat, dropper, malware)
Thor
Cyberchef_tool

Geo:
Chinese

TTPs:
Tactics: 8
Technics: 14

IOCs:
File: 32
Path: 8
Domain: 3
Url: 1
Registry: 4
Coin: 1
Hash: 7
Email: 1

YARA: Found
SIGMA: Found

Links:
https://github.com/decoder-it/NetworkServiceExploit
#ParsedReport
11-07-2022

Meterpreter Distributed to Vulnerable Server of Korean Medical Institution

https://asec.ahnlab.com/en/36397

Threats:
Meterpreter_tool (tags: malware, scan, backdoor, ransomware)
Samsam
Smokeloader
Metasploit_tool
Malware/mdp.download.m1900

Industry:
Healthcare

Geo:
Korean

IOCs:
File: 9
Path: 5
Hash: 3
IP: 1
Url: 3

Links:
https://github.com/joaomatosf/jexboss
#ParsedReport
11-07-2022

Ransomware Spotlight: BlackByte

https://www.trendmicro.com/vinfo/us/security/news/ransomware-spotlight/ransomware-spotlight-blackbyte

Threats:
Blackbyte (tags: rat, phishing, malware, ransomware)
Ransomexx (tags: ransomware)
Avoslocker (tags: ransomware)
Clop (tags: ransomware)
Lockbit (tags: ransomware)
Conti (tags: ransomware)
Proxyshell_vuln (tags: malware)
Cobalt_strike (tags: malware)
Netscan_tool (tags: malware)
Chinachopper (tags: malware)

Industry:
Retail, Foodtech, Financial, Energy, Entertainment, Ics, Government, Healthcare, Transport

Geo:
Russia, America, Peru, American, China

TTPs:
Tactics: 3
Technics: 14

IOCs:
Domain: 2
File: 16
Path: 2
Registry: 2
Url: 2
Coin: 1
#ParsedReport
11-07-2022

GuLoader Disguised as Estimate Requests Being Distributed via Phishing Email

https://asec.ahnlab.com/en/36470

Threats:
Cloudeye (tags: stealer, phishing, rat, malware)
Formbook (tags: phishing)
Agent_tesla (tags: phishing)
Remcos_rat (tags: phishing)
Nanocore_rat (tags: phishing)

Geo:
Korean

IOCs:
File: 5
Url: 1
Hash: 1

Functions Names: 1
#ParsedReport
12-07-2022

From cookie theft to BEC: Attackers use AiTM phishing sites as entry point to further financial fraud

https://www.microsoft.com/security/blog/2022/07/12/from-cookie-theft-to-bec-attackers-use-aitm-phishing-sites-as-entry-point-to-further-financial-fraud

Threats:
Aitm_technique (tags: proxy, fraud, malware, scan, phishing, vpn)

Industry:
Financial, Telco, Government

TTPs:
Tactics: 1
Technics: 0

IOCs:
File: 1
Url: 2
Domain: 50

Links:
https://github.com/drk1wi/Modlishka
https://github.com/kgretzky/evilginx2
https://github.com/muraenateam/muraena
#ParsedReport
12-07-2022

OilRig Attack Graphs: Emulating the Iranian Threat Actors Global Campaigns

https://attackiq.com/2022/07/11/oilrig-attack-graphs-emulating-the-iranian-threat-actors-global-campaigns

Actors/Campaigns:
Oilrig

Threats:
Quadagent (tags: malware, dns, backdoor)
Disttrack
Bespoke (tags: phishing)
Tonedeaf (tags: phishing)
Longwatch (tags: phishing)
Valuevault (tags: phishing)
Pickpocket (tags: phishing)
Lazagne (tags: phishing)
Powerview

Industry:
Financial, Telco, Government, Energy

Geo:
Irans, Iranian

TTPs:

Links:
https://github.com/AlessandroZ/LaZagne
#ParsedReport
12-07-2022

ChromeLoader: New Stubborn Malware Campaign

https://unit42.paloaltonetworks.com/chromeloader-malware

Threats:
Chromeloader (tags: stealer, scan, malware, dropper)
Empire_loader

IOCs:
File: 16
Domain: 83
Hash: 173

Functions Names: 4

Links:
https://github.com/xephora/Threat-Remediation-Scripts/tree/main/Threat-Track/CS\_INSTALLER
#ParsedReport
12-07-2022

Dragon News Blog. An Analysis of Infrastructure linked to the Hagga Threat Actor

https://team-cymru.com/blog/2022/07/12/an-analysis-of-infrastructure-linked-to-the-hagga-threat-actor

Actors/Campaigns:
Aggaa

Threats:
Agent_tesla
Mana_tool
Revenge_rat
Azorult
Lokibot_stealer
Formbook
Beacon

Industry:
Telco

Geo:
Vietnam, Pakistan

IOCs:
IP: 18
Domain: 3
File: 1
Url: 1

Functions Names: 1
#ParsedReport
13-07-2022

Go malware on the rise. Introduction

https://decoded.avast.io/davidalvarez/go-malware-on-the-rise/?utm_source=rss&utm_medium=rss&utm_campaign=go-malware-on-the-rise

Threats:
Synflood

Geo:
Russian

CVEs:
CVE-2021-24098 [Vulners]
Vulners: Score: 2.1, CVSS: 4.2,
Vulners: Exploitation: Unknown
X-Force: Risk: 5.5
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (20h2, 1803, 1809, 1909, 2004)
- microsoft windows server 2016 (20h2, 1909, 2004)
- microsoft windows server 2019 (-)

CVE-2021-28312 [Vulners]
Vulners: Score: 4.3, CVSS: 3.6,
Vulners: Exploitation: Unknown
X-Force: Risk: 3.3
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (20h2, 1909, 2004)
- microsoft windows server 2016 (20h2, 1909, 2004)
- microsoft windows server 2019 (-)


IOCs:
File: 2
IP: 1
Path: 1
Hash: 10

Links:
https://github.com/whyrusleeping/hellabot
https://github.com/avast/ioc/tree/master/Caligula
https://github.com/mattn/go-isatty
https://github.com/ftrvxmtrx/fd
https://github.com/mattn/go-shellwords
https://github.com/mattn/go-colorable
https://github.com/inconshreveable/log15
#ParsedReport
13-07-2022

AIRAVAT Malware Targeting Android Users

https://blog.cyble.com/2022/07/13/airavat-malware-targeting-android-users

Threats:
Airavat_rat (tags: malware, ransomware, phishing, rat)
Opendir (tags: ransomware, rat)
Spynote
Spymax

Industry:
Education, Petroleum, Financial, E-commerce

TTPs:
Tactics: 3
Technics: 0

IOCs:
Url: 3
File: 2
Hash: 3

Functions Names: 2

SIGMA: Found

Links:
https://github.com/Th30neAnd0nly/AIRAVAT
#ParsedReport
13-07-2022

Cobalt Strikes again: UAC-0056 continues to target Ukraine in its latest campaign. Different themes, same techniques

https://blog.malwarebytes.com/threat-intelligence/2022/07/cobalt-strikes-again-uac-0056-continues-to-target-ukraine-in-its-latest-campaign

Actors/Campaigns:
Ember_bear
Unc2589
Ice_fog

Threats:
Cobalt_strike (tags: malware, dropper, phishing, rat)
Beacon

Industry:
Government

Geo:
Ukraine, Ukrainian, Russian

TTPs:
Tactics: 1
Technics: 0

IOCs:
File: 6
Domain: 3
Hash: 6
IP: 1
Registry: 2
Path: 1
#ParsedReport
13-07-2022

Objet: / Feed MISP public

https://www.cert.ssi.gouv.fr/ioc/CERTFR-2022-IOC-001

YARA: Found