CTT Report Hub
3.43K subscribers
9.91K photos
6 videos
67 files
13.6K links
Threat Intelligence Report Hub
Download Telegram
#ParsedReport
13-07-2022

Go malware on the rise. Introduction

https://decoded.avast.io/davidalvarez/go-malware-on-the-rise/?utm_source=rss&utm_medium=rss&utm_campaign=go-malware-on-the-rise

Threats:
Synflood

Geo:
Russian

CVEs:
CVE-2021-24098 [Vulners]
Vulners: Score: 2.1, CVSS: 4.2,
Vulners: Exploitation: Unknown
X-Force: Risk: 5.5
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (20h2, 1803, 1809, 1909, 2004)
- microsoft windows server 2016 (20h2, 1909, 2004)
- microsoft windows server 2019 (-)

CVE-2021-28312 [Vulners]
Vulners: Score: 4.3, CVSS: 3.6,
Vulners: Exploitation: Unknown
X-Force: Risk: 3.3
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (20h2, 1909, 2004)
- microsoft windows server 2016 (20h2, 1909, 2004)
- microsoft windows server 2019 (-)


IOCs:
File: 2
IP: 1
Path: 1
Hash: 10

Links:
https://github.com/whyrusleeping/hellabot
https://github.com/avast/ioc/tree/master/Caligula
https://github.com/mattn/go-isatty
https://github.com/ftrvxmtrx/fd
https://github.com/mattn/go-shellwords
https://github.com/mattn/go-colorable
https://github.com/inconshreveable/log15
#ParsedReport
13-07-2022

AIRAVAT Malware Targeting Android Users

https://blog.cyble.com/2022/07/13/airavat-malware-targeting-android-users

Threats:
Airavat_rat (tags: malware, ransomware, phishing, rat)
Opendir (tags: ransomware, rat)
Spynote
Spymax

Industry:
Education, Petroleum, Financial, E-commerce

TTPs:
Tactics: 3
Technics: 0

IOCs:
Url: 3
File: 2
Hash: 3

Functions Names: 2

SIGMA: Found

Links:
https://github.com/Th30neAnd0nly/AIRAVAT
#ParsedReport
13-07-2022

Cobalt Strikes again: UAC-0056 continues to target Ukraine in its latest campaign. Different themes, same techniques

https://blog.malwarebytes.com/threat-intelligence/2022/07/cobalt-strikes-again-uac-0056-continues-to-target-ukraine-in-its-latest-campaign

Actors/Campaigns:
Ember_bear
Unc2589
Ice_fog

Threats:
Cobalt_strike (tags: malware, dropper, phishing, rat)
Beacon

Industry:
Government

Geo:
Ukraine, Ukrainian, Russian

TTPs:
Tactics: 1
Technics: 0

IOCs:
File: 6
Domain: 3
Hash: 6
IP: 1
Registry: 2
Path: 1
#ParsedReport
13-07-2022

Objet: / Feed MISP public

https://www.cert.ssi.gouv.fr/ioc/CERTFR-2022-IOC-001

YARA: Found
#ParsedReport
12-07-2022

New Ransomware Groups on the Rise

https://blog.cyble.com/2022/07/12/new-ransomware-groups-on-the-rise

Actors/Campaigns:
N13v

Threats:
Red_alert (tags: rat, cryptomining, ransomware, malware)
Lilith_rat (tags: ransomware, malware)
0mega (tags: ransomware, malware)
Lilith (tags: ransomware, malware)
Babuk

Industry:
Financial

TTPs:
Tactics: 4
Technics: 6

IOCs:
File: 4
Hash: 3

Functions Names: 15
#ParsedReport
13-07-2022

ASEC ( 20220704 \~ 20220710 ). ASEC Weekly Malware Statistics (20220704 \~ 20220710)

https://asec.ahnlab.com/ko/36533

Threats:
Agent_tesla (tags: malware)
Azorult (tags: malware)
Cloudeye (tags: malware)
Formbook (tags: malware)
Remcos_rat (tags: malware)
Nanocore_rat (tags: malware)
Clipboard_grabbing_technique (tags: malware)
Redline_stealer (tags: malware)
Beamwinhttp_loader (tags: malware)

Industry:
Financial, Transport

Geo:
Korea

IOCs:
File: 45
Domain: 3
IP: 3
Email: 3
Url: 34
#ParsedReport
13-07-2022

Cobalt Strike Analysis and Tutorial: CS Metadata Encryption and Decryption

https://unit42.paloaltonetworks.com/cobalt-strike-metadata-encryption-decryption

Threats:
Cobalt_strike (tags: malware, rat)
Beacon

IOCs:
File: 1
Hash: 2
IP: 1

Functions Names: 4

Links:
https://github.com/DidierStevens/DidierStevensSuite/blob/master/1768.json
https://github.com/DidierStevens/AdHoc/blob/master/cs-mitm.py
https://gist.github.com/olliencc/af056560e943bafa145120103a0947a3#file-dump-java
Добавил в парсер отчетов:
- словарик с софтами
- словарик криптографических алгоритмов
- алгоритм разбора вертикально ориентированных таблиц с описанием TTP из отчетов.
- автоматический перевод (надоело скармливать руками в гугл транслейт корейские и китайские отчеты). Теперь парсер сам понимает что отчет надо переводить.

Скоро дотащу это и до скрипта, формирующего сообщения в телегу.
#ParsedReport
14-07-2022

. Confucius: The fisherman hidden under Cloudflare

https://www.antiy.cn/research/notice&report/research_report/20220713.html

Actors/Campaigns:
Confucius
Sidewinder
Dropping_elephant

Threats:
Quasar_rat
Chrysaor
Backdoor/win32.agentb
Trojan/win32.agent
Polyloader
Asyncrat_rat

Industry:
Energy, Government, Education, Retail, Telco

Geo:
American, Chinese, India, Pakistan, Indian, Asia, China, Bangladesh, Pakistani

TTPs:
Tactics: 5
Technics: 0

IOCs:
File: 18
IP: 2
Hash: 16
Registry: 1
Path: 1
#ParsedReport
14-07-2022

GhostSec Raising the Bar

https://cyberint.com/blog/research/ghostsec-raising-the-bar

Actors/Campaigns:
Ghostsec (motivation: hacktivism)

Threats:
Conti
Dirty_pipe_vuln
Webadmin_tool
Metasploit_tool
Zerologon_vuln

Industry:
Ics, Telco, Aerospace, Energy, Financial, Iot

Geo:
Israeli, Israel, American, Russian, Lebanon, Ukraine, Nigeria, Colombia, Africa

CVEs:
CVE-2021-41773 [Vulners]
Vulners: Score: 4.3, CVSS: 4.4,
Vulners: Exploitation: True
X-Force: Risk: 7.5
X-Force: Patch: Official fix
Soft:
- apache http server (2.4.49)
- fedoraproject fedora (34, 35)
- oracle instantis enterprisetrack (17.1, 17.2, 17.3)
- netapp cloud backup (-)

CVE-2021-41277 [Vulners]
Vulners: Score: 5.0, CVSS: 3.2,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.9
X-Force: Patch: Official fix
Soft:
- metabase (0.40.0, 0.40.1, 0.40.2, 0.40.3, 0.40.4, 1.40.0, 1.40.1, 1.40.2, 1.40.3, 1.40.4)

CVE-2020-1472 [Vulners]
Vulners: Score: 9.3, CVSS: 3.3,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2)
- microsoft windows server 2012 (-, r2)
- microsoft windows server 2016 (-, 1903, 1909, 2004)
- microsoft windows server 2019 (-)
- fedoraproject fedora (31, 32, 33)
have more...
CVE-2022-0847 [Vulners]
Vulners: Score: 7.2, CVSS: 4.0,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- linux linux kernel (<5.16.11, <5.15.25, <5.10.102)
- fedoraproject fedora (35)
- redhat enterprise linux (8.0)
- redhat enterprise linux eus (8.2, 8.4)
- redhat enterprise linux server tus (8.2, 8.4)
have more...

IOCs:
File: 1

Links:
https://github.com/FueledAmp
https://github.com/SoloMsc
https://github.com/U53RW4R3
https://github.com/ghostsec420
https://github.com/NeverWonderLand
#ParsedReport
14-07-2022

Above the Fold and in Your Inbox: Tracing State-Aligned Activity Targeting Journalists, Media

https://www.proofpoint.com/us/blog/threat-insight/above-fold-and-your-inbox-tracing-state-aligned-activity-targeting-journalists

Actors/Campaigns:
Ta412 (motivation: cyber_espionage)
Apt31
Ta459
Ta404
Lazarus
Dream_job
Ta482
Cleaver
Ta456
Tortoiseshell
Ta457

Threats:
Beacon
Atmosphere

Industry:
Government, Financial, Energy

Geo:
Israel, Ukraine, Iran, Georgia, Belarus, Russia, Korean, Asia, Pakistani, Turkish, Korea, Afghanistan, Turkey, Chinese, China

IOCs:
File: 4
Domain: 2
Email: 1
#ParsedReport
14-07-2022

North Korean threat actor targets small and midsize businesses with H0lyGh0st ransomware

https://www.microsoft.com/security/blog/2022/07/14/north-korean-threat-actor-targets-small-and-midsize-businesses-with-h0lygh0st-ransomware

Actors/Campaigns:
Dev-0530
Plutonium
Lazarus

Threats:
H0lygh0st (tags: ransomware, backdoor, malware)
Siennapurple (tags: ransomware, backdoor, malware)
Siennablue (tags: ransomware, malware)
Lockdown (tags: ransomware)
Beacon (tags: ransomware)

Industry:
Government, Energy, Financial

Geo:
Korea, Korean, India

CVEs:
CVE-2022-26352 [Vulners]
Vulners: Score: Unknown, CVSS: Unknown,
Vulners: Exploitation: Unknown
X-Force: Risk: Unknown
X-Force: Patch: Unknown


TTPs:
Tactics: 1
Technics: 0

IOCs:
File: 5
Url: 7
IP: 3
Email: 1
Hash: 4
Path: 1

YARA: Found

Links:
https://github.com/Azure/Azure-Sentinel/blob/master/Detections/MultipleDataSources/Dev-0530\_FileExtRename.yaml
https://github.com/Azure/Azure-Sentinel/blob/master/Detections/MultipleDataSources/Dev-0530\_July2022.yaml
https://github.com/Azure/Azure-Sentinel/blob/master/Detections/SecurityAlert/Dev-0530AVHits.yaml
#ParsedReport
14-07-2022

Climbing Mount Everest: Black-Byte Bytes Back?

https://research.nccgroup.com/2022/07/13/climbing-mount-everest-black-byte-bytes-back

Threats:
Blackbyte (tags: scan, rat, malware, ransomware)
Everbe (tags: ransomware)
Procdump_tool
Cobalt_strike
Metasploit_tool
Splashtop_tool
Beacon
Meterpreter_tool
Netscan_tool
Atera_tool

TTPs:
Tactics: 10
Technics: 12

IOCs:
File: 12
Path: 5
Url: 3
#ParsedReport
14-07-2022

Targeted Attack on Government Agencies

https://www.trellix.com/en-us/about/newsroom/stories/threat-labs/targeted-attack-on-government-agencies.html

Threats:
Asyncrat_rat
Limerat_rat (tags: rat, malware)

Industry:
Financial, Government, Healthcare

Geo:
Asian, Italy, Poland, Indian, Asia, Afghanistan, India

TTPs:
Tactics: 1
Technics: 8

IOCs:
File: 6
Registry: 1
IP: 1
Email: 7

Links:
https://github.com/NYAN-x-CAT/Lime-RAT
https://github.com/NYAN-x-CAT/AsyncRAT-C-Sharp
#ParsedReport
14-07-2022

Transparent Tribe begins targeting education sector in latest campaign

http://blog.talosintelligence.com/2022/07/transparent-tribe-targets-education.html

Actors/Campaigns:
Transparenttribe (motivation: cyber_espionage)

Threats:
Crimson_rat (tags: rat, keylogger)
Oblique_rat
Capra_rat

Industry:
Government, Education

Geo:
Afghanistan, Indian, Pakistani, Pakistan, India

IOCs:
Hash: 3
Domain: 28
Email: 1
IP: 2
Url: 2

Links:
https://github.com/Cisco-Talos/IOCs/tree/main/2022/07
#ParsedReport
14-07-2022

A Hit is made: Suspected India-based Sidewinder APT successfully cyber attacks Pakistan military focused targets

https://blog.checkpoint.com/2022/07/13/a-hit-is-made-suspected-india-based-sidewinder-apt-successfully-cyber-attacks-pakistan-military-focused-targets

Actors/Campaigns:
Sidewinder (motivation: cyber_espionage)

Industry:
Education, Maritime, Aerospace, Government

Geo:
Ukraine, Pakistan, China, India, Indian, Pakistani, Russian

IOCs:
Hash: 2
Url: 2