#ParsedReport
12-07-2022
New Ransomware Groups on the Rise
https://blog.cyble.com/2022/07/12/new-ransomware-groups-on-the-rise
Actors/Campaigns:
N13v
Threats:
Red_alert (tags: rat, cryptomining, ransomware, malware)
Lilith_rat (tags: ransomware, malware)
0mega (tags: ransomware, malware)
Lilith (tags: ransomware, malware)
Babuk
Industry:
Financial
TTPs:
Tactics: 4
Technics: 6
IOCs:
File: 4
Hash: 3
Functions Names: 15
12-07-2022
New Ransomware Groups on the Rise
https://blog.cyble.com/2022/07/12/new-ransomware-groups-on-the-rise
Actors/Campaigns:
N13v
Threats:
Red_alert (tags: rat, cryptomining, ransomware, malware)
Lilith_rat (tags: ransomware, malware)
0mega (tags: ransomware, malware)
Lilith (tags: ransomware, malware)
Babuk
Industry:
Financial
TTPs:
Tactics: 4
Technics: 6
IOCs:
File: 4
Hash: 3
Functions Names: 15
#ParsedReport
13-07-2022
ASEC ( 20220704 \~ 20220710 ). ASEC Weekly Malware Statistics (20220704 \~ 20220710)
https://asec.ahnlab.com/ko/36533
Threats:
Agent_tesla (tags: malware)
Azorult (tags: malware)
Cloudeye (tags: malware)
Formbook (tags: malware)
Remcos_rat (tags: malware)
Nanocore_rat (tags: malware)
Clipboard_grabbing_technique (tags: malware)
Redline_stealer (tags: malware)
Beamwinhttp_loader (tags: malware)
Industry:
Financial, Transport
Geo:
Korea
IOCs:
File: 45
Domain: 3
IP: 3
Email: 3
Url: 34
13-07-2022
ASEC ( 20220704 \~ 20220710 ). ASEC Weekly Malware Statistics (20220704 \~ 20220710)
https://asec.ahnlab.com/ko/36533
Threats:
Agent_tesla (tags: malware)
Azorult (tags: malware)
Cloudeye (tags: malware)
Formbook (tags: malware)
Remcos_rat (tags: malware)
Nanocore_rat (tags: malware)
Clipboard_grabbing_technique (tags: malware)
Redline_stealer (tags: malware)
Beamwinhttp_loader (tags: malware)
Industry:
Financial, Transport
Geo:
Korea
IOCs:
File: 45
Domain: 3
IP: 3
Email: 3
Url: 34
ASEC BLOG
ASEC 주간 악성코드 통계 ( 20220704 ~ 20220710 ) - ASEC BLOG
ASEC 분석팀에서는 ASEC 자동 분석 시스템 RAPIT 을 활용하여 알려진 악성코드들에 대한 분류 및 대응을 진행하고 있다. 본 포스팅에서는 2022년 7월 4일 월요일부터 7월 10일 일요일까지 한 주간 수집된 악성코드의 통계를 정리한다. 대분류 상으로는 인포스틸러가 43.9%로 1위를 차지하였으며, 그 다음으로는 다운로더 악성코드가 27.2%, 백도어 21.1%, 뱅킹 6.1%, 랜섬웨어 1.1%, 코인마이너가 0.6%로 집계되었다. Top 1…
#ParsedReport
13-07-2022
Cobalt Strike Analysis and Tutorial: CS Metadata Encryption and Decryption
https://unit42.paloaltonetworks.com/cobalt-strike-metadata-encryption-decryption
Threats:
Cobalt_strike (tags: malware, rat)
Beacon
IOCs:
File: 1
Hash: 2
IP: 1
Functions Names: 4
Links:
13-07-2022
Cobalt Strike Analysis and Tutorial: CS Metadata Encryption and Decryption
https://unit42.paloaltonetworks.com/cobalt-strike-metadata-encryption-decryption
Threats:
Cobalt_strike (tags: malware, rat)
Beacon
IOCs:
File: 1
Hash: 2
IP: 1
Functions Names: 4
Links:
https://github.com/DidierStevens/DidierStevensSuite/blob/master/1768.jsonhttps://github.com/DidierStevens/AdHoc/blob/master/cs-mitm.pyhttps://gist.github.com/olliencc/af056560e943bafa145120103a0947a3#file-dump-javaUnit 42
Cobalt Strike Analysis and Tutorial: CS Metadata Encryption and Decryption
We show how metadata encryption and decryption contributes to making Cobalt Strike an effective emulator that is difficult to defend against.
Добавил в парсер отчетов:
- словарик с софтами
- словарик криптографических алгоритмов
- алгоритм разбора вертикально ориентированных таблиц с описанием TTP из отчетов.
- автоматический перевод (надоело скармливать руками в гугл транслейт корейские и китайские отчеты). Теперь парсер сам понимает что отчет надо переводить.
Скоро дотащу это и до скрипта, формирующего сообщения в телегу.
- словарик с софтами
- словарик криптографических алгоритмов
- алгоритм разбора вертикально ориентированных таблиц с описанием TTP из отчетов.
- автоматический перевод (надоело скармливать руками в гугл транслейт корейские и китайские отчеты). Теперь парсер сам понимает что отчет надо переводить.
Скоро дотащу это и до скрипта, формирующего сообщения в телегу.
#ParsedReport
14-07-2022
. Confucius: The fisherman hidden under Cloudflare
https://www.antiy.cn/research/notice&report/research_report/20220713.html
Actors/Campaigns:
Confucius
Sidewinder
Dropping_elephant
Threats:
Quasar_rat
Chrysaor
Backdoor/win32.agentb
Trojan/win32.agent
Polyloader
Asyncrat_rat
Industry:
Energy, Government, Education, Retail, Telco
Geo:
American, Chinese, India, Pakistan, Indian, Asia, China, Bangladesh, Pakistani
TTPs:
Tactics: 5
Technics: 0
IOCs:
File: 18
IP: 2
Hash: 16
Registry: 1
Path: 1
14-07-2022
. Confucius: The fisherman hidden under Cloudflare
https://www.antiy.cn/research/notice&report/research_report/20220713.html
Actors/Campaigns:
Confucius
Sidewinder
Dropping_elephant
Threats:
Quasar_rat
Chrysaor
Backdoor/win32.agentb
Trojan/win32.agent
Polyloader
Asyncrat_rat
Industry:
Energy, Government, Education, Retail, Telco
Geo:
American, Chinese, India, Pakistan, Indian, Asia, China, Bangladesh, Pakistani
TTPs:
Tactics: 5
Technics: 0
IOCs:
File: 18
IP: 2
Hash: 16
Registry: 1
Path: 1
www.antiy.cn
Confucius:隐藏在CloudFlare下的垂钓者
安天是引领威胁检测与防御能力发展的网络安全国家队,为客户构建端点防护、流量监测、边界防护、导流捕获、深度分析、应急处置的安全基石
#ParsedReport
14-07-2022
GhostSec Raising the Bar
https://cyberint.com/blog/research/ghostsec-raising-the-bar
Actors/Campaigns:
Ghostsec (motivation: hacktivism)
Threats:
Conti
Dirty_pipe_vuln
Webadmin_tool
Metasploit_tool
Zerologon_vuln
Industry:
Ics, Telco, Aerospace, Energy, Financial, Iot
Geo:
Israeli, Israel, American, Russian, Lebanon, Ukraine, Nigeria, Colombia, Africa
CVEs:
CVE-2021-41773 [Vulners]
Vulners: Score: 4.3, CVSS: 4.4,
Vulners: Exploitation: True
X-Force: Risk: 7.5
X-Force: Patch: Official fix
Soft:
- apache http server (2.4.49)
- fedoraproject fedora (34, 35)
- oracle instantis enterprisetrack (17.1, 17.2, 17.3)
- netapp cloud backup (-)
CVE-2021-41277 [Vulners]
Vulners: Score: 5.0, CVSS: 3.2,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.9
X-Force: Patch: Official fix
Soft:
- metabase (0.40.0, 0.40.1, 0.40.2, 0.40.3, 0.40.4, 1.40.0, 1.40.1, 1.40.2, 1.40.3, 1.40.4)
CVE-2020-1472 [Vulners]
Vulners: Score: 9.3, CVSS: 3.3,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2)
- microsoft windows server 2012 (-, r2)
- microsoft windows server 2016 (-, 1903, 1909, 2004)
- microsoft windows server 2019 (-)
- fedoraproject fedora (31, 32, 33)
have more...
CVE-2022-0847 [Vulners]
Vulners: Score: 7.2, CVSS: 4.0,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- linux linux kernel (<5.16.11, <5.15.25, <5.10.102)
- fedoraproject fedora (35)
- redhat enterprise linux (8.0)
- redhat enterprise linux eus (8.2, 8.4)
- redhat enterprise linux server tus (8.2, 8.4)
have more...
IOCs:
File: 1
Links:
14-07-2022
GhostSec Raising the Bar
https://cyberint.com/blog/research/ghostsec-raising-the-bar
Actors/Campaigns:
Ghostsec (motivation: hacktivism)
Threats:
Conti
Dirty_pipe_vuln
Webadmin_tool
Metasploit_tool
Zerologon_vuln
Industry:
Ics, Telco, Aerospace, Energy, Financial, Iot
Geo:
Israeli, Israel, American, Russian, Lebanon, Ukraine, Nigeria, Colombia, Africa
CVEs:
CVE-2021-41773 [Vulners]
Vulners: Score: 4.3, CVSS: 4.4,
Vulners: Exploitation: True
X-Force: Risk: 7.5
X-Force: Patch: Official fix
Soft:
- apache http server (2.4.49)
- fedoraproject fedora (34, 35)
- oracle instantis enterprisetrack (17.1, 17.2, 17.3)
- netapp cloud backup (-)
CVE-2021-41277 [Vulners]
Vulners: Score: 5.0, CVSS: 3.2,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.9
X-Force: Patch: Official fix
Soft:
- metabase (0.40.0, 0.40.1, 0.40.2, 0.40.3, 0.40.4, 1.40.0, 1.40.1, 1.40.2, 1.40.3, 1.40.4)
CVE-2020-1472 [Vulners]
Vulners: Score: 9.3, CVSS: 3.3,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2)
- microsoft windows server 2012 (-, r2)
- microsoft windows server 2016 (-, 1903, 1909, 2004)
- microsoft windows server 2019 (-)
- fedoraproject fedora (31, 32, 33)
have more...
CVE-2022-0847 [Vulners]
Vulners: Score: 7.2, CVSS: 4.0,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- linux linux kernel (<5.16.11, <5.15.25, <5.10.102)
- fedoraproject fedora (35)
- redhat enterprise linux (8.0)
- redhat enterprise linux eus (8.2, 8.4)
- redhat enterprise linux server tus (8.2, 8.4)
have more...
IOCs:
File: 1
Links:
https://github.com/FueledAmphttps://github.com/SoloMschttps://github.com/U53RW4R3https://github.com/ghostsec420https://github.com/NeverWonderLandCyberint
GhostSec Raising the Bar
Cyberint observed a new hacktivist campaign targeting multiple organizations. The campaign is led by hacktivists group called GhostSec.
#ParsedReport
14-07-2022
Above the Fold and in Your Inbox: Tracing State-Aligned Activity Targeting Journalists, Media
https://www.proofpoint.com/us/blog/threat-insight/above-fold-and-your-inbox-tracing-state-aligned-activity-targeting-journalists
Actors/Campaigns:
Ta412 (motivation: cyber_espionage)
Apt31
Ta459
Ta404
Lazarus
Dream_job
Ta482
Cleaver
Ta456
Tortoiseshell
Ta457
Threats:
Beacon
Atmosphere
Industry:
Government, Financial, Energy
Geo:
Israel, Ukraine, Iran, Georgia, Belarus, Russia, Korean, Asia, Pakistani, Turkish, Korea, Afghanistan, Turkey, Chinese, China
IOCs:
File: 4
Domain: 2
Email: 1
14-07-2022
Above the Fold and in Your Inbox: Tracing State-Aligned Activity Targeting Journalists, Media
https://www.proofpoint.com/us/blog/threat-insight/above-fold-and-your-inbox-tracing-state-aligned-activity-targeting-journalists
Actors/Campaigns:
Ta412 (motivation: cyber_espionage)
Apt31
Ta459
Ta404
Lazarus
Dream_job
Ta482
Cleaver
Ta456
Tortoiseshell
Ta457
Threats:
Beacon
Atmosphere
Industry:
Government, Financial, Energy
Geo:
Israel, Ukraine, Iran, Georgia, Belarus, Russia, Korean, Asia, Pakistani, Turkish, Korea, Afghanistan, Turkey, Chinese, China
IOCs:
File: 4
Domain: 2
Email: 1
Proofpoint
APTs Targeting Journalists & Media Organizations | Proofpoint US
APTs regularly target and pose as journalists and media organizations to advance their state-aligned initiatives. Learn more about Proofpoint's research.
#ParsedReport
14-07-2022
North Korean threat actor targets small and midsize businesses with H0lyGh0st ransomware
https://www.microsoft.com/security/blog/2022/07/14/north-korean-threat-actor-targets-small-and-midsize-businesses-with-h0lygh0st-ransomware
Actors/Campaigns:
Dev-0530
Plutonium
Lazarus
Threats:
H0lygh0st (tags: ransomware, backdoor, malware)
Siennapurple (tags: ransomware, backdoor, malware)
Siennablue (tags: ransomware, malware)
Lockdown (tags: ransomware)
Beacon (tags: ransomware)
Industry:
Government, Energy, Financial
Geo:
Korea, Korean, India
CVEs:
CVE-2022-26352 [Vulners]
Vulners: Score: Unknown, CVSS: Unknown,
Vulners: Exploitation: Unknown
X-Force: Risk: Unknown
X-Force: Patch: Unknown
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 5
Url: 7
IP: 3
Email: 1
Hash: 4
Path: 1
YARA: Found
Links:
14-07-2022
North Korean threat actor targets small and midsize businesses with H0lyGh0st ransomware
https://www.microsoft.com/security/blog/2022/07/14/north-korean-threat-actor-targets-small-and-midsize-businesses-with-h0lygh0st-ransomware
Actors/Campaigns:
Dev-0530
Plutonium
Lazarus
Threats:
H0lygh0st (tags: ransomware, backdoor, malware)
Siennapurple (tags: ransomware, backdoor, malware)
Siennablue (tags: ransomware, malware)
Lockdown (tags: ransomware)
Beacon (tags: ransomware)
Industry:
Government, Energy, Financial
Geo:
Korea, Korean, India
CVEs:
CVE-2022-26352 [Vulners]
Vulners: Score: Unknown, CVSS: Unknown,
Vulners: Exploitation: Unknown
X-Force: Risk: Unknown
X-Force: Patch: Unknown
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 5
Url: 7
IP: 3
Email: 1
Hash: 4
Path: 1
YARA: Found
Links:
https://github.com/Azure/Azure-Sentinel/blob/master/Detections/MultipleDataSources/Dev-0530\_FileExtRename.yamlhttps://github.com/Azure/Azure-Sentinel/blob/master/Detections/MultipleDataSources/Dev-0530\_July2022.yamlhttps://github.com/Azure/Azure-Sentinel/blob/master/Detections/SecurityAlert/Dev-0530AVHits.yamlMicrosoft News
North Korean threat actor targets small and midsize businesses with H0lyGh0st ransomware
A group of actors originating from North Korea that MSTIC tracks as DEV-0530 has been developing and using ransomware in attacks since June 2021. This group, which calls itself H0lyGh0st, utilizes a ransomware payload with the same name.
#ParsedReport
14-07-2022
Climbing Mount Everest: Black-Byte Bytes Back?
https://research.nccgroup.com/2022/07/13/climbing-mount-everest-black-byte-bytes-back
Threats:
Blackbyte (tags: scan, rat, malware, ransomware)
Everbe (tags: ransomware)
Procdump_tool
Cobalt_strike
Metasploit_tool
Splashtop_tool
Beacon
Meterpreter_tool
Netscan_tool
Atera_tool
TTPs:
Tactics: 10
Technics: 12
IOCs:
File: 12
Path: 5
Url: 3
14-07-2022
Climbing Mount Everest: Black-Byte Bytes Back?
https://research.nccgroup.com/2022/07/13/climbing-mount-everest-black-byte-bytes-back
Threats:
Blackbyte (tags: scan, rat, malware, ransomware)
Everbe (tags: ransomware)
Procdump_tool
Cobalt_strike
Metasploit_tool
Splashtop_tool
Beacon
Meterpreter_tool
Netscan_tool
Atera_tool
TTPs:
Tactics: 10
Technics: 12
IOCs:
File: 12
Path: 5
Url: 3
Nccgroup
Cyber Security Research
Cutting-edge cyber security research from NCC Group. Find public reports, technical advisories, analyses, & other novel insights from our global experts.
#ParsedReport
14-07-2022
Targeted Attack on Government Agencies
https://www.trellix.com/en-us/about/newsroom/stories/threat-labs/targeted-attack-on-government-agencies.html
Threats:
Asyncrat_rat
Limerat_rat (tags: rat, malware)
Industry:
Financial, Government, Healthcare
Geo:
Asian, Italy, Poland, Indian, Asia, Afghanistan, India
TTPs:
Tactics: 1
Technics: 8
IOCs:
File: 6
Registry: 1
IP: 1
Email: 7
Links:
14-07-2022
Targeted Attack on Government Agencies
https://www.trellix.com/en-us/about/newsroom/stories/threat-labs/targeted-attack-on-government-agencies.html
Threats:
Asyncrat_rat
Limerat_rat (tags: rat, malware)
Industry:
Financial, Government, Healthcare
Geo:
Asian, Italy, Poland, Indian, Asia, Afghanistan, India
TTPs:
Tactics: 1
Technics: 8
IOCs:
File: 6
Registry: 1
IP: 1
Email: 7
Links:
https://github.com/NYAN-x-CAT/Lime-RAThttps://github.com/NYAN-x-CAT/AsyncRAT-C-SharpTrellix
Targeted attack on Government Agencies
The Trellix Email Security Research Team has discovered a malicious campaign targeting government agencies of Afghanistan, India, Italy, Poland, and the United States since 2021.
#ParsedReport
14-07-2022
New variant of Android SpyJoker malware removed from Play Store after 3 million+ installs
https://blog.malwarebytes.com/android/2022/07/new-variant-of-android-spyjoker-malware-removed-from-play-store-after-3-million-installs
Threats:
Spyjoker (tags: rat, malware, trojan, fraud)
Joker (tags: malware, trojan)
Industry:
Financial
14-07-2022
New variant of Android SpyJoker malware removed from Play Store after 3 million+ installs
https://blog.malwarebytes.com/android/2022/07/new-variant-of-android-spyjoker-malware-removed-from-play-store-after-3-million-installs
Threats:
Spyjoker (tags: rat, malware, trojan, fraud)
Joker (tags: malware, trojan)
Industry:
Financial
Malwarebytes Labs
New variant of Android SpyJoker malware removed from Play Store after 3 million+ installs
A researcher found eight malware-laden apps in the Play Store which have been downloaded over 3 million times.
#ParsedReport
14-07-2022
Rise in Qakbot attacks traced to evolving threat techniques
https://www.zscaler.com/blogs/security-research/rise-qakbot-attacks-traced-evolving-threat-techniques
Threats:
Qakbot (tags: malware, botnet, scan, trojan)
Industry:
Financial
IOCs:
File: 32
Hash: 11
Path: 4
IP: 57
Domain: 136
Functions Names: 3
14-07-2022
Rise in Qakbot attacks traced to evolving threat techniques
https://www.zscaler.com/blogs/security-research/rise-qakbot-attacks-traced-evolving-threat-techniques
Threats:
Qakbot (tags: malware, botnet, scan, trojan)
Industry:
Financial
IOCs:
File: 32
Hash: 11
Path: 4
IP: 57
Domain: 136
Functions Names: 3
Zscaler
Rise in Qakbot attacks traced to evolving threat techniques | Zscaler
Qakbot leverages ZIP archive file having embedded files such as Microsoft Office files, LNK, Powershell, and more.
#ParsedReport
14-07-2022
Transparent Tribe begins targeting education sector in latest campaign
http://blog.talosintelligence.com/2022/07/transparent-tribe-targets-education.html
Actors/Campaigns:
Transparenttribe (motivation: cyber_espionage)
Threats:
Crimson_rat (tags: rat, keylogger)
Oblique_rat
Capra_rat
Industry:
Government, Education
Geo:
Afghanistan, Indian, Pakistani, Pakistan, India
IOCs:
Hash: 3
Domain: 28
Email: 1
IP: 2
Url: 2
Links:
14-07-2022
Transparent Tribe begins targeting education sector in latest campaign
http://blog.talosintelligence.com/2022/07/transparent-tribe-targets-education.html
Actors/Campaigns:
Transparenttribe (motivation: cyber_espionage)
Threats:
Crimson_rat (tags: rat, keylogger)
Oblique_rat
Capra_rat
Industry:
Government, Education
Geo:
Afghanistan, Indian, Pakistani, Pakistan, India
IOCs:
Hash: 3
Domain: 28
Email: 1
IP: 2
Url: 2
Links:
https://github.com/Cisco-Talos/IOCs/tree/main/2022/07Talosintelligence
Transparent Tribe begins targeting education sector in latest campaign
A blog from the world class Intelligence Group, Talos, Cisco's Intelligence Group
#ParsedReport
14-07-2022
A Hit is made: Suspected India-based Sidewinder APT successfully cyber attacks Pakistan military focused targets
https://blog.checkpoint.com/2022/07/13/a-hit-is-made-suspected-india-based-sidewinder-apt-successfully-cyber-attacks-pakistan-military-focused-targets
Actors/Campaigns:
Sidewinder (motivation: cyber_espionage)
Industry:
Education, Maritime, Aerospace, Government
Geo:
Ukraine, Pakistan, China, India, Indian, Pakistani, Russian
IOCs:
Hash: 2
Url: 2
14-07-2022
A Hit is made: Suspected India-based Sidewinder APT successfully cyber attacks Pakistan military focused targets
https://blog.checkpoint.com/2022/07/13/a-hit-is-made-suspected-india-based-sidewinder-apt-successfully-cyber-attacks-pakistan-military-focused-targets
Actors/Campaigns:
Sidewinder (motivation: cyber_espionage)
Industry:
Education, Maritime, Aerospace, Government
Geo:
Ukraine, Pakistan, China, India, Indian, Pakistani, Russian
IOCs:
Hash: 2
Url: 2
#ParsedReport
14-07-2022
ApolloRat: Evasive Malware Compiled using Nuitka
https://blog.cyble.com/2022/07/14/apollorat-evasive-malware-compiled-using-nuitka
Threats:
Apollorat (tags: trojan, malware, rat, stealer, phishing)
Beacon
IOCs:
Hash: 3
File: 1
14-07-2022
ApolloRat: Evasive Malware Compiled using Nuitka
https://blog.cyble.com/2022/07/14/apollorat-evasive-malware-compiled-using-nuitka
Threats:
Apollorat (tags: trojan, malware, rat, stealer, phishing)
Beacon
IOCs:
Hash: 3
File: 1
Cyble
ApolloRat: Evasive Malware Compiled Using Nuitka - Cyble
Cyble analyzes ApolloRat, an Evasive Remote Access Trojan leveraging Discord as a Command & Control Server.
#ParsedReport
15-07-2022
STOP/DJVU Employs Vidar Stealer Before Encrypting Files
https://labs.k7computing.com/index.php/stop-djvu-employs-vidar-stealer-before-encrypting-files
Threats:
Vidar_stealer (tags: ransomware, malware, stealer, rat, trojan)
Stop (tags: ransomware, malware, stealer, rat, trojan)
Process_injection_technique
Gandcrab
Geo:
Kyrgyzstan, Kazakhstan, Ukraine, Belarus, Syria, Armenia, Azerbaijan, Uzbekistan, Russia, Tajikistan
IOCs:
File: 7
Path: 1
Url: 2
IP: 1
Functions Names: 1
15-07-2022
STOP/DJVU Employs Vidar Stealer Before Encrypting Files
https://labs.k7computing.com/index.php/stop-djvu-employs-vidar-stealer-before-encrypting-files
Threats:
Vidar_stealer (tags: ransomware, malware, stealer, rat, trojan)
Stop (tags: ransomware, malware, stealer, rat, trojan)
Process_injection_technique
Gandcrab
Geo:
Kyrgyzstan, Kazakhstan, Ukraine, Belarus, Syria, Armenia, Azerbaijan, Uzbekistan, Russia, Tajikistan
IOCs:
File: 7
Path: 1
Url: 2
IP: 1
Functions Names: 1
K7 Labs
STOP/DJVU Employs Vidar Stealer Before Encrypting Files
STOP/DJVU ransomware was first seen in the last quarter of 2018. Since then we have seen various forms of this […]
#ParsedReport
15-07-2022
Dragon News Blog. An Analysis of Infrastructure linked to the Hagga Threat Actor
https://team-cymru.com/blog/2022/07/12/an-analysis-of-infrastructure-linked-to-the-hagga-threat-actor/?utm_source=Social&utm_medium=linkedin&utm_campaign=threat%20research%20blog
Actors/Campaigns:
Aggaa
Threats:
Agent_tesla
Mana_tool
Revenge_rat
Azorult
Lokibot_stealer
Formbook
Beacon
Industry:
Telco
Geo:
Vietnam, Pakistan
IOCs:
IP: 18
Domain: 3
File: 1
Url: 1
Functions Names: 1
15-07-2022
Dragon News Blog. An Analysis of Infrastructure linked to the Hagga Threat Actor
https://team-cymru.com/blog/2022/07/12/an-analysis-of-infrastructure-linked-to-the-hagga-threat-actor/?utm_source=Social&utm_medium=linkedin&utm_campaign=threat%20research%20blog
Actors/Campaigns:
Aggaa
Threats:
Agent_tesla
Mana_tool
Revenge_rat
Azorult
Lokibot_stealer
Formbook
Beacon
Industry:
Telco
Geo:
Vietnam, Pakistan
IOCs:
IP: 18
Domain: 3
File: 1
Url: 1
Functions Names: 1
👍1
#ParsedReport
15-07-2022
Digium Phones Under Attack: Insight Into the Web Shell Implant
https://unit42.paloaltonetworks.com/digium-phones-web-shell
Geo:
Netherlands, Russian
CVEs:
CVE-2021-45461 [Vulners]
Vulners: Score: 7.5, CVSS: 6.7,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- sangoma restapps (15.0.19.87, 15.0.19.88, 16.0.18.40, 16.0.18.41)
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 2
Url: 3
IP: 1
Domain: 8
Hash: 1
Functions Names: 1
Links:
15-07-2022
Digium Phones Under Attack: Insight Into the Web Shell Implant
https://unit42.paloaltonetworks.com/digium-phones-web-shell
Geo:
Netherlands, Russian
CVEs:
CVE-2021-45461 [Vulners]
Vulners: Score: 7.5, CVSS: 6.7,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- sangoma restapps (15.0.19.87, 15.0.19.88, 16.0.18.40, 16.0.18.41)
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 2
Url: 3
IP: 1
Domain: 8
Hash: 1
Functions Names: 1
Links:
https://github.com/FreePBX/digium\_phonesUnit 42
Digium Phones Under Attack: Insight Into the Web Shell Implant
We witnessed more than 500,000 unique samples of malicious traffic targeting Digium Asterisk software for VoIP phone devices.
#ParsedReport
15-07-2022
Stealthy OpenDocument Malware Deployed Against Latin American Hotels
https://threatresearch.ext.hp.com/stealthy-opendocument-malware-targets-latin-american-hotels
Threats:
Asyncrat_rat
Geo:
Spanish, Portuguese, America, American
TTPs:
IOCs:
File: 4
Domain: 2
Hash: 14
Functions Names: 2
15-07-2022
Stealthy OpenDocument Malware Deployed Against Latin American Hotels
https://threatresearch.ext.hp.com/stealthy-opendocument-malware-targets-latin-american-hotels
Threats:
Asyncrat_rat
Geo:
Spanish, Portuguese, America, American
TTPs:
IOCs:
File: 4
Domain: 2
Hash: 14
Functions Names: 2
HP Wolf Security
Stealthy OpenDocument Malware Deployed Against Latin American Hotels | HP Wolf Security
Don’t let cyber threats get the best of you. Read our post, Stealthy OpenDocument Malware Deployed Against Latin American Hotels, to learn more about cyber threats and cyber security.
#ParsedReport
15-07-2022
Hacktivist Group DragonForce Actively Targeting Indian Entities, Shares an Exploit for a Critical Confluence Server Vulnerability CVE-2022-26134
https://cloudsek.com/threatintelligence/hacktivist-group-dragonforce-actively-targeting-indian-entities-shares-an-exploit-for-a-critical-confluence-server-vulnerability-cve-2022-26134/?utm_source=rss&utm_medium=rss&utm_campaign=hacktivist-group-dragonforce-actively-targeting-indian-entities-shares-an-exploit-for-a-critical-confluence-server-vulnerability-cve-2022-26134
Actors/Campaigns:
Dragonforce (motivation: hacktivism)
Industry:
Government
Geo:
Malaysia, India, Indian
CVEs:
CVE-2022-26134 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- atlassian confluence data center (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
- atlassian confluence server (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 1
15-07-2022
Hacktivist Group DragonForce Actively Targeting Indian Entities, Shares an Exploit for a Critical Confluence Server Vulnerability CVE-2022-26134
https://cloudsek.com/threatintelligence/hacktivist-group-dragonforce-actively-targeting-indian-entities-shares-an-exploit-for-a-critical-confluence-server-vulnerability-cve-2022-26134/?utm_source=rss&utm_medium=rss&utm_campaign=hacktivist-group-dragonforce-actively-targeting-indian-entities-shares-an-exploit-for-a-critical-confluence-server-vulnerability-cve-2022-26134
Actors/Campaigns:
Dragonforce (motivation: hacktivism)
Industry:
Government
Geo:
Malaysia, India, Indian
CVEs:
CVE-2022-26134 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- atlassian confluence data center (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
- atlassian confluence server (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 1
CloudSEK - Digital Risk Management Enterprise | Artificial Intelligence based Cybersecurity
Hacktivist Group DragonForce Actively Targeting Indian Entities, Shares an Exploit for a Critical Confluence Server Vulnerability…
XVigil identified a post on a Telegram channel where the hacktivist group, DragonForce Malaysia has shared an exploit to CVE-2022-26134 to actively target and exploit Indian entities.
#ParsedReport
15-07-2022
Resurgence in Qakbot Malware Activity
https://www.esentire.com/blog/resurgence-in-qakbot-malware-activity
Threats:
Qakbot (tags: malware, phishing, rat)
More_eggs (tags: malware)
Html_smuggling_technique
Follina_vuln
Emotet
Bumblebee
Icedid
Quantum_tool
Geo:
Emea, Apac, America, Africa
CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...
TTPs:
Tactics: 1
Technics: 0
15-07-2022
Resurgence in Qakbot Malware Activity
https://www.esentire.com/blog/resurgence-in-qakbot-malware-activity
Threats:
Qakbot (tags: malware, phishing, rat)
More_eggs (tags: malware)
Html_smuggling_technique
Follina_vuln
Emotet
Bumblebee
Icedid
Quantum_tool
Geo:
Emea, Apac, America, Africa
CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...
TTPs:
Tactics: 1
Technics: 0
eSentire
Resurgence in Qakbot Malware Activity
Learn about the Qakbot malware including what we found, how we found it and recommendations from our Threat Response Unit (TRU) to protect your business from this cyber threat.