#ParsedReport
15-07-2022
Digium Phones Under Attack: Insight Into the Web Shell Implant
https://unit42.paloaltonetworks.com/digium-phones-web-shell
Geo:
Netherlands, Russian
CVEs:
CVE-2021-45461 [Vulners]
Vulners: Score: 7.5, CVSS: 6.7,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- sangoma restapps (15.0.19.87, 15.0.19.88, 16.0.18.40, 16.0.18.41)
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 2
Url: 3
IP: 1
Domain: 8
Hash: 1
Functions Names: 1
Links:
15-07-2022
Digium Phones Under Attack: Insight Into the Web Shell Implant
https://unit42.paloaltonetworks.com/digium-phones-web-shell
Geo:
Netherlands, Russian
CVEs:
CVE-2021-45461 [Vulners]
Vulners: Score: 7.5, CVSS: 6.7,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- sangoma restapps (15.0.19.87, 15.0.19.88, 16.0.18.40, 16.0.18.41)
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 2
Url: 3
IP: 1
Domain: 8
Hash: 1
Functions Names: 1
Links:
https://github.com/FreePBX/digium\_phonesUnit 42
Digium Phones Under Attack: Insight Into the Web Shell Implant
We witnessed more than 500,000 unique samples of malicious traffic targeting Digium Asterisk software for VoIP phone devices.
#ParsedReport
15-07-2022
Stealthy OpenDocument Malware Deployed Against Latin American Hotels
https://threatresearch.ext.hp.com/stealthy-opendocument-malware-targets-latin-american-hotels
Threats:
Asyncrat_rat
Geo:
Spanish, Portuguese, America, American
TTPs:
IOCs:
File: 4
Domain: 2
Hash: 14
Functions Names: 2
15-07-2022
Stealthy OpenDocument Malware Deployed Against Latin American Hotels
https://threatresearch.ext.hp.com/stealthy-opendocument-malware-targets-latin-american-hotels
Threats:
Asyncrat_rat
Geo:
Spanish, Portuguese, America, American
TTPs:
IOCs:
File: 4
Domain: 2
Hash: 14
Functions Names: 2
HP Wolf Security
Stealthy OpenDocument Malware Deployed Against Latin American Hotels | HP Wolf Security
Don’t let cyber threats get the best of you. Read our post, Stealthy OpenDocument Malware Deployed Against Latin American Hotels, to learn more about cyber threats and cyber security.
#ParsedReport
15-07-2022
Hacktivist Group DragonForce Actively Targeting Indian Entities, Shares an Exploit for a Critical Confluence Server Vulnerability CVE-2022-26134
https://cloudsek.com/threatintelligence/hacktivist-group-dragonforce-actively-targeting-indian-entities-shares-an-exploit-for-a-critical-confluence-server-vulnerability-cve-2022-26134/?utm_source=rss&utm_medium=rss&utm_campaign=hacktivist-group-dragonforce-actively-targeting-indian-entities-shares-an-exploit-for-a-critical-confluence-server-vulnerability-cve-2022-26134
Actors/Campaigns:
Dragonforce (motivation: hacktivism)
Industry:
Government
Geo:
Malaysia, India, Indian
CVEs:
CVE-2022-26134 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- atlassian confluence data center (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
- atlassian confluence server (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 1
15-07-2022
Hacktivist Group DragonForce Actively Targeting Indian Entities, Shares an Exploit for a Critical Confluence Server Vulnerability CVE-2022-26134
https://cloudsek.com/threatintelligence/hacktivist-group-dragonforce-actively-targeting-indian-entities-shares-an-exploit-for-a-critical-confluence-server-vulnerability-cve-2022-26134/?utm_source=rss&utm_medium=rss&utm_campaign=hacktivist-group-dragonforce-actively-targeting-indian-entities-shares-an-exploit-for-a-critical-confluence-server-vulnerability-cve-2022-26134
Actors/Campaigns:
Dragonforce (motivation: hacktivism)
Industry:
Government
Geo:
Malaysia, India, Indian
CVEs:
CVE-2022-26134 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- atlassian confluence data center (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
- atlassian confluence server (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 1
CloudSEK - Digital Risk Management Enterprise | Artificial Intelligence based Cybersecurity
Hacktivist Group DragonForce Actively Targeting Indian Entities, Shares an Exploit for a Critical Confluence Server Vulnerability…
XVigil identified a post on a Telegram channel where the hacktivist group, DragonForce Malaysia has shared an exploit to CVE-2022-26134 to actively target and exploit Indian entities.
#ParsedReport
15-07-2022
Resurgence in Qakbot Malware Activity
https://www.esentire.com/blog/resurgence-in-qakbot-malware-activity
Threats:
Qakbot (tags: malware, phishing, rat)
More_eggs (tags: malware)
Html_smuggling_technique
Follina_vuln
Emotet
Bumblebee
Icedid
Quantum_tool
Geo:
Emea, Apac, America, Africa
CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...
TTPs:
Tactics: 1
Technics: 0
15-07-2022
Resurgence in Qakbot Malware Activity
https://www.esentire.com/blog/resurgence-in-qakbot-malware-activity
Threats:
Qakbot (tags: malware, phishing, rat)
More_eggs (tags: malware)
Html_smuggling_technique
Follina_vuln
Emotet
Bumblebee
Icedid
Quantum_tool
Geo:
Emea, Apac, America, Africa
CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...
TTPs:
Tactics: 1
Technics: 0
eSentire
Resurgence in Qakbot Malware Activity
Learn about the Qakbot malware including what we found, how we found it and recommendations from our Threat Response Unit (TRU) to protect your business from this cyber threat.
#ParsedReport
15-07-2022
APT-C-26Lazarus. APT-C-26 (lazarus) organization forgery e-commerce component attack activity analysis report
https://mp.weixin.qq.com/s/USitU4jAg9y2XkQxbwcAPQ
Actors/Campaigns:
Lazarus
Ice_fog
Threats:
Httpupploader
Nukesped_rat
Nukespd
Mimikatz
Industry:
Government, E-commerce
Geo:
Korean
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 5
Path: 1
Url: 2
Hash: 2
IP: 2
15-07-2022
APT-C-26Lazarus. APT-C-26 (lazarus) organization forgery e-commerce component attack activity analysis report
https://mp.weixin.qq.com/s/USitU4jAg9y2XkQxbwcAPQ
Actors/Campaigns:
Lazarus
Ice_fog
Threats:
Httpupploader
Nukesped_rat
Nukespd
Mimikatz
Industry:
Government, E-commerce
Geo:
Korean
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 5
Path: 1
Url: 2
Hash: 2
IP: 2
Weixin Official Accounts Platform
APT-C-26(Lazarus)组织伪造电商组件攻击活动分析报告
近期,360高级威胁研究院发现了来自Lazarus组织的攻击活动,本次攻击目的明确,攻击手段隐蔽性强,并且不排除有相关后续行动
#ParsedReport
15-07-2022
Exploiting Arbitrary Object Instantiations in PHP without Custom Classes
https://swarm.ptsecurity.com/exploiting-arbitrary-object-instantiations
Geo:
Russian
CVEs:
CVE-2022-31085 [Vulners]
Vulners: Score: 4.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.2
X-Force: Patch: Official fix
Soft:
- ldap-account-manager ldap account manager (<8.0)
- debian debian linux (11.0)
CVE-2022-31084 [Vulners]
Vulners: Score: 6.8, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.4
X-Force: Patch: Official fix
Soft:
- ldap-account-manager ldap account manager (<8.0)
- debian debian linux (11.0)
CVE-2022-31088 [Vulners]
Vulners: Score: 5.0, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 6.5
X-Force: Patch: Official fix
Soft:
- ldap-account-manager ldap account manager (<8.0)
- debian debian linux (11.0)
CVE-2022-31087 [Vulners]
Vulners: Score: 7.2, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- ldap-account-manager ldap account manager (<8.0)
- debian debian linux (11.0)
CVE-2022-31086 [Vulners]
Vulners: Score: 6.0, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 4.7
X-Force: Patch: Official fix
Soft:
- ldap-account-manager ldap account manager (<8.0)
- debian debian linux (11.0)
TTPs:
Tactics: 1
Technics: 0
IOCs:
IP: 1
Functions Names: 3
Links:
15-07-2022
Exploiting Arbitrary Object Instantiations in PHP without Custom Classes
https://swarm.ptsecurity.com/exploiting-arbitrary-object-instantiations
Geo:
Russian
CVEs:
CVE-2022-31085 [Vulners]
Vulners: Score: 4.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.2
X-Force: Patch: Official fix
Soft:
- ldap-account-manager ldap account manager (<8.0)
- debian debian linux (11.0)
CVE-2022-31084 [Vulners]
Vulners: Score: 6.8, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.4
X-Force: Patch: Official fix
Soft:
- ldap-account-manager ldap account manager (<8.0)
- debian debian linux (11.0)
CVE-2022-31088 [Vulners]
Vulners: Score: 5.0, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 6.5
X-Force: Patch: Official fix
Soft:
- ldap-account-manager ldap account manager (<8.0)
- debian debian linux (11.0)
CVE-2022-31087 [Vulners]
Vulners: Score: 7.2, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- ldap-account-manager ldap account manager (<8.0)
- debian debian linux (11.0)
CVE-2022-31086 [Vulners]
Vulners: Score: 6.0, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 4.7
X-Force: Patch: Official fix
Soft:
- ldap-account-manager ldap account manager (<8.0)
- debian debian linux (11.0)
TTPs:
Tactics: 1
Technics: 0
IOCs:
IP: 1
Functions Names: 3
Links:
https://github.com/LDAPAccountManager/lam/blob/6d24baa18223f0babfed2c8890381fb54cdcd6e9/lam-packaging/debian/controlhttps://github.com/ImageMagick/ImageMagick/blob/d2a918098878bd73a57a34b901b5ae85c0c8d17f/MagickCore/utility.c#L692https://github.com/ImageMagick/ImageMagick/blob/d2a918098878bd73a57a34b901b5ae85c0c8d17f/coders/vid.c#L98https://github.com/LDAPAccountManager/lamЕсли к Вам обращаются на CTI-ном, и Вы не совсем понимаете что от Вас хотят, то вотъ словарикъ
https://github.com/BushidoUK/CTI-Lexicon/blob/main/Lexicon.md
https://github.com/BushidoUK/CTI-Lexicon/blob/main/Lexicon.md
GitHub
CTI-Lexicon/Lexicon.md at main · BushidoUK/CTI-Lexicon
Dictionary of CTI-related acronyms, terms, and jargon - BushidoUK/CTI-Lexicon
#ParsedReport
18-07-2022
Raccoon back with new claws!
https://labs.k7computing.com/index.php/raccoon-back-with-new-claws
Threats:
Raccoon_stealer (tags: malware, proxy, trojan, stealer)
Vmprotect
Geo:
Russia
IOCs:
File: 16
Hash: 2
Registry: 3
Url: 1
IP: 1
Functions Names: 10
18-07-2022
Raccoon back with new claws!
https://labs.k7computing.com/index.php/raccoon-back-with-new-claws
Threats:
Raccoon_stealer (tags: malware, proxy, trojan, stealer)
Vmprotect
Geo:
Russia
IOCs:
File: 16
Hash: 2
Registry: 3
Url: 1
IP: 1
Functions Names: 10
K7 Labs
Raccoon back with new claws!
Raccoon infostealer was first released in April 2019, the initial Version1(V1) was distributed in telegram groups and other forums as […]
#ParsedReport
18-07-2022
From the Front Lines \| 8220 Gang Massively Expands Cloud Botnet to 30,000 Infected Hosts
https://www.sentinelone.com/blog/from-the-front-lines-8220-gang-massively-expands-cloud-botnet-to-30000-infected-hosts
Threats:
Pwnrig_botnet (tags: botnet, cryptomining)
Whatminer
Tsunami_botnet (tags: botnet)
Xmrig_miner (tags: cryptomining)
Industry:
Government
Geo:
Brazil
IOCs:
IP: 3
Hash: 145
Domain: 14
Functions Names: 1
Links:
18-07-2022
From the Front Lines \| 8220 Gang Massively Expands Cloud Botnet to 30,000 Infected Hosts
https://www.sentinelone.com/blog/from-the-front-lines-8220-gang-massively-expands-cloud-botnet-to-30000-infected-hosts
Threats:
Pwnrig_botnet (tags: botnet, cryptomining)
Whatminer
Tsunami_botnet (tags: botnet)
Xmrig_miner (tags: cryptomining)
Industry:
Government
Geo:
Brazil
IOCs:
IP: 3
Hash: 145
Domain: 14
Functions Names: 1
Links:
https://github.com/xmrig/xmrigSentinelOne
From the Front Lines | 8220 Gang Massively Expands Cloud Botnet to 30,000 Infected Hosts
Low-level crimeware gang has been exploiting misconfigured and publicly accessible Docker and other cloud instances with roaring success.
#ParsedReport
18-07-2022
Joker, Facestealer and Coper banking malwares on Google Play store
https://www.zscaler.com/blogs/security-research/joker-facestealer-and-coper-banking-malwares-google-play-store
Threats:
Joker (tags: scan, spam, malware)
Facestealer (tags: spam, malware)
Coper (tags: spam, dropper, backdoor, trojan, malware)
Industry:
Healthcare, E-commerce, Financial
Geo:
India, Australia, America
IOCs:
File: 12
Url: 8
Domain: 3
Hash: 1
Functions Names: 1
18-07-2022
Joker, Facestealer and Coper banking malwares on Google Play store
https://www.zscaler.com/blogs/security-research/joker-facestealer-and-coper-banking-malwares-google-play-store
Threats:
Joker (tags: scan, spam, malware)
Facestealer (tags: spam, malware)
Coper (tags: spam, dropper, backdoor, trojan, malware)
Industry:
Healthcare, E-commerce, Financial
Geo:
India, Australia, America
IOCs:
File: 12
Url: 8
Domain: 3
Hash: 1
Functions Names: 1
Zscaler
On Google Play, Joker, Facestealer, & Coper Banking Malware
Joker, Facestealers and Banker swarming Google Play store
#ParsedReport
19-07-2022
Netskope Threat Coverage: Microsoft Discloses New Adversary-in-the-Middle (AiTM) Phishing Attack
https://www.netskope.com/blog/netskope-threat-coverage-microsoft-discloses-new-adversary-in-the-middle-aitm-phishing-attack
Actors/Campaigns:
Bec
Threats:
Aitm_technique (tags: proxy, rat, phishing, scan, malware, fraud)
Phoca_technique
Evilginx2_tool
Emotet
Industry:
Financial, Telco
Links:
19-07-2022
Netskope Threat Coverage: Microsoft Discloses New Adversary-in-the-Middle (AiTM) Phishing Attack
https://www.netskope.com/blog/netskope-threat-coverage-microsoft-discloses-new-adversary-in-the-middle-aitm-phishing-attack
Actors/Campaigns:
Bec
Threats:
Aitm_technique (tags: proxy, rat, phishing, scan, malware, fraud)
Phoca_technique
Evilginx2_tool
Emotet
Industry:
Financial, Telco
Links:
https://github.com/kgretzky/evilginx2Netskope
Netskope Threat Coverage: Microsoft Discloses New Adversary-in-the-Middle (AiTM) Phishing Attack
Summary On July 12, 2022, Microsoft researchers disclosed a large-scale phishing campaign that has targeted more than 10,000 organizations since September
#ParsedReport
19-07-2022
Russian APT29 Hackers Use Online Storage Services, DropBox and Google Drive
https://unit42.paloaltonetworks.com/cloaked-ursa-online-storage-services-campaigns
Actors/Campaigns:
Duke
Threats:
Cobalt_strike
Mispadu (tags: dropper, phishing, malware)
Envyscout (tags: malware)
Whispergate
Html_smuggling_technique (tags: malware)
Beacon
Industry:
Government
Geo:
Ukraine, Russian, Egypt, Turkey, Czech, Emea, Japan, America, Portugal, Austrian, Brazil, Apac, Portuguese
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 12
Hash: 16
Domain: 3
Registry: 3
Path: 1
Email: 1
IP: 3
19-07-2022
Russian APT29 Hackers Use Online Storage Services, DropBox and Google Drive
https://unit42.paloaltonetworks.com/cloaked-ursa-online-storage-services-campaigns
Actors/Campaigns:
Duke
Threats:
Cobalt_strike
Mispadu (tags: dropper, phishing, malware)
Envyscout (tags: malware)
Whispergate
Html_smuggling_technique (tags: malware)
Beacon
Industry:
Government
Geo:
Ukraine, Russian, Egypt, Turkey, Czech, Emea, Japan, America, Portugal, Austrian, Brazil, Apac, Portuguese
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 12
Hash: 16
Domain: 3
Registry: 3
Path: 1
Email: 1
IP: 3
Unit 42
Russian APT29 Hackers Use Online Storage Services, DropBox and Google Drive
Cloaked Ursa (aka APT29, Nobelium or Cozy Bear) has recently used trusted online storage services to deliver Cobalt Strike.
#ParsedReport
19-07-2022
Ongoing Roaming Mantis smishing campaign targeting France
https://blog.sekoia.io/ongoing-roaming-mantis-smishing-campaign-targeting-france
Actors/Campaigns:
Roaming_mantis (motivation: financially_motivated)
Threats:
Moqhao (tags: malware, phishing)
Formbook
Cyberchef_tool
Geo:
France, Korea, Germany, Chinese, French, Taiwan, Japan
TTPs:
IOCs:
Url: 15
IP: 63
File: 1
Domain: 7
Hash: 2
Links:
19-07-2022
Ongoing Roaming Mantis smishing campaign targeting France
https://blog.sekoia.io/ongoing-roaming-mantis-smishing-campaign-targeting-france
Actors/Campaigns:
Roaming_mantis (motivation: financially_motivated)
Threats:
Moqhao (tags: malware, phishing)
Formbook
Cyberchef_tool
Geo:
France, Korea, Germany, Chinese, French, Taiwan, Japan
TTPs:
IOCs:
Url: 15
IP: 63
File: 1
Domain: 7
Hash: 2
Links:
https://github.com/SEKOIA-IO/Community/blob/main/IOCs/roamingmantis/roaming\_mantis\_iocs\_20220718.csvSekoia.io Blog
Ongoing Roaming Mantis smishing campaign targeting France
MoqHao (aka Wroba) is an Android Remote Access Trojan (RAT) with information-stealing and backdoor capabilities that likely spreads via SMS.
#ParsedReport
19-07-2022
ASEC (20220711 \~ 20220717). ASEC Weekly Malware Statistics (20220711 \~ 20220717)
https://asec.ahnlab.com/ko/36688
Threats:
Agent_tesla (tags: malware)
Azorult (tags: malware)
Cloudeye (tags: malware)
Formbook (tags: malware)
Remcos_rat (tags: malware)
Nanocore_rat (tags: malware)
Clipboard_grabbing_technique (tags: malware)
Njrat_rat (tags: malware)
Avemaria_rat (tags: malware)
Lokibot_stealer (tags: malware)
Industry:
Transport, Financial
Geo:
Korea
IOCs:
File: 52
Domain: 6
IP: 3
Email: 6
Url: 16
19-07-2022
ASEC (20220711 \~ 20220717). ASEC Weekly Malware Statistics (20220711 \~ 20220717)
https://asec.ahnlab.com/ko/36688
Threats:
Agent_tesla (tags: malware)
Azorult (tags: malware)
Cloudeye (tags: malware)
Formbook (tags: malware)
Remcos_rat (tags: malware)
Nanocore_rat (tags: malware)
Clipboard_grabbing_technique (tags: malware)
Njrat_rat (tags: malware)
Avemaria_rat (tags: malware)
Lokibot_stealer (tags: malware)
Industry:
Transport, Financial
Geo:
Korea
IOCs:
File: 52
Domain: 6
IP: 3
Email: 6
Url: 16
ASEC BLOG
ASEC 주간 악성코드 통계 (20220711 ~ 20220717) - ASEC BLOG
ASEC 분석팀에서는 ASEC 자동 분석 시스템 RAPIT 을 활용하여 알려진 악성코드들에 대한 분류 및 대응을 진행하고 있다. 본 포스팅에서는 2022년 7월 11일 월요일부터 7월 17일 일요일까지 한 주간 수집된 악성코드의 통계를 정리한다. 대분류 상으로는 인포스틸러가 52.2%로 1위를 차지하였으며, 그 다음으로는 백도어 악성코드가 26.8%, 다운로더 19.7%, 뱅킹 0.6%, 랜섬웨어 0.6%로 집계되었다. Top 1 – Agent Tesla…
#ParsedReport
19-07-2022
New Malware Campaign Targets Russia
https://blog.cyble.com/2022/07/19/new-malware-campaign-targets-russia
Threats:
Apollorat (tags: malware)
Anatsa (tags: malware)
Industry:
Financial
Geo:
Ukraine, Russia, Russian
TTPs:
Tactics: 4
Technics: 0
IOCs:
Hash: 1
Url: 1
Functions Names: 1
19-07-2022
New Malware Campaign Targets Russia
https://blog.cyble.com/2022/07/19/new-malware-campaign-targets-russia
Threats:
Apollorat (tags: malware)
Anatsa (tags: malware)
Industry:
Financial
Geo:
Ukraine, Russia, Russian
TTPs:
Tactics: 4
Technics: 0
IOCs:
Hash: 1
Url: 1
Functions Names: 1
Cyble
New Malware Campaign Targets Russia
Cyble analyzes Falcon, an Android malware variant targeting Russian bank users.
#ParsedReport
20-07-2022
. Analysis report of the attack event of the Linux system regularly
https://www.antiy.cn/research/notice&report/research_report/20220719.html
Geo:
Chinese
IOCs:
File: 4
Hash: 9
Softs:
curl
Algorithms:
rc4
20-07-2022
. Analysis report of the attack event of the Linux system regularly
https://www.antiy.cn/research/notice&report/research_report/20220719.html
Geo:
Chinese
IOCs:
File: 4
Hash: 9
Softs:
curl
Algorithms:
rc4
www.antiy.cn
定时破坏Linux系统的攻击事件分析报告
安天是引领威胁检测与防御能力发展的网络安全国家队,为客户构建端点防护、流量监测、边界防护、导流捕获、深度分析、应急处置的安全基石
#ParsedReport
20-07-2022
Redeemer Ransomware back Action
https://blog.cyble.com/2022/07/20/redeemer-ransomware-back-action
Threats:
Redeemer
Industry:
Financial
TTPs:
Tactics: 5
Technics: 10
IOCs:
File: 8
Path: 3
Hash: 4
Softs:
telegram, vssadmin, bootnxt, winlogon
Functions:
OpenSSL, FindNextFileW, ShellExecuteW, FindFirstFileW
20-07-2022
Redeemer Ransomware back Action
https://blog.cyble.com/2022/07/20/redeemer-ransomware-back-action
Threats:
Redeemer
Industry:
Financial
TTPs:
Tactics: 5
Technics: 10
IOCs:
File: 8
Path: 3
Hash: 4
Softs:
telegram, vssadmin, bootnxt, winlogon
Functions:
OpenSSL, FindNextFileW, ShellExecuteW, FindFirstFileW
Cyble
Redeemer Ransomware back Action
Cyble analyzes the return of Redeemer ransomware and how the ransomware developer is increasingly leveraging affiliates.
#ParsedReport
20-07-2022
Atlas Intelligence Group (A.I.G) The Wrath of a Titan
https://cyberint.com/blog/research/atlas-intelligence-group
Actors/Campaigns:
Atlantis_cyberarmy
Ddosarmy
Industry:
Education, Government, Financial, E-commerce
Geo:
Pakistan, Israel, Colombia, Emirates, German, Germany
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 3
Softs:
telegram
20-07-2022
Atlas Intelligence Group (A.I.G) The Wrath of a Titan
https://cyberint.com/blog/research/atlas-intelligence-group
Actors/Campaigns:
Atlantis_cyberarmy
Ddosarmy
Industry:
Education, Government, Financial, E-commerce
Geo:
Pakistan, Israel, Colombia, Emirates, German, Germany
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 3
Softs:
telegram
Cyberint
Atlas Intelligence Group (A.I.G) – The Wrath of a Titan
The Atlas Intelligence Group is recruiting cyber-mercenaries to do specific jobs as a part of bigger campaigns known only to the admins.
#ParsedReport
20-07-2022
New Variant of QakBot Being Spread by HTML File Attached to Phishing Emails
https://www.fortinet.com/blog/threat-research/new-variant-of-qakbot-spread-by-phishing-emails
Threats:
Qakbot
Procmon_tool
Netstat_tool
Industry:
Financial
IOCs:
File: 43
Path: 1
Hash: 3
IP: 243
Softs:
unix, microsoft defender, curl, microsoft edge
Algorithms:
base64, xor, rc4
Functions:
NetGetJoinInformation, GetVersionEx, LookupAccountSidW, WriteProcessMemory, GetSystemMetrics, CreateThread, built-in, GetComputerNameW, FindResourceW, CreateProcessW, API, GetModuleFileNameW, ResumeThread, GetSystemInfo, encryption, CreatProcessW
20-07-2022
New Variant of QakBot Being Spread by HTML File Attached to Phishing Emails
https://www.fortinet.com/blog/threat-research/new-variant-of-qakbot-spread-by-phishing-emails
Threats:
Qakbot
Procmon_tool
Netstat_tool
Industry:
Financial
IOCs:
File: 43
Path: 1
Hash: 3
IP: 243
Softs:
unix, microsoft defender, curl, microsoft edge
Algorithms:
base64, xor, rc4
Functions:
NetGetJoinInformation, GetVersionEx, LookupAccountSidW, WriteProcessMemory, GetSystemMetrics, CreateThread, built-in, GetComputerNameW, FindResourceW, CreateProcessW, API, GetModuleFileNameW, ResumeThread, GetSystemInfo, encryption, CreatProcessW
Fortinet Blog
New Variant of QakBot Being Spread by HTML File Attached to Phishing Emails
FortiGuard Labs discovered a phishing campaign spreading a new variant of the information stealer and banking Trojan QakBot. Read our blog to learn how the QakBot variant operates. …
#ParsedReport
20-07-2022
Black Basta Ransomware Victim Knauf Forced to Stop Their Services
https://socradar.io/black-basta-ransomware-victim-knauf-forced-to-stop-their-services
Threats:
Blackbasta
Conti
Qakbot
Filecoder
Trojan.win32.delshad.gen
Sabsik
Geo:
India, Australia, Canada
IOCs:
Domain: 1
Hash: 10
File: 1
IP: 20
Softs:
esxi, windows defender
20-07-2022
Black Basta Ransomware Victim Knauf Forced to Stop Their Services
https://socradar.io/black-basta-ransomware-victim-knauf-forced-to-stop-their-services
Threats:
Blackbasta
Conti
Qakbot
Filecoder
Trojan.win32.delshad.gen
Sabsik
Geo:
India, Australia, Canada
IOCs:
Domain: 1
Hash: 10
File: 1
IP: 20
Softs:
esxi, windows defender
SOCRadar® Cyber Intelligence Inc.
Black Basta Ransomware Victim Knauf Forced to Stop Their Services - SOCRadar® Cyber Intelligence Inc.
#ParsedReport
20-07-2022
ISO IcedID. ICEDID distribution through ISO file
https://asec.ahnlab.com/ko/36776
Threats:
Icedid
Bumblebee
Emotet
Dridex
Trojan/win.generic.r503676
Industry:
Financial
IOCs:
File: 12
Path: 2
Url: 2
Hash: 4
20-07-2022
ISO IcedID. ICEDID distribution through ISO file
https://asec.ahnlab.com/ko/36776
Threats:
Icedid
Bumblebee
Emotet
Dridex
Trojan/win.generic.r503676
Industry:
Financial
IOCs:
File: 12
Path: 2
Url: 2
Hash: 4
ASEC BLOG
ISO 파일을 통해 IcedID 유포 중 - ASEC BLOG
ASEC 분석팀은 ISO 파일을 통해 다양한 악성코드가 유포되고 있는 사례를 소개해왔다. 최근에는 ISO 파일을 통해 모듈형 뱅킹 악성코드인 IcedID 가 유포 중인 것을 확인하였다. 확인된 유형은 2가지로, 하나는 이전에 소개했던 Bumblebee 악성코드와 동일한 방식을 이용하였다. 나머지 유형 또한 비슷한 방식을 사용했지만, 스크립트 파일과 cmd 명령어가 추가된 형태이다. 먼저, 첫번째 유형은 IcedID 가 실행되는 과정 및 유포되는 과정이…