CTT Report Hub
3.43K subscribers
9.91K photos
6 videos
67 files
13.6K links
Threat Intelligence Report Hub
Download Telegram
#ParsedReport
15-07-2022

Digium Phones Under Attack: Insight Into the Web Shell Implant

https://unit42.paloaltonetworks.com/digium-phones-web-shell

Geo:
Netherlands, Russian

CVEs:
CVE-2021-45461 [Vulners]
Vulners: Score: 7.5, CVSS: 6.7,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- sangoma restapps (15.0.19.87, 15.0.19.88, 16.0.18.40, 16.0.18.41)


TTPs:
Tactics: 1
Technics: 0

IOCs:
File: 2
Url: 3
IP: 1
Domain: 8
Hash: 1

Functions Names: 1

Links:
https://github.com/FreePBX/digium\_phones
#ParsedReport
15-07-2022

Hacktivist Group DragonForce Actively Targeting Indian Entities, Shares an Exploit for a Critical Confluence Server Vulnerability CVE-2022-26134

https://cloudsek.com/threatintelligence/hacktivist-group-dragonforce-actively-targeting-indian-entities-shares-an-exploit-for-a-critical-confluence-server-vulnerability-cve-2022-26134/?utm_source=rss&utm_medium=rss&utm_campaign=hacktivist-group-dragonforce-actively-targeting-indian-entities-shares-an-exploit-for-a-critical-confluence-server-vulnerability-cve-2022-26134

Actors/Campaigns:
Dragonforce (motivation: hacktivism)

Industry:
Government

Geo:
Malaysia, India, Indian

CVEs:
CVE-2022-26134 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- atlassian confluence data center (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
- atlassian confluence server (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)


TTPs:
Tactics: 1
Technics: 0

IOCs:
File: 1
#ParsedReport
15-07-2022

Resurgence in Qakbot Malware Activity

https://www.esentire.com/blog/resurgence-in-qakbot-malware-activity

Threats:
Qakbot (tags: malware, phishing, rat)
More_eggs (tags: malware)
Html_smuggling_technique
Follina_vuln
Emotet
Bumblebee
Icedid
Quantum_tool

Geo:
Emea, Apac, America, Africa

CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...

TTPs:
Tactics: 1
Technics: 0
#ParsedReport
15-07-2022

APT-C-26Lazarus. APT-C-26 (lazarus) organization forgery e-commerce component attack activity analysis report

https://mp.weixin.qq.com/s/USitU4jAg9y2XkQxbwcAPQ

Actors/Campaigns:
Lazarus
Ice_fog

Threats:
Httpupploader
Nukesped_rat
Nukespd
Mimikatz

Industry:
Government, E-commerce

Geo:
Korean

TTPs:
Tactics: 1
Technics: 0

IOCs:
File: 5
Path: 1
Url: 2
Hash: 2
IP: 2
#ParsedReport
15-07-2022

Exploiting Arbitrary Object Instantiations in PHP without Custom Classes

https://swarm.ptsecurity.com/exploiting-arbitrary-object-instantiations

Geo:
Russian

CVEs:
CVE-2022-31085 [Vulners]
Vulners: Score: 4.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.2
X-Force: Patch: Official fix
Soft:
- ldap-account-manager ldap account manager (<8.0)
- debian debian linux (11.0)

CVE-2022-31084 [Vulners]
Vulners: Score: 6.8, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.4
X-Force: Patch: Official fix
Soft:
- ldap-account-manager ldap account manager (<8.0)
- debian debian linux (11.0)

CVE-2022-31088 [Vulners]
Vulners: Score: 5.0, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 6.5
X-Force: Patch: Official fix
Soft:
- ldap-account-manager ldap account manager (<8.0)
- debian debian linux (11.0)

CVE-2022-31087 [Vulners]
Vulners: Score: 7.2, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- ldap-account-manager ldap account manager (<8.0)
- debian debian linux (11.0)

CVE-2022-31086 [Vulners]
Vulners: Score: 6.0, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 4.7
X-Force: Patch: Official fix
Soft:
- ldap-account-manager ldap account manager (<8.0)
- debian debian linux (11.0)


TTPs:
Tactics: 1
Technics: 0

IOCs:
IP: 1

Functions Names: 3

Links:
https://github.com/LDAPAccountManager/lam/blob/6d24baa18223f0babfed2c8890381fb54cdcd6e9/lam-packaging/debian/control
https://github.com/ImageMagick/ImageMagick/blob/d2a918098878bd73a57a34b901b5ae85c0c8d17f/MagickCore/utility.c#L692
https://github.com/ImageMagick/ImageMagick/blob/d2a918098878bd73a57a34b901b5ae85c0c8d17f/coders/vid.c#L98
https://github.com/LDAPAccountManager/lam
Если к Вам обращаются на CTI-ном, и Вы не совсем понимаете что от Вас хотят, то вотъ словарикъ
https://github.com/BushidoUK/CTI-Lexicon/blob/main/Lexicon.md
#ParsedReport
18-07-2022

Raccoon back with new claws!

https://labs.k7computing.com/index.php/raccoon-back-with-new-claws

Threats:
Raccoon_stealer (tags: malware, proxy, trojan, stealer)
Vmprotect

Geo:
Russia

IOCs:
File: 16
Hash: 2
Registry: 3
Url: 1
IP: 1

Functions Names: 10
#ParsedReport
18-07-2022

From the Front Lines \| 8220 Gang Massively Expands Cloud Botnet to 30,000 Infected Hosts

https://www.sentinelone.com/blog/from-the-front-lines-8220-gang-massively-expands-cloud-botnet-to-30000-infected-hosts

Threats:
Pwnrig_botnet (tags: botnet, cryptomining)
Whatminer
Tsunami_botnet (tags: botnet)
Xmrig_miner (tags: cryptomining)

Industry:
Government

Geo:
Brazil

IOCs:
IP: 3
Hash: 145
Domain: 14

Functions Names: 1

Links:
https://github.com/xmrig/xmrig
#ParsedReport
18-07-2022

Joker, Facestealer and Coper banking malwares on Google Play store

https://www.zscaler.com/blogs/security-research/joker-facestealer-and-coper-banking-malwares-google-play-store

Threats:
Joker (tags: scan, spam, malware)
Facestealer (tags: spam, malware)
Coper (tags: spam, dropper, backdoor, trojan, malware)

Industry:
Healthcare, E-commerce, Financial

Geo:
India, Australia, America

IOCs:
File: 12
Url: 8
Domain: 3
Hash: 1

Functions Names: 1
#ParsedReport
19-07-2022

Netskope Threat Coverage: Microsoft Discloses New Adversary-in-the-Middle (AiTM) Phishing Attack

https://www.netskope.com/blog/netskope-threat-coverage-microsoft-discloses-new-adversary-in-the-middle-aitm-phishing-attack

Actors/Campaigns:
Bec

Threats:
Aitm_technique (tags: proxy, rat, phishing, scan, malware, fraud)
Phoca_technique
Evilginx2_tool
Emotet

Industry:
Financial, Telco

Links:
https://github.com/kgretzky/evilginx2
#ParsedReport
19-07-2022

Russian APT29 Hackers Use Online Storage Services, DropBox and Google Drive

https://unit42.paloaltonetworks.com/cloaked-ursa-online-storage-services-campaigns

Actors/Campaigns:
Duke

Threats:
Cobalt_strike
Mispadu (tags: dropper, phishing, malware)
Envyscout (tags: malware)
Whispergate
Html_smuggling_technique (tags: malware)
Beacon

Industry:
Government

Geo:
Ukraine, Russian, Egypt, Turkey, Czech, Emea, Japan, America, Portugal, Austrian, Brazil, Apac, Portuguese

TTPs:
Tactics: 1
Technics: 0

IOCs:
File: 12
Hash: 16
Domain: 3
Registry: 3
Path: 1
Email: 1
IP: 3
#ParsedReport
19-07-2022

Ongoing Roaming Mantis smishing campaign targeting France

https://blog.sekoia.io/ongoing-roaming-mantis-smishing-campaign-targeting-france

Actors/Campaigns:
Roaming_mantis (motivation: financially_motivated)

Threats:
Moqhao (tags: malware, phishing)
Formbook
Cyberchef_tool

Geo:
France, Korea, Germany, Chinese, French, Taiwan, Japan

TTPs:

IOCs:
Url: 15
IP: 63
File: 1
Domain: 7
Hash: 2

Links:
https://github.com/SEKOIA-IO/Community/blob/main/IOCs/roamingmantis/roaming\_mantis\_iocs\_20220718.csv
#ParsedReport
19-07-2022

ASEC (20220711 \~ 20220717). ASEC Weekly Malware Statistics (20220711 \~ 20220717)

https://asec.ahnlab.com/ko/36688

Threats:
Agent_tesla (tags: malware)
Azorult (tags: malware)
Cloudeye (tags: malware)
Formbook (tags: malware)
Remcos_rat (tags: malware)
Nanocore_rat (tags: malware)
Clipboard_grabbing_technique (tags: malware)
Njrat_rat (tags: malware)
Avemaria_rat (tags: malware)
Lokibot_stealer (tags: malware)

Industry:
Transport, Financial

Geo:
Korea

IOCs:
File: 52
Domain: 6
IP: 3
Email: 6
Url: 16
#ParsedReport
19-07-2022

New Malware Campaign Targets Russia

https://blog.cyble.com/2022/07/19/new-malware-campaign-targets-russia

Threats:
Apollorat (tags: malware)
Anatsa (tags: malware)

Industry:
Financial

Geo:
Ukraine, Russia, Russian

TTPs:
Tactics: 4
Technics: 0

IOCs:
Hash: 1
Url: 1

Functions Names: 1
#ParsedReport
20-07-2022

Redeemer Ransomware back Action

https://blog.cyble.com/2022/07/20/redeemer-ransomware-back-action

Threats:
Redeemer

Industry:
Financial

TTPs:
Tactics: 5
Technics: 10

IOCs:
File: 8
Path: 3
Hash: 4

Softs:
telegram, vssadmin, bootnxt, winlogon

Functions:
OpenSSL, FindNextFileW, ShellExecuteW, FindFirstFileW
#ParsedReport
20-07-2022

Atlas Intelligence Group (A.I.G) The Wrath of a Titan

https://cyberint.com/blog/research/atlas-intelligence-group

Actors/Campaigns:
Atlantis_cyberarmy
Ddosarmy

Industry:
Education, Government, Financial, E-commerce

Geo:
Pakistan, Israel, Colombia, Emirates, German, Germany

TTPs:
Tactics: 1
Technics: 0

IOCs:
File: 3

Softs:
telegram
#ParsedReport
20-07-2022

New Variant of QakBot Being Spread by HTML File Attached to Phishing Emails

https://www.fortinet.com/blog/threat-research/new-variant-of-qakbot-spread-by-phishing-emails

Threats:
Qakbot
Procmon_tool
Netstat_tool

Industry:
Financial

IOCs:
File: 43
Path: 1
Hash: 3
IP: 243

Softs:
unix, microsoft defender, curl, microsoft edge

Algorithms:
base64, xor, rc4

Functions:
NetGetJoinInformation, GetVersionEx, LookupAccountSidW, WriteProcessMemory, GetSystemMetrics, CreateThread, built-in, GetComputerNameW, FindResourceW, CreateProcessW, API, GetModuleFileNameW, ResumeThread, GetSystemInfo, encryption, CreatProcessW
#ParsedReport
20-07-2022

Black Basta Ransomware Victim Knauf Forced to Stop Their Services

https://socradar.io/black-basta-ransomware-victim-knauf-forced-to-stop-their-services

Threats:
Blackbasta
Conti
Qakbot
Filecoder
Trojan.win32.delshad.gen
Sabsik

Geo:
India, Australia, Canada

IOCs:
Domain: 1
Hash: 10
File: 1
IP: 20

Softs:
esxi, windows defender