CTT Report Hub
3.43K subscribers
9.91K photos
6 videos
67 files
13.6K links
Threat Intelligence Report Hub
Download Telegram
#ParsedReport
18-07-2022

From the Front Lines \| 8220 Gang Massively Expands Cloud Botnet to 30,000 Infected Hosts

https://www.sentinelone.com/blog/from-the-front-lines-8220-gang-massively-expands-cloud-botnet-to-30000-infected-hosts

Threats:
Pwnrig_botnet (tags: botnet, cryptomining)
Whatminer
Tsunami_botnet (tags: botnet)
Xmrig_miner (tags: cryptomining)

Industry:
Government

Geo:
Brazil

IOCs:
IP: 3
Hash: 145
Domain: 14

Functions Names: 1

Links:
https://github.com/xmrig/xmrig
#ParsedReport
18-07-2022

Joker, Facestealer and Coper banking malwares on Google Play store

https://www.zscaler.com/blogs/security-research/joker-facestealer-and-coper-banking-malwares-google-play-store

Threats:
Joker (tags: scan, spam, malware)
Facestealer (tags: spam, malware)
Coper (tags: spam, dropper, backdoor, trojan, malware)

Industry:
Healthcare, E-commerce, Financial

Geo:
India, Australia, America

IOCs:
File: 12
Url: 8
Domain: 3
Hash: 1

Functions Names: 1
#ParsedReport
19-07-2022

Netskope Threat Coverage: Microsoft Discloses New Adversary-in-the-Middle (AiTM) Phishing Attack

https://www.netskope.com/blog/netskope-threat-coverage-microsoft-discloses-new-adversary-in-the-middle-aitm-phishing-attack

Actors/Campaigns:
Bec

Threats:
Aitm_technique (tags: proxy, rat, phishing, scan, malware, fraud)
Phoca_technique
Evilginx2_tool
Emotet

Industry:
Financial, Telco

Links:
https://github.com/kgretzky/evilginx2
#ParsedReport
19-07-2022

Russian APT29 Hackers Use Online Storage Services, DropBox and Google Drive

https://unit42.paloaltonetworks.com/cloaked-ursa-online-storage-services-campaigns

Actors/Campaigns:
Duke

Threats:
Cobalt_strike
Mispadu (tags: dropper, phishing, malware)
Envyscout (tags: malware)
Whispergate
Html_smuggling_technique (tags: malware)
Beacon

Industry:
Government

Geo:
Ukraine, Russian, Egypt, Turkey, Czech, Emea, Japan, America, Portugal, Austrian, Brazil, Apac, Portuguese

TTPs:
Tactics: 1
Technics: 0

IOCs:
File: 12
Hash: 16
Domain: 3
Registry: 3
Path: 1
Email: 1
IP: 3
#ParsedReport
19-07-2022

Ongoing Roaming Mantis smishing campaign targeting France

https://blog.sekoia.io/ongoing-roaming-mantis-smishing-campaign-targeting-france

Actors/Campaigns:
Roaming_mantis (motivation: financially_motivated)

Threats:
Moqhao (tags: malware, phishing)
Formbook
Cyberchef_tool

Geo:
France, Korea, Germany, Chinese, French, Taiwan, Japan

TTPs:

IOCs:
Url: 15
IP: 63
File: 1
Domain: 7
Hash: 2

Links:
https://github.com/SEKOIA-IO/Community/blob/main/IOCs/roamingmantis/roaming\_mantis\_iocs\_20220718.csv
#ParsedReport
19-07-2022

ASEC (20220711 \~ 20220717). ASEC Weekly Malware Statistics (20220711 \~ 20220717)

https://asec.ahnlab.com/ko/36688

Threats:
Agent_tesla (tags: malware)
Azorult (tags: malware)
Cloudeye (tags: malware)
Formbook (tags: malware)
Remcos_rat (tags: malware)
Nanocore_rat (tags: malware)
Clipboard_grabbing_technique (tags: malware)
Njrat_rat (tags: malware)
Avemaria_rat (tags: malware)
Lokibot_stealer (tags: malware)

Industry:
Transport, Financial

Geo:
Korea

IOCs:
File: 52
Domain: 6
IP: 3
Email: 6
Url: 16
#ParsedReport
19-07-2022

New Malware Campaign Targets Russia

https://blog.cyble.com/2022/07/19/new-malware-campaign-targets-russia

Threats:
Apollorat (tags: malware)
Anatsa (tags: malware)

Industry:
Financial

Geo:
Ukraine, Russia, Russian

TTPs:
Tactics: 4
Technics: 0

IOCs:
Hash: 1
Url: 1

Functions Names: 1
#ParsedReport
20-07-2022

Redeemer Ransomware back Action

https://blog.cyble.com/2022/07/20/redeemer-ransomware-back-action

Threats:
Redeemer

Industry:
Financial

TTPs:
Tactics: 5
Technics: 10

IOCs:
File: 8
Path: 3
Hash: 4

Softs:
telegram, vssadmin, bootnxt, winlogon

Functions:
OpenSSL, FindNextFileW, ShellExecuteW, FindFirstFileW
#ParsedReport
20-07-2022

Atlas Intelligence Group (A.I.G) The Wrath of a Titan

https://cyberint.com/blog/research/atlas-intelligence-group

Actors/Campaigns:
Atlantis_cyberarmy
Ddosarmy

Industry:
Education, Government, Financial, E-commerce

Geo:
Pakistan, Israel, Colombia, Emirates, German, Germany

TTPs:
Tactics: 1
Technics: 0

IOCs:
File: 3

Softs:
telegram
#ParsedReport
20-07-2022

New Variant of QakBot Being Spread by HTML File Attached to Phishing Emails

https://www.fortinet.com/blog/threat-research/new-variant-of-qakbot-spread-by-phishing-emails

Threats:
Qakbot
Procmon_tool
Netstat_tool

Industry:
Financial

IOCs:
File: 43
Path: 1
Hash: 3
IP: 243

Softs:
unix, microsoft defender, curl, microsoft edge

Algorithms:
base64, xor, rc4

Functions:
NetGetJoinInformation, GetVersionEx, LookupAccountSidW, WriteProcessMemory, GetSystemMetrics, CreateThread, built-in, GetComputerNameW, FindResourceW, CreateProcessW, API, GetModuleFileNameW, ResumeThread, GetSystemInfo, encryption, CreatProcessW
#ParsedReport
20-07-2022

Black Basta Ransomware Victim Knauf Forced to Stop Their Services

https://socradar.io/black-basta-ransomware-victim-knauf-forced-to-stop-their-services

Threats:
Blackbasta
Conti
Qakbot
Filecoder
Trojan.win32.delshad.gen
Sabsik

Geo:
India, Australia, Canada

IOCs:
Domain: 1
Hash: 10
File: 1
IP: 20

Softs:
esxi, windows defender
#ParsedReport
20-07-2022

Luna and Black Basta new ransomware for Windows, Linux and ESXi

https://securelist.com/luna-black-basta-ransomware/106950

Actors/Campaigns:
Blackcat

Threats:
Blackbasta
Luna
Conti

Geo:
Russian, Asia

IOCs:
Path: 2

Softs:
esxi

Algorithms:
chacha20, curve25519, aes
#ParsedReport
20-07-2022

LockBit: Ransomware Puts Servers in the Crosshairs

https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/lockbit-targets-servers

Threats:
Lockbit
Uacme
Conti
Lockdown

Geo:
Russia

TTPs:
Tactics: 3
Technics: 0

IOCs:
File: 9
Path: 2
Hash: 1
Url: 1

Softs:
windows defender, anydesk, active directory, wordpad, process explorer, msexchange, vssadmin

Functions:
DuplicateTokenEx, CreateProcessAsUserW, GetSystemDefaultUILanguage, GetUserDefaultUILanguage
#ParsedReport
21-07-2022

Malware Being Distributed by Disguising Itself as Icon of V3 Lite

https://asec.ahnlab.com/en/36629

Threats:
Avemaria_rat
Agent_tesla
Lokibot_stealer
Formbook
Remcos_rat
Trojan/win.msilkrypt.r495355
Trojan/win.msilkrypt.r498085
Trojan/win.msil.c5152589
Trojan/win.msil.r500015
Trojan/win.msil.c515258
Tnega

Geo:
Korea

IOCs:
File: 4
Hash: 3
IP: 1
Url: 2
#ParsedReport
21-07-2022

Amadey Bot Being Distributed Through SmokeLoader

https://asec.ahnlab.com/en/36634

Actors/Campaigns:
Ta505

Threats:
Amadey
Smokeloader
Gandcrab
Flawedammyy
Clop
Fallout_ek_tool
Rig_tool
Redline_stealer
Tightvnc_tool
Uac_bypass_technique
Dll_hijacking_technique
Trojan/win.malpe.r503126
Delf
Trojan/win.generic.r503640
Malware/win.trojanspy.r438708
Malware/mdp.download.m1197

IOCs:
File: 15
Path: 7
Registry: 1
Url: 15
Hash: 10
IP: 1

Softs:
realvnc, total commander, task scheduler, windows defender, winscp, tigervnc

Languages:
delphi, rust, autoit
#ParsedReport
21-07-2022

Lightning Framework: New Undetected Swiss Army Knife Linux Malware

https://www.intezer.com/blog/research/lightning-framework-new-linux-threat

Threats:
Lightning_tool
Jigsaw
Netstat_tool
Timestomp_technique

TTPs:
Tactics: 4
Technics: 17

IOCs:
File: 7
IP: 1
Hash: 3

Algorithms:
xor

Functions:
GetRemotePathInfo, CloseShellPure, GetDomainSetting, OpenSSH, DeleteGuid, RemoveKernelHide, DeleteVecFile, SetDomainSetting

Links:
https://github.com/raboof/nethogs