#ParsedReport
19-07-2022
Ongoing Roaming Mantis smishing campaign targeting France
https://blog.sekoia.io/ongoing-roaming-mantis-smishing-campaign-targeting-france
Actors/Campaigns:
Roaming_mantis (motivation: financially_motivated)
Threats:
Moqhao (tags: malware, phishing)
Formbook
Cyberchef_tool
Geo:
France, Korea, Germany, Chinese, French, Taiwan, Japan
TTPs:
IOCs:
Url: 15
IP: 63
File: 1
Domain: 7
Hash: 2
Links:
19-07-2022
Ongoing Roaming Mantis smishing campaign targeting France
https://blog.sekoia.io/ongoing-roaming-mantis-smishing-campaign-targeting-france
Actors/Campaigns:
Roaming_mantis (motivation: financially_motivated)
Threats:
Moqhao (tags: malware, phishing)
Formbook
Cyberchef_tool
Geo:
France, Korea, Germany, Chinese, French, Taiwan, Japan
TTPs:
IOCs:
Url: 15
IP: 63
File: 1
Domain: 7
Hash: 2
Links:
https://github.com/SEKOIA-IO/Community/blob/main/IOCs/roamingmantis/roaming\_mantis\_iocs\_20220718.csvSekoia.io Blog
Ongoing Roaming Mantis smishing campaign targeting France
MoqHao (aka Wroba) is an Android Remote Access Trojan (RAT) with information-stealing and backdoor capabilities that likely spreads via SMS.
#ParsedReport
19-07-2022
ASEC (20220711 \~ 20220717). ASEC Weekly Malware Statistics (20220711 \~ 20220717)
https://asec.ahnlab.com/ko/36688
Threats:
Agent_tesla (tags: malware)
Azorult (tags: malware)
Cloudeye (tags: malware)
Formbook (tags: malware)
Remcos_rat (tags: malware)
Nanocore_rat (tags: malware)
Clipboard_grabbing_technique (tags: malware)
Njrat_rat (tags: malware)
Avemaria_rat (tags: malware)
Lokibot_stealer (tags: malware)
Industry:
Transport, Financial
Geo:
Korea
IOCs:
File: 52
Domain: 6
IP: 3
Email: 6
Url: 16
19-07-2022
ASEC (20220711 \~ 20220717). ASEC Weekly Malware Statistics (20220711 \~ 20220717)
https://asec.ahnlab.com/ko/36688
Threats:
Agent_tesla (tags: malware)
Azorult (tags: malware)
Cloudeye (tags: malware)
Formbook (tags: malware)
Remcos_rat (tags: malware)
Nanocore_rat (tags: malware)
Clipboard_grabbing_technique (tags: malware)
Njrat_rat (tags: malware)
Avemaria_rat (tags: malware)
Lokibot_stealer (tags: malware)
Industry:
Transport, Financial
Geo:
Korea
IOCs:
File: 52
Domain: 6
IP: 3
Email: 6
Url: 16
ASEC BLOG
ASEC 주간 악성코드 통계 (20220711 ~ 20220717) - ASEC BLOG
ASEC 분석팀에서는 ASEC 자동 분석 시스템 RAPIT 을 활용하여 알려진 악성코드들에 대한 분류 및 대응을 진행하고 있다. 본 포스팅에서는 2022년 7월 11일 월요일부터 7월 17일 일요일까지 한 주간 수집된 악성코드의 통계를 정리한다. 대분류 상으로는 인포스틸러가 52.2%로 1위를 차지하였으며, 그 다음으로는 백도어 악성코드가 26.8%, 다운로더 19.7%, 뱅킹 0.6%, 랜섬웨어 0.6%로 집계되었다. Top 1 – Agent Tesla…
#ParsedReport
19-07-2022
New Malware Campaign Targets Russia
https://blog.cyble.com/2022/07/19/new-malware-campaign-targets-russia
Threats:
Apollorat (tags: malware)
Anatsa (tags: malware)
Industry:
Financial
Geo:
Ukraine, Russia, Russian
TTPs:
Tactics: 4
Technics: 0
IOCs:
Hash: 1
Url: 1
Functions Names: 1
19-07-2022
New Malware Campaign Targets Russia
https://blog.cyble.com/2022/07/19/new-malware-campaign-targets-russia
Threats:
Apollorat (tags: malware)
Anatsa (tags: malware)
Industry:
Financial
Geo:
Ukraine, Russia, Russian
TTPs:
Tactics: 4
Technics: 0
IOCs:
Hash: 1
Url: 1
Functions Names: 1
Cyble
New Malware Campaign Targets Russia
Cyble analyzes Falcon, an Android malware variant targeting Russian bank users.
#ParsedReport
20-07-2022
. Analysis report of the attack event of the Linux system regularly
https://www.antiy.cn/research/notice&report/research_report/20220719.html
Geo:
Chinese
IOCs:
File: 4
Hash: 9
Softs:
curl
Algorithms:
rc4
20-07-2022
. Analysis report of the attack event of the Linux system regularly
https://www.antiy.cn/research/notice&report/research_report/20220719.html
Geo:
Chinese
IOCs:
File: 4
Hash: 9
Softs:
curl
Algorithms:
rc4
www.antiy.cn
定时破坏Linux系统的攻击事件分析报告
安天是引领威胁检测与防御能力发展的网络安全国家队,为客户构建端点防护、流量监测、边界防护、导流捕获、深度分析、应急处置的安全基石
#ParsedReport
20-07-2022
Redeemer Ransomware back Action
https://blog.cyble.com/2022/07/20/redeemer-ransomware-back-action
Threats:
Redeemer
Industry:
Financial
TTPs:
Tactics: 5
Technics: 10
IOCs:
File: 8
Path: 3
Hash: 4
Softs:
telegram, vssadmin, bootnxt, winlogon
Functions:
OpenSSL, FindNextFileW, ShellExecuteW, FindFirstFileW
20-07-2022
Redeemer Ransomware back Action
https://blog.cyble.com/2022/07/20/redeemer-ransomware-back-action
Threats:
Redeemer
Industry:
Financial
TTPs:
Tactics: 5
Technics: 10
IOCs:
File: 8
Path: 3
Hash: 4
Softs:
telegram, vssadmin, bootnxt, winlogon
Functions:
OpenSSL, FindNextFileW, ShellExecuteW, FindFirstFileW
Cyble
Redeemer Ransomware back Action
Cyble analyzes the return of Redeemer ransomware and how the ransomware developer is increasingly leveraging affiliates.
#ParsedReport
20-07-2022
Atlas Intelligence Group (A.I.G) The Wrath of a Titan
https://cyberint.com/blog/research/atlas-intelligence-group
Actors/Campaigns:
Atlantis_cyberarmy
Ddosarmy
Industry:
Education, Government, Financial, E-commerce
Geo:
Pakistan, Israel, Colombia, Emirates, German, Germany
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 3
Softs:
telegram
20-07-2022
Atlas Intelligence Group (A.I.G) The Wrath of a Titan
https://cyberint.com/blog/research/atlas-intelligence-group
Actors/Campaigns:
Atlantis_cyberarmy
Ddosarmy
Industry:
Education, Government, Financial, E-commerce
Geo:
Pakistan, Israel, Colombia, Emirates, German, Germany
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 3
Softs:
telegram
Cyberint
Atlas Intelligence Group (A.I.G) – The Wrath of a Titan
The Atlas Intelligence Group is recruiting cyber-mercenaries to do specific jobs as a part of bigger campaigns known only to the admins.
#ParsedReport
20-07-2022
New Variant of QakBot Being Spread by HTML File Attached to Phishing Emails
https://www.fortinet.com/blog/threat-research/new-variant-of-qakbot-spread-by-phishing-emails
Threats:
Qakbot
Procmon_tool
Netstat_tool
Industry:
Financial
IOCs:
File: 43
Path: 1
Hash: 3
IP: 243
Softs:
unix, microsoft defender, curl, microsoft edge
Algorithms:
base64, xor, rc4
Functions:
NetGetJoinInformation, GetVersionEx, LookupAccountSidW, WriteProcessMemory, GetSystemMetrics, CreateThread, built-in, GetComputerNameW, FindResourceW, CreateProcessW, API, GetModuleFileNameW, ResumeThread, GetSystemInfo, encryption, CreatProcessW
20-07-2022
New Variant of QakBot Being Spread by HTML File Attached to Phishing Emails
https://www.fortinet.com/blog/threat-research/new-variant-of-qakbot-spread-by-phishing-emails
Threats:
Qakbot
Procmon_tool
Netstat_tool
Industry:
Financial
IOCs:
File: 43
Path: 1
Hash: 3
IP: 243
Softs:
unix, microsoft defender, curl, microsoft edge
Algorithms:
base64, xor, rc4
Functions:
NetGetJoinInformation, GetVersionEx, LookupAccountSidW, WriteProcessMemory, GetSystemMetrics, CreateThread, built-in, GetComputerNameW, FindResourceW, CreateProcessW, API, GetModuleFileNameW, ResumeThread, GetSystemInfo, encryption, CreatProcessW
Fortinet Blog
New Variant of QakBot Being Spread by HTML File Attached to Phishing Emails
FortiGuard Labs discovered a phishing campaign spreading a new variant of the information stealer and banking Trojan QakBot. Read our blog to learn how the QakBot variant operates. …
#ParsedReport
20-07-2022
Black Basta Ransomware Victim Knauf Forced to Stop Their Services
https://socradar.io/black-basta-ransomware-victim-knauf-forced-to-stop-their-services
Threats:
Blackbasta
Conti
Qakbot
Filecoder
Trojan.win32.delshad.gen
Sabsik
Geo:
India, Australia, Canada
IOCs:
Domain: 1
Hash: 10
File: 1
IP: 20
Softs:
esxi, windows defender
20-07-2022
Black Basta Ransomware Victim Knauf Forced to Stop Their Services
https://socradar.io/black-basta-ransomware-victim-knauf-forced-to-stop-their-services
Threats:
Blackbasta
Conti
Qakbot
Filecoder
Trojan.win32.delshad.gen
Sabsik
Geo:
India, Australia, Canada
IOCs:
Domain: 1
Hash: 10
File: 1
IP: 20
Softs:
esxi, windows defender
SOCRadar® Cyber Intelligence Inc.
Black Basta Ransomware Victim Knauf Forced to Stop Their Services - SOCRadar® Cyber Intelligence Inc.
#ParsedReport
20-07-2022
ISO IcedID. ICEDID distribution through ISO file
https://asec.ahnlab.com/ko/36776
Threats:
Icedid
Bumblebee
Emotet
Dridex
Trojan/win.generic.r503676
Industry:
Financial
IOCs:
File: 12
Path: 2
Url: 2
Hash: 4
20-07-2022
ISO IcedID. ICEDID distribution through ISO file
https://asec.ahnlab.com/ko/36776
Threats:
Icedid
Bumblebee
Emotet
Dridex
Trojan/win.generic.r503676
Industry:
Financial
IOCs:
File: 12
Path: 2
Url: 2
Hash: 4
ASEC BLOG
ISO 파일을 통해 IcedID 유포 중 - ASEC BLOG
ASEC 분석팀은 ISO 파일을 통해 다양한 악성코드가 유포되고 있는 사례를 소개해왔다. 최근에는 ISO 파일을 통해 모듈형 뱅킹 악성코드인 IcedID 가 유포 중인 것을 확인하였다. 확인된 유형은 2가지로, 하나는 이전에 소개했던 Bumblebee 악성코드와 동일한 방식을 이용하였다. 나머지 유형 또한 비슷한 방식을 사용했지만, 스크립트 파일과 cmd 명령어가 추가된 형태이다. 먼저, 첫번째 유형은 IcedID 가 실행되는 과정 및 유포되는 과정이…
#ParsedReport
20-07-2022
Analyzing Penetration-Testing Tools That Threat Actors Use to Breach Systems and Steal Data
https://www.trendmicro.com/en_us/research/22/g/analyzing-penetration-testing-tools-that-threat-actors-use-to-br.html
Threats:
Pchunter_tool
Psexec_tool
Minidump_tool
Megasync_tool
IOCs:
Path: 6
File: 6
Url: 1
Softs:
microsoft exchange, unix, mssql, active directory, curl
Links:
20-07-2022
Analyzing Penetration-Testing Tools That Threat Actors Use to Breach Systems and Steal Data
https://www.trendmicro.com/en_us/research/22/g/analyzing-penetration-testing-tools-that-threat-actors-use-to-br.html
Threats:
Pchunter_tool
Psexec_tool
Minidump_tool
Megasync_tool
IOCs:
Path: 6
File: 6
Url: 1
Softs:
microsoft exchange, unix, mssql, active directory, curl
Links:
https://github.com/lgandx/ResponderTrend Micro
Analyzing Penetration-Testing Tools That Threat Actors Use to Breach Systems and Steal Data
We discovered the use of two Python penetration-testing tools, Impacket and Responder, that malicious actors used to compromise systems and exfiltrate data. We share our key findings in this report.
#ParsedReport
20-07-2022
Luna and Black Basta new ransomware for Windows, Linux and ESXi
https://securelist.com/luna-black-basta-ransomware/106950
Actors/Campaigns:
Blackcat
Threats:
Blackbasta
Luna
Conti
Geo:
Russian, Asia
IOCs:
Path: 2
Softs:
esxi
Algorithms:
chacha20, curve25519, aes
20-07-2022
Luna and Black Basta new ransomware for Windows, Linux and ESXi
https://securelist.com/luna-black-basta-ransomware/106950
Actors/Campaigns:
Blackcat
Threats:
Blackbasta
Luna
Conti
Geo:
Russian, Asia
IOCs:
Path: 2
Softs:
esxi
Algorithms:
chacha20, curve25519, aes
Securelist
Kaspersky report on Luna and Black Basta ransomware
This report discusses new ransomware, that targets Windows, Linux and ESXi systems: Luna written in Rust and Black Basta.
#ParsedReport
20-07-2022
LockBit: Ransomware Puts Servers in the Crosshairs
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/lockbit-targets-servers
Threats:
Lockbit
Uacme
Conti
Lockdown
Geo:
Russia
TTPs:
Tactics: 3
Technics: 0
IOCs:
File: 9
Path: 2
Hash: 1
Url: 1
Softs:
windows defender, anydesk, active directory, wordpad, process explorer, msexchange, vssadmin
Functions:
DuplicateTokenEx, CreateProcessAsUserW, GetSystemDefaultUILanguage, GetUserDefaultUILanguage
20-07-2022
LockBit: Ransomware Puts Servers in the Crosshairs
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/lockbit-targets-servers
Threats:
Lockbit
Uacme
Conti
Lockdown
Geo:
Russia
TTPs:
Tactics: 3
Technics: 0
IOCs:
File: 9
Path: 2
Hash: 1
Url: 1
Softs:
windows defender, anydesk, active directory, wordpad, process explorer, msexchange, vssadmin
Functions:
DuplicateTokenEx, CreateProcessAsUserW, GetSystemDefaultUILanguage, GetUserDefaultUILanguage
#ParsedReport
20-07-2022
Google ads lead to major malvertising campaign
https://blog.malwarebytes.com/threat-intelligence/2022/07/google-ads-lead-to-major-malvertising-campaign
IOCs:
Domain: 22
20-07-2022
Google ads lead to major malvertising campaign
https://blog.malwarebytes.com/threat-intelligence/2022/07/google-ads-lead-to-major-malvertising-campaign
IOCs:
Domain: 22
Malwarebytes
Google ads lead to major malvertising campaign
Fraudsters have long been leveraging the shady corners of the internet to place malicious adverts, leading users to various scams. However,...
#ParsedReport
21-07-2022
Change in Injection Method of Magniber Ransomware
https://asec.ahnlab.com/en/36475
Threats:
Magniber
Process_injection_technique
IOCs:
File: 2
Path: 1
Hash: 2
Softs:
chrome, windows installer
Algorithms:
xor
21-07-2022
Change in Injection Method of Magniber Ransomware
https://asec.ahnlab.com/en/36475
Threats:
Magniber
Process_injection_technique
IOCs:
File: 2
Path: 1
Hash: 2
Softs:
chrome, windows installer
Algorithms:
xor
ASEC BLOG
Change in Injection Method of Magniber Ransomware - ASEC BLOG
The ASEC analysis team is constantly monitoring Magniber, which has a higher number of distribution cases. It has been distributed through the IE (Internet Explorer) vulnerability for the past few years but stopped exploiting the vulnerability after the support…
#ParsedReport
21-07-2022
Malware Being Distributed by Disguising Itself as Icon of V3 Lite
https://asec.ahnlab.com/en/36629
Threats:
Avemaria_rat
Agent_tesla
Lokibot_stealer
Formbook
Remcos_rat
Trojan/win.msilkrypt.r495355
Trojan/win.msilkrypt.r498085
Trojan/win.msil.c5152589
Trojan/win.msil.r500015
Trojan/win.msil.c515258
Tnega
Geo:
Korea
IOCs:
File: 4
Hash: 3
IP: 1
Url: 2
21-07-2022
Malware Being Distributed by Disguising Itself as Icon of V3 Lite
https://asec.ahnlab.com/en/36629
Threats:
Avemaria_rat
Agent_tesla
Lokibot_stealer
Formbook
Remcos_rat
Trojan/win.msilkrypt.r495355
Trojan/win.msilkrypt.r498085
Trojan/win.msil.c5152589
Trojan/win.msil.r500015
Trojan/win.msil.c515258
Tnega
Geo:
Korea
IOCs:
File: 4
Hash: 3
IP: 1
Url: 2
ASEC BLOG
Malware Being Distributed by Disguising Itself as Icon of V3 Lite - ASEC BLOG
The ASEC analysis team has discovered the distribution of malware disguised as a V3 Lite icon and packed with the .NET packer. The attacker likely created an icon that is almost identical to that of V3 Lite to trick the user, and AveMaria RAT and AgentTesla…
#ParsedReport
21-07-2022
Amadey Bot Being Distributed Through SmokeLoader
https://asec.ahnlab.com/en/36634
Actors/Campaigns:
Ta505
Threats:
Amadey
Smokeloader
Gandcrab
Flawedammyy
Clop
Fallout_ek_tool
Rig_tool
Redline_stealer
Tightvnc_tool
Uac_bypass_technique
Dll_hijacking_technique
Trojan/win.malpe.r503126
Delf
Trojan/win.generic.r503640
Malware/win.trojanspy.r438708
Malware/mdp.download.m1197
IOCs:
File: 15
Path: 7
Registry: 1
Url: 15
Hash: 10
IP: 1
Softs:
realvnc, total commander, task scheduler, windows defender, winscp, tigervnc
Languages:
delphi, rust, autoit
21-07-2022
Amadey Bot Being Distributed Through SmokeLoader
https://asec.ahnlab.com/en/36634
Actors/Campaigns:
Ta505
Threats:
Amadey
Smokeloader
Gandcrab
Flawedammyy
Clop
Fallout_ek_tool
Rig_tool
Redline_stealer
Tightvnc_tool
Uac_bypass_technique
Dll_hijacking_technique
Trojan/win.malpe.r503126
Delf
Trojan/win.generic.r503640
Malware/win.trojanspy.r438708
Malware/mdp.download.m1197
IOCs:
File: 15
Path: 7
Registry: 1
Url: 15
Hash: 10
IP: 1
Softs:
realvnc, total commander, task scheduler, windows defender, winscp, tigervnc
Languages:
delphi, rust, autoit
ASEC
Amadey Bot Being Distributed Through SmokeLoader - ASEC
Amadey Bot Being Distributed Through SmokeLoader ASEC
#ParsedReport
21-07-2022
Lightning Framework: New Undetected Swiss Army Knife Linux Malware
https://www.intezer.com/blog/research/lightning-framework-new-linux-threat
Threats:
Lightning_tool
Jigsaw
Netstat_tool
Timestomp_technique
TTPs:
Tactics: 4
Technics: 17
IOCs:
File: 7
IP: 1
Hash: 3
Algorithms:
xor
Functions:
GetRemotePathInfo, CloseShellPure, GetDomainSetting, OpenSSH, DeleteGuid, RemoveKernelHide, DeleteVecFile, SetDomainSetting
Links:
21-07-2022
Lightning Framework: New Undetected Swiss Army Knife Linux Malware
https://www.intezer.com/blog/research/lightning-framework-new-linux-threat
Threats:
Lightning_tool
Jigsaw
Netstat_tool
Timestomp_technique
TTPs:
Tactics: 4
Technics: 17
IOCs:
File: 7
IP: 1
Hash: 3
Algorithms:
xor
Functions:
GetRemotePathInfo, CloseShellPure, GetDomainSetting, OpenSSH, DeleteGuid, RemoveKernelHide, DeleteVecFile, SetDomainSetting
Links:
https://github.com/raboof/nethogsIntezer
Lightning Framework: New “Swiss Army Knife” Linux Malware
A new Linux malware we're calling Lightning Framework has modular plugins and the ability to install multiple types of rootkits.
#ParsedReport
21-07-2022
ASEC Weekly Malware Statistics (July 4th, 2022 July 10th, 2022)
https://asec.ahnlab.com/en/36586
Threats:
Agent_tesla
Cloudeye
Formbook
Remcos_rat
Nanocore_rat
Clipboard_grabbing_technique
Redline_stealer
Beamwinhttp_loader
Industry:
Financial
IOCs:
Domain: 4
IP: 4
Email: 4
File: 20
Url: 39
Softs:
discord, nsis installer
Languages:
visual_basic
21-07-2022
ASEC Weekly Malware Statistics (July 4th, 2022 July 10th, 2022)
https://asec.ahnlab.com/en/36586
Threats:
Agent_tesla
Cloudeye
Formbook
Remcos_rat
Nanocore_rat
Clipboard_grabbing_technique
Redline_stealer
Beamwinhttp_loader
Industry:
Financial
IOCs:
Domain: 4
IP: 4
Email: 4
File: 20
Url: 39
Softs:
discord, nsis installer
Languages:
visual_basic
ASEC BLOG
ASEC Weekly Malware Statistics (July 4th, 2022 - July 10th, 2022) - ASEC BLOG
The ASEC analysis team is using the ASEC automatic analysis system RAPIT to categorize and respond to known malware. This post will list weekly statistics collected from July 4th, 2022 (Monday) to July 10th, 2022 (Sunday). For the main category, info-stealer…
#ParsedReport
21-07-2022
eSentire Threat Intelligence Malware Analysis: Gootloader and IcedID
https://www.esentire.com/blog/esentire-threat-intelligence-malware-analysis-gootloader-and-icedid
Actors/Campaigns:
Xinglocker
Threats:
Gootloader
Icedid
Cobalt_strike
Process_hollowing_technique
Pingpull
Antidebugging_technique
Sandbox_evasion_technique
Conti
Quantum_locker
Quantum_tool
Industry:
Financial
Geo:
Apac, America, Africa, Emea
IOCs:
Registry: 6
Domain: 1
File: 2
Hash: 4
Softs:
active directory
Algorithms:
exhibit
Functions:
Foad, WriteProcessMemory, GetTickCount, GetComputerNameExW, GetUserNameW, Test, GetAdaptersInfo
Languages:
java, php
YARA: Found
21-07-2022
eSentire Threat Intelligence Malware Analysis: Gootloader and IcedID
https://www.esentire.com/blog/esentire-threat-intelligence-malware-analysis-gootloader-and-icedid
Actors/Campaigns:
Xinglocker
Threats:
Gootloader
Icedid
Cobalt_strike
Process_hollowing_technique
Pingpull
Antidebugging_technique
Sandbox_evasion_technique
Conti
Quantum_locker
Quantum_tool
Industry:
Financial
Geo:
Apac, America, Africa, Emea
IOCs:
Registry: 6
Domain: 1
File: 2
Hash: 4
Softs:
active directory
Algorithms:
exhibit
Functions:
Foad, WriteProcessMemory, GetTickCount, GetComputerNameExW, GetUserNameW, Test, GetAdaptersInfo
Languages:
java, php
YARA: Found
eSentire
eSentire Threat Intelligence Malware Analysis: Gootloader and IcedID
Dive deeper into the technical details gathered during eSentire’s Threat Response Unit (TRU) team’s research and threat analysis of the Gootloader malware and IcedID payload.
#ParsedReport
21-07-2022
LockBit 3.0 Update \| Unpicking the Ransomwares Latest Anti-Analysis and Evasion Techniques
https://www.sentinelone.com/labs/lockbit-3-0-update-unpicking-the-ransomwares-latest-anti-analysis-and-evasion-techniques
Actors/Campaigns:
Blackmatter
Threats:
Lockbit
Cobalt_strike
Socgholish_loader
Uac_bypass_technique
Blackcat
Egregor
Antidebugging_technique
Conti
Process_injection_technique
Industry:
Financial
Geo:
Russian, Ukraine
TTPs:
IOCs:
Hash: 6
Domain: 19
Softs:
thebat, powerpnt, steam, encsvc, dbsnmp, windows service, onenote, msexchange, zcash, wordpad
Algorithms:
xor, exhibit
Functions:
NtSetInformationThread
21-07-2022
LockBit 3.0 Update \| Unpicking the Ransomwares Latest Anti-Analysis and Evasion Techniques
https://www.sentinelone.com/labs/lockbit-3-0-update-unpicking-the-ransomwares-latest-anti-analysis-and-evasion-techniques
Actors/Campaigns:
Blackmatter
Threats:
Lockbit
Cobalt_strike
Socgholish_loader
Uac_bypass_technique
Blackcat
Egregor
Antidebugging_technique
Conti
Process_injection_technique
Industry:
Financial
Geo:
Russian, Ukraine
TTPs:
IOCs:
Hash: 6
Domain: 19
Softs:
thebat, powerpnt, steam, encsvc, dbsnmp, windows service, onenote, msexchange, zcash, wordpad
Algorithms:
xor, exhibit
Functions:
NtSetInformationThread
SentinelOne
LockBit 3.0 Update | Unpicking the Ransomware's Latest Anti-Analysis and Evasion Techniques
The self-proclaimed 'oldest ransomware affiliate on the planet' has new tricks and new features and continues to beat enterprise defenses.
#ParsedReport
21-07-2022
Buy, Sell, Steal, EvilNum Targets Cryptocurrency, Forex, Commodities
https://www.proofpoint.com/us/blog/threat-insight/buy-sell-steal-evilnum-targets-cryptocurrency-forex-commodities
Actors/Campaigns:
Evilnum (motivation: information_theft)
Venom_spider
Industry:
Financial
IOCs:
Domain: 8
File: 7
Url: 11
Path: 1
Hash: 5
Email: 5
Softs:
windows defender, microsoft word
Languages:
java
21-07-2022
Buy, Sell, Steal, EvilNum Targets Cryptocurrency, Forex, Commodities
https://www.proofpoint.com/us/blog/threat-insight/buy-sell-steal-evilnum-targets-cryptocurrency-forex-commodities
Actors/Campaigns:
Evilnum (motivation: information_theft)
Venom_spider
Industry:
Financial
IOCs:
Domain: 8
File: 7
Url: 11
Path: 1
Hash: 5
Email: 5
Softs:
windows defender, microsoft word
Languages:
java
Proofpoint
Buy, Sell, Steal, EvilNum Targets Cryptocurrency, Forex, Commodities | Proofpoint US
Key Findings TA4563 is a threat actor leveraging EvilNum malware to target European financial and investment entities, especially those with operations supporting foreign exchanges,