CTT Report Hub
3.43K subscribers
9.91K photos
6 videos
67 files
13.6K links
Threat Intelligence Report Hub
Download Telegram
#ParsedReport
20-07-2022

Redeemer Ransomware back Action

https://blog.cyble.com/2022/07/20/redeemer-ransomware-back-action

Threats:
Redeemer

Industry:
Financial

TTPs:
Tactics: 5
Technics: 10

IOCs:
File: 8
Path: 3
Hash: 4

Softs:
telegram, vssadmin, bootnxt, winlogon

Functions:
OpenSSL, FindNextFileW, ShellExecuteW, FindFirstFileW
#ParsedReport
20-07-2022

Atlas Intelligence Group (A.I.G) The Wrath of a Titan

https://cyberint.com/blog/research/atlas-intelligence-group

Actors/Campaigns:
Atlantis_cyberarmy
Ddosarmy

Industry:
Education, Government, Financial, E-commerce

Geo:
Pakistan, Israel, Colombia, Emirates, German, Germany

TTPs:
Tactics: 1
Technics: 0

IOCs:
File: 3

Softs:
telegram
#ParsedReport
20-07-2022

New Variant of QakBot Being Spread by HTML File Attached to Phishing Emails

https://www.fortinet.com/blog/threat-research/new-variant-of-qakbot-spread-by-phishing-emails

Threats:
Qakbot
Procmon_tool
Netstat_tool

Industry:
Financial

IOCs:
File: 43
Path: 1
Hash: 3
IP: 243

Softs:
unix, microsoft defender, curl, microsoft edge

Algorithms:
base64, xor, rc4

Functions:
NetGetJoinInformation, GetVersionEx, LookupAccountSidW, WriteProcessMemory, GetSystemMetrics, CreateThread, built-in, GetComputerNameW, FindResourceW, CreateProcessW, API, GetModuleFileNameW, ResumeThread, GetSystemInfo, encryption, CreatProcessW
#ParsedReport
20-07-2022

Black Basta Ransomware Victim Knauf Forced to Stop Their Services

https://socradar.io/black-basta-ransomware-victim-knauf-forced-to-stop-their-services

Threats:
Blackbasta
Conti
Qakbot
Filecoder
Trojan.win32.delshad.gen
Sabsik

Geo:
India, Australia, Canada

IOCs:
Domain: 1
Hash: 10
File: 1
IP: 20

Softs:
esxi, windows defender
#ParsedReport
20-07-2022

Luna and Black Basta new ransomware for Windows, Linux and ESXi

https://securelist.com/luna-black-basta-ransomware/106950

Actors/Campaigns:
Blackcat

Threats:
Blackbasta
Luna
Conti

Geo:
Russian, Asia

IOCs:
Path: 2

Softs:
esxi

Algorithms:
chacha20, curve25519, aes
#ParsedReport
20-07-2022

LockBit: Ransomware Puts Servers in the Crosshairs

https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/lockbit-targets-servers

Threats:
Lockbit
Uacme
Conti
Lockdown

Geo:
Russia

TTPs:
Tactics: 3
Technics: 0

IOCs:
File: 9
Path: 2
Hash: 1
Url: 1

Softs:
windows defender, anydesk, active directory, wordpad, process explorer, msexchange, vssadmin

Functions:
DuplicateTokenEx, CreateProcessAsUserW, GetSystemDefaultUILanguage, GetUserDefaultUILanguage
#ParsedReport
21-07-2022

Malware Being Distributed by Disguising Itself as Icon of V3 Lite

https://asec.ahnlab.com/en/36629

Threats:
Avemaria_rat
Agent_tesla
Lokibot_stealer
Formbook
Remcos_rat
Trojan/win.msilkrypt.r495355
Trojan/win.msilkrypt.r498085
Trojan/win.msil.c5152589
Trojan/win.msil.r500015
Trojan/win.msil.c515258
Tnega

Geo:
Korea

IOCs:
File: 4
Hash: 3
IP: 1
Url: 2
#ParsedReport
21-07-2022

Amadey Bot Being Distributed Through SmokeLoader

https://asec.ahnlab.com/en/36634

Actors/Campaigns:
Ta505

Threats:
Amadey
Smokeloader
Gandcrab
Flawedammyy
Clop
Fallout_ek_tool
Rig_tool
Redline_stealer
Tightvnc_tool
Uac_bypass_technique
Dll_hijacking_technique
Trojan/win.malpe.r503126
Delf
Trojan/win.generic.r503640
Malware/win.trojanspy.r438708
Malware/mdp.download.m1197

IOCs:
File: 15
Path: 7
Registry: 1
Url: 15
Hash: 10
IP: 1

Softs:
realvnc, total commander, task scheduler, windows defender, winscp, tigervnc

Languages:
delphi, rust, autoit
#ParsedReport
21-07-2022

Lightning Framework: New Undetected Swiss Army Knife Linux Malware

https://www.intezer.com/blog/research/lightning-framework-new-linux-threat

Threats:
Lightning_tool
Jigsaw
Netstat_tool
Timestomp_technique

TTPs:
Tactics: 4
Technics: 17

IOCs:
File: 7
IP: 1
Hash: 3

Algorithms:
xor

Functions:
GetRemotePathInfo, CloseShellPure, GetDomainSetting, OpenSSH, DeleteGuid, RemoveKernelHide, DeleteVecFile, SetDomainSetting

Links:
https://github.com/raboof/nethogs
#ParsedReport
21-07-2022

ASEC Weekly Malware Statistics (July 4th, 2022 July 10th, 2022)

https://asec.ahnlab.com/en/36586

Threats:
Agent_tesla
Cloudeye
Formbook
Remcos_rat
Nanocore_rat
Clipboard_grabbing_technique
Redline_stealer
Beamwinhttp_loader

Industry:
Financial

IOCs:
Domain: 4
IP: 4
Email: 4
File: 20
Url: 39

Softs:
discord, nsis installer

Languages:
visual_basic
#ParsedReport
21-07-2022

eSentire Threat Intelligence Malware Analysis: Gootloader and IcedID

https://www.esentire.com/blog/esentire-threat-intelligence-malware-analysis-gootloader-and-icedid

Actors/Campaigns:
Xinglocker

Threats:
Gootloader
Icedid
Cobalt_strike
Process_hollowing_technique
Pingpull
Antidebugging_technique
Sandbox_evasion_technique
Conti
Quantum_locker
Quantum_tool

Industry:
Financial

Geo:
Apac, America, Africa, Emea

IOCs:
Registry: 6
Domain: 1
File: 2
Hash: 4

Softs:
active directory

Algorithms:
exhibit

Functions:
Foad, WriteProcessMemory, GetTickCount, GetComputerNameExW, GetUserNameW, Test, GetAdaptersInfo

Languages:
java, php

YARA: Found
#ParsedReport
21-07-2022

LockBit 3.0 Update \| Unpicking the Ransomwares Latest Anti-Analysis and Evasion Techniques

https://www.sentinelone.com/labs/lockbit-3-0-update-unpicking-the-ransomwares-latest-anti-analysis-and-evasion-techniques

Actors/Campaigns:
Blackmatter

Threats:
Lockbit
Cobalt_strike
Socgholish_loader
Uac_bypass_technique
Blackcat
Egregor
Antidebugging_technique
Conti
Process_injection_technique

Industry:
Financial

Geo:
Russian, Ukraine

TTPs:

IOCs:
Hash: 6
Domain: 19

Softs:
thebat, powerpnt, steam, encsvc, dbsnmp, windows service, onenote, msexchange, zcash, wordpad

Algorithms:
xor, exhibit

Functions:
NtSetInformationThread
#ParsedReport
21-07-2022

Buy, Sell, Steal, EvilNum Targets Cryptocurrency, Forex, Commodities

https://www.proofpoint.com/us/blog/threat-insight/buy-sell-steal-evilnum-targets-cryptocurrency-forex-commodities

Actors/Campaigns:
Evilnum (motivation: information_theft)
Venom_spider

Industry:
Financial

IOCs:
Domain: 8
File: 7
Url: 11
Path: 1
Hash: 5
Email: 5

Softs:
windows defender, microsoft word

Languages:
java
#ParsedReport
21-07-2022

Attackers target Ukraine using GoMet backdoor

http://blog.talosintelligence.com/2022/07/attackers-target-ukraine-using-gomet.html

Threats:
Gomet_dropper

Industry:
Government

Geo:
Ukrainian, Ukraine, Russian, Ukrainians

CVEs:
CVE-2020-5902 [Vulners]
Vulners: Score: 10.0, CVSS: 4.6,
Vulners: Exploitation: True
X-Force: Risk: 10
X-Force: Patch: Official fix
Soft:
- f5 big-ip access policy manager (<11.6.5.2, <12.1.5.2, <13.1.3.4, <14.1.2.6, le15.0.1.4, <15.1.0.4)
- f5 big-ip advanced firewall manager (<11.6.5.2, <12.1.5.2, <13.1.3.4, <14.1.2.6, <15.0.1.4, <15.1.0.4)
- f5 big-ip advanced web application firewall (<11.6.5.2, <12.1.5.2, <13.1.3.4, <14.1.2.6, <15.0.1.4, <15.1.0.4)
- f5 big-ip analytics (<11.6.5.2, <12.1.5.2, <13.1.3.4, <14.1.2.6, <15.0.1.4, <15.1.0.4)
- f5 big-ip application acceleration manager (<11.6.5.2, <12.1.5.2, <13.1.3.4, <14.1.2.6, <15.0.1.4, <15.1.0.4)
have more...
CVE-2022-1040 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- sophos sfos (le18.5.3)


IOCs:
File: 6
Hash: 3
Path: 1
IP: 1

Softs:
task scheduler

Links:
https://github.com/Laeeth/GoMet
#ParsedReport
21-07-2022

The Return of Candiru: Zero-days in the Middle East

https://decoded.avast.io/janvojtesek/the-return-of-candiru-zero-days-in-the-middle-east/?utm_source=rss&utm_medium=rss&utm_campaign=the-return-of-candiru-zero-days-in-the-middle-east

Threats:
Watering_hole_technique
Devilstongue

Geo:
Palestine, Yemen, Lebanon, Turkey

CVEs:
CVE-2022-2294 [Vulners]
Vulners: Score: Unknown, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 8.8
X-Force: Patch: Official fix


IOCs:
Domain: 11
Path: 30
Registry: 4

Softs:
google chrome, chrome, chromium

Algorithms:
rsa-2048, aes-256-cbc

Languages:
java, Javascript

Links:
https://github.com/avast/ioc/tree/master/Candiru