CTT Report Hub
3.43K subscribers
9.9K photos
6 videos
67 files
13.5K links
Threat Intelligence Report Hub
Download Telegram
#ParsedReport
21-07-2022

Brazen, Unsophisticated and Illogical: Understanding the LAPSUS$ Extortion Group

https://www.tenable.com/blog/brazen-unsophisticated-and-illogical-understanding-the-lapsus-extortion-group

Actors/Campaigns:
Lapsus (motivation: information_theft, script_kiddie, politically_motivated, cyber_criminal)
Karakurt (motivation: information_theft)
Ransomhouse

Threats:
Conti
Empire_loader
Godfather
Silence
Avoslocker
Lockbit

Industry:
Telco, Financial, Media, Healthcare, Government

Geo:
America, Brazil, Portugal

IOCs:
File: 2

Softs:
tiktok, confluence, telegram, active directory, microsoft sharepoint
Попробовал повысить качество вытаскивания функций WIN API из отчетов. Посмотрим что получится )))
#ParsedReport
22-07-2022

The Return of Candiru: Zero-days in the Middle East

https://decoded.avast.io/janvojtesek/the-return-of-candiru-zero-days-in-the-middle-east

Threats:
Watering_hole_technique
Devilstongue

Geo:
Lebanon, Yemen, Turkey, Palestine

CVEs:
CVE-2022-2294 [Vulners]
Vulners: Score: Unknown, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 8.8
X-Force: Patch: Official fix


IOCs:
Domain: 11
Path: 30
Registry: 4

Softs:
chrome, chromium, google chrome

Algorithms:
aes-256-cbc, rsa-2048

Languages:
javascript

Platforms:
apple

Links:
https://github.com/avast/ioc/tree/master/Candiru
#ParsedReport
22-07-2022

OperationShadowTiger

https://mp.weixin.qq.com/s/jX8D8d-4q46pKHS0AIVgjw

Actors/Campaigns:
Shadowtiger
Tiger_hibiscus

Threats:
Dll_hijacking_technique
Putty_tool
Uacme

Geo:
Korean, Korea, Asia, Asian, Polish

CVEs:
CVE-2018-6055 [Vulners]
Vulners: Score: 6.8, CVSS: 4.9,
Vulners: Exploitation: Unknown
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- google chrome (<64.0.3282.119)


TTPs:
Tactics: 2
Technics: 0

IOCs:
File: 19
Url: 3
Email: 2
IP: 5
Hash: 16

Softs:
chrome

Languages:
php
#ParsedReport
22-07-2022

Proxyware. Attackers who make money using ProxyWare

https://asec.ahnlab.com/ko/36762

Threats:
Dropper/win.proxyware.c5173477
Dropper/win.proxyware.c5173478
Dropper/win.proxyware.c5210584

IOCs:
File: 8
Path: 1
Hash: 7

Softs:
ms-sql

Algorithms:
base64

Functions:
startMainRoutine

Platforms:
x86
#ParsedReport
22-07-2022

Alibaba OSS Buckets Compromised to Distribute Malicious Shell Scripts via Steganography

https://www.trendmicro.com/en_us/research/22/g/alibaba-oss-buckets-compromised-to-distribute-malicious-shell-sc.html

Actors/Campaigns:
Teamtnt

Threats:
Monero_miner
Xmrig_miner
Kinsing_miner

Geo:
Chinese

IOCs:
Domain: 1
Hash: 5

Softs:
unix, redis

Links:
https://github.com/xmrig/xmrig
#ParsedReport
22-07-2022

Qakbot Resurfaces with new Playbook

https://blog.cyble.com/2022/07/21/qakbot-resurfaces-with-new-playbook

Threats:
Qakbot
Brata
Beacon
Process_injection_technique

Industry:
Financial

TTPs:
Tactics: 2
Technics: 4

IOCs:
File: 5
Hash: 5

Softs:
android

Algorithms:
base64
Всем привет.
До 1 августа уходим вместе с движком публикации TI-отчетов в отпуск.
Все индикаторы из отчетов продолжат попадать в наш фид автоматически.
winapi_funcs.yml
564 KB
Постепенно выхожу из стазиса.
Напарсил с https://docs.microsoft.com/en-us/windows/win32/api/ список WIN API.
Методы интерфейсов тоже собрал, но пока решил не выкладывать из-за ненадобности )

Как же я долго не хотел прикручивать HyperScan от Intel к парсеру отчетов, но теперь придется.
Кстати ,вот регулярка, которая тоже помогает выявить название WIN API функции в тексте (^| )((Alpc|Cc|Cm|Dbg|Dbgk|Em|Etw|Ex|FsRtl|Hv|Hvl|Io|Kd|Ke|Kse|Lsa|Mm|Nt|Ob|Pf|Po|PoFx|Pp|Ppm|Ps|Rtl|Se|SH|Sm|Tm|Ttm|Vf|Vsl|Wdi|Wfp|Whea|Wmi|Zw)([A-Z][a-z]+){3,}[A-Z]?)([., ]|$)
#technique

Resource-based Constrained Delegation
https://hackitfaster.hopto.org/rbcd.html
#ParsedReport
31-07-2022

Targeted Attacks being carried out via DLL SideLoading

https://blog.cyble.com/2022/07/27/targeted-attacks-being-carried-out-via-dll-sideloading

Threats:
Cobalt_strike
Beacon
Qakbot
Mimikatz

Geo:
Italy

TTPs:
Tactics: 3
Technics: 5

IOCs:
File: 4
Url: 1
Hash: 2

Softs:
microsoft teams

Algorithms:
base64

Functions:
process, EnableContent, GetParagraph, AutoOpen
#ParsedReport
01-08-2022

Heres a Simple Script to Detect the Stealthy Nation-State BPFDoor

https://blog.qualys.com/vulnerabilities-threat-research/2022/08/01/heres-a-simple-script-to-detect-the-stealthy-nation-state-bpfdoor

Threats:
Bpfdoor
Red_menshen
Mangzamel
Gh0st_rat
Metasploit_tool
Timestomp_technique

Industry:
Government, Telco, Education, Logistic

Geo:
Taiwan, Asia, India, Vietnam, Myanmar, Turkey, Chinese, Korea

TTPs:
Tactics: 1
Technics: 7

IOCs:
Hash: 18

Softs:
unix

Functions:
utimes

Languages:
python, perl, lua

YARA: Found