#ParsedReport
01-08-2022
SEARCH. Threat Actor Targets Financial Entities With Evilnum Malware
https://www.proofpoint.com/us/newsroom/news/threat-actor-targets-financial-entities-evilnum-malware
Actors/Campaigns:
Evilnum (motivation: information_theft)
Ta4563
Venom_spider
Industry:
Financial
IOCs:
File: 3
Softs:
windows defender, microsoft word
01-08-2022
SEARCH. Threat Actor Targets Financial Entities With Evilnum Malware
https://www.proofpoint.com/us/newsroom/news/threat-actor-targets-financial-entities-evilnum-malware
Actors/Campaigns:
Evilnum (motivation: information_theft)
Ta4563
Venom_spider
Industry:
Financial
IOCs:
File: 3
Softs:
windows defender, microsoft word
Decipher
Threat Actor Targets Financial Entities With Evilnum Malware
The threat actor has been observed targeting companies with operations supporting foreign exchanges and cryptocurrency, and organizations in the Decentralized Finance (DeFi) industry.
#ParsedReport
31-07-2022
CUBA Ransomware Campaign Analysis. Key Takeaways
https://www.elastic.co/security-labs/cuba-ransomware-campaign-analysis
Actors/Campaigns:
Unc2596
Threats:
Cuba
Seth_locker
Credential_harvesting_technique
Process_injection_technique
Meterpreter_tool
Mimikatz
Cobalt_strike
Bughatch
Systembc
Proxylogon_exploit
Proxyshell_vuln
Bazarbackdoor
Metasploit_tool
Netsupportmanager_rat
Gotoassist_tool
Beacon
Mosquito
Zerologon_vuln
Psexec_tool
Lolbas_technique
Industry:
Financial, Retail
Geo:
Polish, American
TTPs:
Tactics: 9
Technics: 0
IOCs:
File: 15
IP: 21
Domain: 2
Url: 3
Path: 7
Hash: 14
Softs:
microsoft defender, sysinternals, mysql
YARA: Found
Links:
31-07-2022
CUBA Ransomware Campaign Analysis. Key Takeaways
https://www.elastic.co/security-labs/cuba-ransomware-campaign-analysis
Actors/Campaigns:
Unc2596
Threats:
Cuba
Seth_locker
Credential_harvesting_technique
Process_injection_technique
Meterpreter_tool
Mimikatz
Cobalt_strike
Bughatch
Systembc
Proxylogon_exploit
Proxyshell_vuln
Bazarbackdoor
Metasploit_tool
Netsupportmanager_rat
Gotoassist_tool
Beacon
Mosquito
Zerologon_vuln
Psexec_tool
Lolbas_technique
Industry:
Financial, Retail
Geo:
Polish, American
TTPs:
Tactics: 9
Technics: 0
IOCs:
File: 15
IP: 21
Domain: 2
Url: 3
Path: 7
Hash: 14
Softs:
microsoft defender, sysinternals, mysql
YARA: Found
Links:
https://github.com/rapid7/metasploit-frameworkwww.elastic.co
CUBA Ransomware Campaign Analysis — Elastic Security Labs
Elastic Security observed a ransomware and extortion campaign leveraging a combination of offensive security tools, LOLBAS, and exploits to deliver the CUBA ransomware malware.
#ParsedReport
31-07-2022
QBOT Configuration Extractor. Getting Started
https://www.elastic.co/security-labs/qbot-configuration-extractor
Threats:
Qakbot
Seth_locker
Bpfdoor
IOCs:
File: 1
Softs:
docker
Languages:
python
31-07-2022
QBOT Configuration Extractor. Getting Started
https://www.elastic.co/security-labs/qbot-configuration-extractor
Threats:
Qakbot
Seth_locker
Bpfdoor
IOCs:
File: 1
Softs:
docker
Languages:
python
www.elastic.co
QBOT Configuration Extractor — Elastic Security Labs
Python script to extract the configuration from QBOT samples.
35939836.pdf
9.2 MB
Документ от 2021г.
A review of threat modelling approaches for APT-style attacks
A review of threat modelling approaches for APT-style attacks
#technique
NimicStack is the pure Nim implementation of Call Stack Spoofing technique to mimic legitimate programs. Whole project is based on the PoC shared by WithSecure Labs
https://github.com/frkngksl/NimicStack
NimicStack is the pure Nim implementation of Call Stack Spoofing technique to mimic legitimate programs. Whole project is based on the PoC shared by WithSecure Labs
https://github.com/frkngksl/NimicStack
GitHub
GitHub - frkngksl/NimicStack: NimicStack is the pure Nim implementation of Call Stack Spoofing technique to mimic legitimate programs
NimicStack is the pure Nim implementation of Call Stack Spoofing technique to mimic legitimate programs - frkngksl/NimicStack
#technique
A PoC implementation for an evasion technique to terminate the current thread and restore it before resuming execution, while implementing page protection changes during no execution.
https://github.com/janoglezcampos/DeathSleep
A PoC implementation for an evasion technique to terminate the current thread and restore it before resuming execution, while implementing page protection changes during no execution.
https://github.com/janoglezcampos/DeathSleep
GitHub
GitHub - janoglezcampos/DeathSleep: A PoC implementation for an evasion technique to terminate the current thread and restore it…
A PoC implementation for an evasion technique to terminate the current thread and restore it before resuming execution, while implementing page protection changes during no execution. - janoglezcam...
#ParsedReport
02-08-2022
Word File Provided as External Link When Replying to Attackers Email (Kimsuky)
https://asec.ahnlab.com/en/37396
Actors/Campaigns:
Kimsuky
Geo:
Korea, Korean, American
IOCs:
File: 5
Url: 3
Path: 1
Hash: 2
02-08-2022
Word File Provided as External Link When Replying to Attackers Email (Kimsuky)
https://asec.ahnlab.com/en/37396
Actors/Campaigns:
Kimsuky
Geo:
Korea, Korean, American
IOCs:
File: 5
Url: 3
Path: 1
Hash: 2
ASEC BLOG
Word File Provided as External Link When Replying to Attacker's Email (Kimsuky) - ASEC BLOG
The ASEC analysis team has discovered the continuous distribution of malicious Word files with North Korea-related materials. The types of discovered Word files included the one discussed in the “Overall Organizational Analysis Report of 2021 Kimsuky Attack…
#ParsedReport
02-08-2022
Malicious CHM Being Distributed to Korean Universities
https://asec.ahnlab.com/en/37391
Threats:
Dll_hijacking_technique
Revbshell
Powershell_shell_tool
Trojan/vbs.generic
Industry:
Education
Geo:
Korean, Korea
IOCs:
File: 5
Hash: 3
Domain: 1
02-08-2022
Malicious CHM Being Distributed to Korean Universities
https://asec.ahnlab.com/en/37391
Threats:
Dll_hijacking_technique
Revbshell
Powershell_shell_tool
Trojan/vbs.generic
Industry:
Education
Geo:
Korean, Korea
IOCs:
File: 5
Hash: 3
Domain: 1
ASEC BLOG
Malicious CHM Being Distributed to Korean Universities - ASEC BLOG
The ASEC analysis team discovered that a malicious CHM file targeting certain Korean universities is distributed on a massive scale. The file that is being distributed is the same type as the one discussed in a post uploaded in May. Figure 1 shows the code…
#ParsedReport
02-08-2022
Banking Trojans Distributed on Google Play Store in DawDropper Campaign
https://socradar.io/banking-trojans-distributed-on-google-play-store-in-dawdropper-campaign
Actors/Campaigns:
Dawdropper
Killnet
Threats:
Octo
Hydra
Anatsa
Ermac
Industry:
Financial
IOCs:
Domain: 13
Url: 25
File: 1
Hash: 22
Softs:
confluence
02-08-2022
Banking Trojans Distributed on Google Play Store in DawDropper Campaign
https://socradar.io/banking-trojans-distributed-on-google-play-store-in-dawdropper-campaign
Actors/Campaigns:
Dawdropper
Killnet
Threats:
Octo
Hydra
Anatsa
Ermac
Industry:
Financial
IOCs:
Domain: 13
Url: 25
File: 1
Hash: 22
Softs:
confluence
SOCRadar® Cyber Intelligence Inc.
Banking Trojans Distributed on Google Play Store in DawDropper Campaign - SOCRadar
According to research by Trend Micro, software called DawDropper impersonates trusted apps to gain access to victims' mobile devices.
#ParsedReport
02-08-2022
Large-Scale AiTM Attack targeting enterprise users of Microsoft email services
https://www.zscaler.com/blogs/security-research/large-scale-aitm-attack-targeting-enterprise-users-microsoft-email-services
Actors/Campaigns:
Bec
Threats:
Aitm_technique
Glitch
Fingerprintjs_tool
Evilginx2_tool
Pinkbot_botnet
Industry:
Financial, Energy
Geo:
Australia
IOCs:
Domain: 646
File: 1
Softs:
virtualbox, active directory
Languages:
javascript
Links:
02-08-2022
Large-Scale AiTM Attack targeting enterprise users of Microsoft email services
https://www.zscaler.com/blogs/security-research/large-scale-aitm-attack-targeting-enterprise-users-microsoft-email-services
Actors/Campaigns:
Bec
Threats:
Aitm_technique
Glitch
Fingerprintjs_tool
Evilginx2_tool
Pinkbot_botnet
Industry:
Financial, Energy
Geo:
Australia
IOCs:
Domain: 646
File: 1
Softs:
virtualbox, active directory
Languages:
javascript
Links:
https://github.com/fingerprintjs/fingerprintjsZscaler
AITM Attack Targeting Microsoft Email Users | Zscaler
A ThreatLabz technical analysis of the latest variant of proxy-based AiTM attacks that are phishing enterprise users for their Microsoft credentials.
#ParsedReport
02-08-2022
SolidBit Ransomware Enters the RaaS Scene and Takes Aim at Gamers and Social Media Users With New Variant
https://www.trendmicro.com/en_us/research/22/h/solidbit-ransomware-enters-the-raas-scene-and-takes-aim-at-gamer.html
Threats:
Solidbit
Lockbit
Yashma
Ransom.win32.solidbitcrypt.thgabbb
Trojan.win32.solidbitcrypt.thgadbb
Trojan.win32.solidbitcrypt.thgahbb
IOCs:
File: 19
Path: 1
Hash: 12
Url: 1
Softs:
instagram, windows defender
Algorithms:
aes, exhibit
Platforms:
intel, x86
02-08-2022
SolidBit Ransomware Enters the RaaS Scene and Takes Aim at Gamers and Social Media Users With New Variant
https://www.trendmicro.com/en_us/research/22/h/solidbit-ransomware-enters-the-raas-scene-and-takes-aim-at-gamer.html
Threats:
Solidbit
Lockbit
Yashma
Ransom.win32.solidbitcrypt.thgabbb
Trojan.win32.solidbitcrypt.thgadbb
Trojan.win32.solidbitcrypt.thgahbb
IOCs:
File: 19
Path: 1
Hash: 12
Url: 1
Softs:
instagram, windows defender
Algorithms:
aes, exhibit
Platforms:
intel, x86
Trend Micro
SolidBit Ransomware Enters the RaaS Scene and Takes Aim at Gamers and Social Media Users With New Variant
This blog entry offers a technical analysis of a new SolidBit variant that is posing as different applications to lure gamers and social media users. The SolidBit ransomware group appears to be planning to expand its operations through these fraudulent apps…
#ParsedReport
02-08-2022
Fake Atomic Wallet Website Distributing Mars Stealer
https://blog.cyble.com/2022/08/02/fake-atomic-wallet-website-distributing-mars-stealer
Threats:
Mars_stealer
Cashback
Beacon
Industry:
Financial, Government
TTPs:
Tactics: 6
Technics: 10
IOCs:
Url: 3
File: 3
Hash: 2
Softs:
atomic wallet, coinbase, android, discord
Algorithms:
zip , gzip, aes
02-08-2022
Fake Atomic Wallet Website Distributing Mars Stealer
https://blog.cyble.com/2022/08/02/fake-atomic-wallet-website-distributing-mars-stealer
Threats:
Mars_stealer
Cashback
Beacon
Industry:
Financial, Government
TTPs:
Tactics: 6
Technics: 10
IOCs:
Url: 3
File: 3
Hash: 2
Softs:
atomic wallet, coinbase, android, discord
Algorithms:
zip , gzip, aes
Cyble
Cyble - Fake Atomic Wallet Website Distributing Mars Stealer
Cyble analyzes a fake Atomic Wallet website that is being used to distribute Mars Stealer to cryptocurrency users.
#ParsedReport
02-08-2022
APTGamaredon
http://blog.nsfocus.net/gamaredon
Actors/Campaigns:
Gamaredon
Industry:
Government, Telco
Geo:
Russian, Ukraine, Russia, Ukrainian
IOCs:
File: 17
Url: 25
Domain: 8
Hash: 70
02-08-2022
APTGamaredon
http://blog.nsfocus.net/gamaredon
Actors/Campaigns:
Gamaredon
Industry:
Government, Telco
Geo:
Russian, Ukraine, Russia, Ukrainian
IOCs:
File: 17
Url: 25
Domain: 8
Hash: 70
#ParsedReport
02-08-2022
Manjusaka: A Chinese sibling of Sliver and Cobalt Strike
https://blog.talosintelligence.com/2022/08/manjusaka-offensive-framework.html
Actors/Campaigns:
Ice_fog
Threats:
Cobalt_strike
Sliver_tool
Beacon
Skeleton_operation
Metasploit_tool
Industry:
Education
Geo:
China, Chinese, Tibetan, Guangdong
IOCs:
Url: 8
File: 2
IP: 1
Path: 2
Domain: 1
Hash: 9
Softs:
opera, google chrome, mysql, microsoft edge, chrome, postgresql, vivaldi, microsoft word
Algorithms:
xor, base64
Functions:
RtlCreateUserThread, CreateRemoteThread, CreateThread, SetThreadContext
Languages:
rust, php, golang
Platforms:
x64, x86
Links:
02-08-2022
Manjusaka: A Chinese sibling of Sliver and Cobalt Strike
https://blog.talosintelligence.com/2022/08/manjusaka-offensive-framework.html
Actors/Campaigns:
Ice_fog
Threats:
Cobalt_strike
Sliver_tool
Beacon
Skeleton_operation
Metasploit_tool
Industry:
Education
Geo:
China, Chinese, Tibetan, Guangdong
IOCs:
Url: 8
File: 2
IP: 1
Path: 2
Domain: 1
Hash: 9
Softs:
opera, google chrome, mysql, microsoft edge, chrome, postgresql, vivaldi, microsoft word
Algorithms:
xor, base64
Functions:
RtlCreateUserThread, CreateRemoteThread, CreateThread, SetThreadContext
Languages:
rust, php, golang
Platforms:
x64, x86
Links:
https://github.com/BishopFox/sliverhttps://github.com/gobuffalo/packrhttps://github.com/gin-gonic/ginCisco Talos Blog
Manjusaka: A Chinese sibling of Sliver and Cobalt Strike
* Cisco Talos recently discovered a new attack framework called "Manjusaka" being used in the wild that has the potential to become prevalent across the threat landscape. This framework is advertised as an imitation of the Cobalt Strike framework.
* The…
* The…
#ParsedReport
02-08-2022
Hackers Opting New Attack Methods After Microsoft Blocked Macros by Default
https://www.proofpoint.com/us/newsroom/news/hackers-opting-new-attack-methods-after-microsoft-blocked-macros-default
Threats:
Emotet
Icedid
Qakbot
Bumblebee
Softs:
microsoft excel, visual basic for applications
02-08-2022
Hackers Opting New Attack Methods After Microsoft Blocked Macros by Default
https://www.proofpoint.com/us/newsroom/news/hackers-opting-new-attack-methods-after-microsoft-blocked-macros-default
Threats:
Emotet
Icedid
Qakbot
Bumblebee
Softs:
microsoft excel, visual basic for applications
#ParsedReport
02-08-2022
ASEC (20220725 \~ 20220731). ASEC Weekly Malware Statistics (20220725 \~ 20220731)
https://asec.ahnlab.com/ko/37351
Threats:
Agent_tesla
Azorult
Redline_stealer
Cloudeye
Formbook
Remcos_rat
Nanocore_rat
Smokeloader
Clipboard_grabbing_technique
Industry:
Financial, Transport
Geo:
Korea
IOCs:
File: 36
Domain: 15
Email: 6
IP: 1
Url: 17
Softs:
discord, nsisinstaller
Algorithms:
zip
Languages:
visual_basic
02-08-2022
ASEC (20220725 \~ 20220731). ASEC Weekly Malware Statistics (20220725 \~ 20220731)
https://asec.ahnlab.com/ko/37351
Threats:
Agent_tesla
Azorult
Redline_stealer
Cloudeye
Formbook
Remcos_rat
Nanocore_rat
Smokeloader
Clipboard_grabbing_technique
Industry:
Financial, Transport
Geo:
Korea
IOCs:
File: 36
Domain: 15
Email: 6
IP: 1
Url: 17
Softs:
discord, nsisinstaller
Algorithms:
zip
Languages:
visual_basic
ASEC BLOG
ASEC 주간 악성코드 통계 (20220725 ~ 20220731) - ASEC BLOG
ASEC 분석팀에서는 ASEC 자동 분석 시스템 RAPIT 을 활용하여 알려진 악성코드들에 대한 분류 및 대응을 진행하고 있다. 본 포스팅에서는 2022년 7월 25일 월요일부터 7월 31일 일요일까지 한 주간 수집된 악성코드의 통계를 정리한다. 대분류 상으로는 인포스틸러가 38.6%로 1위를 차지하였으며, 그 다음으로는 백도어 악성코드가 38.1%, 다운로더 23.3%로 집계되었다. Top 1 – Agent Tesla 인포스틸러 악성코드인 AgentTesla가…
Расценки в Darknet
https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/the-price-cybercriminals-charge-for-stolen-data/
https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/the-price-cybercriminals-charge-for-stolen-data/
Trustwave
The Price Cybercriminals Charge for Stolen Data | Trustwave
For the price of a Starbuck’s Caramel Frappuccino Grande and a cheese Danish, about $8, a cybercriminal can obtain all the information needed to max out a person’s stolen credit card and possibly steal their identity.
#technique
Creating Processes Using System Calls
https://www.coresecurity.com/core-labs/articles/creating-processes-using-system-calls
Creating Processes Using System Calls
https://www.coresecurity.com/core-labs/articles/creating-processes-using-system-calls
#ParsedReport
03-08-2022
Gwisin Ransomware Targeting Korean Companies
https://asec.ahnlab.com/en/37483
Threats:
Gwisin
Magniber
Geo:
Korean
IOCs:
Path: 1
File: 1
Softs:
bcdedit
03-08-2022
Gwisin Ransomware Targeting Korean Companies
https://asec.ahnlab.com/en/37483
Threats:
Gwisin
Magniber
Geo:
Korean
IOCs:
Path: 1
File: 1
Softs:
bcdedit
ASEC
Gwisin Ransomware Targeting Korean Companies - ASEC
Gwisin Ransomware Targeting Korean Companies ASEC
#ParsedReport
03-08-2022
Large Scale Campaign Created Fake GitHub Projects Clones with Fake Commit Added Malware. Attack Flow
https://checkmarx.com/blog/large-scale-campaign-created-fake-github-projects-clones-with-fake-commit-added-malware
IOCs:
File: 1
Softs:
curl
Languages:
golang
03-08-2022
Large Scale Campaign Created Fake GitHub Projects Clones with Fake Commit Added Malware. Attack Flow
https://checkmarx.com/blog/large-scale-campaign-created-fake-github-projects-clones-with-fake-commit-added-malware
IOCs:
File: 1
Softs:
curl
Languages:
golang
Checkmarx.com
Large Scale Campaign Created Fake GitHub Projects Clones with Fake Commit Added Malware
This attack vector is possibly trying to target what users type in search-engines-related code snippets and land into these malicious random GitHub repositories, as discovered by Stephen Lacy when accidentally browsing through one of the infected fake clones.