CTT Report Hub
3.43K subscribers
9.9K photos
6 videos
67 files
13.5K links
Threat Intelligence Report Hub
Download Telegram
#ParsedReport
02-08-2022

SolidBit Ransomware Enters the RaaS Scene and Takes Aim at Gamers and Social Media Users With New Variant

https://www.trendmicro.com/en_us/research/22/h/solidbit-ransomware-enters-the-raas-scene-and-takes-aim-at-gamer.html

Threats:
Solidbit
Lockbit
Yashma
Ransom.win32.solidbitcrypt.thgabbb
Trojan.win32.solidbitcrypt.thgadbb
Trojan.win32.solidbitcrypt.thgahbb

IOCs:
File: 19
Path: 1
Hash: 12
Url: 1

Softs:
instagram, windows defender

Algorithms:
aes, exhibit

Platforms:
intel, x86
#ParsedReport
02-08-2022

Fake Atomic Wallet Website Distributing Mars Stealer

https://blog.cyble.com/2022/08/02/fake-atomic-wallet-website-distributing-mars-stealer

Threats:
Mars_stealer
Cashback
Beacon

Industry:
Financial, Government

TTPs:
Tactics: 6
Technics: 10

IOCs:
Url: 3
File: 3
Hash: 2

Softs:
atomic wallet, coinbase, android, discord

Algorithms:
zip , gzip, aes
#ParsedReport
02-08-2022

APTGamaredon

http://blog.nsfocus.net/gamaredon

Actors/Campaigns:
Gamaredon

Industry:
Government, Telco

Geo:
Russian, Ukraine, Russia, Ukrainian

IOCs:
File: 17
Url: 25
Domain: 8
Hash: 70
#ParsedReport
02-08-2022

Manjusaka: A Chinese sibling of Sliver and Cobalt Strike

https://blog.talosintelligence.com/2022/08/manjusaka-offensive-framework.html

Actors/Campaigns:
Ice_fog

Threats:
Cobalt_strike
Sliver_tool
Beacon
Skeleton_operation
Metasploit_tool

Industry:
Education

Geo:
China, Chinese, Tibetan, Guangdong

IOCs:
Url: 8
File: 2
IP: 1
Path: 2
Domain: 1
Hash: 9

Softs:
opera, google chrome, mysql, microsoft edge, chrome, postgresql, vivaldi, microsoft word

Algorithms:
xor, base64

Functions:
RtlCreateUserThread, CreateRemoteThread, CreateThread, SetThreadContext

Languages:
rust, php, golang

Platforms:
x64, x86

Links:
https://github.com/BishopFox/sliver
https://github.com/gobuffalo/packr
https://github.com/gin-gonic/gin
#ParsedReport
02-08-2022

Hackers Opting New Attack Methods After Microsoft Blocked Macros by Default

https://www.proofpoint.com/us/newsroom/news/hackers-opting-new-attack-methods-after-microsoft-blocked-macros-default

Threats:
Emotet
Icedid
Qakbot
Bumblebee

Softs:
microsoft excel, visual basic for applications
#ParsedReport
03-08-2022

Gwisin Ransomware Targeting Korean Companies

https://asec.ahnlab.com/en/37483

Threats:
Gwisin
Magniber

Geo:
Korean

IOCs:
Path: 1
File: 1

Softs:
bcdedit
#ParsedReport
03-08-2022

LOLI Stealer Golang-based InfoStealer spotted in the wild

https://blog.cyble.com/2022/08/03/loli-stealer-golang-based-infostealer-spotted-in-the-wild

Threats:
Loli_stealer
Mars_stealer
Beacon

Industry:
E-commerce

TTPs:
Tactics: 5
Technics: 10

IOCs:
File: 4
Url: 1
Hash: 1

Softs:
steam, telegram, chrome, atomic wallet

Algorithms:
base64, zip

Functions:
BitBlt, wine_get_version, theGetProcAddress, DeleteFileW

Languages:
golang
#ParsedReport
03-08-2022

Woody RAT: A new feature-rich malware spotted in the wild

https://blog.malwarebytes.com/threat-intelligence/2022/08/woody-rat-a-new-feature-rich-malware-spotted-in-the-wild

Actors/Campaigns:
Tonto_team

Threats:
Woody_rat
Follina_vuln
Process_injection_technique
Process_hollowing_technique
Konni

Industry:
Aerospace

Geo:
Russia, Russian, Korea, Chinese

CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...

TTPs:
Tactics: 1
Technics: 0

IOCs:
File: 5
Hash: 10
Domain: 4

Softs:
windows gdi+, powersession, microsoft office

Algorithms:
base64, aes-cbc, aes, zip , rsa-4096

Functions:
CreateProcess, SetErrorMode, ReadFile, NtWriteVirtualMemory, GetComputerNameA, WriteProcessMemory, CreateRemoteThread, GetVolumeInformationW, NtQuerySystemInformation, NtSetContextThread, GetAdaptersInfo

Languages:
python, csharp

Links:
https://gist.github.com/kernelm0de/fd018d58ebe78f603a13b2eba7f01917
#ParsedReport
04-08-2022

IcedID leverages PrivateLoader. SmokeLoader Tasks

https://medium.com/walmartglobaltech/icedid-leverages-privateloader-7744771bf87f

Threats:
Icedid
Privateloader
Smokeloader
Stop
Redline_stealer
Raccoon_stealer
Trickbot
Qakbot
Danabot
Dridex

Industry:
Financial

IOCs:
Hash: 2
Domain: 1
File: 7
Email: 2
IP: 4

Languages:
php

Platforms:
x86, intel
#ParsedReport
04-08-2022

: APT31 ,. Flying in the "clouds": APT31 again uses the cloud storage, attacking Russian companies

https://www.ptsecurity.com/ru-ru/research/pt-esc-threat-intelligence/apt31-cloud-attacks

Actors/Campaigns:
Apt31
Taskmasters
Naikon

Threats:
Yarat
Vmprotect_tool
Dllsideloading_technique
Dll_hijacking_technique

Industry:
Energy, Petroleum

Geo:
Russian, Russia

TTPs:
Tactics: 8
Technics: 19

IOCs:
File: 21
Hash: 15

Softs:
curl, windows registry

Algorithms:
rc4, base64

Functions:
GETADAPTERSInfo

Languages:
java

YARA: Found

Links:
https://github.com/nlohmann/json
#ParsedReport
04-08-2022

So RapperBot, What Ya Bruting For?

https://www.fortinet.com/blog/threat-research/rapperbot-malware-discovery

Actors/Campaigns:
Keksec

Threats:
Rapperbot
Mirai
Bashlite

Industry:
Iot

Geo:
Taiwan, Korea

TTPs:
Tactics: 1
Technics: 0

IOCs:
Url: 21
Hash: 26
IP: 4

Softs:
curl

Algorithms:
xor

Platforms:
arm, x86
#ParsedReport
04-08-2022

Stegomalware Identifying possible attack vectors

https://blog.cyble.com/2022/08/04/stegomalware-identifying-possible-attack-vectors

Actors/Campaigns:
Knotweed

Threats:
Loli_stealer
Mimikatz
Rubeus_tool
Nanocore_rat
Agent_tesla
Formbook
Corelump
Beacon

Industry:
Ics

TTPs:
Tactics: 2
Technics: 5

IOCs:
File: 1

Languages:
golang
👍1
#ParsedReport
04-08-2022

Flight of the Bumblebee: Email Lures and File Sharing Services Lead to Malware

https://unit42.paloaltonetworks.com/bumblebee-malware-projector-libra

Actors/Campaigns:
Projector_libra
Exotic_lily
Shathak
Ta578

Threats:
Bumblebee
Cobalt_strike
Conti
Bazarbackdoor
Trickbot
Icedid
Diavol

Industry:
Petroleum

Geo:
Japan, Emea, Apac, America

IOCs:
File: 4
Path: 2
IP: 2
Domain: 1
Hash: 6
Url: 1

Softs:
active directory

Algorithms:
zip
#ParsedReport
04-08-2022

Dark Web Profile: Vice Society

https://socradar.io/dark-web-profile-vice-society

Actors/Campaigns:
Vice_society
Dawdropper
Knotweed
Killnet

Threats:
Printnightmare_vuln

Industry:
Retail, Healthcare, Education, Ngo, Financial

Geo:
Brazil, Germany, Vietnam, Israeli, Indiana, Thailand, Indianapolis, America

Softs:
confluence, esxi
#ParsedReport
04-08-2022

Attackers leveraging Dark Utilities "C2aaS" platform in malware campaigns

http://blog.talosintelligence.com/2022/08/dark-utilities.html

Actors/Campaigns:
Lapsus

Threats:
Darkutilities_tool
Smartbot_tool
Kinsing_miner
Xmrig_miner

Industry:
Iot, Entertainment, Healthcare

Geo:
France, Germany, French

IOCs:
Path: 3
Url: 2
Domain: 6
File: 1
Hash: 52

Softs:
telegram, fivem, teamspeak3, systemd, curl, crontab, teamspeak, gmod, discord, steam

Languages:
python

Platforms:
arm

Links:
https://github.com/Cisco-Talos/IOCs/tree/main/2022/08
#ParsedReport
04-08-2022

Ousaban: LATAM Banking Malware Abusing Cloud Services

https://www.netskope.com/blog/ousaban-latam-banking-malware-abusing-cloud-services

Threats:
Ousaban
Javali
Astaroth
Metamorfo
Grandoreiro
Dll_hijacking_technique
Upx_tool
Enigma_tool
Aitm_technique

Industry:
Financial

Geo:
Brazilian, Latam, Brazil

IOCs:
File: 8

Softs:
telegram

Algorithms:
zip , xor

Languages:
python, delphi, javascript

Links:
https://github.com/netskopeoss/NetskopeThreatLabsIOCs/tree/main/Ousaban/script
https://github.com/netskopeoss/NetskopeThreatLabsIOCs/tree/main/Ousaban