#ParsedReport
04-08-2022
: APT31 ,. Flying in the "clouds": APT31 again uses the cloud storage, attacking Russian companies
https://www.ptsecurity.com/ru-ru/research/pt-esc-threat-intelligence/apt31-cloud-attacks
Actors/Campaigns:
Apt31
Taskmasters
Naikon
Threats:
Yarat
Vmprotect_tool
Dllsideloading_technique
Dll_hijacking_technique
Industry:
Energy, Petroleum
Geo:
Russian, Russia
TTPs:
Tactics: 8
Technics: 19
IOCs:
File: 21
Hash: 15
Softs:
curl, windows registry
Algorithms:
rc4, base64
Functions:
GETADAPTERSInfo
Languages:
java
YARA: Found
Links:
04-08-2022
: APT31 ,. Flying in the "clouds": APT31 again uses the cloud storage, attacking Russian companies
https://www.ptsecurity.com/ru-ru/research/pt-esc-threat-intelligence/apt31-cloud-attacks
Actors/Campaigns:
Apt31
Taskmasters
Naikon
Threats:
Yarat
Vmprotect_tool
Dllsideloading_technique
Dll_hijacking_technique
Industry:
Energy, Petroleum
Geo:
Russian, Russia
TTPs:
Tactics: 8
Technics: 19
IOCs:
File: 21
Hash: 15
Softs:
curl, windows registry
Algorithms:
rc4, base64
Functions:
GETADAPTERSInfo
Languages:
java
YARA: Found
Links:
https://github.com/nlohmann/jsonptsecurity.com
Блог PT ESC Threat Intelligence
В этом блоге вы можете найти информацию об актуальных атаках хакерских группировок по всему миру, разбор их инструментов, информацию об инцидентах, TTP группировок, индикаторы компрометации и названия детектов в наших продуктах
#ParsedReport
04-08-2022
So RapperBot, What Ya Bruting For?
https://www.fortinet.com/blog/threat-research/rapperbot-malware-discovery
Actors/Campaigns:
Keksec
Threats:
Rapperbot
Mirai
Bashlite
Industry:
Iot
Geo:
Taiwan, Korea
TTPs:
Tactics: 1
Technics: 0
IOCs:
Url: 21
Hash: 26
IP: 4
Softs:
curl
Algorithms:
xor
Platforms:
arm, x86
04-08-2022
So RapperBot, What Ya Bruting For?
https://www.fortinet.com/blog/threat-research/rapperbot-malware-discovery
Actors/Campaigns:
Keksec
Threats:
Rapperbot
Mirai
Bashlite
Industry:
Iot
Geo:
Taiwan, Korea
TTPs:
Tactics: 1
Technics: 0
IOCs:
Url: 21
Hash: 26
IP: 4
Softs:
curl
Algorithms:
xor
Platforms:
arm, x86
Fortinet Blog
So RapperBot, What Ya Bruting For?
FortiGuard Labs is tracking a rapidly evolving IoT malware family known as RapperBot. Read to learn how this threat infects and persists on a victim’s device.…
#ParsedReport
04-08-2022
Stegomalware Identifying possible attack vectors
https://blog.cyble.com/2022/08/04/stegomalware-identifying-possible-attack-vectors
Actors/Campaigns:
Knotweed
Threats:
Loli_stealer
Mimikatz
Rubeus_tool
Nanocore_rat
Agent_tesla
Formbook
Corelump
Beacon
Industry:
Ics
TTPs:
Tactics: 2
Technics: 5
IOCs:
File: 1
Languages:
golang
04-08-2022
Stegomalware Identifying possible attack vectors
https://blog.cyble.com/2022/08/04/stegomalware-identifying-possible-attack-vectors
Actors/Campaigns:
Knotweed
Threats:
Loli_stealer
Mimikatz
Rubeus_tool
Nanocore_rat
Agent_tesla
Formbook
Corelump
Beacon
Industry:
Ics
TTPs:
Tactics: 2
Technics: 5
IOCs:
File: 1
Languages:
golang
Cyble
Cyble - Stegomalware - Identifying Possible Attack Vectors
Cyble Research Labs analyzes the rise of Stegomalware and the reason behind it's popularity through careful testing.
👍1
#ParsedReport
04-08-2022
Flight of the Bumblebee: Email Lures and File Sharing Services Lead to Malware
https://unit42.paloaltonetworks.com/bumblebee-malware-projector-libra
Actors/Campaigns:
Projector_libra
Exotic_lily
Shathak
Ta578
Threats:
Bumblebee
Cobalt_strike
Conti
Bazarbackdoor
Trickbot
Icedid
Diavol
Industry:
Petroleum
Geo:
Japan, Emea, Apac, America
IOCs:
File: 4
Path: 2
IP: 2
Domain: 1
Hash: 6
Url: 1
Softs:
active directory
Algorithms:
zip
04-08-2022
Flight of the Bumblebee: Email Lures and File Sharing Services Lead to Malware
https://unit42.paloaltonetworks.com/bumblebee-malware-projector-libra
Actors/Campaigns:
Projector_libra
Exotic_lily
Shathak
Ta578
Threats:
Bumblebee
Cobalt_strike
Conti
Bazarbackdoor
Trickbot
Icedid
Diavol
Industry:
Petroleum
Geo:
Japan, Emea, Apac, America
IOCs:
File: 4
Path: 2
IP: 2
Domain: 1
Hash: 6
Url: 1
Softs:
active directory
Algorithms:
zip
Unit 42
Flight of the Bumblebee: Email Lures and File Sharing Services Lead to Malware
We provide a case study of how the criminal group Projector Libra uses legitimate file sharing services to distribute Bumblebee malware.
#ParsedReport
04-08-2022
Dark Web Profile: Vice Society
https://socradar.io/dark-web-profile-vice-society
Actors/Campaigns:
Vice_society
Dawdropper
Knotweed
Killnet
Threats:
Printnightmare_vuln
Industry:
Retail, Healthcare, Education, Ngo, Financial
Geo:
Brazil, Germany, Vietnam, Israeli, Indiana, Thailand, Indianapolis, America
Softs:
confluence, esxi
04-08-2022
Dark Web Profile: Vice Society
https://socradar.io/dark-web-profile-vice-society
Actors/Campaigns:
Vice_society
Dawdropper
Knotweed
Killnet
Threats:
Printnightmare_vuln
Industry:
Retail, Healthcare, Education, Ngo, Financial
Geo:
Brazil, Germany, Vietnam, Israeli, Indiana, Thailand, Indianapolis, America
Softs:
confluence, esxi
SOCRadar® Cyber Intelligence Inc.
Dark Web Profile: Vice Society Ransomware Group - SOCRadar® Cyber Intelligence Inc.
#ParsedReport
04-08-2022
Attackers leveraging Dark Utilities "C2aaS" platform in malware campaigns
http://blog.talosintelligence.com/2022/08/dark-utilities.html
Actors/Campaigns:
Lapsus
Threats:
Darkutilities_tool
Smartbot_tool
Kinsing_miner
Xmrig_miner
Industry:
Iot, Entertainment, Healthcare
Geo:
France, Germany, French
IOCs:
Path: 3
Url: 2
Domain: 6
File: 1
Hash: 52
Softs:
telegram, fivem, teamspeak3, systemd, curl, crontab, teamspeak, gmod, discord, steam
Languages:
python
Platforms:
arm
Links:
04-08-2022
Attackers leveraging Dark Utilities "C2aaS" platform in malware campaigns
http://blog.talosintelligence.com/2022/08/dark-utilities.html
Actors/Campaigns:
Lapsus
Threats:
Darkutilities_tool
Smartbot_tool
Kinsing_miner
Xmrig_miner
Industry:
Iot, Entertainment, Healthcare
Geo:
France, Germany, French
IOCs:
Path: 3
Url: 2
Domain: 6
File: 1
Hash: 52
Softs:
telegram, fivem, teamspeak3, systemd, curl, crontab, teamspeak, gmod, discord, steam
Languages:
python
Platforms:
arm
Links:
https://github.com/Cisco-Talos/IOCs/tree/main/2022/08Cisco Talos
Attackers leveraging Dark Utilities "C2aaS" platform in malware campaigns
By Edmund Brumaghin, Azim Khodjibaev and Matt Thaxton, with contributions from Arnaud Zobec. Executive Summary * Dark Utilities, released in early 2022, is a platform that provides full-featured C2 capabilities to adversaries. * It is marketed as a means…
#ParsedReport
04-08-2022
Ousaban: LATAM Banking Malware Abusing Cloud Services
https://www.netskope.com/blog/ousaban-latam-banking-malware-abusing-cloud-services
Threats:
Ousaban
Javali
Astaroth
Metamorfo
Grandoreiro
Dll_hijacking_technique
Upx_tool
Enigma_tool
Aitm_technique
Industry:
Financial
Geo:
Brazilian, Latam, Brazil
IOCs:
File: 8
Softs:
telegram
Algorithms:
zip , xor
Languages:
python, delphi, javascript
Links:
04-08-2022
Ousaban: LATAM Banking Malware Abusing Cloud Services
https://www.netskope.com/blog/ousaban-latam-banking-malware-abusing-cloud-services
Threats:
Ousaban
Javali
Astaroth
Metamorfo
Grandoreiro
Dll_hijacking_technique
Upx_tool
Enigma_tool
Aitm_technique
Industry:
Financial
Geo:
Brazilian, Latam, Brazil
IOCs:
File: 8
Softs:
telegram
Algorithms:
zip , xor
Languages:
python, delphi, javascript
Links:
https://github.com/netskopeoss/NetskopeThreatLabsIOCs/tree/main/Ousaban/scripthttps://github.com/netskopeoss/NetskopeThreatLabsIOCs/tree/main/OusabanNetskope
Ousaban: LATAM Banking Malware Abusing Cloud Services
Summary Ousaban (a.k.a. Javali) is a banking malware that emerged between 2017 and 2018, with the primary goal of stealing sensitive data from financial
#ParsedReport
04-08-2022
Who Needs Macros? \| Threat Actors Pivot to Abusing Explorer and Other LOLBins via Windows Shortcuts
https://www.sentinelone.com/labs/who-needs-macros-threat-actors-pivot-to-abusing-explorer-and-other-lolbins-via-windows-shortcuts
Actors/Campaigns:
Exotic_lily
Gamaredon
Threats:
Lolbin
Mlnk_tool
Quantumbuilder_tool
Qakbot
Emotet
Icedid
Bumblebee
Raspberry_robin
Glowsand
Geo:
Russian, Ukraine, Ukrainian
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 12
Hash: 1
Path: 7
Softs:
microsoft defender, windows shell, windows explorer
Algorithms:
exhibit
Functions:
LinkTargetIDList, CreateProcessW
Links:
04-08-2022
Who Needs Macros? \| Threat Actors Pivot to Abusing Explorer and Other LOLBins via Windows Shortcuts
https://www.sentinelone.com/labs/who-needs-macros-threat-actors-pivot-to-abusing-explorer-and-other-lolbins-via-windows-shortcuts
Actors/Campaigns:
Exotic_lily
Gamaredon
Threats:
Lolbin
Mlnk_tool
Quantumbuilder_tool
Qakbot
Emotet
Icedid
Bumblebee
Raspberry_robin
Glowsand
Geo:
Russian, Ukraine, Ukrainian
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 12
Hash: 1
Path: 7
Softs:
microsoft defender, windows shell, windows explorer
Algorithms:
exhibit
Functions:
LinkTargetIDList, CreateProcessW
Links:
https://github.com/EricZimmerman/LECmdSentinelOne
Who Needs Macros? | Threat Actors Pivot to Abusing Explorer and Other LOLBins via Windows Shortcuts
Crimeware vendors say 'macros are dead', but they have a new weapon to help threat actors successfully deploy malware.
#ParsedReport
04-08-2022
Active Phishing Campaign Alert
https://zvelo.com/active-phishing-campaign-alert
IOCs:
Url: 4
Softs:
electrum
04-08-2022
Active Phishing Campaign Alert
https://zvelo.com/active-phishing-campaign-alert
IOCs:
Url: 4
Softs:
electrum
Zvelo
Active Phishing Campaign Alert
Active Threat Alert: Protect against active phishing campaigns serving up personalized and uniquely randomized URL paths or subdomains.
#ParsedReport
04-08-2022
GwisinLocker ransomwaretargets South Korean industrial and pharma firms. GwisinLocker ransomware targets South Korean industrial and pharma firms
https://blog.reversinglabs.com/blog/gwisinlocker-ransomware-targets-south-korean-industrial-and-pharmaceutical-companies
Threats:
Gwisin
Kisa
Gozi
Industry:
Government, Financial, Healthcare
Geo:
Korean, Korea
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 9
Hash: 2
Softs:
esxi, unix, active directory
Algorithms:
rc4, aes
Languages:
java
04-08-2022
GwisinLocker ransomwaretargets South Korean industrial and pharma firms. GwisinLocker ransomware targets South Korean industrial and pharma firms
https://blog.reversinglabs.com/blog/gwisinlocker-ransomware-targets-south-korean-industrial-and-pharmaceutical-companies
Threats:
Gwisin
Kisa
Gozi
Industry:
Government, Financial, Healthcare
Geo:
Korean, Korea
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 9
Hash: 2
Softs:
esxi, unix, active directory
Algorithms:
rc4, aes
Languages:
java
ReversingLabs
GwisinLocker ransomware targets South Korean industrial and pharma firms
GwisinLocker is a new ransomware family that targets Linux in industrial and pharma companies with sophisticated "double extortion" ransomware campaigns.
#ParsedReport
05-08-2022
Minerva Labs Blog
http://blog.minerva-labs.com/lockbit-3.0-aka-lockbit-black-is-here-with-a-new-icon-new-ransom-note-new-wallpaper-but-less-evasiveness
Threats:
Lockbit
Blackcat
Uac_bypass_technique
Geo:
Russian, Moldova, Belarusian, Ukrainian, Romanian, Syria
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 1
Softs:
thebat, dbsnmp, onenote, windows defender, msexchange, powerpnt, steam, wordpad
Algorithms:
xor
Functions:
NtSetInformationThread, GetSystemDefaultUILanguage, GetUserDefaultUILanguage
05-08-2022
Minerva Labs Blog
http://blog.minerva-labs.com/lockbit-3.0-aka-lockbit-black-is-here-with-a-new-icon-new-ransom-note-new-wallpaper-but-less-evasiveness
Threats:
Lockbit
Blackcat
Uac_bypass_technique
Geo:
Russian, Moldova, Belarusian, Ukrainian, Romanian, Syria
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 1
Softs:
thebat, dbsnmp, onenote, windows defender, msexchange, powerpnt, steam, wordpad
Algorithms:
xor
Functions:
NtSetInformationThread, GetSystemDefaultUILanguage, GetUserDefaultUILanguage
Minerva-Labs
Lockbit 3.0 AKA Lockbit Black is here, with a new icon, new ransom note, new wallpaper, but less evasiveness?
Lockbit 3.0, also known as Lockbit Black was recently released and has already claimed its first victims. We dive into how it works and how you can protect yourselves
#ParsedReport
05-08-2022
Dark Utilities Platform Provides C2 Server for Threat Actors
https://socradar.io/dark-utilities-platform-provides-c2-server-for-threat-actors
Actors/Campaigns:
Vice_society
Dawdropper
Knotweed
Lapsus
Threats:
Darkutilities_tool
Industry:
Entertainment, Financial, Iot
IOCs:
Hash: 52
Domain: 5
Softs:
confluence, crontab, gmod, discord, fivem, systemd, teamspeak3, telegram
Platforms:
arm
Links:
05-08-2022
Dark Utilities Platform Provides C2 Server for Threat Actors
https://socradar.io/dark-utilities-platform-provides-c2-server-for-threat-actors
Actors/Campaigns:
Vice_society
Dawdropper
Knotweed
Lapsus
Threats:
Darkutilities_tool
Industry:
Entertainment, Financial, Iot
IOCs:
Hash: 52
Domain: 5
Softs:
confluence, crontab, gmod, discord, fivem, systemd, teamspeak3, telegram
Platforms:
arm
Links:
https://github.com/Cisco-Talos/IOCs/tree/main/2022/08SOCRadar® Cyber Intelligence Inc.
Dark Utilities Platform Provides C2 Server for Threat Actors - SOCRadar
Cybercriminals can now use a new service called Dark Utilities to build up a command and control (C2) center for their malicious activities.
#ParsedReport
05-08-2022
Mysterious threat actor TAC-040 used previously undetected Ljl Backdoor
https://securityaffairs.co/wordpress/134033/hacking/tac-040-ljl-backdoor.html
Actors/Campaigns:
Tac_040 (motivation: financially_motivated)
Threats:
Ljl_backdoor
Spring4shell
Xmrig_miner
Netripper_tool
Powersploit
Cmepowershell_scripts_tool
Crackmapexec_tool
Sessiongopher_tool
Mimipenguin_tool
Mimikittenz_tool
Rid_hijacking_tool
Randomps_scripts_tool
Rapperbot
Industry:
Telco
CVEs:
CVE-2022-26134 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- atlassian confluence data center (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
- atlassian confluence server (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
CVE-2022-22965 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- vmware spring framework (<5.3.18, <5.2.20)
- cisco cx cloud agent (<2.1.0)
- oracle sd-wan edge (9.0, 9.1)
- oracle retail xstore point of service (20.0.1, 21.0.0)
- oracle communications cloud native core security edge protection proxy (1.7.0, 22.1.0)
have more...
IOCs:
File: 1
Softs:
active directory, confluence
Platforms:
intel
05-08-2022
Mysterious threat actor TAC-040 used previously undetected Ljl Backdoor
https://securityaffairs.co/wordpress/134033/hacking/tac-040-ljl-backdoor.html
Actors/Campaigns:
Tac_040 (motivation: financially_motivated)
Threats:
Ljl_backdoor
Spring4shell
Xmrig_miner
Netripper_tool
Powersploit
Cmepowershell_scripts_tool
Crackmapexec_tool
Sessiongopher_tool
Mimipenguin_tool
Mimikittenz_tool
Rid_hijacking_tool
Randomps_scripts_tool
Rapperbot
Industry:
Telco
CVEs:
CVE-2022-26134 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- atlassian confluence data center (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
- atlassian confluence server (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
CVE-2022-22965 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- vmware spring framework (<5.3.18, <5.2.20)
- cisco cx cloud agent (<2.1.0)
- oracle sd-wan edge (9.0, 9.1)
- oracle retail xstore point of service (20.0.1, 21.0.0)
- oracle communications cloud native core security edge protection proxy (1.7.0, 22.1.0)
have more...
IOCs:
File: 1
Softs:
active directory, confluence
Platforms:
intel
Security Affairs
TAC-040 group used previously undetected Ljl Backdoor
A threat actor, tracked as TAC-040, exploited Atlassian Confluence flaw CVE-2022-26134 to deploy previously undetected Ljl Backdoor.
#ParsedReport
05-08-2022
X-FILES Stealer Evolution - An Analysis and Comparison Study. Introduction
https://www.zscaler.com/blogs/security-research/x-files-stealer-evolution-analysis-and-comparison-study
Threats:
Xfiles_stealer
Follina_vuln
Industry:
Financial
Geo:
Russian
TTPs:
Tactics: 2
Technics: 10
IOCs:
Domain: 5
IP: 1
Hash: 6
File: 4
Softs:
steam, nitro generator, discord, telegram, winscp
Algorithms:
zip , base64
05-08-2022
X-FILES Stealer Evolution - An Analysis and Comparison Study. Introduction
https://www.zscaler.com/blogs/security-research/x-files-stealer-evolution-analysis-and-comparison-study
Threats:
Xfiles_stealer
Follina_vuln
Industry:
Financial
Geo:
Russian
TTPs:
Tactics: 2
Technics: 10
IOCs:
Domain: 5
IP: 1
Hash: 6
File: 4
Softs:
steam, nitro generator, discord, telegram, winscp
Algorithms:
zip , base64
Zscaler
Analysis & Comparison of X-FILES Stealer Evolution | Zscaler
An analysis and comparison of X-FILES stealer variants, which have evolved with enhanced features to exfiltrate sensitive information.
#ParsedReport
05-08-2022
Say NO to Nopyfy!
https://labs.k7computing.com/index.php/say-no-to-nopyfy
Threats:
Nopyfy
Geo:
Russian
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 4
Url: 2
Hash: 1
Softs:
mysql
Algorithms:
base64, des, aes
Languages:
php
05-08-2022
Say NO to Nopyfy!
https://labs.k7computing.com/index.php/say-no-to-nopyfy
Threats:
Nopyfy
Geo:
Russian
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 4
Url: 2
Hash: 1
Softs:
mysql
Algorithms:
base64, des, aes
Languages:
php
K7 Labs
Say NO to Nopyfy! - K7 Labs
In the last week of July, we detected a ransomware named Nopyfy in our customer end. In August 2021, Nopyfy […]
#ParsedReport
05-08-2022
DGAOrchardDGA. The DGA family orchard continues to change, and the new version uses Bitcoin transaction information to generate DGA domain name
https://blog.netlab.360.com/orchard-dga
Threats:
Orchard_botnet
Enigma_tool
Xmrig_miner
Industry:
Financial
IOCs:
File: 7
Coin: 1
Hash: 3
Softs:
.net framework
Algorithms:
base64
Languages:
golang
05-08-2022
DGAOrchardDGA. The DGA family orchard continues to change, and the new version uses Bitcoin transaction information to generate DGA domain name
https://blog.netlab.360.com/orchard-dga
Threats:
Orchard_botnet
Enigma_tool
Xmrig_miner
Industry:
Financial
IOCs:
File: 7
Coin: 1
Hash: 3
Softs:
.net framework
Algorithms:
base64
Languages:
golang
360 Netlab Blog - Network Security Research Lab at 360
DGA家族Orchard持续变化,新版本用比特币交易信息生成DGA域名
DGA是一种经典的botnet对抗检测的技术,其原理是使用某种DGA算法,结合特定的种子和当前日期,定期生成大量的域名,而攻击者只是选择性的注册其中的极少数。对于防御者而言,因为难以事先确定哪些域名会被生成和注册,因而防御难度极大。
360 netlab长期专注于botnet攻防技术的研究,维护了专门的DGA算法和情报库,并通过订阅情报的方式与业界分享研究成果。近期我们在分析未知DGA域名时发现一例不但使用日期,还会同时使用中本聪的比特币账号交易信息来生成DGA域名的例子。因为比特币交易的不确定性,…
360 netlab长期专注于botnet攻防技术的研究,维护了专门的DGA算法和情报库,并通过订阅情报的方式与业界分享研究成果。近期我们在分析未知DGA域名时发现一例不但使用日期,还会同时使用中本聪的比特币账号交易信息来生成DGA域名的例子。因为比特币交易的不确定性,…
#ParsedReport
05-08-2022
Likely Iranian Threat Actor Conducts Politically Motivated Disruptive Activity Against Albanian Government Organizations
https://www.mandiant.com/resources/likely-iranian-threat-actor-conducts-politically-motivated-disruptive-activity-against
Actors/Campaigns:
Cleaver (motivation: cyber_espionage)
Axiom
Threats:
Roadsweep
Chimneysweep
Zeroclear
Dustman
Markirat
Mosesstaff
Metasploit_tool
Delf
Netstat_tool
Process_injection_technique
Timestomp_technique
Industry:
Government, Telco
Geo:
Lebanon, Kuwait, Israeli, Iran, Bahrain, Albania, Iranian
TTPs:
Tactics: 3
Technics: 19
IOCs:
Domain: 9
File: 12
Hash: 20
IP: 1
Path: 4
Coin: 1
Registry: 2
Softs:
telegram, windows service, windows registry
Algorithms:
base64, rc4
Functions:
GetProcAddress, FindNextFileW, DeviceIoControl, GetFileSize, FindFirstFileW, GetSystemDirectoryW, GetUpdates
Platforms:
x86
YARA: Found
Links:
05-08-2022
Likely Iranian Threat Actor Conducts Politically Motivated Disruptive Activity Against Albanian Government Organizations
https://www.mandiant.com/resources/likely-iranian-threat-actor-conducts-politically-motivated-disruptive-activity-against
Actors/Campaigns:
Cleaver (motivation: cyber_espionage)
Axiom
Threats:
Roadsweep
Chimneysweep
Zeroclear
Dustman
Markirat
Mosesstaff
Metasploit_tool
Delf
Netstat_tool
Process_injection_technique
Timestomp_technique
Industry:
Government, Telco
Geo:
Lebanon, Kuwait, Israeli, Iran, Bahrain, Albania, Iranian
TTPs:
Tactics: 3
Technics: 19
IOCs:
Domain: 9
File: 12
Hash: 20
IP: 1
Path: 4
Coin: 1
Registry: 2
Softs:
telegram, windows service, windows registry
Algorithms:
base64, rc4
Functions:
GetProcAddress, FindNextFileW, DeviceIoControl, GetFileSize, FindFirstFileW, GetSystemDirectoryW, GetUpdates
Platforms:
x86
YARA: Found
Links:
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/local/bypassuac\_silentcleanup.rbGoogle Cloud Blog
ROADSWEEP Ransomware Targets the Albanian Government | Google Cloud Blog
Mandiant identified the ROADSWEEP ransomware family which targeted the Albanian government in a politically motivated disruptive operation. Learn more.
CloudGuard Spectral detects several malicious packages on PyPI – the official software repository for Python developers
https://research.checkpoint.com/2022/cloudguard-spectral-detects-several-malicious-packages-on-pypi-the-official-software-repository-for-python-developers/
https://research.checkpoint.com/2022/cloudguard-spectral-detects-several-malicious-packages-on-pypi-the-official-software-repository-for-python-developers/
Check Point Research
CloudGuard Spectral detects several malicious packages on PyPI - the official software repository for Python developers - Check…
Highlights: CloudGuard Spectral detects 10 malicious packages on PyPI, the leading Python package index used by developers for the Python programming language Malicious packages install info-stealers that enable attackers to steal developer’s private data…
#technique
EntropyFix: a tool to reduce the entropy of your payload, It works By adding null bytes, in an ordered sequence: every 10 bytes it adds 5 null bytes. - designed to avoid high entropy detection technique
https://gitlab.com/ORCA000/entropyfix
EntropyFix: a tool to reduce the entropy of your payload, It works By adding null bytes, in an ordered sequence: every 10 bytes it adds 5 null bytes. - designed to avoid high entropy detection technique
https://gitlab.com/ORCA000/entropyfix
GitLab
ORCA / EntropyFix · GitLab
A tool with no ascii art that reduces the entropy of your payload
#ParsedReport
08-08-2022
Monero CoinMiner Being Distributed via Webhards
https://asec.ahnlab.com/en/37526
Threats:
Njrat_rat
Udprat
Xmrig_miner
Monero_miner
Trojan/win.fy.c5155016
Xmr_miner
Trojan/win.launcher.c5217400
Geo:
Korean
IOCs:
File: 5
Domain: 1
Coin: 1
Hash: 5
Url: 3
08-08-2022
Monero CoinMiner Being Distributed via Webhards
https://asec.ahnlab.com/en/37526
Threats:
Njrat_rat
Udprat
Xmrig_miner
Monero_miner
Trojan/win.fy.c5155016
Xmr_miner
Trojan/win.launcher.c5217400
Geo:
Korean
IOCs:
File: 5
Domain: 1
Coin: 1
Hash: 5
Url: 3
ASEC BLOG
Monero CoinMiner Being Distributed via Webhards - ASEC BLOG
Webhards are the main platforms that the attackers targeting Korean users exploit to distribute malware. The ASEC analysis team has been monitoring malware types distributed through webhards and uploaded multiple blog posts about them in the past. Generally…
#ParsedReport
08-08-2022
BumbleBee Roasts Its Way to Domain Admin. Case Summary
https://thedfirreport.com/2022/08/08/bumblebee-roasts-its-way-to-domain-admin
Actors/Campaigns:
Exotic_lily
Wizard_spider
Fin12
Threats:
Bumblebee
Bespoke
Cobalt_strike
Beacon
Adfind_tool
Vulnrecon_tool
Procdump_tool
Process_injection_technique
Kerberoasting_technique
Cyberchef_tool
Minidump_tool
Powerview
Anydesk_tool
Geo:
Usa
TTPs:
Tactics: 11
Technics: 26
IOCs:
File: 25
Path: 17
IP: 5
Domain: 3
Hash: 15
Softs:
android, anydesk, active directory, psexec, sysinternals
Algorithms:
zip , gzip, xor, base64, rc4
Functions:
Gunzip, CreateServiceA, OpenSSL, CreateRemoteThread
YARA: Found
SIGMA: Found
Links:
08-08-2022
BumbleBee Roasts Its Way to Domain Admin. Case Summary
https://thedfirreport.com/2022/08/08/bumblebee-roasts-its-way-to-domain-admin
Actors/Campaigns:
Exotic_lily
Wizard_spider
Fin12
Threats:
Bumblebee
Bespoke
Cobalt_strike
Beacon
Adfind_tool
Vulnrecon_tool
Procdump_tool
Process_injection_technique
Kerberoasting_technique
Cyberchef_tool
Minidump_tool
Powerview
Anydesk_tool
Geo:
Usa
TTPs:
Tactics: 11
Technics: 26
IOCs:
File: 25
Path: 17
IP: 5
Domain: 3
Hash: 15
Softs:
android, anydesk, active directory, psexec, sysinternals
Algorithms:
zip , gzip, xor, base64, rc4
Functions:
Gunzip, CreateServiceA, OpenSSL, CreateRemoteThread
YARA: Found
SIGMA: Found
Links:
https://github.com/GhostPack/Seatbelthttps://github.com/DidierStevens/DidierStevensSuite/blob/master/1768.pyThe DFIR Report
BumbleBee Roasts Its Way to Domain Admin - The DFIR Report
In this intrusion from April 2022, the threat actors used BumbleBee as the initial access vector. BumbleBee is a malware loader that was first reported by Google Threat Analysis Group in March 2022. Google TAG attributes this malware to an initial access…