#ParsedReport
04-08-2022
Active Phishing Campaign Alert
https://zvelo.com/active-phishing-campaign-alert
IOCs:
Url: 4
Softs:
electrum
04-08-2022
Active Phishing Campaign Alert
https://zvelo.com/active-phishing-campaign-alert
IOCs:
Url: 4
Softs:
electrum
Zvelo
Active Phishing Campaign Alert
Active Threat Alert: Protect against active phishing campaigns serving up personalized and uniquely randomized URL paths or subdomains.
#ParsedReport
04-08-2022
GwisinLocker ransomwaretargets South Korean industrial and pharma firms. GwisinLocker ransomware targets South Korean industrial and pharma firms
https://blog.reversinglabs.com/blog/gwisinlocker-ransomware-targets-south-korean-industrial-and-pharmaceutical-companies
Threats:
Gwisin
Kisa
Gozi
Industry:
Government, Financial, Healthcare
Geo:
Korean, Korea
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 9
Hash: 2
Softs:
esxi, unix, active directory
Algorithms:
rc4, aes
Languages:
java
04-08-2022
GwisinLocker ransomwaretargets South Korean industrial and pharma firms. GwisinLocker ransomware targets South Korean industrial and pharma firms
https://blog.reversinglabs.com/blog/gwisinlocker-ransomware-targets-south-korean-industrial-and-pharmaceutical-companies
Threats:
Gwisin
Kisa
Gozi
Industry:
Government, Financial, Healthcare
Geo:
Korean, Korea
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 9
Hash: 2
Softs:
esxi, unix, active directory
Algorithms:
rc4, aes
Languages:
java
ReversingLabs
GwisinLocker ransomware targets South Korean industrial and pharma firms
GwisinLocker is a new ransomware family that targets Linux in industrial and pharma companies with sophisticated "double extortion" ransomware campaigns.
#ParsedReport
05-08-2022
Minerva Labs Blog
http://blog.minerva-labs.com/lockbit-3.0-aka-lockbit-black-is-here-with-a-new-icon-new-ransom-note-new-wallpaper-but-less-evasiveness
Threats:
Lockbit
Blackcat
Uac_bypass_technique
Geo:
Russian, Moldova, Belarusian, Ukrainian, Romanian, Syria
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 1
Softs:
thebat, dbsnmp, onenote, windows defender, msexchange, powerpnt, steam, wordpad
Algorithms:
xor
Functions:
NtSetInformationThread, GetSystemDefaultUILanguage, GetUserDefaultUILanguage
05-08-2022
Minerva Labs Blog
http://blog.minerva-labs.com/lockbit-3.0-aka-lockbit-black-is-here-with-a-new-icon-new-ransom-note-new-wallpaper-but-less-evasiveness
Threats:
Lockbit
Blackcat
Uac_bypass_technique
Geo:
Russian, Moldova, Belarusian, Ukrainian, Romanian, Syria
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 1
Softs:
thebat, dbsnmp, onenote, windows defender, msexchange, powerpnt, steam, wordpad
Algorithms:
xor
Functions:
NtSetInformationThread, GetSystemDefaultUILanguage, GetUserDefaultUILanguage
Minerva-Labs
Lockbit 3.0 AKA Lockbit Black is here, with a new icon, new ransom note, new wallpaper, but less evasiveness?
Lockbit 3.0, also known as Lockbit Black was recently released and has already claimed its first victims. We dive into how it works and how you can protect yourselves
#ParsedReport
05-08-2022
Dark Utilities Platform Provides C2 Server for Threat Actors
https://socradar.io/dark-utilities-platform-provides-c2-server-for-threat-actors
Actors/Campaigns:
Vice_society
Dawdropper
Knotweed
Lapsus
Threats:
Darkutilities_tool
Industry:
Entertainment, Financial, Iot
IOCs:
Hash: 52
Domain: 5
Softs:
confluence, crontab, gmod, discord, fivem, systemd, teamspeak3, telegram
Platforms:
arm
Links:
05-08-2022
Dark Utilities Platform Provides C2 Server for Threat Actors
https://socradar.io/dark-utilities-platform-provides-c2-server-for-threat-actors
Actors/Campaigns:
Vice_society
Dawdropper
Knotweed
Lapsus
Threats:
Darkutilities_tool
Industry:
Entertainment, Financial, Iot
IOCs:
Hash: 52
Domain: 5
Softs:
confluence, crontab, gmod, discord, fivem, systemd, teamspeak3, telegram
Platforms:
arm
Links:
https://github.com/Cisco-Talos/IOCs/tree/main/2022/08SOCRadar® Cyber Intelligence Inc.
Dark Utilities Platform Provides C2 Server for Threat Actors - SOCRadar
Cybercriminals can now use a new service called Dark Utilities to build up a command and control (C2) center for their malicious activities.
#ParsedReport
05-08-2022
Mysterious threat actor TAC-040 used previously undetected Ljl Backdoor
https://securityaffairs.co/wordpress/134033/hacking/tac-040-ljl-backdoor.html
Actors/Campaigns:
Tac_040 (motivation: financially_motivated)
Threats:
Ljl_backdoor
Spring4shell
Xmrig_miner
Netripper_tool
Powersploit
Cmepowershell_scripts_tool
Crackmapexec_tool
Sessiongopher_tool
Mimipenguin_tool
Mimikittenz_tool
Rid_hijacking_tool
Randomps_scripts_tool
Rapperbot
Industry:
Telco
CVEs:
CVE-2022-26134 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- atlassian confluence data center (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
- atlassian confluence server (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
CVE-2022-22965 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- vmware spring framework (<5.3.18, <5.2.20)
- cisco cx cloud agent (<2.1.0)
- oracle sd-wan edge (9.0, 9.1)
- oracle retail xstore point of service (20.0.1, 21.0.0)
- oracle communications cloud native core security edge protection proxy (1.7.0, 22.1.0)
have more...
IOCs:
File: 1
Softs:
active directory, confluence
Platforms:
intel
05-08-2022
Mysterious threat actor TAC-040 used previously undetected Ljl Backdoor
https://securityaffairs.co/wordpress/134033/hacking/tac-040-ljl-backdoor.html
Actors/Campaigns:
Tac_040 (motivation: financially_motivated)
Threats:
Ljl_backdoor
Spring4shell
Xmrig_miner
Netripper_tool
Powersploit
Cmepowershell_scripts_tool
Crackmapexec_tool
Sessiongopher_tool
Mimipenguin_tool
Mimikittenz_tool
Rid_hijacking_tool
Randomps_scripts_tool
Rapperbot
Industry:
Telco
CVEs:
CVE-2022-26134 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- atlassian confluence data center (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
- atlassian confluence server (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
CVE-2022-22965 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- vmware spring framework (<5.3.18, <5.2.20)
- cisco cx cloud agent (<2.1.0)
- oracle sd-wan edge (9.0, 9.1)
- oracle retail xstore point of service (20.0.1, 21.0.0)
- oracle communications cloud native core security edge protection proxy (1.7.0, 22.1.0)
have more...
IOCs:
File: 1
Softs:
active directory, confluence
Platforms:
intel
Security Affairs
TAC-040 group used previously undetected Ljl Backdoor
A threat actor, tracked as TAC-040, exploited Atlassian Confluence flaw CVE-2022-26134 to deploy previously undetected Ljl Backdoor.
#ParsedReport
05-08-2022
X-FILES Stealer Evolution - An Analysis and Comparison Study. Introduction
https://www.zscaler.com/blogs/security-research/x-files-stealer-evolution-analysis-and-comparison-study
Threats:
Xfiles_stealer
Follina_vuln
Industry:
Financial
Geo:
Russian
TTPs:
Tactics: 2
Technics: 10
IOCs:
Domain: 5
IP: 1
Hash: 6
File: 4
Softs:
steam, nitro generator, discord, telegram, winscp
Algorithms:
zip , base64
05-08-2022
X-FILES Stealer Evolution - An Analysis and Comparison Study. Introduction
https://www.zscaler.com/blogs/security-research/x-files-stealer-evolution-analysis-and-comparison-study
Threats:
Xfiles_stealer
Follina_vuln
Industry:
Financial
Geo:
Russian
TTPs:
Tactics: 2
Technics: 10
IOCs:
Domain: 5
IP: 1
Hash: 6
File: 4
Softs:
steam, nitro generator, discord, telegram, winscp
Algorithms:
zip , base64
Zscaler
Analysis & Comparison of X-FILES Stealer Evolution | Zscaler
An analysis and comparison of X-FILES stealer variants, which have evolved with enhanced features to exfiltrate sensitive information.
#ParsedReport
05-08-2022
Say NO to Nopyfy!
https://labs.k7computing.com/index.php/say-no-to-nopyfy
Threats:
Nopyfy
Geo:
Russian
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 4
Url: 2
Hash: 1
Softs:
mysql
Algorithms:
base64, des, aes
Languages:
php
05-08-2022
Say NO to Nopyfy!
https://labs.k7computing.com/index.php/say-no-to-nopyfy
Threats:
Nopyfy
Geo:
Russian
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 4
Url: 2
Hash: 1
Softs:
mysql
Algorithms:
base64, des, aes
Languages:
php
K7 Labs
Say NO to Nopyfy! - K7 Labs
In the last week of July, we detected a ransomware named Nopyfy in our customer end. In August 2021, Nopyfy […]
#ParsedReport
05-08-2022
DGAOrchardDGA. The DGA family orchard continues to change, and the new version uses Bitcoin transaction information to generate DGA domain name
https://blog.netlab.360.com/orchard-dga
Threats:
Orchard_botnet
Enigma_tool
Xmrig_miner
Industry:
Financial
IOCs:
File: 7
Coin: 1
Hash: 3
Softs:
.net framework
Algorithms:
base64
Languages:
golang
05-08-2022
DGAOrchardDGA. The DGA family orchard continues to change, and the new version uses Bitcoin transaction information to generate DGA domain name
https://blog.netlab.360.com/orchard-dga
Threats:
Orchard_botnet
Enigma_tool
Xmrig_miner
Industry:
Financial
IOCs:
File: 7
Coin: 1
Hash: 3
Softs:
.net framework
Algorithms:
base64
Languages:
golang
360 Netlab Blog - Network Security Research Lab at 360
DGA家族Orchard持续变化,新版本用比特币交易信息生成DGA域名
DGA是一种经典的botnet对抗检测的技术,其原理是使用某种DGA算法,结合特定的种子和当前日期,定期生成大量的域名,而攻击者只是选择性的注册其中的极少数。对于防御者而言,因为难以事先确定哪些域名会被生成和注册,因而防御难度极大。
360 netlab长期专注于botnet攻防技术的研究,维护了专门的DGA算法和情报库,并通过订阅情报的方式与业界分享研究成果。近期我们在分析未知DGA域名时发现一例不但使用日期,还会同时使用中本聪的比特币账号交易信息来生成DGA域名的例子。因为比特币交易的不确定性,…
360 netlab长期专注于botnet攻防技术的研究,维护了专门的DGA算法和情报库,并通过订阅情报的方式与业界分享研究成果。近期我们在分析未知DGA域名时发现一例不但使用日期,还会同时使用中本聪的比特币账号交易信息来生成DGA域名的例子。因为比特币交易的不确定性,…
#ParsedReport
05-08-2022
Likely Iranian Threat Actor Conducts Politically Motivated Disruptive Activity Against Albanian Government Organizations
https://www.mandiant.com/resources/likely-iranian-threat-actor-conducts-politically-motivated-disruptive-activity-against
Actors/Campaigns:
Cleaver (motivation: cyber_espionage)
Axiom
Threats:
Roadsweep
Chimneysweep
Zeroclear
Dustman
Markirat
Mosesstaff
Metasploit_tool
Delf
Netstat_tool
Process_injection_technique
Timestomp_technique
Industry:
Government, Telco
Geo:
Lebanon, Kuwait, Israeli, Iran, Bahrain, Albania, Iranian
TTPs:
Tactics: 3
Technics: 19
IOCs:
Domain: 9
File: 12
Hash: 20
IP: 1
Path: 4
Coin: 1
Registry: 2
Softs:
telegram, windows service, windows registry
Algorithms:
base64, rc4
Functions:
GetProcAddress, FindNextFileW, DeviceIoControl, GetFileSize, FindFirstFileW, GetSystemDirectoryW, GetUpdates
Platforms:
x86
YARA: Found
Links:
05-08-2022
Likely Iranian Threat Actor Conducts Politically Motivated Disruptive Activity Against Albanian Government Organizations
https://www.mandiant.com/resources/likely-iranian-threat-actor-conducts-politically-motivated-disruptive-activity-against
Actors/Campaigns:
Cleaver (motivation: cyber_espionage)
Axiom
Threats:
Roadsweep
Chimneysweep
Zeroclear
Dustman
Markirat
Mosesstaff
Metasploit_tool
Delf
Netstat_tool
Process_injection_technique
Timestomp_technique
Industry:
Government, Telco
Geo:
Lebanon, Kuwait, Israeli, Iran, Bahrain, Albania, Iranian
TTPs:
Tactics: 3
Technics: 19
IOCs:
Domain: 9
File: 12
Hash: 20
IP: 1
Path: 4
Coin: 1
Registry: 2
Softs:
telegram, windows service, windows registry
Algorithms:
base64, rc4
Functions:
GetProcAddress, FindNextFileW, DeviceIoControl, GetFileSize, FindFirstFileW, GetSystemDirectoryW, GetUpdates
Platforms:
x86
YARA: Found
Links:
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/local/bypassuac\_silentcleanup.rbGoogle Cloud Blog
ROADSWEEP Ransomware Targets the Albanian Government | Google Cloud Blog
Mandiant identified the ROADSWEEP ransomware family which targeted the Albanian government in a politically motivated disruptive operation. Learn more.
CloudGuard Spectral detects several malicious packages on PyPI – the official software repository for Python developers
https://research.checkpoint.com/2022/cloudguard-spectral-detects-several-malicious-packages-on-pypi-the-official-software-repository-for-python-developers/
https://research.checkpoint.com/2022/cloudguard-spectral-detects-several-malicious-packages-on-pypi-the-official-software-repository-for-python-developers/
Check Point Research
CloudGuard Spectral detects several malicious packages on PyPI - the official software repository for Python developers - Check…
Highlights: CloudGuard Spectral detects 10 malicious packages on PyPI, the leading Python package index used by developers for the Python programming language Malicious packages install info-stealers that enable attackers to steal developer’s private data…
#technique
EntropyFix: a tool to reduce the entropy of your payload, It works By adding null bytes, in an ordered sequence: every 10 bytes it adds 5 null bytes. - designed to avoid high entropy detection technique
https://gitlab.com/ORCA000/entropyfix
EntropyFix: a tool to reduce the entropy of your payload, It works By adding null bytes, in an ordered sequence: every 10 bytes it adds 5 null bytes. - designed to avoid high entropy detection technique
https://gitlab.com/ORCA000/entropyfix
GitLab
ORCA / EntropyFix · GitLab
A tool with no ascii art that reduces the entropy of your payload
#ParsedReport
08-08-2022
Monero CoinMiner Being Distributed via Webhards
https://asec.ahnlab.com/en/37526
Threats:
Njrat_rat
Udprat
Xmrig_miner
Monero_miner
Trojan/win.fy.c5155016
Xmr_miner
Trojan/win.launcher.c5217400
Geo:
Korean
IOCs:
File: 5
Domain: 1
Coin: 1
Hash: 5
Url: 3
08-08-2022
Monero CoinMiner Being Distributed via Webhards
https://asec.ahnlab.com/en/37526
Threats:
Njrat_rat
Udprat
Xmrig_miner
Monero_miner
Trojan/win.fy.c5155016
Xmr_miner
Trojan/win.launcher.c5217400
Geo:
Korean
IOCs:
File: 5
Domain: 1
Coin: 1
Hash: 5
Url: 3
ASEC BLOG
Monero CoinMiner Being Distributed via Webhards - ASEC BLOG
Webhards are the main platforms that the attackers targeting Korean users exploit to distribute malware. The ASEC analysis team has been monitoring malware types distributed through webhards and uploaded multiple blog posts about them in the past. Generally…
#ParsedReport
08-08-2022
BumbleBee Roasts Its Way to Domain Admin. Case Summary
https://thedfirreport.com/2022/08/08/bumblebee-roasts-its-way-to-domain-admin
Actors/Campaigns:
Exotic_lily
Wizard_spider
Fin12
Threats:
Bumblebee
Bespoke
Cobalt_strike
Beacon
Adfind_tool
Vulnrecon_tool
Procdump_tool
Process_injection_technique
Kerberoasting_technique
Cyberchef_tool
Minidump_tool
Powerview
Anydesk_tool
Geo:
Usa
TTPs:
Tactics: 11
Technics: 26
IOCs:
File: 25
Path: 17
IP: 5
Domain: 3
Hash: 15
Softs:
android, anydesk, active directory, psexec, sysinternals
Algorithms:
zip , gzip, xor, base64, rc4
Functions:
Gunzip, CreateServiceA, OpenSSL, CreateRemoteThread
YARA: Found
SIGMA: Found
Links:
08-08-2022
BumbleBee Roasts Its Way to Domain Admin. Case Summary
https://thedfirreport.com/2022/08/08/bumblebee-roasts-its-way-to-domain-admin
Actors/Campaigns:
Exotic_lily
Wizard_spider
Fin12
Threats:
Bumblebee
Bespoke
Cobalt_strike
Beacon
Adfind_tool
Vulnrecon_tool
Procdump_tool
Process_injection_technique
Kerberoasting_technique
Cyberchef_tool
Minidump_tool
Powerview
Anydesk_tool
Geo:
Usa
TTPs:
Tactics: 11
Technics: 26
IOCs:
File: 25
Path: 17
IP: 5
Domain: 3
Hash: 15
Softs:
android, anydesk, active directory, psexec, sysinternals
Algorithms:
zip , gzip, xor, base64, rc4
Functions:
Gunzip, CreateServiceA, OpenSSL, CreateRemoteThread
YARA: Found
SIGMA: Found
Links:
https://github.com/GhostPack/Seatbelthttps://github.com/DidierStevens/DidierStevensSuite/blob/master/1768.pyThe DFIR Report
BumbleBee Roasts Its Way to Domain Admin - The DFIR Report
In this intrusion from April 2022, the threat actors used BumbleBee as the initial access vector. BumbleBee is a malware loader that was first reported by Google Threat Analysis Group in March 2022. Google TAG attributes this malware to an initial access…
#ParsedReport
08-08-2022
Linux Malware RapperBotBrute Forcing SSH Servers. Linux Malware RapperBot Brute Forcing SSH Servers
https://socradar.io/linux-malware-rapperbot-brute-forcing-ssh-servers
Actors/Campaigns:
Vice_society
Dawdropper
Threats:
Rapperbot
Mirai
Darkutilities_tool
Industry:
Financial, Iot
IOCs:
Hash: 26
Url: 19
IP: 4
Softs:
confluence
Platforms:
x86
08-08-2022
Linux Malware RapperBotBrute Forcing SSH Servers. Linux Malware RapperBot Brute Forcing SSH Servers
https://socradar.io/linux-malware-rapperbot-brute-forcing-ssh-servers
Actors/Campaigns:
Vice_society
Dawdropper
Threats:
Rapperbot
Mirai
Darkutilities_tool
Industry:
Financial, Iot
IOCs:
Hash: 26
Url: 19
IP: 4
Softs:
confluence
Platforms:
x86
SOCRadar® Cyber Intelligence Inc.
Linux Malware RapperBot Brute Forcing SSH Servers - SOCRadar
RapperBot is an IoT botnet malware that has spread through brute force since it was first identified in June 2022. Over 3,500 unique IPs...
#ParsedReport
08-08-2022
LogoKit update The phishing kit leveraging Open Redirect Vulnerabilities
https://resecurity.com/blog/article/logokit-update-the-phishing-kit-leveraging-open-redirect-vulnerabilities
Actors/Campaigns:
Blackcat
Threats:
Logokit_tool
Blackcat
Industry:
E-commerce, Financial
Geo:
Usa, America
IOCs:
Url: 3
Email: 1
Domain: 6
Softs:
microsoft office
Algorithms:
base64
Languages:
javascript
08-08-2022
LogoKit update The phishing kit leveraging Open Redirect Vulnerabilities
https://resecurity.com/blog/article/logokit-update-the-phishing-kit-leveraging-open-redirect-vulnerabilities
Actors/Campaigns:
Blackcat
Threats:
Logokit_tool
Blackcat
Industry:
E-commerce, Financial
Geo:
Usa, America
IOCs:
Url: 3
Email: 1
Domain: 6
Softs:
microsoft office
Algorithms:
base64
Languages:
javascript
#ParsedReport
08-08-2022
A new Pro Russian hacking group Heawsnet has shared a list of countries that will be on their target
https://www.thetechoutlook.com/news/technology/security/a-new-pro-russian-hacking-group-heawsnet-has-shared-a-list-of-countries-that-will-be-on-their-target
Actors/Campaigns:
Heawsnet
Threats:
Uroburos
Industry:
Government, Financial
Geo:
Iceland, Russian, Ukraines, Taiwan, Usa, Japan, Switzerland, Micronesia, Australia, Andorra, Liechtenstein, Singapore, Russia, Macedonia, Norway, Ukraine, Albania, Ukrainians, Canada, Korea, Ukrainian, Montenegro, Monaco
08-08-2022
A new Pro Russian hacking group Heawsnet has shared a list of countries that will be on their target
https://www.thetechoutlook.com/news/technology/security/a-new-pro-russian-hacking-group-heawsnet-has-shared-a-list-of-countries-that-will-be-on-their-target
Actors/Campaigns:
Heawsnet
Threats:
Uroburos
Industry:
Government, Financial
Geo:
Iceland, Russian, Ukraines, Taiwan, Usa, Japan, Switzerland, Micronesia, Australia, Andorra, Liechtenstein, Singapore, Russia, Macedonia, Norway, Ukraine, Albania, Ukrainians, Canada, Korea, Ukrainian, Montenegro, Monaco
The Tech Outlook
A new Pro Russian hacking group Heawsnet has shared a list of countries that will be on their target
Cyberwarfare has been a factor in the conflict between Russia and Ukraine since the collapse of the Soviet Union in 1991. Although the Ukrainian government and private sector’s computer systems were initially attacked in 2013 during widespread protests, the…
#ParsedReport
08-08-2022
Targeted attack on industrial enterprises and public institutions
https://ics-cert.kaspersky.com/publications/reports/2022/08/08/targeted-attack-on-industrial-enterprises-and-public-institutions
Actors/Campaigns:
Ta428
Threats:
Portdoor
Ncctrojan
Cotx_rat
Dnsep
Logtu
Cotsam
Ladon_tool
Dll_hijacking_technique
Process_hollowing_technique
Shadowpad
Nbtscan_tool
Netstat_tool
Golden_ticket_technique
Apost
Dllhijacker
Backdoor.win32.agent.myuhpj
Backdoor.win32.agentb.ca
Backdoor.win32.agentb.cc
Backdoor.win64.agent.iwv
Backdoor.win64.agent.iwy
Backdoor.win64.agent.iwz
Backdoor.win64.agent.ixl
Backdoor.win64.agent.ixm
Trojan.win32.agentb.kpkq
Trojan.win64.agent.qwhymc
Trojan.win64.agent.qwhypj
Trojan.win64.agentb.bdq
Trojan.win64.agentb.bse
Trojan.win64.agentb.bsf
Industry:
Government, Ics
Geo:
China, Afghanistan, Belarus, Chinese, Ukraine, Russia
CVEs:
CVE-2017-11882 [Vulners]
Vulners: Score: 9.3, CVSS: 4.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2013, 2010, 2016, 2007)
TTPs:
Tactics: 1
Technics: 0
IOCs:
Path: 194
File: 18
IP: 6
Hash: 67
Registry: 3
Domain: 12
Softs:
microsoft office, microsoft word, active directory, task scheduler
Algorithms:
aes-256, zip , xor, aes
Functions:
GetNativeSystemInfo, WriteProcessMemory, GetTickCount
Platforms:
intel
08-08-2022
Targeted attack on industrial enterprises and public institutions
https://ics-cert.kaspersky.com/publications/reports/2022/08/08/targeted-attack-on-industrial-enterprises-and-public-institutions
Actors/Campaigns:
Ta428
Threats:
Portdoor
Ncctrojan
Cotx_rat
Dnsep
Logtu
Cotsam
Ladon_tool
Dll_hijacking_technique
Process_hollowing_technique
Shadowpad
Nbtscan_tool
Netstat_tool
Golden_ticket_technique
Apost
Dllhijacker
Backdoor.win32.agent.myuhpj
Backdoor.win32.agentb.ca
Backdoor.win32.agentb.cc
Backdoor.win64.agent.iwv
Backdoor.win64.agent.iwy
Backdoor.win64.agent.iwz
Backdoor.win64.agent.ixl
Backdoor.win64.agent.ixm
Trojan.win32.agentb.kpkq
Trojan.win64.agent.qwhymc
Trojan.win64.agent.qwhypj
Trojan.win64.agentb.bdq
Trojan.win64.agentb.bse
Trojan.win64.agentb.bsf
Industry:
Government, Ics
Geo:
China, Afghanistan, Belarus, Chinese, Ukraine, Russia
CVEs:
CVE-2017-11882 [Vulners]
Vulners: Score: 9.3, CVSS: 4.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2013, 2010, 2016, 2007)
TTPs:
Tactics: 1
Technics: 0
IOCs:
Path: 194
File: 18
IP: 6
Hash: 67
Registry: 3
Domain: 12
Softs:
microsoft office, microsoft word, active directory, task scheduler
Algorithms:
aes-256, zip , xor, aes
Functions:
GetNativeSystemInfo, WriteProcessMemory, GetTickCount
Platforms:
intel
Kaspersky ICS CERT | Kaspersky Industrial Control Systems Cyber Emergency Response Team
Targeted attack on industrial enterprises and public institutions | Kaspersky ICS CERT
The attackers were able to penetrate dozens of enterprises and even hijack the IT infrastructure of some, taking control of systems used to manage security solutions. The goal of this series of attacks was cyberespionage.
#technique
Rundll32: The Infamous Proxy for Executing Malicious Code
https://www.cybereason.com/blog/rundll32-the-infamous-proxy-for-executing-malicious-code
Rundll32: The Infamous Proxy for Executing Malicious Code
https://www.cybereason.com/blog/rundll32-the-infamous-proxy-for-executing-malicious-code
Cybereason
Rundll32: The Infamous Proxy for Executing Malicious Code
Take a deeper dive into an often abused Microsoft-signed tool, the infamous rundll32.exe, which allows adversaries to execute malicious code during their offensive operations through a technique which we explain in detail...
#ParsedReport
09-08-2022
Andariel deploys DTrack and Maui ransomware
https://securelist.com/andariel-deploys-dtrack-and-maui-ransomware/107063
Actors/Campaigns:
Lazarus (motivation: financially_motivated, cyber_espionage)
Threats:
Mauicrypt
Dtrack_rat
Netstat_tool
Industry:
Healthcare, Financial
Geo:
Korean, Russia, India, Japanese, Vietnam, Japan
CVEs:
CVE-2017-10271 [Vulners]
Vulners: Score: 5.0, CVSS: 2.7,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- oracle weblogic server (10.3.6.0.0, 12.2.1.1.0, 12.1.3.0.0, 12.2.1.2.0)
IOCs:
Path: 6
IP: 1
File: 2
Hash: 8
Url: 2
Softs:
3proxy
Platforms:
intel
09-08-2022
Andariel deploys DTrack and Maui ransomware
https://securelist.com/andariel-deploys-dtrack-and-maui-ransomware/107063
Actors/Campaigns:
Lazarus (motivation: financially_motivated, cyber_espionage)
Threats:
Mauicrypt
Dtrack_rat
Netstat_tool
Industry:
Healthcare, Financial
Geo:
Korean, Russia, India, Japanese, Vietnam, Japan
CVEs:
CVE-2017-10271 [Vulners]
Vulners: Score: 5.0, CVSS: 2.7,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- oracle weblogic server (10.3.6.0.0, 12.2.1.1.0, 12.1.3.0.0, 12.2.1.2.0)
IOCs:
Path: 6
IP: 1
File: 2
Hash: 8
Url: 2
Softs:
3proxy
Platforms:
intel
Securelist
Andariel deploys DTrack and Maui ransomware
Earlier, the CISA published an alert related to a Stairwell report, “Maui Ransomware.” Our data should openly help solidify the attribution of the Maui ransomware incident to the Korean-speaking APT Andariel.
#ParsedReport
09-08-2022
Novel News on Cuba Ransomware aka Greetings From Tropical Scorpius
https://unit42.paloaltonetworks.com/cuba-ransomware-tropical-scorpius
Actors/Campaigns:
Unc2596
Lapsus
Threats:
Cuba
Romcom_rat
Kerbercache_tool
Zerologon_vuln
Hancitor
Proxyshell_vuln
Proxylogon_exploit
Maze
Revil
Lockbit
Burntcigar_tool
Adfind_tool
Kerberoasting_technique
Mimikatz
Themida_tool
Qakbot
Beacon
Pid_spoofing_technique
Process_injection_technique
Industry:
Government, Financial, Education, E-commerce, Transport, Retail, Logistic, Healthcare, Energy
Geo:
Emea, Japan, Apac, America
CVEs:
CVE-2022-24521 [Vulners]
Vulners: Score: 4.6, CVSS: 4.2,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (-, 20h2, 21h1, 21h2, 1607, 1809, 1909)
- microsoft windows 11 (-, -)
- microsoft windows 7 (-)
- microsoft windows 8.1 (-)
- microsoft windows rt 8.1 (-)
have more...
CVE-2020-1472 [Vulners]
Vulners: Score: 9.3, CVSS: 3.8,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2)
- microsoft windows server 2012 (-, r2)
- microsoft windows server 2016 (-, 1903, 1909, 2004)
- microsoft windows server 2019 (-)
- fedoraproject fedora (31, 32, 33)
have more...
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 21
Coin: 5
Domain: 3
Email: 2
IP: 2
Path: 1
Hash: 16
Softs:
sqlbrowser, task scheduler, active directory, microsoft exchange, sqlagent, mysql
Algorithms:
chacha, rsa-4096, zip
Functions:
GetUserSPNs, CreateProcessA, the, MmGetSystemRoutineAddress, LsaLookupAuthenticationPackage, PsGetThreadProcess, IcmpCreateFile, LsaCallAuthenticationPackage, IcmpSendEcho, PsIsThreadTerminating, PsLookupThreadByThreadId
Platforms:
x86
09-08-2022
Novel News on Cuba Ransomware aka Greetings From Tropical Scorpius
https://unit42.paloaltonetworks.com/cuba-ransomware-tropical-scorpius
Actors/Campaigns:
Unc2596
Lapsus
Threats:
Cuba
Romcom_rat
Kerbercache_tool
Zerologon_vuln
Hancitor
Proxyshell_vuln
Proxylogon_exploit
Maze
Revil
Lockbit
Burntcigar_tool
Adfind_tool
Kerberoasting_technique
Mimikatz
Themida_tool
Qakbot
Beacon
Pid_spoofing_technique
Process_injection_technique
Industry:
Government, Financial, Education, E-commerce, Transport, Retail, Logistic, Healthcare, Energy
Geo:
Emea, Japan, Apac, America
CVEs:
CVE-2022-24521 [Vulners]
Vulners: Score: 4.6, CVSS: 4.2,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (-, 20h2, 21h1, 21h2, 1607, 1809, 1909)
- microsoft windows 11 (-, -)
- microsoft windows 7 (-)
- microsoft windows 8.1 (-)
- microsoft windows rt 8.1 (-)
have more...
CVE-2020-1472 [Vulners]
Vulners: Score: 9.3, CVSS: 3.8,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2)
- microsoft windows server 2012 (-, r2)
- microsoft windows server 2016 (-, 1903, 1909, 2004)
- microsoft windows server 2019 (-)
- fedoraproject fedora (31, 32, 33)
have more...
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 21
Coin: 5
Domain: 3
Email: 2
IP: 2
Path: 1
Hash: 16
Softs:
sqlbrowser, task scheduler, active directory, microsoft exchange, sqlagent, mysql
Algorithms:
chacha, rsa-4096, zip
Functions:
GetUserSPNs, CreateProcessA, the, MmGetSystemRoutineAddress, LsaLookupAuthenticationPackage, PsGetThreadProcess, IcmpCreateFile, LsaCallAuthenticationPackage, IcmpSendEcho, PsIsThreadTerminating, PsLookupThreadByThreadId
Platforms:
x86
Unit 42
Novel News on Cuba Ransomware: Greetings From Tropical Scorpius
Tropical Scorpius has been deploying Cuba Ransomware using novel tools and techniques, such as a new malware family, ROMCOM RAT.
#ParsedReport
09-08-2022
Global scam operation "Classiscam" expanded toSingapore. Global scam operation "Classiscam" expanded to Singapore
https://www.group-ib.com/media/classiscam-singapore-global-scam-operation
Threats:
Classiscam
Industry:
Education, Foodtech, Financial, E-commerce
Geo:
Singapore, Asia, Dubai, Russian, Pacific, Asian, Russia
Softs:
telegram
09-08-2022
Global scam operation "Classiscam" expanded toSingapore. Global scam operation "Classiscam" expanded to Singapore
https://www.group-ib.com/media/classiscam-singapore-global-scam-operation
Threats:
Classiscam
Industry:
Education, Foodtech, Financial, E-commerce
Geo:
Singapore, Asia, Dubai, Russian, Pacific, Asian, Russia
Softs:
telegram
Group-IB
Global scam operation "Classiscam" expanded to Singapore
Group-IB has uncovered that Classiscam a sophisticated scam-as-a-service operation has expanded to Singapore in March 2022.