#ParsedReport
05-08-2022
Mysterious threat actor TAC-040 used previously undetected Ljl Backdoor
https://securityaffairs.co/wordpress/134033/hacking/tac-040-ljl-backdoor.html
Actors/Campaigns:
Tac_040 (motivation: financially_motivated)
Threats:
Ljl_backdoor
Spring4shell
Xmrig_miner
Netripper_tool
Powersploit
Cmepowershell_scripts_tool
Crackmapexec_tool
Sessiongopher_tool
Mimipenguin_tool
Mimikittenz_tool
Rid_hijacking_tool
Randomps_scripts_tool
Rapperbot
Industry:
Telco
CVEs:
CVE-2022-26134 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- atlassian confluence data center (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
- atlassian confluence server (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
CVE-2022-22965 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- vmware spring framework (<5.3.18, <5.2.20)
- cisco cx cloud agent (<2.1.0)
- oracle sd-wan edge (9.0, 9.1)
- oracle retail xstore point of service (20.0.1, 21.0.0)
- oracle communications cloud native core security edge protection proxy (1.7.0, 22.1.0)
have more...
IOCs:
File: 1
Softs:
active directory, confluence
Platforms:
intel
05-08-2022
Mysterious threat actor TAC-040 used previously undetected Ljl Backdoor
https://securityaffairs.co/wordpress/134033/hacking/tac-040-ljl-backdoor.html
Actors/Campaigns:
Tac_040 (motivation: financially_motivated)
Threats:
Ljl_backdoor
Spring4shell
Xmrig_miner
Netripper_tool
Powersploit
Cmepowershell_scripts_tool
Crackmapexec_tool
Sessiongopher_tool
Mimipenguin_tool
Mimikittenz_tool
Rid_hijacking_tool
Randomps_scripts_tool
Rapperbot
Industry:
Telco
CVEs:
CVE-2022-26134 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- atlassian confluence data center (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
- atlassian confluence server (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
CVE-2022-22965 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- vmware spring framework (<5.3.18, <5.2.20)
- cisco cx cloud agent (<2.1.0)
- oracle sd-wan edge (9.0, 9.1)
- oracle retail xstore point of service (20.0.1, 21.0.0)
- oracle communications cloud native core security edge protection proxy (1.7.0, 22.1.0)
have more...
IOCs:
File: 1
Softs:
active directory, confluence
Platforms:
intel
Security Affairs
TAC-040 group used previously undetected Ljl Backdoor
A threat actor, tracked as TAC-040, exploited Atlassian Confluence flaw CVE-2022-26134 to deploy previously undetected Ljl Backdoor.
#ParsedReport
05-08-2022
X-FILES Stealer Evolution - An Analysis and Comparison Study. Introduction
https://www.zscaler.com/blogs/security-research/x-files-stealer-evolution-analysis-and-comparison-study
Threats:
Xfiles_stealer
Follina_vuln
Industry:
Financial
Geo:
Russian
TTPs:
Tactics: 2
Technics: 10
IOCs:
Domain: 5
IP: 1
Hash: 6
File: 4
Softs:
steam, nitro generator, discord, telegram, winscp
Algorithms:
zip , base64
05-08-2022
X-FILES Stealer Evolution - An Analysis and Comparison Study. Introduction
https://www.zscaler.com/blogs/security-research/x-files-stealer-evolution-analysis-and-comparison-study
Threats:
Xfiles_stealer
Follina_vuln
Industry:
Financial
Geo:
Russian
TTPs:
Tactics: 2
Technics: 10
IOCs:
Domain: 5
IP: 1
Hash: 6
File: 4
Softs:
steam, nitro generator, discord, telegram, winscp
Algorithms:
zip , base64
Zscaler
Analysis & Comparison of X-FILES Stealer Evolution | Zscaler
An analysis and comparison of X-FILES stealer variants, which have evolved with enhanced features to exfiltrate sensitive information.
#ParsedReport
05-08-2022
Say NO to Nopyfy!
https://labs.k7computing.com/index.php/say-no-to-nopyfy
Threats:
Nopyfy
Geo:
Russian
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 4
Url: 2
Hash: 1
Softs:
mysql
Algorithms:
base64, des, aes
Languages:
php
05-08-2022
Say NO to Nopyfy!
https://labs.k7computing.com/index.php/say-no-to-nopyfy
Threats:
Nopyfy
Geo:
Russian
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 4
Url: 2
Hash: 1
Softs:
mysql
Algorithms:
base64, des, aes
Languages:
php
K7 Labs
Say NO to Nopyfy! - K7 Labs
In the last week of July, we detected a ransomware named Nopyfy in our customer end. In August 2021, Nopyfy […]
#ParsedReport
05-08-2022
DGAOrchardDGA. The DGA family orchard continues to change, and the new version uses Bitcoin transaction information to generate DGA domain name
https://blog.netlab.360.com/orchard-dga
Threats:
Orchard_botnet
Enigma_tool
Xmrig_miner
Industry:
Financial
IOCs:
File: 7
Coin: 1
Hash: 3
Softs:
.net framework
Algorithms:
base64
Languages:
golang
05-08-2022
DGAOrchardDGA. The DGA family orchard continues to change, and the new version uses Bitcoin transaction information to generate DGA domain name
https://blog.netlab.360.com/orchard-dga
Threats:
Orchard_botnet
Enigma_tool
Xmrig_miner
Industry:
Financial
IOCs:
File: 7
Coin: 1
Hash: 3
Softs:
.net framework
Algorithms:
base64
Languages:
golang
360 Netlab Blog - Network Security Research Lab at 360
DGA家族Orchard持续变化,新版本用比特币交易信息生成DGA域名
DGA是一种经典的botnet对抗检测的技术,其原理是使用某种DGA算法,结合特定的种子和当前日期,定期生成大量的域名,而攻击者只是选择性的注册其中的极少数。对于防御者而言,因为难以事先确定哪些域名会被生成和注册,因而防御难度极大。
360 netlab长期专注于botnet攻防技术的研究,维护了专门的DGA算法和情报库,并通过订阅情报的方式与业界分享研究成果。近期我们在分析未知DGA域名时发现一例不但使用日期,还会同时使用中本聪的比特币账号交易信息来生成DGA域名的例子。因为比特币交易的不确定性,…
360 netlab长期专注于botnet攻防技术的研究,维护了专门的DGA算法和情报库,并通过订阅情报的方式与业界分享研究成果。近期我们在分析未知DGA域名时发现一例不但使用日期,还会同时使用中本聪的比特币账号交易信息来生成DGA域名的例子。因为比特币交易的不确定性,…
#ParsedReport
05-08-2022
Likely Iranian Threat Actor Conducts Politically Motivated Disruptive Activity Against Albanian Government Organizations
https://www.mandiant.com/resources/likely-iranian-threat-actor-conducts-politically-motivated-disruptive-activity-against
Actors/Campaigns:
Cleaver (motivation: cyber_espionage)
Axiom
Threats:
Roadsweep
Chimneysweep
Zeroclear
Dustman
Markirat
Mosesstaff
Metasploit_tool
Delf
Netstat_tool
Process_injection_technique
Timestomp_technique
Industry:
Government, Telco
Geo:
Lebanon, Kuwait, Israeli, Iran, Bahrain, Albania, Iranian
TTPs:
Tactics: 3
Technics: 19
IOCs:
Domain: 9
File: 12
Hash: 20
IP: 1
Path: 4
Coin: 1
Registry: 2
Softs:
telegram, windows service, windows registry
Algorithms:
base64, rc4
Functions:
GetProcAddress, FindNextFileW, DeviceIoControl, GetFileSize, FindFirstFileW, GetSystemDirectoryW, GetUpdates
Platforms:
x86
YARA: Found
Links:
05-08-2022
Likely Iranian Threat Actor Conducts Politically Motivated Disruptive Activity Against Albanian Government Organizations
https://www.mandiant.com/resources/likely-iranian-threat-actor-conducts-politically-motivated-disruptive-activity-against
Actors/Campaigns:
Cleaver (motivation: cyber_espionage)
Axiom
Threats:
Roadsweep
Chimneysweep
Zeroclear
Dustman
Markirat
Mosesstaff
Metasploit_tool
Delf
Netstat_tool
Process_injection_technique
Timestomp_technique
Industry:
Government, Telco
Geo:
Lebanon, Kuwait, Israeli, Iran, Bahrain, Albania, Iranian
TTPs:
Tactics: 3
Technics: 19
IOCs:
Domain: 9
File: 12
Hash: 20
IP: 1
Path: 4
Coin: 1
Registry: 2
Softs:
telegram, windows service, windows registry
Algorithms:
base64, rc4
Functions:
GetProcAddress, FindNextFileW, DeviceIoControl, GetFileSize, FindFirstFileW, GetSystemDirectoryW, GetUpdates
Platforms:
x86
YARA: Found
Links:
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/local/bypassuac\_silentcleanup.rbGoogle Cloud Blog
ROADSWEEP Ransomware Targets the Albanian Government | Google Cloud Blog
Mandiant identified the ROADSWEEP ransomware family which targeted the Albanian government in a politically motivated disruptive operation. Learn more.
CloudGuard Spectral detects several malicious packages on PyPI – the official software repository for Python developers
https://research.checkpoint.com/2022/cloudguard-spectral-detects-several-malicious-packages-on-pypi-the-official-software-repository-for-python-developers/
https://research.checkpoint.com/2022/cloudguard-spectral-detects-several-malicious-packages-on-pypi-the-official-software-repository-for-python-developers/
Check Point Research
CloudGuard Spectral detects several malicious packages on PyPI - the official software repository for Python developers - Check…
Highlights: CloudGuard Spectral detects 10 malicious packages on PyPI, the leading Python package index used by developers for the Python programming language Malicious packages install info-stealers that enable attackers to steal developer’s private data…
#technique
EntropyFix: a tool to reduce the entropy of your payload, It works By adding null bytes, in an ordered sequence: every 10 bytes it adds 5 null bytes. - designed to avoid high entropy detection technique
https://gitlab.com/ORCA000/entropyfix
EntropyFix: a tool to reduce the entropy of your payload, It works By adding null bytes, in an ordered sequence: every 10 bytes it adds 5 null bytes. - designed to avoid high entropy detection technique
https://gitlab.com/ORCA000/entropyfix
GitLab
ORCA / EntropyFix · GitLab
A tool with no ascii art that reduces the entropy of your payload
#ParsedReport
08-08-2022
Monero CoinMiner Being Distributed via Webhards
https://asec.ahnlab.com/en/37526
Threats:
Njrat_rat
Udprat
Xmrig_miner
Monero_miner
Trojan/win.fy.c5155016
Xmr_miner
Trojan/win.launcher.c5217400
Geo:
Korean
IOCs:
File: 5
Domain: 1
Coin: 1
Hash: 5
Url: 3
08-08-2022
Monero CoinMiner Being Distributed via Webhards
https://asec.ahnlab.com/en/37526
Threats:
Njrat_rat
Udprat
Xmrig_miner
Monero_miner
Trojan/win.fy.c5155016
Xmr_miner
Trojan/win.launcher.c5217400
Geo:
Korean
IOCs:
File: 5
Domain: 1
Coin: 1
Hash: 5
Url: 3
ASEC BLOG
Monero CoinMiner Being Distributed via Webhards - ASEC BLOG
Webhards are the main platforms that the attackers targeting Korean users exploit to distribute malware. The ASEC analysis team has been monitoring malware types distributed through webhards and uploaded multiple blog posts about them in the past. Generally…
#ParsedReport
08-08-2022
BumbleBee Roasts Its Way to Domain Admin. Case Summary
https://thedfirreport.com/2022/08/08/bumblebee-roasts-its-way-to-domain-admin
Actors/Campaigns:
Exotic_lily
Wizard_spider
Fin12
Threats:
Bumblebee
Bespoke
Cobalt_strike
Beacon
Adfind_tool
Vulnrecon_tool
Procdump_tool
Process_injection_technique
Kerberoasting_technique
Cyberchef_tool
Minidump_tool
Powerview
Anydesk_tool
Geo:
Usa
TTPs:
Tactics: 11
Technics: 26
IOCs:
File: 25
Path: 17
IP: 5
Domain: 3
Hash: 15
Softs:
android, anydesk, active directory, psexec, sysinternals
Algorithms:
zip , gzip, xor, base64, rc4
Functions:
Gunzip, CreateServiceA, OpenSSL, CreateRemoteThread
YARA: Found
SIGMA: Found
Links:
08-08-2022
BumbleBee Roasts Its Way to Domain Admin. Case Summary
https://thedfirreport.com/2022/08/08/bumblebee-roasts-its-way-to-domain-admin
Actors/Campaigns:
Exotic_lily
Wizard_spider
Fin12
Threats:
Bumblebee
Bespoke
Cobalt_strike
Beacon
Adfind_tool
Vulnrecon_tool
Procdump_tool
Process_injection_technique
Kerberoasting_technique
Cyberchef_tool
Minidump_tool
Powerview
Anydesk_tool
Geo:
Usa
TTPs:
Tactics: 11
Technics: 26
IOCs:
File: 25
Path: 17
IP: 5
Domain: 3
Hash: 15
Softs:
android, anydesk, active directory, psexec, sysinternals
Algorithms:
zip , gzip, xor, base64, rc4
Functions:
Gunzip, CreateServiceA, OpenSSL, CreateRemoteThread
YARA: Found
SIGMA: Found
Links:
https://github.com/GhostPack/Seatbelthttps://github.com/DidierStevens/DidierStevensSuite/blob/master/1768.pyThe DFIR Report
BumbleBee Roasts Its Way to Domain Admin - The DFIR Report
In this intrusion from April 2022, the threat actors used BumbleBee as the initial access vector. BumbleBee is a malware loader that was first reported by Google Threat Analysis Group in March 2022. Google TAG attributes this malware to an initial access…
#ParsedReport
08-08-2022
Linux Malware RapperBotBrute Forcing SSH Servers. Linux Malware RapperBot Brute Forcing SSH Servers
https://socradar.io/linux-malware-rapperbot-brute-forcing-ssh-servers
Actors/Campaigns:
Vice_society
Dawdropper
Threats:
Rapperbot
Mirai
Darkutilities_tool
Industry:
Financial, Iot
IOCs:
Hash: 26
Url: 19
IP: 4
Softs:
confluence
Platforms:
x86
08-08-2022
Linux Malware RapperBotBrute Forcing SSH Servers. Linux Malware RapperBot Brute Forcing SSH Servers
https://socradar.io/linux-malware-rapperbot-brute-forcing-ssh-servers
Actors/Campaigns:
Vice_society
Dawdropper
Threats:
Rapperbot
Mirai
Darkutilities_tool
Industry:
Financial, Iot
IOCs:
Hash: 26
Url: 19
IP: 4
Softs:
confluence
Platforms:
x86
SOCRadar® Cyber Intelligence Inc.
Linux Malware RapperBot Brute Forcing SSH Servers - SOCRadar
RapperBot is an IoT botnet malware that has spread through brute force since it was first identified in June 2022. Over 3,500 unique IPs...
#ParsedReport
08-08-2022
LogoKit update The phishing kit leveraging Open Redirect Vulnerabilities
https://resecurity.com/blog/article/logokit-update-the-phishing-kit-leveraging-open-redirect-vulnerabilities
Actors/Campaigns:
Blackcat
Threats:
Logokit_tool
Blackcat
Industry:
E-commerce, Financial
Geo:
Usa, America
IOCs:
Url: 3
Email: 1
Domain: 6
Softs:
microsoft office
Algorithms:
base64
Languages:
javascript
08-08-2022
LogoKit update The phishing kit leveraging Open Redirect Vulnerabilities
https://resecurity.com/blog/article/logokit-update-the-phishing-kit-leveraging-open-redirect-vulnerabilities
Actors/Campaigns:
Blackcat
Threats:
Logokit_tool
Blackcat
Industry:
E-commerce, Financial
Geo:
Usa, America
IOCs:
Url: 3
Email: 1
Domain: 6
Softs:
microsoft office
Algorithms:
base64
Languages:
javascript
#ParsedReport
08-08-2022
A new Pro Russian hacking group Heawsnet has shared a list of countries that will be on their target
https://www.thetechoutlook.com/news/technology/security/a-new-pro-russian-hacking-group-heawsnet-has-shared-a-list-of-countries-that-will-be-on-their-target
Actors/Campaigns:
Heawsnet
Threats:
Uroburos
Industry:
Government, Financial
Geo:
Iceland, Russian, Ukraines, Taiwan, Usa, Japan, Switzerland, Micronesia, Australia, Andorra, Liechtenstein, Singapore, Russia, Macedonia, Norway, Ukraine, Albania, Ukrainians, Canada, Korea, Ukrainian, Montenegro, Monaco
08-08-2022
A new Pro Russian hacking group Heawsnet has shared a list of countries that will be on their target
https://www.thetechoutlook.com/news/technology/security/a-new-pro-russian-hacking-group-heawsnet-has-shared-a-list-of-countries-that-will-be-on-their-target
Actors/Campaigns:
Heawsnet
Threats:
Uroburos
Industry:
Government, Financial
Geo:
Iceland, Russian, Ukraines, Taiwan, Usa, Japan, Switzerland, Micronesia, Australia, Andorra, Liechtenstein, Singapore, Russia, Macedonia, Norway, Ukraine, Albania, Ukrainians, Canada, Korea, Ukrainian, Montenegro, Monaco
The Tech Outlook
A new Pro Russian hacking group Heawsnet has shared a list of countries that will be on their target
Cyberwarfare has been a factor in the conflict between Russia and Ukraine since the collapse of the Soviet Union in 1991. Although the Ukrainian government and private sector’s computer systems were initially attacked in 2013 during widespread protests, the…
#ParsedReport
08-08-2022
Targeted attack on industrial enterprises and public institutions
https://ics-cert.kaspersky.com/publications/reports/2022/08/08/targeted-attack-on-industrial-enterprises-and-public-institutions
Actors/Campaigns:
Ta428
Threats:
Portdoor
Ncctrojan
Cotx_rat
Dnsep
Logtu
Cotsam
Ladon_tool
Dll_hijacking_technique
Process_hollowing_technique
Shadowpad
Nbtscan_tool
Netstat_tool
Golden_ticket_technique
Apost
Dllhijacker
Backdoor.win32.agent.myuhpj
Backdoor.win32.agentb.ca
Backdoor.win32.agentb.cc
Backdoor.win64.agent.iwv
Backdoor.win64.agent.iwy
Backdoor.win64.agent.iwz
Backdoor.win64.agent.ixl
Backdoor.win64.agent.ixm
Trojan.win32.agentb.kpkq
Trojan.win64.agent.qwhymc
Trojan.win64.agent.qwhypj
Trojan.win64.agentb.bdq
Trojan.win64.agentb.bse
Trojan.win64.agentb.bsf
Industry:
Government, Ics
Geo:
China, Afghanistan, Belarus, Chinese, Ukraine, Russia
CVEs:
CVE-2017-11882 [Vulners]
Vulners: Score: 9.3, CVSS: 4.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2013, 2010, 2016, 2007)
TTPs:
Tactics: 1
Technics: 0
IOCs:
Path: 194
File: 18
IP: 6
Hash: 67
Registry: 3
Domain: 12
Softs:
microsoft office, microsoft word, active directory, task scheduler
Algorithms:
aes-256, zip , xor, aes
Functions:
GetNativeSystemInfo, WriteProcessMemory, GetTickCount
Platforms:
intel
08-08-2022
Targeted attack on industrial enterprises and public institutions
https://ics-cert.kaspersky.com/publications/reports/2022/08/08/targeted-attack-on-industrial-enterprises-and-public-institutions
Actors/Campaigns:
Ta428
Threats:
Portdoor
Ncctrojan
Cotx_rat
Dnsep
Logtu
Cotsam
Ladon_tool
Dll_hijacking_technique
Process_hollowing_technique
Shadowpad
Nbtscan_tool
Netstat_tool
Golden_ticket_technique
Apost
Dllhijacker
Backdoor.win32.agent.myuhpj
Backdoor.win32.agentb.ca
Backdoor.win32.agentb.cc
Backdoor.win64.agent.iwv
Backdoor.win64.agent.iwy
Backdoor.win64.agent.iwz
Backdoor.win64.agent.ixl
Backdoor.win64.agent.ixm
Trojan.win32.agentb.kpkq
Trojan.win64.agent.qwhymc
Trojan.win64.agent.qwhypj
Trojan.win64.agentb.bdq
Trojan.win64.agentb.bse
Trojan.win64.agentb.bsf
Industry:
Government, Ics
Geo:
China, Afghanistan, Belarus, Chinese, Ukraine, Russia
CVEs:
CVE-2017-11882 [Vulners]
Vulners: Score: 9.3, CVSS: 4.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2013, 2010, 2016, 2007)
TTPs:
Tactics: 1
Technics: 0
IOCs:
Path: 194
File: 18
IP: 6
Hash: 67
Registry: 3
Domain: 12
Softs:
microsoft office, microsoft word, active directory, task scheduler
Algorithms:
aes-256, zip , xor, aes
Functions:
GetNativeSystemInfo, WriteProcessMemory, GetTickCount
Platforms:
intel
Kaspersky ICS CERT | Kaspersky Industrial Control Systems Cyber Emergency Response Team
Targeted attack on industrial enterprises and public institutions | Kaspersky ICS CERT
The attackers were able to penetrate dozens of enterprises and even hijack the IT infrastructure of some, taking control of systems used to manage security solutions. The goal of this series of attacks was cyberespionage.
#technique
Rundll32: The Infamous Proxy for Executing Malicious Code
https://www.cybereason.com/blog/rundll32-the-infamous-proxy-for-executing-malicious-code
Rundll32: The Infamous Proxy for Executing Malicious Code
https://www.cybereason.com/blog/rundll32-the-infamous-proxy-for-executing-malicious-code
Cybereason
Rundll32: The Infamous Proxy for Executing Malicious Code
Take a deeper dive into an often abused Microsoft-signed tool, the infamous rundll32.exe, which allows adversaries to execute malicious code during their offensive operations through a technique which we explain in detail...
#ParsedReport
09-08-2022
Andariel deploys DTrack and Maui ransomware
https://securelist.com/andariel-deploys-dtrack-and-maui-ransomware/107063
Actors/Campaigns:
Lazarus (motivation: financially_motivated, cyber_espionage)
Threats:
Mauicrypt
Dtrack_rat
Netstat_tool
Industry:
Healthcare, Financial
Geo:
Korean, Russia, India, Japanese, Vietnam, Japan
CVEs:
CVE-2017-10271 [Vulners]
Vulners: Score: 5.0, CVSS: 2.7,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- oracle weblogic server (10.3.6.0.0, 12.2.1.1.0, 12.1.3.0.0, 12.2.1.2.0)
IOCs:
Path: 6
IP: 1
File: 2
Hash: 8
Url: 2
Softs:
3proxy
Platforms:
intel
09-08-2022
Andariel deploys DTrack and Maui ransomware
https://securelist.com/andariel-deploys-dtrack-and-maui-ransomware/107063
Actors/Campaigns:
Lazarus (motivation: financially_motivated, cyber_espionage)
Threats:
Mauicrypt
Dtrack_rat
Netstat_tool
Industry:
Healthcare, Financial
Geo:
Korean, Russia, India, Japanese, Vietnam, Japan
CVEs:
CVE-2017-10271 [Vulners]
Vulners: Score: 5.0, CVSS: 2.7,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- oracle weblogic server (10.3.6.0.0, 12.2.1.1.0, 12.1.3.0.0, 12.2.1.2.0)
IOCs:
Path: 6
IP: 1
File: 2
Hash: 8
Url: 2
Softs:
3proxy
Platforms:
intel
Securelist
Andariel deploys DTrack and Maui ransomware
Earlier, the CISA published an alert related to a Stairwell report, “Maui Ransomware.” Our data should openly help solidify the attribution of the Maui ransomware incident to the Korean-speaking APT Andariel.
#ParsedReport
09-08-2022
Novel News on Cuba Ransomware aka Greetings From Tropical Scorpius
https://unit42.paloaltonetworks.com/cuba-ransomware-tropical-scorpius
Actors/Campaigns:
Unc2596
Lapsus
Threats:
Cuba
Romcom_rat
Kerbercache_tool
Zerologon_vuln
Hancitor
Proxyshell_vuln
Proxylogon_exploit
Maze
Revil
Lockbit
Burntcigar_tool
Adfind_tool
Kerberoasting_technique
Mimikatz
Themida_tool
Qakbot
Beacon
Pid_spoofing_technique
Process_injection_technique
Industry:
Government, Financial, Education, E-commerce, Transport, Retail, Logistic, Healthcare, Energy
Geo:
Emea, Japan, Apac, America
CVEs:
CVE-2022-24521 [Vulners]
Vulners: Score: 4.6, CVSS: 4.2,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (-, 20h2, 21h1, 21h2, 1607, 1809, 1909)
- microsoft windows 11 (-, -)
- microsoft windows 7 (-)
- microsoft windows 8.1 (-)
- microsoft windows rt 8.1 (-)
have more...
CVE-2020-1472 [Vulners]
Vulners: Score: 9.3, CVSS: 3.8,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2)
- microsoft windows server 2012 (-, r2)
- microsoft windows server 2016 (-, 1903, 1909, 2004)
- microsoft windows server 2019 (-)
- fedoraproject fedora (31, 32, 33)
have more...
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 21
Coin: 5
Domain: 3
Email: 2
IP: 2
Path: 1
Hash: 16
Softs:
sqlbrowser, task scheduler, active directory, microsoft exchange, sqlagent, mysql
Algorithms:
chacha, rsa-4096, zip
Functions:
GetUserSPNs, CreateProcessA, the, MmGetSystemRoutineAddress, LsaLookupAuthenticationPackage, PsGetThreadProcess, IcmpCreateFile, LsaCallAuthenticationPackage, IcmpSendEcho, PsIsThreadTerminating, PsLookupThreadByThreadId
Platforms:
x86
09-08-2022
Novel News on Cuba Ransomware aka Greetings From Tropical Scorpius
https://unit42.paloaltonetworks.com/cuba-ransomware-tropical-scorpius
Actors/Campaigns:
Unc2596
Lapsus
Threats:
Cuba
Romcom_rat
Kerbercache_tool
Zerologon_vuln
Hancitor
Proxyshell_vuln
Proxylogon_exploit
Maze
Revil
Lockbit
Burntcigar_tool
Adfind_tool
Kerberoasting_technique
Mimikatz
Themida_tool
Qakbot
Beacon
Pid_spoofing_technique
Process_injection_technique
Industry:
Government, Financial, Education, E-commerce, Transport, Retail, Logistic, Healthcare, Energy
Geo:
Emea, Japan, Apac, America
CVEs:
CVE-2022-24521 [Vulners]
Vulners: Score: 4.6, CVSS: 4.2,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (-, 20h2, 21h1, 21h2, 1607, 1809, 1909)
- microsoft windows 11 (-, -)
- microsoft windows 7 (-)
- microsoft windows 8.1 (-)
- microsoft windows rt 8.1 (-)
have more...
CVE-2020-1472 [Vulners]
Vulners: Score: 9.3, CVSS: 3.8,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2)
- microsoft windows server 2012 (-, r2)
- microsoft windows server 2016 (-, 1903, 1909, 2004)
- microsoft windows server 2019 (-)
- fedoraproject fedora (31, 32, 33)
have more...
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 21
Coin: 5
Domain: 3
Email: 2
IP: 2
Path: 1
Hash: 16
Softs:
sqlbrowser, task scheduler, active directory, microsoft exchange, sqlagent, mysql
Algorithms:
chacha, rsa-4096, zip
Functions:
GetUserSPNs, CreateProcessA, the, MmGetSystemRoutineAddress, LsaLookupAuthenticationPackage, PsGetThreadProcess, IcmpCreateFile, LsaCallAuthenticationPackage, IcmpSendEcho, PsIsThreadTerminating, PsLookupThreadByThreadId
Platforms:
x86
Unit 42
Novel News on Cuba Ransomware: Greetings From Tropical Scorpius
Tropical Scorpius has been deploying Cuba Ransomware using novel tools and techniques, such as a new malware family, ROMCOM RAT.
#ParsedReport
09-08-2022
Global scam operation "Classiscam" expanded toSingapore. Global scam operation "Classiscam" expanded to Singapore
https://www.group-ib.com/media/classiscam-singapore-global-scam-operation
Threats:
Classiscam
Industry:
Education, Foodtech, Financial, E-commerce
Geo:
Singapore, Asia, Dubai, Russian, Pacific, Asian, Russia
Softs:
telegram
09-08-2022
Global scam operation "Classiscam" expanded toSingapore. Global scam operation "Classiscam" expanded to Singapore
https://www.group-ib.com/media/classiscam-singapore-global-scam-operation
Threats:
Classiscam
Industry:
Education, Foodtech, Financial, E-commerce
Geo:
Singapore, Asia, Dubai, Russian, Pacific, Asian, Russia
Softs:
telegram
Group-IB
Global scam operation "Classiscam" expanded to Singapore
Group-IB has uncovered that Classiscam a sophisticated scam-as-a-service operation has expanded to Singapore in March 2022.
#ParsedReport
09-08-2022
CotSam, Never Before Seen Malware linked to TA428 involved in EU attack
https://www.secureblink.com/threat-research/cot-sam-never-before-seen-malware-linked-to-ta-428-involved-in-eu-attack
Actors/Campaigns:
Ta428
Threats:
Cotsam
Cotx_rat
Dll_hijacking_technique
Shadowpad
Nbtscan_tool
Ladon_tool
Netstat_tool
Golden_ticket_technique
Industry:
Government
Geo:
Chinese, Afghanistan
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 10
Hash: 1
Registry: 3
Path: 2
Softs:
task scheduler, active directory, microsoft word
Algorithms:
xor
Functions:
WriteProcessMemory
09-08-2022
CotSam, Never Before Seen Malware linked to TA428 involved in EU attack
https://www.secureblink.com/threat-research/cot-sam-never-before-seen-malware-linked-to-ta-428-involved-in-eu-attack
Actors/Campaigns:
Ta428
Threats:
Cotsam
Cotx_rat
Dll_hijacking_technique
Shadowpad
Nbtscan_tool
Ladon_tool
Netstat_tool
Golden_ticket_technique
Industry:
Government
Geo:
Chinese, Afghanistan
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 10
Hash: 1
Registry: 3
Path: 2
Softs:
task scheduler, active directory, microsoft word
Algorithms:
xor
Functions:
WriteProcessMemory
Secureblink
CotSam, Never Before Seen Malware linked to TA428 involved in EU attack | Secure Blink
CotSam: a never seen before malware strain involved in the targeted attacks across several European & Afghanistan institutions linked to infamous APT group TA428...
#ParsedReport
09-08-2022
Life After DeathSmokeLoader Continues to Haunt Using Old Vulnerabilities
https://www.fortinet.com/blog/threat-research/smokeloader-using-old-vulnerabilities
Threats:
Smokeloader
Trickbot
Quasar_rat
Velvetsweatshop_technique
Vba/agent.bmw!tr.dldr
Industry:
Transport, Financial, Telco
Geo:
Chinese, Taiwan
CVEs:
CVE-2017-11882 [Vulners]
Vulners: Score: 9.3, CVSS: 4.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2013, 2010, 2016, 2007)
CVE-2017-0199 [Vulners]
Vulners: Score: 9.3, CVSS: 7.8,
Vulners: Exploitation: True
X-Force: Risk: 9.3
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2, *)
- microsoft windows server 2012 (-)
- microsoft windows vista (*)
- microsoft office (2010, 2013, 2016, 2007)
- microsoft windows 7 (*)
have more...
IOCs:
IP: 1
File: 2
Domain: 3
Hash: 5
Softs:
microsoft word
Algorithms:
gzip
09-08-2022
Life After DeathSmokeLoader Continues to Haunt Using Old Vulnerabilities
https://www.fortinet.com/blog/threat-research/smokeloader-using-old-vulnerabilities
Threats:
Smokeloader
Trickbot
Quasar_rat
Velvetsweatshop_technique
Vba/agent.bmw!tr.dldr
Industry:
Transport, Financial, Telco
Geo:
Chinese, Taiwan
CVEs:
CVE-2017-11882 [Vulners]
Vulners: Score: 9.3, CVSS: 4.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2013, 2010, 2016, 2007)
CVE-2017-0199 [Vulners]
Vulners: Score: 9.3, CVSS: 7.8,
Vulners: Exploitation: True
X-Force: Risk: 9.3
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2, *)
- microsoft windows server 2012 (-)
- microsoft windows vista (*)
- microsoft office (2010, 2013, 2016, 2007)
- microsoft windows 7 (*)
have more...
IOCs:
IP: 1
File: 2
Domain: 3
Hash: 5
Softs:
microsoft word
Algorithms:
gzip
Fortinet Blog
Life After Death—SmokeLoader Continues to Haunt Using Old Vulnerabilities
FortiGuard Labs examines SmokeLoader, a malware variant that exploits CVE-2017-0199 and CVE-2017-11882 in its deployment chain. Read our analysis blog to learn about the latest sample.…
#ParsedReport
09-08-2022
Bitter APT group using Dracarys Android Spyware
https://blog.cyble.com/2022/08/09/bitter-apt-group-using-dracarys-android-spyware
Actors/Campaigns:
Bitter
Threats:
Dracarys
Industry:
Financial
Geo:
Asia, Pakistan, India, Asian, China
TTPs:
Tactics: 3
Technics: 0
IOCs:
File: 1
Url: 4
Hash: 3
Softs:
android, telegram
09-08-2022
Bitter APT group using Dracarys Android Spyware
https://blog.cyble.com/2022/08/09/bitter-apt-group-using-dracarys-android-spyware
Actors/Campaigns:
Bitter
Threats:
Dracarys
Industry:
Financial
Geo:
Asia, Pakistan, India, Asian, China
TTPs:
Tactics: 3
Technics: 0
IOCs:
File: 1
Url: 4
Hash: 3
Softs:
android, telegram
Cyble
Cyble - Bitter APT Group Using "Dracarys" Android Spyware
Cyble analyzes the Bitter APT group leveraging trojanized Messaging Apps to deliver Dracarys Android Malware.
#ParsedReport
09-08-2022
Pivoting on a SharpExt to profile Kimusky panels for great good. Older Campaigns
https://medium.com/walmartglobaltech/pivoting-on-a-sharpext-to-profile-kimusky-panels-for-great-good-1920dc1bcef9
Actors/Campaigns:
Kimsuky
Threats:
Sharpext
Geo:
Korea
IOCs:
Url: 1
File: 32
Domain: 1
Hash: 38
Path: 1
Registry: 14
09-08-2022
Pivoting on a SharpExt to profile Kimusky panels for great good. Older Campaigns
https://medium.com/walmartglobaltech/pivoting-on-a-sharpext-to-profile-kimusky-panels-for-great-good-1920dc1bcef9
Actors/Campaigns:
Kimsuky
Threats:
Sharpext
Geo:
Korea
IOCs:
Url: 1
File: 32
Domain: 1
Hash: 38
Path: 1
Registry: 14
Medium
Pivoting on a SharpExt to profile Kimusky panels for great good
By: Jason Reaves and Joshua Platt