#ParsedReport
05-08-2022
Likely Iranian Threat Actor Conducts Politically Motivated Disruptive Activity Against Albanian Government Organizations
https://www.mandiant.com/resources/likely-iranian-threat-actor-conducts-politically-motivated-disruptive-activity-against
Actors/Campaigns:
Cleaver (motivation: cyber_espionage)
Axiom
Threats:
Roadsweep
Chimneysweep
Zeroclear
Dustman
Markirat
Mosesstaff
Metasploit_tool
Delf
Netstat_tool
Process_injection_technique
Timestomp_technique
Industry:
Government, Telco
Geo:
Lebanon, Kuwait, Israeli, Iran, Bahrain, Albania, Iranian
TTPs:
Tactics: 3
Technics: 19
IOCs:
Domain: 9
File: 12
Hash: 20
IP: 1
Path: 4
Coin: 1
Registry: 2
Softs:
telegram, windows service, windows registry
Algorithms:
base64, rc4
Functions:
GetProcAddress, FindNextFileW, DeviceIoControl, GetFileSize, FindFirstFileW, GetSystemDirectoryW, GetUpdates
Platforms:
x86
YARA: Found
Links:
05-08-2022
Likely Iranian Threat Actor Conducts Politically Motivated Disruptive Activity Against Albanian Government Organizations
https://www.mandiant.com/resources/likely-iranian-threat-actor-conducts-politically-motivated-disruptive-activity-against
Actors/Campaigns:
Cleaver (motivation: cyber_espionage)
Axiom
Threats:
Roadsweep
Chimneysweep
Zeroclear
Dustman
Markirat
Mosesstaff
Metasploit_tool
Delf
Netstat_tool
Process_injection_technique
Timestomp_technique
Industry:
Government, Telco
Geo:
Lebanon, Kuwait, Israeli, Iran, Bahrain, Albania, Iranian
TTPs:
Tactics: 3
Technics: 19
IOCs:
Domain: 9
File: 12
Hash: 20
IP: 1
Path: 4
Coin: 1
Registry: 2
Softs:
telegram, windows service, windows registry
Algorithms:
base64, rc4
Functions:
GetProcAddress, FindNextFileW, DeviceIoControl, GetFileSize, FindFirstFileW, GetSystemDirectoryW, GetUpdates
Platforms:
x86
YARA: Found
Links:
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/local/bypassuac\_silentcleanup.rbGoogle Cloud Blog
ROADSWEEP Ransomware Targets the Albanian Government | Google Cloud Blog
Mandiant identified the ROADSWEEP ransomware family which targeted the Albanian government in a politically motivated disruptive operation. Learn more.
CloudGuard Spectral detects several malicious packages on PyPI – the official software repository for Python developers
https://research.checkpoint.com/2022/cloudguard-spectral-detects-several-malicious-packages-on-pypi-the-official-software-repository-for-python-developers/
https://research.checkpoint.com/2022/cloudguard-spectral-detects-several-malicious-packages-on-pypi-the-official-software-repository-for-python-developers/
Check Point Research
CloudGuard Spectral detects several malicious packages on PyPI - the official software repository for Python developers - Check…
Highlights: CloudGuard Spectral detects 10 malicious packages on PyPI, the leading Python package index used by developers for the Python programming language Malicious packages install info-stealers that enable attackers to steal developer’s private data…
#technique
EntropyFix: a tool to reduce the entropy of your payload, It works By adding null bytes, in an ordered sequence: every 10 bytes it adds 5 null bytes. - designed to avoid high entropy detection technique
https://gitlab.com/ORCA000/entropyfix
EntropyFix: a tool to reduce the entropy of your payload, It works By adding null bytes, in an ordered sequence: every 10 bytes it adds 5 null bytes. - designed to avoid high entropy detection technique
https://gitlab.com/ORCA000/entropyfix
GitLab
ORCA / EntropyFix · GitLab
A tool with no ascii art that reduces the entropy of your payload
#ParsedReport
08-08-2022
Monero CoinMiner Being Distributed via Webhards
https://asec.ahnlab.com/en/37526
Threats:
Njrat_rat
Udprat
Xmrig_miner
Monero_miner
Trojan/win.fy.c5155016
Xmr_miner
Trojan/win.launcher.c5217400
Geo:
Korean
IOCs:
File: 5
Domain: 1
Coin: 1
Hash: 5
Url: 3
08-08-2022
Monero CoinMiner Being Distributed via Webhards
https://asec.ahnlab.com/en/37526
Threats:
Njrat_rat
Udprat
Xmrig_miner
Monero_miner
Trojan/win.fy.c5155016
Xmr_miner
Trojan/win.launcher.c5217400
Geo:
Korean
IOCs:
File: 5
Domain: 1
Coin: 1
Hash: 5
Url: 3
ASEC BLOG
Monero CoinMiner Being Distributed via Webhards - ASEC BLOG
Webhards are the main platforms that the attackers targeting Korean users exploit to distribute malware. The ASEC analysis team has been monitoring malware types distributed through webhards and uploaded multiple blog posts about them in the past. Generally…
#ParsedReport
08-08-2022
BumbleBee Roasts Its Way to Domain Admin. Case Summary
https://thedfirreport.com/2022/08/08/bumblebee-roasts-its-way-to-domain-admin
Actors/Campaigns:
Exotic_lily
Wizard_spider
Fin12
Threats:
Bumblebee
Bespoke
Cobalt_strike
Beacon
Adfind_tool
Vulnrecon_tool
Procdump_tool
Process_injection_technique
Kerberoasting_technique
Cyberchef_tool
Minidump_tool
Powerview
Anydesk_tool
Geo:
Usa
TTPs:
Tactics: 11
Technics: 26
IOCs:
File: 25
Path: 17
IP: 5
Domain: 3
Hash: 15
Softs:
android, anydesk, active directory, psexec, sysinternals
Algorithms:
zip , gzip, xor, base64, rc4
Functions:
Gunzip, CreateServiceA, OpenSSL, CreateRemoteThread
YARA: Found
SIGMA: Found
Links:
08-08-2022
BumbleBee Roasts Its Way to Domain Admin. Case Summary
https://thedfirreport.com/2022/08/08/bumblebee-roasts-its-way-to-domain-admin
Actors/Campaigns:
Exotic_lily
Wizard_spider
Fin12
Threats:
Bumblebee
Bespoke
Cobalt_strike
Beacon
Adfind_tool
Vulnrecon_tool
Procdump_tool
Process_injection_technique
Kerberoasting_technique
Cyberchef_tool
Minidump_tool
Powerview
Anydesk_tool
Geo:
Usa
TTPs:
Tactics: 11
Technics: 26
IOCs:
File: 25
Path: 17
IP: 5
Domain: 3
Hash: 15
Softs:
android, anydesk, active directory, psexec, sysinternals
Algorithms:
zip , gzip, xor, base64, rc4
Functions:
Gunzip, CreateServiceA, OpenSSL, CreateRemoteThread
YARA: Found
SIGMA: Found
Links:
https://github.com/GhostPack/Seatbelthttps://github.com/DidierStevens/DidierStevensSuite/blob/master/1768.pyThe DFIR Report
BumbleBee Roasts Its Way to Domain Admin - The DFIR Report
In this intrusion from April 2022, the threat actors used BumbleBee as the initial access vector. BumbleBee is a malware loader that was first reported by Google Threat Analysis Group in March 2022. Google TAG attributes this malware to an initial access…
#ParsedReport
08-08-2022
Linux Malware RapperBotBrute Forcing SSH Servers. Linux Malware RapperBot Brute Forcing SSH Servers
https://socradar.io/linux-malware-rapperbot-brute-forcing-ssh-servers
Actors/Campaigns:
Vice_society
Dawdropper
Threats:
Rapperbot
Mirai
Darkutilities_tool
Industry:
Financial, Iot
IOCs:
Hash: 26
Url: 19
IP: 4
Softs:
confluence
Platforms:
x86
08-08-2022
Linux Malware RapperBotBrute Forcing SSH Servers. Linux Malware RapperBot Brute Forcing SSH Servers
https://socradar.io/linux-malware-rapperbot-brute-forcing-ssh-servers
Actors/Campaigns:
Vice_society
Dawdropper
Threats:
Rapperbot
Mirai
Darkutilities_tool
Industry:
Financial, Iot
IOCs:
Hash: 26
Url: 19
IP: 4
Softs:
confluence
Platforms:
x86
SOCRadar® Cyber Intelligence Inc.
Linux Malware RapperBot Brute Forcing SSH Servers - SOCRadar
RapperBot is an IoT botnet malware that has spread through brute force since it was first identified in June 2022. Over 3,500 unique IPs...
#ParsedReport
08-08-2022
LogoKit update The phishing kit leveraging Open Redirect Vulnerabilities
https://resecurity.com/blog/article/logokit-update-the-phishing-kit-leveraging-open-redirect-vulnerabilities
Actors/Campaigns:
Blackcat
Threats:
Logokit_tool
Blackcat
Industry:
E-commerce, Financial
Geo:
Usa, America
IOCs:
Url: 3
Email: 1
Domain: 6
Softs:
microsoft office
Algorithms:
base64
Languages:
javascript
08-08-2022
LogoKit update The phishing kit leveraging Open Redirect Vulnerabilities
https://resecurity.com/blog/article/logokit-update-the-phishing-kit-leveraging-open-redirect-vulnerabilities
Actors/Campaigns:
Blackcat
Threats:
Logokit_tool
Blackcat
Industry:
E-commerce, Financial
Geo:
Usa, America
IOCs:
Url: 3
Email: 1
Domain: 6
Softs:
microsoft office
Algorithms:
base64
Languages:
javascript
#ParsedReport
08-08-2022
A new Pro Russian hacking group Heawsnet has shared a list of countries that will be on their target
https://www.thetechoutlook.com/news/technology/security/a-new-pro-russian-hacking-group-heawsnet-has-shared-a-list-of-countries-that-will-be-on-their-target
Actors/Campaigns:
Heawsnet
Threats:
Uroburos
Industry:
Government, Financial
Geo:
Iceland, Russian, Ukraines, Taiwan, Usa, Japan, Switzerland, Micronesia, Australia, Andorra, Liechtenstein, Singapore, Russia, Macedonia, Norway, Ukraine, Albania, Ukrainians, Canada, Korea, Ukrainian, Montenegro, Monaco
08-08-2022
A new Pro Russian hacking group Heawsnet has shared a list of countries that will be on their target
https://www.thetechoutlook.com/news/technology/security/a-new-pro-russian-hacking-group-heawsnet-has-shared-a-list-of-countries-that-will-be-on-their-target
Actors/Campaigns:
Heawsnet
Threats:
Uroburos
Industry:
Government, Financial
Geo:
Iceland, Russian, Ukraines, Taiwan, Usa, Japan, Switzerland, Micronesia, Australia, Andorra, Liechtenstein, Singapore, Russia, Macedonia, Norway, Ukraine, Albania, Ukrainians, Canada, Korea, Ukrainian, Montenegro, Monaco
The Tech Outlook
A new Pro Russian hacking group Heawsnet has shared a list of countries that will be on their target
Cyberwarfare has been a factor in the conflict between Russia and Ukraine since the collapse of the Soviet Union in 1991. Although the Ukrainian government and private sector’s computer systems were initially attacked in 2013 during widespread protests, the…
#ParsedReport
08-08-2022
Targeted attack on industrial enterprises and public institutions
https://ics-cert.kaspersky.com/publications/reports/2022/08/08/targeted-attack-on-industrial-enterprises-and-public-institutions
Actors/Campaigns:
Ta428
Threats:
Portdoor
Ncctrojan
Cotx_rat
Dnsep
Logtu
Cotsam
Ladon_tool
Dll_hijacking_technique
Process_hollowing_technique
Shadowpad
Nbtscan_tool
Netstat_tool
Golden_ticket_technique
Apost
Dllhijacker
Backdoor.win32.agent.myuhpj
Backdoor.win32.agentb.ca
Backdoor.win32.agentb.cc
Backdoor.win64.agent.iwv
Backdoor.win64.agent.iwy
Backdoor.win64.agent.iwz
Backdoor.win64.agent.ixl
Backdoor.win64.agent.ixm
Trojan.win32.agentb.kpkq
Trojan.win64.agent.qwhymc
Trojan.win64.agent.qwhypj
Trojan.win64.agentb.bdq
Trojan.win64.agentb.bse
Trojan.win64.agentb.bsf
Industry:
Government, Ics
Geo:
China, Afghanistan, Belarus, Chinese, Ukraine, Russia
CVEs:
CVE-2017-11882 [Vulners]
Vulners: Score: 9.3, CVSS: 4.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2013, 2010, 2016, 2007)
TTPs:
Tactics: 1
Technics: 0
IOCs:
Path: 194
File: 18
IP: 6
Hash: 67
Registry: 3
Domain: 12
Softs:
microsoft office, microsoft word, active directory, task scheduler
Algorithms:
aes-256, zip , xor, aes
Functions:
GetNativeSystemInfo, WriteProcessMemory, GetTickCount
Platforms:
intel
08-08-2022
Targeted attack on industrial enterprises and public institutions
https://ics-cert.kaspersky.com/publications/reports/2022/08/08/targeted-attack-on-industrial-enterprises-and-public-institutions
Actors/Campaigns:
Ta428
Threats:
Portdoor
Ncctrojan
Cotx_rat
Dnsep
Logtu
Cotsam
Ladon_tool
Dll_hijacking_technique
Process_hollowing_technique
Shadowpad
Nbtscan_tool
Netstat_tool
Golden_ticket_technique
Apost
Dllhijacker
Backdoor.win32.agent.myuhpj
Backdoor.win32.agentb.ca
Backdoor.win32.agentb.cc
Backdoor.win64.agent.iwv
Backdoor.win64.agent.iwy
Backdoor.win64.agent.iwz
Backdoor.win64.agent.ixl
Backdoor.win64.agent.ixm
Trojan.win32.agentb.kpkq
Trojan.win64.agent.qwhymc
Trojan.win64.agent.qwhypj
Trojan.win64.agentb.bdq
Trojan.win64.agentb.bse
Trojan.win64.agentb.bsf
Industry:
Government, Ics
Geo:
China, Afghanistan, Belarus, Chinese, Ukraine, Russia
CVEs:
CVE-2017-11882 [Vulners]
Vulners: Score: 9.3, CVSS: 4.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2013, 2010, 2016, 2007)
TTPs:
Tactics: 1
Technics: 0
IOCs:
Path: 194
File: 18
IP: 6
Hash: 67
Registry: 3
Domain: 12
Softs:
microsoft office, microsoft word, active directory, task scheduler
Algorithms:
aes-256, zip , xor, aes
Functions:
GetNativeSystemInfo, WriteProcessMemory, GetTickCount
Platforms:
intel
Kaspersky ICS CERT | Kaspersky Industrial Control Systems Cyber Emergency Response Team
Targeted attack on industrial enterprises and public institutions | Kaspersky ICS CERT
The attackers were able to penetrate dozens of enterprises and even hijack the IT infrastructure of some, taking control of systems used to manage security solutions. The goal of this series of attacks was cyberespionage.
#technique
Rundll32: The Infamous Proxy for Executing Malicious Code
https://www.cybereason.com/blog/rundll32-the-infamous-proxy-for-executing-malicious-code
Rundll32: The Infamous Proxy for Executing Malicious Code
https://www.cybereason.com/blog/rundll32-the-infamous-proxy-for-executing-malicious-code
Cybereason
Rundll32: The Infamous Proxy for Executing Malicious Code
Take a deeper dive into an often abused Microsoft-signed tool, the infamous rundll32.exe, which allows adversaries to execute malicious code during their offensive operations through a technique which we explain in detail...
#ParsedReport
09-08-2022
Andariel deploys DTrack and Maui ransomware
https://securelist.com/andariel-deploys-dtrack-and-maui-ransomware/107063
Actors/Campaigns:
Lazarus (motivation: financially_motivated, cyber_espionage)
Threats:
Mauicrypt
Dtrack_rat
Netstat_tool
Industry:
Healthcare, Financial
Geo:
Korean, Russia, India, Japanese, Vietnam, Japan
CVEs:
CVE-2017-10271 [Vulners]
Vulners: Score: 5.0, CVSS: 2.7,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- oracle weblogic server (10.3.6.0.0, 12.2.1.1.0, 12.1.3.0.0, 12.2.1.2.0)
IOCs:
Path: 6
IP: 1
File: 2
Hash: 8
Url: 2
Softs:
3proxy
Platforms:
intel
09-08-2022
Andariel deploys DTrack and Maui ransomware
https://securelist.com/andariel-deploys-dtrack-and-maui-ransomware/107063
Actors/Campaigns:
Lazarus (motivation: financially_motivated, cyber_espionage)
Threats:
Mauicrypt
Dtrack_rat
Netstat_tool
Industry:
Healthcare, Financial
Geo:
Korean, Russia, India, Japanese, Vietnam, Japan
CVEs:
CVE-2017-10271 [Vulners]
Vulners: Score: 5.0, CVSS: 2.7,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- oracle weblogic server (10.3.6.0.0, 12.2.1.1.0, 12.1.3.0.0, 12.2.1.2.0)
IOCs:
Path: 6
IP: 1
File: 2
Hash: 8
Url: 2
Softs:
3proxy
Platforms:
intel
Securelist
Andariel deploys DTrack and Maui ransomware
Earlier, the CISA published an alert related to a Stairwell report, “Maui Ransomware.” Our data should openly help solidify the attribution of the Maui ransomware incident to the Korean-speaking APT Andariel.
#ParsedReport
09-08-2022
Novel News on Cuba Ransomware aka Greetings From Tropical Scorpius
https://unit42.paloaltonetworks.com/cuba-ransomware-tropical-scorpius
Actors/Campaigns:
Unc2596
Lapsus
Threats:
Cuba
Romcom_rat
Kerbercache_tool
Zerologon_vuln
Hancitor
Proxyshell_vuln
Proxylogon_exploit
Maze
Revil
Lockbit
Burntcigar_tool
Adfind_tool
Kerberoasting_technique
Mimikatz
Themida_tool
Qakbot
Beacon
Pid_spoofing_technique
Process_injection_technique
Industry:
Government, Financial, Education, E-commerce, Transport, Retail, Logistic, Healthcare, Energy
Geo:
Emea, Japan, Apac, America
CVEs:
CVE-2022-24521 [Vulners]
Vulners: Score: 4.6, CVSS: 4.2,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (-, 20h2, 21h1, 21h2, 1607, 1809, 1909)
- microsoft windows 11 (-, -)
- microsoft windows 7 (-)
- microsoft windows 8.1 (-)
- microsoft windows rt 8.1 (-)
have more...
CVE-2020-1472 [Vulners]
Vulners: Score: 9.3, CVSS: 3.8,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2)
- microsoft windows server 2012 (-, r2)
- microsoft windows server 2016 (-, 1903, 1909, 2004)
- microsoft windows server 2019 (-)
- fedoraproject fedora (31, 32, 33)
have more...
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 21
Coin: 5
Domain: 3
Email: 2
IP: 2
Path: 1
Hash: 16
Softs:
sqlbrowser, task scheduler, active directory, microsoft exchange, sqlagent, mysql
Algorithms:
chacha, rsa-4096, zip
Functions:
GetUserSPNs, CreateProcessA, the, MmGetSystemRoutineAddress, LsaLookupAuthenticationPackage, PsGetThreadProcess, IcmpCreateFile, LsaCallAuthenticationPackage, IcmpSendEcho, PsIsThreadTerminating, PsLookupThreadByThreadId
Platforms:
x86
09-08-2022
Novel News on Cuba Ransomware aka Greetings From Tropical Scorpius
https://unit42.paloaltonetworks.com/cuba-ransomware-tropical-scorpius
Actors/Campaigns:
Unc2596
Lapsus
Threats:
Cuba
Romcom_rat
Kerbercache_tool
Zerologon_vuln
Hancitor
Proxyshell_vuln
Proxylogon_exploit
Maze
Revil
Lockbit
Burntcigar_tool
Adfind_tool
Kerberoasting_technique
Mimikatz
Themida_tool
Qakbot
Beacon
Pid_spoofing_technique
Process_injection_technique
Industry:
Government, Financial, Education, E-commerce, Transport, Retail, Logistic, Healthcare, Energy
Geo:
Emea, Japan, Apac, America
CVEs:
CVE-2022-24521 [Vulners]
Vulners: Score: 4.6, CVSS: 4.2,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (-, 20h2, 21h1, 21h2, 1607, 1809, 1909)
- microsoft windows 11 (-, -)
- microsoft windows 7 (-)
- microsoft windows 8.1 (-)
- microsoft windows rt 8.1 (-)
have more...
CVE-2020-1472 [Vulners]
Vulners: Score: 9.3, CVSS: 3.8,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2)
- microsoft windows server 2012 (-, r2)
- microsoft windows server 2016 (-, 1903, 1909, 2004)
- microsoft windows server 2019 (-)
- fedoraproject fedora (31, 32, 33)
have more...
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 21
Coin: 5
Domain: 3
Email: 2
IP: 2
Path: 1
Hash: 16
Softs:
sqlbrowser, task scheduler, active directory, microsoft exchange, sqlagent, mysql
Algorithms:
chacha, rsa-4096, zip
Functions:
GetUserSPNs, CreateProcessA, the, MmGetSystemRoutineAddress, LsaLookupAuthenticationPackage, PsGetThreadProcess, IcmpCreateFile, LsaCallAuthenticationPackage, IcmpSendEcho, PsIsThreadTerminating, PsLookupThreadByThreadId
Platforms:
x86
Unit 42
Novel News on Cuba Ransomware: Greetings From Tropical Scorpius
Tropical Scorpius has been deploying Cuba Ransomware using novel tools and techniques, such as a new malware family, ROMCOM RAT.
#ParsedReport
09-08-2022
Global scam operation "Classiscam" expanded toSingapore. Global scam operation "Classiscam" expanded to Singapore
https://www.group-ib.com/media/classiscam-singapore-global-scam-operation
Threats:
Classiscam
Industry:
Education, Foodtech, Financial, E-commerce
Geo:
Singapore, Asia, Dubai, Russian, Pacific, Asian, Russia
Softs:
telegram
09-08-2022
Global scam operation "Classiscam" expanded toSingapore. Global scam operation "Classiscam" expanded to Singapore
https://www.group-ib.com/media/classiscam-singapore-global-scam-operation
Threats:
Classiscam
Industry:
Education, Foodtech, Financial, E-commerce
Geo:
Singapore, Asia, Dubai, Russian, Pacific, Asian, Russia
Softs:
telegram
Group-IB
Global scam operation "Classiscam" expanded to Singapore
Group-IB has uncovered that Classiscam a sophisticated scam-as-a-service operation has expanded to Singapore in March 2022.
#ParsedReport
09-08-2022
CotSam, Never Before Seen Malware linked to TA428 involved in EU attack
https://www.secureblink.com/threat-research/cot-sam-never-before-seen-malware-linked-to-ta-428-involved-in-eu-attack
Actors/Campaigns:
Ta428
Threats:
Cotsam
Cotx_rat
Dll_hijacking_technique
Shadowpad
Nbtscan_tool
Ladon_tool
Netstat_tool
Golden_ticket_technique
Industry:
Government
Geo:
Chinese, Afghanistan
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 10
Hash: 1
Registry: 3
Path: 2
Softs:
task scheduler, active directory, microsoft word
Algorithms:
xor
Functions:
WriteProcessMemory
09-08-2022
CotSam, Never Before Seen Malware linked to TA428 involved in EU attack
https://www.secureblink.com/threat-research/cot-sam-never-before-seen-malware-linked-to-ta-428-involved-in-eu-attack
Actors/Campaigns:
Ta428
Threats:
Cotsam
Cotx_rat
Dll_hijacking_technique
Shadowpad
Nbtscan_tool
Ladon_tool
Netstat_tool
Golden_ticket_technique
Industry:
Government
Geo:
Chinese, Afghanistan
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 10
Hash: 1
Registry: 3
Path: 2
Softs:
task scheduler, active directory, microsoft word
Algorithms:
xor
Functions:
WriteProcessMemory
Secureblink
CotSam, Never Before Seen Malware linked to TA428 involved in EU attack | Secure Blink
CotSam: a never seen before malware strain involved in the targeted attacks across several European & Afghanistan institutions linked to infamous APT group TA428...
#ParsedReport
09-08-2022
Life After DeathSmokeLoader Continues to Haunt Using Old Vulnerabilities
https://www.fortinet.com/blog/threat-research/smokeloader-using-old-vulnerabilities
Threats:
Smokeloader
Trickbot
Quasar_rat
Velvetsweatshop_technique
Vba/agent.bmw!tr.dldr
Industry:
Transport, Financial, Telco
Geo:
Chinese, Taiwan
CVEs:
CVE-2017-11882 [Vulners]
Vulners: Score: 9.3, CVSS: 4.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2013, 2010, 2016, 2007)
CVE-2017-0199 [Vulners]
Vulners: Score: 9.3, CVSS: 7.8,
Vulners: Exploitation: True
X-Force: Risk: 9.3
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2, *)
- microsoft windows server 2012 (-)
- microsoft windows vista (*)
- microsoft office (2010, 2013, 2016, 2007)
- microsoft windows 7 (*)
have more...
IOCs:
IP: 1
File: 2
Domain: 3
Hash: 5
Softs:
microsoft word
Algorithms:
gzip
09-08-2022
Life After DeathSmokeLoader Continues to Haunt Using Old Vulnerabilities
https://www.fortinet.com/blog/threat-research/smokeloader-using-old-vulnerabilities
Threats:
Smokeloader
Trickbot
Quasar_rat
Velvetsweatshop_technique
Vba/agent.bmw!tr.dldr
Industry:
Transport, Financial, Telco
Geo:
Chinese, Taiwan
CVEs:
CVE-2017-11882 [Vulners]
Vulners: Score: 9.3, CVSS: 4.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2013, 2010, 2016, 2007)
CVE-2017-0199 [Vulners]
Vulners: Score: 9.3, CVSS: 7.8,
Vulners: Exploitation: True
X-Force: Risk: 9.3
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2, *)
- microsoft windows server 2012 (-)
- microsoft windows vista (*)
- microsoft office (2010, 2013, 2016, 2007)
- microsoft windows 7 (*)
have more...
IOCs:
IP: 1
File: 2
Domain: 3
Hash: 5
Softs:
microsoft word
Algorithms:
gzip
Fortinet Blog
Life After Death—SmokeLoader Continues to Haunt Using Old Vulnerabilities
FortiGuard Labs examines SmokeLoader, a malware variant that exploits CVE-2017-0199 and CVE-2017-11882 in its deployment chain. Read our analysis blog to learn about the latest sample.…
#ParsedReport
09-08-2022
Bitter APT group using Dracarys Android Spyware
https://blog.cyble.com/2022/08/09/bitter-apt-group-using-dracarys-android-spyware
Actors/Campaigns:
Bitter
Threats:
Dracarys
Industry:
Financial
Geo:
Asia, Pakistan, India, Asian, China
TTPs:
Tactics: 3
Technics: 0
IOCs:
File: 1
Url: 4
Hash: 3
Softs:
android, telegram
09-08-2022
Bitter APT group using Dracarys Android Spyware
https://blog.cyble.com/2022/08/09/bitter-apt-group-using-dracarys-android-spyware
Actors/Campaigns:
Bitter
Threats:
Dracarys
Industry:
Financial
Geo:
Asia, Pakistan, India, Asian, China
TTPs:
Tactics: 3
Technics: 0
IOCs:
File: 1
Url: 4
Hash: 3
Softs:
android, telegram
Cyble
Cyble - Bitter APT Group Using "Dracarys" Android Spyware
Cyble analyzes the Bitter APT group leveraging trojanized Messaging Apps to deliver Dracarys Android Malware.
#ParsedReport
09-08-2022
Pivoting on a SharpExt to profile Kimusky panels for great good. Older Campaigns
https://medium.com/walmartglobaltech/pivoting-on-a-sharpext-to-profile-kimusky-panels-for-great-good-1920dc1bcef9
Actors/Campaigns:
Kimsuky
Threats:
Sharpext
Geo:
Korea
IOCs:
Url: 1
File: 32
Domain: 1
Hash: 38
Path: 1
Registry: 14
09-08-2022
Pivoting on a SharpExt to profile Kimusky panels for great good. Older Campaigns
https://medium.com/walmartglobaltech/pivoting-on-a-sharpext-to-profile-kimusky-panels-for-great-good-1920dc1bcef9
Actors/Campaigns:
Kimsuky
Threats:
Sharpext
Geo:
Korea
IOCs:
Url: 1
File: 32
Domain: 1
Hash: 38
Path: 1
Registry: 14
Medium
Pivoting on a SharpExt to profile Kimusky panels for great good
By: Jason Reaves and Joshua Platt
#technique
D.RDynamicShellcode; Download & Run Dynamic Shellcode : it reads the shellcode from a url (has to be downloadable) locate it in a RWX section in memory and run it, useful for people looking for a shellcode as a 1st stage
https://gitlab.com/ORCA000/d.rdynamicshellcode
D.RDynamicShellcode; Download & Run Dynamic Shellcode : it reads the shellcode from a url (has to be downloadable) locate it in a RWX section in memory and run it, useful for people looking for a shellcode as a 1st stage
https://gitlab.com/ORCA000/d.rdynamicshellcode
GitLab
ORCA / D.RDynamicShellcode · GitLab
Download & Run Dynamic x64 Shellcode
#ParsedReport
09-08-2022
Abusing Google Sites and Microsoft Azure for Crypto Phishing
https://www.netskope.com/blog/abusing-google-sites-and-microsoft-azure-for-crypto-phishing
Threats:
Kraken
Ousaban
Industry:
Financial
Geo:
Latam
IOCs:
Url: 42
Softs:
coinbase
09-08-2022
Abusing Google Sites and Microsoft Azure for Crypto Phishing
https://www.netskope.com/blog/abusing-google-sites-and-microsoft-azure-for-crypto-phishing
Threats:
Kraken
Ousaban
Industry:
Financial
Geo:
Latam
IOCs:
Url: 42
Softs:
coinbase
Netskope
Abusing Google Sites and Microsoft Azure for Crypto Phishing
Summary Throughout 2022, Netskope Threat Labs found that attackers have been creating phishing pages in Google Sites and Microsoft Azure Web App to steal
#ParsedReport
10-08-2022
SpyNote An Android Snooper
https://labs.k7computing.com/index.php/spynote-an-android-snooper
Threats:
Spynote
Cyberchef_tool
Geo:
Indian
TTPs:
Tactics: 4
Technics: 0
IOCs:
File: 6
IP: 1
Hash: 1
Domain: 1
Softs:
android
Algorithms:
gzip
10-08-2022
SpyNote An Android Snooper
https://labs.k7computing.com/index.php/spynote-an-android-snooper
Threats:
Spynote
Cyberchef_tool
Geo:
Indian
TTPs:
Tactics: 4
Technics: 0
IOCs:
File: 6
IP: 1
Hash: 1
Domain: 1
Softs:
android
Algorithms:
gzip
K7 Labs
SpyNote – An Android Snooper
Threat actors are constantly using new tricks and tactics to target users across the globe. This blog is about SpyNote, […]