CTT Report Hub
3.42K subscribers
9.87K photos
6 videos
67 files
13.5K links
Threat Intelligence Report Hub
Download Telegram
#ParsedReport
08-08-2022

BumbleBee Roasts Its Way to Domain Admin. Case Summary

https://thedfirreport.com/2022/08/08/bumblebee-roasts-its-way-to-domain-admin

Actors/Campaigns:
Exotic_lily
Wizard_spider
Fin12

Threats:
Bumblebee
Bespoke
Cobalt_strike
Beacon
Adfind_tool
Vulnrecon_tool
Procdump_tool
Process_injection_technique
Kerberoasting_technique
Cyberchef_tool
Minidump_tool
Powerview
Anydesk_tool

Geo:
Usa

TTPs:
Tactics: 11
Technics: 26

IOCs:
File: 25
Path: 17
IP: 5
Domain: 3
Hash: 15

Softs:
android, anydesk, active directory, psexec, sysinternals

Algorithms:
zip , gzip, xor, base64, rc4

Functions:
Gunzip, CreateServiceA, OpenSSL, CreateRemoteThread

YARA: Found
SIGMA: Found

Links:
https://github.com/GhostPack/Seatbelt
https://github.com/DidierStevens/DidierStevensSuite/blob/master/1768.py
#ParsedReport
08-08-2022

Linux Malware RapperBotBrute Forcing SSH Servers. Linux Malware RapperBot Brute Forcing SSH Servers

https://socradar.io/linux-malware-rapperbot-brute-forcing-ssh-servers

Actors/Campaigns:
Vice_society
Dawdropper

Threats:
Rapperbot
Mirai
Darkutilities_tool

Industry:
Financial, Iot

IOCs:
Hash: 26
Url: 19
IP: 4

Softs:
confluence

Platforms:
x86
#ParsedReport
08-08-2022

LogoKit update The phishing kit leveraging Open Redirect Vulnerabilities

https://resecurity.com/blog/article/logokit-update-the-phishing-kit-leveraging-open-redirect-vulnerabilities

Actors/Campaigns:
Blackcat

Threats:
Logokit_tool
Blackcat

Industry:
E-commerce, Financial

Geo:
Usa, America

IOCs:
Url: 3
Email: 1
Domain: 6

Softs:
microsoft office

Algorithms:
base64

Languages:
javascript
#ParsedReport
08-08-2022

A new Pro Russian hacking group Heawsnet has shared a list of countries that will be on their target

https://www.thetechoutlook.com/news/technology/security/a-new-pro-russian-hacking-group-heawsnet-has-shared-a-list-of-countries-that-will-be-on-their-target

Actors/Campaigns:
Heawsnet

Threats:
Uroburos

Industry:
Government, Financial

Geo:
Iceland, Russian, Ukraines, Taiwan, Usa, Japan, Switzerland, Micronesia, Australia, Andorra, Liechtenstein, Singapore, Russia, Macedonia, Norway, Ukraine, Albania, Ukrainians, Canada, Korea, Ukrainian, Montenegro, Monaco
#ParsedReport
08-08-2022

Targeted attack on industrial enterprises and public institutions

https://ics-cert.kaspersky.com/publications/reports/2022/08/08/targeted-attack-on-industrial-enterprises-and-public-institutions

Actors/Campaigns:
Ta428

Threats:
Portdoor
Ncctrojan
Cotx_rat
Dnsep
Logtu
Cotsam
Ladon_tool
Dll_hijacking_technique
Process_hollowing_technique
Shadowpad
Nbtscan_tool
Netstat_tool
Golden_ticket_technique
Apost
Dllhijacker
Backdoor.win32.agent.myuhpj
Backdoor.win32.agentb.ca
Backdoor.win32.agentb.cc
Backdoor.win64.agent.iwv
Backdoor.win64.agent.iwy
Backdoor.win64.agent.iwz
Backdoor.win64.agent.ixl
Backdoor.win64.agent.ixm
Trojan.win32.agentb.kpkq
Trojan.win64.agent.qwhymc
Trojan.win64.agent.qwhypj
Trojan.win64.agentb.bdq
Trojan.win64.agentb.bse
Trojan.win64.agentb.bsf

Industry:
Government, Ics

Geo:
China, Afghanistan, Belarus, Chinese, Ukraine, Russia

CVEs:
CVE-2017-11882 [Vulners]
Vulners: Score: 9.3, CVSS: 4.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2013, 2010, 2016, 2007)


TTPs:
Tactics: 1
Technics: 0

IOCs:
Path: 194
File: 18
IP: 6
Hash: 67
Registry: 3
Domain: 12

Softs:
microsoft office, microsoft word, active directory, task scheduler

Algorithms:
aes-256, zip , xor, aes

Functions:
GetNativeSystemInfo, WriteProcessMemory, GetTickCount

Platforms:
intel
#ParsedReport
09-08-2022

Andariel deploys DTrack and Maui ransomware

https://securelist.com/andariel-deploys-dtrack-and-maui-ransomware/107063

Actors/Campaigns:
Lazarus (motivation: financially_motivated, cyber_espionage)

Threats:
Mauicrypt
Dtrack_rat
Netstat_tool

Industry:
Healthcare, Financial

Geo:
Korean, Russia, India, Japanese, Vietnam, Japan

CVEs:
CVE-2017-10271 [Vulners]
Vulners: Score: 5.0, CVSS: 2.7,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- oracle weblogic server (10.3.6.0.0, 12.2.1.1.0, 12.1.3.0.0, 12.2.1.2.0)


IOCs:
Path: 6
IP: 1
File: 2
Hash: 8
Url: 2

Softs:
3proxy

Platforms:
intel
#ParsedReport
09-08-2022

Novel News on Cuba Ransomware aka Greetings From Tropical Scorpius

https://unit42.paloaltonetworks.com/cuba-ransomware-tropical-scorpius

Actors/Campaigns:
Unc2596
Lapsus

Threats:
Cuba
Romcom_rat
Kerbercache_tool
Zerologon_vuln
Hancitor
Proxyshell_vuln
Proxylogon_exploit
Maze
Revil
Lockbit
Burntcigar_tool
Adfind_tool
Kerberoasting_technique
Mimikatz
Themida_tool
Qakbot
Beacon
Pid_spoofing_technique
Process_injection_technique

Industry:
Government, Financial, Education, E-commerce, Transport, Retail, Logistic, Healthcare, Energy

Geo:
Emea, Japan, Apac, America

CVEs:
CVE-2022-24521 [Vulners]
Vulners: Score: 4.6, CVSS: 4.2,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (-, 20h2, 21h1, 21h2, 1607, 1809, 1909)
- microsoft windows 11 (-, -)
- microsoft windows 7 (-)
- microsoft windows 8.1 (-)
- microsoft windows rt 8.1 (-)
have more...
CVE-2020-1472 [Vulners]
Vulners: Score: 9.3, CVSS: 3.8,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2)
- microsoft windows server 2012 (-, r2)
- microsoft windows server 2016 (-, 1903, 1909, 2004)
- microsoft windows server 2019 (-)
- fedoraproject fedora (31, 32, 33)
have more...

TTPs:
Tactics: 2
Technics: 0

IOCs:
File: 21
Coin: 5
Domain: 3
Email: 2
IP: 2
Path: 1
Hash: 16

Softs:
sqlbrowser, task scheduler, active directory, microsoft exchange, sqlagent, mysql

Algorithms:
chacha, rsa-4096, zip

Functions:
GetUserSPNs, CreateProcessA, the, MmGetSystemRoutineAddress, LsaLookupAuthenticationPackage, PsGetThreadProcess, IcmpCreateFile, LsaCallAuthenticationPackage, IcmpSendEcho, PsIsThreadTerminating, PsLookupThreadByThreadId

Platforms:
x86
#ParsedReport
09-08-2022

Global scam operation "Classiscam" expanded toSingapore. Global scam operation "Classiscam" expanded to Singapore

https://www.group-ib.com/media/classiscam-singapore-global-scam-operation

Threats:
Classiscam

Industry:
Education, Foodtech, Financial, E-commerce

Geo:
Singapore, Asia, Dubai, Russian, Pacific, Asian, Russia

Softs:
telegram
#ParsedReport
09-08-2022

CotSam, Never Before Seen Malware linked to TA428 involved in EU attack

https://www.secureblink.com/threat-research/cot-sam-never-before-seen-malware-linked-to-ta-428-involved-in-eu-attack

Actors/Campaigns:
Ta428

Threats:
Cotsam
Cotx_rat
Dll_hijacking_technique
Shadowpad
Nbtscan_tool
Ladon_tool
Netstat_tool
Golden_ticket_technique

Industry:
Government

Geo:
Chinese, Afghanistan

TTPs:
Tactics: 1
Technics: 0

IOCs:
File: 10
Hash: 1
Registry: 3
Path: 2

Softs:
task scheduler, active directory, microsoft word

Algorithms:
xor

Functions:
WriteProcessMemory
#ParsedReport
09-08-2022

Life After DeathSmokeLoader Continues to Haunt Using Old Vulnerabilities

https://www.fortinet.com/blog/threat-research/smokeloader-using-old-vulnerabilities

Threats:
Smokeloader
Trickbot
Quasar_rat
Velvetsweatshop_technique
Vba/agent.bmw!tr.dldr

Industry:
Transport, Financial, Telco

Geo:
Chinese, Taiwan

CVEs:
CVE-2017-11882 [Vulners]
Vulners: Score: 9.3, CVSS: 4.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2013, 2010, 2016, 2007)

CVE-2017-0199 [Vulners]
Vulners: Score: 9.3, CVSS: 7.8,
Vulners: Exploitation: True
X-Force: Risk: 9.3
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2, *)
- microsoft windows server 2012 (-)
- microsoft windows vista (*)
- microsoft office (2010, 2013, 2016, 2007)
- microsoft windows 7 (*)
have more...

IOCs:
IP: 1
File: 2
Domain: 3
Hash: 5

Softs:
microsoft word

Algorithms:
gzip
#ParsedReport
09-08-2022

Bitter APT group using Dracarys Android Spyware

https://blog.cyble.com/2022/08/09/bitter-apt-group-using-dracarys-android-spyware

Actors/Campaigns:
Bitter

Threats:
Dracarys

Industry:
Financial

Geo:
Asia, Pakistan, India, Asian, China

TTPs:
Tactics: 3
Technics: 0

IOCs:
File: 1
Url: 4
Hash: 3

Softs:
android, telegram
#ParsedReport
09-08-2022

Pivoting on a SharpExt to profile Kimusky panels for great good. Older Campaigns

https://medium.com/walmartglobaltech/pivoting-on-a-sharpext-to-profile-kimusky-panels-for-great-good-1920dc1bcef9

Actors/Campaigns:
Kimsuky

Threats:
Sharpext

Geo:
Korea

IOCs:
Url: 1
File: 32
Domain: 1
Hash: 38
Path: 1
Registry: 14
#technique

D.RDynamicShellcode; Download & Run Dynamic Shellcode : it reads the shellcode from a url (has to be downloadable) locate it in a RWX section in memory and run it, useful for people looking for a shellcode as a 1st stage

https://gitlab.com/ORCA000/d.rdynamicshellcode
#ParsedReport
10-08-2022

VileRAT: DeathStalkers continuous strike at foreign and cryptocurrency exchanges

https://securelist.com/vilerat-deathstalkers-continuous-strike/107075

Actors/Campaigns:
Evilnum (motivation: financially_motivated)

Threats:
Vilerat
Janicab
Powersing
Powerpepper
Pyvil_rat
Vileloader
Viledropper

Industry:
Financial

Geo:
Russian, Germany, Kuwait, Bulgaria, Malta, Cyprus, Emirates

IOCs:
Url: 6
Hash: 145
File: 13
Path: 1
Domain: 287
IP: 22

Softs:
task scheduler, windows scheduled task, chrome

Algorithms:
rc4, xor, zip , bzip, lzma

Functions:
GetTickCount, NtAllocateVirtualMemory, NtWaitForSingleObject, API, CreateProcessW, NtCreateThreadEx, DelPort, SHGetFolderPathW

Languages:
python, javascript, cpython, php

Platforms:
x64

Links:
https://github.com/bontchev/pcodedmp
https://github.com/andrew-tavera/unpyc37/
https://github.com/eset/malware-ioc/tree/master/evilnum#february-2021-pyvil-and-evilnum-update
https://github.com/python/cpython/commit/0af9bef61afffbf128aba76a2e578059621b4f00
#ParsedReport
10-08-2022

Raspberry Robin: Highly Evasive Worm Spreads over External Disks

https://blogs.cisco.com/security/raspberry-robin-highly-evasive-worm-spreads-over-external-disks

Threats:
Raspberry_robin
Process_injection_technique
Uac_bypass_technique

TTPs:
Tactics: 2
Technics: 0

IOCs:
File: 10
Path: 6
Url: 3
Domain: 37

Softs:
windows installer

Algorithms:
exhibit
#ParsedReport
10-08-2022

Lockbit, Hive, and BlackCat attack automotive supplier in triple ransomware attack

https://news.sophos.com/en-us/2022/08/10/lockbit-hive-and-blackcat-attack-automotive-supplier-in-triple-ransomware-attack

Actors/Campaigns:
Blackcat

Threats:
Lockbit
Blackcat
Mimikatz
Atera_tool
Hive

Industry:
Iot, E-commerce

IOCs:
File: 12
Registry: 1
Hash: 4

Softs:
local security authority, psexec, vssadmin, bcdedit

Links:
https://github.com/sophoslabs/IoCs/blob/master/Ransomware\_Lockbit%20-%20triple%20ransomware%20attack.csv
https://github.com/sophoslabs/IoCs/blob/master/Ransomware\_BlackCat%20-%20triple%20ransomware%20attack.csv
https://github.com/sophoslabs/IoCs/blob/master/Ransomware\_Hive%20-%20triple%20ransomware%20attack.csv