#ParsedReport
08-08-2022
BumbleBee Roasts Its Way to Domain Admin. Case Summary
https://thedfirreport.com/2022/08/08/bumblebee-roasts-its-way-to-domain-admin
Actors/Campaigns:
Exotic_lily
Wizard_spider
Fin12
Threats:
Bumblebee
Bespoke
Cobalt_strike
Beacon
Adfind_tool
Vulnrecon_tool
Procdump_tool
Process_injection_technique
Kerberoasting_technique
Cyberchef_tool
Minidump_tool
Powerview
Anydesk_tool
Geo:
Usa
TTPs:
Tactics: 11
Technics: 26
IOCs:
File: 25
Path: 17
IP: 5
Domain: 3
Hash: 15
Softs:
android, anydesk, active directory, psexec, sysinternals
Algorithms:
zip , gzip, xor, base64, rc4
Functions:
Gunzip, CreateServiceA, OpenSSL, CreateRemoteThread
YARA: Found
SIGMA: Found
Links:
08-08-2022
BumbleBee Roasts Its Way to Domain Admin. Case Summary
https://thedfirreport.com/2022/08/08/bumblebee-roasts-its-way-to-domain-admin
Actors/Campaigns:
Exotic_lily
Wizard_spider
Fin12
Threats:
Bumblebee
Bespoke
Cobalt_strike
Beacon
Adfind_tool
Vulnrecon_tool
Procdump_tool
Process_injection_technique
Kerberoasting_technique
Cyberchef_tool
Minidump_tool
Powerview
Anydesk_tool
Geo:
Usa
TTPs:
Tactics: 11
Technics: 26
IOCs:
File: 25
Path: 17
IP: 5
Domain: 3
Hash: 15
Softs:
android, anydesk, active directory, psexec, sysinternals
Algorithms:
zip , gzip, xor, base64, rc4
Functions:
Gunzip, CreateServiceA, OpenSSL, CreateRemoteThread
YARA: Found
SIGMA: Found
Links:
https://github.com/GhostPack/Seatbelthttps://github.com/DidierStevens/DidierStevensSuite/blob/master/1768.pyThe DFIR Report
BumbleBee Roasts Its Way to Domain Admin - The DFIR Report
In this intrusion from April 2022, the threat actors used BumbleBee as the initial access vector. BumbleBee is a malware loader that was first reported by Google Threat Analysis Group in March 2022. Google TAG attributes this malware to an initial access…
#ParsedReport
08-08-2022
Linux Malware RapperBotBrute Forcing SSH Servers. Linux Malware RapperBot Brute Forcing SSH Servers
https://socradar.io/linux-malware-rapperbot-brute-forcing-ssh-servers
Actors/Campaigns:
Vice_society
Dawdropper
Threats:
Rapperbot
Mirai
Darkutilities_tool
Industry:
Financial, Iot
IOCs:
Hash: 26
Url: 19
IP: 4
Softs:
confluence
Platforms:
x86
08-08-2022
Linux Malware RapperBotBrute Forcing SSH Servers. Linux Malware RapperBot Brute Forcing SSH Servers
https://socradar.io/linux-malware-rapperbot-brute-forcing-ssh-servers
Actors/Campaigns:
Vice_society
Dawdropper
Threats:
Rapperbot
Mirai
Darkutilities_tool
Industry:
Financial, Iot
IOCs:
Hash: 26
Url: 19
IP: 4
Softs:
confluence
Platforms:
x86
SOCRadar® Cyber Intelligence Inc.
Linux Malware RapperBot Brute Forcing SSH Servers - SOCRadar
RapperBot is an IoT botnet malware that has spread through brute force since it was first identified in June 2022. Over 3,500 unique IPs...
#ParsedReport
08-08-2022
LogoKit update The phishing kit leveraging Open Redirect Vulnerabilities
https://resecurity.com/blog/article/logokit-update-the-phishing-kit-leveraging-open-redirect-vulnerabilities
Actors/Campaigns:
Blackcat
Threats:
Logokit_tool
Blackcat
Industry:
E-commerce, Financial
Geo:
Usa, America
IOCs:
Url: 3
Email: 1
Domain: 6
Softs:
microsoft office
Algorithms:
base64
Languages:
javascript
08-08-2022
LogoKit update The phishing kit leveraging Open Redirect Vulnerabilities
https://resecurity.com/blog/article/logokit-update-the-phishing-kit-leveraging-open-redirect-vulnerabilities
Actors/Campaigns:
Blackcat
Threats:
Logokit_tool
Blackcat
Industry:
E-commerce, Financial
Geo:
Usa, America
IOCs:
Url: 3
Email: 1
Domain: 6
Softs:
microsoft office
Algorithms:
base64
Languages:
javascript
#ParsedReport
08-08-2022
A new Pro Russian hacking group Heawsnet has shared a list of countries that will be on their target
https://www.thetechoutlook.com/news/technology/security/a-new-pro-russian-hacking-group-heawsnet-has-shared-a-list-of-countries-that-will-be-on-their-target
Actors/Campaigns:
Heawsnet
Threats:
Uroburos
Industry:
Government, Financial
Geo:
Iceland, Russian, Ukraines, Taiwan, Usa, Japan, Switzerland, Micronesia, Australia, Andorra, Liechtenstein, Singapore, Russia, Macedonia, Norway, Ukraine, Albania, Ukrainians, Canada, Korea, Ukrainian, Montenegro, Monaco
08-08-2022
A new Pro Russian hacking group Heawsnet has shared a list of countries that will be on their target
https://www.thetechoutlook.com/news/technology/security/a-new-pro-russian-hacking-group-heawsnet-has-shared-a-list-of-countries-that-will-be-on-their-target
Actors/Campaigns:
Heawsnet
Threats:
Uroburos
Industry:
Government, Financial
Geo:
Iceland, Russian, Ukraines, Taiwan, Usa, Japan, Switzerland, Micronesia, Australia, Andorra, Liechtenstein, Singapore, Russia, Macedonia, Norway, Ukraine, Albania, Ukrainians, Canada, Korea, Ukrainian, Montenegro, Monaco
The Tech Outlook
A new Pro Russian hacking group Heawsnet has shared a list of countries that will be on their target
Cyberwarfare has been a factor in the conflict between Russia and Ukraine since the collapse of the Soviet Union in 1991. Although the Ukrainian government and private sector’s computer systems were initially attacked in 2013 during widespread protests, the…
#ParsedReport
08-08-2022
Targeted attack on industrial enterprises and public institutions
https://ics-cert.kaspersky.com/publications/reports/2022/08/08/targeted-attack-on-industrial-enterprises-and-public-institutions
Actors/Campaigns:
Ta428
Threats:
Portdoor
Ncctrojan
Cotx_rat
Dnsep
Logtu
Cotsam
Ladon_tool
Dll_hijacking_technique
Process_hollowing_technique
Shadowpad
Nbtscan_tool
Netstat_tool
Golden_ticket_technique
Apost
Dllhijacker
Backdoor.win32.agent.myuhpj
Backdoor.win32.agentb.ca
Backdoor.win32.agentb.cc
Backdoor.win64.agent.iwv
Backdoor.win64.agent.iwy
Backdoor.win64.agent.iwz
Backdoor.win64.agent.ixl
Backdoor.win64.agent.ixm
Trojan.win32.agentb.kpkq
Trojan.win64.agent.qwhymc
Trojan.win64.agent.qwhypj
Trojan.win64.agentb.bdq
Trojan.win64.agentb.bse
Trojan.win64.agentb.bsf
Industry:
Government, Ics
Geo:
China, Afghanistan, Belarus, Chinese, Ukraine, Russia
CVEs:
CVE-2017-11882 [Vulners]
Vulners: Score: 9.3, CVSS: 4.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2013, 2010, 2016, 2007)
TTPs:
Tactics: 1
Technics: 0
IOCs:
Path: 194
File: 18
IP: 6
Hash: 67
Registry: 3
Domain: 12
Softs:
microsoft office, microsoft word, active directory, task scheduler
Algorithms:
aes-256, zip , xor, aes
Functions:
GetNativeSystemInfo, WriteProcessMemory, GetTickCount
Platforms:
intel
08-08-2022
Targeted attack on industrial enterprises and public institutions
https://ics-cert.kaspersky.com/publications/reports/2022/08/08/targeted-attack-on-industrial-enterprises-and-public-institutions
Actors/Campaigns:
Ta428
Threats:
Portdoor
Ncctrojan
Cotx_rat
Dnsep
Logtu
Cotsam
Ladon_tool
Dll_hijacking_technique
Process_hollowing_technique
Shadowpad
Nbtscan_tool
Netstat_tool
Golden_ticket_technique
Apost
Dllhijacker
Backdoor.win32.agent.myuhpj
Backdoor.win32.agentb.ca
Backdoor.win32.agentb.cc
Backdoor.win64.agent.iwv
Backdoor.win64.agent.iwy
Backdoor.win64.agent.iwz
Backdoor.win64.agent.ixl
Backdoor.win64.agent.ixm
Trojan.win32.agentb.kpkq
Trojan.win64.agent.qwhymc
Trojan.win64.agent.qwhypj
Trojan.win64.agentb.bdq
Trojan.win64.agentb.bse
Trojan.win64.agentb.bsf
Industry:
Government, Ics
Geo:
China, Afghanistan, Belarus, Chinese, Ukraine, Russia
CVEs:
CVE-2017-11882 [Vulners]
Vulners: Score: 9.3, CVSS: 4.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2013, 2010, 2016, 2007)
TTPs:
Tactics: 1
Technics: 0
IOCs:
Path: 194
File: 18
IP: 6
Hash: 67
Registry: 3
Domain: 12
Softs:
microsoft office, microsoft word, active directory, task scheduler
Algorithms:
aes-256, zip , xor, aes
Functions:
GetNativeSystemInfo, WriteProcessMemory, GetTickCount
Platforms:
intel
Kaspersky ICS CERT | Kaspersky Industrial Control Systems Cyber Emergency Response Team
Targeted attack on industrial enterprises and public institutions | Kaspersky ICS CERT
The attackers were able to penetrate dozens of enterprises and even hijack the IT infrastructure of some, taking control of systems used to manage security solutions. The goal of this series of attacks was cyberespionage.
#technique
Rundll32: The Infamous Proxy for Executing Malicious Code
https://www.cybereason.com/blog/rundll32-the-infamous-proxy-for-executing-malicious-code
Rundll32: The Infamous Proxy for Executing Malicious Code
https://www.cybereason.com/blog/rundll32-the-infamous-proxy-for-executing-malicious-code
Cybereason
Rundll32: The Infamous Proxy for Executing Malicious Code
Take a deeper dive into an often abused Microsoft-signed tool, the infamous rundll32.exe, which allows adversaries to execute malicious code during their offensive operations through a technique which we explain in detail...
#ParsedReport
09-08-2022
Andariel deploys DTrack and Maui ransomware
https://securelist.com/andariel-deploys-dtrack-and-maui-ransomware/107063
Actors/Campaigns:
Lazarus (motivation: financially_motivated, cyber_espionage)
Threats:
Mauicrypt
Dtrack_rat
Netstat_tool
Industry:
Healthcare, Financial
Geo:
Korean, Russia, India, Japanese, Vietnam, Japan
CVEs:
CVE-2017-10271 [Vulners]
Vulners: Score: 5.0, CVSS: 2.7,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- oracle weblogic server (10.3.6.0.0, 12.2.1.1.0, 12.1.3.0.0, 12.2.1.2.0)
IOCs:
Path: 6
IP: 1
File: 2
Hash: 8
Url: 2
Softs:
3proxy
Platforms:
intel
09-08-2022
Andariel deploys DTrack and Maui ransomware
https://securelist.com/andariel-deploys-dtrack-and-maui-ransomware/107063
Actors/Campaigns:
Lazarus (motivation: financially_motivated, cyber_espionage)
Threats:
Mauicrypt
Dtrack_rat
Netstat_tool
Industry:
Healthcare, Financial
Geo:
Korean, Russia, India, Japanese, Vietnam, Japan
CVEs:
CVE-2017-10271 [Vulners]
Vulners: Score: 5.0, CVSS: 2.7,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- oracle weblogic server (10.3.6.0.0, 12.2.1.1.0, 12.1.3.0.0, 12.2.1.2.0)
IOCs:
Path: 6
IP: 1
File: 2
Hash: 8
Url: 2
Softs:
3proxy
Platforms:
intel
Securelist
Andariel deploys DTrack and Maui ransomware
Earlier, the CISA published an alert related to a Stairwell report, “Maui Ransomware.” Our data should openly help solidify the attribution of the Maui ransomware incident to the Korean-speaking APT Andariel.
#ParsedReport
09-08-2022
Novel News on Cuba Ransomware aka Greetings From Tropical Scorpius
https://unit42.paloaltonetworks.com/cuba-ransomware-tropical-scorpius
Actors/Campaigns:
Unc2596
Lapsus
Threats:
Cuba
Romcom_rat
Kerbercache_tool
Zerologon_vuln
Hancitor
Proxyshell_vuln
Proxylogon_exploit
Maze
Revil
Lockbit
Burntcigar_tool
Adfind_tool
Kerberoasting_technique
Mimikatz
Themida_tool
Qakbot
Beacon
Pid_spoofing_technique
Process_injection_technique
Industry:
Government, Financial, Education, E-commerce, Transport, Retail, Logistic, Healthcare, Energy
Geo:
Emea, Japan, Apac, America
CVEs:
CVE-2022-24521 [Vulners]
Vulners: Score: 4.6, CVSS: 4.2,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (-, 20h2, 21h1, 21h2, 1607, 1809, 1909)
- microsoft windows 11 (-, -)
- microsoft windows 7 (-)
- microsoft windows 8.1 (-)
- microsoft windows rt 8.1 (-)
have more...
CVE-2020-1472 [Vulners]
Vulners: Score: 9.3, CVSS: 3.8,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2)
- microsoft windows server 2012 (-, r2)
- microsoft windows server 2016 (-, 1903, 1909, 2004)
- microsoft windows server 2019 (-)
- fedoraproject fedora (31, 32, 33)
have more...
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 21
Coin: 5
Domain: 3
Email: 2
IP: 2
Path: 1
Hash: 16
Softs:
sqlbrowser, task scheduler, active directory, microsoft exchange, sqlagent, mysql
Algorithms:
chacha, rsa-4096, zip
Functions:
GetUserSPNs, CreateProcessA, the, MmGetSystemRoutineAddress, LsaLookupAuthenticationPackage, PsGetThreadProcess, IcmpCreateFile, LsaCallAuthenticationPackage, IcmpSendEcho, PsIsThreadTerminating, PsLookupThreadByThreadId
Platforms:
x86
09-08-2022
Novel News on Cuba Ransomware aka Greetings From Tropical Scorpius
https://unit42.paloaltonetworks.com/cuba-ransomware-tropical-scorpius
Actors/Campaigns:
Unc2596
Lapsus
Threats:
Cuba
Romcom_rat
Kerbercache_tool
Zerologon_vuln
Hancitor
Proxyshell_vuln
Proxylogon_exploit
Maze
Revil
Lockbit
Burntcigar_tool
Adfind_tool
Kerberoasting_technique
Mimikatz
Themida_tool
Qakbot
Beacon
Pid_spoofing_technique
Process_injection_technique
Industry:
Government, Financial, Education, E-commerce, Transport, Retail, Logistic, Healthcare, Energy
Geo:
Emea, Japan, Apac, America
CVEs:
CVE-2022-24521 [Vulners]
Vulners: Score: 4.6, CVSS: 4.2,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (-, 20h2, 21h1, 21h2, 1607, 1809, 1909)
- microsoft windows 11 (-, -)
- microsoft windows 7 (-)
- microsoft windows 8.1 (-)
- microsoft windows rt 8.1 (-)
have more...
CVE-2020-1472 [Vulners]
Vulners: Score: 9.3, CVSS: 3.8,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2)
- microsoft windows server 2012 (-, r2)
- microsoft windows server 2016 (-, 1903, 1909, 2004)
- microsoft windows server 2019 (-)
- fedoraproject fedora (31, 32, 33)
have more...
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 21
Coin: 5
Domain: 3
Email: 2
IP: 2
Path: 1
Hash: 16
Softs:
sqlbrowser, task scheduler, active directory, microsoft exchange, sqlagent, mysql
Algorithms:
chacha, rsa-4096, zip
Functions:
GetUserSPNs, CreateProcessA, the, MmGetSystemRoutineAddress, LsaLookupAuthenticationPackage, PsGetThreadProcess, IcmpCreateFile, LsaCallAuthenticationPackage, IcmpSendEcho, PsIsThreadTerminating, PsLookupThreadByThreadId
Platforms:
x86
Unit 42
Novel News on Cuba Ransomware: Greetings From Tropical Scorpius
Tropical Scorpius has been deploying Cuba Ransomware using novel tools and techniques, such as a new malware family, ROMCOM RAT.
#ParsedReport
09-08-2022
Global scam operation "Classiscam" expanded toSingapore. Global scam operation "Classiscam" expanded to Singapore
https://www.group-ib.com/media/classiscam-singapore-global-scam-operation
Threats:
Classiscam
Industry:
Education, Foodtech, Financial, E-commerce
Geo:
Singapore, Asia, Dubai, Russian, Pacific, Asian, Russia
Softs:
telegram
09-08-2022
Global scam operation "Classiscam" expanded toSingapore. Global scam operation "Classiscam" expanded to Singapore
https://www.group-ib.com/media/classiscam-singapore-global-scam-operation
Threats:
Classiscam
Industry:
Education, Foodtech, Financial, E-commerce
Geo:
Singapore, Asia, Dubai, Russian, Pacific, Asian, Russia
Softs:
telegram
Group-IB
Global scam operation "Classiscam" expanded to Singapore
Group-IB has uncovered that Classiscam a sophisticated scam-as-a-service operation has expanded to Singapore in March 2022.
#ParsedReport
09-08-2022
CotSam, Never Before Seen Malware linked to TA428 involved in EU attack
https://www.secureblink.com/threat-research/cot-sam-never-before-seen-malware-linked-to-ta-428-involved-in-eu-attack
Actors/Campaigns:
Ta428
Threats:
Cotsam
Cotx_rat
Dll_hijacking_technique
Shadowpad
Nbtscan_tool
Ladon_tool
Netstat_tool
Golden_ticket_technique
Industry:
Government
Geo:
Chinese, Afghanistan
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 10
Hash: 1
Registry: 3
Path: 2
Softs:
task scheduler, active directory, microsoft word
Algorithms:
xor
Functions:
WriteProcessMemory
09-08-2022
CotSam, Never Before Seen Malware linked to TA428 involved in EU attack
https://www.secureblink.com/threat-research/cot-sam-never-before-seen-malware-linked-to-ta-428-involved-in-eu-attack
Actors/Campaigns:
Ta428
Threats:
Cotsam
Cotx_rat
Dll_hijacking_technique
Shadowpad
Nbtscan_tool
Ladon_tool
Netstat_tool
Golden_ticket_technique
Industry:
Government
Geo:
Chinese, Afghanistan
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 10
Hash: 1
Registry: 3
Path: 2
Softs:
task scheduler, active directory, microsoft word
Algorithms:
xor
Functions:
WriteProcessMemory
Secureblink
CotSam, Never Before Seen Malware linked to TA428 involved in EU attack | Secure Blink
CotSam: a never seen before malware strain involved in the targeted attacks across several European & Afghanistan institutions linked to infamous APT group TA428...
#ParsedReport
09-08-2022
Life After DeathSmokeLoader Continues to Haunt Using Old Vulnerabilities
https://www.fortinet.com/blog/threat-research/smokeloader-using-old-vulnerabilities
Threats:
Smokeloader
Trickbot
Quasar_rat
Velvetsweatshop_technique
Vba/agent.bmw!tr.dldr
Industry:
Transport, Financial, Telco
Geo:
Chinese, Taiwan
CVEs:
CVE-2017-11882 [Vulners]
Vulners: Score: 9.3, CVSS: 4.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2013, 2010, 2016, 2007)
CVE-2017-0199 [Vulners]
Vulners: Score: 9.3, CVSS: 7.8,
Vulners: Exploitation: True
X-Force: Risk: 9.3
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2, *)
- microsoft windows server 2012 (-)
- microsoft windows vista (*)
- microsoft office (2010, 2013, 2016, 2007)
- microsoft windows 7 (*)
have more...
IOCs:
IP: 1
File: 2
Domain: 3
Hash: 5
Softs:
microsoft word
Algorithms:
gzip
09-08-2022
Life After DeathSmokeLoader Continues to Haunt Using Old Vulnerabilities
https://www.fortinet.com/blog/threat-research/smokeloader-using-old-vulnerabilities
Threats:
Smokeloader
Trickbot
Quasar_rat
Velvetsweatshop_technique
Vba/agent.bmw!tr.dldr
Industry:
Transport, Financial, Telco
Geo:
Chinese, Taiwan
CVEs:
CVE-2017-11882 [Vulners]
Vulners: Score: 9.3, CVSS: 4.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2013, 2010, 2016, 2007)
CVE-2017-0199 [Vulners]
Vulners: Score: 9.3, CVSS: 7.8,
Vulners: Exploitation: True
X-Force: Risk: 9.3
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2, *)
- microsoft windows server 2012 (-)
- microsoft windows vista (*)
- microsoft office (2010, 2013, 2016, 2007)
- microsoft windows 7 (*)
have more...
IOCs:
IP: 1
File: 2
Domain: 3
Hash: 5
Softs:
microsoft word
Algorithms:
gzip
Fortinet Blog
Life After Death—SmokeLoader Continues to Haunt Using Old Vulnerabilities
FortiGuard Labs examines SmokeLoader, a malware variant that exploits CVE-2017-0199 and CVE-2017-11882 in its deployment chain. Read our analysis blog to learn about the latest sample.…
#ParsedReport
09-08-2022
Bitter APT group using Dracarys Android Spyware
https://blog.cyble.com/2022/08/09/bitter-apt-group-using-dracarys-android-spyware
Actors/Campaigns:
Bitter
Threats:
Dracarys
Industry:
Financial
Geo:
Asia, Pakistan, India, Asian, China
TTPs:
Tactics: 3
Technics: 0
IOCs:
File: 1
Url: 4
Hash: 3
Softs:
android, telegram
09-08-2022
Bitter APT group using Dracarys Android Spyware
https://blog.cyble.com/2022/08/09/bitter-apt-group-using-dracarys-android-spyware
Actors/Campaigns:
Bitter
Threats:
Dracarys
Industry:
Financial
Geo:
Asia, Pakistan, India, Asian, China
TTPs:
Tactics: 3
Technics: 0
IOCs:
File: 1
Url: 4
Hash: 3
Softs:
android, telegram
Cyble
Cyble - Bitter APT Group Using "Dracarys" Android Spyware
Cyble analyzes the Bitter APT group leveraging trojanized Messaging Apps to deliver Dracarys Android Malware.
#ParsedReport
09-08-2022
Pivoting on a SharpExt to profile Kimusky panels for great good. Older Campaigns
https://medium.com/walmartglobaltech/pivoting-on-a-sharpext-to-profile-kimusky-panels-for-great-good-1920dc1bcef9
Actors/Campaigns:
Kimsuky
Threats:
Sharpext
Geo:
Korea
IOCs:
Url: 1
File: 32
Domain: 1
Hash: 38
Path: 1
Registry: 14
09-08-2022
Pivoting on a SharpExt to profile Kimusky panels for great good. Older Campaigns
https://medium.com/walmartglobaltech/pivoting-on-a-sharpext-to-profile-kimusky-panels-for-great-good-1920dc1bcef9
Actors/Campaigns:
Kimsuky
Threats:
Sharpext
Geo:
Korea
IOCs:
Url: 1
File: 32
Domain: 1
Hash: 38
Path: 1
Registry: 14
Medium
Pivoting on a SharpExt to profile Kimusky panels for great good
By: Jason Reaves and Joshua Platt
#technique
D.RDynamicShellcode; Download & Run Dynamic Shellcode : it reads the shellcode from a url (has to be downloadable) locate it in a RWX section in memory and run it, useful for people looking for a shellcode as a 1st stage
https://gitlab.com/ORCA000/d.rdynamicshellcode
D.RDynamicShellcode; Download & Run Dynamic Shellcode : it reads the shellcode from a url (has to be downloadable) locate it in a RWX section in memory and run it, useful for people looking for a shellcode as a 1st stage
https://gitlab.com/ORCA000/d.rdynamicshellcode
GitLab
ORCA / D.RDynamicShellcode · GitLab
Download & Run Dynamic x64 Shellcode
#ParsedReport
09-08-2022
Abusing Google Sites and Microsoft Azure for Crypto Phishing
https://www.netskope.com/blog/abusing-google-sites-and-microsoft-azure-for-crypto-phishing
Threats:
Kraken
Ousaban
Industry:
Financial
Geo:
Latam
IOCs:
Url: 42
Softs:
coinbase
09-08-2022
Abusing Google Sites and Microsoft Azure for Crypto Phishing
https://www.netskope.com/blog/abusing-google-sites-and-microsoft-azure-for-crypto-phishing
Threats:
Kraken
Ousaban
Industry:
Financial
Geo:
Latam
IOCs:
Url: 42
Softs:
coinbase
Netskope
Abusing Google Sites and Microsoft Azure for Crypto Phishing
Summary Throughout 2022, Netskope Threat Labs found that attackers have been creating phishing pages in Google Sites and Microsoft Azure Web App to steal
#ParsedReport
10-08-2022
SpyNote An Android Snooper
https://labs.k7computing.com/index.php/spynote-an-android-snooper
Threats:
Spynote
Cyberchef_tool
Geo:
Indian
TTPs:
Tactics: 4
Technics: 0
IOCs:
File: 6
IP: 1
Hash: 1
Domain: 1
Softs:
android
Algorithms:
gzip
10-08-2022
SpyNote An Android Snooper
https://labs.k7computing.com/index.php/spynote-an-android-snooper
Threats:
Spynote
Cyberchef_tool
Geo:
Indian
TTPs:
Tactics: 4
Technics: 0
IOCs:
File: 6
IP: 1
Hash: 1
Domain: 1
Softs:
android
Algorithms:
gzip
K7 Labs
SpyNote – An Android Snooper
Threat actors are constantly using new tricks and tactics to target users across the globe. This blog is about SpyNote, […]
#ParsedReport
10-08-2022
VileRAT: DeathStalkers continuous strike at foreign and cryptocurrency exchanges
https://securelist.com/vilerat-deathstalkers-continuous-strike/107075
Actors/Campaigns:
Evilnum (motivation: financially_motivated)
Threats:
Vilerat
Janicab
Powersing
Powerpepper
Pyvil_rat
Vileloader
Viledropper
Industry:
Financial
Geo:
Russian, Germany, Kuwait, Bulgaria, Malta, Cyprus, Emirates
IOCs:
Url: 6
Hash: 145
File: 13
Path: 1
Domain: 287
IP: 22
Softs:
task scheduler, windows scheduled task, chrome
Algorithms:
rc4, xor, zip , bzip, lzma
Functions:
GetTickCount, NtAllocateVirtualMemory, NtWaitForSingleObject, API, CreateProcessW, NtCreateThreadEx, DelPort, SHGetFolderPathW
Languages:
python, javascript, cpython, php
Platforms:
x64
Links:
10-08-2022
VileRAT: DeathStalkers continuous strike at foreign and cryptocurrency exchanges
https://securelist.com/vilerat-deathstalkers-continuous-strike/107075
Actors/Campaigns:
Evilnum (motivation: financially_motivated)
Threats:
Vilerat
Janicab
Powersing
Powerpepper
Pyvil_rat
Vileloader
Viledropper
Industry:
Financial
Geo:
Russian, Germany, Kuwait, Bulgaria, Malta, Cyprus, Emirates
IOCs:
Url: 6
Hash: 145
File: 13
Path: 1
Domain: 287
IP: 22
Softs:
task scheduler, windows scheduled task, chrome
Algorithms:
rc4, xor, zip , bzip, lzma
Functions:
GetTickCount, NtAllocateVirtualMemory, NtWaitForSingleObject, API, CreateProcessW, NtCreateThreadEx, DelPort, SHGetFolderPathW
Languages:
python, javascript, cpython, php
Platforms:
x64
Links:
https://github.com/bontchev/pcodedmphttps://github.com/andrew-tavera/unpyc37/https://github.com/eset/malware-ioc/tree/master/evilnum#february-2021-pyvil-and-evilnum-updatehttps://github.com/python/cpython/commit/0af9bef61afffbf128aba76a2e578059621b4f00Securelist
VileRAT: DeathStalker’s continuous strike at foreign and cryptocurrency exchanges
VileRAT is a Python implant, part of an evasive and highly intricate attack campaign against foreign exchange and cryptocurrency trading companies.
#ParsedReport
10-08-2022
Raspberry Robin: Highly Evasive Worm Spreads over External Disks
https://blogs.cisco.com/security/raspberry-robin-highly-evasive-worm-spreads-over-external-disks
Threats:
Raspberry_robin
Process_injection_technique
Uac_bypass_technique
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 10
Path: 6
Url: 3
Domain: 37
Softs:
windows installer
Algorithms:
exhibit
10-08-2022
Raspberry Robin: Highly Evasive Worm Spreads over External Disks
https://blogs.cisco.com/security/raspberry-robin-highly-evasive-worm-spreads-over-external-disks
Threats:
Raspberry_robin
Process_injection_technique
Uac_bypass_technique
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 10
Path: 6
Url: 3
Domain: 37
Softs:
windows installer
Algorithms:
exhibit
Cisco Blogs
Raspberry Robin: Highly Evasive Worm Spreads over External Disks
During our threat hunting exercises in recent months, we’ve started to observe a distinguishing pattern of msiexec.exe usage across different endpoints.
#ParsedReport
10-08-2022
Lockbit, Hive, and BlackCat attack automotive supplier in triple ransomware attack
https://news.sophos.com/en-us/2022/08/10/lockbit-hive-and-blackcat-attack-automotive-supplier-in-triple-ransomware-attack
Actors/Campaigns:
Blackcat
Threats:
Lockbit
Blackcat
Mimikatz
Atera_tool
Hive
Industry:
Iot, E-commerce
IOCs:
File: 12
Registry: 1
Hash: 4
Softs:
local security authority, psexec, vssadmin, bcdedit
Links:
10-08-2022
Lockbit, Hive, and BlackCat attack automotive supplier in triple ransomware attack
https://news.sophos.com/en-us/2022/08/10/lockbit-hive-and-blackcat-attack-automotive-supplier-in-triple-ransomware-attack
Actors/Campaigns:
Blackcat
Threats:
Lockbit
Blackcat
Mimikatz
Atera_tool
Hive
Industry:
Iot, E-commerce
IOCs:
File: 12
Registry: 1
Hash: 4
Softs:
local security authority, psexec, vssadmin, bcdedit
Links:
https://github.com/sophoslabs/IoCs/blob/master/Ransomware\_Lockbit%20-%20triple%20ransomware%20attack.csvhttps://github.com/sophoslabs/IoCs/blob/master/Ransomware\_BlackCat%20-%20triple%20ransomware%20attack.csvhttps://github.com/sophoslabs/IoCs/blob/master/Ransomware\_Hive%20-%20triple%20ransomware%20attack.csvSophos News
Lockbit, Hive, and BlackCat attack automotive supplier in triple ransomware attack
After gaining access via RDP, all three threat actors encrypted files, in an investigation complicated by event log clearing and backups. 3 attackers, 2 weeks – 1 entry point.
#ParsedReport
10-08-2022
ASEC (20220801 \~ 20220807). ASEC Weekly Malware Statistics (20220801 \~ 20220807)
https://asec.ahnlab.com/ko/37552
Threats:
Agent_tesla
Azorult
Formbook
Clipboard_grabbing_technique
Cloudeye
Postealer
Remcos_rat
Nanocore_rat
Redline_stealer
Beamwinhttp_loader
Vidar_stealer
Antefrigus
Revil
Industry:
Financial, Transport
Geo:
Korea
IOCs:
File: 38
Domain: 3
IP: 3
Email: 5
Url: 25
Softs:
nsis installer, discord
Languages:
visual_basic
10-08-2022
ASEC (20220801 \~ 20220807). ASEC Weekly Malware Statistics (20220801 \~ 20220807)
https://asec.ahnlab.com/ko/37552
Threats:
Agent_tesla
Azorult
Formbook
Clipboard_grabbing_technique
Cloudeye
Postealer
Remcos_rat
Nanocore_rat
Redline_stealer
Beamwinhttp_loader
Vidar_stealer
Antefrigus
Revil
Industry:
Financial, Transport
Geo:
Korea
IOCs:
File: 38
Domain: 3
IP: 3
Email: 5
Url: 25
Softs:
nsis installer, discord
Languages:
visual_basic
ASEC BLOG
ASEC 주간 악성코드 통계 (20220801 ~ 20220807) - ASEC BLOG
ASEC 분석팀에서는 ASEC 자동 분석 시스템 RAPIT 을 활용하여 알려진 악성코드들에 대한 분류 및 대응을 진행하고 있다. 본 포스팅에서는 2022년 8월 1일 월요일부터 8월 7일 일요일까지 한 주간 수집된 악성코드의 통계를 정리한다. 대분류 상으로는 인포스틸러가 47.4%로 1위를 차지하였으며, 그 다음으로는 백도어 악성코드가 22.6%, 다운로더 20.0%, 랜섬웨어 6.8%, 뱅킹 2.6%, 코인마이너 악성코드가 0.5%로 집계되었다. Top…