#ParsedReport
09-08-2022
Novel News on Cuba Ransomware aka Greetings From Tropical Scorpius
https://unit42.paloaltonetworks.com/cuba-ransomware-tropical-scorpius
Actors/Campaigns:
Unc2596
Lapsus
Threats:
Cuba
Romcom_rat
Kerbercache_tool
Zerologon_vuln
Hancitor
Proxyshell_vuln
Proxylogon_exploit
Maze
Revil
Lockbit
Burntcigar_tool
Adfind_tool
Kerberoasting_technique
Mimikatz
Themida_tool
Qakbot
Beacon
Pid_spoofing_technique
Process_injection_technique
Industry:
Government, Financial, Education, E-commerce, Transport, Retail, Logistic, Healthcare, Energy
Geo:
Emea, Japan, Apac, America
CVEs:
CVE-2022-24521 [Vulners]
Vulners: Score: 4.6, CVSS: 4.2,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (-, 20h2, 21h1, 21h2, 1607, 1809, 1909)
- microsoft windows 11 (-, -)
- microsoft windows 7 (-)
- microsoft windows 8.1 (-)
- microsoft windows rt 8.1 (-)
have more...
CVE-2020-1472 [Vulners]
Vulners: Score: 9.3, CVSS: 3.8,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2)
- microsoft windows server 2012 (-, r2)
- microsoft windows server 2016 (-, 1903, 1909, 2004)
- microsoft windows server 2019 (-)
- fedoraproject fedora (31, 32, 33)
have more...
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 21
Coin: 5
Domain: 3
Email: 2
IP: 2
Path: 1
Hash: 16
Softs:
sqlbrowser, task scheduler, active directory, microsoft exchange, sqlagent, mysql
Algorithms:
chacha, rsa-4096, zip
Functions:
GetUserSPNs, CreateProcessA, the, MmGetSystemRoutineAddress, LsaLookupAuthenticationPackage, PsGetThreadProcess, IcmpCreateFile, LsaCallAuthenticationPackage, IcmpSendEcho, PsIsThreadTerminating, PsLookupThreadByThreadId
Platforms:
x86
09-08-2022
Novel News on Cuba Ransomware aka Greetings From Tropical Scorpius
https://unit42.paloaltonetworks.com/cuba-ransomware-tropical-scorpius
Actors/Campaigns:
Unc2596
Lapsus
Threats:
Cuba
Romcom_rat
Kerbercache_tool
Zerologon_vuln
Hancitor
Proxyshell_vuln
Proxylogon_exploit
Maze
Revil
Lockbit
Burntcigar_tool
Adfind_tool
Kerberoasting_technique
Mimikatz
Themida_tool
Qakbot
Beacon
Pid_spoofing_technique
Process_injection_technique
Industry:
Government, Financial, Education, E-commerce, Transport, Retail, Logistic, Healthcare, Energy
Geo:
Emea, Japan, Apac, America
CVEs:
CVE-2022-24521 [Vulners]
Vulners: Score: 4.6, CVSS: 4.2,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (-, 20h2, 21h1, 21h2, 1607, 1809, 1909)
- microsoft windows 11 (-, -)
- microsoft windows 7 (-)
- microsoft windows 8.1 (-)
- microsoft windows rt 8.1 (-)
have more...
CVE-2020-1472 [Vulners]
Vulners: Score: 9.3, CVSS: 3.8,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2)
- microsoft windows server 2012 (-, r2)
- microsoft windows server 2016 (-, 1903, 1909, 2004)
- microsoft windows server 2019 (-)
- fedoraproject fedora (31, 32, 33)
have more...
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 21
Coin: 5
Domain: 3
Email: 2
IP: 2
Path: 1
Hash: 16
Softs:
sqlbrowser, task scheduler, active directory, microsoft exchange, sqlagent, mysql
Algorithms:
chacha, rsa-4096, zip
Functions:
GetUserSPNs, CreateProcessA, the, MmGetSystemRoutineAddress, LsaLookupAuthenticationPackage, PsGetThreadProcess, IcmpCreateFile, LsaCallAuthenticationPackage, IcmpSendEcho, PsIsThreadTerminating, PsLookupThreadByThreadId
Platforms:
x86
Unit 42
Novel News on Cuba Ransomware: Greetings From Tropical Scorpius
Tropical Scorpius has been deploying Cuba Ransomware using novel tools and techniques, such as a new malware family, ROMCOM RAT.
#ParsedReport
09-08-2022
Global scam operation "Classiscam" expanded toSingapore. Global scam operation "Classiscam" expanded to Singapore
https://www.group-ib.com/media/classiscam-singapore-global-scam-operation
Threats:
Classiscam
Industry:
Education, Foodtech, Financial, E-commerce
Geo:
Singapore, Asia, Dubai, Russian, Pacific, Asian, Russia
Softs:
telegram
09-08-2022
Global scam operation "Classiscam" expanded toSingapore. Global scam operation "Classiscam" expanded to Singapore
https://www.group-ib.com/media/classiscam-singapore-global-scam-operation
Threats:
Classiscam
Industry:
Education, Foodtech, Financial, E-commerce
Geo:
Singapore, Asia, Dubai, Russian, Pacific, Asian, Russia
Softs:
telegram
Group-IB
Global scam operation "Classiscam" expanded to Singapore
Group-IB has uncovered that Classiscam a sophisticated scam-as-a-service operation has expanded to Singapore in March 2022.
#ParsedReport
09-08-2022
CotSam, Never Before Seen Malware linked to TA428 involved in EU attack
https://www.secureblink.com/threat-research/cot-sam-never-before-seen-malware-linked-to-ta-428-involved-in-eu-attack
Actors/Campaigns:
Ta428
Threats:
Cotsam
Cotx_rat
Dll_hijacking_technique
Shadowpad
Nbtscan_tool
Ladon_tool
Netstat_tool
Golden_ticket_technique
Industry:
Government
Geo:
Chinese, Afghanistan
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 10
Hash: 1
Registry: 3
Path: 2
Softs:
task scheduler, active directory, microsoft word
Algorithms:
xor
Functions:
WriteProcessMemory
09-08-2022
CotSam, Never Before Seen Malware linked to TA428 involved in EU attack
https://www.secureblink.com/threat-research/cot-sam-never-before-seen-malware-linked-to-ta-428-involved-in-eu-attack
Actors/Campaigns:
Ta428
Threats:
Cotsam
Cotx_rat
Dll_hijacking_technique
Shadowpad
Nbtscan_tool
Ladon_tool
Netstat_tool
Golden_ticket_technique
Industry:
Government
Geo:
Chinese, Afghanistan
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 10
Hash: 1
Registry: 3
Path: 2
Softs:
task scheduler, active directory, microsoft word
Algorithms:
xor
Functions:
WriteProcessMemory
Secureblink
CotSam, Never Before Seen Malware linked to TA428 involved in EU attack | Secure Blink
CotSam: a never seen before malware strain involved in the targeted attacks across several European & Afghanistan institutions linked to infamous APT group TA428...
#ParsedReport
09-08-2022
Life After DeathSmokeLoader Continues to Haunt Using Old Vulnerabilities
https://www.fortinet.com/blog/threat-research/smokeloader-using-old-vulnerabilities
Threats:
Smokeloader
Trickbot
Quasar_rat
Velvetsweatshop_technique
Vba/agent.bmw!tr.dldr
Industry:
Transport, Financial, Telco
Geo:
Chinese, Taiwan
CVEs:
CVE-2017-11882 [Vulners]
Vulners: Score: 9.3, CVSS: 4.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2013, 2010, 2016, 2007)
CVE-2017-0199 [Vulners]
Vulners: Score: 9.3, CVSS: 7.8,
Vulners: Exploitation: True
X-Force: Risk: 9.3
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2, *)
- microsoft windows server 2012 (-)
- microsoft windows vista (*)
- microsoft office (2010, 2013, 2016, 2007)
- microsoft windows 7 (*)
have more...
IOCs:
IP: 1
File: 2
Domain: 3
Hash: 5
Softs:
microsoft word
Algorithms:
gzip
09-08-2022
Life After DeathSmokeLoader Continues to Haunt Using Old Vulnerabilities
https://www.fortinet.com/blog/threat-research/smokeloader-using-old-vulnerabilities
Threats:
Smokeloader
Trickbot
Quasar_rat
Velvetsweatshop_technique
Vba/agent.bmw!tr.dldr
Industry:
Transport, Financial, Telco
Geo:
Chinese, Taiwan
CVEs:
CVE-2017-11882 [Vulners]
Vulners: Score: 9.3, CVSS: 4.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2013, 2010, 2016, 2007)
CVE-2017-0199 [Vulners]
Vulners: Score: 9.3, CVSS: 7.8,
Vulners: Exploitation: True
X-Force: Risk: 9.3
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2, *)
- microsoft windows server 2012 (-)
- microsoft windows vista (*)
- microsoft office (2010, 2013, 2016, 2007)
- microsoft windows 7 (*)
have more...
IOCs:
IP: 1
File: 2
Domain: 3
Hash: 5
Softs:
microsoft word
Algorithms:
gzip
Fortinet Blog
Life After DeathโSmokeLoader Continues to Haunt Using Old Vulnerabilities
FortiGuard Labs examines SmokeLoader, a malware variant that exploits CVE-2017-0199 and CVE-2017-11882 in its deployment chain. Read our analysis blog to learn about the latest sample.โฆ
#ParsedReport
09-08-2022
Bitter APT group using Dracarys Android Spyware
https://blog.cyble.com/2022/08/09/bitter-apt-group-using-dracarys-android-spyware
Actors/Campaigns:
Bitter
Threats:
Dracarys
Industry:
Financial
Geo:
Asia, Pakistan, India, Asian, China
TTPs:
Tactics: 3
Technics: 0
IOCs:
File: 1
Url: 4
Hash: 3
Softs:
android, telegram
09-08-2022
Bitter APT group using Dracarys Android Spyware
https://blog.cyble.com/2022/08/09/bitter-apt-group-using-dracarys-android-spyware
Actors/Campaigns:
Bitter
Threats:
Dracarys
Industry:
Financial
Geo:
Asia, Pakistan, India, Asian, China
TTPs:
Tactics: 3
Technics: 0
IOCs:
File: 1
Url: 4
Hash: 3
Softs:
android, telegram
Cyble
Cyble - Bitter APT Group Using "Dracarys" Android Spyware
Cyble analyzes the Bitter APT group leveraging trojanized Messaging Apps to deliver Dracarys Android Malware.
#ParsedReport
09-08-2022
Pivoting on a SharpExt to profile Kimusky panels for great good. Older Campaigns
https://medium.com/walmartglobaltech/pivoting-on-a-sharpext-to-profile-kimusky-panels-for-great-good-1920dc1bcef9
Actors/Campaigns:
Kimsuky
Threats:
Sharpext
Geo:
Korea
IOCs:
Url: 1
File: 32
Domain: 1
Hash: 38
Path: 1
Registry: 14
09-08-2022
Pivoting on a SharpExt to profile Kimusky panels for great good. Older Campaigns
https://medium.com/walmartglobaltech/pivoting-on-a-sharpext-to-profile-kimusky-panels-for-great-good-1920dc1bcef9
Actors/Campaigns:
Kimsuky
Threats:
Sharpext
Geo:
Korea
IOCs:
Url: 1
File: 32
Domain: 1
Hash: 38
Path: 1
Registry: 14
Medium
Pivoting on a SharpExt to profile Kimusky panels for great good
By: Jason Reaves and Joshua Platt
#technique
D.RDynamicShellcode; Download & Run Dynamic Shellcode : it reads the shellcode from a url (has to be downloadable) locate it in a RWX section in memory and run it, useful for people looking for a shellcode as a 1st stage
https://gitlab.com/ORCA000/d.rdynamicshellcode
D.RDynamicShellcode; Download & Run Dynamic Shellcode : it reads the shellcode from a url (has to be downloadable) locate it in a RWX section in memory and run it, useful for people looking for a shellcode as a 1st stage
https://gitlab.com/ORCA000/d.rdynamicshellcode
GitLab
ORCA / D.RDynamicShellcode ยท GitLab
Download & Run Dynamic x64 Shellcode
#ParsedReport
09-08-2022
Abusing Google Sites and Microsoft Azure for Crypto Phishing
https://www.netskope.com/blog/abusing-google-sites-and-microsoft-azure-for-crypto-phishing
Threats:
Kraken
Ousaban
Industry:
Financial
Geo:
Latam
IOCs:
Url: 42
Softs:
coinbase
09-08-2022
Abusing Google Sites and Microsoft Azure for Crypto Phishing
https://www.netskope.com/blog/abusing-google-sites-and-microsoft-azure-for-crypto-phishing
Threats:
Kraken
Ousaban
Industry:
Financial
Geo:
Latam
IOCs:
Url: 42
Softs:
coinbase
Netskope
Abusing Google Sites and Microsoft Azure for Crypto Phishing
Summary Throughout 2022, Netskope Threat Labs found that attackers have been creating phishing pages in Google Sites and Microsoft Azure Web App to steal
#ParsedReport
10-08-2022
SpyNote An Android Snooper
https://labs.k7computing.com/index.php/spynote-an-android-snooper
Threats:
Spynote
Cyberchef_tool
Geo:
Indian
TTPs:
Tactics: 4
Technics: 0
IOCs:
File: 6
IP: 1
Hash: 1
Domain: 1
Softs:
android
Algorithms:
gzip
10-08-2022
SpyNote An Android Snooper
https://labs.k7computing.com/index.php/spynote-an-android-snooper
Threats:
Spynote
Cyberchef_tool
Geo:
Indian
TTPs:
Tactics: 4
Technics: 0
IOCs:
File: 6
IP: 1
Hash: 1
Domain: 1
Softs:
android
Algorithms:
gzip
K7 Labs
SpyNote โ An Android Snooper
Threat actors are constantly using new tricks and tactics to target users across the globe. This blog is about SpyNote, [โฆ]
#ParsedReport
10-08-2022
VileRAT: DeathStalkers continuous strike at foreign and cryptocurrency exchanges
https://securelist.com/vilerat-deathstalkers-continuous-strike/107075
Actors/Campaigns:
Evilnum (motivation: financially_motivated)
Threats:
Vilerat
Janicab
Powersing
Powerpepper
Pyvil_rat
Vileloader
Viledropper
Industry:
Financial
Geo:
Russian, Germany, Kuwait, Bulgaria, Malta, Cyprus, Emirates
IOCs:
Url: 6
Hash: 145
File: 13
Path: 1
Domain: 287
IP: 22
Softs:
task scheduler, windows scheduled task, chrome
Algorithms:
rc4, xor, zip , bzip, lzma
Functions:
GetTickCount, NtAllocateVirtualMemory, NtWaitForSingleObject, API, CreateProcessW, NtCreateThreadEx, DelPort, SHGetFolderPathW
Languages:
python, javascript, cpython, php
Platforms:
x64
Links:
10-08-2022
VileRAT: DeathStalkers continuous strike at foreign and cryptocurrency exchanges
https://securelist.com/vilerat-deathstalkers-continuous-strike/107075
Actors/Campaigns:
Evilnum (motivation: financially_motivated)
Threats:
Vilerat
Janicab
Powersing
Powerpepper
Pyvil_rat
Vileloader
Viledropper
Industry:
Financial
Geo:
Russian, Germany, Kuwait, Bulgaria, Malta, Cyprus, Emirates
IOCs:
Url: 6
Hash: 145
File: 13
Path: 1
Domain: 287
IP: 22
Softs:
task scheduler, windows scheduled task, chrome
Algorithms:
rc4, xor, zip , bzip, lzma
Functions:
GetTickCount, NtAllocateVirtualMemory, NtWaitForSingleObject, API, CreateProcessW, NtCreateThreadEx, DelPort, SHGetFolderPathW
Languages:
python, javascript, cpython, php
Platforms:
x64
Links:
https://github.com/bontchev/pcodedmphttps://github.com/andrew-tavera/unpyc37/https://github.com/eset/malware-ioc/tree/master/evilnum#february-2021-pyvil-and-evilnum-updatehttps://github.com/python/cpython/commit/0af9bef61afffbf128aba76a2e578059621b4f00Securelist
VileRAT: DeathStalkerโs continuous strike at foreign and cryptocurrency exchanges
VileRAT is a Python implant, part of an evasive and highly intricate attack campaign against foreign exchange and cryptocurrency trading companies.
#ParsedReport
10-08-2022
Raspberry Robin: Highly Evasive Worm Spreads over External Disks
https://blogs.cisco.com/security/raspberry-robin-highly-evasive-worm-spreads-over-external-disks
Threats:
Raspberry_robin
Process_injection_technique
Uac_bypass_technique
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 10
Path: 6
Url: 3
Domain: 37
Softs:
windows installer
Algorithms:
exhibit
10-08-2022
Raspberry Robin: Highly Evasive Worm Spreads over External Disks
https://blogs.cisco.com/security/raspberry-robin-highly-evasive-worm-spreads-over-external-disks
Threats:
Raspberry_robin
Process_injection_technique
Uac_bypass_technique
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 10
Path: 6
Url: 3
Domain: 37
Softs:
windows installer
Algorithms:
exhibit
Cisco Blogs
Raspberry Robin: Highly Evasive Worm Spreads over External Disks
During our threat hunting exercises in recent months, weโve started to observe a distinguishing pattern of msiexec.exe usage across different endpoints.
#ParsedReport
10-08-2022
Lockbit, Hive, and BlackCat attack automotive supplier in triple ransomware attack
https://news.sophos.com/en-us/2022/08/10/lockbit-hive-and-blackcat-attack-automotive-supplier-in-triple-ransomware-attack
Actors/Campaigns:
Blackcat
Threats:
Lockbit
Blackcat
Mimikatz
Atera_tool
Hive
Industry:
Iot, E-commerce
IOCs:
File: 12
Registry: 1
Hash: 4
Softs:
local security authority, psexec, vssadmin, bcdedit
Links:
10-08-2022
Lockbit, Hive, and BlackCat attack automotive supplier in triple ransomware attack
https://news.sophos.com/en-us/2022/08/10/lockbit-hive-and-blackcat-attack-automotive-supplier-in-triple-ransomware-attack
Actors/Campaigns:
Blackcat
Threats:
Lockbit
Blackcat
Mimikatz
Atera_tool
Hive
Industry:
Iot, E-commerce
IOCs:
File: 12
Registry: 1
Hash: 4
Softs:
local security authority, psexec, vssadmin, bcdedit
Links:
https://github.com/sophoslabs/IoCs/blob/master/Ransomware\_Lockbit%20-%20triple%20ransomware%20attack.csvhttps://github.com/sophoslabs/IoCs/blob/master/Ransomware\_BlackCat%20-%20triple%20ransomware%20attack.csvhttps://github.com/sophoslabs/IoCs/blob/master/Ransomware\_Hive%20-%20triple%20ransomware%20attack.csvSophos News
Lockbit, Hive, and BlackCat attack automotive supplier in triple ransomware attack
After gaining access via RDP, all three threat actors encrypted files, in an investigation complicated by event log clearing and backups. 3 attackers, 2 weeks โ 1 entry point.
#ParsedReport
10-08-2022
ASEC (20220801 \~ 20220807). ASEC Weekly Malware Statistics (20220801 \~ 20220807)
https://asec.ahnlab.com/ko/37552
Threats:
Agent_tesla
Azorult
Formbook
Clipboard_grabbing_technique
Cloudeye
Postealer
Remcos_rat
Nanocore_rat
Redline_stealer
Beamwinhttp_loader
Vidar_stealer
Antefrigus
Revil
Industry:
Financial, Transport
Geo:
Korea
IOCs:
File: 38
Domain: 3
IP: 3
Email: 5
Url: 25
Softs:
nsis installer, discord
Languages:
visual_basic
10-08-2022
ASEC (20220801 \~ 20220807). ASEC Weekly Malware Statistics (20220801 \~ 20220807)
https://asec.ahnlab.com/ko/37552
Threats:
Agent_tesla
Azorult
Formbook
Clipboard_grabbing_technique
Cloudeye
Postealer
Remcos_rat
Nanocore_rat
Redline_stealer
Beamwinhttp_loader
Vidar_stealer
Antefrigus
Revil
Industry:
Financial, Transport
Geo:
Korea
IOCs:
File: 38
Domain: 3
IP: 3
Email: 5
Url: 25
Softs:
nsis installer, discord
Languages:
visual_basic
ASEC BLOG
ASEC ์ฃผ๊ฐ ์
์ฑ์ฝ๋ ํต๊ณ (20220801 ~ 20220807) - ASEC BLOG
ASEC ๋ถ์ํ์์๋ ASEC ์๋ ๋ถ์ ์์คํ
RAPIT ์ ํ์ฉํ์ฌ ์๋ ค์ง ์
์ฑ์ฝ๋๋ค์ ๋ํ ๋ถ๋ฅ ๋ฐ ๋์์ ์งํํ๊ณ ์๋ค. ๋ณธ ํฌ์คํ
์์๋ 2022๋
8์ 1์ผ ์์์ผ๋ถํฐ 8์ 7์ผ ์ผ์์ผ๊น์ง ํ ์ฃผ๊ฐ ์์ง๋ ์
์ฑ์ฝ๋์ ํต๊ณ๋ฅผ ์ ๋ฆฌํ๋ค. ๋๋ถ๋ฅ ์์ผ๋ก๋ ์ธํฌ์คํธ๋ฌ๊ฐ 47.4%๋ก 1์๋ฅผ ์ฐจ์งํ์์ผ๋ฉฐ, ๊ทธ ๋ค์์ผ๋ก๋ ๋ฐฑ๋์ด ์
์ฑ์ฝ๋๊ฐ 22.6%, ๋ค์ด๋ก๋ 20.0%, ๋์ฌ์จ์ด 6.8%, ๋ฑ
ํน 2.6%, ์ฝ์ธ๋ง์ด๋ ์
์ฑ์ฝ๋๊ฐ 0.5%๋ก ์ง๊ณ๋์๋ค. Topโฆ
#ParsedReport
11-08-2022
Cisco Talos shares insights related to recent cyber attack on Cisco
https://blog.talosintelligence.com/2022/08/recent-cyber-attack.html
Actors/Campaigns:
Unc2447 (motivation: financially_motivated)
Lapsus
Threats:
Yanluowang
Silence
Cobalt_strike
Logmein_tool
Teamviewer_tool
Powersploit
Mimikatz
Impacket_tool
Fivehands
Hellokitty
Industry:
Education
Geo:
Russia
TTPs:
Tactics: 10
Technics: 21
IOCs:
File: 1
Path: 1
Hash: 10
IP: 71
Domain: 14
Email: 1
Softs:
active directory, google chrome
Languages:
php
Platforms:
x64
11-08-2022
Cisco Talos shares insights related to recent cyber attack on Cisco
https://blog.talosintelligence.com/2022/08/recent-cyber-attack.html
Actors/Campaigns:
Unc2447 (motivation: financially_motivated)
Lapsus
Threats:
Yanluowang
Silence
Cobalt_strike
Logmein_tool
Teamviewer_tool
Powersploit
Mimikatz
Impacket_tool
Fivehands
Hellokitty
Industry:
Education
Geo:
Russia
TTPs:
Tactics: 10
Technics: 21
IOCs:
File: 1
Path: 1
Hash: 10
IP: 71
Domain: 14
Email: 1
Softs:
active directory, google chrome
Languages:
php
Platforms:
x64
Cisco Talos
Cisco Talos shares insights related to recent cyber attack on Cisco
Update History Aug. 10, 2022 Adding clarifying details on activity involving active directory. Aug. 10, 2022 Update made to the Cisco Response and Recommendations section related to MFA.
#ParsedReport
11-08-2022
BlueSky Ransomware: Fast Encryption via Multithreading
https://unit42.paloaltonetworks.com/bluesky-ransomware
Actors/Campaigns:
Bluesky
Threats:
Conti
Babuk
Redline_stealer
Juicypotato_tool
Api_obfuscation_technique
Smbghost_tool
Industry:
Ics
Geo:
America, Japan, Apac, Emea
CVEs:
CVE-2021-1732 [Vulners]
Vulners: Score: 4.6, CVSS: 4.3,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (20h2, 1803, 1809, 1909, 2004)
- microsoft windows server 2016 (20h2, 1909, 2004)
- microsoft windows server 2019 (-)
CVE-2020-0796 [Vulners]
Vulners: Score: 7.5, CVSS: 3.2,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (1903, 1909)
- microsoft windows server 2016 (1903, 1909)
TTPs:
Tactics: 2
Technics: 6
IOCs:
Path: 2
Url: 11
File: 10
Domain: 1
Hash: 21
Algorithms:
chacha20, aes, rc4, curve25519
Functions:
PostQueuedCompletionStatus, GetQueuedCompletionPort, CreateIoCompletionPort, NetShareEnum
Platforms:
x86
Links:
11-08-2022
BlueSky Ransomware: Fast Encryption via Multithreading
https://unit42.paloaltonetworks.com/bluesky-ransomware
Actors/Campaigns:
Bluesky
Threats:
Conti
Babuk
Redline_stealer
Juicypotato_tool
Api_obfuscation_technique
Smbghost_tool
Industry:
Ics
Geo:
America, Japan, Apac, Emea
CVEs:
CVE-2021-1732 [Vulners]
Vulners: Score: 4.6, CVSS: 4.3,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (20h2, 1803, 1809, 1909, 2004)
- microsoft windows server 2016 (20h2, 1909, 2004)
- microsoft windows server 2019 (-)
CVE-2020-0796 [Vulners]
Vulners: Score: 7.5, CVSS: 3.2,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (1903, 1909)
- microsoft windows server 2016 (1903, 1909)
TTPs:
Tactics: 2
Technics: 6
IOCs:
Path: 2
Url: 11
File: 10
Domain: 1
Hash: 21
Algorithms:
chacha20, aes, rc4, curve25519
Functions:
PostQueuedCompletionStatus, GetQueuedCompletionPort, CreateIoCompletionPort, NetShareEnum
Platforms:
x86
Links:
https://github.com/gharty03/Conti-Ransomwarehttps://github.com/ohpe/juicy-potatoUnit 42
BlueSky Ransomware: Fast Encryption via Multithreading
BlueSky ransomware is an emerging family that has adopted modern techniques to evade security defenses. Read our technical analysis.
#ParsedReport
11-08-2022
MikuBot Spotted In The Wild
https://blog.cyble.com/2022/08/11/mikubot-spotted-in-the-wild
Threats:
Mikubot
Hiddenvnc_tool
Upx_tool
Beacon
Industry:
Financial
Geo:
India, Taiwan, Georgia, Dubai, Singapore, Australia
TTPs:
Tactics: 5
Technics: 9
IOCs:
Path: 1
Hash: 8
Softs:
task scheduler
Algorithms:
base64
Functions:
ShellExecuteW
Languages:
php
11-08-2022
MikuBot Spotted In The Wild
https://blog.cyble.com/2022/08/11/mikubot-spotted-in-the-wild
Threats:
Mikubot
Hiddenvnc_tool
Upx_tool
Beacon
Industry:
Financial
Geo:
India, Taiwan, Georgia, Dubai, Singapore, Australia
TTPs:
Tactics: 5
Technics: 9
IOCs:
Path: 1
Hash: 8
Softs:
task scheduler
Algorithms:
base64
Functions:
ShellExecuteW
Languages:
php
Cyble
MikuBot Spotted In The Wild
Cyble analyzes the newly discovered Mikubot and the spyware activities that it conducts using HVNCs.
#ParsedReport
11-08-2022
A Comprehensive Analysis of the Zimbra Vulnerability CVE-2022-30333
https://cloudsek.com/threatintelligence/a-comprehensive-analysis-of-the-zimbra-vulnerability-cve-2022-30333/?utm_source=rss&utm_medium=rss&utm_campaign=a-comprehensive-analysis-of-the-zimbra-vulnerability-cve-2022-30333
Actors/Campaigns:
Emailthief
Industry:
Government
CVEs:
CVE-2022-30333 [Vulners]
Vulners: Score: 5.0, CVSS: 5.1,
Vulners: Exploitation: True
X-Force: Risk: 7.5
X-Force: Patch: Official fix
Soft:
- rarlab unrar (<6.12)
TTPs:
Tactics: 3
Technics: 0
IOCs:
Url: 5
IP: 4
Domain: 5
Softs:
unix
Functions:
DosSlashToUnix
11-08-2022
A Comprehensive Analysis of the Zimbra Vulnerability CVE-2022-30333
https://cloudsek.com/threatintelligence/a-comprehensive-analysis-of-the-zimbra-vulnerability-cve-2022-30333/?utm_source=rss&utm_medium=rss&utm_campaign=a-comprehensive-analysis-of-the-zimbra-vulnerability-cve-2022-30333
Actors/Campaigns:
Emailthief
Industry:
Government
CVEs:
CVE-2022-30333 [Vulners]
Vulners: Score: 5.0, CVSS: 5.1,
Vulners: Exploitation: True
X-Force: Risk: 7.5
X-Force: Patch: Official fix
Soft:
- rarlab unrar (<6.12)
TTPs:
Tactics: 3
Technics: 0
IOCs:
Url: 5
IP: 4
Domain: 5
Softs:
unix
Functions:
DosSlashToUnix
Cloudsek
A Comprehensive Analysis of the Zimbra Vulnerability CVE-2022-30333 | Threat Intelligence | CloudSEK
An RCE vulnerability in Zimbra webmail servers being actively exploited to target multiple organizations worldwide. The exploit was used to launch a spear phishing campaign against Europe.
#ParsedReport
11-08-2022
APT-C-35 Gets a New Upgrade
https://blog.morphisec.com/apt-c-35-new-windows-framework-revealed
Actors/Campaigns:
Donot
Threats:
Yty
Beacon
Industry:
Government
Geo:
Asia, Asian, India, Pakistan, Bangladesh
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 27
Path: 5
Url: 2
IP: 2
Hash: 17
Domain: 12
Softs:
android, virtualbox, google chrome, mozilla firefox, microsoft office
Algorithms:
base64, aes-256, xor
Functions:
ZwAllocateVirtualMemory
Languages:
python, php
Platforms:
x86
11-08-2022
APT-C-35 Gets a New Upgrade
https://blog.morphisec.com/apt-c-35-new-windows-framework-revealed
Actors/Campaigns:
Donot
Threats:
Yty
Beacon
Industry:
Government
Geo:
Asia, Asian, India, Pakistan, Bangladesh
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 27
Path: 5
Url: 2
IP: 2
Hash: 17
Domain: 12
Softs:
android, virtualbox, google chrome, mozilla firefox, microsoft office
Algorithms:
base64, aes-256, xor
Functions:
ZwAllocateVirtualMemory
Languages:
python, php
Platforms:
x86
Morphisec
APT-C-35: New Windows Framework Revealed
Morphisec Labs exclusively details new updates to the Windows framework of the advanced persistent threat actors APT-C-35, a.k.a the DoNot Team.
#ParsedReport
11-08-2022
BazarCall Advisory: Essential Guide to Attack Vector that Revolutionized Data Breaches
https://www.advintel.io/post/bazarcall-advisory-the-essential-guide-to-call-back-phishing-attacks-that-revolutionized-the-data
Actors/Campaigns:
Luna_moth
Threats:
Bazarbackdoor
Ryuk
Conti
Quantum_tool
Zeon
Emotet
Trickbot
Avaddon
Industry:
Foodtech, Financial
Geo:
Ukraine, Russian
11-08-2022
BazarCall Advisory: Essential Guide to Attack Vector that Revolutionized Data Breaches
https://www.advintel.io/post/bazarcall-advisory-the-essential-guide-to-call-back-phishing-attacks-that-revolutionized-the-data
Actors/Campaigns:
Luna_moth
Threats:
Bazarbackdoor
Ryuk
Conti
Quantum_tool
Zeon
Emotet
Trickbot
Avaddon
Industry:
Foodtech, Financial
Geo:
Ukraine, Russian
#ParsedReport
11-08-2022
SOVA malware is back and is evolving rapidly
https://www.cleafy.com/cleafy-labs/sova-malware-is-back-and-is-evolving-rapidly
Threats:
Sova
Anatsa
Oscorp
Brata
Industry:
Financial
Geo:
Philippine, Francesco, Ukraine, Russian
IOCs:
File: 1
Hash: 3
Domain: 2
Softs:
chrome, android
Algorithms:
aes
11-08-2022
SOVA malware is back and is evolving rapidly
https://www.cleafy.com/cleafy-labs/sova-malware-is-back-and-is-evolving-rapidly
Threats:
Sova
Anatsa
Oscorp
Brata
Industry:
Financial
Geo:
Philippine, Francesco, Ukraine, Russian
IOCs:
File: 1
Hash: 3
Domain: 2
Softs:
chrome, android
Algorithms:
aes
Cleafy
SOVA malware is back and is evolving rapidly | Cleafy Labs
SOVA, a new Android Banking Trojan, is spreading across Europe. Already appeared in different versions, this malware is now evolving, and it is targeting more than 200 mobile applications, ranging from banking apps to crypto exchanges/wallets. Here's theโฆ