CTT Report Hub
3.42K subscribers
9.87K photos
6 videos
67 files
13.5K links
Threat Intelligence Report Hub
Download Telegram
#technique

D.RDynamicShellcode; Download & Run Dynamic Shellcode : it reads the shellcode from a url (has to be downloadable) locate it in a RWX section in memory and run it, useful for people looking for a shellcode as a 1st stage

https://gitlab.com/ORCA000/d.rdynamicshellcode
#ParsedReport
10-08-2022

VileRAT: DeathStalkers continuous strike at foreign and cryptocurrency exchanges

https://securelist.com/vilerat-deathstalkers-continuous-strike/107075

Actors/Campaigns:
Evilnum (motivation: financially_motivated)

Threats:
Vilerat
Janicab
Powersing
Powerpepper
Pyvil_rat
Vileloader
Viledropper

Industry:
Financial

Geo:
Russian, Germany, Kuwait, Bulgaria, Malta, Cyprus, Emirates

IOCs:
Url: 6
Hash: 145
File: 13
Path: 1
Domain: 287
IP: 22

Softs:
task scheduler, windows scheduled task, chrome

Algorithms:
rc4, xor, zip , bzip, lzma

Functions:
GetTickCount, NtAllocateVirtualMemory, NtWaitForSingleObject, API, CreateProcessW, NtCreateThreadEx, DelPort, SHGetFolderPathW

Languages:
python, javascript, cpython, php

Platforms:
x64

Links:
https://github.com/bontchev/pcodedmp
https://github.com/andrew-tavera/unpyc37/
https://github.com/eset/malware-ioc/tree/master/evilnum#february-2021-pyvil-and-evilnum-update
https://github.com/python/cpython/commit/0af9bef61afffbf128aba76a2e578059621b4f00
#ParsedReport
10-08-2022

Raspberry Robin: Highly Evasive Worm Spreads over External Disks

https://blogs.cisco.com/security/raspberry-robin-highly-evasive-worm-spreads-over-external-disks

Threats:
Raspberry_robin
Process_injection_technique
Uac_bypass_technique

TTPs:
Tactics: 2
Technics: 0

IOCs:
File: 10
Path: 6
Url: 3
Domain: 37

Softs:
windows installer

Algorithms:
exhibit
#ParsedReport
10-08-2022

Lockbit, Hive, and BlackCat attack automotive supplier in triple ransomware attack

https://news.sophos.com/en-us/2022/08/10/lockbit-hive-and-blackcat-attack-automotive-supplier-in-triple-ransomware-attack

Actors/Campaigns:
Blackcat

Threats:
Lockbit
Blackcat
Mimikatz
Atera_tool
Hive

Industry:
Iot, E-commerce

IOCs:
File: 12
Registry: 1
Hash: 4

Softs:
local security authority, psexec, vssadmin, bcdedit

Links:
https://github.com/sophoslabs/IoCs/blob/master/Ransomware\_Lockbit%20-%20triple%20ransomware%20attack.csv
https://github.com/sophoslabs/IoCs/blob/master/Ransomware\_BlackCat%20-%20triple%20ransomware%20attack.csv
https://github.com/sophoslabs/IoCs/blob/master/Ransomware\_Hive%20-%20triple%20ransomware%20attack.csv
#ParsedReport
11-08-2022

Cisco Talos shares insights related to recent cyber attack on Cisco

https://blog.talosintelligence.com/2022/08/recent-cyber-attack.html

Actors/Campaigns:
Unc2447 (motivation: financially_motivated)
Lapsus

Threats:
Yanluowang
Silence
Cobalt_strike
Logmein_tool
Teamviewer_tool
Powersploit
Mimikatz
Impacket_tool
Fivehands
Hellokitty

Industry:
Education

Geo:
Russia

TTPs:
Tactics: 10
Technics: 21

IOCs:
File: 1
Path: 1
Hash: 10
IP: 71
Domain: 14
Email: 1

Softs:
active directory, google chrome

Languages:
php

Platforms:
x64
#ParsedReport
11-08-2022

BlueSky Ransomware: Fast Encryption via Multithreading

https://unit42.paloaltonetworks.com/bluesky-ransomware

Actors/Campaigns:
Bluesky

Threats:
Conti
Babuk
Redline_stealer
Juicypotato_tool
Api_obfuscation_technique
Smbghost_tool

Industry:
Ics

Geo:
America, Japan, Apac, Emea

CVEs:
CVE-2021-1732 [Vulners]
Vulners: Score: 4.6, CVSS: 4.3,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (20h2, 1803, 1809, 1909, 2004)
- microsoft windows server 2016 (20h2, 1909, 2004)
- microsoft windows server 2019 (-)

CVE-2020-0796 [Vulners]
Vulners: Score: 7.5, CVSS: 3.2,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (1903, 1909)
- microsoft windows server 2016 (1903, 1909)


TTPs:
Tactics: 2
Technics: 6

IOCs:
Path: 2
Url: 11
File: 10
Domain: 1
Hash: 21

Algorithms:
chacha20, aes, rc4, curve25519

Functions:
PostQueuedCompletionStatus, GetQueuedCompletionPort, CreateIoCompletionPort, NetShareEnum

Platforms:
x86

Links:
https://github.com/gharty03/Conti-Ransomware
https://github.com/ohpe/juicy-potato
#ParsedReport
11-08-2022

MikuBot Spotted In The Wild

https://blog.cyble.com/2022/08/11/mikubot-spotted-in-the-wild

Threats:
Mikubot
Hiddenvnc_tool
Upx_tool
Beacon

Industry:
Financial

Geo:
India, Taiwan, Georgia, Dubai, Singapore, Australia

TTPs:
Tactics: 5
Technics: 9

IOCs:
Path: 1
Hash: 8

Softs:
task scheduler

Algorithms:
base64

Functions:
ShellExecuteW

Languages:
php
#ParsedReport
11-08-2022

A Comprehensive Analysis of the Zimbra Vulnerability CVE-2022-30333

https://cloudsek.com/threatintelligence/a-comprehensive-analysis-of-the-zimbra-vulnerability-cve-2022-30333/?utm_source=rss&utm_medium=rss&utm_campaign=a-comprehensive-analysis-of-the-zimbra-vulnerability-cve-2022-30333

Actors/Campaigns:
Emailthief

Industry:
Government

CVEs:
CVE-2022-30333 [Vulners]
Vulners: Score: 5.0, CVSS: 5.1,
Vulners: Exploitation: True
X-Force: Risk: 7.5
X-Force: Patch: Official fix
Soft:
- rarlab unrar (<6.12)


TTPs:
Tactics: 3
Technics: 0

IOCs:
Url: 5
IP: 4
Domain: 5

Softs:
unix

Functions:
DosSlashToUnix
#ParsedReport
11-08-2022

APT-C-35 Gets a New Upgrade

https://blog.morphisec.com/apt-c-35-new-windows-framework-revealed

Actors/Campaigns:
Donot

Threats:
Yty
Beacon

Industry:
Government

Geo:
Asia, Asian, India, Pakistan, Bangladesh

TTPs:
Tactics: 1
Technics: 0

IOCs:
File: 27
Path: 5
Url: 2
IP: 2
Hash: 17
Domain: 12

Softs:
android, virtualbox, google chrome, mozilla firefox, microsoft office

Algorithms:
base64, aes-256, xor

Functions:
ZwAllocateVirtualMemory

Languages:
python, php

Platforms:
x86
#ParsedReport
11-08-2022

BazarCall Advisory: Essential Guide to Attack Vector that Revolutionized Data Breaches

https://www.advintel.io/post/bazarcall-advisory-the-essential-guide-to-call-back-phishing-attacks-that-revolutionized-the-data

Actors/Campaigns:
Luna_moth

Threats:
Bazarbackdoor
Ryuk
Conti
Quantum_tool
Zeon
Emotet
Trickbot
Avaddon

Industry:
Foodtech, Financial

Geo:
Ukraine, Russian
#ParsedReport
11-08-2022

Detecting DNS implants: Old kitten, new tricks A Saitama Case Study

https://research.nccgroup.com/2022/08/11/detecting-dns-implants-old-kitten-new-tricks-a-saitama-case-study

Threats:
Saitama
Dnstunnelling_technique
Cobalt_strike
Sliver_tool

Industry:
Government

Geo:
Jordan

IOCs:
File: 2

Algorithms:
prng

Links:
https://github.com/fox-it/saitama-server
#ParsedReport
11-08-2022

CopperStealer Distributes Malicious Chromium-based Browser Extension to Steal Cryptocurrencies

https://www.trendmicro.com/en_us/research/22/h/copperstealer-distributes-malicious-chromium-browser-extension-steal-cryptocurrencies.html

Threats:
Copperstealer
Upx_tool
Tron

Industry:
Financial

Geo:
Turkish, Japanese, Italian, Polish, German, Portuguese, Indonesia, French, Spanish, Russian

IOCs:
File: 3
Hash: 30
Domain: 1

Softs:
zcash, centbrowser, orbitum, vivaldi, comodo dragon, opera, chromium, coinbase, chrome

Languages:
java, javascript, php
#ParsedReport
12-08-2022

Iron Tiger Compromises Chat Application Mimi, Targets Windows, Mac, and Linux Users

https://www.trendmicro.com/en_us/research/22/h/irontiger-compromises-chat-app-Mimi-targets-windows-mac-linux-users.html

Actors/Campaigns:
Emissary_panda (motivation: cyber_espionage)
Earth_berberoka
Drbcontrol

Threats:
Hyperbro
Rshell
Dll_sideloading_technique
Gh0st_rat
Plugx_rat
Shadowpad

Industry:
Entertainment

Geo:
Taiwan, Chinese, Philippines

IOCs:
File: 4
IP: 3
Domain: 4
Hash: 11

Softs:
windows installer, macos, node.js, mac os, android

Languages:
javascript

Links:
https://github.com/f0rb1dd3n/Reptile
#ParsedReport
13-08-2022

LuckyMouse uses a backdoored Electron app to target MacOS

https://blog.sekoia.io/luckymouse-uses-a-backdoored-electron-app-to-target-macos

Actors/Campaigns:
Emissary_panda (motivation: cyber_espionage)
Stealthytrident

Threats:
Hyberbro
Rshell
Plugx_rat
Tmanger
Hyperbro
Watering_hole_technique
Luckymouse

Geo:
Mongolia, China, Chinese

IOCs:
Domain: 1
File: 10
IP: 6
Url: 2
Hash: 9

Softs:
macos, android

Languages:
javascript

Platforms:
apple

YARA: Found
#ParsedReport
14-08-2022

Typosquatting Campaign Targeting Pythons Top Packages, Dropping GitHub Hosted Malware with DGA Capabilities. Attack Vector Typosquatting

https://checkmarx.com/blog/typosquatting-campaign-targeting-pythons-top-packages-dropping-github-hosted-malware-with-dga-capabilities

Threats:
Typosquatting_technique

TTPs:
Tactics: 1
Technics: 0

IOCs:
File: 3
Path: 2
Url: 10
Hash: 3

Algorithms:
xor

Languages:
python

Links:
https://github.com/jagermager999/8746465cdg78cdsxasy8a/commits/main
https://github.com/jagermager999
https://github.com/jagermager999/8746465cdg78cdsxasy8a
#ParsedReport
15-08-2022

Shuckworm: Russia-Linked Group Maintains Ukraine Focus

https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/russia-ukraine-shuckworm

Actors/Campaigns:
Gamaredon (motivation: cyber_espionage)

Threats:
Giddome
Ammyy_admin_tool
Anydesk_tool
Decay

Geo:
Russian, Ukrainian, Ukraine, Russia

IOCs:
File: 14
Domain: 5
Hash: 43
Url: 10
Path: 1

Functions:
PowerShell, InternetExplorer

Languages:
php