#ParsedReport
11-08-2022
A Comprehensive Analysis of the Zimbra Vulnerability CVE-2022-30333
https://cloudsek.com/threatintelligence/a-comprehensive-analysis-of-the-zimbra-vulnerability-cve-2022-30333/?utm_source=rss&utm_medium=rss&utm_campaign=a-comprehensive-analysis-of-the-zimbra-vulnerability-cve-2022-30333
Actors/Campaigns:
Emailthief
Industry:
Government
CVEs:
CVE-2022-30333 [Vulners]
Vulners: Score: 5.0, CVSS: 5.1,
Vulners: Exploitation: True
X-Force: Risk: 7.5
X-Force: Patch: Official fix
Soft:
- rarlab unrar (<6.12)
TTPs:
Tactics: 3
Technics: 0
IOCs:
Url: 5
IP: 4
Domain: 5
Softs:
unix
Functions:
DosSlashToUnix
11-08-2022
A Comprehensive Analysis of the Zimbra Vulnerability CVE-2022-30333
https://cloudsek.com/threatintelligence/a-comprehensive-analysis-of-the-zimbra-vulnerability-cve-2022-30333/?utm_source=rss&utm_medium=rss&utm_campaign=a-comprehensive-analysis-of-the-zimbra-vulnerability-cve-2022-30333
Actors/Campaigns:
Emailthief
Industry:
Government
CVEs:
CVE-2022-30333 [Vulners]
Vulners: Score: 5.0, CVSS: 5.1,
Vulners: Exploitation: True
X-Force: Risk: 7.5
X-Force: Patch: Official fix
Soft:
- rarlab unrar (<6.12)
TTPs:
Tactics: 3
Technics: 0
IOCs:
Url: 5
IP: 4
Domain: 5
Softs:
unix
Functions:
DosSlashToUnix
Cloudsek
A Comprehensive Analysis of the Zimbra Vulnerability CVE-2022-30333 | Threat Intelligence | CloudSEK
An RCE vulnerability in Zimbra webmail servers being actively exploited to target multiple organizations worldwide. The exploit was used to launch a spear phishing campaign against Europe.
#ParsedReport
11-08-2022
APT-C-35 Gets a New Upgrade
https://blog.morphisec.com/apt-c-35-new-windows-framework-revealed
Actors/Campaigns:
Donot
Threats:
Yty
Beacon
Industry:
Government
Geo:
Asia, Asian, India, Pakistan, Bangladesh
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 27
Path: 5
Url: 2
IP: 2
Hash: 17
Domain: 12
Softs:
android, virtualbox, google chrome, mozilla firefox, microsoft office
Algorithms:
base64, aes-256, xor
Functions:
ZwAllocateVirtualMemory
Languages:
python, php
Platforms:
x86
11-08-2022
APT-C-35 Gets a New Upgrade
https://blog.morphisec.com/apt-c-35-new-windows-framework-revealed
Actors/Campaigns:
Donot
Threats:
Yty
Beacon
Industry:
Government
Geo:
Asia, Asian, India, Pakistan, Bangladesh
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 27
Path: 5
Url: 2
IP: 2
Hash: 17
Domain: 12
Softs:
android, virtualbox, google chrome, mozilla firefox, microsoft office
Algorithms:
base64, aes-256, xor
Functions:
ZwAllocateVirtualMemory
Languages:
python, php
Platforms:
x86
Morphisec
APT-C-35: New Windows Framework Revealed
Morphisec Labs exclusively details new updates to the Windows framework of the advanced persistent threat actors APT-C-35, a.k.a the DoNot Team.
#ParsedReport
11-08-2022
BazarCall Advisory: Essential Guide to Attack Vector that Revolutionized Data Breaches
https://www.advintel.io/post/bazarcall-advisory-the-essential-guide-to-call-back-phishing-attacks-that-revolutionized-the-data
Actors/Campaigns:
Luna_moth
Threats:
Bazarbackdoor
Ryuk
Conti
Quantum_tool
Zeon
Emotet
Trickbot
Avaddon
Industry:
Foodtech, Financial
Geo:
Ukraine, Russian
11-08-2022
BazarCall Advisory: Essential Guide to Attack Vector that Revolutionized Data Breaches
https://www.advintel.io/post/bazarcall-advisory-the-essential-guide-to-call-back-phishing-attacks-that-revolutionized-the-data
Actors/Campaigns:
Luna_moth
Threats:
Bazarbackdoor
Ryuk
Conti
Quantum_tool
Zeon
Emotet
Trickbot
Avaddon
Industry:
Foodtech, Financial
Geo:
Ukraine, Russian
#ParsedReport
11-08-2022
SOVA malware is back and is evolving rapidly
https://www.cleafy.com/cleafy-labs/sova-malware-is-back-and-is-evolving-rapidly
Threats:
Sova
Anatsa
Oscorp
Brata
Industry:
Financial
Geo:
Philippine, Francesco, Ukraine, Russian
IOCs:
File: 1
Hash: 3
Domain: 2
Softs:
chrome, android
Algorithms:
aes
11-08-2022
SOVA malware is back and is evolving rapidly
https://www.cleafy.com/cleafy-labs/sova-malware-is-back-and-is-evolving-rapidly
Threats:
Sova
Anatsa
Oscorp
Brata
Industry:
Financial
Geo:
Philippine, Francesco, Ukraine, Russian
IOCs:
File: 1
Hash: 3
Domain: 2
Softs:
chrome, android
Algorithms:
aes
Cleafy
SOVA malware is back and is evolving rapidly | Cleafy Labs
SOVA, a new Android Banking Trojan, is spreading across Europe. Already appeared in different versions, this malware is now evolving, and it is targeting more than 200 mobile applications, ranging from banking apps to crypto exchanges/wallets. Here's the…
#ParsedReport
11-08-2022
Detecting DNS implants: Old kitten, new tricks A Saitama Case Study
https://research.nccgroup.com/2022/08/11/detecting-dns-implants-old-kitten-new-tricks-a-saitama-case-study
Threats:
Saitama
Dnstunnelling_technique
Cobalt_strike
Sliver_tool
Industry:
Government
Geo:
Jordan
IOCs:
File: 2
Algorithms:
prng
Links:
11-08-2022
Detecting DNS implants: Old kitten, new tricks A Saitama Case Study
https://research.nccgroup.com/2022/08/11/detecting-dns-implants-old-kitten-new-tricks-a-saitama-case-study
Threats:
Saitama
Dnstunnelling_technique
Cobalt_strike
Sliver_tool
Industry:
Government
Geo:
Jordan
IOCs:
File: 2
Algorithms:
prng
Links:
https://github.com/fox-it/saitama-server#ParsedReport
11-08-2022
CopperStealer Distributes Malicious Chromium-based Browser Extension to Steal Cryptocurrencies
https://www.trendmicro.com/en_us/research/22/h/copperstealer-distributes-malicious-chromium-browser-extension-steal-cryptocurrencies.html
Threats:
Copperstealer
Upx_tool
Tron
Industry:
Financial
Geo:
Turkish, Japanese, Italian, Polish, German, Portuguese, Indonesia, French, Spanish, Russian
IOCs:
File: 3
Hash: 30
Domain: 1
Softs:
zcash, centbrowser, orbitum, vivaldi, comodo dragon, opera, chromium, coinbase, chrome
Languages:
java, javascript, php
11-08-2022
CopperStealer Distributes Malicious Chromium-based Browser Extension to Steal Cryptocurrencies
https://www.trendmicro.com/en_us/research/22/h/copperstealer-distributes-malicious-chromium-browser-extension-steal-cryptocurrencies.html
Threats:
Copperstealer
Upx_tool
Tron
Industry:
Financial
Geo:
Turkish, Japanese, Italian, Polish, German, Portuguese, Indonesia, French, Spanish, Russian
IOCs:
File: 3
Hash: 30
Domain: 1
Softs:
zcash, centbrowser, orbitum, vivaldi, comodo dragon, opera, chromium, coinbase, chrome
Languages:
java, javascript, php
Trend Micro
CopperStealer Distributes Malicious Chromium-based Browser Extension to Steal Cryptocurrencies
We tracked the latest deployment of the group behind CopperStealer, this time stealing cryptocurrencies and users’ wallet account information via a malicious Chromium-based browser extension.
#ParsedReport
11-08-2022
SolidBit Ransomware Group Actively Recruiting Affiliates
https://cloudsek.com/threatintelligence/solidbit-ransomware-group-actively-recruiting-affiliates/?utm_source=rss&utm_medium=rss&utm_campaign=solidbit-ransomware-group-actively-recruiting-affiliates
Threats:
Solidbit
Lockbit
Industry:
Financial
Geo:
America
CVEs:
CVE-2022-30333 [Vulners]
Vulners: Score: 5.0, CVSS: 5.1,
Vulners: Exploitation: True
X-Force: Risk: 7.5
X-Force: Patch: Official fix
Soft:
- rarlab unrar (<6.12)
TTPs:
Tactics: 1
Technics: 0
IOCs:
Path: 1
Hash: 2
File: 1
Softs:
windows defender
11-08-2022
SolidBit Ransomware Group Actively Recruiting Affiliates
https://cloudsek.com/threatintelligence/solidbit-ransomware-group-actively-recruiting-affiliates/?utm_source=rss&utm_medium=rss&utm_campaign=solidbit-ransomware-group-actively-recruiting-affiliates
Threats:
Solidbit
Lockbit
Industry:
Financial
Geo:
America
CVEs:
CVE-2022-30333 [Vulners]
Vulners: Score: 5.0, CVSS: 5.1,
Vulners: Exploitation: True
X-Force: Risk: 7.5
X-Force: Patch: Official fix
Soft:
- rarlab unrar (<6.12)
TTPs:
Tactics: 1
Technics: 0
IOCs:
Path: 1
Hash: 2
File: 1
Softs:
windows defender
CloudSEK - Digital Risk Management Enterprise | Artificial Intelligence based Cybersecurity
SolidBit Ransomware Group Actively Recruiting Affiliates - CloudSEK
CloudSEK discovered a threat actor group named SolidBit, offering RaaS (Ransom-as-a-Service) on an underground forum. The group is actively looking for partners to gain access to companies’ private networks in order to spread the ransomware called SolidBit.
#ParsedReport
12-08-2022
Iron Tiger Compromises Chat Application Mimi, Targets Windows, Mac, and Linux Users
https://www.trendmicro.com/en_us/research/22/h/irontiger-compromises-chat-app-Mimi-targets-windows-mac-linux-users.html
Actors/Campaigns:
Emissary_panda (motivation: cyber_espionage)
Earth_berberoka
Drbcontrol
Threats:
Hyperbro
Rshell
Dll_sideloading_technique
Gh0st_rat
Plugx_rat
Shadowpad
Industry:
Entertainment
Geo:
Taiwan, Chinese, Philippines
IOCs:
File: 4
IP: 3
Domain: 4
Hash: 11
Softs:
windows installer, macos, node.js, mac os, android
Languages:
javascript
Links:
12-08-2022
Iron Tiger Compromises Chat Application Mimi, Targets Windows, Mac, and Linux Users
https://www.trendmicro.com/en_us/research/22/h/irontiger-compromises-chat-app-Mimi-targets-windows-mac-linux-users.html
Actors/Campaigns:
Emissary_panda (motivation: cyber_espionage)
Earth_berberoka
Drbcontrol
Threats:
Hyperbro
Rshell
Dll_sideloading_technique
Gh0st_rat
Plugx_rat
Shadowpad
Industry:
Entertainment
Geo:
Taiwan, Chinese, Philippines
IOCs:
File: 4
IP: 3
Domain: 4
Hash: 11
Softs:
windows installer, macos, node.js, mac os, android
Languages:
javascript
Links:
https://github.com/f0rb1dd3n/ReptileTrend Micro
Iron Tiger Compromises Chat Application Mimi, Targets Windows, Mac, and Linux Users
https://www.trendmicro.com/en_no/research/21/d/iron-tiger-apt-updates-toolkit-with-evolved-sysupdate-malware-va.html
#ParsedReport
13-08-2022
LuckyMouse uses a backdoored Electron app to target MacOS
https://blog.sekoia.io/luckymouse-uses-a-backdoored-electron-app-to-target-macos
Actors/Campaigns:
Emissary_panda (motivation: cyber_espionage)
Stealthytrident
Threats:
Hyberbro
Rshell
Plugx_rat
Tmanger
Hyperbro
Watering_hole_technique
Luckymouse
Geo:
Mongolia, China, Chinese
IOCs:
Domain: 1
File: 10
IP: 6
Url: 2
Hash: 9
Softs:
macos, android
Languages:
javascript
Platforms:
apple
YARA: Found
13-08-2022
LuckyMouse uses a backdoored Electron app to target MacOS
https://blog.sekoia.io/luckymouse-uses-a-backdoored-electron-app-to-target-macos
Actors/Campaigns:
Emissary_panda (motivation: cyber_espionage)
Stealthytrident
Threats:
Hyberbro
Rshell
Plugx_rat
Tmanger
Hyperbro
Watering_hole_technique
Luckymouse
Geo:
Mongolia, China, Chinese
IOCs:
Domain: 1
File: 10
IP: 6
Url: 2
Hash: 9
Softs:
macos, android
Languages:
javascript
Platforms:
apple
YARA: Found
Sekoia.io Blog
LuckyMouse uses a backdoored Electron app to target MacOS
This is the first time that SEKOIA observed LuckyMouse targeting MacOS.
#ParsedReport
14-08-2022
Typosquatting Campaign Targeting Pythons Top Packages, Dropping GitHub Hosted Malware with DGA Capabilities. Attack Vector Typosquatting
https://checkmarx.com/blog/typosquatting-campaign-targeting-pythons-top-packages-dropping-github-hosted-malware-with-dga-capabilities
Threats:
Typosquatting_technique
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 3
Path: 2
Url: 10
Hash: 3
Algorithms:
xor
Languages:
python
Links:
14-08-2022
Typosquatting Campaign Targeting Pythons Top Packages, Dropping GitHub Hosted Malware with DGA Capabilities. Attack Vector Typosquatting
https://checkmarx.com/blog/typosquatting-campaign-targeting-pythons-top-packages-dropping-github-hosted-malware-with-dga-capabilities
Threats:
Typosquatting_technique
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 3
Path: 2
Url: 10
Hash: 3
Algorithms:
xor
Languages:
python
Links:
https://github.com/jagermager999/8746465cdg78cdsxasy8a/commits/mainhttps://github.com/jagermager999https://github.com/jagermager999/8746465cdg78cdsxasy8aCheckmarx.com
Typosquatting Campaign Targeting Python's Top Packages, Dropping GitHub Hosted Malware with DGA Capabilities
Right after Checkmarx’s automatic engines detected the malicious packages we started an analysis process involving our security researchers analyzing this campaign and reverse engineering the dropped embedded malware to understand the full picture.
#ParsedReport
15-08-2022
Shuckworm: Russia-Linked Group Maintains Ukraine Focus
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/russia-ukraine-shuckworm
Actors/Campaigns:
Gamaredon (motivation: cyber_espionage)
Threats:
Giddome
Ammyy_admin_tool
Anydesk_tool
Decay
Geo:
Russian, Ukrainian, Ukraine, Russia
IOCs:
File: 14
Domain: 5
Hash: 43
Url: 10
Path: 1
Functions:
PowerShell, InternetExplorer
Languages:
php
15-08-2022
Shuckworm: Russia-Linked Group Maintains Ukraine Focus
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/russia-ukraine-shuckworm
Actors/Campaigns:
Gamaredon (motivation: cyber_espionage)
Threats:
Giddome
Ammyy_admin_tool
Anydesk_tool
Decay
Geo:
Russian, Ukrainian, Ukraine, Russia
IOCs:
File: 14
Domain: 5
Hash: 43
Url: 10
Path: 1
Functions:
PowerShell, InternetExplorer
Languages:
php
Security
Shuckworm: Russia-Linked Group Maintains Ukraine Focus
Infostealer appears to be payload in recent activity aimed at Ukrainian organizations.
#ParsedReport
15-08-2022
Patchwork APT. Analysis of the characteristics of new activities in Patchwork APT in South Asia
https://mp.weixin.qq.com/s/egG0nORZFvo_rCY_zmTgVQ
Actors/Campaigns:
Dropping_elephant
Threats:
Patchinfecter
Grat2_tool
Industry:
Government, Healthcare
Geo:
China, Asia, Asian, Pakistan
CVEs:
CVE-2021-40444 [Vulners]
Vulners: Score: 6.8, CVSS: 2.2,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2, -)
- microsoft windows 10 (1607, -, 1809, 1909, 2004, 20h2, 21h1)
- microsoft windows server 2016 (-, 2004, 20h2)
- microsoft windows rt 8.1 (-)
- microsoft windows server 2012 (-, -)
have more...
IOCs:
File: 11
Path: 1
IP: 1
Url: 1
Hash: 4
Softs:
microsoft office
Algorithms:
zip , xor, base64
15-08-2022
Patchwork APT. Analysis of the characteristics of new activities in Patchwork APT in South Asia
https://mp.weixin.qq.com/s/egG0nORZFvo_rCY_zmTgVQ
Actors/Campaigns:
Dropping_elephant
Threats:
Patchinfecter
Grat2_tool
Industry:
Government, Healthcare
Geo:
China, Asia, Asian, Pakistan
CVEs:
CVE-2021-40444 [Vulners]
Vulners: Score: 6.8, CVSS: 2.2,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2, -)
- microsoft windows 10 (1607, -, 1809, 1909, 2004, 20h2, 21h1)
- microsoft windows server 2016 (-, 2004, 20h2)
- microsoft windows rt 8.1 (-)
- microsoft windows server 2012 (-, -)
have more...
IOCs:
File: 11
Path: 1
IP: 1
Url: 1
Hash: 4
Softs:
microsoft office
Algorithms:
zip , xor, base64
Weixin Official Accounts Platform
南亚Patchwork APT组织新活动特点分析
PatchWork APT在近期攻击活动中应用了跟以往不同的攻击工具。
#ParsedReport
15-08-2022
Ransomware Gangs Adopt Callback Phishing Techniques for Gaining Initial Network Access
https://www.hipaajournal.com/ransomware-gangs-adopt-callback-phishing-techniques-for-gaining-initial-network-access
Actors/Campaigns:
Luna_moth
Threats:
Bazarbackdoor
Ryuk
Conti
Quantum_tool
Zeon
Industry:
Healthcare, Financial
Languages:
javascript
15-08-2022
Ransomware Gangs Adopt Callback Phishing Techniques for Gaining Initial Network Access
https://www.hipaajournal.com/ransomware-gangs-adopt-callback-phishing-techniques-for-gaining-initial-network-access
Actors/Campaigns:
Luna_moth
Threats:
Bazarbackdoor
Ryuk
Conti
Quantum_tool
Zeon
Industry:
Healthcare, Financial
Languages:
javascript
HIPAA Journal
Ransomware Gangs Adopt Callback Phishing Techniques for Gaining Initial Network Access
Multiple ransomware groups have adopted the BazarCall callback phishing technique to gain initial access to victims’ networks, including threat actors More ransomware gangs have adopted the BazarCall callback phishing technique to gain initial access to victims’…
#ParsedReport
15-08-2022
Disrupting SEABORGIUMs ongoing phishing operations
https://www.microsoft.com/security/blog/2022/08/15/disrupting-seaborgiums-ongoing-phishing-operations
Actors/Campaigns:
Coldriver
Gamaredon
Threats:
Seaborgium
Evilginx_tool
Credential_harvesting_technique
Aitm_technique
Industry:
Education, Financial, Government, Ngo
Geo:
Ukraine, Russia, Russian
IOCs:
Domain: 69
Softs:
microsoft 365 defender, microsoft defender
Links:
15-08-2022
Disrupting SEABORGIUMs ongoing phishing operations
https://www.microsoft.com/security/blog/2022/08/15/disrupting-seaborgiums-ongoing-phishing-operations
Actors/Campaigns:
Coldriver
Gamaredon
Threats:
Seaborgium
Evilginx_tool
Credential_harvesting_technique
Aitm_technique
Industry:
Education, Financial, Government, Ngo
Geo:
Ukraine, Russia, Russian
IOCs:
Domain: 69
Softs:
microsoft 365 defender, microsoft defender
Links:
https://github.com/Azure/Azure-Sentinel/blob/master/Detections/MultipleDataSources/SEABORGIUMDomainsAugust2022.yamlhttps://github.com/Azure/Azure-Sentinel/blob/master/Hunting%20Queries/Microsoft%20365%20Defender/Campaigns/SEABORGIUMDomainIOCsAug2022.yamlMicrosoft News
Disrupting SEABORGIUM’s ongoing phishing operations
The Microsoft Threat Intelligence Center (MSTIC) has observed and taken actions to disrupt campaigns launched by SEABORGIUM in campaigns involve persistent phishing and credential theft campaigns leading to intrusions and data theft.
#ParsedReport
16-08-2022
Threat in your browser: what dangers innocent-looking extensions hold for users
https://securelist.com/threat-in-your-browser-extensions/107181
Threats:
Websearch
Dealply
Nullmixer
Fbstealer
Industry:
Government, E-commerce, Healthcare, Financial, Petroleum
IOCs:
Domain: 1
Coin: 3
Path: 1
Url: 1
Hash: 6
Softs:
chrome, windows registry, chromium, google chrome
Languages:
javascript
16-08-2022
Threat in your browser: what dangers innocent-looking extensions hold for users
https://securelist.com/threat-in-your-browser-extensions/107181
Threats:
Websearch
Dealply
Nullmixer
Fbstealer
Industry:
Government, E-commerce, Healthcare, Financial, Petroleum
IOCs:
Domain: 1
Coin: 3
Path: 1
Url: 1
Hash: 6
Softs:
chrome, windows registry, chromium, google chrome
Languages:
javascript
Securelist
Threat in your browser: what dangers innocent-looking extensions hold for users
In this research, we observed various types of threats that mimic useful web browser extensions, and the number of users attacked by them.
#ParsedReport
16-08-2022
Banking Trojan SOVA Has New Version with Updated Features
https://socradar.io/banking-trojan-sova-has-new-version-with-updated-features
Threats:
Sova
Industry:
Financial
Geo:
China, Taiwan
TTPs:
Tactics: 1
Technics: 2
IOCs:
File: 1
Hash: 6
Domain: 2
Url: 3
Softs:
android, chrome
16-08-2022
Banking Trojan SOVA Has New Version with Updated Features
https://socradar.io/banking-trojan-sova-has-new-version-with-updated-features
Threats:
Sova
Industry:
Financial
Geo:
China, Taiwan
TTPs:
Tactics: 1
Technics: 2
IOCs:
File: 1
Hash: 6
Domain: 2
Url: 3
Softs:
android, chrome
SOCRadar® Cyber Intelligence Inc.
Banking Trojan SOVA Has New Version with Updated Features - SOCRadar® Cyber Intelligence Inc.
#ParsedReport
16-08-2022
Two more malicious Python packages in the PyPI
https://securelist.com/two-more-malicious-python-packages-in-the-pypi/107218
Threats:
Junk_code_technique
Industry:
Financial
Geo:
French
IOCs:
File: 7
Url: 3
Path: 2
Registry: 1
Hash: 5
Softs:
discord
Languages:
python, javascript
Links:
16-08-2022
Two more malicious Python packages in the PyPI
https://securelist.com/two-more-malicious-python-packages-in-the-pypi/107218
Threats:
Junk_code_technique
Industry:
Financial
Geo:
French
IOCs:
File: 7
Url: 3
Path: 2
Registry: 1
Hash: 5
Softs:
discord
Languages:
python, javascript
Links:
https://github.com/billythegoat356/HyperionSecurelist
Two more malicious Python packages in the PyPI
We used our internal automated system for monitoring open-source repositories and discovered two other malicious Python packages in the PyPI.
#ParsedReport
16-08-2022
BlackGuard Infostealer Malware: Dissecting the State of Exfiltrated Data
https://www.f5.com/labs/articles/threat-intelligence/blackguard-infostealer-malware-dissecting-the-state-of-exfiltrated-data
Threats:
Blackguard_stealer
Dll_injection_technique
Malibot
Qakbot
Industry:
E-commerce, Education, Iot, Government, Financial
Geo:
Russian, African, Switzerland, Sweden
IOCs:
File: 5
Softs:
android, mozilla firefox, google chrome, dashcore, bitcoincore, telegram, electrum, microsoft edge, chrome, litecoincore, discord
Algorithms:
zip
Languages:
javascript
Platforms:
intel
16-08-2022
BlackGuard Infostealer Malware: Dissecting the State of Exfiltrated Data
https://www.f5.com/labs/articles/threat-intelligence/blackguard-infostealer-malware-dissecting-the-state-of-exfiltrated-data
Threats:
Blackguard_stealer
Dll_injection_technique
Malibot
Qakbot
Industry:
E-commerce, Education, Iot, Government, Financial
Geo:
Russian, African, Switzerland, Sweden
IOCs:
File: 5
Softs:
android, mozilla firefox, google chrome, dashcore, bitcoincore, telegram, electrum, microsoft edge, chrome, litecoincore, discord
Algorithms:
zip
Languages:
javascript
Platforms:
intel
F5 Labs
BlackGuard Infostealer Malware: Dissecting the State of Exfiltrated Data | F5 Labs
Your data is at risk. Are you equipped to combat the risks posed by BlackGuard?
#ParsedReport
16-08-2022
Phishing Site used to Spread Typhon Stealer
https://blog.cyble.com/2022/08/16/phishing-site-used-to-spread-typhon-stealer
Threats:
Typhon_stealer
Xmrig_miner
Backbend
Netstat_tool
Beacon
Industry:
Financial, Entertainment
Geo:
Dubai, Singapore, Australia, Sweden, India, Georgia
TTPs:
Tactics: 8
Technics: 17
IOCs:
File: 13
Coin: 1
Url: 2
Hash: 5
Registry: 3
Path: 1
Softs:
winscp, discord, microsoft edge, telegram
Algorithms:
base64
Functions:
CheckRemoteDebuggerPresent, GetModuleHandle
Languages:
java, php
16-08-2022
Phishing Site used to Spread Typhon Stealer
https://blog.cyble.com/2022/08/16/phishing-site-used-to-spread-typhon-stealer
Threats:
Typhon_stealer
Xmrig_miner
Backbend
Netstat_tool
Beacon
Industry:
Financial, Entertainment
Geo:
Dubai, Singapore, Australia, Sweden, India, Georgia
TTPs:
Tactics: 8
Technics: 17
IOCs:
File: 13
Coin: 1
Url: 2
Hash: 5
Registry: 3
Path: 1
Softs:
winscp, discord, microsoft edge, telegram
Algorithms:
base64
Functions:
CheckRemoteDebuggerPresent, GetModuleHandle
Languages:
java, php
Cyble
Phishing Site used to Spread Typhon Stealer
Cyble analyzes Typhon, an information stealer being spread via a phishing site.
#ParsedReport
16-08-2022
Detecting a Rogue Domain Controller DCShadow Attack
https://www.sentinelone.com/blog/detecting-a-rogue-domain-controller-dcshadow-attack
Threats:
Dcshadow_technique
Dcsync_technique
Lsadump_tool
Mimikatz
Golden_ticket_technique
Trickbot
Softs:
active directory
Functions:
GetNCChanges
Links:
16-08-2022
Detecting a Rogue Domain Controller DCShadow Attack
https://www.sentinelone.com/blog/detecting-a-rogue-domain-controller-dcshadow-attack
Threats:
Dcshadow_technique
Dcsync_technique
Lsadump_tool
Mimikatz
Golden_ticket_technique
Trickbot
Softs:
active directory
Functions:
GetNCChanges
Links:
https://github.com/gentilkiwi/mimikatz/wiki/module-\~-lsadumpSentinelOne
DCShadow Attacks: Detecting a Rogue Domain Controller
Learn what DCShadow attacks are, how they work, methods for detecting them, and effective mitigation strategies to protect your Active Directory environment.
#ParsedReport
16-08-2022
BitRAT, XMRig. Bitrat, XMRIG Coin Minor, distributed using the Windows Genuine Certification tool
https://asec.ahnlab.com/ko/37602
Threats:
Sbit_rat
Xmrig_miner
Trojan/win.generic.c5223158
Malware/mdp.download.m1197
Malware/mdp.drivebydownload.m1298
IOCs:
File: 14
Domain: 1
Hash: 4
Url: 3
IP: 1
Softs:
telegram, google chrome
16-08-2022
BitRAT, XMRig. Bitrat, XMRIG Coin Minor, distributed using the Windows Genuine Certification tool
https://asec.ahnlab.com/ko/37602
Threats:
Sbit_rat
Xmrig_miner
Trojan/win.generic.c5223158
Malware/mdp.download.m1197
Malware/mdp.drivebydownload.m1298
IOCs:
File: 14
Domain: 1
Hash: 4
Url: 3
IP: 1
Softs:
telegram, google chrome
ASEC BLOG
윈도우 정품 인증 툴을 이용해 유포 중인 BitRAT, XMRig 코인 마이너 - ASEC BLOG
ASEC 분석팀에서는 최근 윈도우 정품 인증 툴을 위장하여 BitRAT과 XMRig 코인 마이너가 유포 중인 것을 확인하였다. BitRAT은 아래의 블로그들에서 다룬 바와 같이 이전에도 웹하드를 통해 MS 윈도우 정품 인증 툴과 MS 오피스 설치 프로그램으로 위장하여 유포된 이력이 있으며, 현재 블로그에서 다루는 사례도 동일한 공격자로 추정된다. 특이한 점으로는 V3 설치되지 않은 환경에서는 BitRAT 원격제어툴이 설치되며, V3 설치 환경에서는 (BitRAT…