#ParsedReport
16-08-2022
. Move forward, prevent problems before -the 5G era of network security risk trends and industrial response to thinking
https://www.antiy.cn/research/notice&report/research_report/20220815.html
Threats:
Neuron
Pacemaker
Industry:
Healthcare, Energy, Financial, Iot, Transport
Geo:
China, Chinese, Vietnamese
IOCs:
File: 4
Softs:
android
16-08-2022
. Move forward, prevent problems before -the 5G era of network security risk trends and industrial response to thinking
https://www.antiy.cn/research/notice&report/research_report/20220815.html
Threats:
Neuron
Pacemaker
Industry:
Healthcare, Energy, Financial, Iot, Transport
Geo:
China, Chinese, Vietnamese
IOCs:
File: 4
Softs:
android
www.antiy.cn
关口前移,防患于未然——5G时代的网络安全风险趋势与产业应对思考
安天是引领威胁检测与防御能力发展的网络安全国家队,为客户构建端点防护、流量监测、边界防护、导流捕获、深度分析、应急处置的安全基石
#ParsedReport
17-08-2022
CISA and FBI issue alert about Zeppelin ransomware
https://www.malwarebytes.com/blog/news/2022/08/cisa-and-fbi-issue-alert-about-zeppelin-ransomware
Threats:
Zeppelin
Vega_locker
Industry:
Healthcare
Languages:
delphi
YARA: Found
17-08-2022
CISA and FBI issue alert about Zeppelin ransomware
https://www.malwarebytes.com/blog/news/2022/08/cisa-and-fbi-issue-alert-about-zeppelin-ransomware
Threats:
Zeppelin
Vega_locker
Industry:
Healthcare
Languages:
delphi
YARA: Found
ThreatDown by Malwarebytes
CISA and FBI issue alert about Zeppelin ransomware - ThreatDown by Malwarebytes
The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) have released a joint Cybersecurity Advisory (CSA) about Zeppelin ransomware.
#ParsedReport
17-08-2022
ASEC Weekly Malware Statistics (August 1st, 2022 August 7th, 2022)
https://asec.ahnlab.com/en/37593
Threats:
Agent_tesla
Formbook
Clipboard_grabbing_technique
Cloudeye
Remcos_rat
Nanocore_rat
Redline_stealer
Beamwinhttp_loader
Vidar_stealer
Industry:
Financial, Transport
Geo:
Korea
IOCs:
Domain: 3
IP: 3
Email: 5
File: 20
Url: 25
Softs:
nsis installer, discord
Languages:
visual_basic
17-08-2022
ASEC Weekly Malware Statistics (August 1st, 2022 August 7th, 2022)
https://asec.ahnlab.com/en/37593
Threats:
Agent_tesla
Formbook
Clipboard_grabbing_technique
Cloudeye
Remcos_rat
Nanocore_rat
Redline_stealer
Beamwinhttp_loader
Vidar_stealer
Industry:
Financial, Transport
Geo:
Korea
IOCs:
Domain: 3
IP: 3
Email: 5
File: 20
Url: 25
Softs:
nsis installer, discord
Languages:
visual_basic
ASEC BLOG
ASEC Weekly Malware Statistics (August 1st, 2022 – August 7th, 2022) - ASEC BLOG
The ASEC analysis team is using the ASEC automatic analysis system RAPIT to categorize and respond to known malware. This post will list weekly statistics collected from August 1st, 2022 (Monday) to August 7th, 2022 (Sunday). For the main category, info-stealer…
#ParsedReport
17-08-2022
Suspected Iranian Actor Targeting Israeli Shipping, Healthcare, Government and Energy Sectors
https://www.mandiant.com/resources/suspected-iranian-actor-targeting-israeli-shipping
Actors/Campaigns:
Unc3890 (motivation: cyber_espionage)
Fox_kitten
Cleaver
Threats:
Watering_hole_technique
Sugarush
Sugardump
Metasploit_tool
Northstar_tool
Credential_harvesting_technique
Industry:
Energy, Healthcare, Government, Maritime, Transport, Aerospace
Geo:
Israel, Iran, Israeli, Iranian
IOCs:
Domain: 9
Url: 1
Hash: 1
Softs:
instagram
Algorithms:
zip
17-08-2022
Suspected Iranian Actor Targeting Israeli Shipping, Healthcare, Government and Energy Sectors
https://www.mandiant.com/resources/suspected-iranian-actor-targeting-israeli-shipping
Actors/Campaigns:
Unc3890 (motivation: cyber_espionage)
Fox_kitten
Cleaver
Threats:
Watering_hole_technique
Sugarush
Sugardump
Metasploit_tool
Northstar_tool
Credential_harvesting_technique
Industry:
Energy, Healthcare, Government, Maritime, Transport, Aerospace
Geo:
Israel, Iran, Israeli, Iranian
IOCs:
Domain: 9
Url: 1
Hash: 1
Softs:
Algorithms:
zip
Google Cloud Blog
UNC3890: Suspected Iranian Threat Actor Targeting Israeli Shipping, Healthcare, Government and Energy Sectors | Google Cloud Blog
#ParsedReport
17-08-2022
Malicious PyPi User Strikes Again with Typosquatting, StarJacking and Unpacks Tailor-made Malware written in C#. Intro
https://checkmarx.com/blog/malicious-pypi-user-strikes-again-with-typosquatting-starjacking-and-unpacks-tailor-made-malware-written-in-c
Threats:
Typosquatting_technique
Starjacking_technique
Joao
Cobalt_strike
Beacon
Intellilock_tool
Geo:
Kazakhstan
IOCs:
Path: 1
Url: 2
IP: 1
Hash: 4
Algorithms:
base64, exhibit
Languages:
python
17-08-2022
Malicious PyPi User Strikes Again with Typosquatting, StarJacking and Unpacks Tailor-made Malware written in C#. Intro
https://checkmarx.com/blog/malicious-pypi-user-strikes-again-with-typosquatting-starjacking-and-unpacks-tailor-made-malware-written-in-c
Threats:
Typosquatting_technique
Starjacking_technique
Joao
Cobalt_strike
Beacon
Intellilock_tool
Geo:
Kazakhstan
IOCs:
Path: 1
Url: 2
IP: 1
Hash: 4
Algorithms:
base64, exhibit
Languages:
python
Checkmarx
Malicious PyPi User Strikes Again with Typosquatting, StarJacking and Unpacks Tailor-made Malware written in C#
On Saturday, August 13th, Checkmarx's Software Supply Chain Security Typosquatting and StarJacking engines detected what seemed like an attack on the Python ecosystem. Further investigation revealed multiple evasion and obfuscation techniques, C2 communication…
#ParsedReport
17-08-2022
MasterFred Using Gymdrop to Distribute Xenomorph Android Banking Trojan
https://blog.cyble.com/2022/08/17/masterfred-using-gymdrop-to-distribute-xenomorph-android-banking-trojan
Actors/Campaigns:
Hadoken_security
Threats:
Masterfred
Gymdrop
Xenomorph
Hostile
Opendir
Hydra
Alien
Octo
Typhon_stealer
Industry:
Financial
Geo:
India, Dubai, Georgia, Poland, Australia, Singapore, Turkey
TTPs:
Tactics: 5
Technics: 9
IOCs:
Url: 7
File: 3
Hash: 2
Softs:
android
17-08-2022
MasterFred Using Gymdrop to Distribute Xenomorph Android Banking Trojan
https://blog.cyble.com/2022/08/17/masterfred-using-gymdrop-to-distribute-xenomorph-android-banking-trojan
Actors/Campaigns:
Hadoken_security
Threats:
Masterfred
Gymdrop
Xenomorph
Hostile
Opendir
Hydra
Alien
Octo
Typhon_stealer
Industry:
Financial
Geo:
India, Dubai, Georgia, Poland, Australia, Singapore, Turkey
TTPs:
Tactics: 5
Technics: 9
IOCs:
Url: 7
File: 3
Hash: 2
Softs:
android
Cyble
MasterFred Using Gymdrop to Distribute Xenomorph Android Banking Trojan
Cyble analyzes the new variant of MasterFred, which acts as the Hostile Downloader and distributes Xenomorph Banking Trojan.
#ParsedReport
17-08-2022
DarkTortilla Malware Analysis
https://www.secureworks.com/research/darktortilla-malware-analysis
Threats:
Darktortilla
Agent_tesla
Asyncrat_rat
Nanocore_rat
Redline_stealer
Cobalt_strike
Metasploit_tool
Process_injection_technique
Confuserex_tool
Junk_code_technique
Industry:
Logistic
Geo:
German, Italian, Romanian, Spanish
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 35
Hash: 56
Softs:
virtualbox, .net framework, windows shell, winlogon, windows registry, discord, hyper-v
Algorithms:
aes
Links:
17-08-2022
DarkTortilla Malware Analysis
https://www.secureworks.com/research/darktortilla-malware-analysis
Threats:
Darktortilla
Agent_tesla
Asyncrat_rat
Nanocore_rat
Redline_stealer
Cobalt_strike
Metasploit_tool
Process_injection_technique
Confuserex_tool
Junk_code_technique
Industry:
Logistic
Geo:
German, Italian, Romanian, Spanish
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 35
Hash: 56
Softs:
virtualbox, .net framework, windows shell, winlogon, windows registry, discord, hyper-v
Algorithms:
aes
Links:
https://github.com/malwares/Crypter/tree/master/%5BC%23%5D%20The%20RATs%20Crew%20Crypterhttps://github.com/malwares/Crypter/blob/master/%5BC%23%5D%20The%20RATs%20Crew%20Crypter/Form1.cs#L161-L163https://github.com/dnSpyEx/dnSpySophos
DarkTortilla Malware Analysis
Learn how Secureworks CTU researchers have identified DarkTortilla samples delivering targeted malicious payloads, benign decoy documents, and executables.
#ParsedReport
17-08-2022
THREAT ANALYSIS REPORT: Bumblebee Loader The High Road to Enterprise Domain Control
https://www.cybereason.com/blog/threat-analysis-report-bumblebee-loader-the-high-road-to-enterprise-domain-control
Threats:
Bumblebee
Bazarbackdoor
Trickbot
Icedid
Cobalt_strike
Meterpreter_tool
Zerologon_vuln
Beacon
Adfind_tool
Lolbin
Uac_bypass_technique
Process_injection_technique
Anydesk_tool
Industry:
Government
CVEs:
CVE-2020-1472 [Vulners]
Vulners: Score: 9.3, CVSS: 3.8,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2)
- microsoft windows server 2012 (-, r2)
- microsoft windows server 2016 (-, 1903, 1909, 2004)
- microsoft windows server 2019 (-)
- fedoraproject fedora (31, 32, 33)
have more...
TTPs:
Tactics: 10
Technics: 24
IOCs:
File: 19
Path: 5
Domain: 1
IP: 1
Hash: 1
Softs:
winlogon, active directory, microsoft exchange, local security authority, curl, vssadmin
Links:
17-08-2022
THREAT ANALYSIS REPORT: Bumblebee Loader The High Road to Enterprise Domain Control
https://www.cybereason.com/blog/threat-analysis-report-bumblebee-loader-the-high-road-to-enterprise-domain-control
Threats:
Bumblebee
Bazarbackdoor
Trickbot
Icedid
Cobalt_strike
Meterpreter_tool
Zerologon_vuln
Beacon
Adfind_tool
Lolbin
Uac_bypass_technique
Process_injection_technique
Anydesk_tool
Industry:
Government
CVEs:
CVE-2020-1472 [Vulners]
Vulners: Score: 9.3, CVSS: 3.8,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2)
- microsoft windows server 2012 (-, r2)
- microsoft windows server 2016 (-, 1903, 1909, 2004)
- microsoft windows server 2019 (-)
- fedoraproject fedora (31, 32, 33)
have more...
TTPs:
Tactics: 10
Technics: 24
IOCs:
File: 19
Path: 5
Domain: 1
IP: 1
Hash: 1
Softs:
winlogon, active directory, microsoft exchange, local security authority, curl, vssadmin
Links:
https://github.com/leitosama/SharpZeroLogonCybereason
THREAT ANALYSIS REPORT: Bumblebee Loader – The High Road to Enterprise Domain Control
Cybereason GSOC observed distribution of the Bumblebee Loader and post-exploitation activities including privilege escalation, reconnaissance and credential theft. Bumblebee operators use the Cobalt Strike framework throughout the attack and abuse credentials…
#ParsedReport
17-08-2022
An In-Depth Look at Quantum Ransomware
https://explore.avertium.com/resource/an-in-depth-look-at-quantum-ransomware
Actors/Campaigns:
Xinglocker
Jormungandr
Threats:
Quantum_locker
Astrolocker
Mountlocker
Conti
Bazarbackdoor
Ryuk
Zeon
Icedid
Cobalt_strike
Adfind_tool
Metasploit_tool
Beacon
Industry:
Healthcare, Financial
Geo:
India
IOCs:
File: 10
Domain: 3
IP: 1
Hash: 8
Softs:
psexec, active directory
17-08-2022
An In-Depth Look at Quantum Ransomware
https://explore.avertium.com/resource/an-in-depth-look-at-quantum-ransomware
Actors/Campaigns:
Xinglocker
Jormungandr
Threats:
Quantum_locker
Astrolocker
Mountlocker
Conti
Bazarbackdoor
Ryuk
Zeon
Icedid
Cobalt_strike
Adfind_tool
Metasploit_tool
Beacon
Industry:
Healthcare, Financial
Geo:
India
IOCs:
File: 10
Domain: 3
IP: 1
Hash: 8
Softs:
psexec, active directory
Avertium
An In-Depth Look at Quantum Ransomware
Quantum ransomware is a newer, lesser-known ransomware that operates with the RaaS model & has been successful with compromising healthcare organizations.
#ParsedReport
17-08-2022
AsyncRAT C2 Framework: Overview, Technical Analysis & Detection
https://blog.qualys.com/vulnerabilities-threat-research/2022/08/16/asyncrat-c2-framework-overview-technical-analysis-and-detection
Actors/Campaigns:
Layover
Ta2541
Threats:
Asyncrat_rat
Follina_vuln
Antidebugging_technique
Limelogger_tool
Industry:
Transport, Aerospace, Healthcare, Government
Geo:
Thailand, Asia, America, Australia
TTPs:
Tactics: 3
Technics: 9
IOCs:
File: 4
Softs:
virtualbox
Algorithms:
pbkdf2, aes-256
Functions:
GetKeyState, GetModuleHandle, GetForegroundWindow, GetKeyboardLayout, SetThreadExecutionState, RtlSetProcessIsCritical
Links:
17-08-2022
AsyncRAT C2 Framework: Overview, Technical Analysis & Detection
https://blog.qualys.com/vulnerabilities-threat-research/2022/08/16/asyncrat-c2-framework-overview-technical-analysis-and-detection
Actors/Campaigns:
Layover
Ta2541
Threats:
Asyncrat_rat
Follina_vuln
Antidebugging_technique
Limelogger_tool
Industry:
Transport, Aerospace, Healthcare, Government
Geo:
Thailand, Asia, America, Australia
TTPs:
Tactics: 3
Technics: 9
IOCs:
File: 4
Softs:
virtualbox
Algorithms:
pbkdf2, aes-256
Functions:
GetKeyState, GetModuleHandle, GetForegroundWindow, GetKeyboardLayout, SetThreadExecutionState, RtlSetProcessIsCritical
Links:
https://github.com/NYAN-x-CAT/AsyncRAT-C-Sharphttps://github.com/NYAN-x-CAT/LimeLogger/blob/master/LimeLogger/LimeLogger.csQualys
AsyncRAT C2 Framework: Overview, Technical Analysis & Detection | Qualys
In this blog we describe the AsyncRAT C2 (command & control) Framework, which allows attackers to remotely monitor and control other computers over a secure encrypted link. We provide an overview of…
#ParsedReport
17-08-2022
FileLess AsyncRAT
https://asec.ahnlab.com/ko/37676
Threats:
Asyncrat_rat
Trojan/vbs.runner
IOCs:
File: 14
Path: 6
Url: 1
Domain: 1
Hash: 11
Softs:
task scheduler
17-08-2022
FileLess AsyncRAT
https://asec.ahnlab.com/ko/37676
Threats:
Asyncrat_rat
Trojan/vbs.runner
IOCs:
File: 14
Path: 6
Url: 1
Domain: 1
Hash: 11
Softs:
task scheduler
ASEC BLOG
FileLess 형태로 유포 중인 AsyncRAT - ASEC BLOG
ASEC 분석팀은 최근 FileLess 형태로 AsyncRAT 악성코드가 유포 중인 것을 확인하였다. 유포 중인 AsyncRAT 은 다수의 스크립트 파일을 통해 FileLess 형태로 실행되며, 이메일 내 압축파일로 첨부되어 유포되는 것으로 추정된다. AsyncRAT 은 닷넷으로 개발된 오픈 소스 RAT 악성코드로 공격자의 명령을 받아 다양한 악성 행위를 수행할 수 있다. 피싱 메일을 통해 유포되는 압축파일 내부에는 html 파일이 존재하며, 실행 시…
#ParsedReport
17-08-2022
Desorden Group The Thai Blitz
https://cyberint.com/blog/research/desorden-group-the-thai-blitz
Actors/Campaigns:
Thai_blitz (motivation: financially_motivated, cyber_criminal)
Desorden (motivation: financially_motivated, cyber_criminal)
Threats:
Chaos
Onyx
Yashma
Industry:
Retail, Healthcare, Logistic, Foodtech, Financial
Geo:
India, Asia, Thailand, Asian, Singapore, Malaysia, Spanish, Taiwan, Philippines
Softs:
telegram
Languages:
python
17-08-2022
Desorden Group The Thai Blitz
https://cyberint.com/blog/research/desorden-group-the-thai-blitz
Actors/Campaigns:
Thai_blitz (motivation: financially_motivated, cyber_criminal)
Desorden (motivation: financially_motivated, cyber_criminal)
Threats:
Chaos
Onyx
Yashma
Industry:
Retail, Healthcare, Logistic, Foodtech, Financial
Geo:
India, Asia, Thailand, Asian, Singapore, Malaysia, Spanish, Taiwan, Philippines
Softs:
telegram
Languages:
python
Cyberint
Desorden Group – The Summer 2023 Update
The Desorden group, previously known as “chaoscc”,added Thai organizations to their victim, list in what seems to be a region based attacks
#ParsedReport
18-08-2022
ASEC Weekly Malware Statistics (August 8th, 2022 August 14th, 2022)
https://asec.ahnlab.com/en/37837
Threats:
Agent_tesla
Remcos_rat
Formbook
Nanocore_rat
Smokeloader
Clipboard_grabbing_technique
Redline_stealer
Beamwinhttp_loader
IOCs:
Domain: 7
IP: 3
Email: 6
File: 17
Url: 27
Softs:
discord
18-08-2022
ASEC Weekly Malware Statistics (August 8th, 2022 August 14th, 2022)
https://asec.ahnlab.com/en/37837
Threats:
Agent_tesla
Remcos_rat
Formbook
Nanocore_rat
Smokeloader
Clipboard_grabbing_technique
Redline_stealer
Beamwinhttp_loader
IOCs:
Domain: 7
IP: 3
Email: 6
File: 17
Url: 27
Softs:
discord
ASEC BLOG
ASEC Weekly Malware Statistics (August 8th, 2022 - August 14th, 2022) - ASEC BLOG
The ASEC analysis team is using the ASEC automatic analysis system RAPIT to categorize and respond to known malware. This post will list weekly statistics collected from August 8th, 2022 (Monday) to August 14th, 2022 (Sunday). For the main category, info…
#ParsedReport
18-08-2022
Reservations Requested: TA558 Targets Hospitality and Travel
https://www.proofpoint.com/us/blog/threat-insight/reservations-requested-ta558-targets-hospitality-and-travel
Actors/Campaigns:
Ta558 (motivation: cyber_criminal, financially_motivated, information_theft)
Threats:
Loda_rat
Revenge_rat
Vjw0rm
Njrat_rat
Ozone
Asyncrat_rat
Tur
Houdini_rat
Bladabindi
Industry:
Transport, Financial, Healthcare
Geo:
Portuguese, Brazilian, Portugal, America, Brazil, Brasil, Spanish
CVEs:
CVE-2017-11882 [Vulners]
Vulners: Score: 9.3, CVSS: 4.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2013, 2010, 2016, 2007)
CVE-2017-8570 [Vulners]
Vulners: Score: 9.3, CVSS: 4.3,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2007, 2010, 2013, 2016, 2013)
IOCs:
File: 4
Hash: 5
Url: 5
Email: 2
Domain: 17
IP: 1
Softs:
microsoft office, microsoft word
Algorithms:
zip
18-08-2022
Reservations Requested: TA558 Targets Hospitality and Travel
https://www.proofpoint.com/us/blog/threat-insight/reservations-requested-ta558-targets-hospitality-and-travel
Actors/Campaigns:
Ta558 (motivation: cyber_criminal, financially_motivated, information_theft)
Threats:
Loda_rat
Revenge_rat
Vjw0rm
Njrat_rat
Ozone
Asyncrat_rat
Tur
Houdini_rat
Bladabindi
Industry:
Transport, Financial, Healthcare
Geo:
Portuguese, Brazilian, Portugal, America, Brazil, Brasil, Spanish
CVEs:
CVE-2017-11882 [Vulners]
Vulners: Score: 9.3, CVSS: 4.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2013, 2010, 2016, 2007)
CVE-2017-8570 [Vulners]
Vulners: Score: 9.3, CVSS: 4.3,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2007, 2010, 2013, 2016, 2013)
IOCs:
File: 4
Hash: 5
Url: 5
Email: 2
Domain: 17
IP: 1
Softs:
microsoft office, microsoft word
Algorithms:
zip
Proofpoint
TA558 Threat Actor Targets Hospitality & Travel | Proofpoint US
Learn about TA558, the financially-motivated threat actor targeting hospitality, hotel, and travel organizations. Find out what our researchers have learned.
#ParsedReport
18-08-2022
BianLian: New Ransomware variant on the rise
https://blog.cyble.com/2022/08/18/bianlian-new-ransomware-variant-on-the-rise
Threats:
Hydra
Industry:
Financial, Education, Healthcare
Geo:
Georgia, Dubai, Singapore, Australia, India
TTPs:
Tactics: 5
Technics: 11
IOCs:
Path: 2
File: 6
Hash: 2
Softs:
bootnxt
Algorithms:
aes
Functions:
FindFirstFileW, wine_get_version, GetProcAddress, CreateThread, FindNextFileW, MoveFileExW, GetDriveTypeW
Languages:
golang
18-08-2022
BianLian: New Ransomware variant on the rise
https://blog.cyble.com/2022/08/18/bianlian-new-ransomware-variant-on-the-rise
Threats:
Hydra
Industry:
Financial, Education, Healthcare
Geo:
Georgia, Dubai, Singapore, Australia, India
TTPs:
Tactics: 5
Technics: 11
IOCs:
Path: 2
File: 6
Hash: 2
Softs:
bootnxt
Algorithms:
aes
Functions:
FindFirstFileW, wine_get_version, GetProcAddress, CreateThread, FindNextFileW, MoveFileExW, GetDriveTypeW
Languages:
golang
Cyble
BianLian: New Ransomware variant on the rise
Cyble analyzes BianLian Ransomware and the increasing popularity of GoLang amongst Threat Actors.
#ParsedReport
18-08-2022
From Ramnit To Bumblebee (via NeverQuest): Similarities and Code Overlap Shed Light On Relationships Between Malware Developers
https://securityintelligence.com/posts/from-ramnit-to-bumblebee-via-neverquest
Actors/Campaigns:
Wizard_spider
Contileaks
Trickleaks
Exotic_lily
Ta579
Ta578
Ta554
Threats:
Ramnit
Bumblebee
Vawtrak
Camellia_loader
Trickbot
Karius
Conti
Bazarbackdoor
Cobalt_strike
Sliver_tool
Meterpreter_tool
Mountlocker
Icedid
Dyre
Zeus
Carberp
Gozi
Starslord
Hooker2
Process_injection_technique
Dll_injection_technique
Industry:
Financial
Geo:
Spain, Russian
CVEs:
CVE-2021-4044 [Vulners]
Vulners: Score: 5.0, CVSS: 1.7,
Vulners: Exploitation: Unknown
X-Force: Risk: 6.5
X-Force: Patch: Official fix
Soft:
- openssl (<1.0.2, 1.1.0, 3.0.0)
- netapp cloud backup (-)
- netapp e-series performance analyzer (-)
- netapp ontap select deploy administration utility (-)
- netapp snapcenter (-)
have more...
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 8
Path: 5
Hash: 44
Softs:
microsoft office, visual studio, mshtml engine, microsoft visual studio, microsoft edge, internet explorer, google chrome
Algorithms:
xor, base64, rc4
Functions:
ZwMapViewOfFile, Stub, ZwCreateSection, ZwMapViewOfSection, OpenSSL, API, LdrLoadDll, NtQueueApcThread, GetSystemInfo, ZwOpenSection, ZwOpenFile
Languages:
javascript
Links:
18-08-2022
From Ramnit To Bumblebee (via NeverQuest): Similarities and Code Overlap Shed Light On Relationships Between Malware Developers
https://securityintelligence.com/posts/from-ramnit-to-bumblebee-via-neverquest
Actors/Campaigns:
Wizard_spider
Contileaks
Trickleaks
Exotic_lily
Ta579
Ta578
Ta554
Threats:
Ramnit
Bumblebee
Vawtrak
Camellia_loader
Trickbot
Karius
Conti
Bazarbackdoor
Cobalt_strike
Sliver_tool
Meterpreter_tool
Mountlocker
Icedid
Dyre
Zeus
Carberp
Gozi
Starslord
Hooker2
Process_injection_technique
Dll_injection_technique
Industry:
Financial
Geo:
Spain, Russian
CVEs:
CVE-2021-4044 [Vulners]
Vulners: Score: 5.0, CVSS: 1.7,
Vulners: Exploitation: Unknown
X-Force: Risk: 6.5
X-Force: Patch: Official fix
Soft:
- openssl (<1.0.2, 1.1.0, 3.0.0)
- netapp cloud backup (-)
- netapp e-series performance analyzer (-)
- netapp ontap select deploy administration utility (-)
- netapp snapcenter (-)
have more...
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 8
Path: 5
Hash: 44
Softs:
microsoft office, visual studio, mshtml engine, microsoft visual studio, microsoft edge, internet explorer, google chrome
Algorithms:
xor, base64, rc4
Functions:
ZwMapViewOfFile, Stub, ZwCreateSection, ZwMapViewOfSection, OpenSSL, API, LdrLoadDll, NtQueueApcThread, GetSystemInfo, ZwOpenSection, ZwOpenFile
Languages:
javascript
Links:
https://github.com/LordNoteworthy/al-khaserhttps://github.com/t3rabyt3-zz/Gozi/blob/master/AcDll/activdll.c#L824Security Intelligence
From Ramnit To Bumblebee (via NeverQuest): Similarities and Code Overlap Shed Light On Relationships Between Malware Developers
Take a deep dive into IBM Security X-Force's comparative analysis, which uncovered evidence that suggests Bumblebee malware was likely developed directly from source code associated with the Ramnit banking trojan.
#ParsedReport
18-08-2022
Cookie stealing: the new perimeter bypass
https://news.sophos.com/en-us/2022/08/18/cookie-stealing-the-new-perimeter-bypass
Actors/Campaigns:
Lapsus
Threats:
Credential_stealing_technique
Emotet
Raccoon_stealer
Redline_stealer
Meterpreter_tool
Cobalt_strike
Mimikatz
Metasploit_tool
Phoenix_keylogger
Quasar_rat
Impacket_tool
Industry:
E-commerce, Financial
Geo:
Turkish
IOCs:
File: 6
Softs:
slack, google chrome, chrome, discord, microsoft visual studio, windows smb, mozilla firefox, microsoft edge
Algorithms:
zip
Languages:
autoit, perl, delphi
Links:
18-08-2022
Cookie stealing: the new perimeter bypass
https://news.sophos.com/en-us/2022/08/18/cookie-stealing-the-new-perimeter-bypass
Actors/Campaigns:
Lapsus
Threats:
Credential_stealing_technique
Emotet
Raccoon_stealer
Redline_stealer
Meterpreter_tool
Cobalt_strike
Mimikatz
Metasploit_tool
Phoenix_keylogger
Quasar_rat
Impacket_tool
Industry:
E-commerce, Financial
Geo:
Turkish
IOCs:
File: 6
Softs:
slack, google chrome, chrome, discord, microsoft visual studio, windows smb, mozilla firefox, microsoft edge
Algorithms:
zip
Languages:
autoit, perl, delphi
Links:
https://github.com/malwares/QuasarRAThttps://github.com/SecureAuthCorp/impacketSophos News
Cookie stealing: the new perimeter bypass
As organizations move to cloud services and multifactor authentication, cookies tied to identity and authentication give attackers a new path to compromise.
#ParsedReport
18-08-2022
Ransomware Roundup: Gwisin, Kriptor, Cuba, and More
https://www.fortinet.com/blog/threat-research/ransomware-roundup-gwisin-kriptor-cuba-and-more
Threats:
Gwisin
Kriptor
Cuba
Darkylock
Babuk
Lockbit
W32/filecoderprot.f183!tr.ransom
W32/coinminer.nbh!tr
W32/stealer.3389!tr
Filecoder
Kryptik_trojan
W32/injector.eqgy!tr
Stop
Wannacry
Industry:
Financial
Geo:
Korea
IOCs:
File: 1
18-08-2022
Ransomware Roundup: Gwisin, Kriptor, Cuba, and More
https://www.fortinet.com/blog/threat-research/ransomware-roundup-gwisin-kriptor-cuba-and-more
Threats:
Gwisin
Kriptor
Cuba
Darkylock
Babuk
Lockbit
W32/filecoderprot.f183!tr.ransom
W32/coinminer.nbh!tr
W32/stealer.3389!tr
Filecoder
Kryptik_trojan
W32/injector.eqgy!tr
Stop
Wannacry
Industry:
Financial
Geo:
Korea
IOCs:
File: 1
Fortinet Blog
Ransomware Roundup: Gwisin, Kriptor, Cuba, and More | FortiGuard Labs
The latest edition of the Ransomware Roundup from FortiGuard Labs covers the Gwisin, Kriptor, and Cuba ransomware. Read to learn more about protections against these variants.…
#ParsedReport
18-08-2022
Kasablanka. Kasablanka (Casablanca) organization against the political groups and public welfare organizations in the Middle East
https://mp.weixin.qq.com/s/mstwBMkS0G3Et4GOji2mwA
Threats:
Spynote_rat
Loda_rat
Nanocore_rat
Njrat_rat
Upx_tool
Industry:
Financial, Government, Healthcare
Geo:
Bangladesh, Yemen, India
IOCs:
File: 7
Hash: 17
IP: 1
Softs:
android
Languages:
autoit
18-08-2022
Kasablanka. Kasablanka (Casablanca) organization against the political groups and public welfare organizations in the Middle East
https://mp.weixin.qq.com/s/mstwBMkS0G3Et4GOji2mwA
Threats:
Spynote_rat
Loda_rat
Nanocore_rat
Njrat_rat
Upx_tool
Industry:
Financial, Government, Healthcare
Geo:
Bangladesh, Yemen, India
IOCs:
File: 7
Hash: 17
IP: 1
Softs:
android
Languages:
autoit
Weixin Official Accounts Platform
Kasablanka(卡萨布兰卡)组织针对中东地区政治团体和公益组织的攻击行动
近期,360高级威胁研究院在日常情报挖掘中发现并捕获到了Kasablanka组织针对Windows和Android两个平台的攻击活动,经分析后推测该组织不简简单单是为了经济利益,其动机似乎更倾向于信息收集和间谍活动
#ParsedReport
18-08-2022
GitHub (*.sln) RAT. RAT tools distributed by disguised as a solution file (*.sln) in github
https://asec.ahnlab.com/ko/37764
Threats:
Asyncrat_rat
Trojan/win.leonem.c5218555
Trojan/win.agent.c4526491
Vbinder
Smokeloader
Trojan/win.msilzilla.c5129545
Trojan/win.generic.c5198415
Malware/mdp.inject.m3037
Malware/mdp.autorun.m1037
Malware/mdp.inject.m1252
IOCs:
File: 4
Url: 4
Hash: 6
Softs:
windows explorer
Algorithms:
zip
18-08-2022
GitHub (*.sln) RAT. RAT tools distributed by disguised as a solution file (*.sln) in github
https://asec.ahnlab.com/ko/37764
Threats:
Asyncrat_rat
Trojan/win.leonem.c5218555
Trojan/win.agent.c4526491
Vbinder
Smokeloader
Trojan/win.msilzilla.c5129545
Trojan/win.generic.c5198415
Malware/mdp.inject.m3037
Malware/mdp.autorun.m1037
Malware/mdp.inject.m1252
IOCs:
File: 4
Url: 4
Hash: 6
Softs:
windows explorer
Algorithms:
zip
ASEC BLOG
GitHub에 솔루션파일(*.sln) 위장하여 유포되는 RAT 툴 - ASEC BLOG
ASEC 분석팀에서는 최근 GitHub 에서 솔루션파일(*.sln)을 위장하여 RAT 툴이 유포 중인 것을 확인하였다. [그림1] 은 악성코드 유포자가 GitHub에 “Jpg Png Exploit Downloader Fud Cryter Malware Builder Cve 2022” 제목으로 소스코드를 공유한 내용이다. 프로그램의 구성파일이 정상적으로 보이지만 이 중 솔루션파일(*.sln)은 RAT 툴이다. 이와 같은 방법으로 악성코드 유포자는 RAT 툴을…
#ParsedReport
18-08-2022
Grandoreiro Banking Trojan with New TTPs Targeting Various Industry Verticals
https://www.zscaler.com/blogs/security-research/grandoreiro-banking-trojan-new-ttps-targeting-various-industry-verticals
Threats:
Grandoreiro
Latentbot
Beacon
Industry:
Logistic, Government, Financial, Chemical
Geo:
America, Brazil, Spain, Spanish, Mexico
TTPs:
Tactics: 1
Technics: 0
IOCs:
Url: 6
File: 19
Path: 1
Domain: 5
Registry: 1
Hash: 10
Softs:
electrum, coinomi
Algorithms:
xor, zip
Functions:
CreateMutexA, IsDebuggerPresent, URLDownloadToFile, GetUserNameW, Process32First, GetComputerNameW, Process32Next, GetWindowTextW, EnumWindows, CreateToolhelp32Snapshot, FindWindowW
Languages:
delphi
Platforms:
x86
Links:
18-08-2022
Grandoreiro Banking Trojan with New TTPs Targeting Various Industry Verticals
https://www.zscaler.com/blogs/security-research/grandoreiro-banking-trojan-new-ttps-targeting-various-industry-verticals
Threats:
Grandoreiro
Latentbot
Beacon
Industry:
Logistic, Government, Financial, Chemical
Geo:
America, Brazil, Spain, Spanish, Mexico
TTPs:
Tactics: 1
Technics: 0
IOCs:
Url: 6
File: 19
Path: 1
Domain: 5
Registry: 1
Hash: 10
Softs:
electrum, coinomi
Algorithms:
xor, zip
Functions:
CreateMutexA, IsDebuggerPresent, URLDownloadToFile, GetUserNameW, Process32First, GetComputerNameW, Process32Next, GetWindowTextW, EnumWindows, CreateToolhelp32Snapshot, FindWindowW
Languages:
delphi
Platforms:
x86
Links:
https://github.com/SpiderLabs/Grandoreiro-decryptor/blob/main/grandoreiro\_string\_decryptor.pyZscaler
Grandoreiro Banking Trojan with New TTPs Targeting Various Industry Verticals | Zscaler
Grandoreiro, one of the top banking trojans in Latin America, is using new tactics in a malware campaign that impersonates government officials.