#ParsedReport
17-08-2022
Suspected Iranian Actor Targeting Israeli Shipping, Healthcare, Government and Energy Sectors
https://www.mandiant.com/resources/suspected-iranian-actor-targeting-israeli-shipping
Actors/Campaigns:
Unc3890 (motivation: cyber_espionage)
Fox_kitten
Cleaver
Threats:
Watering_hole_technique
Sugarush
Sugardump
Metasploit_tool
Northstar_tool
Credential_harvesting_technique
Industry:
Energy, Healthcare, Government, Maritime, Transport, Aerospace
Geo:
Israel, Iran, Israeli, Iranian
IOCs:
Domain: 9
Url: 1
Hash: 1
Softs:
instagram
Algorithms:
zip
17-08-2022
Suspected Iranian Actor Targeting Israeli Shipping, Healthcare, Government and Energy Sectors
https://www.mandiant.com/resources/suspected-iranian-actor-targeting-israeli-shipping
Actors/Campaigns:
Unc3890 (motivation: cyber_espionage)
Fox_kitten
Cleaver
Threats:
Watering_hole_technique
Sugarush
Sugardump
Metasploit_tool
Northstar_tool
Credential_harvesting_technique
Industry:
Energy, Healthcare, Government, Maritime, Transport, Aerospace
Geo:
Israel, Iran, Israeli, Iranian
IOCs:
Domain: 9
Url: 1
Hash: 1
Softs:
Algorithms:
zip
Google Cloud Blog
UNC3890: Suspected Iranian Threat Actor Targeting Israeli Shipping, Healthcare, Government and Energy Sectors | Google Cloud Blog
#ParsedReport
17-08-2022
Malicious PyPi User Strikes Again with Typosquatting, StarJacking and Unpacks Tailor-made Malware written in C#. Intro
https://checkmarx.com/blog/malicious-pypi-user-strikes-again-with-typosquatting-starjacking-and-unpacks-tailor-made-malware-written-in-c
Threats:
Typosquatting_technique
Starjacking_technique
Joao
Cobalt_strike
Beacon
Intellilock_tool
Geo:
Kazakhstan
IOCs:
Path: 1
Url: 2
IP: 1
Hash: 4
Algorithms:
base64, exhibit
Languages:
python
17-08-2022
Malicious PyPi User Strikes Again with Typosquatting, StarJacking and Unpacks Tailor-made Malware written in C#. Intro
https://checkmarx.com/blog/malicious-pypi-user-strikes-again-with-typosquatting-starjacking-and-unpacks-tailor-made-malware-written-in-c
Threats:
Typosquatting_technique
Starjacking_technique
Joao
Cobalt_strike
Beacon
Intellilock_tool
Geo:
Kazakhstan
IOCs:
Path: 1
Url: 2
IP: 1
Hash: 4
Algorithms:
base64, exhibit
Languages:
python
Checkmarx
Malicious PyPi User Strikes Again with Typosquatting, StarJacking and Unpacks Tailor-made Malware written in C#
On Saturday, August 13th, Checkmarx's Software Supply Chain Security Typosquatting and StarJacking engines detected what seemed like an attack on the Python ecosystem. Further investigation revealed multiple evasion and obfuscation techniques, C2 communication…
#ParsedReport
17-08-2022
MasterFred Using Gymdrop to Distribute Xenomorph Android Banking Trojan
https://blog.cyble.com/2022/08/17/masterfred-using-gymdrop-to-distribute-xenomorph-android-banking-trojan
Actors/Campaigns:
Hadoken_security
Threats:
Masterfred
Gymdrop
Xenomorph
Hostile
Opendir
Hydra
Alien
Octo
Typhon_stealer
Industry:
Financial
Geo:
India, Dubai, Georgia, Poland, Australia, Singapore, Turkey
TTPs:
Tactics: 5
Technics: 9
IOCs:
Url: 7
File: 3
Hash: 2
Softs:
android
17-08-2022
MasterFred Using Gymdrop to Distribute Xenomorph Android Banking Trojan
https://blog.cyble.com/2022/08/17/masterfred-using-gymdrop-to-distribute-xenomorph-android-banking-trojan
Actors/Campaigns:
Hadoken_security
Threats:
Masterfred
Gymdrop
Xenomorph
Hostile
Opendir
Hydra
Alien
Octo
Typhon_stealer
Industry:
Financial
Geo:
India, Dubai, Georgia, Poland, Australia, Singapore, Turkey
TTPs:
Tactics: 5
Technics: 9
IOCs:
Url: 7
File: 3
Hash: 2
Softs:
android
Cyble
MasterFred Using Gymdrop to Distribute Xenomorph Android Banking Trojan
Cyble analyzes the new variant of MasterFred, which acts as the Hostile Downloader and distributes Xenomorph Banking Trojan.
#ParsedReport
17-08-2022
DarkTortilla Malware Analysis
https://www.secureworks.com/research/darktortilla-malware-analysis
Threats:
Darktortilla
Agent_tesla
Asyncrat_rat
Nanocore_rat
Redline_stealer
Cobalt_strike
Metasploit_tool
Process_injection_technique
Confuserex_tool
Junk_code_technique
Industry:
Logistic
Geo:
German, Italian, Romanian, Spanish
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 35
Hash: 56
Softs:
virtualbox, .net framework, windows shell, winlogon, windows registry, discord, hyper-v
Algorithms:
aes
Links:
17-08-2022
DarkTortilla Malware Analysis
https://www.secureworks.com/research/darktortilla-malware-analysis
Threats:
Darktortilla
Agent_tesla
Asyncrat_rat
Nanocore_rat
Redline_stealer
Cobalt_strike
Metasploit_tool
Process_injection_technique
Confuserex_tool
Junk_code_technique
Industry:
Logistic
Geo:
German, Italian, Romanian, Spanish
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 35
Hash: 56
Softs:
virtualbox, .net framework, windows shell, winlogon, windows registry, discord, hyper-v
Algorithms:
aes
Links:
https://github.com/malwares/Crypter/tree/master/%5BC%23%5D%20The%20RATs%20Crew%20Crypterhttps://github.com/malwares/Crypter/blob/master/%5BC%23%5D%20The%20RATs%20Crew%20Crypter/Form1.cs#L161-L163https://github.com/dnSpyEx/dnSpySophos
DarkTortilla Malware Analysis
Learn how Secureworks CTU researchers have identified DarkTortilla samples delivering targeted malicious payloads, benign decoy documents, and executables.
#ParsedReport
17-08-2022
THREAT ANALYSIS REPORT: Bumblebee Loader The High Road to Enterprise Domain Control
https://www.cybereason.com/blog/threat-analysis-report-bumblebee-loader-the-high-road-to-enterprise-domain-control
Threats:
Bumblebee
Bazarbackdoor
Trickbot
Icedid
Cobalt_strike
Meterpreter_tool
Zerologon_vuln
Beacon
Adfind_tool
Lolbin
Uac_bypass_technique
Process_injection_technique
Anydesk_tool
Industry:
Government
CVEs:
CVE-2020-1472 [Vulners]
Vulners: Score: 9.3, CVSS: 3.8,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2)
- microsoft windows server 2012 (-, r2)
- microsoft windows server 2016 (-, 1903, 1909, 2004)
- microsoft windows server 2019 (-)
- fedoraproject fedora (31, 32, 33)
have more...
TTPs:
Tactics: 10
Technics: 24
IOCs:
File: 19
Path: 5
Domain: 1
IP: 1
Hash: 1
Softs:
winlogon, active directory, microsoft exchange, local security authority, curl, vssadmin
Links:
17-08-2022
THREAT ANALYSIS REPORT: Bumblebee Loader The High Road to Enterprise Domain Control
https://www.cybereason.com/blog/threat-analysis-report-bumblebee-loader-the-high-road-to-enterprise-domain-control
Threats:
Bumblebee
Bazarbackdoor
Trickbot
Icedid
Cobalt_strike
Meterpreter_tool
Zerologon_vuln
Beacon
Adfind_tool
Lolbin
Uac_bypass_technique
Process_injection_technique
Anydesk_tool
Industry:
Government
CVEs:
CVE-2020-1472 [Vulners]
Vulners: Score: 9.3, CVSS: 3.8,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2)
- microsoft windows server 2012 (-, r2)
- microsoft windows server 2016 (-, 1903, 1909, 2004)
- microsoft windows server 2019 (-)
- fedoraproject fedora (31, 32, 33)
have more...
TTPs:
Tactics: 10
Technics: 24
IOCs:
File: 19
Path: 5
Domain: 1
IP: 1
Hash: 1
Softs:
winlogon, active directory, microsoft exchange, local security authority, curl, vssadmin
Links:
https://github.com/leitosama/SharpZeroLogonCybereason
THREAT ANALYSIS REPORT: Bumblebee Loader – The High Road to Enterprise Domain Control
Cybereason GSOC observed distribution of the Bumblebee Loader and post-exploitation activities including privilege escalation, reconnaissance and credential theft. Bumblebee operators use the Cobalt Strike framework throughout the attack and abuse credentials…
#ParsedReport
17-08-2022
An In-Depth Look at Quantum Ransomware
https://explore.avertium.com/resource/an-in-depth-look-at-quantum-ransomware
Actors/Campaigns:
Xinglocker
Jormungandr
Threats:
Quantum_locker
Astrolocker
Mountlocker
Conti
Bazarbackdoor
Ryuk
Zeon
Icedid
Cobalt_strike
Adfind_tool
Metasploit_tool
Beacon
Industry:
Healthcare, Financial
Geo:
India
IOCs:
File: 10
Domain: 3
IP: 1
Hash: 8
Softs:
psexec, active directory
17-08-2022
An In-Depth Look at Quantum Ransomware
https://explore.avertium.com/resource/an-in-depth-look-at-quantum-ransomware
Actors/Campaigns:
Xinglocker
Jormungandr
Threats:
Quantum_locker
Astrolocker
Mountlocker
Conti
Bazarbackdoor
Ryuk
Zeon
Icedid
Cobalt_strike
Adfind_tool
Metasploit_tool
Beacon
Industry:
Healthcare, Financial
Geo:
India
IOCs:
File: 10
Domain: 3
IP: 1
Hash: 8
Softs:
psexec, active directory
Avertium
An In-Depth Look at Quantum Ransomware
Quantum ransomware is a newer, lesser-known ransomware that operates with the RaaS model & has been successful with compromising healthcare organizations.
#ParsedReport
17-08-2022
AsyncRAT C2 Framework: Overview, Technical Analysis & Detection
https://blog.qualys.com/vulnerabilities-threat-research/2022/08/16/asyncrat-c2-framework-overview-technical-analysis-and-detection
Actors/Campaigns:
Layover
Ta2541
Threats:
Asyncrat_rat
Follina_vuln
Antidebugging_technique
Limelogger_tool
Industry:
Transport, Aerospace, Healthcare, Government
Geo:
Thailand, Asia, America, Australia
TTPs:
Tactics: 3
Technics: 9
IOCs:
File: 4
Softs:
virtualbox
Algorithms:
pbkdf2, aes-256
Functions:
GetKeyState, GetModuleHandle, GetForegroundWindow, GetKeyboardLayout, SetThreadExecutionState, RtlSetProcessIsCritical
Links:
17-08-2022
AsyncRAT C2 Framework: Overview, Technical Analysis & Detection
https://blog.qualys.com/vulnerabilities-threat-research/2022/08/16/asyncrat-c2-framework-overview-technical-analysis-and-detection
Actors/Campaigns:
Layover
Ta2541
Threats:
Asyncrat_rat
Follina_vuln
Antidebugging_technique
Limelogger_tool
Industry:
Transport, Aerospace, Healthcare, Government
Geo:
Thailand, Asia, America, Australia
TTPs:
Tactics: 3
Technics: 9
IOCs:
File: 4
Softs:
virtualbox
Algorithms:
pbkdf2, aes-256
Functions:
GetKeyState, GetModuleHandle, GetForegroundWindow, GetKeyboardLayout, SetThreadExecutionState, RtlSetProcessIsCritical
Links:
https://github.com/NYAN-x-CAT/AsyncRAT-C-Sharphttps://github.com/NYAN-x-CAT/LimeLogger/blob/master/LimeLogger/LimeLogger.csQualys
AsyncRAT C2 Framework: Overview, Technical Analysis & Detection | Qualys
In this blog we describe the AsyncRAT C2 (command & control) Framework, which allows attackers to remotely monitor and control other computers over a secure encrypted link. We provide an overview of…
#ParsedReport
17-08-2022
FileLess AsyncRAT
https://asec.ahnlab.com/ko/37676
Threats:
Asyncrat_rat
Trojan/vbs.runner
IOCs:
File: 14
Path: 6
Url: 1
Domain: 1
Hash: 11
Softs:
task scheduler
17-08-2022
FileLess AsyncRAT
https://asec.ahnlab.com/ko/37676
Threats:
Asyncrat_rat
Trojan/vbs.runner
IOCs:
File: 14
Path: 6
Url: 1
Domain: 1
Hash: 11
Softs:
task scheduler
ASEC BLOG
FileLess 형태로 유포 중인 AsyncRAT - ASEC BLOG
ASEC 분석팀은 최근 FileLess 형태로 AsyncRAT 악성코드가 유포 중인 것을 확인하였다. 유포 중인 AsyncRAT 은 다수의 스크립트 파일을 통해 FileLess 형태로 실행되며, 이메일 내 압축파일로 첨부되어 유포되는 것으로 추정된다. AsyncRAT 은 닷넷으로 개발된 오픈 소스 RAT 악성코드로 공격자의 명령을 받아 다양한 악성 행위를 수행할 수 있다. 피싱 메일을 통해 유포되는 압축파일 내부에는 html 파일이 존재하며, 실행 시…
#ParsedReport
17-08-2022
Desorden Group The Thai Blitz
https://cyberint.com/blog/research/desorden-group-the-thai-blitz
Actors/Campaigns:
Thai_blitz (motivation: financially_motivated, cyber_criminal)
Desorden (motivation: financially_motivated, cyber_criminal)
Threats:
Chaos
Onyx
Yashma
Industry:
Retail, Healthcare, Logistic, Foodtech, Financial
Geo:
India, Asia, Thailand, Asian, Singapore, Malaysia, Spanish, Taiwan, Philippines
Softs:
telegram
Languages:
python
17-08-2022
Desorden Group The Thai Blitz
https://cyberint.com/blog/research/desorden-group-the-thai-blitz
Actors/Campaigns:
Thai_blitz (motivation: financially_motivated, cyber_criminal)
Desorden (motivation: financially_motivated, cyber_criminal)
Threats:
Chaos
Onyx
Yashma
Industry:
Retail, Healthcare, Logistic, Foodtech, Financial
Geo:
India, Asia, Thailand, Asian, Singapore, Malaysia, Spanish, Taiwan, Philippines
Softs:
telegram
Languages:
python
Cyberint
Desorden Group – The Summer 2023 Update
The Desorden group, previously known as “chaoscc”,added Thai organizations to their victim, list in what seems to be a region based attacks
#ParsedReport
18-08-2022
ASEC Weekly Malware Statistics (August 8th, 2022 August 14th, 2022)
https://asec.ahnlab.com/en/37837
Threats:
Agent_tesla
Remcos_rat
Formbook
Nanocore_rat
Smokeloader
Clipboard_grabbing_technique
Redline_stealer
Beamwinhttp_loader
IOCs:
Domain: 7
IP: 3
Email: 6
File: 17
Url: 27
Softs:
discord
18-08-2022
ASEC Weekly Malware Statistics (August 8th, 2022 August 14th, 2022)
https://asec.ahnlab.com/en/37837
Threats:
Agent_tesla
Remcos_rat
Formbook
Nanocore_rat
Smokeloader
Clipboard_grabbing_technique
Redline_stealer
Beamwinhttp_loader
IOCs:
Domain: 7
IP: 3
Email: 6
File: 17
Url: 27
Softs:
discord
ASEC BLOG
ASEC Weekly Malware Statistics (August 8th, 2022 - August 14th, 2022) - ASEC BLOG
The ASEC analysis team is using the ASEC automatic analysis system RAPIT to categorize and respond to known malware. This post will list weekly statistics collected from August 8th, 2022 (Monday) to August 14th, 2022 (Sunday). For the main category, info…
#ParsedReport
18-08-2022
Reservations Requested: TA558 Targets Hospitality and Travel
https://www.proofpoint.com/us/blog/threat-insight/reservations-requested-ta558-targets-hospitality-and-travel
Actors/Campaigns:
Ta558 (motivation: cyber_criminal, financially_motivated, information_theft)
Threats:
Loda_rat
Revenge_rat
Vjw0rm
Njrat_rat
Ozone
Asyncrat_rat
Tur
Houdini_rat
Bladabindi
Industry:
Transport, Financial, Healthcare
Geo:
Portuguese, Brazilian, Portugal, America, Brazil, Brasil, Spanish
CVEs:
CVE-2017-11882 [Vulners]
Vulners: Score: 9.3, CVSS: 4.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2013, 2010, 2016, 2007)
CVE-2017-8570 [Vulners]
Vulners: Score: 9.3, CVSS: 4.3,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2007, 2010, 2013, 2016, 2013)
IOCs:
File: 4
Hash: 5
Url: 5
Email: 2
Domain: 17
IP: 1
Softs:
microsoft office, microsoft word
Algorithms:
zip
18-08-2022
Reservations Requested: TA558 Targets Hospitality and Travel
https://www.proofpoint.com/us/blog/threat-insight/reservations-requested-ta558-targets-hospitality-and-travel
Actors/Campaigns:
Ta558 (motivation: cyber_criminal, financially_motivated, information_theft)
Threats:
Loda_rat
Revenge_rat
Vjw0rm
Njrat_rat
Ozone
Asyncrat_rat
Tur
Houdini_rat
Bladabindi
Industry:
Transport, Financial, Healthcare
Geo:
Portuguese, Brazilian, Portugal, America, Brazil, Brasil, Spanish
CVEs:
CVE-2017-11882 [Vulners]
Vulners: Score: 9.3, CVSS: 4.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2013, 2010, 2016, 2007)
CVE-2017-8570 [Vulners]
Vulners: Score: 9.3, CVSS: 4.3,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2007, 2010, 2013, 2016, 2013)
IOCs:
File: 4
Hash: 5
Url: 5
Email: 2
Domain: 17
IP: 1
Softs:
microsoft office, microsoft word
Algorithms:
zip
Proofpoint
TA558 Threat Actor Targets Hospitality & Travel | Proofpoint US
Learn about TA558, the financially-motivated threat actor targeting hospitality, hotel, and travel organizations. Find out what our researchers have learned.
#ParsedReport
18-08-2022
BianLian: New Ransomware variant on the rise
https://blog.cyble.com/2022/08/18/bianlian-new-ransomware-variant-on-the-rise
Threats:
Hydra
Industry:
Financial, Education, Healthcare
Geo:
Georgia, Dubai, Singapore, Australia, India
TTPs:
Tactics: 5
Technics: 11
IOCs:
Path: 2
File: 6
Hash: 2
Softs:
bootnxt
Algorithms:
aes
Functions:
FindFirstFileW, wine_get_version, GetProcAddress, CreateThread, FindNextFileW, MoveFileExW, GetDriveTypeW
Languages:
golang
18-08-2022
BianLian: New Ransomware variant on the rise
https://blog.cyble.com/2022/08/18/bianlian-new-ransomware-variant-on-the-rise
Threats:
Hydra
Industry:
Financial, Education, Healthcare
Geo:
Georgia, Dubai, Singapore, Australia, India
TTPs:
Tactics: 5
Technics: 11
IOCs:
Path: 2
File: 6
Hash: 2
Softs:
bootnxt
Algorithms:
aes
Functions:
FindFirstFileW, wine_get_version, GetProcAddress, CreateThread, FindNextFileW, MoveFileExW, GetDriveTypeW
Languages:
golang
Cyble
BianLian: New Ransomware variant on the rise
Cyble analyzes BianLian Ransomware and the increasing popularity of GoLang amongst Threat Actors.
#ParsedReport
18-08-2022
From Ramnit To Bumblebee (via NeverQuest): Similarities and Code Overlap Shed Light On Relationships Between Malware Developers
https://securityintelligence.com/posts/from-ramnit-to-bumblebee-via-neverquest
Actors/Campaigns:
Wizard_spider
Contileaks
Trickleaks
Exotic_lily
Ta579
Ta578
Ta554
Threats:
Ramnit
Bumblebee
Vawtrak
Camellia_loader
Trickbot
Karius
Conti
Bazarbackdoor
Cobalt_strike
Sliver_tool
Meterpreter_tool
Mountlocker
Icedid
Dyre
Zeus
Carberp
Gozi
Starslord
Hooker2
Process_injection_technique
Dll_injection_technique
Industry:
Financial
Geo:
Spain, Russian
CVEs:
CVE-2021-4044 [Vulners]
Vulners: Score: 5.0, CVSS: 1.7,
Vulners: Exploitation: Unknown
X-Force: Risk: 6.5
X-Force: Patch: Official fix
Soft:
- openssl (<1.0.2, 1.1.0, 3.0.0)
- netapp cloud backup (-)
- netapp e-series performance analyzer (-)
- netapp ontap select deploy administration utility (-)
- netapp snapcenter (-)
have more...
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 8
Path: 5
Hash: 44
Softs:
microsoft office, visual studio, mshtml engine, microsoft visual studio, microsoft edge, internet explorer, google chrome
Algorithms:
xor, base64, rc4
Functions:
ZwMapViewOfFile, Stub, ZwCreateSection, ZwMapViewOfSection, OpenSSL, API, LdrLoadDll, NtQueueApcThread, GetSystemInfo, ZwOpenSection, ZwOpenFile
Languages:
javascript
Links:
18-08-2022
From Ramnit To Bumblebee (via NeverQuest): Similarities and Code Overlap Shed Light On Relationships Between Malware Developers
https://securityintelligence.com/posts/from-ramnit-to-bumblebee-via-neverquest
Actors/Campaigns:
Wizard_spider
Contileaks
Trickleaks
Exotic_lily
Ta579
Ta578
Ta554
Threats:
Ramnit
Bumblebee
Vawtrak
Camellia_loader
Trickbot
Karius
Conti
Bazarbackdoor
Cobalt_strike
Sliver_tool
Meterpreter_tool
Mountlocker
Icedid
Dyre
Zeus
Carberp
Gozi
Starslord
Hooker2
Process_injection_technique
Dll_injection_technique
Industry:
Financial
Geo:
Spain, Russian
CVEs:
CVE-2021-4044 [Vulners]
Vulners: Score: 5.0, CVSS: 1.7,
Vulners: Exploitation: Unknown
X-Force: Risk: 6.5
X-Force: Patch: Official fix
Soft:
- openssl (<1.0.2, 1.1.0, 3.0.0)
- netapp cloud backup (-)
- netapp e-series performance analyzer (-)
- netapp ontap select deploy administration utility (-)
- netapp snapcenter (-)
have more...
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 8
Path: 5
Hash: 44
Softs:
microsoft office, visual studio, mshtml engine, microsoft visual studio, microsoft edge, internet explorer, google chrome
Algorithms:
xor, base64, rc4
Functions:
ZwMapViewOfFile, Stub, ZwCreateSection, ZwMapViewOfSection, OpenSSL, API, LdrLoadDll, NtQueueApcThread, GetSystemInfo, ZwOpenSection, ZwOpenFile
Languages:
javascript
Links:
https://github.com/LordNoteworthy/al-khaserhttps://github.com/t3rabyt3-zz/Gozi/blob/master/AcDll/activdll.c#L824Security Intelligence
From Ramnit To Bumblebee (via NeverQuest): Similarities and Code Overlap Shed Light On Relationships Between Malware Developers
Take a deep dive into IBM Security X-Force's comparative analysis, which uncovered evidence that suggests Bumblebee malware was likely developed directly from source code associated with the Ramnit banking trojan.
#ParsedReport
18-08-2022
Cookie stealing: the new perimeter bypass
https://news.sophos.com/en-us/2022/08/18/cookie-stealing-the-new-perimeter-bypass
Actors/Campaigns:
Lapsus
Threats:
Credential_stealing_technique
Emotet
Raccoon_stealer
Redline_stealer
Meterpreter_tool
Cobalt_strike
Mimikatz
Metasploit_tool
Phoenix_keylogger
Quasar_rat
Impacket_tool
Industry:
E-commerce, Financial
Geo:
Turkish
IOCs:
File: 6
Softs:
slack, google chrome, chrome, discord, microsoft visual studio, windows smb, mozilla firefox, microsoft edge
Algorithms:
zip
Languages:
autoit, perl, delphi
Links:
18-08-2022
Cookie stealing: the new perimeter bypass
https://news.sophos.com/en-us/2022/08/18/cookie-stealing-the-new-perimeter-bypass
Actors/Campaigns:
Lapsus
Threats:
Credential_stealing_technique
Emotet
Raccoon_stealer
Redline_stealer
Meterpreter_tool
Cobalt_strike
Mimikatz
Metasploit_tool
Phoenix_keylogger
Quasar_rat
Impacket_tool
Industry:
E-commerce, Financial
Geo:
Turkish
IOCs:
File: 6
Softs:
slack, google chrome, chrome, discord, microsoft visual studio, windows smb, mozilla firefox, microsoft edge
Algorithms:
zip
Languages:
autoit, perl, delphi
Links:
https://github.com/malwares/QuasarRAThttps://github.com/SecureAuthCorp/impacketSophos News
Cookie stealing: the new perimeter bypass
As organizations move to cloud services and multifactor authentication, cookies tied to identity and authentication give attackers a new path to compromise.
#ParsedReport
18-08-2022
Ransomware Roundup: Gwisin, Kriptor, Cuba, and More
https://www.fortinet.com/blog/threat-research/ransomware-roundup-gwisin-kriptor-cuba-and-more
Threats:
Gwisin
Kriptor
Cuba
Darkylock
Babuk
Lockbit
W32/filecoderprot.f183!tr.ransom
W32/coinminer.nbh!tr
W32/stealer.3389!tr
Filecoder
Kryptik_trojan
W32/injector.eqgy!tr
Stop
Wannacry
Industry:
Financial
Geo:
Korea
IOCs:
File: 1
18-08-2022
Ransomware Roundup: Gwisin, Kriptor, Cuba, and More
https://www.fortinet.com/blog/threat-research/ransomware-roundup-gwisin-kriptor-cuba-and-more
Threats:
Gwisin
Kriptor
Cuba
Darkylock
Babuk
Lockbit
W32/filecoderprot.f183!tr.ransom
W32/coinminer.nbh!tr
W32/stealer.3389!tr
Filecoder
Kryptik_trojan
W32/injector.eqgy!tr
Stop
Wannacry
Industry:
Financial
Geo:
Korea
IOCs:
File: 1
Fortinet Blog
Ransomware Roundup: Gwisin, Kriptor, Cuba, and More | FortiGuard Labs
The latest edition of the Ransomware Roundup from FortiGuard Labs covers the Gwisin, Kriptor, and Cuba ransomware. Read to learn more about protections against these variants.…
#ParsedReport
18-08-2022
Kasablanka. Kasablanka (Casablanca) organization against the political groups and public welfare organizations in the Middle East
https://mp.weixin.qq.com/s/mstwBMkS0G3Et4GOji2mwA
Threats:
Spynote_rat
Loda_rat
Nanocore_rat
Njrat_rat
Upx_tool
Industry:
Financial, Government, Healthcare
Geo:
Bangladesh, Yemen, India
IOCs:
File: 7
Hash: 17
IP: 1
Softs:
android
Languages:
autoit
18-08-2022
Kasablanka. Kasablanka (Casablanca) organization against the political groups and public welfare organizations in the Middle East
https://mp.weixin.qq.com/s/mstwBMkS0G3Et4GOji2mwA
Threats:
Spynote_rat
Loda_rat
Nanocore_rat
Njrat_rat
Upx_tool
Industry:
Financial, Government, Healthcare
Geo:
Bangladesh, Yemen, India
IOCs:
File: 7
Hash: 17
IP: 1
Softs:
android
Languages:
autoit
Weixin Official Accounts Platform
Kasablanka(卡萨布兰卡)组织针对中东地区政治团体和公益组织的攻击行动
近期,360高级威胁研究院在日常情报挖掘中发现并捕获到了Kasablanka组织针对Windows和Android两个平台的攻击活动,经分析后推测该组织不简简单单是为了经济利益,其动机似乎更倾向于信息收集和间谍活动
#ParsedReport
18-08-2022
GitHub (*.sln) RAT. RAT tools distributed by disguised as a solution file (*.sln) in github
https://asec.ahnlab.com/ko/37764
Threats:
Asyncrat_rat
Trojan/win.leonem.c5218555
Trojan/win.agent.c4526491
Vbinder
Smokeloader
Trojan/win.msilzilla.c5129545
Trojan/win.generic.c5198415
Malware/mdp.inject.m3037
Malware/mdp.autorun.m1037
Malware/mdp.inject.m1252
IOCs:
File: 4
Url: 4
Hash: 6
Softs:
windows explorer
Algorithms:
zip
18-08-2022
GitHub (*.sln) RAT. RAT tools distributed by disguised as a solution file (*.sln) in github
https://asec.ahnlab.com/ko/37764
Threats:
Asyncrat_rat
Trojan/win.leonem.c5218555
Trojan/win.agent.c4526491
Vbinder
Smokeloader
Trojan/win.msilzilla.c5129545
Trojan/win.generic.c5198415
Malware/mdp.inject.m3037
Malware/mdp.autorun.m1037
Malware/mdp.inject.m1252
IOCs:
File: 4
Url: 4
Hash: 6
Softs:
windows explorer
Algorithms:
zip
ASEC BLOG
GitHub에 솔루션파일(*.sln) 위장하여 유포되는 RAT 툴 - ASEC BLOG
ASEC 분석팀에서는 최근 GitHub 에서 솔루션파일(*.sln)을 위장하여 RAT 툴이 유포 중인 것을 확인하였다. [그림1] 은 악성코드 유포자가 GitHub에 “Jpg Png Exploit Downloader Fud Cryter Malware Builder Cve 2022” 제목으로 소스코드를 공유한 내용이다. 프로그램의 구성파일이 정상적으로 보이지만 이 중 솔루션파일(*.sln)은 RAT 툴이다. 이와 같은 방법으로 악성코드 유포자는 RAT 툴을…
#ParsedReport
18-08-2022
Grandoreiro Banking Trojan with New TTPs Targeting Various Industry Verticals
https://www.zscaler.com/blogs/security-research/grandoreiro-banking-trojan-new-ttps-targeting-various-industry-verticals
Threats:
Grandoreiro
Latentbot
Beacon
Industry:
Logistic, Government, Financial, Chemical
Geo:
America, Brazil, Spain, Spanish, Mexico
TTPs:
Tactics: 1
Technics: 0
IOCs:
Url: 6
File: 19
Path: 1
Domain: 5
Registry: 1
Hash: 10
Softs:
electrum, coinomi
Algorithms:
xor, zip
Functions:
CreateMutexA, IsDebuggerPresent, URLDownloadToFile, GetUserNameW, Process32First, GetComputerNameW, Process32Next, GetWindowTextW, EnumWindows, CreateToolhelp32Snapshot, FindWindowW
Languages:
delphi
Platforms:
x86
Links:
18-08-2022
Grandoreiro Banking Trojan with New TTPs Targeting Various Industry Verticals
https://www.zscaler.com/blogs/security-research/grandoreiro-banking-trojan-new-ttps-targeting-various-industry-verticals
Threats:
Grandoreiro
Latentbot
Beacon
Industry:
Logistic, Government, Financial, Chemical
Geo:
America, Brazil, Spain, Spanish, Mexico
TTPs:
Tactics: 1
Technics: 0
IOCs:
Url: 6
File: 19
Path: 1
Domain: 5
Registry: 1
Hash: 10
Softs:
electrum, coinomi
Algorithms:
xor, zip
Functions:
CreateMutexA, IsDebuggerPresent, URLDownloadToFile, GetUserNameW, Process32First, GetComputerNameW, Process32Next, GetWindowTextW, EnumWindows, CreateToolhelp32Snapshot, FindWindowW
Languages:
delphi
Platforms:
x86
Links:
https://github.com/SpiderLabs/Grandoreiro-decryptor/blob/main/grandoreiro\_string\_decryptor.pyZscaler
Grandoreiro Banking Trojan with New TTPs Targeting Various Industry Verticals | Zscaler
Grandoreiro, one of the top banking trojans in Latin America, is using new tactics in a malware campaign that impersonates government officials.
#ParsedReport
19-08-2022
Beating Black Basta Ransomware
https://www.deepinstinct.com/blog/black-basta-ransomware-threat-emergence
Threats:
Blackbasta
Qakbot
Conti
Cobalt_strike
Adfind_tool
Industry:
Financial
IOCs:
File: 10
Path: 3
Hash: 8
Registry: 1
Softs:
esxi
Algorithms:
chacha20
19-08-2022
Beating Black Basta Ransomware
https://www.deepinstinct.com/blog/black-basta-ransomware-threat-emergence
Threats:
Blackbasta
Qakbot
Conti
Cobalt_strike
Adfind_tool
Industry:
Financial
IOCs:
File: 10
Path: 3
Hash: 8
Registry: 1
Softs:
esxi
Algorithms:
chacha20
Deep Instinct
Preventing Black Basta Ransomware in 2022 | Deep Instinct
Prevent Black Basta Ransomware with Deep Instinct. Stop more threats, faster, including new and unknown ransomware and zero-day attacks.
#ParsedReport
19-08-2022
EvilCoder Project Selling Multiple Dangerous Tools Online
https://blog.cyble.com/2022/08/19/evilcoder-project-selling-multiple-dangerous-tools-online
Threats:
Evilcoder_project
Xworm_rat
Xbinder
Uac_bypass_technique
Process_injection_technique
Geo:
Dubai, India, Australia, Singapore, Georgia
TTPs:
Tactics: 6
Technics: 7
IOCs:
File: 1
Domain: 1
Hash: 27
Softs:
virtualbox, android, .net framework
Algorithms:
aes
Functions:
CheckRemoteDebuggerPresent, Read, SetWorkPath
19-08-2022
EvilCoder Project Selling Multiple Dangerous Tools Online
https://blog.cyble.com/2022/08/19/evilcoder-project-selling-multiple-dangerous-tools-online
Threats:
Evilcoder_project
Xworm_rat
Xbinder
Uac_bypass_technique
Process_injection_technique
Geo:
Dubai, India, Australia, Singapore, Georgia
TTPs:
Tactics: 6
Technics: 7
IOCs:
File: 1
Domain: 1
Hash: 27
Softs:
virtualbox, android, .net framework
Algorithms:
aes
Functions:
CheckRemoteDebuggerPresent, Read, SetWorkPath
Cyble
EvilCoder Project Selling Multiple Dangerous Tools Online
Cyble Analyzes EvilCoder, a new project spotted selling multiple dangerous tools online capable of Ransomware and HNVC attacks.
#ParsedReport
19-08-2022
. Malicious Word documents targeting specific people related to North Korea
https://asec.ahnlab.com/ko/37879
Actors/Campaigns:
Kimsuky
Geo:
Korea, Korean
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 15
Url: 3
Registry: 7
Path: 1
Hash: 1
Languages:
php
Platforms:
x86
19-08-2022
. Malicious Word documents targeting specific people related to North Korea
https://asec.ahnlab.com/ko/37879
Actors/Campaigns:
Kimsuky
Geo:
Korea, Korean
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 15
Url: 3
Registry: 7
Path: 1
Hash: 1
Languages:
php
Platforms:
x86
ASEC BLOG
대북 관련 특정인을 타겟으로 하는 악성 워드 문서 - ASEC BLOG
ASEC 분석팀은 안보 및 대북 관련 특정인을 타겟으로 하는 악성 워드 문서가 지속적으로 유포되고 있음을 확인하였다. 유포가 확인된 워드 문서의 파일명에는 대북 관련 인물의 이름이 포함된 경우가 다수 존재하여 해당 분야를 타겟으로 공격이 이루어지는 것으로 추정된다. 최근 확인된 워드 문서의 파일명은 다음과 같다. 날짜 파일명 7/18 (작성양식)2022년 광복절 경축사 전문가 사전 의견수렴.doc 7/20 0511_통일부 *** 부장 회의록.doc 8/1…