CTT Report Hub
3.42K subscribers
9.85K photos
6 videos
67 files
13.5K links
Threat Intelligence Report Hub
Download Telegram
#ParsedReport
17-08-2022

DarkTortilla Malware Analysis

https://www.secureworks.com/research/darktortilla-malware-analysis

Threats:
Darktortilla
Agent_tesla
Asyncrat_rat
Nanocore_rat
Redline_stealer
Cobalt_strike
Metasploit_tool
Process_injection_technique
Confuserex_tool
Junk_code_technique

Industry:
Logistic

Geo:
German, Italian, Romanian, Spanish

TTPs:
Tactics: 2
Technics: 0

IOCs:
File: 35
Hash: 56

Softs:
virtualbox, .net framework, windows shell, winlogon, windows registry, discord, hyper-v

Algorithms:
aes

Links:
https://github.com/malwares/Crypter/tree/master/%5BC%23%5D%20The%20RATs%20Crew%20Crypter
https://github.com/malwares/Crypter/blob/master/%5BC%23%5D%20The%20RATs%20Crew%20Crypter/Form1.cs#L161-L163
https://github.com/dnSpyEx/dnSpy
#ParsedReport
17-08-2022

THREAT ANALYSIS REPORT: Bumblebee Loader The High Road to Enterprise Domain Control

https://www.cybereason.com/blog/threat-analysis-report-bumblebee-loader-the-high-road-to-enterprise-domain-control

Threats:
Bumblebee
Bazarbackdoor
Trickbot
Icedid
Cobalt_strike
Meterpreter_tool
Zerologon_vuln
Beacon
Adfind_tool
Lolbin
Uac_bypass_technique
Process_injection_technique
Anydesk_tool

Industry:
Government

CVEs:
CVE-2020-1472 [Vulners]
Vulners: Score: 9.3, CVSS: 3.8,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2)
- microsoft windows server 2012 (-, r2)
- microsoft windows server 2016 (-, 1903, 1909, 2004)
- microsoft windows server 2019 (-)
- fedoraproject fedora (31, 32, 33)
have more...

TTPs:
Tactics: 10
Technics: 24

IOCs:
File: 19
Path: 5
Domain: 1
IP: 1
Hash: 1

Softs:
winlogon, active directory, microsoft exchange, local security authority, curl, vssadmin

Links:
https://github.com/leitosama/SharpZeroLogon
#ParsedReport
17-08-2022

An In-Depth Look at Quantum Ransomware

https://explore.avertium.com/resource/an-in-depth-look-at-quantum-ransomware

Actors/Campaigns:
Xinglocker
Jormungandr

Threats:
Quantum_locker
Astrolocker
Mountlocker
Conti
Bazarbackdoor
Ryuk
Zeon
Icedid
Cobalt_strike
Adfind_tool
Metasploit_tool
Beacon

Industry:
Healthcare, Financial

Geo:
India

IOCs:
File: 10
Domain: 3
IP: 1
Hash: 8

Softs:
psexec, active directory
#ParsedReport
17-08-2022

AsyncRAT C2 Framework: Overview, Technical Analysis & Detection

https://blog.qualys.com/vulnerabilities-threat-research/2022/08/16/asyncrat-c2-framework-overview-technical-analysis-and-detection

Actors/Campaigns:
Layover
Ta2541

Threats:
Asyncrat_rat
Follina_vuln
Antidebugging_technique
Limelogger_tool

Industry:
Transport, Aerospace, Healthcare, Government

Geo:
Thailand, Asia, America, Australia

TTPs:
Tactics: 3
Technics: 9

IOCs:
File: 4

Softs:
virtualbox

Algorithms:
pbkdf2, aes-256

Functions:
GetKeyState, GetModuleHandle, GetForegroundWindow, GetKeyboardLayout, SetThreadExecutionState, RtlSetProcessIsCritical

Links:
https://github.com/NYAN-x-CAT/AsyncRAT-C-Sharp
https://github.com/NYAN-x-CAT/LimeLogger/blob/master/LimeLogger/LimeLogger.cs
#ParsedReport
17-08-2022

Desorden Group The Thai Blitz

https://cyberint.com/blog/research/desorden-group-the-thai-blitz

Actors/Campaigns:
Thai_blitz (motivation: financially_motivated, cyber_criminal)
Desorden (motivation: financially_motivated, cyber_criminal)

Threats:
Chaos
Onyx
Yashma

Industry:
Retail, Healthcare, Logistic, Foodtech, Financial

Geo:
India, Asia, Thailand, Asian, Singapore, Malaysia, Spanish, Taiwan, Philippines

Softs:
telegram

Languages:
python
#ParsedReport
18-08-2022

Reservations Requested: TA558 Targets Hospitality and Travel

https://www.proofpoint.com/us/blog/threat-insight/reservations-requested-ta558-targets-hospitality-and-travel

Actors/Campaigns:
Ta558 (motivation: cyber_criminal, financially_motivated, information_theft)

Threats:
Loda_rat
Revenge_rat
Vjw0rm
Njrat_rat
Ozone
Asyncrat_rat
Tur
Houdini_rat
Bladabindi

Industry:
Transport, Financial, Healthcare

Geo:
Portuguese, Brazilian, Portugal, America, Brazil, Brasil, Spanish

CVEs:
CVE-2017-11882 [Vulners]
Vulners: Score: 9.3, CVSS: 4.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2013, 2010, 2016, 2007)

CVE-2017-8570 [Vulners]
Vulners: Score: 9.3, CVSS: 4.3,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2007, 2010, 2013, 2016, 2013)


IOCs:
File: 4
Hash: 5
Url: 5
Email: 2
Domain: 17
IP: 1

Softs:
microsoft office, microsoft word

Algorithms:
zip
#ParsedReport
18-08-2022

BianLian: New Ransomware variant on the rise

https://blog.cyble.com/2022/08/18/bianlian-new-ransomware-variant-on-the-rise

Threats:
Hydra

Industry:
Financial, Education, Healthcare

Geo:
Georgia, Dubai, Singapore, Australia, India

TTPs:
Tactics: 5
Technics: 11

IOCs:
Path: 2
File: 6
Hash: 2

Softs:
bootnxt

Algorithms:
aes

Functions:
FindFirstFileW, wine_get_version, GetProcAddress, CreateThread, FindNextFileW, MoveFileExW, GetDriveTypeW

Languages:
golang
#ParsedReport
18-08-2022

From Ramnit To Bumblebee (via NeverQuest): Similarities and Code Overlap Shed Light On Relationships Between Malware Developers

https://securityintelligence.com/posts/from-ramnit-to-bumblebee-via-neverquest

Actors/Campaigns:
Wizard_spider
Contileaks
Trickleaks
Exotic_lily
Ta579
Ta578
Ta554

Threats:
Ramnit
Bumblebee
Vawtrak
Camellia_loader
Trickbot
Karius
Conti
Bazarbackdoor
Cobalt_strike
Sliver_tool
Meterpreter_tool
Mountlocker
Icedid
Dyre
Zeus
Carberp
Gozi
Starslord
Hooker2
Process_injection_technique
Dll_injection_technique

Industry:
Financial

Geo:
Spain, Russian

CVEs:
CVE-2021-4044 [Vulners]
Vulners: Score: 5.0, CVSS: 1.7,
Vulners: Exploitation: Unknown
X-Force: Risk: 6.5
X-Force: Patch: Official fix
Soft:
- openssl (<1.0.2, 1.1.0, 3.0.0)
- netapp cloud backup (-)
- netapp e-series performance analyzer (-)
- netapp ontap select deploy administration utility (-)
- netapp snapcenter (-)
have more...

TTPs:
Tactics: 1
Technics: 0

IOCs:
File: 8
Path: 5
Hash: 44

Softs:
microsoft office, visual studio, mshtml engine, microsoft visual studio, microsoft edge, internet explorer, google chrome

Algorithms:
xor, base64, rc4

Functions:
ZwMapViewOfFile, Stub, ZwCreateSection, ZwMapViewOfSection, OpenSSL, API, LdrLoadDll, NtQueueApcThread, GetSystemInfo, ZwOpenSection, ZwOpenFile

Languages:
javascript

Links:
https://github.com/LordNoteworthy/al-khaser
https://github.com/t3rabyt3-zz/Gozi/blob/master/AcDll/activdll.c#L824
#ParsedReport
18-08-2022

Cookie stealing: the new perimeter bypass

https://news.sophos.com/en-us/2022/08/18/cookie-stealing-the-new-perimeter-bypass

Actors/Campaigns:
Lapsus

Threats:
Credential_stealing_technique
Emotet
Raccoon_stealer
Redline_stealer
Meterpreter_tool
Cobalt_strike
Mimikatz
Metasploit_tool
Phoenix_keylogger
Quasar_rat
Impacket_tool

Industry:
E-commerce, Financial

Geo:
Turkish

IOCs:
File: 6

Softs:
slack, google chrome, chrome, discord, microsoft visual studio, windows smb, mozilla firefox, microsoft edge

Algorithms:
zip

Languages:
autoit, perl, delphi

Links:
https://github.com/malwares/QuasarRAT
https://github.com/SecureAuthCorp/impacket
#ParsedReport
18-08-2022

Ransomware Roundup: Gwisin, Kriptor, Cuba, and More

https://www.fortinet.com/blog/threat-research/ransomware-roundup-gwisin-kriptor-cuba-and-more

Threats:
Gwisin
Kriptor
Cuba
Darkylock
Babuk
Lockbit
W32/filecoderprot.f183!tr.ransom
W32/coinminer.nbh!tr
W32/stealer.3389!tr
Filecoder
Kryptik_trojan
W32/injector.eqgy!tr
Stop
Wannacry

Industry:
Financial

Geo:
Korea

IOCs:
File: 1
#ParsedReport
18-08-2022

Kasablanka. Kasablanka (Casablanca) organization against the political groups and public welfare organizations in the Middle East

https://mp.weixin.qq.com/s/mstwBMkS0G3Et4GOji2mwA

Threats:
Spynote_rat
Loda_rat
Nanocore_rat
Njrat_rat
Upx_tool

Industry:
Financial, Government, Healthcare

Geo:
Bangladesh, Yemen, India

IOCs:
File: 7
Hash: 17
IP: 1

Softs:
android

Languages:
autoit
#ParsedReport
18-08-2022

Grandoreiro Banking Trojan with New TTPs Targeting Various Industry Verticals

https://www.zscaler.com/blogs/security-research/grandoreiro-banking-trojan-new-ttps-targeting-various-industry-verticals

Threats:
Grandoreiro
Latentbot
Beacon

Industry:
Logistic, Government, Financial, Chemical

Geo:
America, Brazil, Spain, Spanish, Mexico

TTPs:
Tactics: 1
Technics: 0

IOCs:
Url: 6
File: 19
Path: 1
Domain: 5
Registry: 1
Hash: 10

Softs:
electrum, coinomi

Algorithms:
xor, zip

Functions:
CreateMutexA, IsDebuggerPresent, URLDownloadToFile, GetUserNameW, Process32First, GetComputerNameW, Process32Next, GetWindowTextW, EnumWindows, CreateToolhelp32Snapshot, FindWindowW

Languages:
delphi

Platforms:
x86

Links:
https://github.com/SpiderLabs/Grandoreiro-decryptor/blob/main/grandoreiro\_string\_decryptor.py
#ParsedReport
19-08-2022

EvilCoder Project Selling Multiple Dangerous Tools Online

https://blog.cyble.com/2022/08/19/evilcoder-project-selling-multiple-dangerous-tools-online

Threats:
Evilcoder_project
Xworm_rat
Xbinder
Uac_bypass_technique
Process_injection_technique

Geo:
Dubai, India, Australia, Singapore, Georgia

TTPs:
Tactics: 6
Technics: 7

IOCs:
File: 1
Domain: 1
Hash: 27

Softs:
virtualbox, android, .net framework

Algorithms:
aes

Functions:
CheckRemoteDebuggerPresent, Read, SetWorkPath
#ParsedReport
19-08-2022

You Cant Audit Me: APT29 Continues Targeting Microsoft 365

https://www.mandiant.com/resources/apt29-continues-targeting-microsoft

Actors/Campaigns:
Duke (motivation: cyber_espionage)

Industry:
Government

Geo:
Russian

Softs:
active directory, azure ad

Links:
https://github.com/mandiant/Mandiant-Azure-AD-Investigator
#ParsedReport
19-08-2022

Honker Union: Has the grandfather of Chinese Hacktivism returned?

https://www.digitalshadows.com/blog-and-research/honker-union-has-the-grandfather-of-chinese-hacktivism-returned

Actors/Campaigns:
Honker_union (motivation: hacktivism)
Green_army (motivation: hacktivism)

Industry:
Education, Government

Geo:
Japan, Chinese, Indonesia, Taiwan, China, Japanese

Softs:
tiktok, weibo, wechat

Platforms:
intel
#ParsedReport
19-08-2022

Suspected Iranian Actor Targeting Israeli Shipping, Healthcare, Government and Energy Sectors

https://www.mandiant.com/resources/blog/suspected-iranian-actor-targeting-israeli-shipping

Actors/Campaigns:
Unc3890 (motivation: cyber_espionage)
Fox_kitten
Cleaver

Threats:
Watering_hole_technique
Sugarush
Sugardump
Metasploit_tool
Northstar_tool
Credential_harvesting_technique
Unicorn

Industry:
Maritime, Energy, Transport, Aerospace, Government, Healthcare

Geo:
Iran, Iranian, Israeli, Israel

IOCs:
Domain: 9
Url: 1
Hash: 1

Softs:
instagram

Algorithms:
zip