#ParsedReport
18-08-2022
From Ramnit To Bumblebee (via NeverQuest): Similarities and Code Overlap Shed Light On Relationships Between Malware Developers
https://securityintelligence.com/posts/from-ramnit-to-bumblebee-via-neverquest
Actors/Campaigns:
Wizard_spider
Contileaks
Trickleaks
Exotic_lily
Ta579
Ta578
Ta554
Threats:
Ramnit
Bumblebee
Vawtrak
Camellia_loader
Trickbot
Karius
Conti
Bazarbackdoor
Cobalt_strike
Sliver_tool
Meterpreter_tool
Mountlocker
Icedid
Dyre
Zeus
Carberp
Gozi
Starslord
Hooker2
Process_injection_technique
Dll_injection_technique
Industry:
Financial
Geo:
Spain, Russian
CVEs:
CVE-2021-4044 [Vulners]
Vulners: Score: 5.0, CVSS: 1.7,
Vulners: Exploitation: Unknown
X-Force: Risk: 6.5
X-Force: Patch: Official fix
Soft:
- openssl (<1.0.2, 1.1.0, 3.0.0)
- netapp cloud backup (-)
- netapp e-series performance analyzer (-)
- netapp ontap select deploy administration utility (-)
- netapp snapcenter (-)
have more...
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 8
Path: 5
Hash: 44
Softs:
microsoft office, visual studio, mshtml engine, microsoft visual studio, microsoft edge, internet explorer, google chrome
Algorithms:
xor, base64, rc4
Functions:
ZwMapViewOfFile, Stub, ZwCreateSection, ZwMapViewOfSection, OpenSSL, API, LdrLoadDll, NtQueueApcThread, GetSystemInfo, ZwOpenSection, ZwOpenFile
Languages:
javascript
Links:
18-08-2022
From Ramnit To Bumblebee (via NeverQuest): Similarities and Code Overlap Shed Light On Relationships Between Malware Developers
https://securityintelligence.com/posts/from-ramnit-to-bumblebee-via-neverquest
Actors/Campaigns:
Wizard_spider
Contileaks
Trickleaks
Exotic_lily
Ta579
Ta578
Ta554
Threats:
Ramnit
Bumblebee
Vawtrak
Camellia_loader
Trickbot
Karius
Conti
Bazarbackdoor
Cobalt_strike
Sliver_tool
Meterpreter_tool
Mountlocker
Icedid
Dyre
Zeus
Carberp
Gozi
Starslord
Hooker2
Process_injection_technique
Dll_injection_technique
Industry:
Financial
Geo:
Spain, Russian
CVEs:
CVE-2021-4044 [Vulners]
Vulners: Score: 5.0, CVSS: 1.7,
Vulners: Exploitation: Unknown
X-Force: Risk: 6.5
X-Force: Patch: Official fix
Soft:
- openssl (<1.0.2, 1.1.0, 3.0.0)
- netapp cloud backup (-)
- netapp e-series performance analyzer (-)
- netapp ontap select deploy administration utility (-)
- netapp snapcenter (-)
have more...
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 8
Path: 5
Hash: 44
Softs:
microsoft office, visual studio, mshtml engine, microsoft visual studio, microsoft edge, internet explorer, google chrome
Algorithms:
xor, base64, rc4
Functions:
ZwMapViewOfFile, Stub, ZwCreateSection, ZwMapViewOfSection, OpenSSL, API, LdrLoadDll, NtQueueApcThread, GetSystemInfo, ZwOpenSection, ZwOpenFile
Languages:
javascript
Links:
https://github.com/LordNoteworthy/al-khaserhttps://github.com/t3rabyt3-zz/Gozi/blob/master/AcDll/activdll.c#L824Security Intelligence
From Ramnit To Bumblebee (via NeverQuest): Similarities and Code Overlap Shed Light On Relationships Between Malware Developers
Take a deep dive into IBM Security X-Force's comparative analysis, which uncovered evidence that suggests Bumblebee malware was likely developed directly from source code associated with the Ramnit banking trojan.
#ParsedReport
18-08-2022
Cookie stealing: the new perimeter bypass
https://news.sophos.com/en-us/2022/08/18/cookie-stealing-the-new-perimeter-bypass
Actors/Campaigns:
Lapsus
Threats:
Credential_stealing_technique
Emotet
Raccoon_stealer
Redline_stealer
Meterpreter_tool
Cobalt_strike
Mimikatz
Metasploit_tool
Phoenix_keylogger
Quasar_rat
Impacket_tool
Industry:
E-commerce, Financial
Geo:
Turkish
IOCs:
File: 6
Softs:
slack, google chrome, chrome, discord, microsoft visual studio, windows smb, mozilla firefox, microsoft edge
Algorithms:
zip
Languages:
autoit, perl, delphi
Links:
18-08-2022
Cookie stealing: the new perimeter bypass
https://news.sophos.com/en-us/2022/08/18/cookie-stealing-the-new-perimeter-bypass
Actors/Campaigns:
Lapsus
Threats:
Credential_stealing_technique
Emotet
Raccoon_stealer
Redline_stealer
Meterpreter_tool
Cobalt_strike
Mimikatz
Metasploit_tool
Phoenix_keylogger
Quasar_rat
Impacket_tool
Industry:
E-commerce, Financial
Geo:
Turkish
IOCs:
File: 6
Softs:
slack, google chrome, chrome, discord, microsoft visual studio, windows smb, mozilla firefox, microsoft edge
Algorithms:
zip
Languages:
autoit, perl, delphi
Links:
https://github.com/malwares/QuasarRAThttps://github.com/SecureAuthCorp/impacketSophos News
Cookie stealing: the new perimeter bypass
As organizations move to cloud services and multifactor authentication, cookies tied to identity and authentication give attackers a new path to compromise.
#ParsedReport
18-08-2022
Ransomware Roundup: Gwisin, Kriptor, Cuba, and More
https://www.fortinet.com/blog/threat-research/ransomware-roundup-gwisin-kriptor-cuba-and-more
Threats:
Gwisin
Kriptor
Cuba
Darkylock
Babuk
Lockbit
W32/filecoderprot.f183!tr.ransom
W32/coinminer.nbh!tr
W32/stealer.3389!tr
Filecoder
Kryptik_trojan
W32/injector.eqgy!tr
Stop
Wannacry
Industry:
Financial
Geo:
Korea
IOCs:
File: 1
18-08-2022
Ransomware Roundup: Gwisin, Kriptor, Cuba, and More
https://www.fortinet.com/blog/threat-research/ransomware-roundup-gwisin-kriptor-cuba-and-more
Threats:
Gwisin
Kriptor
Cuba
Darkylock
Babuk
Lockbit
W32/filecoderprot.f183!tr.ransom
W32/coinminer.nbh!tr
W32/stealer.3389!tr
Filecoder
Kryptik_trojan
W32/injector.eqgy!tr
Stop
Wannacry
Industry:
Financial
Geo:
Korea
IOCs:
File: 1
Fortinet Blog
Ransomware Roundup: Gwisin, Kriptor, Cuba, and More | FortiGuard Labs
The latest edition of the Ransomware Roundup from FortiGuard Labs covers the Gwisin, Kriptor, and Cuba ransomware. Read to learn more about protections against these variants.…
#ParsedReport
18-08-2022
Kasablanka. Kasablanka (Casablanca) organization against the political groups and public welfare organizations in the Middle East
https://mp.weixin.qq.com/s/mstwBMkS0G3Et4GOji2mwA
Threats:
Spynote_rat
Loda_rat
Nanocore_rat
Njrat_rat
Upx_tool
Industry:
Financial, Government, Healthcare
Geo:
Bangladesh, Yemen, India
IOCs:
File: 7
Hash: 17
IP: 1
Softs:
android
Languages:
autoit
18-08-2022
Kasablanka. Kasablanka (Casablanca) organization against the political groups and public welfare organizations in the Middle East
https://mp.weixin.qq.com/s/mstwBMkS0G3Et4GOji2mwA
Threats:
Spynote_rat
Loda_rat
Nanocore_rat
Njrat_rat
Upx_tool
Industry:
Financial, Government, Healthcare
Geo:
Bangladesh, Yemen, India
IOCs:
File: 7
Hash: 17
IP: 1
Softs:
android
Languages:
autoit
Weixin Official Accounts Platform
Kasablanka(卡萨布兰卡)组织针对中东地区政治团体和公益组织的攻击行动
近期,360高级威胁研究院在日常情报挖掘中发现并捕获到了Kasablanka组织针对Windows和Android两个平台的攻击活动,经分析后推测该组织不简简单单是为了经济利益,其动机似乎更倾向于信息收集和间谍活动
#ParsedReport
18-08-2022
GitHub (*.sln) RAT. RAT tools distributed by disguised as a solution file (*.sln) in github
https://asec.ahnlab.com/ko/37764
Threats:
Asyncrat_rat
Trojan/win.leonem.c5218555
Trojan/win.agent.c4526491
Vbinder
Smokeloader
Trojan/win.msilzilla.c5129545
Trojan/win.generic.c5198415
Malware/mdp.inject.m3037
Malware/mdp.autorun.m1037
Malware/mdp.inject.m1252
IOCs:
File: 4
Url: 4
Hash: 6
Softs:
windows explorer
Algorithms:
zip
18-08-2022
GitHub (*.sln) RAT. RAT tools distributed by disguised as a solution file (*.sln) in github
https://asec.ahnlab.com/ko/37764
Threats:
Asyncrat_rat
Trojan/win.leonem.c5218555
Trojan/win.agent.c4526491
Vbinder
Smokeloader
Trojan/win.msilzilla.c5129545
Trojan/win.generic.c5198415
Malware/mdp.inject.m3037
Malware/mdp.autorun.m1037
Malware/mdp.inject.m1252
IOCs:
File: 4
Url: 4
Hash: 6
Softs:
windows explorer
Algorithms:
zip
ASEC BLOG
GitHub에 솔루션파일(*.sln) 위장하여 유포되는 RAT 툴 - ASEC BLOG
ASEC 분석팀에서는 최근 GitHub 에서 솔루션파일(*.sln)을 위장하여 RAT 툴이 유포 중인 것을 확인하였다. [그림1] 은 악성코드 유포자가 GitHub에 “Jpg Png Exploit Downloader Fud Cryter Malware Builder Cve 2022” 제목으로 소스코드를 공유한 내용이다. 프로그램의 구성파일이 정상적으로 보이지만 이 중 솔루션파일(*.sln)은 RAT 툴이다. 이와 같은 방법으로 악성코드 유포자는 RAT 툴을…
#ParsedReport
18-08-2022
Grandoreiro Banking Trojan with New TTPs Targeting Various Industry Verticals
https://www.zscaler.com/blogs/security-research/grandoreiro-banking-trojan-new-ttps-targeting-various-industry-verticals
Threats:
Grandoreiro
Latentbot
Beacon
Industry:
Logistic, Government, Financial, Chemical
Geo:
America, Brazil, Spain, Spanish, Mexico
TTPs:
Tactics: 1
Technics: 0
IOCs:
Url: 6
File: 19
Path: 1
Domain: 5
Registry: 1
Hash: 10
Softs:
electrum, coinomi
Algorithms:
xor, zip
Functions:
CreateMutexA, IsDebuggerPresent, URLDownloadToFile, GetUserNameW, Process32First, GetComputerNameW, Process32Next, GetWindowTextW, EnumWindows, CreateToolhelp32Snapshot, FindWindowW
Languages:
delphi
Platforms:
x86
Links:
18-08-2022
Grandoreiro Banking Trojan with New TTPs Targeting Various Industry Verticals
https://www.zscaler.com/blogs/security-research/grandoreiro-banking-trojan-new-ttps-targeting-various-industry-verticals
Threats:
Grandoreiro
Latentbot
Beacon
Industry:
Logistic, Government, Financial, Chemical
Geo:
America, Brazil, Spain, Spanish, Mexico
TTPs:
Tactics: 1
Technics: 0
IOCs:
Url: 6
File: 19
Path: 1
Domain: 5
Registry: 1
Hash: 10
Softs:
electrum, coinomi
Algorithms:
xor, zip
Functions:
CreateMutexA, IsDebuggerPresent, URLDownloadToFile, GetUserNameW, Process32First, GetComputerNameW, Process32Next, GetWindowTextW, EnumWindows, CreateToolhelp32Snapshot, FindWindowW
Languages:
delphi
Platforms:
x86
Links:
https://github.com/SpiderLabs/Grandoreiro-decryptor/blob/main/grandoreiro\_string\_decryptor.pyZscaler
Grandoreiro Banking Trojan with New TTPs Targeting Various Industry Verticals | Zscaler
Grandoreiro, one of the top banking trojans in Latin America, is using new tactics in a malware campaign that impersonates government officials.
#ParsedReport
19-08-2022
Beating Black Basta Ransomware
https://www.deepinstinct.com/blog/black-basta-ransomware-threat-emergence
Threats:
Blackbasta
Qakbot
Conti
Cobalt_strike
Adfind_tool
Industry:
Financial
IOCs:
File: 10
Path: 3
Hash: 8
Registry: 1
Softs:
esxi
Algorithms:
chacha20
19-08-2022
Beating Black Basta Ransomware
https://www.deepinstinct.com/blog/black-basta-ransomware-threat-emergence
Threats:
Blackbasta
Qakbot
Conti
Cobalt_strike
Adfind_tool
Industry:
Financial
IOCs:
File: 10
Path: 3
Hash: 8
Registry: 1
Softs:
esxi
Algorithms:
chacha20
Deep Instinct
Preventing Black Basta Ransomware in 2022 | Deep Instinct
Prevent Black Basta Ransomware with Deep Instinct. Stop more threats, faster, including new and unknown ransomware and zero-day attacks.
#ParsedReport
19-08-2022
EvilCoder Project Selling Multiple Dangerous Tools Online
https://blog.cyble.com/2022/08/19/evilcoder-project-selling-multiple-dangerous-tools-online
Threats:
Evilcoder_project
Xworm_rat
Xbinder
Uac_bypass_technique
Process_injection_technique
Geo:
Dubai, India, Australia, Singapore, Georgia
TTPs:
Tactics: 6
Technics: 7
IOCs:
File: 1
Domain: 1
Hash: 27
Softs:
virtualbox, android, .net framework
Algorithms:
aes
Functions:
CheckRemoteDebuggerPresent, Read, SetWorkPath
19-08-2022
EvilCoder Project Selling Multiple Dangerous Tools Online
https://blog.cyble.com/2022/08/19/evilcoder-project-selling-multiple-dangerous-tools-online
Threats:
Evilcoder_project
Xworm_rat
Xbinder
Uac_bypass_technique
Process_injection_technique
Geo:
Dubai, India, Australia, Singapore, Georgia
TTPs:
Tactics: 6
Technics: 7
IOCs:
File: 1
Domain: 1
Hash: 27
Softs:
virtualbox, android, .net framework
Algorithms:
aes
Functions:
CheckRemoteDebuggerPresent, Read, SetWorkPath
Cyble
EvilCoder Project Selling Multiple Dangerous Tools Online
Cyble Analyzes EvilCoder, a new project spotted selling multiple dangerous tools online capable of Ransomware and HNVC attacks.
#ParsedReport
19-08-2022
. Malicious Word documents targeting specific people related to North Korea
https://asec.ahnlab.com/ko/37879
Actors/Campaigns:
Kimsuky
Geo:
Korea, Korean
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 15
Url: 3
Registry: 7
Path: 1
Hash: 1
Languages:
php
Platforms:
x86
19-08-2022
. Malicious Word documents targeting specific people related to North Korea
https://asec.ahnlab.com/ko/37879
Actors/Campaigns:
Kimsuky
Geo:
Korea, Korean
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 15
Url: 3
Registry: 7
Path: 1
Hash: 1
Languages:
php
Platforms:
x86
ASEC BLOG
대북 관련 특정인을 타겟으로 하는 악성 워드 문서 - ASEC BLOG
ASEC 분석팀은 안보 및 대북 관련 특정인을 타겟으로 하는 악성 워드 문서가 지속적으로 유포되고 있음을 확인하였다. 유포가 확인된 워드 문서의 파일명에는 대북 관련 인물의 이름이 포함된 경우가 다수 존재하여 해당 분야를 타겟으로 공격이 이루어지는 것으로 추정된다. 최근 확인된 워드 문서의 파일명은 다음과 같다. 날짜 파일명 7/18 (작성양식)2022년 광복절 경축사 전문가 사전 의견수렴.doc 7/20 0511_통일부 *** 부장 회의록.doc 8/1…
#ParsedReport
19-08-2022
You Cant Audit Me: APT29 Continues Targeting Microsoft 365
https://www.mandiant.com/resources/apt29-continues-targeting-microsoft
Actors/Campaigns:
Duke (motivation: cyber_espionage)
Industry:
Government
Geo:
Russian
Softs:
active directory, azure ad
Links:
19-08-2022
You Cant Audit Me: APT29 Continues Targeting Microsoft 365
https://www.mandiant.com/resources/apt29-continues-targeting-microsoft
Actors/Campaigns:
Duke (motivation: cyber_espionage)
Industry:
Government
Geo:
Russian
Softs:
active directory, azure ad
Links:
https://github.com/mandiant/Mandiant-Azure-AD-InvestigatorMandiant
You Can’t Audit Me: APT29 Continues Targeting Microsoft 365 | Mandiant
#ParsedReport
19-08-2022
Honker Union: Has the grandfather of Chinese Hacktivism returned?
https://www.digitalshadows.com/blog-and-research/honker-union-has-the-grandfather-of-chinese-hacktivism-returned
Actors/Campaigns:
Honker_union (motivation: hacktivism)
Green_army (motivation: hacktivism)
Industry:
Education, Government
Geo:
Japan, Chinese, Indonesia, Taiwan, China, Japanese
Softs:
tiktok, weibo, wechat
Platforms:
intel
19-08-2022
Honker Union: Has the grandfather of Chinese Hacktivism returned?
https://www.digitalshadows.com/blog-and-research/honker-union-has-the-grandfather-of-chinese-hacktivism-returned
Actors/Campaigns:
Honker_union (motivation: hacktivism)
Green_army (motivation: hacktivism)
Industry:
Education, Government
Geo:
Japan, Chinese, Indonesia, Taiwan, China, Japanese
Softs:
tiktok, weibo, wechat
Platforms:
intel
Digital Shadows
Honker Union: Has the grandfather of Chinese Hacktivism returned? | Digital Shadows
The Photon Research Team provides insights into Chinese hacktivism’s responses to the growing tensions between the People’s Republic of China (PRC) and Taiwan.
#ParsedReport
19-08-2022
Suspected Iranian Actor Targeting Israeli Shipping, Healthcare, Government and Energy Sectors
https://www.mandiant.com/resources/blog/suspected-iranian-actor-targeting-israeli-shipping
Actors/Campaigns:
Unc3890 (motivation: cyber_espionage)
Fox_kitten
Cleaver
Threats:
Watering_hole_technique
Sugarush
Sugardump
Metasploit_tool
Northstar_tool
Credential_harvesting_technique
Unicorn
Industry:
Maritime, Energy, Transport, Aerospace, Government, Healthcare
Geo:
Iran, Iranian, Israeli, Israel
IOCs:
Domain: 9
Url: 1
Hash: 1
Softs:
instagram
Algorithms:
zip
19-08-2022
Suspected Iranian Actor Targeting Israeli Shipping, Healthcare, Government and Energy Sectors
https://www.mandiant.com/resources/blog/suspected-iranian-actor-targeting-israeli-shipping
Actors/Campaigns:
Unc3890 (motivation: cyber_espionage)
Fox_kitten
Cleaver
Threats:
Watering_hole_technique
Sugarush
Sugardump
Metasploit_tool
Northstar_tool
Credential_harvesting_technique
Unicorn
Industry:
Maritime, Energy, Transport, Aerospace, Government, Healthcare
Geo:
Iran, Iranian, Israeli, Israel
IOCs:
Domain: 9
Url: 1
Hash: 1
Softs:
Algorithms:
zip
Mandiant
UNC3890 | Suspected Iranian Threat Actor Targets Israel
This blog post details the activity of UNC3890, including their proprietary malware, TTPs we have not previously seen deployed by Iran, and the tools they use.
#ParsedReport
19-08-2022
Back in Black: Unlocking a LockBit 3.0 Ransomware Attack. Summary
https://research.nccgroup.com/2022/08/19/back-in-black-unlocking-a-lockbit-3-0-ransomware-attack
Threats:
Lockbit
Socgholish_loader
Cobalt_strike
Beacon
Bloodhound_tool
Seatbelt_tool
Conti
Megasync_tool
TTPs:
Tactics: 9
Technics: 15
IOCs:
Path: 12
File: 5
Email: 1
Domain: 1
IP: 1
Hash: 1
Softs:
psexec, windows defender
Algorithms:
zip
Links:
19-08-2022
Back in Black: Unlocking a LockBit 3.0 Ransomware Attack. Summary
https://research.nccgroup.com/2022/08/19/back-in-black-unlocking-a-lockbit-3-0-ransomware-attack
Threats:
Lockbit
Socgholish_loader
Cobalt_strike
Beacon
Bloodhound_tool
Seatbelt_tool
Conti
Megasync_tool
TTPs:
Tactics: 9
Technics: 15
IOCs:
Path: 12
File: 5
Email: 1
Domain: 1
IP: 1
Hash: 1
Softs:
psexec, windows defender
Algorithms:
zip
Links:
https://github.com/GhostPack/Seatbelt#ParsedReport
19-08-2022
Originalus tekstas
http://www.hackdig.com/08/hack-751533.htm
Actors/Campaigns:
Murenshark
Threats:
Shark
Cobalt_strike
Industry:
Education
Geo:
Turkey, China, Cyprus, Turkish
CVEs:
CVE-2022-26138 [Vulners]
Vulners: Score: Unknown, CVSS: 4.0,
Vulners: Exploitation: True
X-Force: Risk: 8.6
X-Force: Patch: Official fix
Soft:
- atlassian questions for confluence (3.0.2, 2.7.35, 2.7.34)
CVE-2022-34918 [Vulners]
Vulners: Score: 7.2, CVSS: 4.8,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.4
X-Force: Patch: Official fix
Soft:
- linux linux kernel (le5.18.9)
IOCs:
File: 5
Softs:
android, confluence
19-08-2022
Originalus tekstas
http://www.hackdig.com/08/hack-751533.htm
Actors/Campaigns:
Murenshark
Threats:
Shark
Cobalt_strike
Industry:
Education
Geo:
Turkey, China, Cyprus, Turkish
CVEs:
CVE-2022-26138 [Vulners]
Vulners: Score: Unknown, CVSS: 4.0,
Vulners: Exploitation: True
X-Force: Risk: 8.6
X-Force: Patch: Official fix
Soft:
- atlassian questions for confluence (3.0.2, 2.7.35, 2.7.34)
CVE-2022-34918 [Vulners]
Vulners: Score: 7.2, CVSS: 4.8,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.4
X-Force: Patch: Official fix
Soft:
- linux linux kernel (le5.18.9)
IOCs:
File: 5
Softs:
android, confluence
Hackdig
新APT组织穆伦鲨(MurenShark) 调查报告:袭向土耳其海军的鱼雷_黑客技术
阅读:46一、概述2022年第二季度,绿盟科技伏影实验室监测到了一系列针对土耳其的网络攻击活动。经过分析,研究人员确认本轮攻击活动来自一个由伏影实验室于21年4月确认的新型威胁实体Actor210426。伏影实验室通过行为模式、攻击手法、攻击工具、攻击目标等线索,对该威胁实体进行了深入调查,确认了其独立性与高级威胁性质。基于该威胁实体的活动区域与近期攻击目标(土耳其海军项目“MÜREN”),伏影实验室将其正式命名为穆伦鲨(MurenShark),对应绿盟科技高级威胁组织标识为APT-N-04。已监测活动…
#ParsedReport
19-08-2022
THREAT ALERT: Inside the Redeemer 2.0 Ransomware
https://www.cybereason.com/blog/threat-alert-inside-the-redeemer-2.0-ransomware
Threats:
Redeemer
Industry:
Government
IOCs:
File: 2
19-08-2022
THREAT ALERT: Inside the Redeemer 2.0 Ransomware
https://www.cybereason.com/blog/threat-alert-inside-the-redeemer-2.0-ransomware
Threats:
Redeemer
Industry:
Government
IOCs:
File: 2
Cybereason
THREAT ALERT: Inside the Redeemer 2.0 Ransomware
A new and improved Redeemer 2.0 ransomware version was released on an underground forum and is described by the developers as a “C++ no dependency ransomware with no privacy intrusions” targeting the Windows OS with support for Windows 11 systems...
#ParsedReport
19-08-2022
Pulling together the pieces to build the puzzle
https://inquest.net/blog/2022/08/18/pulling-together-pieces-build-puzzle
Threats:
Gozi
Procmon_tool
Geo:
Italian
IOCs:
File: 7
Hash: 1
Registry: 1
Algorithms:
7zip , zip
19-08-2022
Pulling together the pieces to build the puzzle
https://inquest.net/blog/2022/08/18/pulling-together-pieces-build-puzzle
Threats:
Gozi
Procmon_tool
Geo:
Italian
IOCs:
File: 7
Hash: 1
Registry: 1
Algorithms:
7zip , zip
inquest.net
Pulling together the pieces to build the puzzle
Follow along through the dissection and analysis of an oddly obfuscated maldoc that ultimately delivers the well-known GOZI ISFB banking trojan.
#technique
https://www.malwarebytes.com/blog/news/2022/08/spying-on-the-spies-see-what-javascript-commands-get-injected-by-an-in-app-browser
https://www.malwarebytes.com/blog/news/2022/08/spying-on-the-spies-see-what-javascript-commands-get-injected-by-an-in-app-browser
Malwarebytes
Spying on the spies. See what JavaScript commands get injected by in-app browsers
A developer and privacy expert created a platform that allows iOS users to see injected JavaScript in their in-app browsers
#ParsedReport
22-08-2022
LockBit Allegedly DDoSed After Leaking Entrusts Data
https://socradar.io/lockbit-is-allegedly-ddosed-after-leaking-entrust-data
Actors/Campaigns:
Blackmatter
Threats:
Lockbit
Sova
Process_injection_technique
Industry:
Financial
Geo:
China, Taiwan
TTPs:
Tactics: 2
Technics: 9
IOCs:
Hash: 13
Platforms:
apple
22-08-2022
LockBit Allegedly DDoSed After Leaking Entrusts Data
https://socradar.io/lockbit-is-allegedly-ddosed-after-leaking-entrust-data
Actors/Campaigns:
Blackmatter
Threats:
Lockbit
Sova
Process_injection_technique
Industry:
Financial
Geo:
China, Taiwan
TTPs:
Tactics: 2
Technics: 9
IOCs:
Hash: 13
Platforms:
apple
SOCRadar® Cyber Intelligence Inc.
LockBit Allegedly DDoSed After Leaking Entrust's Data - SOCRadar
IT security company Entrust suffered a cyberattack on June 18. Attackers gained unauthorized access to the company's network to reach...
#ParsedReport
#technique
22-08-2022
Is Tox The New C&C Method For Coinminers?
https://www.uptycs.com/blog/is-tox-the-new-cc-method-for-coinminers
Threats:
Helloxd
IOCs:
Hash: 1
Softs:
curl, crontab
Functions:
main
Links:
#technique
22-08-2022
Is Tox The New C&C Method For Coinminers?
https://www.uptycs.com/blog/is-tox-the-new-cc-method-for-coinminers
Threats:
Helloxd
IOCs:
Hash: 1
Softs:
curl, crontab
Functions:
main
Links:
https://github.com/irungentoo/toxcore/blob/master/docs/updates/DHT.md
https://github.com/TokTok/c-toxcoreUptycs
Is Tox the New C&C Method for Coinminers?
New discovery by the Uptycs Threat Research Team of peer-to-peer serverless messaging system Tox.
#ParsedReport
22-08-2022
Escanor Malware delivered in Weaponized Microsoft Office Documents
https://resecurity.com/blog/article/escanor-malware-delivered-in-weaponized-microsoft-office-documents
Actors/Campaigns:
Aridviper
Threats:
Escanor_rat
Venomrat
Pandora
Geo:
Israeli, Bahrain, Canada, Kuwait, Singapore, Asia, Egypt, Israel, Mexico
IOCs:
Domain: 1
Softs:
microsoft office, android, telegram
22-08-2022
Escanor Malware delivered in Weaponized Microsoft Office Documents
https://resecurity.com/blog/article/escanor-malware-delivered-in-weaponized-microsoft-office-documents
Actors/Campaigns:
Aridviper
Threats:
Escanor_rat
Venomrat
Pandora
Geo:
Israeli, Bahrain, Canada, Kuwait, Singapore, Asia, Egypt, Israel, Mexico
IOCs:
Domain: 1
Softs:
microsoft office, android, telegram