#ParsedReport
19-08-2022
EvilCoder Project Selling Multiple Dangerous Tools Online
https://blog.cyble.com/2022/08/19/evilcoder-project-selling-multiple-dangerous-tools-online
Threats:
Evilcoder_project
Xworm_rat
Xbinder
Uac_bypass_technique
Process_injection_technique
Geo:
Dubai, India, Australia, Singapore, Georgia
TTPs:
Tactics: 6
Technics: 7
IOCs:
File: 1
Domain: 1
Hash: 27
Softs:
virtualbox, android, .net framework
Algorithms:
aes
Functions:
CheckRemoteDebuggerPresent, Read, SetWorkPath
19-08-2022
EvilCoder Project Selling Multiple Dangerous Tools Online
https://blog.cyble.com/2022/08/19/evilcoder-project-selling-multiple-dangerous-tools-online
Threats:
Evilcoder_project
Xworm_rat
Xbinder
Uac_bypass_technique
Process_injection_technique
Geo:
Dubai, India, Australia, Singapore, Georgia
TTPs:
Tactics: 6
Technics: 7
IOCs:
File: 1
Domain: 1
Hash: 27
Softs:
virtualbox, android, .net framework
Algorithms:
aes
Functions:
CheckRemoteDebuggerPresent, Read, SetWorkPath
Cyble
EvilCoder Project Selling Multiple Dangerous Tools Online
Cyble Analyzes EvilCoder, a new project spotted selling multiple dangerous tools online capable of Ransomware and HNVC attacks.
#ParsedReport
19-08-2022
. Malicious Word documents targeting specific people related to North Korea
https://asec.ahnlab.com/ko/37879
Actors/Campaigns:
Kimsuky
Geo:
Korea, Korean
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 15
Url: 3
Registry: 7
Path: 1
Hash: 1
Languages:
php
Platforms:
x86
19-08-2022
. Malicious Word documents targeting specific people related to North Korea
https://asec.ahnlab.com/ko/37879
Actors/Campaigns:
Kimsuky
Geo:
Korea, Korean
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 15
Url: 3
Registry: 7
Path: 1
Hash: 1
Languages:
php
Platforms:
x86
ASEC BLOG
대북 관련 특정인을 타겟으로 하는 악성 워드 문서 - ASEC BLOG
ASEC 분석팀은 안보 및 대북 관련 특정인을 타겟으로 하는 악성 워드 문서가 지속적으로 유포되고 있음을 확인하였다. 유포가 확인된 워드 문서의 파일명에는 대북 관련 인물의 이름이 포함된 경우가 다수 존재하여 해당 분야를 타겟으로 공격이 이루어지는 것으로 추정된다. 최근 확인된 워드 문서의 파일명은 다음과 같다. 날짜 파일명 7/18 (작성양식)2022년 광복절 경축사 전문가 사전 의견수렴.doc 7/20 0511_통일부 *** 부장 회의록.doc 8/1…
#ParsedReport
19-08-2022
You Cant Audit Me: APT29 Continues Targeting Microsoft 365
https://www.mandiant.com/resources/apt29-continues-targeting-microsoft
Actors/Campaigns:
Duke (motivation: cyber_espionage)
Industry:
Government
Geo:
Russian
Softs:
active directory, azure ad
Links:
19-08-2022
You Cant Audit Me: APT29 Continues Targeting Microsoft 365
https://www.mandiant.com/resources/apt29-continues-targeting-microsoft
Actors/Campaigns:
Duke (motivation: cyber_espionage)
Industry:
Government
Geo:
Russian
Softs:
active directory, azure ad
Links:
https://github.com/mandiant/Mandiant-Azure-AD-InvestigatorMandiant
You Can’t Audit Me: APT29 Continues Targeting Microsoft 365 | Mandiant
#ParsedReport
19-08-2022
Honker Union: Has the grandfather of Chinese Hacktivism returned?
https://www.digitalshadows.com/blog-and-research/honker-union-has-the-grandfather-of-chinese-hacktivism-returned
Actors/Campaigns:
Honker_union (motivation: hacktivism)
Green_army (motivation: hacktivism)
Industry:
Education, Government
Geo:
Japan, Chinese, Indonesia, Taiwan, China, Japanese
Softs:
tiktok, weibo, wechat
Platforms:
intel
19-08-2022
Honker Union: Has the grandfather of Chinese Hacktivism returned?
https://www.digitalshadows.com/blog-and-research/honker-union-has-the-grandfather-of-chinese-hacktivism-returned
Actors/Campaigns:
Honker_union (motivation: hacktivism)
Green_army (motivation: hacktivism)
Industry:
Education, Government
Geo:
Japan, Chinese, Indonesia, Taiwan, China, Japanese
Softs:
tiktok, weibo, wechat
Platforms:
intel
Digital Shadows
Honker Union: Has the grandfather of Chinese Hacktivism returned? | Digital Shadows
The Photon Research Team provides insights into Chinese hacktivism’s responses to the growing tensions between the People’s Republic of China (PRC) and Taiwan.
#ParsedReport
19-08-2022
Suspected Iranian Actor Targeting Israeli Shipping, Healthcare, Government and Energy Sectors
https://www.mandiant.com/resources/blog/suspected-iranian-actor-targeting-israeli-shipping
Actors/Campaigns:
Unc3890 (motivation: cyber_espionage)
Fox_kitten
Cleaver
Threats:
Watering_hole_technique
Sugarush
Sugardump
Metasploit_tool
Northstar_tool
Credential_harvesting_technique
Unicorn
Industry:
Maritime, Energy, Transport, Aerospace, Government, Healthcare
Geo:
Iran, Iranian, Israeli, Israel
IOCs:
Domain: 9
Url: 1
Hash: 1
Softs:
instagram
Algorithms:
zip
19-08-2022
Suspected Iranian Actor Targeting Israeli Shipping, Healthcare, Government and Energy Sectors
https://www.mandiant.com/resources/blog/suspected-iranian-actor-targeting-israeli-shipping
Actors/Campaigns:
Unc3890 (motivation: cyber_espionage)
Fox_kitten
Cleaver
Threats:
Watering_hole_technique
Sugarush
Sugardump
Metasploit_tool
Northstar_tool
Credential_harvesting_technique
Unicorn
Industry:
Maritime, Energy, Transport, Aerospace, Government, Healthcare
Geo:
Iran, Iranian, Israeli, Israel
IOCs:
Domain: 9
Url: 1
Hash: 1
Softs:
Algorithms:
zip
Mandiant
UNC3890 | Suspected Iranian Threat Actor Targets Israel
This blog post details the activity of UNC3890, including their proprietary malware, TTPs we have not previously seen deployed by Iran, and the tools they use.
#ParsedReport
19-08-2022
Back in Black: Unlocking a LockBit 3.0 Ransomware Attack. Summary
https://research.nccgroup.com/2022/08/19/back-in-black-unlocking-a-lockbit-3-0-ransomware-attack
Threats:
Lockbit
Socgholish_loader
Cobalt_strike
Beacon
Bloodhound_tool
Seatbelt_tool
Conti
Megasync_tool
TTPs:
Tactics: 9
Technics: 15
IOCs:
Path: 12
File: 5
Email: 1
Domain: 1
IP: 1
Hash: 1
Softs:
psexec, windows defender
Algorithms:
zip
Links:
19-08-2022
Back in Black: Unlocking a LockBit 3.0 Ransomware Attack. Summary
https://research.nccgroup.com/2022/08/19/back-in-black-unlocking-a-lockbit-3-0-ransomware-attack
Threats:
Lockbit
Socgholish_loader
Cobalt_strike
Beacon
Bloodhound_tool
Seatbelt_tool
Conti
Megasync_tool
TTPs:
Tactics: 9
Technics: 15
IOCs:
Path: 12
File: 5
Email: 1
Domain: 1
IP: 1
Hash: 1
Softs:
psexec, windows defender
Algorithms:
zip
Links:
https://github.com/GhostPack/Seatbelt#ParsedReport
19-08-2022
Originalus tekstas
http://www.hackdig.com/08/hack-751533.htm
Actors/Campaigns:
Murenshark
Threats:
Shark
Cobalt_strike
Industry:
Education
Geo:
Turkey, China, Cyprus, Turkish
CVEs:
CVE-2022-26138 [Vulners]
Vulners: Score: Unknown, CVSS: 4.0,
Vulners: Exploitation: True
X-Force: Risk: 8.6
X-Force: Patch: Official fix
Soft:
- atlassian questions for confluence (3.0.2, 2.7.35, 2.7.34)
CVE-2022-34918 [Vulners]
Vulners: Score: 7.2, CVSS: 4.8,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.4
X-Force: Patch: Official fix
Soft:
- linux linux kernel (le5.18.9)
IOCs:
File: 5
Softs:
android, confluence
19-08-2022
Originalus tekstas
http://www.hackdig.com/08/hack-751533.htm
Actors/Campaigns:
Murenshark
Threats:
Shark
Cobalt_strike
Industry:
Education
Geo:
Turkey, China, Cyprus, Turkish
CVEs:
CVE-2022-26138 [Vulners]
Vulners: Score: Unknown, CVSS: 4.0,
Vulners: Exploitation: True
X-Force: Risk: 8.6
X-Force: Patch: Official fix
Soft:
- atlassian questions for confluence (3.0.2, 2.7.35, 2.7.34)
CVE-2022-34918 [Vulners]
Vulners: Score: 7.2, CVSS: 4.8,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.4
X-Force: Patch: Official fix
Soft:
- linux linux kernel (le5.18.9)
IOCs:
File: 5
Softs:
android, confluence
Hackdig
新APT组织穆伦鲨(MurenShark) 调查报告:袭向土耳其海军的鱼雷_黑客技术
阅读:46一、概述2022年第二季度,绿盟科技伏影实验室监测到了一系列针对土耳其的网络攻击活动。经过分析,研究人员确认本轮攻击活动来自一个由伏影实验室于21年4月确认的新型威胁实体Actor210426。伏影实验室通过行为模式、攻击手法、攻击工具、攻击目标等线索,对该威胁实体进行了深入调查,确认了其独立性与高级威胁性质。基于该威胁实体的活动区域与近期攻击目标(土耳其海军项目“MÜREN”),伏影实验室将其正式命名为穆伦鲨(MurenShark),对应绿盟科技高级威胁组织标识为APT-N-04。已监测活动…
#ParsedReport
19-08-2022
THREAT ALERT: Inside the Redeemer 2.0 Ransomware
https://www.cybereason.com/blog/threat-alert-inside-the-redeemer-2.0-ransomware
Threats:
Redeemer
Industry:
Government
IOCs:
File: 2
19-08-2022
THREAT ALERT: Inside the Redeemer 2.0 Ransomware
https://www.cybereason.com/blog/threat-alert-inside-the-redeemer-2.0-ransomware
Threats:
Redeemer
Industry:
Government
IOCs:
File: 2
Cybereason
THREAT ALERT: Inside the Redeemer 2.0 Ransomware
A new and improved Redeemer 2.0 ransomware version was released on an underground forum and is described by the developers as a “C++ no dependency ransomware with no privacy intrusions” targeting the Windows OS with support for Windows 11 systems...
#ParsedReport
19-08-2022
Pulling together the pieces to build the puzzle
https://inquest.net/blog/2022/08/18/pulling-together-pieces-build-puzzle
Threats:
Gozi
Procmon_tool
Geo:
Italian
IOCs:
File: 7
Hash: 1
Registry: 1
Algorithms:
7zip , zip
19-08-2022
Pulling together the pieces to build the puzzle
https://inquest.net/blog/2022/08/18/pulling-together-pieces-build-puzzle
Threats:
Gozi
Procmon_tool
Geo:
Italian
IOCs:
File: 7
Hash: 1
Registry: 1
Algorithms:
7zip , zip
inquest.net
Pulling together the pieces to build the puzzle
Follow along through the dissection and analysis of an oddly obfuscated maldoc that ultimately delivers the well-known GOZI ISFB banking trojan.
#technique
https://www.malwarebytes.com/blog/news/2022/08/spying-on-the-spies-see-what-javascript-commands-get-injected-by-an-in-app-browser
https://www.malwarebytes.com/blog/news/2022/08/spying-on-the-spies-see-what-javascript-commands-get-injected-by-an-in-app-browser
Malwarebytes
Spying on the spies. See what JavaScript commands get injected by in-app browsers
A developer and privacy expert created a platform that allows iOS users to see injected JavaScript in their in-app browsers
#ParsedReport
22-08-2022
LockBit Allegedly DDoSed After Leaking Entrusts Data
https://socradar.io/lockbit-is-allegedly-ddosed-after-leaking-entrust-data
Actors/Campaigns:
Blackmatter
Threats:
Lockbit
Sova
Process_injection_technique
Industry:
Financial
Geo:
China, Taiwan
TTPs:
Tactics: 2
Technics: 9
IOCs:
Hash: 13
Platforms:
apple
22-08-2022
LockBit Allegedly DDoSed After Leaking Entrusts Data
https://socradar.io/lockbit-is-allegedly-ddosed-after-leaking-entrust-data
Actors/Campaigns:
Blackmatter
Threats:
Lockbit
Sova
Process_injection_technique
Industry:
Financial
Geo:
China, Taiwan
TTPs:
Tactics: 2
Technics: 9
IOCs:
Hash: 13
Platforms:
apple
SOCRadar® Cyber Intelligence Inc.
LockBit Allegedly DDoSed After Leaking Entrust's Data - SOCRadar
IT security company Entrust suffered a cyberattack on June 18. Attackers gained unauthorized access to the company's network to reach...
#ParsedReport
#technique
22-08-2022
Is Tox The New C&C Method For Coinminers?
https://www.uptycs.com/blog/is-tox-the-new-cc-method-for-coinminers
Threats:
Helloxd
IOCs:
Hash: 1
Softs:
curl, crontab
Functions:
main
Links:
#technique
22-08-2022
Is Tox The New C&C Method For Coinminers?
https://www.uptycs.com/blog/is-tox-the-new-cc-method-for-coinminers
Threats:
Helloxd
IOCs:
Hash: 1
Softs:
curl, crontab
Functions:
main
Links:
https://github.com/irungentoo/toxcore/blob/master/docs/updates/DHT.md
https://github.com/TokTok/c-toxcoreUptycs
Is Tox the New C&C Method for Coinminers?
New discovery by the Uptycs Threat Research Team of peer-to-peer serverless messaging system Tox.
#ParsedReport
22-08-2022
Escanor Malware delivered in Weaponized Microsoft Office Documents
https://resecurity.com/blog/article/escanor-malware-delivered-in-weaponized-microsoft-office-documents
Actors/Campaigns:
Aridviper
Threats:
Escanor_rat
Venomrat
Pandora
Geo:
Israeli, Bahrain, Canada, Kuwait, Singapore, Asia, Egypt, Israel, Mexico
IOCs:
Domain: 1
Softs:
microsoft office, android, telegram
22-08-2022
Escanor Malware delivered in Weaponized Microsoft Office Documents
https://resecurity.com/blog/article/escanor-malware-delivered-in-weaponized-microsoft-office-documents
Actors/Campaigns:
Aridviper
Threats:
Escanor_rat
Venomrat
Pandora
Geo:
Israeli, Bahrain, Canada, Kuwait, Singapore, Asia, Egypt, Israel, Mexico
IOCs:
Domain: 1
Softs:
microsoft office, android, telegram
#ParsedReport
22-08-2022
XCSSET Malware Update \| macOS Threat Actors Prepare for Life Without Python
https://www.sentinelone.com/blog/xcsset-malware-update-macos-threat-actors-prepare-for-life-without-python
Threats:
Xcsset
Xcssset
Applescript
Industry:
Financial
Geo:
Chinese, China
IOCs:
Hash: 37
File: 7
Domain: 8
Softs:
chrome, macos, opera, telegram, wechat
Functions:
check_loop, runme
Languages:
python
Platforms:
apple
Links:
22-08-2022
XCSSET Malware Update \| macOS Threat Actors Prepare for Life Without Python
https://www.sentinelone.com/blog/xcsset-malware-update-macos-threat-actors-prepare-for-life-without-python
Threats:
Xcsset
Xcssset
Applescript
Industry:
Financial
Geo:
Chinese, China
IOCs:
Hash: 37
File: 7
Domain: 8
Softs:
chrome, macos, opera, telegram, wechat
Functions:
check_loop, runme
Languages:
python
Platforms:
apple
Links:
https://github.com/ydkhatri/mac\_apt/blob/master/plugins/notes.pyhttps://github.com/neurobin/shcSentinelOne
XCSSET Malware Update | macOS Threat Actors Prepare for Life Without Python
New domains and new behavioral indicators, but malware authors stick to tried and tested architecture despite Apple’s updates.
#ParsedReport
22-08-2022
Anatomy of a Solidbit Ransomware Attack
https://www.varonis.com/blog/anatomy-of-a-solidbit-ransomware-attack
Threats:
Solidbit
Lockbit
Yashma
Deepsea_obfuscator_tool
Chaos
Redline_stealer
Teamviewer_tool
Industry:
Financial
Geo:
Israeli, Syria
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 14
Softs:
telegram, windows service, windows registry, defwatch, microsoft visual studio
Algorithms:
aes-256, cbc
Platforms:
x86, intel
22-08-2022
Anatomy of a Solidbit Ransomware Attack
https://www.varonis.com/blog/anatomy-of-a-solidbit-ransomware-attack
Threats:
Solidbit
Lockbit
Yashma
Deepsea_obfuscator_tool
Chaos
Redline_stealer
Teamviewer_tool
Industry:
Financial
Geo:
Israeli, Syria
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 14
Softs:
telegram, windows service, windows registry, defwatch, microsoft visual studio
Algorithms:
aes-256, cbc
Platforms:
x86, intel
Varonis
Anatomy of a SolidBit Ransomware Attack
Solidbit is a ransomware variant derived from Yashma and containing elements of LockBit. Discover how Solidbit's capabilities, execution, what file types it targets, and how to tell if you're been infected.
#ParsedReport
23-08-2022
New Iranian APT data extraction tool
https://blog.google/threat-analysis-group/new-iranian-apt-data-extraction-tool
Actors/Campaigns:
Cleaver (motivation: government_sponsored)
Threats:
Hyperscrape_tool
Pwcs_tool
Industry:
Government
Geo:
Iran, Iranian
IOCs:
File: 14
IP: 2
Hash: 9
Path: 2
Softs:
microsoft outlook, telegram
Algorithms:
crc, gzip, base64
Functions:
ManageTakeOut, IsThereAnyEMail
Languages:
php
23-08-2022
New Iranian APT data extraction tool
https://blog.google/threat-analysis-group/new-iranian-apt-data-extraction-tool
Actors/Campaigns:
Cleaver (motivation: government_sponsored)
Threats:
Hyperscrape_tool
Pwcs_tool
Industry:
Government
Geo:
Iran, Iranian
IOCs:
File: 14
IP: 2
Hash: 9
Path: 2
Softs:
microsoft outlook, telegram
Algorithms:
crc, gzip, base64
Functions:
ManageTakeOut, IsThereAnyEMail
Languages:
php
Google
New Iranian APT data extraction tool
As part of TAG's mission to counter serious threats to Google and our users, we've analyzed a range of persistent threats including APT35 and Charming Kitten, …
#ParsedReport
23-08-2022
Dissecting IBAN Clipper
https://blog.cyble.com/2022/08/22/dissecting-iban-clipper
Threats:
Iban_clipper
Beacon
Industry:
Financial
Geo:
Singapore, India, Australia, Georgia, Dubai
TTPs:
Tactics: 6
Technics: 9
IOCs:
File: 2
Hash: 1
Softs:
microsoft store
Functions:
getexecutingassembly
23-08-2022
Dissecting IBAN Clipper
https://blog.cyble.com/2022/08/22/dissecting-iban-clipper
Threats:
Iban_clipper
Beacon
Industry:
Financial
Geo:
Singapore, India, Australia, Georgia, Dubai
TTPs:
Tactics: 6
Technics: 9
IOCs:
File: 2
Hash: 1
Softs:
microsoft store
Functions:
getexecutingassembly
#ParsedReport
23-08-2022
THREAT ALERT: HavanaCrypt Ransomware Masquerading as Google Update
https://www.cybereason.com/blog/threat-alert-havanacrypt-ransomware-masquerading-as-google-update
Threats:
Havanacrypt
Industry:
Government
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 2
File: 7
IP: 1
Path: 1
Softs:
thebat, keepass, onenote, defwatch, dbsnmp, windows defender, microsoft word, thebat64, sqlagent, vssadmin, mssql, google chrome, powerpnt, wordpad, sqlbrowser, encsvc
Algorithms:
aes
Languages:
php
Links:
23-08-2022
THREAT ALERT: HavanaCrypt Ransomware Masquerading as Google Update
https://www.cybereason.com/blog/threat-alert-havanacrypt-ransomware-masquerading-as-google-update
Threats:
Havanacrypt
Industry:
Government
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 2
File: 7
IP: 1
Path: 1
Softs:
thebat, keepass, onenote, defwatch, dbsnmp, windows defender, microsoft word, thebat64, sqlagent, vssadmin, mssql, google chrome, powerpnt, wordpad, sqlbrowser, encsvc
Algorithms:
aes
Languages:
php
Links:
https://github.com/obfuscar/obfuscarCybereason
THREAT ALERT: HavanaCrypt Ransomware Masquerading as Google Update
First observed in June 2022 in the wild, HavanaCrypt Ransomware masquerades as a legitimate Google Chrome update with sophisticated anti-analysis techniques and other functionality that may be used for data exfiltration and privilege escalation...
#ParsedReport
23-08-2022
Exploring the QBOT Attack Pattern. Key Takeaways
https://www.elastic.co/security-labs/exploring-the-qbot-attack-pattern
Threats:
Qakbot
Seth_locker
Emotet
Geo:
Kyrgyzstan, Turkmenistan, Armenia, Uzbekistan, Tajikistan, Belarus, Russia, Georgia, Kazakhstan, Ukraine
TTPs:
Tactics: 5
Technics: 0
IOCs:
Domain: 2
Url: 1
Path: 7
File: 9
Hash: 1
Registry: 4
Softs:
windows registry, microsoft office, docker, curl, windows defender, kibana
Algorithms:
zip
YARA: Found
Links:
23-08-2022
Exploring the QBOT Attack Pattern. Key Takeaways
https://www.elastic.co/security-labs/exploring-the-qbot-attack-pattern
Threats:
Qakbot
Seth_locker
Emotet
Geo:
Kyrgyzstan, Turkmenistan, Armenia, Uzbekistan, Tajikistan, Belarus, Russia, Georgia, Kazakhstan, Ukraine
TTPs:
Tactics: 5
Technics: 0
IOCs:
Domain: 2
Url: 1
Path: 7
File: 9
Hash: 1
Registry: 4
Softs:
windows registry, microsoft office, docker, curl, windows defender, kibana
Algorithms:
zip
YARA: Found
Links:
https://github.com/drole/qakbot-registry-decrypthttps://github.com/ipinfo/clihttps://github.com/peasead/elastic-containerwww.elastic.co
Exploring the QBOT Attack Pattern — Elastic Security Labs
In this research publication, we'll explore our analysis of the QBOT attack pattern — a full-featured and prolific malware family.
#ParsedReport
23-08-2022
A Tale of PivNoxy and Chinoxy Puppeteer
https://www.fortinet.com/blog/threat-research/pivnoxy-and-chinoxy-puppeteer-analysis
Actors/Campaigns:
Nightscout
Fakeupdates
Shell_crew
Threats:
Pivnoxy_dropper
Chinoxy_dropper
Velar
Cannon
Poison_ivy
Plugx_rat
Noxplayer
Funnydream
Kryptik_trojan
W32/injector.kr!tr
W32/rekvex.iy!tr
W32/agent.bjwzyi!tr
Sanny
Renos
W32/zuguo.a!tr
W32/agent.smc!tr
W32/generik.cijixom!tr
W32/injector.smc!tr
W32/rekvex.johugye!tr
W32/agent.adwj!tr
Process_injection_technique
Industry:
Government, Telco
Geo:
Ukraine, Vietnam, Chinese, Pakistan, Asia, Kirghizstan, India, Israel, France, Asian, Mexico
CVEs:
CVE-2018-0802 [Vulners]
Vulners: Score: 9.3, CVSS: 3.5,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2007, 2013, 2016, 2010, 2016)
- microsoft word (2013, 2007, 2010, 2013, 2016)
- microsoft office compatibility pack (-)
CVE-2017-11882 [Vulners]
Vulners: Score: 9.3, CVSS: 4.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2013, 2010, 2016, 2007)
CVE-2018-0798 [Vulners]
Vulners: Score: 9.3, CVSS: 3.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2010, 2016, 2016, 2007, 2013)
- microsoft word (2013, 2016, 2007, 2010, 2013)
- microsoft office compatibility pack (-)
TTPs:
Tactics: 11
Technics: 0
IOCs:
File: 7
Domain: 10
Hash: 47
Softs:
microsoft word, android, windows service
Algorithms:
base64
Functions:
LGBT_Launch
23-08-2022
A Tale of PivNoxy and Chinoxy Puppeteer
https://www.fortinet.com/blog/threat-research/pivnoxy-and-chinoxy-puppeteer-analysis
Actors/Campaigns:
Nightscout
Fakeupdates
Shell_crew
Threats:
Pivnoxy_dropper
Chinoxy_dropper
Velar
Cannon
Poison_ivy
Plugx_rat
Noxplayer
Funnydream
Kryptik_trojan
W32/injector.kr!tr
W32/rekvex.iy!tr
W32/agent.bjwzyi!tr
Sanny
Renos
W32/zuguo.a!tr
W32/agent.smc!tr
W32/generik.cijixom!tr
W32/injector.smc!tr
W32/rekvex.johugye!tr
W32/agent.adwj!tr
Process_injection_technique
Industry:
Government, Telco
Geo:
Ukraine, Vietnam, Chinese, Pakistan, Asia, Kirghizstan, India, Israel, France, Asian, Mexico
CVEs:
CVE-2018-0802 [Vulners]
Vulners: Score: 9.3, CVSS: 3.5,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2007, 2013, 2016, 2010, 2016)
- microsoft word (2013, 2007, 2010, 2013, 2016)
- microsoft office compatibility pack (-)
CVE-2017-11882 [Vulners]
Vulners: Score: 9.3, CVSS: 4.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2013, 2010, 2016, 2007)
CVE-2018-0798 [Vulners]
Vulners: Score: 9.3, CVSS: 3.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2010, 2016, 2016, 2007, 2013)
- microsoft word (2013, 2016, 2007, 2010, 2013)
- microsoft office compatibility pack (-)
TTPs:
Tactics: 11
Technics: 0
IOCs:
File: 7
Domain: 10
Hash: 47
Softs:
microsoft word, android, windows service
Algorithms:
base64
Functions:
LGBT_Launch
Fortinet Blog
A Tale of PivNoxy and Chinoxy Puppeteer
FortiGuard Labs discovered an email with a suspicious RTF attachment sent to a telecommunications agency that delivered a PivNoxy malware. Read our blog to learn how the attack works and the techni…