#ParsedReport
19-08-2022
You Cant Audit Me: APT29 Continues Targeting Microsoft 365
https://www.mandiant.com/resources/apt29-continues-targeting-microsoft
Actors/Campaigns:
Duke (motivation: cyber_espionage)
Industry:
Government
Geo:
Russian
Softs:
active directory, azure ad
Links:
19-08-2022
You Cant Audit Me: APT29 Continues Targeting Microsoft 365
https://www.mandiant.com/resources/apt29-continues-targeting-microsoft
Actors/Campaigns:
Duke (motivation: cyber_espionage)
Industry:
Government
Geo:
Russian
Softs:
active directory, azure ad
Links:
https://github.com/mandiant/Mandiant-Azure-AD-InvestigatorMandiant
You Can’t Audit Me: APT29 Continues Targeting Microsoft 365 | Mandiant
#ParsedReport
19-08-2022
Honker Union: Has the grandfather of Chinese Hacktivism returned?
https://www.digitalshadows.com/blog-and-research/honker-union-has-the-grandfather-of-chinese-hacktivism-returned
Actors/Campaigns:
Honker_union (motivation: hacktivism)
Green_army (motivation: hacktivism)
Industry:
Education, Government
Geo:
Japan, Chinese, Indonesia, Taiwan, China, Japanese
Softs:
tiktok, weibo, wechat
Platforms:
intel
19-08-2022
Honker Union: Has the grandfather of Chinese Hacktivism returned?
https://www.digitalshadows.com/blog-and-research/honker-union-has-the-grandfather-of-chinese-hacktivism-returned
Actors/Campaigns:
Honker_union (motivation: hacktivism)
Green_army (motivation: hacktivism)
Industry:
Education, Government
Geo:
Japan, Chinese, Indonesia, Taiwan, China, Japanese
Softs:
tiktok, weibo, wechat
Platforms:
intel
Digital Shadows
Honker Union: Has the grandfather of Chinese Hacktivism returned? | Digital Shadows
The Photon Research Team provides insights into Chinese hacktivism’s responses to the growing tensions between the People’s Republic of China (PRC) and Taiwan.
#ParsedReport
19-08-2022
Suspected Iranian Actor Targeting Israeli Shipping, Healthcare, Government and Energy Sectors
https://www.mandiant.com/resources/blog/suspected-iranian-actor-targeting-israeli-shipping
Actors/Campaigns:
Unc3890 (motivation: cyber_espionage)
Fox_kitten
Cleaver
Threats:
Watering_hole_technique
Sugarush
Sugardump
Metasploit_tool
Northstar_tool
Credential_harvesting_technique
Unicorn
Industry:
Maritime, Energy, Transport, Aerospace, Government, Healthcare
Geo:
Iran, Iranian, Israeli, Israel
IOCs:
Domain: 9
Url: 1
Hash: 1
Softs:
instagram
Algorithms:
zip
19-08-2022
Suspected Iranian Actor Targeting Israeli Shipping, Healthcare, Government and Energy Sectors
https://www.mandiant.com/resources/blog/suspected-iranian-actor-targeting-israeli-shipping
Actors/Campaigns:
Unc3890 (motivation: cyber_espionage)
Fox_kitten
Cleaver
Threats:
Watering_hole_technique
Sugarush
Sugardump
Metasploit_tool
Northstar_tool
Credential_harvesting_technique
Unicorn
Industry:
Maritime, Energy, Transport, Aerospace, Government, Healthcare
Geo:
Iran, Iranian, Israeli, Israel
IOCs:
Domain: 9
Url: 1
Hash: 1
Softs:
Algorithms:
zip
Mandiant
UNC3890 | Suspected Iranian Threat Actor Targets Israel
This blog post details the activity of UNC3890, including their proprietary malware, TTPs we have not previously seen deployed by Iran, and the tools they use.
#ParsedReport
19-08-2022
Back in Black: Unlocking a LockBit 3.0 Ransomware Attack. Summary
https://research.nccgroup.com/2022/08/19/back-in-black-unlocking-a-lockbit-3-0-ransomware-attack
Threats:
Lockbit
Socgholish_loader
Cobalt_strike
Beacon
Bloodhound_tool
Seatbelt_tool
Conti
Megasync_tool
TTPs:
Tactics: 9
Technics: 15
IOCs:
Path: 12
File: 5
Email: 1
Domain: 1
IP: 1
Hash: 1
Softs:
psexec, windows defender
Algorithms:
zip
Links:
19-08-2022
Back in Black: Unlocking a LockBit 3.0 Ransomware Attack. Summary
https://research.nccgroup.com/2022/08/19/back-in-black-unlocking-a-lockbit-3-0-ransomware-attack
Threats:
Lockbit
Socgholish_loader
Cobalt_strike
Beacon
Bloodhound_tool
Seatbelt_tool
Conti
Megasync_tool
TTPs:
Tactics: 9
Technics: 15
IOCs:
Path: 12
File: 5
Email: 1
Domain: 1
IP: 1
Hash: 1
Softs:
psexec, windows defender
Algorithms:
zip
Links:
https://github.com/GhostPack/Seatbelt#ParsedReport
19-08-2022
Originalus tekstas
http://www.hackdig.com/08/hack-751533.htm
Actors/Campaigns:
Murenshark
Threats:
Shark
Cobalt_strike
Industry:
Education
Geo:
Turkey, China, Cyprus, Turkish
CVEs:
CVE-2022-26138 [Vulners]
Vulners: Score: Unknown, CVSS: 4.0,
Vulners: Exploitation: True
X-Force: Risk: 8.6
X-Force: Patch: Official fix
Soft:
- atlassian questions for confluence (3.0.2, 2.7.35, 2.7.34)
CVE-2022-34918 [Vulners]
Vulners: Score: 7.2, CVSS: 4.8,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.4
X-Force: Patch: Official fix
Soft:
- linux linux kernel (le5.18.9)
IOCs:
File: 5
Softs:
android, confluence
19-08-2022
Originalus tekstas
http://www.hackdig.com/08/hack-751533.htm
Actors/Campaigns:
Murenshark
Threats:
Shark
Cobalt_strike
Industry:
Education
Geo:
Turkey, China, Cyprus, Turkish
CVEs:
CVE-2022-26138 [Vulners]
Vulners: Score: Unknown, CVSS: 4.0,
Vulners: Exploitation: True
X-Force: Risk: 8.6
X-Force: Patch: Official fix
Soft:
- atlassian questions for confluence (3.0.2, 2.7.35, 2.7.34)
CVE-2022-34918 [Vulners]
Vulners: Score: 7.2, CVSS: 4.8,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.4
X-Force: Patch: Official fix
Soft:
- linux linux kernel (le5.18.9)
IOCs:
File: 5
Softs:
android, confluence
Hackdig
新APT组织穆伦鲨(MurenShark) 调查报告:袭向土耳其海军的鱼雷_黑客技术
阅读:46一、概述2022年第二季度,绿盟科技伏影实验室监测到了一系列针对土耳其的网络攻击活动。经过分析,研究人员确认本轮攻击活动来自一个由伏影实验室于21年4月确认的新型威胁实体Actor210426。伏影实验室通过行为模式、攻击手法、攻击工具、攻击目标等线索,对该威胁实体进行了深入调查,确认了其独立性与高级威胁性质。基于该威胁实体的活动区域与近期攻击目标(土耳其海军项目“MÜREN”),伏影实验室将其正式命名为穆伦鲨(MurenShark),对应绿盟科技高级威胁组织标识为APT-N-04。已监测活动…
#ParsedReport
19-08-2022
THREAT ALERT: Inside the Redeemer 2.0 Ransomware
https://www.cybereason.com/blog/threat-alert-inside-the-redeemer-2.0-ransomware
Threats:
Redeemer
Industry:
Government
IOCs:
File: 2
19-08-2022
THREAT ALERT: Inside the Redeemer 2.0 Ransomware
https://www.cybereason.com/blog/threat-alert-inside-the-redeemer-2.0-ransomware
Threats:
Redeemer
Industry:
Government
IOCs:
File: 2
Cybereason
THREAT ALERT: Inside the Redeemer 2.0 Ransomware
A new and improved Redeemer 2.0 ransomware version was released on an underground forum and is described by the developers as a “C++ no dependency ransomware with no privacy intrusions” targeting the Windows OS with support for Windows 11 systems...
#ParsedReport
19-08-2022
Pulling together the pieces to build the puzzle
https://inquest.net/blog/2022/08/18/pulling-together-pieces-build-puzzle
Threats:
Gozi
Procmon_tool
Geo:
Italian
IOCs:
File: 7
Hash: 1
Registry: 1
Algorithms:
7zip , zip
19-08-2022
Pulling together the pieces to build the puzzle
https://inquest.net/blog/2022/08/18/pulling-together-pieces-build-puzzle
Threats:
Gozi
Procmon_tool
Geo:
Italian
IOCs:
File: 7
Hash: 1
Registry: 1
Algorithms:
7zip , zip
inquest.net
Pulling together the pieces to build the puzzle
Follow along through the dissection and analysis of an oddly obfuscated maldoc that ultimately delivers the well-known GOZI ISFB banking trojan.
#technique
https://www.malwarebytes.com/blog/news/2022/08/spying-on-the-spies-see-what-javascript-commands-get-injected-by-an-in-app-browser
https://www.malwarebytes.com/blog/news/2022/08/spying-on-the-spies-see-what-javascript-commands-get-injected-by-an-in-app-browser
Malwarebytes
Spying on the spies. See what JavaScript commands get injected by in-app browsers
A developer and privacy expert created a platform that allows iOS users to see injected JavaScript in their in-app browsers
#ParsedReport
22-08-2022
LockBit Allegedly DDoSed After Leaking Entrusts Data
https://socradar.io/lockbit-is-allegedly-ddosed-after-leaking-entrust-data
Actors/Campaigns:
Blackmatter
Threats:
Lockbit
Sova
Process_injection_technique
Industry:
Financial
Geo:
China, Taiwan
TTPs:
Tactics: 2
Technics: 9
IOCs:
Hash: 13
Platforms:
apple
22-08-2022
LockBit Allegedly DDoSed After Leaking Entrusts Data
https://socradar.io/lockbit-is-allegedly-ddosed-after-leaking-entrust-data
Actors/Campaigns:
Blackmatter
Threats:
Lockbit
Sova
Process_injection_technique
Industry:
Financial
Geo:
China, Taiwan
TTPs:
Tactics: 2
Technics: 9
IOCs:
Hash: 13
Platforms:
apple
SOCRadar® Cyber Intelligence Inc.
LockBit Allegedly DDoSed After Leaking Entrust's Data - SOCRadar
IT security company Entrust suffered a cyberattack on June 18. Attackers gained unauthorized access to the company's network to reach...
#ParsedReport
#technique
22-08-2022
Is Tox The New C&C Method For Coinminers?
https://www.uptycs.com/blog/is-tox-the-new-cc-method-for-coinminers
Threats:
Helloxd
IOCs:
Hash: 1
Softs:
curl, crontab
Functions:
main
Links:
#technique
22-08-2022
Is Tox The New C&C Method For Coinminers?
https://www.uptycs.com/blog/is-tox-the-new-cc-method-for-coinminers
Threats:
Helloxd
IOCs:
Hash: 1
Softs:
curl, crontab
Functions:
main
Links:
https://github.com/irungentoo/toxcore/blob/master/docs/updates/DHT.md
https://github.com/TokTok/c-toxcoreUptycs
Is Tox the New C&C Method for Coinminers?
New discovery by the Uptycs Threat Research Team of peer-to-peer serverless messaging system Tox.
#ParsedReport
22-08-2022
Escanor Malware delivered in Weaponized Microsoft Office Documents
https://resecurity.com/blog/article/escanor-malware-delivered-in-weaponized-microsoft-office-documents
Actors/Campaigns:
Aridviper
Threats:
Escanor_rat
Venomrat
Pandora
Geo:
Israeli, Bahrain, Canada, Kuwait, Singapore, Asia, Egypt, Israel, Mexico
IOCs:
Domain: 1
Softs:
microsoft office, android, telegram
22-08-2022
Escanor Malware delivered in Weaponized Microsoft Office Documents
https://resecurity.com/blog/article/escanor-malware-delivered-in-weaponized-microsoft-office-documents
Actors/Campaigns:
Aridviper
Threats:
Escanor_rat
Venomrat
Pandora
Geo:
Israeli, Bahrain, Canada, Kuwait, Singapore, Asia, Egypt, Israel, Mexico
IOCs:
Domain: 1
Softs:
microsoft office, android, telegram
#ParsedReport
22-08-2022
XCSSET Malware Update \| macOS Threat Actors Prepare for Life Without Python
https://www.sentinelone.com/blog/xcsset-malware-update-macos-threat-actors-prepare-for-life-without-python
Threats:
Xcsset
Xcssset
Applescript
Industry:
Financial
Geo:
Chinese, China
IOCs:
Hash: 37
File: 7
Domain: 8
Softs:
chrome, macos, opera, telegram, wechat
Functions:
check_loop, runme
Languages:
python
Platforms:
apple
Links:
22-08-2022
XCSSET Malware Update \| macOS Threat Actors Prepare for Life Without Python
https://www.sentinelone.com/blog/xcsset-malware-update-macos-threat-actors-prepare-for-life-without-python
Threats:
Xcsset
Xcssset
Applescript
Industry:
Financial
Geo:
Chinese, China
IOCs:
Hash: 37
File: 7
Domain: 8
Softs:
chrome, macos, opera, telegram, wechat
Functions:
check_loop, runme
Languages:
python
Platforms:
apple
Links:
https://github.com/ydkhatri/mac\_apt/blob/master/plugins/notes.pyhttps://github.com/neurobin/shcSentinelOne
XCSSET Malware Update | macOS Threat Actors Prepare for Life Without Python
New domains and new behavioral indicators, but malware authors stick to tried and tested architecture despite Apple’s updates.
#ParsedReport
22-08-2022
Anatomy of a Solidbit Ransomware Attack
https://www.varonis.com/blog/anatomy-of-a-solidbit-ransomware-attack
Threats:
Solidbit
Lockbit
Yashma
Deepsea_obfuscator_tool
Chaos
Redline_stealer
Teamviewer_tool
Industry:
Financial
Geo:
Israeli, Syria
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 14
Softs:
telegram, windows service, windows registry, defwatch, microsoft visual studio
Algorithms:
aes-256, cbc
Platforms:
x86, intel
22-08-2022
Anatomy of a Solidbit Ransomware Attack
https://www.varonis.com/blog/anatomy-of-a-solidbit-ransomware-attack
Threats:
Solidbit
Lockbit
Yashma
Deepsea_obfuscator_tool
Chaos
Redline_stealer
Teamviewer_tool
Industry:
Financial
Geo:
Israeli, Syria
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 14
Softs:
telegram, windows service, windows registry, defwatch, microsoft visual studio
Algorithms:
aes-256, cbc
Platforms:
x86, intel
Varonis
Anatomy of a SolidBit Ransomware Attack
Solidbit is a ransomware variant derived from Yashma and containing elements of LockBit. Discover how Solidbit's capabilities, execution, what file types it targets, and how to tell if you're been infected.
#ParsedReport
23-08-2022
New Iranian APT data extraction tool
https://blog.google/threat-analysis-group/new-iranian-apt-data-extraction-tool
Actors/Campaigns:
Cleaver (motivation: government_sponsored)
Threats:
Hyperscrape_tool
Pwcs_tool
Industry:
Government
Geo:
Iran, Iranian
IOCs:
File: 14
IP: 2
Hash: 9
Path: 2
Softs:
microsoft outlook, telegram
Algorithms:
crc, gzip, base64
Functions:
ManageTakeOut, IsThereAnyEMail
Languages:
php
23-08-2022
New Iranian APT data extraction tool
https://blog.google/threat-analysis-group/new-iranian-apt-data-extraction-tool
Actors/Campaigns:
Cleaver (motivation: government_sponsored)
Threats:
Hyperscrape_tool
Pwcs_tool
Industry:
Government
Geo:
Iran, Iranian
IOCs:
File: 14
IP: 2
Hash: 9
Path: 2
Softs:
microsoft outlook, telegram
Algorithms:
crc, gzip, base64
Functions:
ManageTakeOut, IsThereAnyEMail
Languages:
php
Google
New Iranian APT data extraction tool
As part of TAG's mission to counter serious threats to Google and our users, we've analyzed a range of persistent threats including APT35 and Charming Kitten, …
#ParsedReport
23-08-2022
Dissecting IBAN Clipper
https://blog.cyble.com/2022/08/22/dissecting-iban-clipper
Threats:
Iban_clipper
Beacon
Industry:
Financial
Geo:
Singapore, India, Australia, Georgia, Dubai
TTPs:
Tactics: 6
Technics: 9
IOCs:
File: 2
Hash: 1
Softs:
microsoft store
Functions:
getexecutingassembly
23-08-2022
Dissecting IBAN Clipper
https://blog.cyble.com/2022/08/22/dissecting-iban-clipper
Threats:
Iban_clipper
Beacon
Industry:
Financial
Geo:
Singapore, India, Australia, Georgia, Dubai
TTPs:
Tactics: 6
Technics: 9
IOCs:
File: 2
Hash: 1
Softs:
microsoft store
Functions:
getexecutingassembly
#ParsedReport
23-08-2022
THREAT ALERT: HavanaCrypt Ransomware Masquerading as Google Update
https://www.cybereason.com/blog/threat-alert-havanacrypt-ransomware-masquerading-as-google-update
Threats:
Havanacrypt
Industry:
Government
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 2
File: 7
IP: 1
Path: 1
Softs:
thebat, keepass, onenote, defwatch, dbsnmp, windows defender, microsoft word, thebat64, sqlagent, vssadmin, mssql, google chrome, powerpnt, wordpad, sqlbrowser, encsvc
Algorithms:
aes
Languages:
php
Links:
23-08-2022
THREAT ALERT: HavanaCrypt Ransomware Masquerading as Google Update
https://www.cybereason.com/blog/threat-alert-havanacrypt-ransomware-masquerading-as-google-update
Threats:
Havanacrypt
Industry:
Government
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 2
File: 7
IP: 1
Path: 1
Softs:
thebat, keepass, onenote, defwatch, dbsnmp, windows defender, microsoft word, thebat64, sqlagent, vssadmin, mssql, google chrome, powerpnt, wordpad, sqlbrowser, encsvc
Algorithms:
aes
Languages:
php
Links:
https://github.com/obfuscar/obfuscarCybereason
THREAT ALERT: HavanaCrypt Ransomware Masquerading as Google Update
First observed in June 2022 in the wild, HavanaCrypt Ransomware masquerades as a legitimate Google Chrome update with sophisticated anti-analysis techniques and other functionality that may be used for data exfiltration and privilege escalation...
#ParsedReport
23-08-2022
Exploring the QBOT Attack Pattern. Key Takeaways
https://www.elastic.co/security-labs/exploring-the-qbot-attack-pattern
Threats:
Qakbot
Seth_locker
Emotet
Geo:
Kyrgyzstan, Turkmenistan, Armenia, Uzbekistan, Tajikistan, Belarus, Russia, Georgia, Kazakhstan, Ukraine
TTPs:
Tactics: 5
Technics: 0
IOCs:
Domain: 2
Url: 1
Path: 7
File: 9
Hash: 1
Registry: 4
Softs:
windows registry, microsoft office, docker, curl, windows defender, kibana
Algorithms:
zip
YARA: Found
Links:
23-08-2022
Exploring the QBOT Attack Pattern. Key Takeaways
https://www.elastic.co/security-labs/exploring-the-qbot-attack-pattern
Threats:
Qakbot
Seth_locker
Emotet
Geo:
Kyrgyzstan, Turkmenistan, Armenia, Uzbekistan, Tajikistan, Belarus, Russia, Georgia, Kazakhstan, Ukraine
TTPs:
Tactics: 5
Technics: 0
IOCs:
Domain: 2
Url: 1
Path: 7
File: 9
Hash: 1
Registry: 4
Softs:
windows registry, microsoft office, docker, curl, windows defender, kibana
Algorithms:
zip
YARA: Found
Links:
https://github.com/drole/qakbot-registry-decrypthttps://github.com/ipinfo/clihttps://github.com/peasead/elastic-containerwww.elastic.co
Exploring the QBOT Attack Pattern — Elastic Security Labs
In this research publication, we'll explore our analysis of the QBOT attack pattern — a full-featured and prolific malware family.
#ParsedReport
23-08-2022
A Tale of PivNoxy and Chinoxy Puppeteer
https://www.fortinet.com/blog/threat-research/pivnoxy-and-chinoxy-puppeteer-analysis
Actors/Campaigns:
Nightscout
Fakeupdates
Shell_crew
Threats:
Pivnoxy_dropper
Chinoxy_dropper
Velar
Cannon
Poison_ivy
Plugx_rat
Noxplayer
Funnydream
Kryptik_trojan
W32/injector.kr!tr
W32/rekvex.iy!tr
W32/agent.bjwzyi!tr
Sanny
Renos
W32/zuguo.a!tr
W32/agent.smc!tr
W32/generik.cijixom!tr
W32/injector.smc!tr
W32/rekvex.johugye!tr
W32/agent.adwj!tr
Process_injection_technique
Industry:
Government, Telco
Geo:
Ukraine, Vietnam, Chinese, Pakistan, Asia, Kirghizstan, India, Israel, France, Asian, Mexico
CVEs:
CVE-2018-0802 [Vulners]
Vulners: Score: 9.3, CVSS: 3.5,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2007, 2013, 2016, 2010, 2016)
- microsoft word (2013, 2007, 2010, 2013, 2016)
- microsoft office compatibility pack (-)
CVE-2017-11882 [Vulners]
Vulners: Score: 9.3, CVSS: 4.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2013, 2010, 2016, 2007)
CVE-2018-0798 [Vulners]
Vulners: Score: 9.3, CVSS: 3.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2010, 2016, 2016, 2007, 2013)
- microsoft word (2013, 2016, 2007, 2010, 2013)
- microsoft office compatibility pack (-)
TTPs:
Tactics: 11
Technics: 0
IOCs:
File: 7
Domain: 10
Hash: 47
Softs:
microsoft word, android, windows service
Algorithms:
base64
Functions:
LGBT_Launch
23-08-2022
A Tale of PivNoxy and Chinoxy Puppeteer
https://www.fortinet.com/blog/threat-research/pivnoxy-and-chinoxy-puppeteer-analysis
Actors/Campaigns:
Nightscout
Fakeupdates
Shell_crew
Threats:
Pivnoxy_dropper
Chinoxy_dropper
Velar
Cannon
Poison_ivy
Plugx_rat
Noxplayer
Funnydream
Kryptik_trojan
W32/injector.kr!tr
W32/rekvex.iy!tr
W32/agent.bjwzyi!tr
Sanny
Renos
W32/zuguo.a!tr
W32/agent.smc!tr
W32/generik.cijixom!tr
W32/injector.smc!tr
W32/rekvex.johugye!tr
W32/agent.adwj!tr
Process_injection_technique
Industry:
Government, Telco
Geo:
Ukraine, Vietnam, Chinese, Pakistan, Asia, Kirghizstan, India, Israel, France, Asian, Mexico
CVEs:
CVE-2018-0802 [Vulners]
Vulners: Score: 9.3, CVSS: 3.5,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2007, 2013, 2016, 2010, 2016)
- microsoft word (2013, 2007, 2010, 2013, 2016)
- microsoft office compatibility pack (-)
CVE-2017-11882 [Vulners]
Vulners: Score: 9.3, CVSS: 4.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2013, 2010, 2016, 2007)
CVE-2018-0798 [Vulners]
Vulners: Score: 9.3, CVSS: 3.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2010, 2016, 2016, 2007, 2013)
- microsoft word (2013, 2016, 2007, 2010, 2013)
- microsoft office compatibility pack (-)
TTPs:
Tactics: 11
Technics: 0
IOCs:
File: 7
Domain: 10
Hash: 47
Softs:
microsoft word, android, windows service
Algorithms:
base64
Functions:
LGBT_Launch
Fortinet Blog
A Tale of PivNoxy and Chinoxy Puppeteer
FortiGuard Labs discovered an email with a suspicious RTF attachment sent to a telecommunications agency that delivered a PivNoxy malware. Read our blog to learn how the attack works and the techni…
#ParsedReport
23-08-2022
Venom ControlRAT With a Sting
https://cyberint.com/blog/research/venom-control-rat-with-a-sting
Actors/Campaigns:
Atlantis_cyberarmy
Threats:
Control_rat
Venomrat
Sbit_rat
Bratarat
Industry:
Financial
Softs:
telegram, chrome, opera, windows defender
23-08-2022
Venom ControlRAT With a Sting
https://cyberint.com/blog/research/venom-control-rat-with-a-sting
Actors/Campaigns:
Atlantis_cyberarmy
Threats:
Control_rat
Venomrat
Sbit_rat
Bratarat
Industry:
Financial
Softs:
telegram, chrome, opera, windows defender
#ParsedReport
23-08-2022
Reversing Golang Developed Ransomware: SNAKE. Introduction
https://www.0ffset.net/reverse-engineering/analysing-snake-ransomware/?utm_source=rss&utm_medium=rss&utm_campaign=analysing-snake-ransomware
Threats:
Snake_ransomware
Snakehose
IOCs:
Hash: 1
File: 19
IP: 1
Path: 1
Email: 1
Softs:
bootnxt, windows firewall
Algorithms:
xor, aes, rsa-2048
Functions:
WriteAt, LazyDLL, OpenService, OpenServiceW, CoInitializeEx, OpenSCManagerA, OpenProcess, DeleteInstance, main
Languages:
python, golang
Links:
23-08-2022
Reversing Golang Developed Ransomware: SNAKE. Introduction
https://www.0ffset.net/reverse-engineering/analysing-snake-ransomware/?utm_source=rss&utm_medium=rss&utm_campaign=analysing-snake-ransomware
Threats:
Snake_ransomware
Snakehose
IOCs:
Hash: 1
File: 19
IP: 1
Path: 1
Email: 1
Softs:
bootnxt, windows firewall
Algorithms:
xor, aes, rsa-2048
Functions:
WriteAt, LazyDLL, OpenService, OpenServiceW, CoInitializeEx, OpenSCManagerA, OpenProcess, DeleteInstance, main
Languages:
python, golang
Links:
https://github.com/unixpickle/gobfuscate0ffset Training Solutions | Practical and Affordable Cyber Security Training
Reversing Golang Developed Ransomware: SNAKE | 0ffset Training Solutions
Introduction Snake Ransomware (or EKANS Ransomware) is a Golang ransomware which in the past has affected several companies such as Enel and Honda. The MD5 hashing of the analyzed sample is ED3C05BDE9F0EA0F1321355B03AC42D0. This sample in particular is obfuscated…