CTT Report Hub
3.42K subscribers
9.83K photos
6 videos
67 files
13.5K links
Threat Intelligence Report Hub
Download Telegram
#ParsedReport
22-08-2022

LockBit Allegedly DDoSed After Leaking Entrusts Data

https://socradar.io/lockbit-is-allegedly-ddosed-after-leaking-entrust-data

Actors/Campaigns:
Blackmatter

Threats:
Lockbit
Sova
Process_injection_technique

Industry:
Financial

Geo:
China, Taiwan

TTPs:
Tactics: 2
Technics: 9

IOCs:
Hash: 13

Platforms:
apple
#ParsedReport
#technique
22-08-2022

Is Tox The New C&C Method For Coinminers?

https://www.uptycs.com/blog/is-tox-the-new-cc-method-for-coinminers

Threats:
Helloxd

IOCs:
Hash: 1

Softs:
curl, crontab

Functions:
main

Links:
https://github.com/irungentoo/toxcore/blob/master/docs/updates/DHT.md
https://github.com/TokTok/c-toxcore
#ParsedReport
22-08-2022

Escanor Malware delivered in Weaponized Microsoft Office Documents

https://resecurity.com/blog/article/escanor-malware-delivered-in-weaponized-microsoft-office-documents

Actors/Campaigns:
Aridviper

Threats:
Escanor_rat
Venomrat
Pandora

Geo:
Israeli, Bahrain, Canada, Kuwait, Singapore, Asia, Egypt, Israel, Mexico

IOCs:
Domain: 1

Softs:
microsoft office, android, telegram
#ParsedReport
22-08-2022

XCSSET Malware Update \| macOS Threat Actors Prepare for Life Without Python

https://www.sentinelone.com/blog/xcsset-malware-update-macos-threat-actors-prepare-for-life-without-python

Threats:
Xcsset
Xcssset
Applescript

Industry:
Financial

Geo:
Chinese, China

IOCs:
Hash: 37
File: 7
Domain: 8

Softs:
chrome, macos, opera, telegram, wechat

Functions:
check_loop, runme

Languages:
python

Platforms:
apple

Links:
https://github.com/ydkhatri/mac\_apt/blob/master/plugins/notes.py
https://github.com/neurobin/shc
#ParsedReport
22-08-2022

Anatomy of a Solidbit Ransomware Attack

https://www.varonis.com/blog/anatomy-of-a-solidbit-ransomware-attack

Threats:
Solidbit
Lockbit
Yashma
Deepsea_obfuscator_tool
Chaos
Redline_stealer
Teamviewer_tool

Industry:
Financial

Geo:
Israeli, Syria

TTPs:
Tactics: 2
Technics: 0

IOCs:
File: 14

Softs:
telegram, windows service, windows registry, defwatch, microsoft visual studio

Algorithms:
aes-256, cbc

Platforms:
x86, intel
#ParsedReport
23-08-2022

New Iranian APT data extraction tool

https://blog.google/threat-analysis-group/new-iranian-apt-data-extraction-tool

Actors/Campaigns:
Cleaver (motivation: government_sponsored)

Threats:
Hyperscrape_tool
Pwcs_tool

Industry:
Government

Geo:
Iran, Iranian

IOCs:
File: 14
IP: 2
Hash: 9
Path: 2

Softs:
microsoft outlook, telegram

Algorithms:
crc, gzip, base64

Functions:
ManageTakeOut, IsThereAnyEMail

Languages:
php
#ParsedReport
23-08-2022

Dissecting IBAN Clipper

https://blog.cyble.com/2022/08/22/dissecting-iban-clipper

Threats:
Iban_clipper
Beacon

Industry:
Financial

Geo:
Singapore, India, Australia, Georgia, Dubai

TTPs:
Tactics: 6
Technics: 9

IOCs:
File: 2
Hash: 1

Softs:
microsoft store

Functions:
getexecutingassembly
#ParsedReport
23-08-2022

THREAT ALERT: HavanaCrypt Ransomware Masquerading as Google Update

https://www.cybereason.com/blog/threat-alert-havanacrypt-ransomware-masquerading-as-google-update

Threats:
Havanacrypt

Industry:
Government

TTPs:
Tactics: 1
Technics: 0

IOCs:
Hash: 2
File: 7
IP: 1
Path: 1

Softs:
thebat, keepass, onenote, defwatch, dbsnmp, windows defender, microsoft word, thebat64, sqlagent, vssadmin, mssql, google chrome, powerpnt, wordpad, sqlbrowser, encsvc

Algorithms:
aes

Languages:
php

Links:
https://github.com/obfuscar/obfuscar
#ParsedReport
23-08-2022

Exploring the QBOT Attack Pattern. Key Takeaways

https://www.elastic.co/security-labs/exploring-the-qbot-attack-pattern

Threats:
Qakbot
Seth_locker
Emotet

Geo:
Kyrgyzstan, Turkmenistan, Armenia, Uzbekistan, Tajikistan, Belarus, Russia, Georgia, Kazakhstan, Ukraine

TTPs:
Tactics: 5
Technics: 0

IOCs:
Domain: 2
Url: 1
Path: 7
File: 9
Hash: 1
Registry: 4

Softs:
windows registry, microsoft office, docker, curl, windows defender, kibana

Algorithms:
zip

YARA: Found

Links:
https://github.com/drole/qakbot-registry-decrypt
https://github.com/ipinfo/cli
https://github.com/peasead/elastic-container
#ParsedReport
23-08-2022

A Tale of PivNoxy and Chinoxy Puppeteer

https://www.fortinet.com/blog/threat-research/pivnoxy-and-chinoxy-puppeteer-analysis

Actors/Campaigns:
Nightscout
Fakeupdates
Shell_crew

Threats:
Pivnoxy_dropper
Chinoxy_dropper
Velar
Cannon
Poison_ivy
Plugx_rat
Noxplayer
Funnydream
Kryptik_trojan
W32/injector.kr!tr
W32/rekvex.iy!tr
W32/agent.bjwzyi!tr
Sanny
Renos
W32/zuguo.a!tr
W32/agent.smc!tr
W32/generik.cijixom!tr
W32/injector.smc!tr
W32/rekvex.johugye!tr
W32/agent.adwj!tr
Process_injection_technique

Industry:
Government, Telco

Geo:
Ukraine, Vietnam, Chinese, Pakistan, Asia, Kirghizstan, India, Israel, France, Asian, Mexico

CVEs:
CVE-2018-0802 [Vulners]
Vulners: Score: 9.3, CVSS: 3.5,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2007, 2013, 2016, 2010, 2016)
- microsoft word (2013, 2007, 2010, 2013, 2016)
- microsoft office compatibility pack (-)

CVE-2017-11882 [Vulners]
Vulners: Score: 9.3, CVSS: 4.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2013, 2010, 2016, 2007)

CVE-2018-0798 [Vulners]
Vulners: Score: 9.3, CVSS: 3.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2010, 2016, 2016, 2007, 2013)
- microsoft word (2013, 2016, 2007, 2010, 2013)
- microsoft office compatibility pack (-)


TTPs:
Tactics: 11
Technics: 0

IOCs:
File: 7
Domain: 10
Hash: 47

Softs:
microsoft word, android, windows service

Algorithms:
base64

Functions:
LGBT_Launch
#ParsedReport
23-08-2022

Venom ControlRAT With a Sting

https://cyberint.com/blog/research/venom-control-rat-with-a-sting

Actors/Campaigns:
Atlantis_cyberarmy

Threats:
Control_rat
Venomrat
Sbit_rat
Bratarat

Industry:
Financial

Softs:
telegram, chrome, opera, windows defender
#ParsedReport
23-08-2022

Reversing Golang Developed Ransomware: SNAKE. Introduction

https://www.0ffset.net/reverse-engineering/analysing-snake-ransomware/?utm_source=rss&utm_medium=rss&utm_campaign=analysing-snake-ransomware

Threats:
Snake_ransomware
Snakehose

IOCs:
Hash: 1
File: 19
IP: 1
Path: 1
Email: 1

Softs:
bootnxt, windows firewall

Algorithms:
xor, aes, rsa-2048

Functions:
WriteAt, LazyDLL, OpenService, OpenServiceW, CoInitializeEx, OpenSCManagerA, OpenProcess, DeleteInstance, main

Languages:
python, golang

Links:
https://github.com/unixpickle/gobfuscate
#ParsedReport
23-08-2022

Get a demo. Emotet Resurgence: Cross-Industry Campaign Analysis

https://darktrace.com/blog/emotet-resurgence-cross-industry-campaign-analysis

Threats:
Emotet
Trickbot
Ryuk
Cobalt_strike
Beacon

Industry:
Telco, Healthcare

Geo:
London, Japanese

IOCs:
Domain: 3
File: 7
Hash: 5

Softs:
microsoft outlook

Algorithms:
ecc, zip , gzip

Platforms:
intel
#ParsedReport
24-08-2022

BitRAT and XMRig CoinMiner Being Distributed via Windows License Verification Tool

https://asec.ahnlab.com/en/37939

Threats:
Sbit_rat
Xmrig_miner
Trojan/win.generic.c5223158
Malware/mdp.download.m1197
Malware/mdp.drivebydownload.m1298

Geo:
Korean

IOCs:
File: 9
Path: 1
Domain: 1
Hash: 4
Url: 3
IP: 1

Softs:
google chrome, windows defender, telegram
#ParsedReport
24-08-2022

AgentTesla is threatening businesses around the world with a new campaign

https://decoded.avast.io/pavelnovak/agenttesla-is-threatening-businesses-around-the-world-with-a-new-campaign/?utm_source=rss&utm_medium=rss&utm_campaign=agenttesla-is-threatening-businesses-around-the-world-with-a-new-campaign

Threats:
Agent_tesla

Geo:
Switzerland, Argentina, Italy, Portugal, American, Germany, Romania, America, Spain, France, German

TTPs:
Tactics: 2
Technics: 0

IOCs:
File: 3
Hash: 3
Domain: 1

Softs:
android

Languages:
javascript

Links:
https://github.com/avast/ioc/tree/master/AgentTeslaISOCampaign