#ParsedReport
19-08-2022
Pulling together the pieces to build the puzzle
https://inquest.net/blog/2022/08/18/pulling-together-pieces-build-puzzle
Threats:
Gozi
Procmon_tool
Geo:
Italian
IOCs:
File: 7
Hash: 1
Registry: 1
Algorithms:
7zip , zip
19-08-2022
Pulling together the pieces to build the puzzle
https://inquest.net/blog/2022/08/18/pulling-together-pieces-build-puzzle
Threats:
Gozi
Procmon_tool
Geo:
Italian
IOCs:
File: 7
Hash: 1
Registry: 1
Algorithms:
7zip , zip
inquest.net
Pulling together the pieces to build the puzzle
Follow along through the dissection and analysis of an oddly obfuscated maldoc that ultimately delivers the well-known GOZI ISFB banking trojan.
#technique
https://www.malwarebytes.com/blog/news/2022/08/spying-on-the-spies-see-what-javascript-commands-get-injected-by-an-in-app-browser
https://www.malwarebytes.com/blog/news/2022/08/spying-on-the-spies-see-what-javascript-commands-get-injected-by-an-in-app-browser
Malwarebytes
Spying on the spies. See what JavaScript commands get injected by in-app browsers
A developer and privacy expert created a platform that allows iOS users to see injected JavaScript in their in-app browsers
#ParsedReport
22-08-2022
LockBit Allegedly DDoSed After Leaking Entrusts Data
https://socradar.io/lockbit-is-allegedly-ddosed-after-leaking-entrust-data
Actors/Campaigns:
Blackmatter
Threats:
Lockbit
Sova
Process_injection_technique
Industry:
Financial
Geo:
China, Taiwan
TTPs:
Tactics: 2
Technics: 9
IOCs:
Hash: 13
Platforms:
apple
22-08-2022
LockBit Allegedly DDoSed After Leaking Entrusts Data
https://socradar.io/lockbit-is-allegedly-ddosed-after-leaking-entrust-data
Actors/Campaigns:
Blackmatter
Threats:
Lockbit
Sova
Process_injection_technique
Industry:
Financial
Geo:
China, Taiwan
TTPs:
Tactics: 2
Technics: 9
IOCs:
Hash: 13
Platforms:
apple
SOCRadar® Cyber Intelligence Inc.
LockBit Allegedly DDoSed After Leaking Entrust's Data - SOCRadar
IT security company Entrust suffered a cyberattack on June 18. Attackers gained unauthorized access to the company's network to reach...
#ParsedReport
#technique
22-08-2022
Is Tox The New C&C Method For Coinminers?
https://www.uptycs.com/blog/is-tox-the-new-cc-method-for-coinminers
Threats:
Helloxd
IOCs:
Hash: 1
Softs:
curl, crontab
Functions:
main
Links:
#technique
22-08-2022
Is Tox The New C&C Method For Coinminers?
https://www.uptycs.com/blog/is-tox-the-new-cc-method-for-coinminers
Threats:
Helloxd
IOCs:
Hash: 1
Softs:
curl, crontab
Functions:
main
Links:
https://github.com/irungentoo/toxcore/blob/master/docs/updates/DHT.md
https://github.com/TokTok/c-toxcoreUptycs
Is Tox the New C&C Method for Coinminers?
New discovery by the Uptycs Threat Research Team of peer-to-peer serverless messaging system Tox.
#ParsedReport
22-08-2022
Escanor Malware delivered in Weaponized Microsoft Office Documents
https://resecurity.com/blog/article/escanor-malware-delivered-in-weaponized-microsoft-office-documents
Actors/Campaigns:
Aridviper
Threats:
Escanor_rat
Venomrat
Pandora
Geo:
Israeli, Bahrain, Canada, Kuwait, Singapore, Asia, Egypt, Israel, Mexico
IOCs:
Domain: 1
Softs:
microsoft office, android, telegram
22-08-2022
Escanor Malware delivered in Weaponized Microsoft Office Documents
https://resecurity.com/blog/article/escanor-malware-delivered-in-weaponized-microsoft-office-documents
Actors/Campaigns:
Aridviper
Threats:
Escanor_rat
Venomrat
Pandora
Geo:
Israeli, Bahrain, Canada, Kuwait, Singapore, Asia, Egypt, Israel, Mexico
IOCs:
Domain: 1
Softs:
microsoft office, android, telegram
#ParsedReport
22-08-2022
XCSSET Malware Update \| macOS Threat Actors Prepare for Life Without Python
https://www.sentinelone.com/blog/xcsset-malware-update-macos-threat-actors-prepare-for-life-without-python
Threats:
Xcsset
Xcssset
Applescript
Industry:
Financial
Geo:
Chinese, China
IOCs:
Hash: 37
File: 7
Domain: 8
Softs:
chrome, macos, opera, telegram, wechat
Functions:
check_loop, runme
Languages:
python
Platforms:
apple
Links:
22-08-2022
XCSSET Malware Update \| macOS Threat Actors Prepare for Life Without Python
https://www.sentinelone.com/blog/xcsset-malware-update-macos-threat-actors-prepare-for-life-without-python
Threats:
Xcsset
Xcssset
Applescript
Industry:
Financial
Geo:
Chinese, China
IOCs:
Hash: 37
File: 7
Domain: 8
Softs:
chrome, macos, opera, telegram, wechat
Functions:
check_loop, runme
Languages:
python
Platforms:
apple
Links:
https://github.com/ydkhatri/mac\_apt/blob/master/plugins/notes.pyhttps://github.com/neurobin/shcSentinelOne
XCSSET Malware Update | macOS Threat Actors Prepare for Life Without Python
New domains and new behavioral indicators, but malware authors stick to tried and tested architecture despite Apple’s updates.
#ParsedReport
22-08-2022
Anatomy of a Solidbit Ransomware Attack
https://www.varonis.com/blog/anatomy-of-a-solidbit-ransomware-attack
Threats:
Solidbit
Lockbit
Yashma
Deepsea_obfuscator_tool
Chaos
Redline_stealer
Teamviewer_tool
Industry:
Financial
Geo:
Israeli, Syria
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 14
Softs:
telegram, windows service, windows registry, defwatch, microsoft visual studio
Algorithms:
aes-256, cbc
Platforms:
x86, intel
22-08-2022
Anatomy of a Solidbit Ransomware Attack
https://www.varonis.com/blog/anatomy-of-a-solidbit-ransomware-attack
Threats:
Solidbit
Lockbit
Yashma
Deepsea_obfuscator_tool
Chaos
Redline_stealer
Teamviewer_tool
Industry:
Financial
Geo:
Israeli, Syria
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 14
Softs:
telegram, windows service, windows registry, defwatch, microsoft visual studio
Algorithms:
aes-256, cbc
Platforms:
x86, intel
Varonis
Anatomy of a SolidBit Ransomware Attack
Solidbit is a ransomware variant derived from Yashma and containing elements of LockBit. Discover how Solidbit's capabilities, execution, what file types it targets, and how to tell if you're been infected.
#ParsedReport
23-08-2022
New Iranian APT data extraction tool
https://blog.google/threat-analysis-group/new-iranian-apt-data-extraction-tool
Actors/Campaigns:
Cleaver (motivation: government_sponsored)
Threats:
Hyperscrape_tool
Pwcs_tool
Industry:
Government
Geo:
Iran, Iranian
IOCs:
File: 14
IP: 2
Hash: 9
Path: 2
Softs:
microsoft outlook, telegram
Algorithms:
crc, gzip, base64
Functions:
ManageTakeOut, IsThereAnyEMail
Languages:
php
23-08-2022
New Iranian APT data extraction tool
https://blog.google/threat-analysis-group/new-iranian-apt-data-extraction-tool
Actors/Campaigns:
Cleaver (motivation: government_sponsored)
Threats:
Hyperscrape_tool
Pwcs_tool
Industry:
Government
Geo:
Iran, Iranian
IOCs:
File: 14
IP: 2
Hash: 9
Path: 2
Softs:
microsoft outlook, telegram
Algorithms:
crc, gzip, base64
Functions:
ManageTakeOut, IsThereAnyEMail
Languages:
php
Google
New Iranian APT data extraction tool
As part of TAG's mission to counter serious threats to Google and our users, we've analyzed a range of persistent threats including APT35 and Charming Kitten, …
#ParsedReport
23-08-2022
Dissecting IBAN Clipper
https://blog.cyble.com/2022/08/22/dissecting-iban-clipper
Threats:
Iban_clipper
Beacon
Industry:
Financial
Geo:
Singapore, India, Australia, Georgia, Dubai
TTPs:
Tactics: 6
Technics: 9
IOCs:
File: 2
Hash: 1
Softs:
microsoft store
Functions:
getexecutingassembly
23-08-2022
Dissecting IBAN Clipper
https://blog.cyble.com/2022/08/22/dissecting-iban-clipper
Threats:
Iban_clipper
Beacon
Industry:
Financial
Geo:
Singapore, India, Australia, Georgia, Dubai
TTPs:
Tactics: 6
Technics: 9
IOCs:
File: 2
Hash: 1
Softs:
microsoft store
Functions:
getexecutingassembly
#ParsedReport
23-08-2022
THREAT ALERT: HavanaCrypt Ransomware Masquerading as Google Update
https://www.cybereason.com/blog/threat-alert-havanacrypt-ransomware-masquerading-as-google-update
Threats:
Havanacrypt
Industry:
Government
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 2
File: 7
IP: 1
Path: 1
Softs:
thebat, keepass, onenote, defwatch, dbsnmp, windows defender, microsoft word, thebat64, sqlagent, vssadmin, mssql, google chrome, powerpnt, wordpad, sqlbrowser, encsvc
Algorithms:
aes
Languages:
php
Links:
23-08-2022
THREAT ALERT: HavanaCrypt Ransomware Masquerading as Google Update
https://www.cybereason.com/blog/threat-alert-havanacrypt-ransomware-masquerading-as-google-update
Threats:
Havanacrypt
Industry:
Government
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 2
File: 7
IP: 1
Path: 1
Softs:
thebat, keepass, onenote, defwatch, dbsnmp, windows defender, microsoft word, thebat64, sqlagent, vssadmin, mssql, google chrome, powerpnt, wordpad, sqlbrowser, encsvc
Algorithms:
aes
Languages:
php
Links:
https://github.com/obfuscar/obfuscarCybereason
THREAT ALERT: HavanaCrypt Ransomware Masquerading as Google Update
First observed in June 2022 in the wild, HavanaCrypt Ransomware masquerades as a legitimate Google Chrome update with sophisticated anti-analysis techniques and other functionality that may be used for data exfiltration and privilege escalation...
#ParsedReport
23-08-2022
Exploring the QBOT Attack Pattern. Key Takeaways
https://www.elastic.co/security-labs/exploring-the-qbot-attack-pattern
Threats:
Qakbot
Seth_locker
Emotet
Geo:
Kyrgyzstan, Turkmenistan, Armenia, Uzbekistan, Tajikistan, Belarus, Russia, Georgia, Kazakhstan, Ukraine
TTPs:
Tactics: 5
Technics: 0
IOCs:
Domain: 2
Url: 1
Path: 7
File: 9
Hash: 1
Registry: 4
Softs:
windows registry, microsoft office, docker, curl, windows defender, kibana
Algorithms:
zip
YARA: Found
Links:
23-08-2022
Exploring the QBOT Attack Pattern. Key Takeaways
https://www.elastic.co/security-labs/exploring-the-qbot-attack-pattern
Threats:
Qakbot
Seth_locker
Emotet
Geo:
Kyrgyzstan, Turkmenistan, Armenia, Uzbekistan, Tajikistan, Belarus, Russia, Georgia, Kazakhstan, Ukraine
TTPs:
Tactics: 5
Technics: 0
IOCs:
Domain: 2
Url: 1
Path: 7
File: 9
Hash: 1
Registry: 4
Softs:
windows registry, microsoft office, docker, curl, windows defender, kibana
Algorithms:
zip
YARA: Found
Links:
https://github.com/drole/qakbot-registry-decrypthttps://github.com/ipinfo/clihttps://github.com/peasead/elastic-containerwww.elastic.co
Exploring the QBOT Attack Pattern — Elastic Security Labs
In this research publication, we'll explore our analysis of the QBOT attack pattern — a full-featured and prolific malware family.
#ParsedReport
23-08-2022
A Tale of PivNoxy and Chinoxy Puppeteer
https://www.fortinet.com/blog/threat-research/pivnoxy-and-chinoxy-puppeteer-analysis
Actors/Campaigns:
Nightscout
Fakeupdates
Shell_crew
Threats:
Pivnoxy_dropper
Chinoxy_dropper
Velar
Cannon
Poison_ivy
Plugx_rat
Noxplayer
Funnydream
Kryptik_trojan
W32/injector.kr!tr
W32/rekvex.iy!tr
W32/agent.bjwzyi!tr
Sanny
Renos
W32/zuguo.a!tr
W32/agent.smc!tr
W32/generik.cijixom!tr
W32/injector.smc!tr
W32/rekvex.johugye!tr
W32/agent.adwj!tr
Process_injection_technique
Industry:
Government, Telco
Geo:
Ukraine, Vietnam, Chinese, Pakistan, Asia, Kirghizstan, India, Israel, France, Asian, Mexico
CVEs:
CVE-2018-0802 [Vulners]
Vulners: Score: 9.3, CVSS: 3.5,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2007, 2013, 2016, 2010, 2016)
- microsoft word (2013, 2007, 2010, 2013, 2016)
- microsoft office compatibility pack (-)
CVE-2017-11882 [Vulners]
Vulners: Score: 9.3, CVSS: 4.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2013, 2010, 2016, 2007)
CVE-2018-0798 [Vulners]
Vulners: Score: 9.3, CVSS: 3.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2010, 2016, 2016, 2007, 2013)
- microsoft word (2013, 2016, 2007, 2010, 2013)
- microsoft office compatibility pack (-)
TTPs:
Tactics: 11
Technics: 0
IOCs:
File: 7
Domain: 10
Hash: 47
Softs:
microsoft word, android, windows service
Algorithms:
base64
Functions:
LGBT_Launch
23-08-2022
A Tale of PivNoxy and Chinoxy Puppeteer
https://www.fortinet.com/blog/threat-research/pivnoxy-and-chinoxy-puppeteer-analysis
Actors/Campaigns:
Nightscout
Fakeupdates
Shell_crew
Threats:
Pivnoxy_dropper
Chinoxy_dropper
Velar
Cannon
Poison_ivy
Plugx_rat
Noxplayer
Funnydream
Kryptik_trojan
W32/injector.kr!tr
W32/rekvex.iy!tr
W32/agent.bjwzyi!tr
Sanny
Renos
W32/zuguo.a!tr
W32/agent.smc!tr
W32/generik.cijixom!tr
W32/injector.smc!tr
W32/rekvex.johugye!tr
W32/agent.adwj!tr
Process_injection_technique
Industry:
Government, Telco
Geo:
Ukraine, Vietnam, Chinese, Pakistan, Asia, Kirghizstan, India, Israel, France, Asian, Mexico
CVEs:
CVE-2018-0802 [Vulners]
Vulners: Score: 9.3, CVSS: 3.5,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2007, 2013, 2016, 2010, 2016)
- microsoft word (2013, 2007, 2010, 2013, 2016)
- microsoft office compatibility pack (-)
CVE-2017-11882 [Vulners]
Vulners: Score: 9.3, CVSS: 4.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2013, 2010, 2016, 2007)
CVE-2018-0798 [Vulners]
Vulners: Score: 9.3, CVSS: 3.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2010, 2016, 2016, 2007, 2013)
- microsoft word (2013, 2016, 2007, 2010, 2013)
- microsoft office compatibility pack (-)
TTPs:
Tactics: 11
Technics: 0
IOCs:
File: 7
Domain: 10
Hash: 47
Softs:
microsoft word, android, windows service
Algorithms:
base64
Functions:
LGBT_Launch
Fortinet Blog
A Tale of PivNoxy and Chinoxy Puppeteer
FortiGuard Labs discovered an email with a suspicious RTF attachment sent to a telecommunications agency that delivered a PivNoxy malware. Read our blog to learn how the attack works and the techni…
#ParsedReport
23-08-2022
Venom ControlRAT With a Sting
https://cyberint.com/blog/research/venom-control-rat-with-a-sting
Actors/Campaigns:
Atlantis_cyberarmy
Threats:
Control_rat
Venomrat
Sbit_rat
Bratarat
Industry:
Financial
Softs:
telegram, chrome, opera, windows defender
23-08-2022
Venom ControlRAT With a Sting
https://cyberint.com/blog/research/venom-control-rat-with-a-sting
Actors/Campaigns:
Atlantis_cyberarmy
Threats:
Control_rat
Venomrat
Sbit_rat
Bratarat
Industry:
Financial
Softs:
telegram, chrome, opera, windows defender
#ParsedReport
23-08-2022
Reversing Golang Developed Ransomware: SNAKE. Introduction
https://www.0ffset.net/reverse-engineering/analysing-snake-ransomware/?utm_source=rss&utm_medium=rss&utm_campaign=analysing-snake-ransomware
Threats:
Snake_ransomware
Snakehose
IOCs:
Hash: 1
File: 19
IP: 1
Path: 1
Email: 1
Softs:
bootnxt, windows firewall
Algorithms:
xor, aes, rsa-2048
Functions:
WriteAt, LazyDLL, OpenService, OpenServiceW, CoInitializeEx, OpenSCManagerA, OpenProcess, DeleteInstance, main
Languages:
python, golang
Links:
23-08-2022
Reversing Golang Developed Ransomware: SNAKE. Introduction
https://www.0ffset.net/reverse-engineering/analysing-snake-ransomware/?utm_source=rss&utm_medium=rss&utm_campaign=analysing-snake-ransomware
Threats:
Snake_ransomware
Snakehose
IOCs:
Hash: 1
File: 19
IP: 1
Path: 1
Email: 1
Softs:
bootnxt, windows firewall
Algorithms:
xor, aes, rsa-2048
Functions:
WriteAt, LazyDLL, OpenService, OpenServiceW, CoInitializeEx, OpenSCManagerA, OpenProcess, DeleteInstance, main
Languages:
python, golang
Links:
https://github.com/unixpickle/gobfuscate0ffset Training Solutions | Practical and Affordable Cyber Security Training
Reversing Golang Developed Ransomware: SNAKE | 0ffset Training Solutions
Introduction Snake Ransomware (or EKANS Ransomware) is a Golang ransomware which in the past has affected several companies such as Enel and Honda. The MD5 hashing of the analyzed sample is ED3C05BDE9F0EA0F1321355B03AC42D0. This sample in particular is obfuscated…
#ParsedReport
23-08-2022
Get a demo. Emotet Resurgence: Cross-Industry Campaign Analysis
https://darktrace.com/blog/emotet-resurgence-cross-industry-campaign-analysis
Threats:
Emotet
Trickbot
Ryuk
Cobalt_strike
Beacon
Industry:
Telco, Healthcare
Geo:
London, Japanese
IOCs:
Domain: 3
File: 7
Hash: 5
Softs:
microsoft outlook
Algorithms:
ecc, zip , gzip
Platforms:
intel
23-08-2022
Get a demo. Emotet Resurgence: Cross-Industry Campaign Analysis
https://darktrace.com/blog/emotet-resurgence-cross-industry-campaign-analysis
Threats:
Emotet
Trickbot
Ryuk
Cobalt_strike
Beacon
Industry:
Telco, Healthcare
Geo:
London, Japanese
IOCs:
Domain: 3
File: 7
Hash: 5
Softs:
microsoft outlook
Algorithms:
ecc, zip , gzip
Platforms:
intel
Darktrace
Emotet Resurgence: Cross-Industry Analysis | Darktrace Blog
Technical insights on the Emotet resurgence in 2022 across various client environments, industries, and regions.
#ParsedReport
24-08-2022
BitRAT and XMRig CoinMiner Being Distributed via Windows License Verification Tool
https://asec.ahnlab.com/en/37939
Threats:
Sbit_rat
Xmrig_miner
Trojan/win.generic.c5223158
Malware/mdp.download.m1197
Malware/mdp.drivebydownload.m1298
Geo:
Korean
IOCs:
File: 9
Path: 1
Domain: 1
Hash: 4
Url: 3
IP: 1
Softs:
google chrome, windows defender, telegram
24-08-2022
BitRAT and XMRig CoinMiner Being Distributed via Windows License Verification Tool
https://asec.ahnlab.com/en/37939
Threats:
Sbit_rat
Xmrig_miner
Trojan/win.generic.c5223158
Malware/mdp.download.m1197
Malware/mdp.drivebydownload.m1298
Geo:
Korean
IOCs:
File: 9
Path: 1
Domain: 1
Hash: 4
Url: 3
IP: 1
Softs:
google chrome, windows defender, telegram
ASEC BLOG
BitRAT and XMRig CoinMiner Being Distributed via Windows License Verification Tool - ASEC BLOG
The ASEC analysis team has recently discovered the distribution of BitRAT and XMRig CoinMiner disguised as a Windows license verification tool. As introduced in previous posts, BitRAT has a history of being distributed on webhards as MS Windows license verification…
#ParsedReport
24-08-2022
AsyncRAT Being Distributed in Fileless Form
https://asec.ahnlab.com/en/37954
Threats:
Asyncrat_rat
Trojan/vbs.runner
IOCs:
File: 8
Path: 9
Url: 1
Domain: 1
Hash: 11
Softs:
task scheduler
24-08-2022
AsyncRAT Being Distributed in Fileless Form
https://asec.ahnlab.com/en/37954
Threats:
Asyncrat_rat
Trojan/vbs.runner
IOCs:
File: 8
Path: 9
Url: 1
Domain: 1
Hash: 11
Softs:
task scheduler
ASEC BLOG
AsyncRAT Being Distributed in Fileless Form - ASEC BLOG
The ASEC analysis team has recently discovered that malicious AsyncRAT codes are being distributed in fileless form. The distributed AsyncRAT is executed in fileless form through multiple script files and is thought to be distributed as a compressed file…
#ParsedReport
24-08-2022
AgentTesla is threatening businesses around the world with a new campaign
https://decoded.avast.io/pavelnovak/agenttesla-is-threatening-businesses-around-the-world-with-a-new-campaign/?utm_source=rss&utm_medium=rss&utm_campaign=agenttesla-is-threatening-businesses-around-the-world-with-a-new-campaign
Threats:
Agent_tesla
Geo:
Switzerland, Argentina, Italy, Portugal, American, Germany, Romania, America, Spain, France, German
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 3
Hash: 3
Domain: 1
Softs:
android
Languages:
javascript
Links:
24-08-2022
AgentTesla is threatening businesses around the world with a new campaign
https://decoded.avast.io/pavelnovak/agenttesla-is-threatening-businesses-around-the-world-with-a-new-campaign/?utm_source=rss&utm_medium=rss&utm_campaign=agenttesla-is-threatening-businesses-around-the-world-with-a-new-campaign
Threats:
Agent_tesla
Geo:
Switzerland, Argentina, Italy, Portugal, American, Germany, Romania, America, Spain, France, German
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 3
Hash: 3
Domain: 1
Softs:
android
Languages:
javascript
Links:
https://github.com/avast/ioc/tree/master/AgentTeslaISOCampaignAvast Threat Labs
AgentTesla is threatening businesses around the world with a new campaign - Avast Threat Labs
A new campaign targeting businesses in Europe and South America is making its rounds, spreading the information stealer, AgentTesla, via spoofed phishing emails.
#ParsedReport
24-08-2022
Ransomware updates & 1-day exploits
https://securelist.com/ransomware-updates-1-day-exploits/107291
Threats:
Redalert
Monster
Industry:
Financial, Retail
Geo:
Indonesia, Singapore, Bolivia, Apac
CVEs:
CVE-2022-24521 [Vulners]
Vulners: Score: 4.6, CVSS: 4.2,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (-, 20h2, 21h1, 21h2, 1607, 1809, 1909)
- microsoft windows 11 (-, -)
- microsoft windows 7 (-)
- microsoft windows 8.1 (-)
- microsoft windows rt 8.1 (-)
have more...
Softs:
esxi
Algorithms:
aes
Languages:
rust, delphi
YARA: Found
24-08-2022
Ransomware updates & 1-day exploits
https://securelist.com/ransomware-updates-1-day-exploits/107291
Threats:
Redalert
Monster
Industry:
Financial, Retail
Geo:
Indonesia, Singapore, Bolivia, Apac
CVEs:
CVE-2022-24521 [Vulners]
Vulners: Score: 4.6, CVSS: 4.2,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (-, 20h2, 21h1, 21h2, 1607, 1809, 1909)
- microsoft windows 11 (-, -)
- microsoft windows 7 (-)
- microsoft windows 8.1 (-)
- microsoft windows rt 8.1 (-)
have more...
Softs:
esxi
Algorithms:
aes
Languages:
rust, delphi
YARA: Found
Securelist
Kaspersky crimeware report: new ransomware and 1-day exploits
In this report, we discuss the new multi-platform ransomware RedAlert (aka N13V) and Monster, as well as private 1-day exploits for the CVE-2022-24521 vulnerability.
#ParsedReport
24-08-2022
Ransomware Actor Abuses Genshin Impact Anti-Cheat Driver to Kill Antivirus
https://www.trendmicro.com/en_us/research/22/h/ransomware-actor-abuses-genshin-impact-anti-cheat-driver-to-kill-antivirus.html
Threats:
Fire_chili_rootkit
Fivesys
Impacket_tool
Industry:
Entertainment
IOCs:
File: 10
Hash: 1
Softs:
psexec, windows installer
Functions:
NtOpenFile, ZwTerminateProcess
Languages:
python
Links:
24-08-2022
Ransomware Actor Abuses Genshin Impact Anti-Cheat Driver to Kill Antivirus
https://www.trendmicro.com/en_us/research/22/h/ransomware-actor-abuses-genshin-impact-anti-cheat-driver-to-kill-antivirus.html
Threats:
Fire_chili_rootkit
Fivesys
Impacket_tool
Industry:
Entertainment
IOCs:
File: 10
Hash: 1
Softs:
psexec, windows installer
Functions:
NtOpenFile, ZwTerminateProcess
Languages:
python
Links:
https://github.com/kagurazakasanae/Mhyprot2DrvControlhttps://github.com/kkent030315/evil-mhyprot-clihttps://github.com/SecureAuthCorp/impacket/blob/impacket\_0\_10\_0/examples/wmiexec.pyhttps://github.com/SecureAuthCorp/impacket/blob/master/examples/secretsdump.pyhttps://github.com/kkent030315Trend Micro
Ransomware Actor Abuses Genshin Impact Anti-Cheat Driver to Kill Antivirus
We investigate mhyprot2.sys, a vulnerable anti-cheat driver for the popular role-playing game Genshin Impact. The driver is currently being abused by a ransomware actor to kill antivirus processes and services for mass-deploying ransomware.