#ParsedReport
23-08-2022
New Iranian APT data extraction tool
https://blog.google/threat-analysis-group/new-iranian-apt-data-extraction-tool
Actors/Campaigns:
Cleaver (motivation: government_sponsored)
Threats:
Hyperscrape_tool
Pwcs_tool
Industry:
Government
Geo:
Iran, Iranian
IOCs:
File: 14
IP: 2
Hash: 9
Path: 2
Softs:
microsoft outlook, telegram
Algorithms:
crc, gzip, base64
Functions:
ManageTakeOut, IsThereAnyEMail
Languages:
php
23-08-2022
New Iranian APT data extraction tool
https://blog.google/threat-analysis-group/new-iranian-apt-data-extraction-tool
Actors/Campaigns:
Cleaver (motivation: government_sponsored)
Threats:
Hyperscrape_tool
Pwcs_tool
Industry:
Government
Geo:
Iran, Iranian
IOCs:
File: 14
IP: 2
Hash: 9
Path: 2
Softs:
microsoft outlook, telegram
Algorithms:
crc, gzip, base64
Functions:
ManageTakeOut, IsThereAnyEMail
Languages:
php
Google
New Iranian APT data extraction tool
As part of TAG's mission to counter serious threats to Google and our users, we've analyzed a range of persistent threats including APT35 and Charming Kitten, …
#ParsedReport
23-08-2022
Dissecting IBAN Clipper
https://blog.cyble.com/2022/08/22/dissecting-iban-clipper
Threats:
Iban_clipper
Beacon
Industry:
Financial
Geo:
Singapore, India, Australia, Georgia, Dubai
TTPs:
Tactics: 6
Technics: 9
IOCs:
File: 2
Hash: 1
Softs:
microsoft store
Functions:
getexecutingassembly
23-08-2022
Dissecting IBAN Clipper
https://blog.cyble.com/2022/08/22/dissecting-iban-clipper
Threats:
Iban_clipper
Beacon
Industry:
Financial
Geo:
Singapore, India, Australia, Georgia, Dubai
TTPs:
Tactics: 6
Technics: 9
IOCs:
File: 2
Hash: 1
Softs:
microsoft store
Functions:
getexecutingassembly
#ParsedReport
23-08-2022
THREAT ALERT: HavanaCrypt Ransomware Masquerading as Google Update
https://www.cybereason.com/blog/threat-alert-havanacrypt-ransomware-masquerading-as-google-update
Threats:
Havanacrypt
Industry:
Government
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 2
File: 7
IP: 1
Path: 1
Softs:
thebat, keepass, onenote, defwatch, dbsnmp, windows defender, microsoft word, thebat64, sqlagent, vssadmin, mssql, google chrome, powerpnt, wordpad, sqlbrowser, encsvc
Algorithms:
aes
Languages:
php
Links:
23-08-2022
THREAT ALERT: HavanaCrypt Ransomware Masquerading as Google Update
https://www.cybereason.com/blog/threat-alert-havanacrypt-ransomware-masquerading-as-google-update
Threats:
Havanacrypt
Industry:
Government
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 2
File: 7
IP: 1
Path: 1
Softs:
thebat, keepass, onenote, defwatch, dbsnmp, windows defender, microsoft word, thebat64, sqlagent, vssadmin, mssql, google chrome, powerpnt, wordpad, sqlbrowser, encsvc
Algorithms:
aes
Languages:
php
Links:
https://github.com/obfuscar/obfuscarCybereason
THREAT ALERT: HavanaCrypt Ransomware Masquerading as Google Update
First observed in June 2022 in the wild, HavanaCrypt Ransomware masquerades as a legitimate Google Chrome update with sophisticated anti-analysis techniques and other functionality that may be used for data exfiltration and privilege escalation...
#ParsedReport
23-08-2022
Exploring the QBOT Attack Pattern. Key Takeaways
https://www.elastic.co/security-labs/exploring-the-qbot-attack-pattern
Threats:
Qakbot
Seth_locker
Emotet
Geo:
Kyrgyzstan, Turkmenistan, Armenia, Uzbekistan, Tajikistan, Belarus, Russia, Georgia, Kazakhstan, Ukraine
TTPs:
Tactics: 5
Technics: 0
IOCs:
Domain: 2
Url: 1
Path: 7
File: 9
Hash: 1
Registry: 4
Softs:
windows registry, microsoft office, docker, curl, windows defender, kibana
Algorithms:
zip
YARA: Found
Links:
23-08-2022
Exploring the QBOT Attack Pattern. Key Takeaways
https://www.elastic.co/security-labs/exploring-the-qbot-attack-pattern
Threats:
Qakbot
Seth_locker
Emotet
Geo:
Kyrgyzstan, Turkmenistan, Armenia, Uzbekistan, Tajikistan, Belarus, Russia, Georgia, Kazakhstan, Ukraine
TTPs:
Tactics: 5
Technics: 0
IOCs:
Domain: 2
Url: 1
Path: 7
File: 9
Hash: 1
Registry: 4
Softs:
windows registry, microsoft office, docker, curl, windows defender, kibana
Algorithms:
zip
YARA: Found
Links:
https://github.com/drole/qakbot-registry-decrypthttps://github.com/ipinfo/clihttps://github.com/peasead/elastic-containerwww.elastic.co
Exploring the QBOT Attack Pattern — Elastic Security Labs
In this research publication, we'll explore our analysis of the QBOT attack pattern — a full-featured and prolific malware family.
#ParsedReport
23-08-2022
A Tale of PivNoxy and Chinoxy Puppeteer
https://www.fortinet.com/blog/threat-research/pivnoxy-and-chinoxy-puppeteer-analysis
Actors/Campaigns:
Nightscout
Fakeupdates
Shell_crew
Threats:
Pivnoxy_dropper
Chinoxy_dropper
Velar
Cannon
Poison_ivy
Plugx_rat
Noxplayer
Funnydream
Kryptik_trojan
W32/injector.kr!tr
W32/rekvex.iy!tr
W32/agent.bjwzyi!tr
Sanny
Renos
W32/zuguo.a!tr
W32/agent.smc!tr
W32/generik.cijixom!tr
W32/injector.smc!tr
W32/rekvex.johugye!tr
W32/agent.adwj!tr
Process_injection_technique
Industry:
Government, Telco
Geo:
Ukraine, Vietnam, Chinese, Pakistan, Asia, Kirghizstan, India, Israel, France, Asian, Mexico
CVEs:
CVE-2018-0802 [Vulners]
Vulners: Score: 9.3, CVSS: 3.5,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2007, 2013, 2016, 2010, 2016)
- microsoft word (2013, 2007, 2010, 2013, 2016)
- microsoft office compatibility pack (-)
CVE-2017-11882 [Vulners]
Vulners: Score: 9.3, CVSS: 4.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2013, 2010, 2016, 2007)
CVE-2018-0798 [Vulners]
Vulners: Score: 9.3, CVSS: 3.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2010, 2016, 2016, 2007, 2013)
- microsoft word (2013, 2016, 2007, 2010, 2013)
- microsoft office compatibility pack (-)
TTPs:
Tactics: 11
Technics: 0
IOCs:
File: 7
Domain: 10
Hash: 47
Softs:
microsoft word, android, windows service
Algorithms:
base64
Functions:
LGBT_Launch
23-08-2022
A Tale of PivNoxy and Chinoxy Puppeteer
https://www.fortinet.com/blog/threat-research/pivnoxy-and-chinoxy-puppeteer-analysis
Actors/Campaigns:
Nightscout
Fakeupdates
Shell_crew
Threats:
Pivnoxy_dropper
Chinoxy_dropper
Velar
Cannon
Poison_ivy
Plugx_rat
Noxplayer
Funnydream
Kryptik_trojan
W32/injector.kr!tr
W32/rekvex.iy!tr
W32/agent.bjwzyi!tr
Sanny
Renos
W32/zuguo.a!tr
W32/agent.smc!tr
W32/generik.cijixom!tr
W32/injector.smc!tr
W32/rekvex.johugye!tr
W32/agent.adwj!tr
Process_injection_technique
Industry:
Government, Telco
Geo:
Ukraine, Vietnam, Chinese, Pakistan, Asia, Kirghizstan, India, Israel, France, Asian, Mexico
CVEs:
CVE-2018-0802 [Vulners]
Vulners: Score: 9.3, CVSS: 3.5,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2007, 2013, 2016, 2010, 2016)
- microsoft word (2013, 2007, 2010, 2013, 2016)
- microsoft office compatibility pack (-)
CVE-2017-11882 [Vulners]
Vulners: Score: 9.3, CVSS: 4.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2013, 2010, 2016, 2007)
CVE-2018-0798 [Vulners]
Vulners: Score: 9.3, CVSS: 3.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2010, 2016, 2016, 2007, 2013)
- microsoft word (2013, 2016, 2007, 2010, 2013)
- microsoft office compatibility pack (-)
TTPs:
Tactics: 11
Technics: 0
IOCs:
File: 7
Domain: 10
Hash: 47
Softs:
microsoft word, android, windows service
Algorithms:
base64
Functions:
LGBT_Launch
Fortinet Blog
A Tale of PivNoxy and Chinoxy Puppeteer
FortiGuard Labs discovered an email with a suspicious RTF attachment sent to a telecommunications agency that delivered a PivNoxy malware. Read our blog to learn how the attack works and the techni…
#ParsedReport
23-08-2022
Venom ControlRAT With a Sting
https://cyberint.com/blog/research/venom-control-rat-with-a-sting
Actors/Campaigns:
Atlantis_cyberarmy
Threats:
Control_rat
Venomrat
Sbit_rat
Bratarat
Industry:
Financial
Softs:
telegram, chrome, opera, windows defender
23-08-2022
Venom ControlRAT With a Sting
https://cyberint.com/blog/research/venom-control-rat-with-a-sting
Actors/Campaigns:
Atlantis_cyberarmy
Threats:
Control_rat
Venomrat
Sbit_rat
Bratarat
Industry:
Financial
Softs:
telegram, chrome, opera, windows defender
#ParsedReport
23-08-2022
Reversing Golang Developed Ransomware: SNAKE. Introduction
https://www.0ffset.net/reverse-engineering/analysing-snake-ransomware/?utm_source=rss&utm_medium=rss&utm_campaign=analysing-snake-ransomware
Threats:
Snake_ransomware
Snakehose
IOCs:
Hash: 1
File: 19
IP: 1
Path: 1
Email: 1
Softs:
bootnxt, windows firewall
Algorithms:
xor, aes, rsa-2048
Functions:
WriteAt, LazyDLL, OpenService, OpenServiceW, CoInitializeEx, OpenSCManagerA, OpenProcess, DeleteInstance, main
Languages:
python, golang
Links:
23-08-2022
Reversing Golang Developed Ransomware: SNAKE. Introduction
https://www.0ffset.net/reverse-engineering/analysing-snake-ransomware/?utm_source=rss&utm_medium=rss&utm_campaign=analysing-snake-ransomware
Threats:
Snake_ransomware
Snakehose
IOCs:
Hash: 1
File: 19
IP: 1
Path: 1
Email: 1
Softs:
bootnxt, windows firewall
Algorithms:
xor, aes, rsa-2048
Functions:
WriteAt, LazyDLL, OpenService, OpenServiceW, CoInitializeEx, OpenSCManagerA, OpenProcess, DeleteInstance, main
Languages:
python, golang
Links:
https://github.com/unixpickle/gobfuscate0ffset Training Solutions | Practical and Affordable Cyber Security Training
Reversing Golang Developed Ransomware: SNAKE | 0ffset Training Solutions
Introduction Snake Ransomware (or EKANS Ransomware) is a Golang ransomware which in the past has affected several companies such as Enel and Honda. The MD5 hashing of the analyzed sample is ED3C05BDE9F0EA0F1321355B03AC42D0. This sample in particular is obfuscated…
#ParsedReport
23-08-2022
Get a demo. Emotet Resurgence: Cross-Industry Campaign Analysis
https://darktrace.com/blog/emotet-resurgence-cross-industry-campaign-analysis
Threats:
Emotet
Trickbot
Ryuk
Cobalt_strike
Beacon
Industry:
Telco, Healthcare
Geo:
London, Japanese
IOCs:
Domain: 3
File: 7
Hash: 5
Softs:
microsoft outlook
Algorithms:
ecc, zip , gzip
Platforms:
intel
23-08-2022
Get a demo. Emotet Resurgence: Cross-Industry Campaign Analysis
https://darktrace.com/blog/emotet-resurgence-cross-industry-campaign-analysis
Threats:
Emotet
Trickbot
Ryuk
Cobalt_strike
Beacon
Industry:
Telco, Healthcare
Geo:
London, Japanese
IOCs:
Domain: 3
File: 7
Hash: 5
Softs:
microsoft outlook
Algorithms:
ecc, zip , gzip
Platforms:
intel
Darktrace
Emotet Resurgence: Cross-Industry Analysis | Darktrace Blog
Technical insights on the Emotet resurgence in 2022 across various client environments, industries, and regions.
#ParsedReport
24-08-2022
BitRAT and XMRig CoinMiner Being Distributed via Windows License Verification Tool
https://asec.ahnlab.com/en/37939
Threats:
Sbit_rat
Xmrig_miner
Trojan/win.generic.c5223158
Malware/mdp.download.m1197
Malware/mdp.drivebydownload.m1298
Geo:
Korean
IOCs:
File: 9
Path: 1
Domain: 1
Hash: 4
Url: 3
IP: 1
Softs:
google chrome, windows defender, telegram
24-08-2022
BitRAT and XMRig CoinMiner Being Distributed via Windows License Verification Tool
https://asec.ahnlab.com/en/37939
Threats:
Sbit_rat
Xmrig_miner
Trojan/win.generic.c5223158
Malware/mdp.download.m1197
Malware/mdp.drivebydownload.m1298
Geo:
Korean
IOCs:
File: 9
Path: 1
Domain: 1
Hash: 4
Url: 3
IP: 1
Softs:
google chrome, windows defender, telegram
ASEC BLOG
BitRAT and XMRig CoinMiner Being Distributed via Windows License Verification Tool - ASEC BLOG
The ASEC analysis team has recently discovered the distribution of BitRAT and XMRig CoinMiner disguised as a Windows license verification tool. As introduced in previous posts, BitRAT has a history of being distributed on webhards as MS Windows license verification…
#ParsedReport
24-08-2022
AsyncRAT Being Distributed in Fileless Form
https://asec.ahnlab.com/en/37954
Threats:
Asyncrat_rat
Trojan/vbs.runner
IOCs:
File: 8
Path: 9
Url: 1
Domain: 1
Hash: 11
Softs:
task scheduler
24-08-2022
AsyncRAT Being Distributed in Fileless Form
https://asec.ahnlab.com/en/37954
Threats:
Asyncrat_rat
Trojan/vbs.runner
IOCs:
File: 8
Path: 9
Url: 1
Domain: 1
Hash: 11
Softs:
task scheduler
ASEC BLOG
AsyncRAT Being Distributed in Fileless Form - ASEC BLOG
The ASEC analysis team has recently discovered that malicious AsyncRAT codes are being distributed in fileless form. The distributed AsyncRAT is executed in fileless form through multiple script files and is thought to be distributed as a compressed file…
#ParsedReport
24-08-2022
AgentTesla is threatening businesses around the world with a new campaign
https://decoded.avast.io/pavelnovak/agenttesla-is-threatening-businesses-around-the-world-with-a-new-campaign/?utm_source=rss&utm_medium=rss&utm_campaign=agenttesla-is-threatening-businesses-around-the-world-with-a-new-campaign
Threats:
Agent_tesla
Geo:
Switzerland, Argentina, Italy, Portugal, American, Germany, Romania, America, Spain, France, German
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 3
Hash: 3
Domain: 1
Softs:
android
Languages:
javascript
Links:
24-08-2022
AgentTesla is threatening businesses around the world with a new campaign
https://decoded.avast.io/pavelnovak/agenttesla-is-threatening-businesses-around-the-world-with-a-new-campaign/?utm_source=rss&utm_medium=rss&utm_campaign=agenttesla-is-threatening-businesses-around-the-world-with-a-new-campaign
Threats:
Agent_tesla
Geo:
Switzerland, Argentina, Italy, Portugal, American, Germany, Romania, America, Spain, France, German
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 3
Hash: 3
Domain: 1
Softs:
android
Languages:
javascript
Links:
https://github.com/avast/ioc/tree/master/AgentTeslaISOCampaignAvast Threat Labs
AgentTesla is threatening businesses around the world with a new campaign - Avast Threat Labs
A new campaign targeting businesses in Europe and South America is making its rounds, spreading the information stealer, AgentTesla, via spoofed phishing emails.
#ParsedReport
24-08-2022
Ransomware updates & 1-day exploits
https://securelist.com/ransomware-updates-1-day-exploits/107291
Threats:
Redalert
Monster
Industry:
Financial, Retail
Geo:
Indonesia, Singapore, Bolivia, Apac
CVEs:
CVE-2022-24521 [Vulners]
Vulners: Score: 4.6, CVSS: 4.2,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (-, 20h2, 21h1, 21h2, 1607, 1809, 1909)
- microsoft windows 11 (-, -)
- microsoft windows 7 (-)
- microsoft windows 8.1 (-)
- microsoft windows rt 8.1 (-)
have more...
Softs:
esxi
Algorithms:
aes
Languages:
rust, delphi
YARA: Found
24-08-2022
Ransomware updates & 1-day exploits
https://securelist.com/ransomware-updates-1-day-exploits/107291
Threats:
Redalert
Monster
Industry:
Financial, Retail
Geo:
Indonesia, Singapore, Bolivia, Apac
CVEs:
CVE-2022-24521 [Vulners]
Vulners: Score: 4.6, CVSS: 4.2,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (-, 20h2, 21h1, 21h2, 1607, 1809, 1909)
- microsoft windows 11 (-, -)
- microsoft windows 7 (-)
- microsoft windows 8.1 (-)
- microsoft windows rt 8.1 (-)
have more...
Softs:
esxi
Algorithms:
aes
Languages:
rust, delphi
YARA: Found
Securelist
Kaspersky crimeware report: new ransomware and 1-day exploits
In this report, we discuss the new multi-platform ransomware RedAlert (aka N13V) and Monster, as well as private 1-day exploits for the CVE-2022-24521 vulnerability.
#ParsedReport
24-08-2022
Ransomware Actor Abuses Genshin Impact Anti-Cheat Driver to Kill Antivirus
https://www.trendmicro.com/en_us/research/22/h/ransomware-actor-abuses-genshin-impact-anti-cheat-driver-to-kill-antivirus.html
Threats:
Fire_chili_rootkit
Fivesys
Impacket_tool
Industry:
Entertainment
IOCs:
File: 10
Hash: 1
Softs:
psexec, windows installer
Functions:
NtOpenFile, ZwTerminateProcess
Languages:
python
Links:
24-08-2022
Ransomware Actor Abuses Genshin Impact Anti-Cheat Driver to Kill Antivirus
https://www.trendmicro.com/en_us/research/22/h/ransomware-actor-abuses-genshin-impact-anti-cheat-driver-to-kill-antivirus.html
Threats:
Fire_chili_rootkit
Fivesys
Impacket_tool
Industry:
Entertainment
IOCs:
File: 10
Hash: 1
Softs:
psexec, windows installer
Functions:
NtOpenFile, ZwTerminateProcess
Languages:
python
Links:
https://github.com/kagurazakasanae/Mhyprot2DrvControlhttps://github.com/kkent030315/evil-mhyprot-clihttps://github.com/SecureAuthCorp/impacket/blob/impacket\_0\_10\_0/examples/wmiexec.pyhttps://github.com/SecureAuthCorp/impacket/blob/master/examples/secretsdump.pyhttps://github.com/kkent030315Trend Micro
Ransomware Actor Abuses Genshin Impact Anti-Cheat Driver to Kill Antivirus
We investigate mhyprot2.sys, a vulnerable anti-cheat driver for the popular role-playing game Genshin Impact. The driver is currently being abused by a ransomware actor to kill antivirus processes and services for mass-deploying ransomware.
#ParsedReport
24-08-2022
ASEC (20220815 \~ 20220821). ASEC Weekly Malware Statistics (20220815 \~ 20220821)
https://asec.ahnlab.com/ko/37997
Threats:
Agent_tesla
Azorult
Formbook
Clipboard_grabbing_technique
Redline_stealer
Beamwinhttp_loader
Postealer
Cloudeye
Remcos_rat
Nanocore_rat
Avemaria_rat
Lokibot_stealer
Industry:
Transport, Financial
Geo:
Korea
TTPs:
IOCs:
File: 30
Domain: 3
IP: 11
Email: 6
Url: 15
Softs:
discord, nsis installer
Languages:
visual_basic
24-08-2022
ASEC (20220815 \~ 20220821). ASEC Weekly Malware Statistics (20220815 \~ 20220821)
https://asec.ahnlab.com/ko/37997
Threats:
Agent_tesla
Azorult
Formbook
Clipboard_grabbing_technique
Redline_stealer
Beamwinhttp_loader
Postealer
Cloudeye
Remcos_rat
Nanocore_rat
Avemaria_rat
Lokibot_stealer
Industry:
Transport, Financial
Geo:
Korea
TTPs:
IOCs:
File: 30
Domain: 3
IP: 11
Email: 6
Url: 15
Softs:
discord, nsis installer
Languages:
visual_basic
ASEC
ASEC 주간 악성코드 통계 (20220815 ~ 20220821) - ASEC
ASEC 분석팀에서는 ASEC 자동 분석 시스템 RAPIT 을 활용하여 알려진 악성코드들에 대한 분류 및 대응을 진행하고 있다. 본 포스팅에서는 2022년 8월 15일 월요일부터 8월 21일 일요일까지 한 주간 수집된 악성코드의 통계를 정리한다. 대분류 상으로는 인포스틸러가 57.8%로 1위를 차지하였으며, 그 다음으로는 백도어 악성코드가 24.2%, 다운로더 13.7%, 랜섬웨어 3.7%, 코인마이너 악성코드가 0.6%로 집계되었다. Top 1 – Agent…
#ParsedReport
24-08-2022
MagicWeb: NOBELIUMs post-compromise trick to authenticate as anyone
https://www.microsoft.com/security/blog/2022/08/24/magicweb-nobeliums-post-compromise-trick-to-authenticate-as-anyone
Actors/Campaigns:
Darkhalo (motivation: information_theft)
Threats:
Magicweb
Foggyweb
Industry:
Government, Ngo
Geo:
Asia
IOCs:
File: 17
Path: 1
Softs:
microsoft defender, active directory, microsoft 365 defender, windows firewall, adfs, azure ad
Functions:
beginprocessclaims, GetClientCertificate, ValidateX509Extensions, begingetclientcertificate, MagicWebs, AddClaims, beginendpointconfiguration, Build, Initialize, ProcessClaims, GetType, MagicWeb, ComputeHash, EndpointConfiguration, beginbuild, OverloadMethod, GetClaims, AddClaim, Add
Links:
24-08-2022
MagicWeb: NOBELIUMs post-compromise trick to authenticate as anyone
https://www.microsoft.com/security/blog/2022/08/24/magicweb-nobeliums-post-compromise-trick-to-authenticate-as-anyone
Actors/Campaigns:
Darkhalo (motivation: information_theft)
Threats:
Magicweb
Foggyweb
Industry:
Government, Ngo
Geo:
Asia
IOCs:
File: 17
Path: 1
Softs:
microsoft defender, active directory, microsoft 365 defender, windows firewall, adfs, azure ad
Functions:
beginprocessclaims, GetClientCertificate, ValidateX509Extensions, begingetclientcertificate, MagicWebs, AddClaims, beginendpointconfiguration, Build, Initialize, ProcessClaims, GetType, MagicWeb, ComputeHash, EndpointConfiguration, beginbuild, OverloadMethod, GetClaims, AddClaim, Add
Links:
https://github.com/Azure/Azure-Sentinel/tree/master/Detections/SecurityEvent/ADFSAbnormalEnhancedKeyUsageAttribute-OID.yamlMicrosoft Security Blog
MagicWeb: NOBELIUM’s post-compromise trick to authenticate as anyone | Microsoft Security Blog
Microsoft security researchers have discovered a post-compromise capability we’re calling MagicWeb, which is used by a threat actor we track as NOBELIUM to maintain persistent access to compromised environments.
#ParsedReport
24-08-2022
The Anatomy of Wiper Malware, Part 2: Third-Party Drivers
https://www.crowdstrike.com/blog/the-anatomy-of-wiper-malware-part-2
Actors/Campaigns:
Turla
Agrius
Threats:
Sierras
Hermeticwiper
Disttrack
Dustman_wiper
Zerocleare_wiper
Alureon
Apostle
Killdisk
Doublezero
Isaacwiper
Israbye
Meteor_wiper
Ordinypt
Petya
Stonedrill_wiper
Whispergate
Industry:
Petroleum
Geo:
Ukraine, Tokyo
IOCs:
File: 3
Hash: 39
Softs:
windows service
Functions:
IoGetAttachedDeviceReference, WriteFile, SetFilePointer, IoBuildAsynchronousFsdRequest, DeviceIoControl, IoGetDeviceObjectPointer, CreateFile, IoBuildDeviceIoControlRequest
Links:
24-08-2022
The Anatomy of Wiper Malware, Part 2: Third-Party Drivers
https://www.crowdstrike.com/blog/the-anatomy-of-wiper-malware-part-2
Actors/Campaigns:
Turla
Agrius
Threats:
Sierras
Hermeticwiper
Disttrack
Dustman_wiper
Zerocleare_wiper
Alureon
Apostle
Killdisk
Doublezero
Isaacwiper
Israbye
Meteor_wiper
Ordinypt
Petya
Stonedrill_wiper
Whispergate
Industry:
Petroleum
Geo:
Ukraine, Tokyo
IOCs:
File: 3
Hash: 39
Softs:
windows service
Functions:
IoGetAttachedDeviceReference, WriteFile, SetFilePointer, IoBuildAsynchronousFsdRequest, DeviceIoControl, IoGetDeviceObjectPointer, CreateFile, IoBuildDeviceIoControlRequest
Links:
https://github.com/hfiref0x/TDL#ParsedReport
24-08-2022
The Anatomy of Wiper Malware, Part 1: Common Techniques
https://www.crowdstrike.com/blog/the-anatomy-of-wiper-malware-part-1
Actors/Campaigns:
Agrius
Threats:
Disttrack
Petya
Ordinypt
Stonedrill
Olympic_destroyer
Dustman
Israbye
Killdisk
Doublezero
Hermeticwiper
Isaacwiper
Whispergate
Apostle
Meteor_wiper
Sierras
Industry:
Government, Energy, Petroleum, Entertainment
Geo:
Israel, Germany, Ukraine, Russia, Tokyo, Israeli, Russian, Korea
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 39
File: 1
Algorithms:
prng
Functions:
CreateFile, DeleteFile, FindFirstFile, NtFsControlFile, GetFileSize, FindNextFile, WriteFile
Platforms:
arm
24-08-2022
The Anatomy of Wiper Malware, Part 1: Common Techniques
https://www.crowdstrike.com/blog/the-anatomy-of-wiper-malware-part-1
Actors/Campaigns:
Agrius
Threats:
Disttrack
Petya
Ordinypt
Stonedrill
Olympic_destroyer
Dustman
Israbye
Killdisk
Doublezero
Hermeticwiper
Isaacwiper
Whispergate
Apostle
Meteor_wiper
Sierras
Industry:
Government, Energy, Petroleum, Entertainment
Geo:
Israel, Germany, Ukraine, Russia, Tokyo, Israeli, Russian, Korea
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 39
File: 1
Algorithms:
prng
Functions:
CreateFile, DeleteFile, FindFirstFile, NtFsControlFile, GetFileSize, FindNextFile, WriteFile
Platforms:
arm
#ParsedReport
25-08-2022
Kimsukys GoldDragon cluster and its C2 operations
https://securelist.com/kimsukys-golddragon-cluster-and-its-c2-operations/107258
Actors/Campaigns:
Kimsuky
Threats:
Gold_dragon
Industry:
Education, Government
Geo:
Korea, Asian, Australian, Korean
IOCs:
File: 35
Url: 51
Email: 7
Hash: 64
Domain: 6
Softs:
microsoft office, chrome, .net framework
Algorithms:
base64
Functions:
CreateObject, GetOfficeVersionNumber
Languages:
visual_basic, php
Platforms:
x64, x86
25-08-2022
Kimsukys GoldDragon cluster and its C2 operations
https://securelist.com/kimsukys-golddragon-cluster-and-its-c2-operations/107258
Actors/Campaigns:
Kimsuky
Threats:
Gold_dragon
Industry:
Education, Government
Geo:
Korea, Asian, Australian, Korean
IOCs:
File: 35
Url: 51
Email: 7
Hash: 64
Domain: 6
Softs:
microsoft office, chrome, .net framework
Algorithms:
base64
Functions:
CreateObject, GetOfficeVersionNumber
Languages:
visual_basic, php
Platforms:
x64, x86
Securelist
Kimsuky’s GoldDragon cluster and its C2 operations
Kimsuky is a prolific and active threat actor primarily targeting Korea-related entities. In early 2022, we observed this group was attacking the media and a think-tank in South Korea.
#ParsedReport
25-08-2022
BleachGap Revamped
https://labs.k7computing.com/index.php/bleachgap-revamped
Threats:
Bleachgap
IOCs:
File: 2
Path: 1
Hash: 1
Softs:
discord
Algorithms:
xor, aes
Functions:
FindNextFileW, ReadFile, FindFirstFileExW, the
25-08-2022
BleachGap Revamped
https://labs.k7computing.com/index.php/bleachgap-revamped
Threats:
Bleachgap
IOCs:
File: 2
Path: 1
Hash: 1
Softs:
discord
Algorithms:
xor, aes
Functions:
FindNextFileW, ReadFile, FindFirstFileExW, the
K7 Labs
BleachGap Revamped - K7 Labs
BleachGap ransomware was first reported in Feb 2021 by a researcher named Petrovic on Twitter. This ransomware variant that we […]
#ParsedReport
25-08-2022
The Dark Side of Bumblebee Malware Loader
https://www.deepinstinct.com/blog/the-dark-side-of-bumblebee-malware-loader
Actors/Campaigns:
Exotic_lily
Threats:
Bumblebee
Conti
Diavol
Ramnit
Trickbot
Quantum_locker
Geo:
Usa
IOCs:
File: 3
Hash: 5
Algorithms:
gzip
Functions:
main
Links:
25-08-2022
The Dark Side of Bumblebee Malware Loader
https://www.deepinstinct.com/blog/the-dark-side-of-bumblebee-malware-loader
Actors/Campaigns:
Exotic_lily
Threats:
Bumblebee
Conti
Diavol
Ramnit
Trickbot
Quantum_locker
Geo:
Usa
IOCs:
File: 3
Hash: 5
Algorithms:
gzip
Functions:
main
Links:
https://github.com/LordNoteworthy/al-khaserDeep Instinct
Bumblebee Malware: Deep Instinct Prevents Attack Pre-Execution | Deep Instinct
Deep Instinct prevented a complicated Bumblebee malware loader attack pre-execution. Read more about the Bumblebee attack and how Deep Instinct can help your business.
#ParsedReport
25-08-2022
BlueSky Ransomware \| AD Lateral Movement, Evasion and Fast Encryption Puts Threat on the Radar
https://www.sentinelone.com/blog/bluesky-ransomware-ad-lateral-movement-evasion-and-fast-encryption-puts-threat-on-the-radar
Actors/Campaigns:
Bluesky
Threats:
Cobalt_strike
Brc4_tool
Juicypotato_tool
Industry:
Ics
CVEs:
CVE-2022-21882 [Vulners]
Vulners: Score: 7.2, CVSS: 3.8,
Vulners: Exploitation: True
X-Force: Risk: 7
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2019 (-)
- microsoft windows 10 (1809, 1809, 1809, 1909, 1909, 1909, 20h2, 20h2, 20h2, 21h1, 21h1, 21h1, 21h2, 21h2, 21h2)
- microsoft windows 11 (-, -)
- microsoft windows server (20h2, 2022)
CVE-2021-1732 [Vulners]
Vulners: Score: 4.6, CVSS: 4.3,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (20h2, 1803, 1809, 1909, 2004)
- microsoft windows server 2016 (20h2, 1909, 2004)
- microsoft windows server 2019 (-)
CVE-2020-0796 [Vulners]
Vulners: Score: 7.5, CVSS: 3.2,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (1903, 1909)
- microsoft windows server 2016 (1903, 1909)
TTPs:
IOCs:
Domain: 2
Url: 15
File: 1
Path: 1
Hash: 18
Softs:
active directory
Functions:
GetLogicalDriveStringsW, NtSetInformationThread, NtQueryInformationProcess, TerminateProcess
25-08-2022
BlueSky Ransomware \| AD Lateral Movement, Evasion and Fast Encryption Puts Threat on the Radar
https://www.sentinelone.com/blog/bluesky-ransomware-ad-lateral-movement-evasion-and-fast-encryption-puts-threat-on-the-radar
Actors/Campaigns:
Bluesky
Threats:
Cobalt_strike
Brc4_tool
Juicypotato_tool
Industry:
Ics
CVEs:
CVE-2022-21882 [Vulners]
Vulners: Score: 7.2, CVSS: 3.8,
Vulners: Exploitation: True
X-Force: Risk: 7
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2019 (-)
- microsoft windows 10 (1809, 1809, 1809, 1909, 1909, 1909, 20h2, 20h2, 20h2, 21h1, 21h1, 21h1, 21h2, 21h2, 21h2)
- microsoft windows 11 (-, -)
- microsoft windows server (20h2, 2022)
CVE-2021-1732 [Vulners]
Vulners: Score: 4.6, CVSS: 4.3,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (20h2, 1803, 1809, 1909, 2004)
- microsoft windows server 2016 (20h2, 1909, 2004)
- microsoft windows server 2019 (-)
CVE-2020-0796 [Vulners]
Vulners: Score: 7.5, CVSS: 3.2,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (1903, 1909)
- microsoft windows server 2016 (1903, 1909)
TTPs:
IOCs:
Domain: 2
Url: 15
File: 1
Path: 1
Hash: 18
Softs:
active directory
Functions:
GetLogicalDriveStringsW, NtSetInformationThread, NtQueryInformationProcess, TerminateProcess
SentinelOne
BlueSky Ransomware | AD Lateral Movement, Evasion and Fast Encryption Put Threat on the Radar
This new ransomware threat uses multi-threaded encryption and exploits known Windows vulnerabilities to infect hosts across Active Directory.