#ParsedReport
23-08-2022
Venom ControlRAT With a Sting
https://cyberint.com/blog/research/venom-control-rat-with-a-sting
Actors/Campaigns:
Atlantis_cyberarmy
Threats:
Control_rat
Venomrat
Sbit_rat
Bratarat
Industry:
Financial
Softs:
telegram, chrome, opera, windows defender
23-08-2022
Venom ControlRAT With a Sting
https://cyberint.com/blog/research/venom-control-rat-with-a-sting
Actors/Campaigns:
Atlantis_cyberarmy
Threats:
Control_rat
Venomrat
Sbit_rat
Bratarat
Industry:
Financial
Softs:
telegram, chrome, opera, windows defender
#ParsedReport
23-08-2022
Reversing Golang Developed Ransomware: SNAKE. Introduction
https://www.0ffset.net/reverse-engineering/analysing-snake-ransomware/?utm_source=rss&utm_medium=rss&utm_campaign=analysing-snake-ransomware
Threats:
Snake_ransomware
Snakehose
IOCs:
Hash: 1
File: 19
IP: 1
Path: 1
Email: 1
Softs:
bootnxt, windows firewall
Algorithms:
xor, aes, rsa-2048
Functions:
WriteAt, LazyDLL, OpenService, OpenServiceW, CoInitializeEx, OpenSCManagerA, OpenProcess, DeleteInstance, main
Languages:
python, golang
Links:
23-08-2022
Reversing Golang Developed Ransomware: SNAKE. Introduction
https://www.0ffset.net/reverse-engineering/analysing-snake-ransomware/?utm_source=rss&utm_medium=rss&utm_campaign=analysing-snake-ransomware
Threats:
Snake_ransomware
Snakehose
IOCs:
Hash: 1
File: 19
IP: 1
Path: 1
Email: 1
Softs:
bootnxt, windows firewall
Algorithms:
xor, aes, rsa-2048
Functions:
WriteAt, LazyDLL, OpenService, OpenServiceW, CoInitializeEx, OpenSCManagerA, OpenProcess, DeleteInstance, main
Languages:
python, golang
Links:
https://github.com/unixpickle/gobfuscate0ffset Training Solutions | Practical and Affordable Cyber Security Training
Reversing Golang Developed Ransomware: SNAKE | 0ffset Training Solutions
Introduction Snake Ransomware (or EKANS Ransomware) is a Golang ransomware which in the past has affected several companies such as Enel and Honda. The MD5 hashing of the analyzed sample is ED3C05BDE9F0EA0F1321355B03AC42D0. This sample in particular is obfuscated…
#ParsedReport
23-08-2022
Get a demo. Emotet Resurgence: Cross-Industry Campaign Analysis
https://darktrace.com/blog/emotet-resurgence-cross-industry-campaign-analysis
Threats:
Emotet
Trickbot
Ryuk
Cobalt_strike
Beacon
Industry:
Telco, Healthcare
Geo:
London, Japanese
IOCs:
Domain: 3
File: 7
Hash: 5
Softs:
microsoft outlook
Algorithms:
ecc, zip , gzip
Platforms:
intel
23-08-2022
Get a demo. Emotet Resurgence: Cross-Industry Campaign Analysis
https://darktrace.com/blog/emotet-resurgence-cross-industry-campaign-analysis
Threats:
Emotet
Trickbot
Ryuk
Cobalt_strike
Beacon
Industry:
Telco, Healthcare
Geo:
London, Japanese
IOCs:
Domain: 3
File: 7
Hash: 5
Softs:
microsoft outlook
Algorithms:
ecc, zip , gzip
Platforms:
intel
Darktrace
Emotet Resurgence: Cross-Industry Analysis | Darktrace Blog
Technical insights on the Emotet resurgence in 2022 across various client environments, industries, and regions.
#ParsedReport
24-08-2022
BitRAT and XMRig CoinMiner Being Distributed via Windows License Verification Tool
https://asec.ahnlab.com/en/37939
Threats:
Sbit_rat
Xmrig_miner
Trojan/win.generic.c5223158
Malware/mdp.download.m1197
Malware/mdp.drivebydownload.m1298
Geo:
Korean
IOCs:
File: 9
Path: 1
Domain: 1
Hash: 4
Url: 3
IP: 1
Softs:
google chrome, windows defender, telegram
24-08-2022
BitRAT and XMRig CoinMiner Being Distributed via Windows License Verification Tool
https://asec.ahnlab.com/en/37939
Threats:
Sbit_rat
Xmrig_miner
Trojan/win.generic.c5223158
Malware/mdp.download.m1197
Malware/mdp.drivebydownload.m1298
Geo:
Korean
IOCs:
File: 9
Path: 1
Domain: 1
Hash: 4
Url: 3
IP: 1
Softs:
google chrome, windows defender, telegram
ASEC BLOG
BitRAT and XMRig CoinMiner Being Distributed via Windows License Verification Tool - ASEC BLOG
The ASEC analysis team has recently discovered the distribution of BitRAT and XMRig CoinMiner disguised as a Windows license verification tool. As introduced in previous posts, BitRAT has a history of being distributed on webhards as MS Windows license verification…
#ParsedReport
24-08-2022
AsyncRAT Being Distributed in Fileless Form
https://asec.ahnlab.com/en/37954
Threats:
Asyncrat_rat
Trojan/vbs.runner
IOCs:
File: 8
Path: 9
Url: 1
Domain: 1
Hash: 11
Softs:
task scheduler
24-08-2022
AsyncRAT Being Distributed in Fileless Form
https://asec.ahnlab.com/en/37954
Threats:
Asyncrat_rat
Trojan/vbs.runner
IOCs:
File: 8
Path: 9
Url: 1
Domain: 1
Hash: 11
Softs:
task scheduler
ASEC BLOG
AsyncRAT Being Distributed in Fileless Form - ASEC BLOG
The ASEC analysis team has recently discovered that malicious AsyncRAT codes are being distributed in fileless form. The distributed AsyncRAT is executed in fileless form through multiple script files and is thought to be distributed as a compressed file…
#ParsedReport
24-08-2022
AgentTesla is threatening businesses around the world with a new campaign
https://decoded.avast.io/pavelnovak/agenttesla-is-threatening-businesses-around-the-world-with-a-new-campaign/?utm_source=rss&utm_medium=rss&utm_campaign=agenttesla-is-threatening-businesses-around-the-world-with-a-new-campaign
Threats:
Agent_tesla
Geo:
Switzerland, Argentina, Italy, Portugal, American, Germany, Romania, America, Spain, France, German
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 3
Hash: 3
Domain: 1
Softs:
android
Languages:
javascript
Links:
24-08-2022
AgentTesla is threatening businesses around the world with a new campaign
https://decoded.avast.io/pavelnovak/agenttesla-is-threatening-businesses-around-the-world-with-a-new-campaign/?utm_source=rss&utm_medium=rss&utm_campaign=agenttesla-is-threatening-businesses-around-the-world-with-a-new-campaign
Threats:
Agent_tesla
Geo:
Switzerland, Argentina, Italy, Portugal, American, Germany, Romania, America, Spain, France, German
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 3
Hash: 3
Domain: 1
Softs:
android
Languages:
javascript
Links:
https://github.com/avast/ioc/tree/master/AgentTeslaISOCampaignAvast Threat Labs
AgentTesla is threatening businesses around the world with a new campaign - Avast Threat Labs
A new campaign targeting businesses in Europe and South America is making its rounds, spreading the information stealer, AgentTesla, via spoofed phishing emails.
#ParsedReport
24-08-2022
Ransomware updates & 1-day exploits
https://securelist.com/ransomware-updates-1-day-exploits/107291
Threats:
Redalert
Monster
Industry:
Financial, Retail
Geo:
Indonesia, Singapore, Bolivia, Apac
CVEs:
CVE-2022-24521 [Vulners]
Vulners: Score: 4.6, CVSS: 4.2,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (-, 20h2, 21h1, 21h2, 1607, 1809, 1909)
- microsoft windows 11 (-, -)
- microsoft windows 7 (-)
- microsoft windows 8.1 (-)
- microsoft windows rt 8.1 (-)
have more...
Softs:
esxi
Algorithms:
aes
Languages:
rust, delphi
YARA: Found
24-08-2022
Ransomware updates & 1-day exploits
https://securelist.com/ransomware-updates-1-day-exploits/107291
Threats:
Redalert
Monster
Industry:
Financial, Retail
Geo:
Indonesia, Singapore, Bolivia, Apac
CVEs:
CVE-2022-24521 [Vulners]
Vulners: Score: 4.6, CVSS: 4.2,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (-, 20h2, 21h1, 21h2, 1607, 1809, 1909)
- microsoft windows 11 (-, -)
- microsoft windows 7 (-)
- microsoft windows 8.1 (-)
- microsoft windows rt 8.1 (-)
have more...
Softs:
esxi
Algorithms:
aes
Languages:
rust, delphi
YARA: Found
Securelist
Kaspersky crimeware report: new ransomware and 1-day exploits
In this report, we discuss the new multi-platform ransomware RedAlert (aka N13V) and Monster, as well as private 1-day exploits for the CVE-2022-24521 vulnerability.
#ParsedReport
24-08-2022
Ransomware Actor Abuses Genshin Impact Anti-Cheat Driver to Kill Antivirus
https://www.trendmicro.com/en_us/research/22/h/ransomware-actor-abuses-genshin-impact-anti-cheat-driver-to-kill-antivirus.html
Threats:
Fire_chili_rootkit
Fivesys
Impacket_tool
Industry:
Entertainment
IOCs:
File: 10
Hash: 1
Softs:
psexec, windows installer
Functions:
NtOpenFile, ZwTerminateProcess
Languages:
python
Links:
24-08-2022
Ransomware Actor Abuses Genshin Impact Anti-Cheat Driver to Kill Antivirus
https://www.trendmicro.com/en_us/research/22/h/ransomware-actor-abuses-genshin-impact-anti-cheat-driver-to-kill-antivirus.html
Threats:
Fire_chili_rootkit
Fivesys
Impacket_tool
Industry:
Entertainment
IOCs:
File: 10
Hash: 1
Softs:
psexec, windows installer
Functions:
NtOpenFile, ZwTerminateProcess
Languages:
python
Links:
https://github.com/kagurazakasanae/Mhyprot2DrvControlhttps://github.com/kkent030315/evil-mhyprot-clihttps://github.com/SecureAuthCorp/impacket/blob/impacket\_0\_10\_0/examples/wmiexec.pyhttps://github.com/SecureAuthCorp/impacket/blob/master/examples/secretsdump.pyhttps://github.com/kkent030315Trend Micro
Ransomware Actor Abuses Genshin Impact Anti-Cheat Driver to Kill Antivirus
We investigate mhyprot2.sys, a vulnerable anti-cheat driver for the popular role-playing game Genshin Impact. The driver is currently being abused by a ransomware actor to kill antivirus processes and services for mass-deploying ransomware.
#ParsedReport
24-08-2022
ASEC (20220815 \~ 20220821). ASEC Weekly Malware Statistics (20220815 \~ 20220821)
https://asec.ahnlab.com/ko/37997
Threats:
Agent_tesla
Azorult
Formbook
Clipboard_grabbing_technique
Redline_stealer
Beamwinhttp_loader
Postealer
Cloudeye
Remcos_rat
Nanocore_rat
Avemaria_rat
Lokibot_stealer
Industry:
Transport, Financial
Geo:
Korea
TTPs:
IOCs:
File: 30
Domain: 3
IP: 11
Email: 6
Url: 15
Softs:
discord, nsis installer
Languages:
visual_basic
24-08-2022
ASEC (20220815 \~ 20220821). ASEC Weekly Malware Statistics (20220815 \~ 20220821)
https://asec.ahnlab.com/ko/37997
Threats:
Agent_tesla
Azorult
Formbook
Clipboard_grabbing_technique
Redline_stealer
Beamwinhttp_loader
Postealer
Cloudeye
Remcos_rat
Nanocore_rat
Avemaria_rat
Lokibot_stealer
Industry:
Transport, Financial
Geo:
Korea
TTPs:
IOCs:
File: 30
Domain: 3
IP: 11
Email: 6
Url: 15
Softs:
discord, nsis installer
Languages:
visual_basic
ASEC
ASEC 주간 악성코드 통계 (20220815 ~ 20220821) - ASEC
ASEC 분석팀에서는 ASEC 자동 분석 시스템 RAPIT 을 활용하여 알려진 악성코드들에 대한 분류 및 대응을 진행하고 있다. 본 포스팅에서는 2022년 8월 15일 월요일부터 8월 21일 일요일까지 한 주간 수집된 악성코드의 통계를 정리한다. 대분류 상으로는 인포스틸러가 57.8%로 1위를 차지하였으며, 그 다음으로는 백도어 악성코드가 24.2%, 다운로더 13.7%, 랜섬웨어 3.7%, 코인마이너 악성코드가 0.6%로 집계되었다. Top 1 – Agent…
#ParsedReport
24-08-2022
MagicWeb: NOBELIUMs post-compromise trick to authenticate as anyone
https://www.microsoft.com/security/blog/2022/08/24/magicweb-nobeliums-post-compromise-trick-to-authenticate-as-anyone
Actors/Campaigns:
Darkhalo (motivation: information_theft)
Threats:
Magicweb
Foggyweb
Industry:
Government, Ngo
Geo:
Asia
IOCs:
File: 17
Path: 1
Softs:
microsoft defender, active directory, microsoft 365 defender, windows firewall, adfs, azure ad
Functions:
beginprocessclaims, GetClientCertificate, ValidateX509Extensions, begingetclientcertificate, MagicWebs, AddClaims, beginendpointconfiguration, Build, Initialize, ProcessClaims, GetType, MagicWeb, ComputeHash, EndpointConfiguration, beginbuild, OverloadMethod, GetClaims, AddClaim, Add
Links:
24-08-2022
MagicWeb: NOBELIUMs post-compromise trick to authenticate as anyone
https://www.microsoft.com/security/blog/2022/08/24/magicweb-nobeliums-post-compromise-trick-to-authenticate-as-anyone
Actors/Campaigns:
Darkhalo (motivation: information_theft)
Threats:
Magicweb
Foggyweb
Industry:
Government, Ngo
Geo:
Asia
IOCs:
File: 17
Path: 1
Softs:
microsoft defender, active directory, microsoft 365 defender, windows firewall, adfs, azure ad
Functions:
beginprocessclaims, GetClientCertificate, ValidateX509Extensions, begingetclientcertificate, MagicWebs, AddClaims, beginendpointconfiguration, Build, Initialize, ProcessClaims, GetType, MagicWeb, ComputeHash, EndpointConfiguration, beginbuild, OverloadMethod, GetClaims, AddClaim, Add
Links:
https://github.com/Azure/Azure-Sentinel/tree/master/Detections/SecurityEvent/ADFSAbnormalEnhancedKeyUsageAttribute-OID.yamlMicrosoft Security Blog
MagicWeb: NOBELIUM’s post-compromise trick to authenticate as anyone | Microsoft Security Blog
Microsoft security researchers have discovered a post-compromise capability we’re calling MagicWeb, which is used by a threat actor we track as NOBELIUM to maintain persistent access to compromised environments.
#ParsedReport
24-08-2022
The Anatomy of Wiper Malware, Part 2: Third-Party Drivers
https://www.crowdstrike.com/blog/the-anatomy-of-wiper-malware-part-2
Actors/Campaigns:
Turla
Agrius
Threats:
Sierras
Hermeticwiper
Disttrack
Dustman_wiper
Zerocleare_wiper
Alureon
Apostle
Killdisk
Doublezero
Isaacwiper
Israbye
Meteor_wiper
Ordinypt
Petya
Stonedrill_wiper
Whispergate
Industry:
Petroleum
Geo:
Ukraine, Tokyo
IOCs:
File: 3
Hash: 39
Softs:
windows service
Functions:
IoGetAttachedDeviceReference, WriteFile, SetFilePointer, IoBuildAsynchronousFsdRequest, DeviceIoControl, IoGetDeviceObjectPointer, CreateFile, IoBuildDeviceIoControlRequest
Links:
24-08-2022
The Anatomy of Wiper Malware, Part 2: Third-Party Drivers
https://www.crowdstrike.com/blog/the-anatomy-of-wiper-malware-part-2
Actors/Campaigns:
Turla
Agrius
Threats:
Sierras
Hermeticwiper
Disttrack
Dustman_wiper
Zerocleare_wiper
Alureon
Apostle
Killdisk
Doublezero
Isaacwiper
Israbye
Meteor_wiper
Ordinypt
Petya
Stonedrill_wiper
Whispergate
Industry:
Petroleum
Geo:
Ukraine, Tokyo
IOCs:
File: 3
Hash: 39
Softs:
windows service
Functions:
IoGetAttachedDeviceReference, WriteFile, SetFilePointer, IoBuildAsynchronousFsdRequest, DeviceIoControl, IoGetDeviceObjectPointer, CreateFile, IoBuildDeviceIoControlRequest
Links:
https://github.com/hfiref0x/TDL#ParsedReport
24-08-2022
The Anatomy of Wiper Malware, Part 1: Common Techniques
https://www.crowdstrike.com/blog/the-anatomy-of-wiper-malware-part-1
Actors/Campaigns:
Agrius
Threats:
Disttrack
Petya
Ordinypt
Stonedrill
Olympic_destroyer
Dustman
Israbye
Killdisk
Doublezero
Hermeticwiper
Isaacwiper
Whispergate
Apostle
Meteor_wiper
Sierras
Industry:
Government, Energy, Petroleum, Entertainment
Geo:
Israel, Germany, Ukraine, Russia, Tokyo, Israeli, Russian, Korea
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 39
File: 1
Algorithms:
prng
Functions:
CreateFile, DeleteFile, FindFirstFile, NtFsControlFile, GetFileSize, FindNextFile, WriteFile
Platforms:
arm
24-08-2022
The Anatomy of Wiper Malware, Part 1: Common Techniques
https://www.crowdstrike.com/blog/the-anatomy-of-wiper-malware-part-1
Actors/Campaigns:
Agrius
Threats:
Disttrack
Petya
Ordinypt
Stonedrill
Olympic_destroyer
Dustman
Israbye
Killdisk
Doublezero
Hermeticwiper
Isaacwiper
Whispergate
Apostle
Meteor_wiper
Sierras
Industry:
Government, Energy, Petroleum, Entertainment
Geo:
Israel, Germany, Ukraine, Russia, Tokyo, Israeli, Russian, Korea
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 39
File: 1
Algorithms:
prng
Functions:
CreateFile, DeleteFile, FindFirstFile, NtFsControlFile, GetFileSize, FindNextFile, WriteFile
Platforms:
arm
#ParsedReport
25-08-2022
Kimsukys GoldDragon cluster and its C2 operations
https://securelist.com/kimsukys-golddragon-cluster-and-its-c2-operations/107258
Actors/Campaigns:
Kimsuky
Threats:
Gold_dragon
Industry:
Education, Government
Geo:
Korea, Asian, Australian, Korean
IOCs:
File: 35
Url: 51
Email: 7
Hash: 64
Domain: 6
Softs:
microsoft office, chrome, .net framework
Algorithms:
base64
Functions:
CreateObject, GetOfficeVersionNumber
Languages:
visual_basic, php
Platforms:
x64, x86
25-08-2022
Kimsukys GoldDragon cluster and its C2 operations
https://securelist.com/kimsukys-golddragon-cluster-and-its-c2-operations/107258
Actors/Campaigns:
Kimsuky
Threats:
Gold_dragon
Industry:
Education, Government
Geo:
Korea, Asian, Australian, Korean
IOCs:
File: 35
Url: 51
Email: 7
Hash: 64
Domain: 6
Softs:
microsoft office, chrome, .net framework
Algorithms:
base64
Functions:
CreateObject, GetOfficeVersionNumber
Languages:
visual_basic, php
Platforms:
x64, x86
Securelist
Kimsuky’s GoldDragon cluster and its C2 operations
Kimsuky is a prolific and active threat actor primarily targeting Korea-related entities. In early 2022, we observed this group was attacking the media and a think-tank in South Korea.
#ParsedReport
25-08-2022
BleachGap Revamped
https://labs.k7computing.com/index.php/bleachgap-revamped
Threats:
Bleachgap
IOCs:
File: 2
Path: 1
Hash: 1
Softs:
discord
Algorithms:
xor, aes
Functions:
FindNextFileW, ReadFile, FindFirstFileExW, the
25-08-2022
BleachGap Revamped
https://labs.k7computing.com/index.php/bleachgap-revamped
Threats:
Bleachgap
IOCs:
File: 2
Path: 1
Hash: 1
Softs:
discord
Algorithms:
xor, aes
Functions:
FindNextFileW, ReadFile, FindFirstFileExW, the
K7 Labs
BleachGap Revamped - K7 Labs
BleachGap ransomware was first reported in Feb 2021 by a researcher named Petrovic on Twitter. This ransomware variant that we […]
#ParsedReport
25-08-2022
The Dark Side of Bumblebee Malware Loader
https://www.deepinstinct.com/blog/the-dark-side-of-bumblebee-malware-loader
Actors/Campaigns:
Exotic_lily
Threats:
Bumblebee
Conti
Diavol
Ramnit
Trickbot
Quantum_locker
Geo:
Usa
IOCs:
File: 3
Hash: 5
Algorithms:
gzip
Functions:
main
Links:
25-08-2022
The Dark Side of Bumblebee Malware Loader
https://www.deepinstinct.com/blog/the-dark-side-of-bumblebee-malware-loader
Actors/Campaigns:
Exotic_lily
Threats:
Bumblebee
Conti
Diavol
Ramnit
Trickbot
Quantum_locker
Geo:
Usa
IOCs:
File: 3
Hash: 5
Algorithms:
gzip
Functions:
main
Links:
https://github.com/LordNoteworthy/al-khaserDeep Instinct
Bumblebee Malware: Deep Instinct Prevents Attack Pre-Execution | Deep Instinct
Deep Instinct prevented a complicated Bumblebee malware loader attack pre-execution. Read more about the Bumblebee attack and how Deep Instinct can help your business.
#ParsedReport
25-08-2022
BlueSky Ransomware \| AD Lateral Movement, Evasion and Fast Encryption Puts Threat on the Radar
https://www.sentinelone.com/blog/bluesky-ransomware-ad-lateral-movement-evasion-and-fast-encryption-puts-threat-on-the-radar
Actors/Campaigns:
Bluesky
Threats:
Cobalt_strike
Brc4_tool
Juicypotato_tool
Industry:
Ics
CVEs:
CVE-2022-21882 [Vulners]
Vulners: Score: 7.2, CVSS: 3.8,
Vulners: Exploitation: True
X-Force: Risk: 7
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2019 (-)
- microsoft windows 10 (1809, 1809, 1809, 1909, 1909, 1909, 20h2, 20h2, 20h2, 21h1, 21h1, 21h1, 21h2, 21h2, 21h2)
- microsoft windows 11 (-, -)
- microsoft windows server (20h2, 2022)
CVE-2021-1732 [Vulners]
Vulners: Score: 4.6, CVSS: 4.3,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (20h2, 1803, 1809, 1909, 2004)
- microsoft windows server 2016 (20h2, 1909, 2004)
- microsoft windows server 2019 (-)
CVE-2020-0796 [Vulners]
Vulners: Score: 7.5, CVSS: 3.2,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (1903, 1909)
- microsoft windows server 2016 (1903, 1909)
TTPs:
IOCs:
Domain: 2
Url: 15
File: 1
Path: 1
Hash: 18
Softs:
active directory
Functions:
GetLogicalDriveStringsW, NtSetInformationThread, NtQueryInformationProcess, TerminateProcess
25-08-2022
BlueSky Ransomware \| AD Lateral Movement, Evasion and Fast Encryption Puts Threat on the Radar
https://www.sentinelone.com/blog/bluesky-ransomware-ad-lateral-movement-evasion-and-fast-encryption-puts-threat-on-the-radar
Actors/Campaigns:
Bluesky
Threats:
Cobalt_strike
Brc4_tool
Juicypotato_tool
Industry:
Ics
CVEs:
CVE-2022-21882 [Vulners]
Vulners: Score: 7.2, CVSS: 3.8,
Vulners: Exploitation: True
X-Force: Risk: 7
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2019 (-)
- microsoft windows 10 (1809, 1809, 1809, 1909, 1909, 1909, 20h2, 20h2, 20h2, 21h1, 21h1, 21h1, 21h2, 21h2, 21h2)
- microsoft windows 11 (-, -)
- microsoft windows server (20h2, 2022)
CVE-2021-1732 [Vulners]
Vulners: Score: 4.6, CVSS: 4.3,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (20h2, 1803, 1809, 1909, 2004)
- microsoft windows server 2016 (20h2, 1909, 2004)
- microsoft windows server 2019 (-)
CVE-2020-0796 [Vulners]
Vulners: Score: 7.5, CVSS: 3.2,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (1903, 1909)
- microsoft windows server 2016 (1903, 1909)
TTPs:
IOCs:
Domain: 2
Url: 15
File: 1
Path: 1
Hash: 18
Softs:
active directory
Functions:
GetLogicalDriveStringsW, NtSetInformationThread, NtQueryInformationProcess, TerminateProcess
SentinelOne
BlueSky Ransomware | AD Lateral Movement, Evasion and Fast Encryption Put Threat on the Radar
This new ransomware threat uses multi-threaded encryption and exploits known Windows vulnerabilities to infect hosts across Active Directory.
#ParsedReport
25-08-2022
MERCURY leveraging Log4j 2 vulnerabilities in unpatched systems to target Israeli organizations
https://www.microsoft.com/security/blog/2022/08/25/mercury-leveraging-log4j-2-vulnerabilities-in-unpatched-systems-to-target-israeli-organizations
Actors/Campaigns:
Muddywater
Threats:
Mercury_tool
Log4shell_vuln
Screenconnect_tool
Venom_proxy_tool
Ligolo
Mimikatz
Remcom_tool
Ehorus_tool
Lsadump_tool
Dumplsass_tool
Geo:
Iran, Irans, Iranian, Israel, Israeli
CVEs:
CVE-2021-45046 [Vulners]
Vulners: Score: 5.1, CVSS: 1.8,
Vulners: Exploitation: True
X-Force: Risk: 9
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, <2.12.2, <2.16.0)
- intel oneapi (-)
- intel audio development kit (-)
- intel datacenter manager (-)
- intel system debugger (-)
have more...
CVE-2021-44228 [Vulners]
Vulners: Score: 9.3, CVSS: 4.5,
Vulners: Exploitation: True
X-Force: Risk: 10
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, <2.15.0, <2.3.1, <2.12.2)
- siemens sppa-t3000 ses3000 firmware (*)
- siemens logo\! soft comfort (*)
- siemens spectrum power 4 (4.70, 4.70, <4.70, 4.70)
- siemens siveillance control pro (*)
have more...
TTPs:
Tactics: 3
Technics: 0
IOCs:
File: 4
Path: 1
Url: 1
IP: 2
Hash: 11
Softs:
apache log4j, microsoft 365 defender, microsoft sql, microsoft defender
Languages:
php
Links:
25-08-2022
MERCURY leveraging Log4j 2 vulnerabilities in unpatched systems to target Israeli organizations
https://www.microsoft.com/security/blog/2022/08/25/mercury-leveraging-log4j-2-vulnerabilities-in-unpatched-systems-to-target-israeli-organizations
Actors/Campaigns:
Muddywater
Threats:
Mercury_tool
Log4shell_vuln
Screenconnect_tool
Venom_proxy_tool
Ligolo
Mimikatz
Remcom_tool
Ehorus_tool
Lsadump_tool
Dumplsass_tool
Geo:
Iran, Irans, Iranian, Israel, Israeli
CVEs:
CVE-2021-45046 [Vulners]
Vulners: Score: 5.1, CVSS: 1.8,
Vulners: Exploitation: True
X-Force: Risk: 9
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, <2.12.2, <2.16.0)
- intel oneapi (-)
- intel audio development kit (-)
- intel datacenter manager (-)
- intel system debugger (-)
have more...
CVE-2021-44228 [Vulners]
Vulners: Score: 9.3, CVSS: 4.5,
Vulners: Exploitation: True
X-Force: Risk: 10
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, <2.15.0, <2.3.1, <2.12.2)
- siemens sppa-t3000 ses3000 firmware (*)
- siemens logo\! soft comfort (*)
- siemens spectrum power 4 (4.70, 4.70, <4.70, 4.70)
- siemens siveillance control pro (*)
have more...
TTPs:
Tactics: 3
Technics: 0
IOCs:
File: 4
Path: 1
Url: 1
IP: 2
Hash: 11
Softs:
apache log4j, microsoft 365 defender, microsoft sql, microsoft defender
Languages:
php
Links:
https://github.com/Azure/Azure-Sentinel/blob/master/Detections/MultipleDataSources/PotentialMercury\_Webshell.yamlhttps://github.com/Azure/Azure-Sentinel/blob/master/Detections/MultipleDataSources/powershell\_mercury.yamlhttps://github.com/Azure/Azure-Sentinel/blob/master/Detections/MultipleDataSources/Mercury\_Log4j\_August2022.yamlMicrosoft News
MERCURY leveraging Log4j 2 vulnerabilities in unpatched systems to target Israeli organizations
Microsoft detected an Iran-based threat actor the Microsoft Threat Intelligence Center (MSTIC) tracks as MERCURY leveraging exploitation of Log4j 2 vulnerabilities in SysAid applications against organizations located in Israel.
#ParsedReport
25-08-2022
SEARCH. Cybercrime Group TA558 Ramps Up Email Attacks Against Hotels
https://www.proofpoint.com/us/newsroom/news/cybercrime-group-ta558-ramps-email-attacks-against-hotels
Actors/Campaigns:
Ta558 (motivation: cyber_criminal, information_theft)
Threats:
Revenge_rat
Loda_rat
Vjw0rm
Asyncrat_rat
Industry:
Financial, Healthcare
Geo:
America, Spanish, Portuguese
CVEs:
CVE-2017-11882 [Vulners]
Vulners: Score: 9.3, CVSS: 4.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2013, 2010, 2016, 2007)
Languages:
javascript, autoit
25-08-2022
SEARCH. Cybercrime Group TA558 Ramps Up Email Attacks Against Hotels
https://www.proofpoint.com/us/newsroom/news/cybercrime-group-ta558-ramps-email-attacks-against-hotels
Actors/Campaigns:
Ta558 (motivation: cyber_criminal, information_theft)
Threats:
Revenge_rat
Loda_rat
Vjw0rm
Asyncrat_rat
Industry:
Financial, Healthcare
Geo:
America, Spanish, Portuguese
CVEs:
CVE-2017-11882 [Vulners]
Vulners: Score: 9.3, CVSS: 4.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2013, 2010, 2016, 2007)
Languages:
javascript, autoit
Decipher
Cybercrime Group TA558 Ramps Up Email Attacks Against Hotels
The small cybercrime actor is upping its operational tempo in 2022 against hospitality organizations like hotels and travel companies.
#ParsedReport
25-08-2022
Roasting 0ktapus: The phishing campaign going after Okta identity credentials
https://blog.group-ib.com/0ktapus
Actors/Campaigns:
0ktapus (motivation: cyber_criminal)
Threats:
Dharma
Anydesk_tool
Blackcat
Industry:
Financial, Education, Telco
Geo:
Canada, Usa, Singapore
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 2
Domain: 168
IP: 56
Softs:
django, telegram
25-08-2022
Roasting 0ktapus: The phishing campaign going after Okta identity credentials
https://blog.group-ib.com/0ktapus
Actors/Campaigns:
0ktapus (motivation: cyber_criminal)
Threats:
Dharma
Anydesk_tool
Blackcat
Industry:
Financial, Education, Telco
Geo:
Canada, Usa, Singapore
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 2
Domain: 168
IP: 56
Softs:
django, telegram
Group-IB
Roasting 0ktapus: The phishing campaign going after Okta identity credentials
All about the phishing campaign that compromised over 130 organizations and the resources involved.
#ParsedReport
22-08-2022
Raven Storm, the Multi-Threading Tool Employed by Hacktivists for DDoS Attacks
https://cloudsek.com/threatintelligence/raven-storm-the-multi-threading-tool-employed-by-hacktivists-for-ddos-attacks/?utm_source=rss&utm_medium=rss&utm_campaign=raven-storm-the-multi-threading-tool-employed-by-hacktivists-for-ddos-attacks
22-08-2022
Raven Storm, the Multi-Threading Tool Employed by Hacktivists for DDoS Attacks
https://cloudsek.com/threatintelligence/raven-storm-the-multi-threading-tool-employed-by-hacktivists-for-ddos-attacks/?utm_source=rss&utm_medium=rss&utm_campaign=raven-storm-the-multi-threading-tool-employed-by-hacktivists-for-ddos-attacks
Cloudsek
Raven Storm, the Multi-Threading Tool Employed by Hacktivists for DDoS Attacks | Threat Intelligence | CloudSEK
CloudSEK’s contextual AI digital risk platform XVigil discovered a post by the Mysterious Team announcing the use of the Raven Storm tool DDoS attacks. The tool uses multi-threading for sending multiple packets at a single moment of time and getting the target…
#ParsedReport
25-08-2022
Scammers Impersonate Electricity Board Officials to Gain Device Access & Exfiltrate Funds
https://cloudsek.com/threatintelligence/scammers-impersonate-electricity-board-officials-to-gain-device-access-exfiltrate-funds/?utm_source=rss&utm_medium=rss&utm_campaign=scammers-impersonate-electricity-board-officials-to-gain-device-access-exfiltrate-funds
Industry:
Financial
25-08-2022
Scammers Impersonate Electricity Board Officials to Gain Device Access & Exfiltrate Funds
https://cloudsek.com/threatintelligence/scammers-impersonate-electricity-board-officials-to-gain-device-access-exfiltrate-funds/?utm_source=rss&utm_medium=rss&utm_campaign=scammers-impersonate-electricity-board-officials-to-gain-device-access-exfiltrate-funds
Industry:
Financial
CloudSEK - Digital Risk Management Enterprise | Artificial Intelligence based Cybersecurity
Scammers Impersonate Electricity Board Officials to Gain Device Access & Exfiltrate Funds - CloudSEK
We discovered a social engineering campaign launched by threat actors impersonating the official employees of KSEB (Kerala State Electricity Board).The campaign was carried out via text messages which requested the customers to connect with a particular number…