CTT Report Hub
3.42K subscribers
9.83K photos
6 videos
67 files
13.5K links
Threat Intelligence Report Hub
Download Telegram
#ParsedReport
24-08-2022

BitRAT and XMRig CoinMiner Being Distributed via Windows License Verification Tool

https://asec.ahnlab.com/en/37939

Threats:
Sbit_rat
Xmrig_miner
Trojan/win.generic.c5223158
Malware/mdp.download.m1197
Malware/mdp.drivebydownload.m1298

Geo:
Korean

IOCs:
File: 9
Path: 1
Domain: 1
Hash: 4
Url: 3
IP: 1

Softs:
google chrome, windows defender, telegram
#ParsedReport
24-08-2022

AgentTesla is threatening businesses around the world with a new campaign

https://decoded.avast.io/pavelnovak/agenttesla-is-threatening-businesses-around-the-world-with-a-new-campaign/?utm_source=rss&utm_medium=rss&utm_campaign=agenttesla-is-threatening-businesses-around-the-world-with-a-new-campaign

Threats:
Agent_tesla

Geo:
Switzerland, Argentina, Italy, Portugal, American, Germany, Romania, America, Spain, France, German

TTPs:
Tactics: 2
Technics: 0

IOCs:
File: 3
Hash: 3
Domain: 1

Softs:
android

Languages:
javascript

Links:
https://github.com/avast/ioc/tree/master/AgentTeslaISOCampaign
#ParsedReport
24-08-2022

Ransomware updates & 1-day exploits

https://securelist.com/ransomware-updates-1-day-exploits/107291

Threats:
Redalert
Monster

Industry:
Financial, Retail

Geo:
Indonesia, Singapore, Bolivia, Apac

CVEs:
CVE-2022-24521 [Vulners]
Vulners: Score: 4.6, CVSS: 4.2,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (-, 20h2, 21h1, 21h2, 1607, 1809, 1909)
- microsoft windows 11 (-, -)
- microsoft windows 7 (-)
- microsoft windows 8.1 (-)
- microsoft windows rt 8.1 (-)
have more...

Softs:
esxi

Algorithms:
aes

Languages:
rust, delphi

YARA: Found
#ParsedReport
24-08-2022

Ransomware Actor Abuses Genshin Impact Anti-Cheat Driver to Kill Antivirus

https://www.trendmicro.com/en_us/research/22/h/ransomware-actor-abuses-genshin-impact-anti-cheat-driver-to-kill-antivirus.html

Threats:
Fire_chili_rootkit
Fivesys
Impacket_tool

Industry:
Entertainment

IOCs:
File: 10
Hash: 1

Softs:
psexec, windows installer

Functions:
NtOpenFile, ZwTerminateProcess

Languages:
python

Links:
https://github.com/kagurazakasanae/Mhyprot2DrvControl
https://github.com/kkent030315/evil-mhyprot-cli
https://github.com/SecureAuthCorp/impacket/blob/impacket\_0\_10\_0/examples/wmiexec.py
https://github.com/SecureAuthCorp/impacket/blob/master/examples/secretsdump.py
https://github.com/kkent030315
#ParsedReport
24-08-2022

MagicWeb: NOBELIUMs post-compromise trick to authenticate as anyone

https://www.microsoft.com/security/blog/2022/08/24/magicweb-nobeliums-post-compromise-trick-to-authenticate-as-anyone

Actors/Campaigns:
Darkhalo (motivation: information_theft)

Threats:
Magicweb
Foggyweb

Industry:
Government, Ngo

Geo:
Asia

IOCs:
File: 17
Path: 1

Softs:
microsoft defender, active directory, microsoft 365 defender, windows firewall, adfs, azure ad

Functions:
beginprocessclaims, GetClientCertificate, ValidateX509Extensions, begingetclientcertificate, MagicWebs, AddClaims, beginendpointconfiguration, Build, Initialize, ProcessClaims, GetType, MagicWeb, ComputeHash, EndpointConfiguration, beginbuild, OverloadMethod, GetClaims, AddClaim, Add

Links:
https://github.com/Azure/Azure-Sentinel/tree/master/Detections/SecurityEvent/ADFSAbnormalEnhancedKeyUsageAttribute-OID.yaml
#ParsedReport
24-08-2022

The Anatomy of Wiper Malware, Part 2: Third-Party Drivers

https://www.crowdstrike.com/blog/the-anatomy-of-wiper-malware-part-2

Actors/Campaigns:
Turla
Agrius

Threats:
Sierras
Hermeticwiper
Disttrack
Dustman_wiper
Zerocleare_wiper
Alureon
Apostle
Killdisk
Doublezero
Isaacwiper
Israbye
Meteor_wiper
Ordinypt
Petya
Stonedrill_wiper
Whispergate

Industry:
Petroleum

Geo:
Ukraine, Tokyo

IOCs:
File: 3
Hash: 39

Softs:
windows service

Functions:
IoGetAttachedDeviceReference, WriteFile, SetFilePointer, IoBuildAsynchronousFsdRequest, DeviceIoControl, IoGetDeviceObjectPointer, CreateFile, IoBuildDeviceIoControlRequest

Links:
https://github.com/hfiref0x/TDL
#ParsedReport
24-08-2022

The Anatomy of Wiper Malware, Part 1: Common Techniques

https://www.crowdstrike.com/blog/the-anatomy-of-wiper-malware-part-1

Actors/Campaigns:
Agrius

Threats:
Disttrack
Petya
Ordinypt
Stonedrill
Olympic_destroyer
Dustman
Israbye
Killdisk
Doublezero
Hermeticwiper
Isaacwiper
Whispergate
Apostle
Meteor_wiper
Sierras

Industry:
Government, Energy, Petroleum, Entertainment

Geo:
Israel, Germany, Ukraine, Russia, Tokyo, Israeli, Russian, Korea

TTPs:
Tactics: 1
Technics: 0

IOCs:
Hash: 39
File: 1

Algorithms:
prng

Functions:
CreateFile, DeleteFile, FindFirstFile, NtFsControlFile, GetFileSize, FindNextFile, WriteFile

Platforms:
arm
#ParsedReport
25-08-2022

Kimsukys GoldDragon cluster and its C2 operations

https://securelist.com/kimsukys-golddragon-cluster-and-its-c2-operations/107258

Actors/Campaigns:
Kimsuky

Threats:
Gold_dragon

Industry:
Education, Government

Geo:
Korea, Asian, Australian, Korean

IOCs:
File: 35
Url: 51
Email: 7
Hash: 64
Domain: 6

Softs:
microsoft office, chrome, .net framework

Algorithms:
base64

Functions:
CreateObject, GetOfficeVersionNumber

Languages:
visual_basic, php

Platforms:
x64, x86
#ParsedReport
25-08-2022

The Dark Side of Bumblebee Malware Loader

https://www.deepinstinct.com/blog/the-dark-side-of-bumblebee-malware-loader

Actors/Campaigns:
Exotic_lily

Threats:
Bumblebee
Conti
Diavol
Ramnit
Trickbot
Quantum_locker

Geo:
Usa

IOCs:
File: 3
Hash: 5

Algorithms:
gzip

Functions:
main

Links:
https://github.com/LordNoteworthy/al-khaser
#ParsedReport
25-08-2022

BlueSky Ransomware \| AD Lateral Movement, Evasion and Fast Encryption Puts Threat on the Radar

https://www.sentinelone.com/blog/bluesky-ransomware-ad-lateral-movement-evasion-and-fast-encryption-puts-threat-on-the-radar

Actors/Campaigns:
Bluesky

Threats:
Cobalt_strike
Brc4_tool
Juicypotato_tool

Industry:
Ics

CVEs:
CVE-2022-21882 [Vulners]
Vulners: Score: 7.2, CVSS: 3.8,
Vulners: Exploitation: True
X-Force: Risk: 7
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2019 (-)
- microsoft windows 10 (1809, 1809, 1809, 1909, 1909, 1909, 20h2, 20h2, 20h2, 21h1, 21h1, 21h1, 21h2, 21h2, 21h2)
- microsoft windows 11 (-, -)
- microsoft windows server (20h2, 2022)

CVE-2021-1732 [Vulners]
Vulners: Score: 4.6, CVSS: 4.3,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (20h2, 1803, 1809, 1909, 2004)
- microsoft windows server 2016 (20h2, 1909, 2004)
- microsoft windows server 2019 (-)

CVE-2020-0796 [Vulners]
Vulners: Score: 7.5, CVSS: 3.2,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (1903, 1909)
- microsoft windows server 2016 (1903, 1909)


TTPs:

IOCs:
Domain: 2
Url: 15
File: 1
Path: 1
Hash: 18

Softs:
active directory

Functions:
GetLogicalDriveStringsW, NtSetInformationThread, NtQueryInformationProcess, TerminateProcess
#ParsedReport
25-08-2022

MERCURY leveraging Log4j 2 vulnerabilities in unpatched systems to target Israeli organizations

https://www.microsoft.com/security/blog/2022/08/25/mercury-leveraging-log4j-2-vulnerabilities-in-unpatched-systems-to-target-israeli-organizations

Actors/Campaigns:
Muddywater

Threats:
Mercury_tool
Log4shell_vuln
Screenconnect_tool
Venom_proxy_tool
Ligolo
Mimikatz
Remcom_tool
Ehorus_tool
Lsadump_tool
Dumplsass_tool

Geo:
Iran, Irans, Iranian, Israel, Israeli

CVEs:
CVE-2021-45046 [Vulners]
Vulners: Score: 5.1, CVSS: 1.8,
Vulners: Exploitation: True
X-Force: Risk: 9
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, <2.12.2, <2.16.0)
- intel oneapi (-)
- intel audio development kit (-)
- intel datacenter manager (-)
- intel system debugger (-)
have more...
CVE-2021-44228 [Vulners]
Vulners: Score: 9.3, CVSS: 4.5,
Vulners: Exploitation: True
X-Force: Risk: 10
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, <2.15.0, <2.3.1, <2.12.2)
- siemens sppa-t3000 ses3000 firmware (*)
- siemens logo\! soft comfort (*)
- siemens spectrum power 4 (4.70, 4.70, <4.70, 4.70)
- siemens siveillance control pro (*)
have more...

TTPs:
Tactics: 3
Technics: 0

IOCs:
File: 4
Path: 1
Url: 1
IP: 2
Hash: 11

Softs:
apache log4j, microsoft 365 defender, microsoft sql, microsoft defender

Languages:
php

Links:
https://github.com/Azure/Azure-Sentinel/blob/master/Detections/MultipleDataSources/PotentialMercury\_Webshell.yaml
https://github.com/Azure/Azure-Sentinel/blob/master/Detections/MultipleDataSources/powershell\_mercury.yaml
https://github.com/Azure/Azure-Sentinel/blob/master/Detections/MultipleDataSources/Mercury\_Log4j\_August2022.yaml
#ParsedReport
25-08-2022

SEARCH. Cybercrime Group TA558 Ramps Up Email Attacks Against Hotels

https://www.proofpoint.com/us/newsroom/news/cybercrime-group-ta558-ramps-email-attacks-against-hotels

Actors/Campaigns:
Ta558 (motivation: cyber_criminal, information_theft)

Threats:
Revenge_rat
Loda_rat
Vjw0rm
Asyncrat_rat

Industry:
Financial, Healthcare

Geo:
America, Spanish, Portuguese

CVEs:
CVE-2017-11882 [Vulners]
Vulners: Score: 9.3, CVSS: 4.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2013, 2010, 2016, 2007)


Languages:
javascript, autoit
#ParsedReport
25-08-2022

Roasting 0ktapus: The phishing campaign going after Okta identity credentials

https://blog.group-ib.com/0ktapus

Actors/Campaigns:
0ktapus (motivation: cyber_criminal)

Threats:
Dharma
Anydesk_tool
Blackcat

Industry:
Financial, Education, Telco

Geo:
Canada, Usa, Singapore

TTPs:
Tactics: 1
Technics: 0

IOCs:
File: 2
Domain: 168
IP: 56

Softs:
django, telegram
#ParsedReport
25-08-2022

Moisha Ransomware In Action

https://blog.cyble.com/2022/08/25/moisha-ransomware-in-action

Threats:
Moisha

Industry:
Financial

Geo:
Georgia, India, Australia, Singapore, Dubai

TTPs:
Tactics: 3
Technics: 12

IOCs:
File: 2
Hash: 1

Softs:
vssadmin, microsoft defender

Algorithms:
base64, aes

Functions:
RecursePath, GetAllShares, OnItemArrived, GetComputerShares, NetWkstaGetInfo, WriteToFileThreadSafe, EnumNetShares, encryptor
#ParsedReport
25-08-2022

Making victims pay, infostealer malwares mimick pirated-software download sites

https://www.zscaler.com/blogs/security-research/making-victims-pay-infostealer-malwares-mimick-pirated-software-download

Threats:
Redline_stealer
Recordbreaker_stealer
Themida_tool
Vmprotect_tool
Mpress_tool

Industry:
Financial

IOCs:
File: 3
Coin: 3
IP: 39
Domain: 124

Softs:
coin98, iconex, liquality, keplr, discord, solflare, cloverwallet, binancechain, coinbase, microsoft office, xdefi, polymeshwallet, tronlink, guildwallet, aurowallet, cyanowallet, rabby, waveskeeper, terrastation, neoline, sollet, tezbox, saturnwallet

Algorithms:
zip

Functions:
FindWindow
#ParsedReport
25-08-2022

Timeline & TTPs of TeamTNT Cybercrime Group

https://cloudsek.com/threatintelligence/timeline-ttps-of-teamtnt-cybercrime-group/?utm_source=rss&utm_medium=rss&utm_campaign=timeline-ttps-of-teamtnt-cybercrime-group

Actors/Campaigns:
Teamtnt
Chimaera
Wayback

Threats:
Credential_stealing_technique
Hildegard
Pnscan_tool
Tsunami_botnet
Masscan_tool
Zgrab_scanner_tool
Diamorphine_rootkit
Mimipy
Mimipenguin_tool
Lazagne
Xmrig_miner
Upx_tool
Cetus

Geo:
Asian, German, Chinese, Germany, Deutschland

CVEs:
CVE-2019-5736 [Vulners]
Vulners: Score: 9.3, CVSS: 4.7,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.7
X-Force: Patch: Official fix
Soft:
- docker (<18.09.2)
- linuxfoundation runc (le0.1.1, 1.0.0, 1.0.0, 1.0.0, 1.0.0, 1.0.0, 1.0.0)
- redhat container development kit (3.7)
- redhat openshift (3.4, 3.5, 3.6, 3.7)
- redhat enterprise linux (8.0)
have more...

TTPs:
Tactics: 2
Technics: 0

IOCs:
Url: 1
Hash: 29
Domain: 2
Email: 1
File: 2
IP: 7

Softs:
unix, postgresql, curl, redis, ubuntu, docker

Links:
https://github.com/zmap/zgrab2
https://github.com/AlessandroZ/LaZagne
https://github.com/n1nj4sec/mimipy
https://github.com/guitmz/ezuri
https://github.com/PercussiveElbow/docker-escape-tool
https://github.com/Bendr0id/xmrigCC
https://github.com/isdrupter/ziggystartux
https://github.com/robertdavidgraham/masscan
https://github.com/r3vn/punk.py
https://github.com/upx/upx
https://github.com/weaveworks/scope
https://github.com/huntergregal/mimipenguin
https://github.com/HildeTeamTNT
https://github.com/ptrrkssn/pnscan
https://github.com/brompwnie/botb
https://github.com/IncSTK/rathole
https://github.com/m0nad/Diamorphine
https://github.com/gianlucaborello/libprocesshider
https://github.com/inguardians/peirates