CTT Report Hub
3.42K subscribers
9.83K photos
6 videos
67 files
13.5K links
Threat Intelligence Report Hub
Download Telegram
#ParsedReport
25-08-2022

SEARCH. Cybercrime Group TA558 Ramps Up Email Attacks Against Hotels

https://www.proofpoint.com/us/newsroom/news/cybercrime-group-ta558-ramps-email-attacks-against-hotels

Actors/Campaigns:
Ta558 (motivation: cyber_criminal, information_theft)

Threats:
Revenge_rat
Loda_rat
Vjw0rm
Asyncrat_rat

Industry:
Financial, Healthcare

Geo:
America, Spanish, Portuguese

CVEs:
CVE-2017-11882 [Vulners]
Vulners: Score: 9.3, CVSS: 4.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2013, 2010, 2016, 2007)


Languages:
javascript, autoit
#ParsedReport
25-08-2022

Roasting 0ktapus: The phishing campaign going after Okta identity credentials

https://blog.group-ib.com/0ktapus

Actors/Campaigns:
0ktapus (motivation: cyber_criminal)

Threats:
Dharma
Anydesk_tool
Blackcat

Industry:
Financial, Education, Telco

Geo:
Canada, Usa, Singapore

TTPs:
Tactics: 1
Technics: 0

IOCs:
File: 2
Domain: 168
IP: 56

Softs:
django, telegram
#ParsedReport
25-08-2022

Moisha Ransomware In Action

https://blog.cyble.com/2022/08/25/moisha-ransomware-in-action

Threats:
Moisha

Industry:
Financial

Geo:
Georgia, India, Australia, Singapore, Dubai

TTPs:
Tactics: 3
Technics: 12

IOCs:
File: 2
Hash: 1

Softs:
vssadmin, microsoft defender

Algorithms:
base64, aes

Functions:
RecursePath, GetAllShares, OnItemArrived, GetComputerShares, NetWkstaGetInfo, WriteToFileThreadSafe, EnumNetShares, encryptor
#ParsedReport
25-08-2022

Making victims pay, infostealer malwares mimick pirated-software download sites

https://www.zscaler.com/blogs/security-research/making-victims-pay-infostealer-malwares-mimick-pirated-software-download

Threats:
Redline_stealer
Recordbreaker_stealer
Themida_tool
Vmprotect_tool
Mpress_tool

Industry:
Financial

IOCs:
File: 3
Coin: 3
IP: 39
Domain: 124

Softs:
coin98, iconex, liquality, keplr, discord, solflare, cloverwallet, binancechain, coinbase, microsoft office, xdefi, polymeshwallet, tronlink, guildwallet, aurowallet, cyanowallet, rabby, waveskeeper, terrastation, neoline, sollet, tezbox, saturnwallet

Algorithms:
zip

Functions:
FindWindow
#ParsedReport
25-08-2022

Timeline & TTPs of TeamTNT Cybercrime Group

https://cloudsek.com/threatintelligence/timeline-ttps-of-teamtnt-cybercrime-group/?utm_source=rss&utm_medium=rss&utm_campaign=timeline-ttps-of-teamtnt-cybercrime-group

Actors/Campaigns:
Teamtnt
Chimaera
Wayback

Threats:
Credential_stealing_technique
Hildegard
Pnscan_tool
Tsunami_botnet
Masscan_tool
Zgrab_scanner_tool
Diamorphine_rootkit
Mimipy
Mimipenguin_tool
Lazagne
Xmrig_miner
Upx_tool
Cetus

Geo:
Asian, German, Chinese, Germany, Deutschland

CVEs:
CVE-2019-5736 [Vulners]
Vulners: Score: 9.3, CVSS: 4.7,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.7
X-Force: Patch: Official fix
Soft:
- docker (<18.09.2)
- linuxfoundation runc (le0.1.1, 1.0.0, 1.0.0, 1.0.0, 1.0.0, 1.0.0, 1.0.0)
- redhat container development kit (3.7)
- redhat openshift (3.4, 3.5, 3.6, 3.7)
- redhat enterprise linux (8.0)
have more...

TTPs:
Tactics: 2
Technics: 0

IOCs:
Url: 1
Hash: 29
Domain: 2
Email: 1
File: 2
IP: 7

Softs:
unix, postgresql, curl, redis, ubuntu, docker

Links:
https://github.com/zmap/zgrab2
https://github.com/AlessandroZ/LaZagne
https://github.com/n1nj4sec/mimipy
https://github.com/guitmz/ezuri
https://github.com/PercussiveElbow/docker-escape-tool
https://github.com/Bendr0id/xmrigCC
https://github.com/isdrupter/ziggystartux
https://github.com/robertdavidgraham/masscan
https://github.com/r3vn/punk.py
https://github.com/upx/upx
https://github.com/weaveworks/scope
https://github.com/huntergregal/mimipenguin
https://github.com/HildeTeamTNT
https://github.com/ptrrkssn/pnscan
https://github.com/brompwnie/botb
https://github.com/IncSTK/rathole
https://github.com/m0nad/Diamorphine
https://github.com/gianlucaborello/libprocesshider
https://github.com/inguardians/peirates
#ParsedReport
25-08-2022

New Golang Ransomware Agenda Customizes Attacks

https://www.trendmicro.com/en_us/research/22/h/new-golang-ransomware-agenda-customizes-attacks.html

Actors/Campaigns:
Qilin

Threats:
Mauicrypt
Blackbasta
Revil
Process_injection_technique
Trojan.win64.agenda.svt

Industry:
Healthcare, Financial, Education

Geo:
Africa, Asia, Thailand, Indonesia

IOCs:
Path: 2
File: 31
Registry: 2

Softs:
ntrtscan, bcdedit, active directory, vssadmin, winlogon

Algorithms:
rsa-2048, aes-256

Functions:
rand_read, CreateProcessAsUserW

Languages:
golang
#ParsedReport
25-08-2022

Luca Stealer Targets Password Managers and Cryptocurrency Wallets

https://blogs.blackberry.com/en/2022/08/luca-stealer-targets-password-managers-and-cryptocurrency-wallets

Threats:
Luca_stealer
Screengrab
Zingo_stealer

Industry:
E-commerce, Financial

TTPs:
Tactics: 2
Technics: 0

IOCs:
File: 5
Hash: 2

Softs:
coccoc, onekey, iconex, google chrome, coinomi, byone, jaxx, 7star, coin98, chrome, microsoft edge, coowoo, macos, sleipnir, binancechain, torch, discord, vivaldi, telegram, bitwarden, zcash, steem, liebao, kometa, orbitum, lastpass, terra, opera, tronlink, chedot, brave-browser, sollet, neoline, keychain, amigo, dappplay, keplr, chromium, iwallet, wombat, bitclip, electrum, tezbox, centbrowser

Algorithms:
zip

Languages:
rust

YARA: Found
#ParsedReport
26-08-2022

Dark Web Profile: BlackCat (ALPHV)

https://socradar.io/dark-web-profile-blackcat-alphv

Actors/Campaigns:
Blackcat
Darkside

Threats:
Blackcat
Revil
Lockbit

Industry:
Aerospace, Financial, E-commerce

Geo:
Austrian, Spain, Kuwait, Russian, Thailand, America

IOCs:
Hash: 21

Softs:
lastpass

Languages:
rust
#ParsedReport
26-08-2022

Twilio and MailChimp Attackers Hit 130 Organizations with Okta Phishing Campaign

https://socradar.io/twilio-and-mailchimp-attackers-hit-130-organizations-with-okta-phishing-campaign

Actors/Campaigns:
0ktapus

Industry:
Education, Retail, Telco, Logistic, E-commerce, Financial

Geo:
Usa, Australia, India, Canada, France, Spain, Sweden

IOCs:
Domain: 168

Softs:
coinbase, slack, telegram, lastpass
#ParsedReport
26-08-2022

Threat Assessment: Black Basta Ransomware

https://unit42.paloaltonetworks.com/threat-assessment-black-basta-ransomware

Threats:
Blackbasta
Conti
Qakbot
Megacortex
Prolock
Doppelpaymer
Egregor
Antidebugging_technique
Mimikatz
Teamviewer_tool
Cobalt_strike

Industry:
E-commerce, Energy, Financial, Foodtech, Government, Transport

Geo:
Japanese, Australia, Germany, Japan, France, Canada, Switzerland, Emea, Netherlands, America, Italy, Apac

TTPs:
Tactics: 12
Technics: 28

IOCs:
File: 8
Path: 2

Softs:
windows service, esxi, psexec, windows defender, bcdedit, vssadmin

Algorithms:
zip , chacha20, rsa-4096

Functions:
GetComputerName, North
Channel name was changed to «TI Reports»
#ParsedReport
26-08-2022

ISaPWN research on the security of ISaGRAF Runtime

https://ics-cert.kaspersky.com/publications/reports/2022/05/23/isapwn-research-on-the-security-of-isagraf-runtime

Industry:
Energy, Ics, Transport

CVEs:
CVE-2020-25180 [Vulners]
Vulners: Score: 4.3, CVSS: 3.1,
Vulners: Exploitation: Unknown
X-Force: Risk: Unknown
X-Force: Patch: Unknown
Soft:
- schneider-electric easergy t300 firmware (le2.7.1)
- schneider-electric easergy c5 firmware (<1.1.0)
- schneider-electric micom c264 firmware (<d6.1)
- schneider-electric pacis gtw firmware (5.1, 5.2, 6.1, 6.3, 6.3)
- schneider-electric saitel dp firmware (le11.06.21)
have more...
CVE-2020-25182 [Vulners]
Vulners: Score: 4.6, CVSS: 6.7,
Vulners: Exploitation: Unknown
X-Force: Risk: 6.7
X-Force: Patch: Official fix
Soft:
- schneider-electric easergy t300 firmware (le2.7.1)
- schneider-electric easergy c5 firmware (<1.1.0)
- schneider-electric micom c264 firmware (<d6.1)
- schneider-electric pacis gtw firmware (5.1, 5.2, 6.1, 6.3, 6.3)
- schneider-electric saitel dp firmware (le11.06.21)
have more...
CVE-2020-25176 [Vulners]
Vulners: Score: 9.3, CVSS: 5.3,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.1
X-Force: Patch: Official fix
Soft:
- schneider-electric easergy t300 firmware (le2.7.1)
- schneider-electric easergy c5 firmware (<1.1.0)
- schneider-electric micom c264 firmware (<d6.1)
- schneider-electric pacis gtw firmware (5.1, 5.2, 6.1, 6.3, 6.3)
- schneider-electric saitel dp firmware (le11.06.21)
have more...

IOCs:
File: 6

Algorithms:
crc

Languages:
python
#ParsedReport
26-08-2022

QBOT Malware Analysis. Key takeaways

https://www.elastic.co/security-labs/qbot-malware-analysis

Threats:
Qakbot
Process_injection_technique
Dll_injection_technique

Industry:
Financial, Government

TTPs:
Tactics: 6
Technics: 12

IOCs:
File: 31
Path: 2
Registry: 1
IP: 150

Softs:
windows defender

Algorithms:
xor, crc, prng

Functions:
GetString, GetStringAux, WriteProcessMemory, GetApi, CreateProcess

Platforms:
x64, x86

YARA: Found

Links:
https://github.com/elastic/protections-artifacts/blob/main/yara/rules/Windows\_Trojan\_Qbot.yar
#technique

https://github.com/Markakd/DirtyCred

DirtyCred is a kernel exploitation concept that swaps unprivileged kernel credentials with privileged ones to escalate privilege. Instead of overwriting any critical data fields on kernel heap, DirtyCred abuses the heap memory reuse mechanism to get privileged. Although the concept is simple, it is effective.
#technique

https://github.com/KiFilterFiberContext/warbird-hook

On Windows 10 21H2, PatchGuard does not (afaik) verify the integrity of pointers of nt!g_kernelCallbacks, unlike nt!SeCiCallbacks. The callback table contains pointers to an image named ClipSp.sys, which is a signed driver protected by Microsoft Warbird used for licensing checks (called from nt!SPCall2ServerInternal).

The interesting thing about it is that PatchGuard does not verify the integrity of several image sections, including PAGEwx, which the driver contains in order to decrypt and re-encrypt its own code during runtime.
#ParsedReport
29-08-2022

Check Point Research detects Crypto Miner malware disguised as Google translate desktop and other legitimate applications

https://research.checkpoint.com/2022/check-point-research-detects-crypto-miner-malware-disguised-as-google-translate-desktop-and-other-legitimate-applications

Threats:
Nitrokod
Xmrig_miner

Geo:
Turkish

IOCs:
Domain: 3
File: 8
Url: 1
Path: 3
IP: 1
Hash: 6

Softs:
windows defender, chromium, windows installer

Algorithms:
base64

Platforms:
x86
#ParsedReport
29-08-2022

(OLE). Hangul document disguised as a profile form (OLE object)

https://asec.ahnlab.com/ko/38216

Actors/Campaigns:
Darkhalo

Threats:
Trojan/win.agent.c5228370

Geo:
Korean

CVEs:
CVE-2018-15982 [Vulners]
Vulners: Score: 10.0, CVSS: 5.9,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- adobe flash player (le31.0.0.153, le31.0.0.153, le31.0.0.153, le31.0.0.153)
- redhat enterprise linux desktop (6.0)
- redhat enterprise linux workstation (6.0)
- redhat enterprise linux server (6.0)
- adobe flash player installer (le31.0.0.108)
have more...

IOCs:
File: 22
Url: 4
Path: 1
Hash: 6