CTT Report Hub
3.42K subscribers
9.84K photos
6 videos
67 files
13.5K links
Threat Intelligence Report Hub
Download Telegram
#ParsedReport
25-08-2022

New Golang Ransomware Agenda Customizes Attacks

https://www.trendmicro.com/en_us/research/22/h/new-golang-ransomware-agenda-customizes-attacks.html

Actors/Campaigns:
Qilin

Threats:
Mauicrypt
Blackbasta
Revil
Process_injection_technique
Trojan.win64.agenda.svt

Industry:
Healthcare, Financial, Education

Geo:
Africa, Asia, Thailand, Indonesia

IOCs:
Path: 2
File: 31
Registry: 2

Softs:
ntrtscan, bcdedit, active directory, vssadmin, winlogon

Algorithms:
rsa-2048, aes-256

Functions:
rand_read, CreateProcessAsUserW

Languages:
golang
#ParsedReport
25-08-2022

Luca Stealer Targets Password Managers and Cryptocurrency Wallets

https://blogs.blackberry.com/en/2022/08/luca-stealer-targets-password-managers-and-cryptocurrency-wallets

Threats:
Luca_stealer
Screengrab
Zingo_stealer

Industry:
E-commerce, Financial

TTPs:
Tactics: 2
Technics: 0

IOCs:
File: 5
Hash: 2

Softs:
coccoc, onekey, iconex, google chrome, coinomi, byone, jaxx, 7star, coin98, chrome, microsoft edge, coowoo, macos, sleipnir, binancechain, torch, discord, vivaldi, telegram, bitwarden, zcash, steem, liebao, kometa, orbitum, lastpass, terra, opera, tronlink, chedot, brave-browser, sollet, neoline, keychain, amigo, dappplay, keplr, chromium, iwallet, wombat, bitclip, electrum, tezbox, centbrowser

Algorithms:
zip

Languages:
rust

YARA: Found
#ParsedReport
26-08-2022

Dark Web Profile: BlackCat (ALPHV)

https://socradar.io/dark-web-profile-blackcat-alphv

Actors/Campaigns:
Blackcat
Darkside

Threats:
Blackcat
Revil
Lockbit

Industry:
Aerospace, Financial, E-commerce

Geo:
Austrian, Spain, Kuwait, Russian, Thailand, America

IOCs:
Hash: 21

Softs:
lastpass

Languages:
rust
#ParsedReport
26-08-2022

Twilio and MailChimp Attackers Hit 130 Organizations with Okta Phishing Campaign

https://socradar.io/twilio-and-mailchimp-attackers-hit-130-organizations-with-okta-phishing-campaign

Actors/Campaigns:
0ktapus

Industry:
Education, Retail, Telco, Logistic, E-commerce, Financial

Geo:
Usa, Australia, India, Canada, France, Spain, Sweden

IOCs:
Domain: 168

Softs:
coinbase, slack, telegram, lastpass
#ParsedReport
26-08-2022

Threat Assessment: Black Basta Ransomware

https://unit42.paloaltonetworks.com/threat-assessment-black-basta-ransomware

Threats:
Blackbasta
Conti
Qakbot
Megacortex
Prolock
Doppelpaymer
Egregor
Antidebugging_technique
Mimikatz
Teamviewer_tool
Cobalt_strike

Industry:
E-commerce, Energy, Financial, Foodtech, Government, Transport

Geo:
Japanese, Australia, Germany, Japan, France, Canada, Switzerland, Emea, Netherlands, America, Italy, Apac

TTPs:
Tactics: 12
Technics: 28

IOCs:
File: 8
Path: 2

Softs:
windows service, esxi, psexec, windows defender, bcdedit, vssadmin

Algorithms:
zip , chacha20, rsa-4096

Functions:
GetComputerName, North
Channel name was changed to «TI Reports»
#ParsedReport
26-08-2022

ISaPWN research on the security of ISaGRAF Runtime

https://ics-cert.kaspersky.com/publications/reports/2022/05/23/isapwn-research-on-the-security-of-isagraf-runtime

Industry:
Energy, Ics, Transport

CVEs:
CVE-2020-25180 [Vulners]
Vulners: Score: 4.3, CVSS: 3.1,
Vulners: Exploitation: Unknown
X-Force: Risk: Unknown
X-Force: Patch: Unknown
Soft:
- schneider-electric easergy t300 firmware (le2.7.1)
- schneider-electric easergy c5 firmware (<1.1.0)
- schneider-electric micom c264 firmware (<d6.1)
- schneider-electric pacis gtw firmware (5.1, 5.2, 6.1, 6.3, 6.3)
- schneider-electric saitel dp firmware (le11.06.21)
have more...
CVE-2020-25182 [Vulners]
Vulners: Score: 4.6, CVSS: 6.7,
Vulners: Exploitation: Unknown
X-Force: Risk: 6.7
X-Force: Patch: Official fix
Soft:
- schneider-electric easergy t300 firmware (le2.7.1)
- schneider-electric easergy c5 firmware (<1.1.0)
- schneider-electric micom c264 firmware (<d6.1)
- schneider-electric pacis gtw firmware (5.1, 5.2, 6.1, 6.3, 6.3)
- schneider-electric saitel dp firmware (le11.06.21)
have more...
CVE-2020-25176 [Vulners]
Vulners: Score: 9.3, CVSS: 5.3,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.1
X-Force: Patch: Official fix
Soft:
- schneider-electric easergy t300 firmware (le2.7.1)
- schneider-electric easergy c5 firmware (<1.1.0)
- schneider-electric micom c264 firmware (<d6.1)
- schneider-electric pacis gtw firmware (5.1, 5.2, 6.1, 6.3, 6.3)
- schneider-electric saitel dp firmware (le11.06.21)
have more...

IOCs:
File: 6

Algorithms:
crc

Languages:
python
#ParsedReport
26-08-2022

QBOT Malware Analysis. Key takeaways

https://www.elastic.co/security-labs/qbot-malware-analysis

Threats:
Qakbot
Process_injection_technique
Dll_injection_technique

Industry:
Financial, Government

TTPs:
Tactics: 6
Technics: 12

IOCs:
File: 31
Path: 2
Registry: 1
IP: 150

Softs:
windows defender

Algorithms:
xor, crc, prng

Functions:
GetString, GetStringAux, WriteProcessMemory, GetApi, CreateProcess

Platforms:
x64, x86

YARA: Found

Links:
https://github.com/elastic/protections-artifacts/blob/main/yara/rules/Windows\_Trojan\_Qbot.yar
#technique

https://github.com/Markakd/DirtyCred

DirtyCred is a kernel exploitation concept that swaps unprivileged kernel credentials with privileged ones to escalate privilege. Instead of overwriting any critical data fields on kernel heap, DirtyCred abuses the heap memory reuse mechanism to get privileged. Although the concept is simple, it is effective.
#technique

https://github.com/KiFilterFiberContext/warbird-hook

On Windows 10 21H2, PatchGuard does not (afaik) verify the integrity of pointers of nt!g_kernelCallbacks, unlike nt!SeCiCallbacks. The callback table contains pointers to an image named ClipSp.sys, which is a signed driver protected by Microsoft Warbird used for licensing checks (called from nt!SPCall2ServerInternal).

The interesting thing about it is that PatchGuard does not verify the integrity of several image sections, including PAGEwx, which the driver contains in order to decrypt and re-encrypt its own code during runtime.
#ParsedReport
29-08-2022

Check Point Research detects Crypto Miner malware disguised as Google translate desktop and other legitimate applications

https://research.checkpoint.com/2022/check-point-research-detects-crypto-miner-malware-disguised-as-google-translate-desktop-and-other-legitimate-applications

Threats:
Nitrokod
Xmrig_miner

Geo:
Turkish

IOCs:
Domain: 3
File: 8
Url: 1
Path: 3
IP: 1
Hash: 6

Softs:
windows defender, chromium, windows installer

Algorithms:
base64

Platforms:
x86
#ParsedReport
29-08-2022

(OLE). Hangul document disguised as a profile form (OLE object)

https://asec.ahnlab.com/ko/38216

Actors/Campaigns:
Darkhalo

Threats:
Trojan/win.agent.c5228370

Geo:
Korean

CVEs:
CVE-2018-15982 [Vulners]
Vulners: Score: 10.0, CVSS: 5.9,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- adobe flash player (le31.0.0.153, le31.0.0.153, le31.0.0.153, le31.0.0.153)
- redhat enterprise linux desktop (6.0)
- redhat enterprise linux workstation (6.0)
- redhat enterprise linux server (6.0)
- adobe flash player installer (le31.0.0.108)
have more...

IOCs:
File: 22
Url: 4
Path: 1
Hash: 6
#ParsedReport
29-08-2022

Crypto miners latest techniques

https://cybersecurity.att.com/blogs/labs-research/crypto-miners-latest-techniques

Threats:
Alien

Industry:
Iot

TTPs:
Tactics: 8
Technics: 22

IOCs:
Registry: 3
Path: 10
Domain: 3
File: 5
Hash: 7

Softs:
microsoft excel, windows service, windows defender

Win API:
CmRcService, CmRccService
#ParsedReport
29-08-2022

Traffers: a deep dive into the information stealer ecosystem

https://blog.sekoia.io/traffers-a-deep-dive-into-the-information-stealer-ecosystem

Threats:
Traffer
Raccoon_stealer
Vidar_stealer
Redline_stealer
Hydra
Meta_stealer
Ytstealer

Industry:
Media, E-commerce, Financial, Entertainment

Geo:
Russian

IOCs:
Url: 6
Domain: 1
File: 2
Hash: 2
IP: 1

Softs:
windows defender, telegram, discord
#ParsedReport
29-08-2022

AsyncRAT: Using Fully Undetected Downloader

https://www.netskope.com/blog/asyncrat-using-fully-undetected-downloader

Threats:
Asyncrat_rat
Process_hollowing_technique
Ousaban

Industry:
Financial

Geo:
Japanese, Latam

TTPs:
Tactics: 1
Technics: 0

IOCs:
File: 7

Softs:
microsoft office, windows defender

Algorithms:
hmac, cbc, aes, aes-256, base64

Functions:
InitializeSettings

Languages:
python

SIGMA: Found

Links:
https://github.com/NYAN-x-CAT/AsyncRAT-C-Sharp
https://github.com/netskopeoss/NetskopeThreatLabsIOCs/tree/main/AsyncRAT
https://github.com/netskopeoss/NetskopeThreatLabsIOCs/tree/main/AsyncRAT/script
#ParsedReport
30-08-2022

Rising Tide: Chasing the Currents of Espionage in the South China Sea

https://www.proofpoint.com/us/blog/threat-insight/chasing-currents-espionage-south-china-sea

Actors/Campaigns:
Red_ladon (motivation: cyber_espionage)
Leviathan
Red_sylvan
Stone_panda
Emissary_panda
Earth_empusa
Luckycat

Threats:
Scanbox
Ladon_tool
Rtf_template_inject_technique
Phoenix_keylogger
Meterpreter_tool
Watering_hole_technique
Dll_sideloading_technique
Beacon

Industry:
Maritime, Financial, Healthcare, Energy, Government, Petroleum, Education

Geo:
Taiwan, Australia, Malaysia, Australian, China, Cambodia, Pacific, Chinese, Asia

IOCs:
Domain: 7
Url: 28
File: 7
IP: 6
Email: 18
Hash: 31

Softs:
chrome, webrtc, opera, microsoft word, mariadb, internet explorer

Algorithms:
xor, zip

Languages:
php, java, javascript

Links:
https://github.com/nico3333fr/CSP-useful/blob/master/csp-wtf/explained.md
#ParsedReport
30-08-2022

Mini Stealer: Possible Predecessor of Parrot Stealer

https://blog.cyble.com/2022/08/29/mini-stealer-possible-predecessor-of-parrot-stealer

Threats:
Ministealer
Parrotstealer
Timestomp_technique
Antidebugging_technique
Beacon

TTPs:
Tactics: 6
Technics: 13

IOCs:
File: 2
Hash: 1

Softs:
sleipnir, vivaldi, winscp, kometa, orbitum, browser360, operagx, avastbrowser, chedot, epicprivacybrowser, centbrowser, comododragon

Algorithms:
zip

Win API:
IsDebuggerPresent
#ParsedReport
30-08-2022

Crypto miners latest techniques

https://cybersecurity.att.com/blogs/labs-research/crypto-miners-latest-techniques

Threats:
Alien

Industry:
Iot

Geo:
Mexican

TTPs:
Tactics: 8
Technics: 22

IOCs:
Registry: 3
Path: 10
Domain: 3
File: 5
Hash: 7

Softs:
microsoft excel, windows service, windows defender

Win API:
CmRccService, CmRcService