#ParsedReport
25-08-2022
New Golang Ransomware Agenda Customizes Attacks
https://www.trendmicro.com/en_us/research/22/h/new-golang-ransomware-agenda-customizes-attacks.html
Actors/Campaigns:
Qilin
Threats:
Mauicrypt
Blackbasta
Revil
Process_injection_technique
Trojan.win64.agenda.svt
Industry:
Healthcare, Financial, Education
Geo:
Africa, Asia, Thailand, Indonesia
IOCs:
Path: 2
File: 31
Registry: 2
Softs:
ntrtscan, bcdedit, active directory, vssadmin, winlogon
Algorithms:
rsa-2048, aes-256
Functions:
rand_read, CreateProcessAsUserW
Languages:
golang
25-08-2022
New Golang Ransomware Agenda Customizes Attacks
https://www.trendmicro.com/en_us/research/22/h/new-golang-ransomware-agenda-customizes-attacks.html
Actors/Campaigns:
Qilin
Threats:
Mauicrypt
Blackbasta
Revil
Process_injection_technique
Trojan.win64.agenda.svt
Industry:
Healthcare, Financial, Education
Geo:
Africa, Asia, Thailand, Indonesia
IOCs:
Path: 2
File: 31
Registry: 2
Softs:
ntrtscan, bcdedit, active directory, vssadmin, winlogon
Algorithms:
rsa-2048, aes-256
Functions:
rand_read, CreateProcessAsUserW
Languages:
golang
Trend Micro
New Golang Ransomware Agenda Customizes Attacks
A new piece of ransomware written in the Go language has been targeting healthcare and education enterprises in Asia and Africa. This ransomware is called Agenda and is customized per victim.
#ParsedReport
25-08-2022
Luca Stealer Targets Password Managers and Cryptocurrency Wallets
https://blogs.blackberry.com/en/2022/08/luca-stealer-targets-password-managers-and-cryptocurrency-wallets
Threats:
Luca_stealer
Screengrab
Zingo_stealer
Industry:
E-commerce, Financial
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 5
Hash: 2
Softs:
coccoc, onekey, iconex, google chrome, coinomi, byone, jaxx, 7star, coin98, chrome, microsoft edge, coowoo, macos, sleipnir, binancechain, torch, discord, vivaldi, telegram, bitwarden, zcash, steem, liebao, kometa, orbitum, lastpass, terra, opera, tronlink, chedot, brave-browser, sollet, neoline, keychain, amigo, dappplay, keplr, chromium, iwallet, wombat, bitclip, electrum, tezbox, centbrowser
Algorithms:
zip
Languages:
rust
YARA: Found
25-08-2022
Luca Stealer Targets Password Managers and Cryptocurrency Wallets
https://blogs.blackberry.com/en/2022/08/luca-stealer-targets-password-managers-and-cryptocurrency-wallets
Threats:
Luca_stealer
Screengrab
Zingo_stealer
Industry:
E-commerce, Financial
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 5
Hash: 2
Softs:
coccoc, onekey, iconex, google chrome, coinomi, byone, jaxx, 7star, coin98, chrome, microsoft edge, coowoo, macos, sleipnir, binancechain, torch, discord, vivaldi, telegram, bitwarden, zcash, steem, liebao, kometa, orbitum, lastpass, terra, opera, tronlink, chedot, brave-browser, sollet, neoline, keychain, amigo, dappplay, keplr, chromium, iwallet, wombat, bitclip, electrum, tezbox, centbrowser
Algorithms:
zip
Languages:
rust
YARA: Found
BlackBerry
Luca Stealer Targets Password Managers and Cryptocurrency Wallets
Luca Stealer contains much of the functionality expected from a typical infostealer, with an added focus on crypto-wallets and password management software. This malware is likely to continue to see a steady rise in use, as more and more threat actors get…
#ParsedReport
26-08-2022
Dark Web Profile: BlackCat (ALPHV)
https://socradar.io/dark-web-profile-blackcat-alphv
Actors/Campaigns:
Blackcat
Darkside
Threats:
Blackcat
Revil
Lockbit
Industry:
Aerospace, Financial, E-commerce
Geo:
Austrian, Spain, Kuwait, Russian, Thailand, America
IOCs:
Hash: 21
Softs:
lastpass
Languages:
rust
26-08-2022
Dark Web Profile: BlackCat (ALPHV)
https://socradar.io/dark-web-profile-blackcat-alphv
Actors/Campaigns:
Blackcat
Darkside
Threats:
Blackcat
Revil
Lockbit
Industry:
Aerospace, Financial, E-commerce
Geo:
Austrian, Spain, Kuwait, Russian, Thailand, America
IOCs:
Hash: 21
Softs:
lastpass
Languages:
rust
SOCRadar® Cyber Intelligence Inc.
Dark Web Profile: BlackCat (ALPHV) - SOCRadar® Cyber Intelligence Inc.
December 19, 2023: As we speculated recently, law enforcement agencies have successfully taken control of the official site of the ALPHV.** Read more under
#ParsedReport
26-08-2022
Twilio and MailChimp Attackers Hit 130 Organizations with Okta Phishing Campaign
https://socradar.io/twilio-and-mailchimp-attackers-hit-130-organizations-with-okta-phishing-campaign
Actors/Campaigns:
0ktapus
Industry:
Education, Retail, Telco, Logistic, E-commerce, Financial
Geo:
Usa, Australia, India, Canada, France, Spain, Sweden
IOCs:
Domain: 168
Softs:
coinbase, slack, telegram, lastpass
26-08-2022
Twilio and MailChimp Attackers Hit 130 Organizations with Okta Phishing Campaign
https://socradar.io/twilio-and-mailchimp-attackers-hit-130-organizations-with-okta-phishing-campaign
Actors/Campaigns:
0ktapus
Industry:
Education, Retail, Telco, Logistic, E-commerce, Financial
Geo:
Usa, Australia, India, Canada, France, Spain, Sweden
IOCs:
Domain: 168
Softs:
coinbase, slack, telegram, lastpass
SOCRadar® Cyber Intelligence Inc.
Twilio and MailChimp Attackers Hit 130 Organizations with Okta Phishing Campaign
A larger phishing campaign that targeted 136 organizations and resulted in the theft of 9,931 account login credentials has been linked to...
#ParsedReport
26-08-2022
Threat Assessment: Black Basta Ransomware
https://unit42.paloaltonetworks.com/threat-assessment-black-basta-ransomware
Threats:
Blackbasta
Conti
Qakbot
Megacortex
Prolock
Doppelpaymer
Egregor
Antidebugging_technique
Mimikatz
Teamviewer_tool
Cobalt_strike
Industry:
E-commerce, Energy, Financial, Foodtech, Government, Transport
Geo:
Japanese, Australia, Germany, Japan, France, Canada, Switzerland, Emea, Netherlands, America, Italy, Apac
TTPs:
Tactics: 12
Technics: 28
IOCs:
File: 8
Path: 2
Softs:
windows service, esxi, psexec, windows defender, bcdedit, vssadmin
Algorithms:
zip , chacha20, rsa-4096
Functions:
GetComputerName, North
26-08-2022
Threat Assessment: Black Basta Ransomware
https://unit42.paloaltonetworks.com/threat-assessment-black-basta-ransomware
Threats:
Blackbasta
Conti
Qakbot
Megacortex
Prolock
Doppelpaymer
Egregor
Antidebugging_technique
Mimikatz
Teamviewer_tool
Cobalt_strike
Industry:
E-commerce, Energy, Financial, Foodtech, Government, Transport
Geo:
Japanese, Australia, Germany, Japan, France, Canada, Switzerland, Emea, Netherlands, America, Italy, Apac
TTPs:
Tactics: 12
Technics: 28
IOCs:
File: 8
Path: 2
Softs:
windows service, esxi, psexec, windows defender, bcdedit, vssadmin
Algorithms:
zip , chacha20, rsa-4096
Functions:
GetComputerName, North
Unit 42
Threat Assessment: Black Basta Ransomware
Black Basta is ransomware as a service (RaaS) that first emerged in April 2022. However, evidence suggests that it has been in development since February. The Black Basta operator(s) use the double extortion technique, meaning that in addition to encrypting…
#ParsedReport
26-08-2022
ISaPWN research on the security of ISaGRAF Runtime
https://ics-cert.kaspersky.com/publications/reports/2022/05/23/isapwn-research-on-the-security-of-isagraf-runtime
Industry:
Energy, Ics, Transport
CVEs:
CVE-2020-25180 [Vulners]
Vulners: Score: 4.3, CVSS: 3.1,
Vulners: Exploitation: Unknown
X-Force: Risk: Unknown
X-Force: Patch: Unknown
Soft:
- schneider-electric easergy t300 firmware (le2.7.1)
- schneider-electric easergy c5 firmware (<1.1.0)
- schneider-electric micom c264 firmware (<d6.1)
- schneider-electric pacis gtw firmware (5.1, 5.2, 6.1, 6.3, 6.3)
- schneider-electric saitel dp firmware (le11.06.21)
have more...
CVE-2020-25182 [Vulners]
Vulners: Score: 4.6, CVSS: 6.7,
Vulners: Exploitation: Unknown
X-Force: Risk: 6.7
X-Force: Patch: Official fix
Soft:
- schneider-electric easergy t300 firmware (le2.7.1)
- schneider-electric easergy c5 firmware (<1.1.0)
- schneider-electric micom c264 firmware (<d6.1)
- schneider-electric pacis gtw firmware (5.1, 5.2, 6.1, 6.3, 6.3)
- schneider-electric saitel dp firmware (le11.06.21)
have more...
CVE-2020-25176 [Vulners]
Vulners: Score: 9.3, CVSS: 5.3,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.1
X-Force: Patch: Official fix
Soft:
- schneider-electric easergy t300 firmware (le2.7.1)
- schneider-electric easergy c5 firmware (<1.1.0)
- schneider-electric micom c264 firmware (<d6.1)
- schneider-electric pacis gtw firmware (5.1, 5.2, 6.1, 6.3, 6.3)
- schneider-electric saitel dp firmware (le11.06.21)
have more...
IOCs:
File: 6
Algorithms:
crc
Languages:
python
26-08-2022
ISaPWN research on the security of ISaGRAF Runtime
https://ics-cert.kaspersky.com/publications/reports/2022/05/23/isapwn-research-on-the-security-of-isagraf-runtime
Industry:
Energy, Ics, Transport
CVEs:
CVE-2020-25180 [Vulners]
Vulners: Score: 4.3, CVSS: 3.1,
Vulners: Exploitation: Unknown
X-Force: Risk: Unknown
X-Force: Patch: Unknown
Soft:
- schneider-electric easergy t300 firmware (le2.7.1)
- schneider-electric easergy c5 firmware (<1.1.0)
- schneider-electric micom c264 firmware (<d6.1)
- schneider-electric pacis gtw firmware (5.1, 5.2, 6.1, 6.3, 6.3)
- schneider-electric saitel dp firmware (le11.06.21)
have more...
CVE-2020-25182 [Vulners]
Vulners: Score: 4.6, CVSS: 6.7,
Vulners: Exploitation: Unknown
X-Force: Risk: 6.7
X-Force: Patch: Official fix
Soft:
- schneider-electric easergy t300 firmware (le2.7.1)
- schneider-electric easergy c5 firmware (<1.1.0)
- schneider-electric micom c264 firmware (<d6.1)
- schneider-electric pacis gtw firmware (5.1, 5.2, 6.1, 6.3, 6.3)
- schneider-electric saitel dp firmware (le11.06.21)
have more...
CVE-2020-25176 [Vulners]
Vulners: Score: 9.3, CVSS: 5.3,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.1
X-Force: Patch: Official fix
Soft:
- schneider-electric easergy t300 firmware (le2.7.1)
- schneider-electric easergy c5 firmware (<1.1.0)
- schneider-electric micom c264 firmware (<d6.1)
- schneider-electric pacis gtw firmware (5.1, 5.2, 6.1, 6.3, 6.3)
- schneider-electric saitel dp firmware (le11.06.21)
have more...
IOCs:
File: 6
Algorithms:
crc
Languages:
python
Kaspersky ICS CERT | Kaspersky Industrial Control Systems Cyber Emergency Response Team
ISaPWN – research on the security of ISaGRAF Runtime | Kaspersky ICS CERT
This report includes an analysis of the ISaGRAF framework, its architecture, the IXL and SNCP protocols and the description of several vulnerabilities the Kaspersky ICS CERT team had identified.
#ParsedReport
26-08-2022
QBOT Malware Analysis. Key takeaways
https://www.elastic.co/security-labs/qbot-malware-analysis
Threats:
Qakbot
Process_injection_technique
Dll_injection_technique
Industry:
Financial, Government
TTPs:
Tactics: 6
Technics: 12
IOCs:
File: 31
Path: 2
Registry: 1
IP: 150
Softs:
windows defender
Algorithms:
xor, crc, prng
Functions:
GetString, GetStringAux, WriteProcessMemory, GetApi, CreateProcess
Platforms:
x64, x86
YARA: Found
Links:
26-08-2022
QBOT Malware Analysis. Key takeaways
https://www.elastic.co/security-labs/qbot-malware-analysis
Threats:
Qakbot
Process_injection_technique
Dll_injection_technique
Industry:
Financial, Government
TTPs:
Tactics: 6
Technics: 12
IOCs:
File: 31
Path: 2
Registry: 1
IP: 150
Softs:
windows defender
Algorithms:
xor, crc, prng
Functions:
GetString, GetStringAux, WriteProcessMemory, GetApi, CreateProcess
Platforms:
x64, x86
YARA: Found
Links:
https://github.com/elastic/protections-artifacts/blob/main/yara/rules/Windows\_Trojan\_Qbot.yarwww.elastic.co
QBOT Malware Analysis — Elastic Security Labs
Elastic Security Labs releases a QBOT malware analysis report covering the execution chain. From this research, the team has produced a YARA rule, configuration-extractor, and indicators of compromises (IOCs).
#technique
https://github.com/Markakd/DirtyCred
DirtyCred is a kernel exploitation concept that swaps unprivileged kernel credentials with privileged ones to escalate privilege. Instead of overwriting any critical data fields on kernel heap, DirtyCred abuses the heap memory reuse mechanism to get privileged. Although the concept is simple, it is effective.
https://github.com/Markakd/DirtyCred
DirtyCred is a kernel exploitation concept that swaps unprivileged kernel credentials with privileged ones to escalate privilege. Instead of overwriting any critical data fields on kernel heap, DirtyCred abuses the heap memory reuse mechanism to get privileged. Although the concept is simple, it is effective.
GitHub
GitHub - Markakd/DirtyCred: Kernel exploitation technique
Kernel exploitation technique. Contribute to Markakd/DirtyCred development by creating an account on GitHub.
#technique
https://github.com/KiFilterFiberContext/warbird-hook
On Windows 10 21H2, PatchGuard does not (afaik) verify the integrity of pointers of nt!g_kernelCallbacks, unlike nt!SeCiCallbacks. The callback table contains pointers to an image named ClipSp.sys, which is a signed driver protected by Microsoft Warbird used for licensing checks (called from nt!SPCall2ServerInternal).
The interesting thing about it is that PatchGuard does not verify the integrity of several image sections, including PAGEwx, which the driver contains in order to decrypt and re-encrypt its own code during runtime.
https://github.com/KiFilterFiberContext/warbird-hook
On Windows 10 21H2, PatchGuard does not (afaik) verify the integrity of pointers of nt!g_kernelCallbacks, unlike nt!SeCiCallbacks. The callback table contains pointers to an image named ClipSp.sys, which is a signed driver protected by Microsoft Warbird used for licensing checks (called from nt!SPCall2ServerInternal).
The interesting thing about it is that PatchGuard does not verify the integrity of several image sections, including PAGEwx, which the driver contains in order to decrypt and re-encrypt its own code during runtime.
GitHub
GitHub - KiFilterFiberContext/warbird-hook: Using Microsoft Warbird to automatically unpack and execute encrypted shellcode in…
Using Microsoft Warbird to automatically unpack and execute encrypted shellcode in ClipSp.sys without triggering PatchGuard - KiFilterFiberContext/warbird-hook
#technique
https://www.offensive-security.com/offsec/bypassing-intel-cet-with-counterfeit-objects/?utm_source=twitter&utm_medium=&utm_campaign=d6813b98-789f-4854-80b2-d6d68d2fc4f0
https://www.offensive-security.com/offsec/bypassing-intel-cet-with-counterfeit-objects/?utm_source=twitter&utm_medium=&utm_campaign=d6813b98-789f-4854-80b2-d6d68d2fc4f0
OffSec
Bypassing Intel CET with Counterfeit Objects
In this blog, we’ll briefly cover how CFI mitigations works, including CET, and how we can leverage COOP to effectively bypass Intel CET on the latest Windows releases.
#ParsedReport
29-08-2022
Check Point Research detects Crypto Miner malware disguised as Google translate desktop and other legitimate applications
https://research.checkpoint.com/2022/check-point-research-detects-crypto-miner-malware-disguised-as-google-translate-desktop-and-other-legitimate-applications
Threats:
Nitrokod
Xmrig_miner
Geo:
Turkish
IOCs:
Domain: 3
File: 8
Url: 1
Path: 3
IP: 1
Hash: 6
Softs:
windows defender, chromium, windows installer
Algorithms:
base64
Platforms:
x86
29-08-2022
Check Point Research detects Crypto Miner malware disguised as Google translate desktop and other legitimate applications
https://research.checkpoint.com/2022/check-point-research-detects-crypto-miner-malware-disguised-as-google-translate-desktop-and-other-legitimate-applications
Threats:
Nitrokod
Xmrig_miner
Geo:
Turkish
IOCs:
Domain: 3
File: 8
Url: 1
Path: 3
IP: 1
Hash: 6
Softs:
windows defender, chromium, windows installer
Algorithms:
base64
Platforms:
x86
#ParsedReport
29-08-2022
(OLE). Hangul document disguised as a profile form (OLE object)
https://asec.ahnlab.com/ko/38216
Actors/Campaigns:
Darkhalo
Threats:
Trojan/win.agent.c5228370
Geo:
Korean
CVEs:
CVE-2018-15982 [Vulners]
Vulners: Score: 10.0, CVSS: 5.9,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- adobe flash player (le31.0.0.153, le31.0.0.153, le31.0.0.153, le31.0.0.153)
- redhat enterprise linux desktop (6.0)
- redhat enterprise linux workstation (6.0)
- redhat enterprise linux server (6.0)
- adobe flash player installer (le31.0.0.108)
have more...
IOCs:
File: 22
Url: 4
Path: 1
Hash: 6
29-08-2022
(OLE). Hangul document disguised as a profile form (OLE object)
https://asec.ahnlab.com/ko/38216
Actors/Campaigns:
Darkhalo
Threats:
Trojan/win.agent.c5228370
Geo:
Korean
CVEs:
CVE-2018-15982 [Vulners]
Vulners: Score: 10.0, CVSS: 5.9,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- adobe flash player (le31.0.0.153, le31.0.0.153, le31.0.0.153, le31.0.0.153)
- redhat enterprise linux desktop (6.0)
- redhat enterprise linux workstation (6.0)
- redhat enterprise linux server (6.0)
- adobe flash player installer (le31.0.0.108)
have more...
IOCs:
File: 22
Url: 4
Path: 1
Hash: 6
ASEC BLOG
프로필 양식 위장한 한글문서 (OLE개체) - ASEC BLOG
ASEC 분석팀은 최근 OLE 개체 및 플래쉬 취약점 이용한 악성 한글 문서를 확인하였다. 해당 취약점은 2020년 공유한 <한글문서(HWP) 내부 플래쉬 취약점 이용한 새로운 공격> 게시글에서 소개되었으며, 이번에 확인된 파일에도 당시와 동일한 악성 URL을 사용하고 있다. 해당 URL에는 여전히 플래시 취약점(CVE-2018-15982) 파일이 업로드되어 있어 사용자의 주의가 필요하다. 확인된 한글 파일 내부에는 OLE 개체가 삽입되어 있으며 해당…
#ParsedReport
29-08-2022
The CryptoLocker ransomware
https://www.telsy.com/the-cryptolocker-ransomware
Industry:
Financial
Algorithms:
zip
Platforms:
apple
29-08-2022
The CryptoLocker ransomware
https://www.telsy.com/the-cryptolocker-ransomware
Industry:
Financial
Algorithms:
zip
Platforms:
apple
Telsy
The CryptoLocker ransomware - Telsy
CryptoLocker is a ransomware that blocks documents on your computer by encrypting them with a password and making them impossible to open.
#ParsedReport
29-08-2022
Crypto miners latest techniques
https://cybersecurity.att.com/blogs/labs-research/crypto-miners-latest-techniques
Threats:
Alien
Industry:
Iot
TTPs:
Tactics: 8
Technics: 22
IOCs:
Registry: 3
Path: 10
Domain: 3
File: 5
Hash: 7
Softs:
microsoft excel, windows service, windows defender
Win API:
CmRcService, CmRccService
29-08-2022
Crypto miners latest techniques
https://cybersecurity.att.com/blogs/labs-research/crypto-miners-latest-techniques
Threats:
Alien
Industry:
Iot
TTPs:
Tactics: 8
Technics: 22
IOCs:
Registry: 3
Path: 10
Domain: 3
File: 5
Hash: 7
Softs:
microsoft excel, windows service, windows defender
Win API:
CmRcService, CmRccService
LevelBlue
Crypto miners’ latest techniques
An exploration of the newest methods used by crypto miners to exploit systems, enhancing threat awareness.
#ParsedReport
29-08-2022
Traffers: a deep dive into the information stealer ecosystem
https://blog.sekoia.io/traffers-a-deep-dive-into-the-information-stealer-ecosystem
Threats:
Traffer
Raccoon_stealer
Vidar_stealer
Redline_stealer
Hydra
Meta_stealer
Ytstealer
Industry:
Media, E-commerce, Financial, Entertainment
Geo:
Russian
IOCs:
Url: 6
Domain: 1
File: 2
Hash: 2
IP: 1
Softs:
windows defender, telegram, discord
29-08-2022
Traffers: a deep dive into the information stealer ecosystem
https://blog.sekoia.io/traffers-a-deep-dive-into-the-information-stealer-ecosystem
Threats:
Traffer
Raccoon_stealer
Vidar_stealer
Redline_stealer
Hydra
Meta_stealer
Ytstealer
Industry:
Media, E-commerce, Financial, Entertainment
Geo:
Russian
IOCs:
Url: 6
Domain: 1
File: 2
Hash: 2
IP: 1
Softs:
windows defender, telegram, discord
Sekoia.io Blog
Traffers: a deep dive into the information stealer ecosystem
Traffers are responsible for redirecting user traffic to malicious content (malware, fraud, phishing, scam) exploited by other threat actors.
#ParsedReport
28-08-2022
Kimsuky Group, Targeting Russian Foreign Ministry is attacking!Malware Analysis Report
https://blog.alyac.co.kr/4892
Actors/Campaigns:
Kimsuky
Threats:
Emotet
Lockbit
Venus_locker
Geo:
Korea, Japanese, Russian
IOCs:
File: 4
Url: 1
IP: 1
Hash: 1
Softs:
android, task scheduler
Algorithms:
zipx
Languages:
visual_basic
28-08-2022
Kimsuky Group, Targeting Russian Foreign Ministry is attacking!Malware Analysis Report
https://blog.alyac.co.kr/4892
Actors/Campaigns:
Kimsuky
Threats:
Emotet
Lockbit
Venus_locker
Geo:
Korea, Japanese, Russian
IOCs:
File: 4
Url: 1
IP: 1
Hash: 1
Softs:
android, task scheduler
Algorithms:
zipx
Languages:
visual_basic
이스트시큐리티 알약 블로그
김수키(Kimsuky) 그룹, 러시아 외무부를 타겟으로 공격 진행중!
안녕하세요? 이스트시큐리티 시큐리티대응센터(이하 ESRC)입니다. 김수키(Kimsuky) 그룹이 러시아 외무부를 타겟으로 진행한 공격이 포착되었습니다. 이번에 포착된 공격은 이메일을 통해 진행되었으며, Kimsuky 그룹은 선제적 공격을 통해 탈취한 심양 러시아 총 영사관 계정을 사용하여 일본 러시아 총 영사관에 추가 공격행위를 시도한 것으로 추정됩니다. 해당 공격은 대사관 회계과를 위장한 이메일을 통해 시도되었으며, 자금 이체를 위한 대사관 정보를 보내드린다는…
#ParsedReport
29-08-2022
AsyncRAT: Using Fully Undetected Downloader
https://www.netskope.com/blog/asyncrat-using-fully-undetected-downloader
Threats:
Asyncrat_rat
Process_hollowing_technique
Ousaban
Industry:
Financial
Geo:
Japanese, Latam
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 7
Softs:
microsoft office, windows defender
Algorithms:
hmac, cbc, aes, aes-256, base64
Functions:
InitializeSettings
Languages:
python
SIGMA: Found
Links:
29-08-2022
AsyncRAT: Using Fully Undetected Downloader
https://www.netskope.com/blog/asyncrat-using-fully-undetected-downloader
Threats:
Asyncrat_rat
Process_hollowing_technique
Ousaban
Industry:
Financial
Geo:
Japanese, Latam
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 7
Softs:
microsoft office, windows defender
Algorithms:
hmac, cbc, aes, aes-256, base64
Functions:
InitializeSettings
Languages:
python
SIGMA: Found
Links:
https://github.com/NYAN-x-CAT/AsyncRAT-C-Sharp
https://github.com/netskopeoss/NetskopeThreatLabsIOCs/tree/main/AsyncRAT
https://github.com/netskopeoss/NetskopeThreatLabsIOCs/tree/main/AsyncRAT/scriptNetskope
AsyncRAT: Using Fully Undetected Downloader
Summary AsyncRAT is an open-source remote administration tool released on GitHub in January 2019. It’s designed to remotely control computers via
#ParsedReport
30-08-2022
Rising Tide: Chasing the Currents of Espionage in the South China Sea
https://www.proofpoint.com/us/blog/threat-insight/chasing-currents-espionage-south-china-sea
Actors/Campaigns:
Red_ladon (motivation: cyber_espionage)
Leviathan
Red_sylvan
Stone_panda
Emissary_panda
Earth_empusa
Luckycat
Threats:
Scanbox
Ladon_tool
Rtf_template_inject_technique
Phoenix_keylogger
Meterpreter_tool
Watering_hole_technique
Dll_sideloading_technique
Beacon
Industry:
Maritime, Financial, Healthcare, Energy, Government, Petroleum, Education
Geo:
Taiwan, Australia, Malaysia, Australian, China, Cambodia, Pacific, Chinese, Asia
IOCs:
Domain: 7
Url: 28
File: 7
IP: 6
Email: 18
Hash: 31
Softs:
chrome, webrtc, opera, microsoft word, mariadb, internet explorer
Algorithms:
xor, zip
Languages:
php, java, javascript
Links:
30-08-2022
Rising Tide: Chasing the Currents of Espionage in the South China Sea
https://www.proofpoint.com/us/blog/threat-insight/chasing-currents-espionage-south-china-sea
Actors/Campaigns:
Red_ladon (motivation: cyber_espionage)
Leviathan
Red_sylvan
Stone_panda
Emissary_panda
Earth_empusa
Luckycat
Threats:
Scanbox
Ladon_tool
Rtf_template_inject_technique
Phoenix_keylogger
Meterpreter_tool
Watering_hole_technique
Dll_sideloading_technique
Beacon
Industry:
Maritime, Financial, Healthcare, Energy, Government, Petroleum, Education
Geo:
Taiwan, Australia, Malaysia, Australian, China, Cambodia, Pacific, Chinese, Asia
IOCs:
Domain: 7
Url: 28
File: 7
IP: 6
Email: 18
Hash: 31
Softs:
chrome, webrtc, opera, microsoft word, mariadb, internet explorer
Algorithms:
xor, zip
Languages:
php, java, javascript
Links:
https://github.com/nico3333fr/CSP-useful/blob/master/csp-wtf/explained.mdProofpoint
Cyber Espionage in the South China Sea | Proofpoint US
Proofpoint's Threat Research Team has released details on recent cyber espionage activity in the South China Sea. Learn more about the recent campaigns.
#ParsedReport
30-08-2022
Mini Stealer: Possible Predecessor of Parrot Stealer
https://blog.cyble.com/2022/08/29/mini-stealer-possible-predecessor-of-parrot-stealer
Threats:
Ministealer
Parrotstealer
Timestomp_technique
Antidebugging_technique
Beacon
TTPs:
Tactics: 6
Technics: 13
IOCs:
File: 2
Hash: 1
Softs:
sleipnir, vivaldi, winscp, kometa, orbitum, browser360, operagx, avastbrowser, chedot, epicprivacybrowser, centbrowser, comododragon
Algorithms:
zip
Win API:
IsDebuggerPresent
30-08-2022
Mini Stealer: Possible Predecessor of Parrot Stealer
https://blog.cyble.com/2022/08/29/mini-stealer-possible-predecessor-of-parrot-stealer
Threats:
Ministealer
Parrotstealer
Timestomp_technique
Antidebugging_technique
Beacon
TTPs:
Tactics: 6
Technics: 13
IOCs:
File: 2
Hash: 1
Softs:
sleipnir, vivaldi, winscp, kometa, orbitum, browser360, operagx, avastbrowser, chedot, epicprivacybrowser, centbrowser, comododragon
Algorithms:
zip
Win API:
IsDebuggerPresent
#ParsedReport
30-08-2022
Crypto miners latest techniques
https://cybersecurity.att.com/blogs/labs-research/crypto-miners-latest-techniques
Threats:
Alien
Industry:
Iot
Geo:
Mexican
TTPs:
Tactics: 8
Technics: 22
IOCs:
Registry: 3
Path: 10
Domain: 3
File: 5
Hash: 7
Softs:
microsoft excel, windows service, windows defender
Win API:
CmRccService, CmRcService
30-08-2022
Crypto miners latest techniques
https://cybersecurity.att.com/blogs/labs-research/crypto-miners-latest-techniques
Threats:
Alien
Industry:
Iot
Geo:
Mexican
TTPs:
Tactics: 8
Technics: 22
IOCs:
Registry: 3
Path: 10
Domain: 3
File: 5
Hash: 7
Softs:
microsoft excel, windows service, windows defender
Win API:
CmRccService, CmRcService
LevelBlue
Crypto miners’ latest techniques
An exploration of the newest methods used by crypto miners to exploit systems, enhancing threat awareness.