#ParsedReport
26-08-2022
Threat Assessment: Black Basta Ransomware
https://unit42.paloaltonetworks.com/threat-assessment-black-basta-ransomware
Threats:
Blackbasta
Conti
Qakbot
Megacortex
Prolock
Doppelpaymer
Egregor
Antidebugging_technique
Mimikatz
Teamviewer_tool
Cobalt_strike
Industry:
E-commerce, Energy, Financial, Foodtech, Government, Transport
Geo:
Japanese, Australia, Germany, Japan, France, Canada, Switzerland, Emea, Netherlands, America, Italy, Apac
TTPs:
Tactics: 12
Technics: 28
IOCs:
File: 8
Path: 2
Softs:
windows service, esxi, psexec, windows defender, bcdedit, vssadmin
Algorithms:
zip , chacha20, rsa-4096
Functions:
GetComputerName, North
26-08-2022
Threat Assessment: Black Basta Ransomware
https://unit42.paloaltonetworks.com/threat-assessment-black-basta-ransomware
Threats:
Blackbasta
Conti
Qakbot
Megacortex
Prolock
Doppelpaymer
Egregor
Antidebugging_technique
Mimikatz
Teamviewer_tool
Cobalt_strike
Industry:
E-commerce, Energy, Financial, Foodtech, Government, Transport
Geo:
Japanese, Australia, Germany, Japan, France, Canada, Switzerland, Emea, Netherlands, America, Italy, Apac
TTPs:
Tactics: 12
Technics: 28
IOCs:
File: 8
Path: 2
Softs:
windows service, esxi, psexec, windows defender, bcdedit, vssadmin
Algorithms:
zip , chacha20, rsa-4096
Functions:
GetComputerName, North
Unit 42
Threat Assessment: Black Basta Ransomware
Black Basta is ransomware as a service (RaaS) that first emerged in April 2022. However, evidence suggests that it has been in development since February. The Black Basta operator(s) use the double extortion technique, meaning that in addition to encrypting…
#ParsedReport
26-08-2022
ISaPWN research on the security of ISaGRAF Runtime
https://ics-cert.kaspersky.com/publications/reports/2022/05/23/isapwn-research-on-the-security-of-isagraf-runtime
Industry:
Energy, Ics, Transport
CVEs:
CVE-2020-25180 [Vulners]
Vulners: Score: 4.3, CVSS: 3.1,
Vulners: Exploitation: Unknown
X-Force: Risk: Unknown
X-Force: Patch: Unknown
Soft:
- schneider-electric easergy t300 firmware (le2.7.1)
- schneider-electric easergy c5 firmware (<1.1.0)
- schneider-electric micom c264 firmware (<d6.1)
- schneider-electric pacis gtw firmware (5.1, 5.2, 6.1, 6.3, 6.3)
- schneider-electric saitel dp firmware (le11.06.21)
have more...
CVE-2020-25182 [Vulners]
Vulners: Score: 4.6, CVSS: 6.7,
Vulners: Exploitation: Unknown
X-Force: Risk: 6.7
X-Force: Patch: Official fix
Soft:
- schneider-electric easergy t300 firmware (le2.7.1)
- schneider-electric easergy c5 firmware (<1.1.0)
- schneider-electric micom c264 firmware (<d6.1)
- schneider-electric pacis gtw firmware (5.1, 5.2, 6.1, 6.3, 6.3)
- schneider-electric saitel dp firmware (le11.06.21)
have more...
CVE-2020-25176 [Vulners]
Vulners: Score: 9.3, CVSS: 5.3,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.1
X-Force: Patch: Official fix
Soft:
- schneider-electric easergy t300 firmware (le2.7.1)
- schneider-electric easergy c5 firmware (<1.1.0)
- schneider-electric micom c264 firmware (<d6.1)
- schneider-electric pacis gtw firmware (5.1, 5.2, 6.1, 6.3, 6.3)
- schneider-electric saitel dp firmware (le11.06.21)
have more...
IOCs:
File: 6
Algorithms:
crc
Languages:
python
26-08-2022
ISaPWN research on the security of ISaGRAF Runtime
https://ics-cert.kaspersky.com/publications/reports/2022/05/23/isapwn-research-on-the-security-of-isagraf-runtime
Industry:
Energy, Ics, Transport
CVEs:
CVE-2020-25180 [Vulners]
Vulners: Score: 4.3, CVSS: 3.1,
Vulners: Exploitation: Unknown
X-Force: Risk: Unknown
X-Force: Patch: Unknown
Soft:
- schneider-electric easergy t300 firmware (le2.7.1)
- schneider-electric easergy c5 firmware (<1.1.0)
- schneider-electric micom c264 firmware (<d6.1)
- schneider-electric pacis gtw firmware (5.1, 5.2, 6.1, 6.3, 6.3)
- schneider-electric saitel dp firmware (le11.06.21)
have more...
CVE-2020-25182 [Vulners]
Vulners: Score: 4.6, CVSS: 6.7,
Vulners: Exploitation: Unknown
X-Force: Risk: 6.7
X-Force: Patch: Official fix
Soft:
- schneider-electric easergy t300 firmware (le2.7.1)
- schneider-electric easergy c5 firmware (<1.1.0)
- schneider-electric micom c264 firmware (<d6.1)
- schneider-electric pacis gtw firmware (5.1, 5.2, 6.1, 6.3, 6.3)
- schneider-electric saitel dp firmware (le11.06.21)
have more...
CVE-2020-25176 [Vulners]
Vulners: Score: 9.3, CVSS: 5.3,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.1
X-Force: Patch: Official fix
Soft:
- schneider-electric easergy t300 firmware (le2.7.1)
- schneider-electric easergy c5 firmware (<1.1.0)
- schneider-electric micom c264 firmware (<d6.1)
- schneider-electric pacis gtw firmware (5.1, 5.2, 6.1, 6.3, 6.3)
- schneider-electric saitel dp firmware (le11.06.21)
have more...
IOCs:
File: 6
Algorithms:
crc
Languages:
python
Kaspersky ICS CERT | Kaspersky Industrial Control Systems Cyber Emergency Response Team
ISaPWN – research on the security of ISaGRAF Runtime | Kaspersky ICS CERT
This report includes an analysis of the ISaGRAF framework, its architecture, the IXL and SNCP protocols and the description of several vulnerabilities the Kaspersky ICS CERT team had identified.
#ParsedReport
26-08-2022
QBOT Malware Analysis. Key takeaways
https://www.elastic.co/security-labs/qbot-malware-analysis
Threats:
Qakbot
Process_injection_technique
Dll_injection_technique
Industry:
Financial, Government
TTPs:
Tactics: 6
Technics: 12
IOCs:
File: 31
Path: 2
Registry: 1
IP: 150
Softs:
windows defender
Algorithms:
xor, crc, prng
Functions:
GetString, GetStringAux, WriteProcessMemory, GetApi, CreateProcess
Platforms:
x64, x86
YARA: Found
Links:
26-08-2022
QBOT Malware Analysis. Key takeaways
https://www.elastic.co/security-labs/qbot-malware-analysis
Threats:
Qakbot
Process_injection_technique
Dll_injection_technique
Industry:
Financial, Government
TTPs:
Tactics: 6
Technics: 12
IOCs:
File: 31
Path: 2
Registry: 1
IP: 150
Softs:
windows defender
Algorithms:
xor, crc, prng
Functions:
GetString, GetStringAux, WriteProcessMemory, GetApi, CreateProcess
Platforms:
x64, x86
YARA: Found
Links:
https://github.com/elastic/protections-artifacts/blob/main/yara/rules/Windows\_Trojan\_Qbot.yarwww.elastic.co
QBOT Malware Analysis — Elastic Security Labs
Elastic Security Labs releases a QBOT malware analysis report covering the execution chain. From this research, the team has produced a YARA rule, configuration-extractor, and indicators of compromises (IOCs).
#technique
https://github.com/Markakd/DirtyCred
DirtyCred is a kernel exploitation concept that swaps unprivileged kernel credentials with privileged ones to escalate privilege. Instead of overwriting any critical data fields on kernel heap, DirtyCred abuses the heap memory reuse mechanism to get privileged. Although the concept is simple, it is effective.
https://github.com/Markakd/DirtyCred
DirtyCred is a kernel exploitation concept that swaps unprivileged kernel credentials with privileged ones to escalate privilege. Instead of overwriting any critical data fields on kernel heap, DirtyCred abuses the heap memory reuse mechanism to get privileged. Although the concept is simple, it is effective.
GitHub
GitHub - Markakd/DirtyCred: Kernel exploitation technique
Kernel exploitation technique. Contribute to Markakd/DirtyCred development by creating an account on GitHub.
#technique
https://github.com/KiFilterFiberContext/warbird-hook
On Windows 10 21H2, PatchGuard does not (afaik) verify the integrity of pointers of nt!g_kernelCallbacks, unlike nt!SeCiCallbacks. The callback table contains pointers to an image named ClipSp.sys, which is a signed driver protected by Microsoft Warbird used for licensing checks (called from nt!SPCall2ServerInternal).
The interesting thing about it is that PatchGuard does not verify the integrity of several image sections, including PAGEwx, which the driver contains in order to decrypt and re-encrypt its own code during runtime.
https://github.com/KiFilterFiberContext/warbird-hook
On Windows 10 21H2, PatchGuard does not (afaik) verify the integrity of pointers of nt!g_kernelCallbacks, unlike nt!SeCiCallbacks. The callback table contains pointers to an image named ClipSp.sys, which is a signed driver protected by Microsoft Warbird used for licensing checks (called from nt!SPCall2ServerInternal).
The interesting thing about it is that PatchGuard does not verify the integrity of several image sections, including PAGEwx, which the driver contains in order to decrypt and re-encrypt its own code during runtime.
GitHub
GitHub - KiFilterFiberContext/warbird-hook: Using Microsoft Warbird to automatically unpack and execute encrypted shellcode in…
Using Microsoft Warbird to automatically unpack and execute encrypted shellcode in ClipSp.sys without triggering PatchGuard - KiFilterFiberContext/warbird-hook
#technique
https://www.offensive-security.com/offsec/bypassing-intel-cet-with-counterfeit-objects/?utm_source=twitter&utm_medium=&utm_campaign=d6813b98-789f-4854-80b2-d6d68d2fc4f0
https://www.offensive-security.com/offsec/bypassing-intel-cet-with-counterfeit-objects/?utm_source=twitter&utm_medium=&utm_campaign=d6813b98-789f-4854-80b2-d6d68d2fc4f0
OffSec
Bypassing Intel CET with Counterfeit Objects
In this blog, we’ll briefly cover how CFI mitigations works, including CET, and how we can leverage COOP to effectively bypass Intel CET on the latest Windows releases.
#ParsedReport
29-08-2022
Check Point Research detects Crypto Miner malware disguised as Google translate desktop and other legitimate applications
https://research.checkpoint.com/2022/check-point-research-detects-crypto-miner-malware-disguised-as-google-translate-desktop-and-other-legitimate-applications
Threats:
Nitrokod
Xmrig_miner
Geo:
Turkish
IOCs:
Domain: 3
File: 8
Url: 1
Path: 3
IP: 1
Hash: 6
Softs:
windows defender, chromium, windows installer
Algorithms:
base64
Platforms:
x86
29-08-2022
Check Point Research detects Crypto Miner malware disguised as Google translate desktop and other legitimate applications
https://research.checkpoint.com/2022/check-point-research-detects-crypto-miner-malware-disguised-as-google-translate-desktop-and-other-legitimate-applications
Threats:
Nitrokod
Xmrig_miner
Geo:
Turkish
IOCs:
Domain: 3
File: 8
Url: 1
Path: 3
IP: 1
Hash: 6
Softs:
windows defender, chromium, windows installer
Algorithms:
base64
Platforms:
x86
#ParsedReport
29-08-2022
(OLE). Hangul document disguised as a profile form (OLE object)
https://asec.ahnlab.com/ko/38216
Actors/Campaigns:
Darkhalo
Threats:
Trojan/win.agent.c5228370
Geo:
Korean
CVEs:
CVE-2018-15982 [Vulners]
Vulners: Score: 10.0, CVSS: 5.9,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- adobe flash player (le31.0.0.153, le31.0.0.153, le31.0.0.153, le31.0.0.153)
- redhat enterprise linux desktop (6.0)
- redhat enterprise linux workstation (6.0)
- redhat enterprise linux server (6.0)
- adobe flash player installer (le31.0.0.108)
have more...
IOCs:
File: 22
Url: 4
Path: 1
Hash: 6
29-08-2022
(OLE). Hangul document disguised as a profile form (OLE object)
https://asec.ahnlab.com/ko/38216
Actors/Campaigns:
Darkhalo
Threats:
Trojan/win.agent.c5228370
Geo:
Korean
CVEs:
CVE-2018-15982 [Vulners]
Vulners: Score: 10.0, CVSS: 5.9,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- adobe flash player (le31.0.0.153, le31.0.0.153, le31.0.0.153, le31.0.0.153)
- redhat enterprise linux desktop (6.0)
- redhat enterprise linux workstation (6.0)
- redhat enterprise linux server (6.0)
- adobe flash player installer (le31.0.0.108)
have more...
IOCs:
File: 22
Url: 4
Path: 1
Hash: 6
ASEC BLOG
프로필 양식 위장한 한글문서 (OLE개체) - ASEC BLOG
ASEC 분석팀은 최근 OLE 개체 및 플래쉬 취약점 이용한 악성 한글 문서를 확인하였다. 해당 취약점은 2020년 공유한 <한글문서(HWP) 내부 플래쉬 취약점 이용한 새로운 공격> 게시글에서 소개되었으며, 이번에 확인된 파일에도 당시와 동일한 악성 URL을 사용하고 있다. 해당 URL에는 여전히 플래시 취약점(CVE-2018-15982) 파일이 업로드되어 있어 사용자의 주의가 필요하다. 확인된 한글 파일 내부에는 OLE 개체가 삽입되어 있으며 해당…
#ParsedReport
29-08-2022
The CryptoLocker ransomware
https://www.telsy.com/the-cryptolocker-ransomware
Industry:
Financial
Algorithms:
zip
Platforms:
apple
29-08-2022
The CryptoLocker ransomware
https://www.telsy.com/the-cryptolocker-ransomware
Industry:
Financial
Algorithms:
zip
Platforms:
apple
Telsy
The CryptoLocker ransomware - Telsy
CryptoLocker is a ransomware that blocks documents on your computer by encrypting them with a password and making them impossible to open.
#ParsedReport
29-08-2022
Crypto miners latest techniques
https://cybersecurity.att.com/blogs/labs-research/crypto-miners-latest-techniques
Threats:
Alien
Industry:
Iot
TTPs:
Tactics: 8
Technics: 22
IOCs:
Registry: 3
Path: 10
Domain: 3
File: 5
Hash: 7
Softs:
microsoft excel, windows service, windows defender
Win API:
CmRcService, CmRccService
29-08-2022
Crypto miners latest techniques
https://cybersecurity.att.com/blogs/labs-research/crypto-miners-latest-techniques
Threats:
Alien
Industry:
Iot
TTPs:
Tactics: 8
Technics: 22
IOCs:
Registry: 3
Path: 10
Domain: 3
File: 5
Hash: 7
Softs:
microsoft excel, windows service, windows defender
Win API:
CmRcService, CmRccService
LevelBlue
Crypto miners’ latest techniques
An exploration of the newest methods used by crypto miners to exploit systems, enhancing threat awareness.
#ParsedReport
29-08-2022
Traffers: a deep dive into the information stealer ecosystem
https://blog.sekoia.io/traffers-a-deep-dive-into-the-information-stealer-ecosystem
Threats:
Traffer
Raccoon_stealer
Vidar_stealer
Redline_stealer
Hydra
Meta_stealer
Ytstealer
Industry:
Media, E-commerce, Financial, Entertainment
Geo:
Russian
IOCs:
Url: 6
Domain: 1
File: 2
Hash: 2
IP: 1
Softs:
windows defender, telegram, discord
29-08-2022
Traffers: a deep dive into the information stealer ecosystem
https://blog.sekoia.io/traffers-a-deep-dive-into-the-information-stealer-ecosystem
Threats:
Traffer
Raccoon_stealer
Vidar_stealer
Redline_stealer
Hydra
Meta_stealer
Ytstealer
Industry:
Media, E-commerce, Financial, Entertainment
Geo:
Russian
IOCs:
Url: 6
Domain: 1
File: 2
Hash: 2
IP: 1
Softs:
windows defender, telegram, discord
Sekoia.io Blog
Traffers: a deep dive into the information stealer ecosystem
Traffers are responsible for redirecting user traffic to malicious content (malware, fraud, phishing, scam) exploited by other threat actors.
#ParsedReport
28-08-2022
Kimsuky Group, Targeting Russian Foreign Ministry is attacking!Malware Analysis Report
https://blog.alyac.co.kr/4892
Actors/Campaigns:
Kimsuky
Threats:
Emotet
Lockbit
Venus_locker
Geo:
Korea, Japanese, Russian
IOCs:
File: 4
Url: 1
IP: 1
Hash: 1
Softs:
android, task scheduler
Algorithms:
zipx
Languages:
visual_basic
28-08-2022
Kimsuky Group, Targeting Russian Foreign Ministry is attacking!Malware Analysis Report
https://blog.alyac.co.kr/4892
Actors/Campaigns:
Kimsuky
Threats:
Emotet
Lockbit
Venus_locker
Geo:
Korea, Japanese, Russian
IOCs:
File: 4
Url: 1
IP: 1
Hash: 1
Softs:
android, task scheduler
Algorithms:
zipx
Languages:
visual_basic
이스트시큐리티 알약 블로그
김수키(Kimsuky) 그룹, 러시아 외무부를 타겟으로 공격 진행중!
안녕하세요? 이스트시큐리티 시큐리티대응센터(이하 ESRC)입니다. 김수키(Kimsuky) 그룹이 러시아 외무부를 타겟으로 진행한 공격이 포착되었습니다. 이번에 포착된 공격은 이메일을 통해 진행되었으며, Kimsuky 그룹은 선제적 공격을 통해 탈취한 심양 러시아 총 영사관 계정을 사용하여 일본 러시아 총 영사관에 추가 공격행위를 시도한 것으로 추정됩니다. 해당 공격은 대사관 회계과를 위장한 이메일을 통해 시도되었으며, 자금 이체를 위한 대사관 정보를 보내드린다는…
#ParsedReport
29-08-2022
AsyncRAT: Using Fully Undetected Downloader
https://www.netskope.com/blog/asyncrat-using-fully-undetected-downloader
Threats:
Asyncrat_rat
Process_hollowing_technique
Ousaban
Industry:
Financial
Geo:
Japanese, Latam
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 7
Softs:
microsoft office, windows defender
Algorithms:
hmac, cbc, aes, aes-256, base64
Functions:
InitializeSettings
Languages:
python
SIGMA: Found
Links:
29-08-2022
AsyncRAT: Using Fully Undetected Downloader
https://www.netskope.com/blog/asyncrat-using-fully-undetected-downloader
Threats:
Asyncrat_rat
Process_hollowing_technique
Ousaban
Industry:
Financial
Geo:
Japanese, Latam
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 7
Softs:
microsoft office, windows defender
Algorithms:
hmac, cbc, aes, aes-256, base64
Functions:
InitializeSettings
Languages:
python
SIGMA: Found
Links:
https://github.com/NYAN-x-CAT/AsyncRAT-C-Sharp
https://github.com/netskopeoss/NetskopeThreatLabsIOCs/tree/main/AsyncRAT
https://github.com/netskopeoss/NetskopeThreatLabsIOCs/tree/main/AsyncRAT/scriptNetskope
AsyncRAT: Using Fully Undetected Downloader
Summary AsyncRAT is an open-source remote administration tool released on GitHub in January 2019. It’s designed to remotely control computers via
#ParsedReport
30-08-2022
Rising Tide: Chasing the Currents of Espionage in the South China Sea
https://www.proofpoint.com/us/blog/threat-insight/chasing-currents-espionage-south-china-sea
Actors/Campaigns:
Red_ladon (motivation: cyber_espionage)
Leviathan
Red_sylvan
Stone_panda
Emissary_panda
Earth_empusa
Luckycat
Threats:
Scanbox
Ladon_tool
Rtf_template_inject_technique
Phoenix_keylogger
Meterpreter_tool
Watering_hole_technique
Dll_sideloading_technique
Beacon
Industry:
Maritime, Financial, Healthcare, Energy, Government, Petroleum, Education
Geo:
Taiwan, Australia, Malaysia, Australian, China, Cambodia, Pacific, Chinese, Asia
IOCs:
Domain: 7
Url: 28
File: 7
IP: 6
Email: 18
Hash: 31
Softs:
chrome, webrtc, opera, microsoft word, mariadb, internet explorer
Algorithms:
xor, zip
Languages:
php, java, javascript
Links:
30-08-2022
Rising Tide: Chasing the Currents of Espionage in the South China Sea
https://www.proofpoint.com/us/blog/threat-insight/chasing-currents-espionage-south-china-sea
Actors/Campaigns:
Red_ladon (motivation: cyber_espionage)
Leviathan
Red_sylvan
Stone_panda
Emissary_panda
Earth_empusa
Luckycat
Threats:
Scanbox
Ladon_tool
Rtf_template_inject_technique
Phoenix_keylogger
Meterpreter_tool
Watering_hole_technique
Dll_sideloading_technique
Beacon
Industry:
Maritime, Financial, Healthcare, Energy, Government, Petroleum, Education
Geo:
Taiwan, Australia, Malaysia, Australian, China, Cambodia, Pacific, Chinese, Asia
IOCs:
Domain: 7
Url: 28
File: 7
IP: 6
Email: 18
Hash: 31
Softs:
chrome, webrtc, opera, microsoft word, mariadb, internet explorer
Algorithms:
xor, zip
Languages:
php, java, javascript
Links:
https://github.com/nico3333fr/CSP-useful/blob/master/csp-wtf/explained.mdProofpoint
Cyber Espionage in the South China Sea | Proofpoint US
Proofpoint's Threat Research Team has released details on recent cyber espionage activity in the South China Sea. Learn more about the recent campaigns.
#ParsedReport
30-08-2022
Mini Stealer: Possible Predecessor of Parrot Stealer
https://blog.cyble.com/2022/08/29/mini-stealer-possible-predecessor-of-parrot-stealer
Threats:
Ministealer
Parrotstealer
Timestomp_technique
Antidebugging_technique
Beacon
TTPs:
Tactics: 6
Technics: 13
IOCs:
File: 2
Hash: 1
Softs:
sleipnir, vivaldi, winscp, kometa, orbitum, browser360, operagx, avastbrowser, chedot, epicprivacybrowser, centbrowser, comododragon
Algorithms:
zip
Win API:
IsDebuggerPresent
30-08-2022
Mini Stealer: Possible Predecessor of Parrot Stealer
https://blog.cyble.com/2022/08/29/mini-stealer-possible-predecessor-of-parrot-stealer
Threats:
Ministealer
Parrotstealer
Timestomp_technique
Antidebugging_technique
Beacon
TTPs:
Tactics: 6
Technics: 13
IOCs:
File: 2
Hash: 1
Softs:
sleipnir, vivaldi, winscp, kometa, orbitum, browser360, operagx, avastbrowser, chedot, epicprivacybrowser, centbrowser, comododragon
Algorithms:
zip
Win API:
IsDebuggerPresent
#ParsedReport
30-08-2022
Crypto miners latest techniques
https://cybersecurity.att.com/blogs/labs-research/crypto-miners-latest-techniques
Threats:
Alien
Industry:
Iot
Geo:
Mexican
TTPs:
Tactics: 8
Technics: 22
IOCs:
Registry: 3
Path: 10
Domain: 3
File: 5
Hash: 7
Softs:
microsoft excel, windows service, windows defender
Win API:
CmRccService, CmRcService
30-08-2022
Crypto miners latest techniques
https://cybersecurity.att.com/blogs/labs-research/crypto-miners-latest-techniques
Threats:
Alien
Industry:
Iot
Geo:
Mexican
TTPs:
Tactics: 8
Technics: 22
IOCs:
Registry: 3
Path: 10
Domain: 3
File: 5
Hash: 7
Softs:
microsoft excel, windows service, windows defender
Win API:
CmRccService, CmRcService
LevelBlue
Crypto miners’ latest techniques
An exploration of the newest methods used by crypto miners to exploit systems, enhancing threat awareness.
#ParsedReport
30-08-2022
ModernLoader delivers multiple stealers, cryptominers and RATs
https://blog.talosintelligence.com/2022/08/modernloader-delivers-multiple-stealers.html
Threats:
Modern_loader
Redline_stealer
Systembc
Dcrat_rat
Xmrig_miner
Sharphide_tool
Confuserex_tool
Process_hollowing_technique
Process_injection_technique
Emotet
Upx_tool
Silentxmr
Ethminer
Themida_tool
Avatarloader
Industry:
Financial
Geo:
Polish, Asian, Indonesia, Bulgarian, Russian, Hungarian
IOCs:
IP: 5
Url: 67
File: 43
Hash: 102
Registry: 3
Path: 23
Coin: 1
Softs:
discord, visual studio, scripting engine, windows explorer, chrome, cpanel, windows defender
Algorithms:
zip, base64
Functions:
PowerShell
Win API:
NtSetValueKey, AmsiScanBuffer, ZwUnmapViewOfSection
Languages:
csharp, golang, php, visual_basic
30-08-2022
ModernLoader delivers multiple stealers, cryptominers and RATs
https://blog.talosintelligence.com/2022/08/modernloader-delivers-multiple-stealers.html
Threats:
Modern_loader
Redline_stealer
Systembc
Dcrat_rat
Xmrig_miner
Sharphide_tool
Confuserex_tool
Process_hollowing_technique
Process_injection_technique
Emotet
Upx_tool
Silentxmr
Ethminer
Themida_tool
Avatarloader
Industry:
Financial
Geo:
Polish, Asian, Indonesia, Bulgarian, Russian, Hungarian
IOCs:
IP: 5
Url: 67
File: 43
Hash: 102
Registry: 3
Path: 23
Coin: 1
Softs:
discord, visual studio, scripting engine, windows explorer, chrome, cpanel, windows defender
Algorithms:
zip, base64
Functions:
PowerShell
Win API:
NtSetValueKey, AmsiScanBuffer, ZwUnmapViewOfSection
Languages:
csharp, golang, php, visual_basic
👍2🤬1😢1
CTT Report Hub pinned «Отдельный канал для трендов (срезы за неделю/месяц/квартал/год) https://t.me/threatinteltrends»
#ParsedReport
31-08-2022
. Analysis of the ransom incidents of Changjietong T+vulnerabilities
https://www.antiy.cn/research/notice&report/research_report/20220830.html
Threats:
Tellyouthepass
Industry:
Financial
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 4
Hash: 2
Email: 1
Softs:
asp.net
Algorithms:
aes, zip
Platforms:
intel, x86
31-08-2022
. Analysis of the ransom incidents of Changjietong T+vulnerabilities
https://www.antiy.cn/research/notice&report/research_report/20220830.html
Threats:
Tellyouthepass
Industry:
Financial
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 4
Hash: 2
Email: 1
Softs:
asp.net
Algorithms:
aes, zip
Platforms:
intel, x86
www.antiy.cn
畅捷通0day勒索攻击事件关联归因及产品解决方案
畅捷通T+软件的0day漏洞,被“魔笛”黑客组织利用进行勒索攻击活动,引起较大社会影响,安天CERT畅捷通0day对该勒索攻击事件关联归因,并提供了包括云主机防护、端点防护、应用防火墙等产品在内的综合解决方案。