#ParsedReport
29-08-2022
Crypto miners latest techniques
https://cybersecurity.att.com/blogs/labs-research/crypto-miners-latest-techniques
Threats:
Alien
Industry:
Iot
TTPs:
Tactics: 8
Technics: 22
IOCs:
Registry: 3
Path: 10
Domain: 3
File: 5
Hash: 7
Softs:
microsoft excel, windows service, windows defender
Win API:
CmRcService, CmRccService
29-08-2022
Crypto miners latest techniques
https://cybersecurity.att.com/blogs/labs-research/crypto-miners-latest-techniques
Threats:
Alien
Industry:
Iot
TTPs:
Tactics: 8
Technics: 22
IOCs:
Registry: 3
Path: 10
Domain: 3
File: 5
Hash: 7
Softs:
microsoft excel, windows service, windows defender
Win API:
CmRcService, CmRccService
LevelBlue
Crypto miners’ latest techniques
An exploration of the newest methods used by crypto miners to exploit systems, enhancing threat awareness.
#ParsedReport
29-08-2022
Traffers: a deep dive into the information stealer ecosystem
https://blog.sekoia.io/traffers-a-deep-dive-into-the-information-stealer-ecosystem
Threats:
Traffer
Raccoon_stealer
Vidar_stealer
Redline_stealer
Hydra
Meta_stealer
Ytstealer
Industry:
Media, E-commerce, Financial, Entertainment
Geo:
Russian
IOCs:
Url: 6
Domain: 1
File: 2
Hash: 2
IP: 1
Softs:
windows defender, telegram, discord
29-08-2022
Traffers: a deep dive into the information stealer ecosystem
https://blog.sekoia.io/traffers-a-deep-dive-into-the-information-stealer-ecosystem
Threats:
Traffer
Raccoon_stealer
Vidar_stealer
Redline_stealer
Hydra
Meta_stealer
Ytstealer
Industry:
Media, E-commerce, Financial, Entertainment
Geo:
Russian
IOCs:
Url: 6
Domain: 1
File: 2
Hash: 2
IP: 1
Softs:
windows defender, telegram, discord
Sekoia.io Blog
Traffers: a deep dive into the information stealer ecosystem
Traffers are responsible for redirecting user traffic to malicious content (malware, fraud, phishing, scam) exploited by other threat actors.
#ParsedReport
28-08-2022
Kimsuky Group, Targeting Russian Foreign Ministry is attacking!Malware Analysis Report
https://blog.alyac.co.kr/4892
Actors/Campaigns:
Kimsuky
Threats:
Emotet
Lockbit
Venus_locker
Geo:
Korea, Japanese, Russian
IOCs:
File: 4
Url: 1
IP: 1
Hash: 1
Softs:
android, task scheduler
Algorithms:
zipx
Languages:
visual_basic
28-08-2022
Kimsuky Group, Targeting Russian Foreign Ministry is attacking!Malware Analysis Report
https://blog.alyac.co.kr/4892
Actors/Campaigns:
Kimsuky
Threats:
Emotet
Lockbit
Venus_locker
Geo:
Korea, Japanese, Russian
IOCs:
File: 4
Url: 1
IP: 1
Hash: 1
Softs:
android, task scheduler
Algorithms:
zipx
Languages:
visual_basic
이스트시큐리티 알약 블로그
김수키(Kimsuky) 그룹, 러시아 외무부를 타겟으로 공격 진행중!
안녕하세요? 이스트시큐리티 시큐리티대응센터(이하 ESRC)입니다. 김수키(Kimsuky) 그룹이 러시아 외무부를 타겟으로 진행한 공격이 포착되었습니다. 이번에 포착된 공격은 이메일을 통해 진행되었으며, Kimsuky 그룹은 선제적 공격을 통해 탈취한 심양 러시아 총 영사관 계정을 사용하여 일본 러시아 총 영사관에 추가 공격행위를 시도한 것으로 추정됩니다. 해당 공격은 대사관 회계과를 위장한 이메일을 통해 시도되었으며, 자금 이체를 위한 대사관 정보를 보내드린다는…
#ParsedReport
29-08-2022
AsyncRAT: Using Fully Undetected Downloader
https://www.netskope.com/blog/asyncrat-using-fully-undetected-downloader
Threats:
Asyncrat_rat
Process_hollowing_technique
Ousaban
Industry:
Financial
Geo:
Japanese, Latam
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 7
Softs:
microsoft office, windows defender
Algorithms:
hmac, cbc, aes, aes-256, base64
Functions:
InitializeSettings
Languages:
python
SIGMA: Found
Links:
29-08-2022
AsyncRAT: Using Fully Undetected Downloader
https://www.netskope.com/blog/asyncrat-using-fully-undetected-downloader
Threats:
Asyncrat_rat
Process_hollowing_technique
Ousaban
Industry:
Financial
Geo:
Japanese, Latam
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 7
Softs:
microsoft office, windows defender
Algorithms:
hmac, cbc, aes, aes-256, base64
Functions:
InitializeSettings
Languages:
python
SIGMA: Found
Links:
https://github.com/NYAN-x-CAT/AsyncRAT-C-Sharp
https://github.com/netskopeoss/NetskopeThreatLabsIOCs/tree/main/AsyncRAT
https://github.com/netskopeoss/NetskopeThreatLabsIOCs/tree/main/AsyncRAT/scriptNetskope
AsyncRAT: Using Fully Undetected Downloader
Summary AsyncRAT is an open-source remote administration tool released on GitHub in January 2019. It’s designed to remotely control computers via
#ParsedReport
30-08-2022
Rising Tide: Chasing the Currents of Espionage in the South China Sea
https://www.proofpoint.com/us/blog/threat-insight/chasing-currents-espionage-south-china-sea
Actors/Campaigns:
Red_ladon (motivation: cyber_espionage)
Leviathan
Red_sylvan
Stone_panda
Emissary_panda
Earth_empusa
Luckycat
Threats:
Scanbox
Ladon_tool
Rtf_template_inject_technique
Phoenix_keylogger
Meterpreter_tool
Watering_hole_technique
Dll_sideloading_technique
Beacon
Industry:
Maritime, Financial, Healthcare, Energy, Government, Petroleum, Education
Geo:
Taiwan, Australia, Malaysia, Australian, China, Cambodia, Pacific, Chinese, Asia
IOCs:
Domain: 7
Url: 28
File: 7
IP: 6
Email: 18
Hash: 31
Softs:
chrome, webrtc, opera, microsoft word, mariadb, internet explorer
Algorithms:
xor, zip
Languages:
php, java, javascript
Links:
30-08-2022
Rising Tide: Chasing the Currents of Espionage in the South China Sea
https://www.proofpoint.com/us/blog/threat-insight/chasing-currents-espionage-south-china-sea
Actors/Campaigns:
Red_ladon (motivation: cyber_espionage)
Leviathan
Red_sylvan
Stone_panda
Emissary_panda
Earth_empusa
Luckycat
Threats:
Scanbox
Ladon_tool
Rtf_template_inject_technique
Phoenix_keylogger
Meterpreter_tool
Watering_hole_technique
Dll_sideloading_technique
Beacon
Industry:
Maritime, Financial, Healthcare, Energy, Government, Petroleum, Education
Geo:
Taiwan, Australia, Malaysia, Australian, China, Cambodia, Pacific, Chinese, Asia
IOCs:
Domain: 7
Url: 28
File: 7
IP: 6
Email: 18
Hash: 31
Softs:
chrome, webrtc, opera, microsoft word, mariadb, internet explorer
Algorithms:
xor, zip
Languages:
php, java, javascript
Links:
https://github.com/nico3333fr/CSP-useful/blob/master/csp-wtf/explained.mdProofpoint
Cyber Espionage in the South China Sea | Proofpoint US
Proofpoint's Threat Research Team has released details on recent cyber espionage activity in the South China Sea. Learn more about the recent campaigns.
#ParsedReport
30-08-2022
Mini Stealer: Possible Predecessor of Parrot Stealer
https://blog.cyble.com/2022/08/29/mini-stealer-possible-predecessor-of-parrot-stealer
Threats:
Ministealer
Parrotstealer
Timestomp_technique
Antidebugging_technique
Beacon
TTPs:
Tactics: 6
Technics: 13
IOCs:
File: 2
Hash: 1
Softs:
sleipnir, vivaldi, winscp, kometa, orbitum, browser360, operagx, avastbrowser, chedot, epicprivacybrowser, centbrowser, comododragon
Algorithms:
zip
Win API:
IsDebuggerPresent
30-08-2022
Mini Stealer: Possible Predecessor of Parrot Stealer
https://blog.cyble.com/2022/08/29/mini-stealer-possible-predecessor-of-parrot-stealer
Threats:
Ministealer
Parrotstealer
Timestomp_technique
Antidebugging_technique
Beacon
TTPs:
Tactics: 6
Technics: 13
IOCs:
File: 2
Hash: 1
Softs:
sleipnir, vivaldi, winscp, kometa, orbitum, browser360, operagx, avastbrowser, chedot, epicprivacybrowser, centbrowser, comododragon
Algorithms:
zip
Win API:
IsDebuggerPresent
#ParsedReport
30-08-2022
Crypto miners latest techniques
https://cybersecurity.att.com/blogs/labs-research/crypto-miners-latest-techniques
Threats:
Alien
Industry:
Iot
Geo:
Mexican
TTPs:
Tactics: 8
Technics: 22
IOCs:
Registry: 3
Path: 10
Domain: 3
File: 5
Hash: 7
Softs:
microsoft excel, windows service, windows defender
Win API:
CmRccService, CmRcService
30-08-2022
Crypto miners latest techniques
https://cybersecurity.att.com/blogs/labs-research/crypto-miners-latest-techniques
Threats:
Alien
Industry:
Iot
Geo:
Mexican
TTPs:
Tactics: 8
Technics: 22
IOCs:
Registry: 3
Path: 10
Domain: 3
File: 5
Hash: 7
Softs:
microsoft excel, windows service, windows defender
Win API:
CmRccService, CmRcService
LevelBlue
Crypto miners’ latest techniques
An exploration of the newest methods used by crypto miners to exploit systems, enhancing threat awareness.
#ParsedReport
30-08-2022
ModernLoader delivers multiple stealers, cryptominers and RATs
https://blog.talosintelligence.com/2022/08/modernloader-delivers-multiple-stealers.html
Threats:
Modern_loader
Redline_stealer
Systembc
Dcrat_rat
Xmrig_miner
Sharphide_tool
Confuserex_tool
Process_hollowing_technique
Process_injection_technique
Emotet
Upx_tool
Silentxmr
Ethminer
Themida_tool
Avatarloader
Industry:
Financial
Geo:
Polish, Asian, Indonesia, Bulgarian, Russian, Hungarian
IOCs:
IP: 5
Url: 67
File: 43
Hash: 102
Registry: 3
Path: 23
Coin: 1
Softs:
discord, visual studio, scripting engine, windows explorer, chrome, cpanel, windows defender
Algorithms:
zip, base64
Functions:
PowerShell
Win API:
NtSetValueKey, AmsiScanBuffer, ZwUnmapViewOfSection
Languages:
csharp, golang, php, visual_basic
30-08-2022
ModernLoader delivers multiple stealers, cryptominers and RATs
https://blog.talosintelligence.com/2022/08/modernloader-delivers-multiple-stealers.html
Threats:
Modern_loader
Redline_stealer
Systembc
Dcrat_rat
Xmrig_miner
Sharphide_tool
Confuserex_tool
Process_hollowing_technique
Process_injection_technique
Emotet
Upx_tool
Silentxmr
Ethminer
Themida_tool
Avatarloader
Industry:
Financial
Geo:
Polish, Asian, Indonesia, Bulgarian, Russian, Hungarian
IOCs:
IP: 5
Url: 67
File: 43
Hash: 102
Registry: 3
Path: 23
Coin: 1
Softs:
discord, visual studio, scripting engine, windows explorer, chrome, cpanel, windows defender
Algorithms:
zip, base64
Functions:
PowerShell
Win API:
NtSetValueKey, AmsiScanBuffer, ZwUnmapViewOfSection
Languages:
csharp, golang, php, visual_basic
👍2🤬1😢1
CTT Report Hub pinned «Отдельный канал для трендов (срезы за неделю/месяц/квартал/год) https://t.me/threatinteltrends»
#ParsedReport
31-08-2022
. Analysis of the ransom incidents of Changjietong T+vulnerabilities
https://www.antiy.cn/research/notice&report/research_report/20220830.html
Threats:
Tellyouthepass
Industry:
Financial
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 4
Hash: 2
Email: 1
Softs:
asp.net
Algorithms:
aes, zip
Platforms:
intel, x86
31-08-2022
. Analysis of the ransom incidents of Changjietong T+vulnerabilities
https://www.antiy.cn/research/notice&report/research_report/20220830.html
Threats:
Tellyouthepass
Industry:
Financial
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 4
Hash: 2
Email: 1
Softs:
asp.net
Algorithms:
aes, zip
Platforms:
intel, x86
www.antiy.cn
畅捷通0day勒索攻击事件关联归因及产品解决方案
畅捷通T+软件的0day漏洞,被“魔笛”黑客组织利用进行勒索攻击活动,引起较大社会影响,安天CERT畅捷通0day对该勒索攻击事件关联归因,并提供了包括云主机防护、端点防护、应用防火墙等产品在内的综合解决方案。
#ParsedReport
31-08-2022
Securonix Threat Labs Security Advisory:New Golang Attack Campaign GO#WEBBFUSCATOR Leverages Office Macros and James Webb Images to Infect Systems. Securonix Threat Labs Security Advisory: New Golang Attack Campaign GO#WEBBFUSCATOR Leverages Office Macros and James Webb Images to Infect Systems
https://www.securonix.com/blog/golang-attack-campaign-gowebbfuscator-leverages-office-macros-and-james-webb-images-to-infect-systems
Actors/Campaigns:
Red_delta
Threats:
Dnscat2_tool
Lolbin
Dns_tunneling_technique
Plugx_rat
TTPs:
Tactics: 7
Technics: 14
IOCs:
Url: 2
File: 6
Path: 10
IP: 3
Registry: 1
Domain: 9
Hash: 4
Softs:
windows registry, microsoft office, curl
Algorithms:
base64, rot25, rot1, xor
Win API:
WmiCreateProcess
Languages:
golang
YARA: Found
31-08-2022
Securonix Threat Labs Security Advisory:New Golang Attack Campaign GO#WEBBFUSCATOR Leverages Office Macros and James Webb Images to Infect Systems. Securonix Threat Labs Security Advisory: New Golang Attack Campaign GO#WEBBFUSCATOR Leverages Office Macros and James Webb Images to Infect Systems
https://www.securonix.com/blog/golang-attack-campaign-gowebbfuscator-leverages-office-macros-and-james-webb-images-to-infect-systems
Actors/Campaigns:
Red_delta
Threats:
Dnscat2_tool
Lolbin
Dns_tunneling_technique
Plugx_rat
TTPs:
Tactics: 7
Technics: 14
IOCs:
Url: 2
File: 6
Path: 10
IP: 3
Registry: 1
Domain: 9
Hash: 4
Softs:
windows registry, microsoft office, curl
Algorithms:
base64, rot25, rot1, xor
Win API:
WmiCreateProcess
Languages:
golang
YARA: Found
Securonix
Securonix Threat Labs Security Advisory: New Golang Attack Campaign GO#WEBBFUSCATOR Leverages Office Macros and James Webb Images…
Learn about the GO#WEBBFUSCATOR malware attack campaign, leveraging James Webb images and Office macros, and discover mitigation strategies.
#ParsedReport
31-08-2022
Asbit: An Emerging Remote Desktop Trojan. Introduction
https://blogs.juniper.net/en-us/threat-research/asbit-an-emerging-remote-desktop-trojan
Threats:
Asbit_rat
Tightvnc_tool
Geo:
Pacific, Chinese, China, Asia
IOCs:
Domain: 6
IP: 11
Path: 3
Hash: 9
File: 7
Url: 3
Softs:
discord, net framework
Algorithms:
gzip
31-08-2022
Asbit: An Emerging Remote Desktop Trojan. Introduction
https://blogs.juniper.net/en-us/threat-research/asbit-an-emerging-remote-desktop-trojan
Threats:
Asbit_rat
Tightvnc_tool
Geo:
Pacific, Chinese, China, Asia
IOCs:
Domain: 6
IP: 11
Path: 3
Hash: 9
File: 7
Url: 3
Softs:
discord, net framework
Algorithms:
gzip
Juniper Networks
Introduction
Introduction Juniper Threat Labs is currently monitoring an emerging Chinese Remote Desktop Trojan called Asbit. It’s a remote access Trojan being advertised on its developer’s website as a “Fast
#ParsedReport
31-08-2022
Check Point Research detects Crypto Miner malware disguised as Google translate desktop and other legitimate applications
https://research.checkpoint.com/2022/check-point-research-detects-crypto-miner-malware-disguised-as-google-translate-desktop-and-other-legitimate-applications
Threats:
Nitrokod
Xmrig_miner
Geo:
Turkish
IOCs:
Domain: 3
File: 8
Url: 1
Path: 3
IP: 1
Hash: 6
Softs:
chromium, windows defender, windows installer
Algorithms:
base64
Platforms:
x86
31-08-2022
Check Point Research detects Crypto Miner malware disguised as Google translate desktop and other legitimate applications
https://research.checkpoint.com/2022/check-point-research-detects-crypto-miner-malware-disguised-as-google-translate-desktop-and-other-legitimate-applications
Threats:
Nitrokod
Xmrig_miner
Geo:
Turkish
IOCs:
Domain: 3
File: 8
Url: 1
Path: 3
IP: 1
Hash: 6
Softs:
chromium, windows defender, windows installer
Algorithms:
base64
Platforms:
x86
#ParsedReport
31-08-2022
APT-C-08 wmRAT. Detailed analysis report
https://mp.weixin.qq.com/s/IZNl6N2K1LUU7e1hT4JeYw
Actors/Campaigns:
Manlinghua
Threats:
Wmrat
Industry:
Government
Geo:
Asian
IOCs:
File: 4
Hash: 13
IP: 1
Softs:
curl
31-08-2022
APT-C-08 wmRAT. Detailed analysis report
https://mp.weixin.qq.com/s/IZNl6N2K1LUU7e1hT4JeYw
Actors/Campaigns:
Manlinghua
Threats:
Wmrat
Industry:
Government
Geo:
Asian
IOCs:
File: 4
Hash: 13
IP: 1
Softs:
curl
#ParsedReport
31-08-2022
First Known Phishing Attack Against PyPi Users
https://checkmarx.com/blog/first-known-phishing-attack-against-pypi-users
Threats:
Typosquatting_technique
IOCs:
Domain: 3
Url: 6
File: 2
Hash: 2
Algorithms:
exhibit, zip
Languages:
python
Links:
31-08-2022
First Known Phishing Attack Against PyPi Users
https://checkmarx.com/blog/first-known-phishing-attack-against-pypi-users
Threats:
Typosquatting_technique
IOCs:
Domain: 3
Url: 6
File: 2
Hash: 2
Algorithms:
exhibit, zip
Languages:
python
Links:
https://gist.github.com/Aviadg/e10696f3a215a577585433b0854ccb31#file-pypi\_phishing-csvCheckmarx
First Known Phishing Attack Against PyPi Users
A few hours ago, PyPi disclose information on the first seen phishing attack aimed at a Python contributor. Right now, we are aware of hundreds of malicious packages that were related to this attack based on the known indicator.
#ParsedReport
31-08-2022
RAT Tool Disguised as Solution File (*.sln) Being Distributed on Github
https://asec.ahnlab.com/en/38150
Threats:
Asyncrat_rat
Trojan/win.leonem.c5218555
Trojan/win.agent.c4526491
Vbinder
Smokeloader
Trojan/win.msilzilla.c5129545
Trojan/win.generic.c5198415
Malware/mdp.inject.m3037
Malware/mdp.autorun.m1037
Malware/mdp.inject.m1252
Control_rat
IOCs:
File: 3
Url: 4
Hash: 6
Softs:
windows explorer
Algorithms:
zip
31-08-2022
RAT Tool Disguised as Solution File (*.sln) Being Distributed on Github
https://asec.ahnlab.com/en/38150
Threats:
Asyncrat_rat
Trojan/win.leonem.c5218555
Trojan/win.agent.c4526491
Vbinder
Smokeloader
Trojan/win.msilzilla.c5129545
Trojan/win.generic.c5198415
Malware/mdp.inject.m3037
Malware/mdp.autorun.m1037
Malware/mdp.inject.m1252
Control_rat
IOCs:
File: 3
Url: 4
Hash: 6
Softs:
windows explorer
Algorithms:
zip
ASEC
RAT Tool Disguised as Solution File (*.sln) Being Distributed on Github - ASEC
RAT Tool Disguised as Solution File (*.sln) Being Distributed on Github ASEC
#ParsedReport
31-08-2022
Malicious Word Files Targeting Specific Individuals Related to North Korea
https://asec.ahnlab.com/en/38182
Actors/Campaigns:
Kimsuky
Geo:
Korea, Gyeonggi-do, Korean
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 9
Url: 3
Path: 3
Registry: 7
Hash: 1
Platforms:
x86
31-08-2022
Malicious Word Files Targeting Specific Individuals Related to North Korea
https://asec.ahnlab.com/en/38182
Actors/Campaigns:
Kimsuky
Geo:
Korea, Gyeonggi-do, Korean
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 9
Url: 3
Path: 3
Registry: 7
Hash: 1
Platforms:
x86
ASEC
Malicious Word Files Targeting Specific Individuals Related to North Korea - ASEC
Malicious Word Files Targeting Specific Individuals Related to North Korea ASEC
#ParsedReport
01-09-2022
Malicious HWP File Disguised as a Happy Birthday Message (OLE Object)
https://asec.ahnlab.com/en/38203
Industry:
Education
Geo:
Korean, Korea
IOCs:
Url: 7
File: 2
Path: 3
Hash: 5
Softs:
task scheduler, curl
Platforms:
x64
01-09-2022
Malicious HWP File Disguised as a Happy Birthday Message (OLE Object)
https://asec.ahnlab.com/en/38203
Industry:
Education
Geo:
Korean, Korea
IOCs:
Url: 7
File: 2
Path: 3
Hash: 5
Softs:
task scheduler, curl
Platforms:
x64
ASEC
Malicious HWP File Disguised as a Happy Birthday Message (OLE Object) - ASEC
The ASEC analysis team has recently discovered a VBScript that downloads a malicious HWP file. The distribution path of malware is yet to be determined, but the VBScript is downloaded through curl. The commands discovered so far are as follows: curl -H ”user…