CTT Report Hub
3.42K subscribers
9.87K photos
6 videos
67 files
13.5K links
Threat Intelligence Report Hub
Download Telegram
#ParsedReport
31-08-2022

First Known Phishing Attack Against PyPi Users

https://checkmarx.com/blog/first-known-phishing-attack-against-pypi-users

Threats:
Typosquatting_technique

IOCs:
Domain: 3
Url: 6
File: 2
Hash: 2

Algorithms:
exhibit, zip

Languages:
python

Links:
https://gist.github.com/Aviadg/e10696f3a215a577585433b0854ccb31#file-pypi\_phishing-csv
#ParsedReport
31-08-2022

RAT Tool Disguised as Solution File (*.sln) Being Distributed on Github

https://asec.ahnlab.com/en/38150

Threats:
Asyncrat_rat
Trojan/win.leonem.c5218555
Trojan/win.agent.c4526491
Vbinder
Smokeloader
Trojan/win.msilzilla.c5129545
Trojan/win.generic.c5198415
Malware/mdp.inject.m3037
Malware/mdp.autorun.m1037
Malware/mdp.inject.m1252
Control_rat

IOCs:
File: 3
Url: 4
Hash: 6

Softs:
windows explorer

Algorithms:
zip
#ParsedReport
31-08-2022

Malicious Word Files Targeting Specific Individuals Related to North Korea

https://asec.ahnlab.com/en/38182

Actors/Campaigns:
Kimsuky

Geo:
Korea, Gyeonggi-do, Korean

TTPs:
Tactics: 1
Technics: 0

IOCs:
File: 9
Url: 3
Path: 3
Registry: 7
Hash: 1

Platforms:
x86
#ParsedReport
01-09-2022

ASEC Weekly Malware Statistics (August 22nd, 2022 August 28th, 2022)

https://asec.ahnlab.com/en/38379

Threats:
Agent_tesla
Redline_stealer
Beamwinhttp_loader
Formbook
Clipboard_grabbing_technique
Cloudeye
Remcos_rat
Nanocore_rat

Industry:
Energy, Financial, Transport

Geo:
Korea, Emirates

IOCs:
Domain: 16
IP: 3
Email: 6
File: 33
Url: 16

Softs:
nsis installer, discord

Languages:
visual_basic
#ParsedReport
01-09-2022

ASEC Weekly Malware Statistics (August 15th, 2022 August 21st, 2022)

https://asec.ahnlab.com/en/38170

Threats:
Agent_tesla
Formbook
Redline_stealer
Clipboard_grabbing_technique
Beamwinhttp_loader
Cloudeye
Remcos_rat
Nanocore_rat
Avemaria_rat
Lokibot_stealer

Industry:
Financial

Geo:
Korea

TTPs:

IOCs:
Domain: 3
IP: 11
Email: 6
File: 20
Url: 15

Softs:
discord, nsis installer

Languages:
visual_basic
#ParsedReport
01-09-2022

ERMAC 2.0: Perfecting the Account Takeover

https://intel471.com/blog/rmac-2-0-perfecting-the-art-of-account-takeover

Actors/Campaigns:
Dukeeugene

Threats:
Ermac
Cerberus
Blackrock

Industry:
Financial, E-commerce

Geo:
China, Russia

IOCs:
File: 1

Softs:
android, telegram

Platforms:
intel
#ParsedReport
01-09-2022

THREAT ANALYSIS REPORT: Ragnar Locker Ransomware Targeting the Energy Sector

https://www.cybereason.com/blog/threat-analysis-report-ragnar-locker-ransomware-targeting-the-energy-sector

Threats:
Ragnarlocker
Blackcat
Clop
Logmein_tool
Splashtop_tool

Industry:
Petroleum, Government, Energy, Financial

Geo:
Kazakhstan, Israel, Kyrgyzstan, Belarus, Tajikistan, Russia, Azerbaijan, Uzbekistan, Luxembourg, Ukraine, Greece, Moldova, Georgia, Armenia, Turkmenistan, China

TTPs:
Tactics: 3
Technics: 7

IOCs:
File: 17
Path: 2
Hash: 35

Softs:
hyper-v, opera, internet explorer, mozilla firefox, vssadmin

Algorithms:
salsa20, rc4

Functions:
Locker

Win API:
CryptBinaryToStringA, GetComputerNameW, CreateFileW, CreateEventW, CreateProcessAsUserW, FindFirstVolumeA, FindNextVolumeA, GetLocaleInfoW, DeviceIoControl, GetUserNameW
#ParsedReport
01-09-2022

Raspberry Robin and Dridex: Two Birds of a Feather

https://securityintelligence.com/posts/raspberry-robin-worm-dridex-malware

Actors/Campaigns:
Evil_corp (motivation: cyber_criminal)
Fakeupdates

Threats:
Raspberry_robin
Dridex
Socgholish_loader
Dopplepaymer
Lockbit
Wastedlocker
Lolbin

Industry:
Transport, Petroleum

Geo:
Russia

IOCs:
Hash: 3
File: 10

Algorithms:
xor, rc4, crc

Functions:
GetPrcAddress, LdrLoadDll, bytearray, the, LdrGetProcedureAddress

Win API:
LoadLibraryA, VirtualAlloc, wglGetProcAddress, VirtualProtect

Languages:
python
#ParsedReport
01-09-2022

Highly evasive Magecart JavaScript Skimmer active in the wild

https://blog.cyble.com/2022/09/01/highly-evasive-magecart-javascript-skimmer-active-in-the-wild

Actors/Campaigns:
Magecart

Threats:
Beacon

Industry:
E-commerce, Financial

Geo:
Dubai, Georgia, Singapore, Australia, India

TTPs:
Tactics: 6
Technics: 6

IOCs:
File: 1
Hash: 1

Languages:
javascript, php
#ParsedReport
30-08-2022

[ \] Appleseed v2.1. [Threat Analysis\] Appleseed V2.1 running on JavaScript

https://stic.secui.com/main/main/threatInfo?id=69

Threats:
Appleseed

IOCs:
File: 15

Algorithms:
zip, rc4, xor, base64

Win API:
Compress

Languages:
javascript, python

Platforms:
x86
#ParsedReport
01-09-2022

PyPI Phishing Campaign \| JuiceLedger Threat Actor Pivots From Fake Apps to Supply Chain Attacks

https://www.sentinelone.com/labs/pypi-phishing-campaign-juiceledger-threat-actor-pivots-from-fake-apps-to-supply-chain-attacks

Actors/Campaigns:
Juiceledger

Threats:
Juicestealer
Typosquatting_technique
Agent_tesla
Cratedepression

IOCs:
Domain: 14
Hash: 45
File: 11
Path: 1
Url: 1
IP: 1
Email: 1

Softs:
chrome, discord

Algorithms:
zip

Languages:
python, rust
#ParsedReport
01-09-2022

No Honor Among Thieves - Prynt Stealers Backdoor Exposed. Key Points

https://www.zscaler.com/blogs/security-research/no-honor-among-thieves-prynt-stealers-backdoor-exposed

Threats:
Prynt_stealer
Asyncrat_rat
Stormkitty_stealer
Loda_rat
Njrat_rat
Quasar_rat
Cobian_rat
Binder
Netstat_tool

Industry:
Entertainment, Financial

IOCs:
IP: 1
Url: 4
Domain: 6
File: 9
Hash: 10
Path: 1

Softs:
telegram

Win API:
RtlSetProcessIsCritical, SetThreadExecutionState

Languages:
autoit

Links:
https://github.com/threatlabz/iocs/tree/main/pryntstealer
https://github.com/NYAN-x-CAT/AsyncRAT-C-Sharp
https://github.com/NYAN-x-CAT/AsyncRAT-C-Sharp/blob/master/AsyncRAT-C%23/Client/Settings.cs
https://github.com/swagkarna/StormKitty/
#ParsedReport
02-09-2022

Buzzing in the Background: BumbleBee, a New Modular Backdoor Evolved From BookWorm. Introduction

https://www.trendmicro.com/en_us/research/22/i/buzzing-in-the-background-bumblebee-a-new-modular-backdoor-evolv.html

Threats:
Bumblebee
Bookworm
Beacon
Trojan.win32.multicom.ztic
Trojan.win32.regload.zti
Backdoor.win32.bumbleb.ztic
Dll_sideloading_technique
Process_injection_technique

Industry:
Government

Geo:
Asia, Taiwan, Chinese, China, Asian

TTPs:
Tactics: 7
Technics: 15

IOCs:
File: 11
Path: 2
Registry: 2
Hash: 9
Url: 2

Softs:
windows service

Algorithms:
crc, rc4, xor
#ParsedReport
02-09-2022

Zanubis: New Android Banking Trojan spotted in the wild

https://blog.cyble.com/2022/09/02/zanubis-new-android-banking-trojan

Threats:
Zanubis
Hydra
Ermac
Bratarat

Industry:
Financial

Geo:
Dubai, Georgia, India, Peruvian, Australia, Peru, Singapore

TTPs:
Tactics: 3
Technics: 9

IOCs:
File: 18
Url: 1
Hash: 3

Softs:
android

Functions:
onAccessibilityEvent
#ParsedReport
03-09-2022

No Honor Among Thieves - Prynt Stealers Backdoor Exposed. Key Points

https://www.zscaler.com/blogs/security-research/no-honor-among-thieves-prynt-stealers-backdoor-exposed

Threats:
Asyncrat_rat
Stormkitty_stealer
Loda_rat
Njrat_rat
Quasar_rat
Cobian_rat
Binder
Netstat_tool

Industry:
Financial, Entertainment

IOCs:
IP: 1
Url: 4
Domain: 6
File: 9
Hash: 10
Path: 1

Softs:
telegram

Win API:
RtlSetProcessIsCritical, SetThreadExecutionState

Languages:
autoit

Links:
https://github.com/threatlabz/iocs/tree/main/pryntstealer
https://github.com/NYAN-x-CAT/AsyncRAT-C-Sharp/blob/master/AsyncRAT-C%23/Client/Settings.cs
https://github.com/NYAN-x-CAT/AsyncRAT-C-Sharp
https://github.com/swagkarna/StormKitty/
#ParsedReport
03-09-2022

SafeBreach Labs Researchers Uncover New Remote Access Trojan (RAT). CodeRAT Overview

https://www.safebreach.com/resources/blog/remote-access-trojan-coderat

Threats:
Coderat
Robothief
Antidebugging_technique

Industry:
Media, Government, E-commerce

Geo:
Iranian, Tehran, Irans, Iran

IOCs:
File: 9
Hash: 5

Softs:
microsoft powerpoint, microsoft word, windows media player, android, egram grou, microsoft office, visual studio, ram.org/bo, instagram, telegram

Functions:
BossWatch, CheckBoss

Win API:
CryptUnprotectData

Languages:
python

Platforms:
x86

YARA: Found

Links:
https://github.com/MrModed/DWM
#ParsedReport
03-09-2022

Crypto miners latest techniques

https://cybersecurity.att.com/blogs/labs-research/crypto-miners-latest-techniques

Threats:
Alien

Industry:
Iot

Geo:
Mexican

TTPs:
Tactics: 8
Technics: 22

IOCs:
Registry: 3
Path: 10
Domain: 3
File: 5
Hash: 7

Softs:
windows service, microsoft excel, windows defender

Win API:
CmRccService, CmRcService