CTT Report Hub
3.42K subscribers
9.87K photos
6 videos
67 files
13.5K links
Threat Intelligence Report Hub
Download Telegram
#ParsedReport
01-09-2022

ASEC Weekly Malware Statistics (August 22nd, 2022 August 28th, 2022)

https://asec.ahnlab.com/en/38379

Threats:
Agent_tesla
Redline_stealer
Beamwinhttp_loader
Formbook
Clipboard_grabbing_technique
Cloudeye
Remcos_rat
Nanocore_rat

Industry:
Energy, Financial, Transport

Geo:
Korea, Emirates

IOCs:
Domain: 16
IP: 3
Email: 6
File: 33
Url: 16

Softs:
nsis installer, discord

Languages:
visual_basic
#ParsedReport
01-09-2022

ASEC Weekly Malware Statistics (August 15th, 2022 August 21st, 2022)

https://asec.ahnlab.com/en/38170

Threats:
Agent_tesla
Formbook
Redline_stealer
Clipboard_grabbing_technique
Beamwinhttp_loader
Cloudeye
Remcos_rat
Nanocore_rat
Avemaria_rat
Lokibot_stealer

Industry:
Financial

Geo:
Korea

TTPs:

IOCs:
Domain: 3
IP: 11
Email: 6
File: 20
Url: 15

Softs:
discord, nsis installer

Languages:
visual_basic
#ParsedReport
01-09-2022

ERMAC 2.0: Perfecting the Account Takeover

https://intel471.com/blog/rmac-2-0-perfecting-the-art-of-account-takeover

Actors/Campaigns:
Dukeeugene

Threats:
Ermac
Cerberus
Blackrock

Industry:
Financial, E-commerce

Geo:
China, Russia

IOCs:
File: 1

Softs:
android, telegram

Platforms:
intel
#ParsedReport
01-09-2022

THREAT ANALYSIS REPORT: Ragnar Locker Ransomware Targeting the Energy Sector

https://www.cybereason.com/blog/threat-analysis-report-ragnar-locker-ransomware-targeting-the-energy-sector

Threats:
Ragnarlocker
Blackcat
Clop
Logmein_tool
Splashtop_tool

Industry:
Petroleum, Government, Energy, Financial

Geo:
Kazakhstan, Israel, Kyrgyzstan, Belarus, Tajikistan, Russia, Azerbaijan, Uzbekistan, Luxembourg, Ukraine, Greece, Moldova, Georgia, Armenia, Turkmenistan, China

TTPs:
Tactics: 3
Technics: 7

IOCs:
File: 17
Path: 2
Hash: 35

Softs:
hyper-v, opera, internet explorer, mozilla firefox, vssadmin

Algorithms:
salsa20, rc4

Functions:
Locker

Win API:
CryptBinaryToStringA, GetComputerNameW, CreateFileW, CreateEventW, CreateProcessAsUserW, FindFirstVolumeA, FindNextVolumeA, GetLocaleInfoW, DeviceIoControl, GetUserNameW
#ParsedReport
01-09-2022

Raspberry Robin and Dridex: Two Birds of a Feather

https://securityintelligence.com/posts/raspberry-robin-worm-dridex-malware

Actors/Campaigns:
Evil_corp (motivation: cyber_criminal)
Fakeupdates

Threats:
Raspberry_robin
Dridex
Socgholish_loader
Dopplepaymer
Lockbit
Wastedlocker
Lolbin

Industry:
Transport, Petroleum

Geo:
Russia

IOCs:
Hash: 3
File: 10

Algorithms:
xor, rc4, crc

Functions:
GetPrcAddress, LdrLoadDll, bytearray, the, LdrGetProcedureAddress

Win API:
LoadLibraryA, VirtualAlloc, wglGetProcAddress, VirtualProtect

Languages:
python
#ParsedReport
01-09-2022

Highly evasive Magecart JavaScript Skimmer active in the wild

https://blog.cyble.com/2022/09/01/highly-evasive-magecart-javascript-skimmer-active-in-the-wild

Actors/Campaigns:
Magecart

Threats:
Beacon

Industry:
E-commerce, Financial

Geo:
Dubai, Georgia, Singapore, Australia, India

TTPs:
Tactics: 6
Technics: 6

IOCs:
File: 1
Hash: 1

Languages:
javascript, php
#ParsedReport
30-08-2022

[ \] Appleseed v2.1. [Threat Analysis\] Appleseed V2.1 running on JavaScript

https://stic.secui.com/main/main/threatInfo?id=69

Threats:
Appleseed

IOCs:
File: 15

Algorithms:
zip, rc4, xor, base64

Win API:
Compress

Languages:
javascript, python

Platforms:
x86
#ParsedReport
01-09-2022

PyPI Phishing Campaign \| JuiceLedger Threat Actor Pivots From Fake Apps to Supply Chain Attacks

https://www.sentinelone.com/labs/pypi-phishing-campaign-juiceledger-threat-actor-pivots-from-fake-apps-to-supply-chain-attacks

Actors/Campaigns:
Juiceledger

Threats:
Juicestealer
Typosquatting_technique
Agent_tesla
Cratedepression

IOCs:
Domain: 14
Hash: 45
File: 11
Path: 1
Url: 1
IP: 1
Email: 1

Softs:
chrome, discord

Algorithms:
zip

Languages:
python, rust
#ParsedReport
01-09-2022

No Honor Among Thieves - Prynt Stealers Backdoor Exposed. Key Points

https://www.zscaler.com/blogs/security-research/no-honor-among-thieves-prynt-stealers-backdoor-exposed

Threats:
Prynt_stealer
Asyncrat_rat
Stormkitty_stealer
Loda_rat
Njrat_rat
Quasar_rat
Cobian_rat
Binder
Netstat_tool

Industry:
Entertainment, Financial

IOCs:
IP: 1
Url: 4
Domain: 6
File: 9
Hash: 10
Path: 1

Softs:
telegram

Win API:
RtlSetProcessIsCritical, SetThreadExecutionState

Languages:
autoit

Links:
https://github.com/threatlabz/iocs/tree/main/pryntstealer
https://github.com/NYAN-x-CAT/AsyncRAT-C-Sharp
https://github.com/NYAN-x-CAT/AsyncRAT-C-Sharp/blob/master/AsyncRAT-C%23/Client/Settings.cs
https://github.com/swagkarna/StormKitty/
#ParsedReport
02-09-2022

Buzzing in the Background: BumbleBee, a New Modular Backdoor Evolved From BookWorm. Introduction

https://www.trendmicro.com/en_us/research/22/i/buzzing-in-the-background-bumblebee-a-new-modular-backdoor-evolv.html

Threats:
Bumblebee
Bookworm
Beacon
Trojan.win32.multicom.ztic
Trojan.win32.regload.zti
Backdoor.win32.bumbleb.ztic
Dll_sideloading_technique
Process_injection_technique

Industry:
Government

Geo:
Asia, Taiwan, Chinese, China, Asian

TTPs:
Tactics: 7
Technics: 15

IOCs:
File: 11
Path: 2
Registry: 2
Hash: 9
Url: 2

Softs:
windows service

Algorithms:
crc, rc4, xor
#ParsedReport
02-09-2022

Zanubis: New Android Banking Trojan spotted in the wild

https://blog.cyble.com/2022/09/02/zanubis-new-android-banking-trojan

Threats:
Zanubis
Hydra
Ermac
Bratarat

Industry:
Financial

Geo:
Dubai, Georgia, India, Peruvian, Australia, Peru, Singapore

TTPs:
Tactics: 3
Technics: 9

IOCs:
File: 18
Url: 1
Hash: 3

Softs:
android

Functions:
onAccessibilityEvent
#ParsedReport
03-09-2022

No Honor Among Thieves - Prynt Stealers Backdoor Exposed. Key Points

https://www.zscaler.com/blogs/security-research/no-honor-among-thieves-prynt-stealers-backdoor-exposed

Threats:
Asyncrat_rat
Stormkitty_stealer
Loda_rat
Njrat_rat
Quasar_rat
Cobian_rat
Binder
Netstat_tool

Industry:
Financial, Entertainment

IOCs:
IP: 1
Url: 4
Domain: 6
File: 9
Hash: 10
Path: 1

Softs:
telegram

Win API:
RtlSetProcessIsCritical, SetThreadExecutionState

Languages:
autoit

Links:
https://github.com/threatlabz/iocs/tree/main/pryntstealer
https://github.com/NYAN-x-CAT/AsyncRAT-C-Sharp/blob/master/AsyncRAT-C%23/Client/Settings.cs
https://github.com/NYAN-x-CAT/AsyncRAT-C-Sharp
https://github.com/swagkarna/StormKitty/
#ParsedReport
03-09-2022

SafeBreach Labs Researchers Uncover New Remote Access Trojan (RAT). CodeRAT Overview

https://www.safebreach.com/resources/blog/remote-access-trojan-coderat

Threats:
Coderat
Robothief
Antidebugging_technique

Industry:
Media, Government, E-commerce

Geo:
Iranian, Tehran, Irans, Iran

IOCs:
File: 9
Hash: 5

Softs:
microsoft powerpoint, microsoft word, windows media player, android, egram grou, microsoft office, visual studio, ram.org/bo, instagram, telegram

Functions:
BossWatch, CheckBoss

Win API:
CryptUnprotectData

Languages:
python

Platforms:
x86

YARA: Found

Links:
https://github.com/MrModed/DWM
#ParsedReport
03-09-2022

Crypto miners latest techniques

https://cybersecurity.att.com/blogs/labs-research/crypto-miners-latest-techniques

Threats:
Alien

Industry:
Iot

Geo:
Mexican

TTPs:
Tactics: 8
Technics: 22

IOCs:
Registry: 3
Path: 10
Domain: 3
File: 5
Hash: 7

Softs:
windows service, microsoft excel, windows defender

Win API:
CmRccService, CmRcService
#ParsedReport
03-09-2022

Sharkbot is back in Google Play

https://blog.fox-it.com/2022/09/02/sharkbot-is-back-in-google-play

Actors/Campaigns:
Fakeupdates

Threats:
Sharkbot

Industry:
Financial

Geo:
Poland, Spain, America, Austria, Australia, Italy, Germany

IOCs:
Url: 4
Hash: 2
IP: 1
Domain: 2

Softs:
android

Algorithms:
base64, rc4
#ParsedReport
03-09-2022

TTPs #8 : Operation GWISIN -. TTPS #8: Operation gwisin -custom ransomware attack strategy analysis

https://thorcert.notion.site/TTPs-8-Operation-GWISIN-c3483353d20241b3a313fa4a8726302a

Threats:
Gwisin
Process_injection_technique
Nmap_tool
Winrm_tool
Dumplsass_tool
Netstat_tool
Mimikatz

Geo:
Korea, Korean

TTPs:
Tactics: 11
Technics: 29

IOCs:
File: 16
Path: 1
Registry: 1
IP: 1

Softs:
curl, bcdedit

Algorithms:
aes, base64, rc4, rsa-aes

Languages:
php, visual_basic