#ParsedReport
01-09-2022
ERMAC 2.0: Perfecting the Account Takeover
https://intel471.com/blog/rmac-2-0-perfecting-the-art-of-account-takeover
Actors/Campaigns:
Dukeeugene
Threats:
Ermac
Cerberus
Blackrock
Industry:
Financial, E-commerce
Geo:
China, Russia
IOCs:
File: 1
Softs:
android, telegram
Platforms:
intel
01-09-2022
ERMAC 2.0: Perfecting the Account Takeover
https://intel471.com/blog/rmac-2-0-perfecting-the-art-of-account-takeover
Actors/Campaigns:
Dukeeugene
Threats:
Ermac
Cerberus
Blackrock
Industry:
Financial, E-commerce
Geo:
China, Russia
IOCs:
File: 1
Softs:
android, telegram
Platforms:
intel
#ParsedReport
01-09-2022
THREAT ANALYSIS REPORT: Ragnar Locker Ransomware Targeting the Energy Sector
https://www.cybereason.com/blog/threat-analysis-report-ragnar-locker-ransomware-targeting-the-energy-sector
Threats:
Ragnarlocker
Blackcat
Clop
Logmein_tool
Splashtop_tool
Industry:
Petroleum, Government, Energy, Financial
Geo:
Kazakhstan, Israel, Kyrgyzstan, Belarus, Tajikistan, Russia, Azerbaijan, Uzbekistan, Luxembourg, Ukraine, Greece, Moldova, Georgia, Armenia, Turkmenistan, China
TTPs:
Tactics: 3
Technics: 7
IOCs:
File: 17
Path: 2
Hash: 35
Softs:
hyper-v, opera, internet explorer, mozilla firefox, vssadmin
Algorithms:
salsa20, rc4
Functions:
Locker
Win API:
CryptBinaryToStringA, GetComputerNameW, CreateFileW, CreateEventW, CreateProcessAsUserW, FindFirstVolumeA, FindNextVolumeA, GetLocaleInfoW, DeviceIoControl, GetUserNameW
01-09-2022
THREAT ANALYSIS REPORT: Ragnar Locker Ransomware Targeting the Energy Sector
https://www.cybereason.com/blog/threat-analysis-report-ragnar-locker-ransomware-targeting-the-energy-sector
Threats:
Ragnarlocker
Blackcat
Clop
Logmein_tool
Splashtop_tool
Industry:
Petroleum, Government, Energy, Financial
Geo:
Kazakhstan, Israel, Kyrgyzstan, Belarus, Tajikistan, Russia, Azerbaijan, Uzbekistan, Luxembourg, Ukraine, Greece, Moldova, Georgia, Armenia, Turkmenistan, China
TTPs:
Tactics: 3
Technics: 7
IOCs:
File: 17
Path: 2
Hash: 35
Softs:
hyper-v, opera, internet explorer, mozilla firefox, vssadmin
Algorithms:
salsa20, rc4
Functions:
Locker
Win API:
CryptBinaryToStringA, GetComputerNameW, CreateFileW, CreateEventW, CreateProcessAsUserW, FindFirstVolumeA, FindNextVolumeA, GetLocaleInfoW, DeviceIoControl, GetUserNameW
Cybereason
THREAT ANALYSIS REPORT: Ragnar Locker Ransomware Targeting the Energy Sector
Ragnar Locker is a ransomware family with security evasion capabilities which is targeting the energy sector and recently claimed to have breached DESFA, a Greek pipeline company...
#ParsedReport
01-09-2022
Raspberry Robin and Dridex: Two Birds of a Feather
https://securityintelligence.com/posts/raspberry-robin-worm-dridex-malware
Actors/Campaigns:
Evil_corp (motivation: cyber_criminal)
Fakeupdates
Threats:
Raspberry_robin
Dridex
Socgholish_loader
Dopplepaymer
Lockbit
Wastedlocker
Lolbin
Industry:
Transport, Petroleum
Geo:
Russia
IOCs:
Hash: 3
File: 10
Algorithms:
xor, rc4, crc
Functions:
GetPrcAddress, LdrLoadDll, bytearray, the, LdrGetProcedureAddress
Win API:
LoadLibraryA, VirtualAlloc, wglGetProcAddress, VirtualProtect
Languages:
python
01-09-2022
Raspberry Robin and Dridex: Two Birds of a Feather
https://securityintelligence.com/posts/raspberry-robin-worm-dridex-malware
Actors/Campaigns:
Evil_corp (motivation: cyber_criminal)
Fakeupdates
Threats:
Raspberry_robin
Dridex
Socgholish_loader
Dopplepaymer
Lockbit
Wastedlocker
Lolbin
Industry:
Transport, Petroleum
Geo:
Russia
IOCs:
Hash: 3
File: 10
Algorithms:
xor, rc4, crc
Functions:
GetPrcAddress, LdrLoadDll, bytearray, the, LdrGetProcedureAddress
Win API:
LoadLibraryA, VirtualAlloc, wglGetProcAddress, VirtualProtect
Languages:
python
Security Intelligence
Raspberry Robin and Dridex: Two Birds of a Feather
Explore in-depth analysis on the Raspberry Robin worm, tying it to Russia-based cybercriminal group 'Evil Corp' — the same group behind the Dridex Malware.
#ParsedReport
01-09-2022
Highly evasive Magecart JavaScript Skimmer active in the wild
https://blog.cyble.com/2022/09/01/highly-evasive-magecart-javascript-skimmer-active-in-the-wild
Actors/Campaigns:
Magecart
Threats:
Beacon
Industry:
E-commerce, Financial
Geo:
Dubai, Georgia, Singapore, Australia, India
TTPs:
Tactics: 6
Technics: 6
IOCs:
File: 1
Hash: 1
Languages:
javascript, php
01-09-2022
Highly evasive Magecart JavaScript Skimmer active in the wild
https://blog.cyble.com/2022/09/01/highly-evasive-magecart-javascript-skimmer-active-in-the-wild
Actors/Campaigns:
Magecart
Threats:
Beacon
Industry:
E-commerce, Financial
Geo:
Dubai, Georgia, Singapore, Australia, India
TTPs:
Tactics: 6
Technics: 6
IOCs:
File: 1
Hash: 1
Languages:
javascript, php
Cyble
Cyble - Highly Evasive Magecart JavaScript Skimmer Active In The Wild
Cyble Research and Intelligence Labs analyzes a highly-evasive Magecart Javascript skimmer that is active in the wild.
#ParsedReport
01-09-2022
Threat Actor "Robin Banks" Phishing Kit Revisions
https://www.wmcglobal.com/blog/robin-banks-phishing-kit-revisions
Threats:
Robin_banks_tool
IOCs:
Hash: 1
Languages:
php
Platforms:
intel
01-09-2022
Threat Actor "Robin Banks" Phishing Kit Revisions
https://www.wmcglobal.com/blog/robin-banks-phishing-kit-revisions
Threats:
Robin_banks_tool
IOCs:
Hash: 1
Languages:
php
Platforms:
intel
Wmcglobal
Threat Actor "Robin Banks" Phishing Kit Revisions
In July, a report was released spotlighting a threat actor known as Robin Banks. WMC Global was tracking this threat actor and noticed the scammer's...
#ParsedReport
30-08-2022
[ \] Appleseed v2.1. [Threat Analysis\] Appleseed V2.1 running on JavaScript
https://stic.secui.com/main/main/threatInfo?id=69
Threats:
Appleseed
IOCs:
File: 15
Algorithms:
zip, rc4, xor, base64
Win API:
Compress
Languages:
javascript, python
Platforms:
x86
30-08-2022
[ \] Appleseed v2.1. [Threat Analysis\] Appleseed V2.1 running on JavaScript
https://stic.secui.com/main/main/threatInfo?id=69
Threats:
Appleseed
IOCs:
File: 15
Algorithms:
zip, rc4, xor, base64
Win API:
Compress
Languages:
javascript, python
Platforms:
x86
#ParsedReport
01-09-2022
PyPI Phishing Campaign \| JuiceLedger Threat Actor Pivots From Fake Apps to Supply Chain Attacks
https://www.sentinelone.com/labs/pypi-phishing-campaign-juiceledger-threat-actor-pivots-from-fake-apps-to-supply-chain-attacks
Actors/Campaigns:
Juiceledger
Threats:
Juicestealer
Typosquatting_technique
Agent_tesla
Cratedepression
IOCs:
Domain: 14
Hash: 45
File: 11
Path: 1
Url: 1
IP: 1
Email: 1
Softs:
chrome, discord
Algorithms:
zip
Languages:
python, rust
01-09-2022
PyPI Phishing Campaign \| JuiceLedger Threat Actor Pivots From Fake Apps to Supply Chain Attacks
https://www.sentinelone.com/labs/pypi-phishing-campaign-juiceledger-threat-actor-pivots-from-fake-apps-to-supply-chain-attacks
Actors/Campaigns:
Juiceledger
Threats:
Juicestealer
Typosquatting_technique
Agent_tesla
Cratedepression
IOCs:
Domain: 14
Hash: 45
File: 11
Path: 1
Url: 1
IP: 1
Email: 1
Softs:
chrome, discord
Algorithms:
zip
Languages:
python, rust
SentinelOne
PyPI Phishing Campaign | JuiceLedger Threat Actor Pivots From Fake Apps to Supply Chain Attacks
A new threat actor is spreading infostealer malware through targeted attacks on developers and fraudulent cryptotrading applications.
#ParsedReport
01-09-2022
No Honor Among Thieves - Prynt Stealers Backdoor Exposed. Key Points
https://www.zscaler.com/blogs/security-research/no-honor-among-thieves-prynt-stealers-backdoor-exposed
Threats:
Prynt_stealer
Asyncrat_rat
Stormkitty_stealer
Loda_rat
Njrat_rat
Quasar_rat
Cobian_rat
Binder
Netstat_tool
Industry:
Entertainment, Financial
IOCs:
IP: 1
Url: 4
Domain: 6
File: 9
Hash: 10
Path: 1
Softs:
telegram
Win API:
RtlSetProcessIsCritical, SetThreadExecutionState
Languages:
autoit
Links:
01-09-2022
No Honor Among Thieves - Prynt Stealers Backdoor Exposed. Key Points
https://www.zscaler.com/blogs/security-research/no-honor-among-thieves-prynt-stealers-backdoor-exposed
Threats:
Prynt_stealer
Asyncrat_rat
Stormkitty_stealer
Loda_rat
Njrat_rat
Quasar_rat
Cobian_rat
Binder
Netstat_tool
Industry:
Entertainment, Financial
IOCs:
IP: 1
Url: 4
Domain: 6
File: 9
Hash: 10
Path: 1
Softs:
telegram
Win API:
RtlSetProcessIsCritical, SetThreadExecutionState
Languages:
autoit
Links:
https://github.com/threatlabz/iocs/tree/main/pryntstealerhttps://github.com/NYAN-x-CAT/AsyncRAT-C-Sharphttps://github.com/NYAN-x-CAT/AsyncRAT-C-Sharp/blob/master/AsyncRAT-C%23/Client/Settings.cshttps://github.com/swagkarna/StormKitty/Zscaler
Prynt Stealer’s Backdoor Exposed | Zscaler Blog
Prynt Stealer shares codebase with AsyncRAT and StormKitty. DarkEye and WorldWind are virtually identical to Prynt Stealer.
#ParsedReport
02-09-2022
Buzzing in the Background: BumbleBee, a New Modular Backdoor Evolved From BookWorm. Introduction
https://www.trendmicro.com/en_us/research/22/i/buzzing-in-the-background-bumblebee-a-new-modular-backdoor-evolv.html
Threats:
Bumblebee
Bookworm
Beacon
Trojan.win32.multicom.ztic
Trojan.win32.regload.zti
Backdoor.win32.bumbleb.ztic
Dll_sideloading_technique
Process_injection_technique
Industry:
Government
Geo:
Asia, Taiwan, Chinese, China, Asian
TTPs:
Tactics: 7
Technics: 15
IOCs:
File: 11
Path: 2
Registry: 2
Hash: 9
Url: 2
Softs:
windows service
Algorithms:
crc, rc4, xor
02-09-2022
Buzzing in the Background: BumbleBee, a New Modular Backdoor Evolved From BookWorm. Introduction
https://www.trendmicro.com/en_us/research/22/i/buzzing-in-the-background-bumblebee-a-new-modular-backdoor-evolv.html
Threats:
Bumblebee
Bookworm
Beacon
Trojan.win32.multicom.ztic
Trojan.win32.regload.zti
Backdoor.win32.bumbleb.ztic
Dll_sideloading_technique
Process_injection_technique
Industry:
Government
Geo:
Asia, Taiwan, Chinese, China, Asian
TTPs:
Tactics: 7
Technics: 15
IOCs:
File: 11
Path: 2
Registry: 2
Hash: 9
Url: 2
Softs:
windows service
Algorithms:
crc, rc4, xor
Trend Micro
BumbleBee a New Modular Backdoor Evolved From BookWorm
In March 2021, we investigated a backdoor with a unique modular architecture and called it BumbleBee due to a string embedded in the malware. However, in our recent investigations, we have discovered a controller application that expands its capabilities.
#ParsedReport
02-09-2022
Zanubis: New Android Banking Trojan spotted in the wild
https://blog.cyble.com/2022/09/02/zanubis-new-android-banking-trojan
Threats:
Zanubis
Hydra
Ermac
Bratarat
Industry:
Financial
Geo:
Dubai, Georgia, India, Peruvian, Australia, Peru, Singapore
TTPs:
Tactics: 3
Technics: 9
IOCs:
File: 18
Url: 1
Hash: 3
Softs:
android
Functions:
onAccessibilityEvent
02-09-2022
Zanubis: New Android Banking Trojan spotted in the wild
https://blog.cyble.com/2022/09/02/zanubis-new-android-banking-trojan
Threats:
Zanubis
Hydra
Ermac
Bratarat
Industry:
Financial
Geo:
Dubai, Georgia, India, Peruvian, Australia, Peru, Singapore
TTPs:
Tactics: 3
Technics: 9
IOCs:
File: 18
Url: 1
Hash: 3
Softs:
android
Functions:
onAccessibilityEvent
#ParsedReport
03-09-2022
No Honor Among Thieves - Prynt Stealers Backdoor Exposed. Key Points
https://www.zscaler.com/blogs/security-research/no-honor-among-thieves-prynt-stealers-backdoor-exposed
Threats:
Asyncrat_rat
Stormkitty_stealer
Loda_rat
Njrat_rat
Quasar_rat
Cobian_rat
Binder
Netstat_tool
Industry:
Financial, Entertainment
IOCs:
IP: 1
Url: 4
Domain: 6
File: 9
Hash: 10
Path: 1
Softs:
telegram
Win API:
RtlSetProcessIsCritical, SetThreadExecutionState
Languages:
autoit
Links:
03-09-2022
No Honor Among Thieves - Prynt Stealers Backdoor Exposed. Key Points
https://www.zscaler.com/blogs/security-research/no-honor-among-thieves-prynt-stealers-backdoor-exposed
Threats:
Asyncrat_rat
Stormkitty_stealer
Loda_rat
Njrat_rat
Quasar_rat
Cobian_rat
Binder
Netstat_tool
Industry:
Financial, Entertainment
IOCs:
IP: 1
Url: 4
Domain: 6
File: 9
Hash: 10
Path: 1
Softs:
telegram
Win API:
RtlSetProcessIsCritical, SetThreadExecutionState
Languages:
autoit
Links:
https://github.com/threatlabz/iocs/tree/main/pryntstealerhttps://github.com/NYAN-x-CAT/AsyncRAT-C-Sharp/blob/master/AsyncRAT-C%23/Client/Settings.cshttps://github.com/NYAN-x-CAT/AsyncRAT-C-Sharphttps://github.com/swagkarna/StormKitty/Zscaler
Prynt Stealer’s Backdoor Exposed | Zscaler Blog
Prynt Stealer shares codebase with AsyncRAT and StormKitty. DarkEye and WorldWind are virtually identical to Prynt Stealer.
#ParsedReport
03-09-2022
SafeBreach Labs Researchers Uncover New Remote Access Trojan (RAT). CodeRAT Overview
https://www.safebreach.com/resources/blog/remote-access-trojan-coderat
Threats:
Coderat
Robothief
Antidebugging_technique
Industry:
Media, Government, E-commerce
Geo:
Iranian, Tehran, Irans, Iran
IOCs:
File: 9
Hash: 5
Softs:
microsoft powerpoint, microsoft word, windows media player, android, egram grou, microsoft office, visual studio, ram.org/bo, instagram, telegram
Functions:
BossWatch, CheckBoss
Win API:
CryptUnprotectData
Languages:
python
Platforms:
x86
YARA: Found
Links:
03-09-2022
SafeBreach Labs Researchers Uncover New Remote Access Trojan (RAT). CodeRAT Overview
https://www.safebreach.com/resources/blog/remote-access-trojan-coderat
Threats:
Coderat
Robothief
Antidebugging_technique
Industry:
Media, Government, E-commerce
Geo:
Iranian, Tehran, Irans, Iran
IOCs:
File: 9
Hash: 5
Softs:
microsoft powerpoint, microsoft word, windows media player, android, egram grou, microsoft office, visual studio, ram.org/bo, instagram, telegram
Functions:
BossWatch, CheckBoss
Win API:
CryptUnprotectData
Languages:
python
Platforms:
x86
YARA: Found
Links:
https://github.com/MrModed/DWMSafeBreach
SafeBreach Uncovers New Remote Access Trojan (RAT)
Dubbed CodeRAT, the new RAT is used in attacks targeting Farsi-speaking code developers using a Microsoft Dynamic Data Exchange (DDE) exploit.
#ParsedReport
03-09-2022
Crypto miners latest techniques
https://cybersecurity.att.com/blogs/labs-research/crypto-miners-latest-techniques
Threats:
Alien
Industry:
Iot
Geo:
Mexican
TTPs:
Tactics: 8
Technics: 22
IOCs:
Registry: 3
Path: 10
Domain: 3
File: 5
Hash: 7
Softs:
windows service, microsoft excel, windows defender
Win API:
CmRccService, CmRcService
03-09-2022
Crypto miners latest techniques
https://cybersecurity.att.com/blogs/labs-research/crypto-miners-latest-techniques
Threats:
Alien
Industry:
Iot
Geo:
Mexican
TTPs:
Tactics: 8
Technics: 22
IOCs:
Registry: 3
Path: 10
Domain: 3
File: 5
Hash: 7
Softs:
windows service, microsoft excel, windows defender
Win API:
CmRccService, CmRcService
LevelBlue
Crypto miners’ latest techniques
An exploration of the newest methods used by crypto miners to exploit systems, enhancing threat awareness.
#ParsedReport
03-09-2022
Another Ransomware For Linux Likely In Development
https://www.uptycs.com/blog/another-ransomware-for-linux-likely-in-development
Threats:
Babuk
IOCs:
Hash: 1
Url: 1
Functions:
pthread_create, fcntl
YARA: Found
03-09-2022
Another Ransomware For Linux Likely In Development
https://www.uptycs.com/blog/another-ransomware-for-linux-likely-in-development
Threats:
Babuk
IOCs:
Hash: 1
Url: 1
Functions:
pthread_create, fcntl
YARA: Found
Uptycs
Another Ransomware for Linux Likely in Development
New discovery by the Uptycs Threat Research Team of Executable and Linkable Format (ELF) ransomware by ransomware group DarkAngels.
#ParsedReport
02-09-2022
Cloudflare Pages Misused in a Phishing Campaign Against Indian Banking Customers
https://cloudsek.com/threatintelligence/cloudflare-pages-misused-in-a-phishing-campaign-against-indian-banking-customers/?utm_source=rss&utm_medium=rss&utm_campaign=cloudflare-pages-misused-in-a-phishing-campaign-against-indian-banking-customers
Industry:
Financial
Geo:
Indian, India
02-09-2022
Cloudflare Pages Misused in a Phishing Campaign Against Indian Banking Customers
https://cloudsek.com/threatintelligence/cloudflare-pages-misused-in-a-phishing-campaign-against-indian-banking-customers/?utm_source=rss&utm_medium=rss&utm_campaign=cloudflare-pages-misused-in-a-phishing-campaign-against-indian-banking-customers
Industry:
Financial
Geo:
Indian, India
Cloudsek
Cloudflare Pages Misused in a Phishing Campaign Against Indian Banking Customers | Threat Intelligence | CloudSEK
CloudSEK’s uncovered yet another improvised modus operandi used by threat actors to target banking customers in India through a phishing campaign.
#ParsedReport
03-09-2022
Sharkbot is back in Google Play
https://blog.fox-it.com/2022/09/02/sharkbot-is-back-in-google-play
Actors/Campaigns:
Fakeupdates
Threats:
Sharkbot
Industry:
Financial
Geo:
Poland, Spain, America, Austria, Australia, Italy, Germany
IOCs:
Url: 4
Hash: 2
IP: 1
Domain: 2
Softs:
android
Algorithms:
base64, rc4
03-09-2022
Sharkbot is back in Google Play
https://blog.fox-it.com/2022/09/02/sharkbot-is-back-in-google-play
Actors/Campaigns:
Fakeupdates
Threats:
Sharkbot
Industry:
Financial
Geo:
Poland, Spain, America, Austria, Australia, Italy, Germany
IOCs:
Url: 4
Hash: 2
IP: 1
Domain: 2
Softs:
android
Algorithms:
base64, rc4
Fox-IT International blog
Sharkbot is back in Google Play
Authored by Alberto Segura (main author) and Mike Stokkel (co-author) Introduction After we discovered in February 2022 the SharkBotDropper in Google Play posing as a fake Android antivirus and cle…
#ParsedReport
03-09-2022
TTPs #8 : Operation GWISIN -. TTPS #8: Operation gwisin -custom ransomware attack strategy analysis
https://thorcert.notion.site/TTPs-8-Operation-GWISIN-c3483353d20241b3a313fa4a8726302a
Threats:
Gwisin
Process_injection_technique
Nmap_tool
Winrm_tool
Dumplsass_tool
Netstat_tool
Mimikatz
Geo:
Korea, Korean
TTPs:
Tactics: 11
Technics: 29
IOCs:
File: 16
Path: 1
Registry: 1
IP: 1
Softs:
curl, bcdedit
Algorithms:
aes, base64, rc4, rsa-aes
Languages:
php, visual_basic
03-09-2022
TTPs #8 : Operation GWISIN -. TTPS #8: Operation gwisin -custom ransomware attack strategy analysis
https://thorcert.notion.site/TTPs-8-Operation-GWISIN-c3483353d20241b3a313fa4a8726302a
Threats:
Gwisin
Process_injection_technique
Nmap_tool
Winrm_tool
Dumplsass_tool
Netstat_tool
Mimikatz
Geo:
Korea, Korean
TTPs:
Tactics: 11
Technics: 29
IOCs:
File: 16
Path: 1
Registry: 1
IP: 1
Softs:
curl, bcdedit
Algorithms:
aes, base64, rc4, rsa-aes
Languages:
php, visual_basic
Notion
Notion | Where teams and agents work together
A collaborative AI workspace, built on your company context. Build and orchestrate agents right alongside your team's projects, meetings, and connected apps.
#ParsedReport
03-09-2022
PLAY Ransomware
https://chuongdong.com/reverse%20engineering/2022/09/03/PLAYRansomware
Threats:
Playcrypt
Cobalt_strike
Systembc
Adfind_tool
Dll_injection_technique
Rook
IOCs:
Hash: 2
Softs:
winscp
Algorithms:
aes-cbc, aes, xor, rsa-aes, cbc, aes-gcm
Functions:
traversal, ReadMe, PLAY
Win API:
VirtualAlloc, GetDiskFreeSpaceExW, FindNextVolumeW, BCryptEncrypt, CreateThread, BCryptGenRandom, BCryptOpenAlgorithmProvider, FindFirstVolumeW, FindFirstFileW, MoveFileW, WinMain, BCryptSetProperty, GetDriveTypeW, ReadFile, SetVolumeMountPointW, SetFilePointerEx, WNetGetUniversalNameW, FindNextFileW, Sleep, BCryptExportKey, BCryptImportKeyPair, WriteFile, BCryptGenerateSymmetricKey, GetVolumePathNamesForVolumeNameW
Links:
03-09-2022
PLAY Ransomware
https://chuongdong.com/reverse%20engineering/2022/09/03/PLAYRansomware
Threats:
Playcrypt
Cobalt_strike
Systembc
Adfind_tool
Dll_injection_technique
Rook
IOCs:
Hash: 2
Softs:
winscp
Algorithms:
aes-cbc, aes, xor, rsa-aes, cbc, aes-gcm
Functions:
traversal, ReadMe, PLAY
Win API:
VirtualAlloc, GetDiskFreeSpaceExW, FindNextVolumeW, BCryptEncrypt, CreateThread, BCryptGenRandom, BCryptOpenAlgorithmProvider, FindFirstVolumeW, FindFirstFileW, MoveFileW, WinMain, BCryptSetProperty, GetDriveTypeW, ReadFile, SetVolumeMountPointW, SetFilePointerEx, WNetGetUniversalNameW, FindNextFileW, Sleep, BCryptExportKey, BCryptImportKeyPair, WriteFile, BCryptGenerateSymmetricKey, GetVolumePathNamesForVolumeNameW
Links:
https://github.com/cdong1012/IDAPython-Malware-Scripts/blob/master/PLAY/script.pyhttps://github.com/cdong1012/IDAPython-Malware-Scripts/blob/master/PLAY/API\_resolve.pyChuong Dong
PLAY Ransomware
Malware Analysis Report - PLAY Ransomware
#ParsedReport
04-09-2022
EvilProxy Phishing-as-a-Service with MFA Bypass Emerged in Dark Web
https://resecurity.com/blog/article/evilproxy-phishing-as-a-service-with-mfa-bypass-emerged-in-dark-web
Actors/Campaigns:
Bec
Threats:
Evilproxy
Moloch
Industry:
Financial, E-commerce
IOCs:
Domain: 4
Softs:
telegram, docker, instagram
Platforms:
apple
04-09-2022
EvilProxy Phishing-as-a-Service with MFA Bypass Emerged in Dark Web
https://resecurity.com/blog/article/evilproxy-phishing-as-a-service-with-mfa-bypass-emerged-in-dark-web
Actors/Campaigns:
Bec
Threats:
Evilproxy
Moloch
Industry:
Financial, E-commerce
IOCs:
Domain: 4
Softs:
telegram, docker, instagram
Platforms:
apple
#ParsedReport
04-09-2022
. LilithJester
https://www.antiy.cn/research/notice&report/research_report/20220902.html
Threats:
Lilith_jester
Lilith_rat
Jester_stealer
Trojan/win32.botnet
TTPs:
Tactics: 4
Technics: 0
IOCs:
File: 5
Hash: 1
IP: 1
Algorithms:
zip, base64, aes
Platforms:
x64
04-09-2022
. LilithJester
https://www.antiy.cn/research/notice&report/research_report/20220902.html
Threats:
Lilith_jester
Lilith_rat
Jester_stealer
Trojan/win32.botnet
TTPs:
Tactics: 4
Technics: 0
IOCs:
File: 5
Hash: 1
IP: 1
Algorithms:
zip, base64, aes
Platforms:
x64
www.antiy.cn
Lilith僵尸网络及其背后的Jester黑客团伙跟进分析
安天CERT捕获到了Jester黑客团伙开发售卖的Lilith僵尸网络。该僵尸网络除了具备该团伙开发售卖的窃密木马、剪贴板劫持器、挖矿木马等恶意代码的功能外,还增加了持久化及远控功能,对用户造成机密数据泄露、虚拟财产损失、系统资源耗尽等威胁,安天智甲终端防御系统(简称IEP)可实现对该僵尸网络程序的有效查杀,安天探海威胁检测系统(简称PTD)能够实现对该僵尸网络C2通信的精准检测。