CTT Report Hub
3.42K subscribers
9.87K photos
6 videos
67 files
13.5K links
Threat Intelligence Report Hub
Download Telegram
#ParsedReport
30-08-2022

[ \] Appleseed v2.1. [Threat Analysis\] Appleseed V2.1 running on JavaScript

https://stic.secui.com/main/main/threatInfo?id=69

Threats:
Appleseed

IOCs:
File: 15

Algorithms:
zip, rc4, xor, base64

Win API:
Compress

Languages:
javascript, python

Platforms:
x86
#ParsedReport
01-09-2022

PyPI Phishing Campaign \| JuiceLedger Threat Actor Pivots From Fake Apps to Supply Chain Attacks

https://www.sentinelone.com/labs/pypi-phishing-campaign-juiceledger-threat-actor-pivots-from-fake-apps-to-supply-chain-attacks

Actors/Campaigns:
Juiceledger

Threats:
Juicestealer
Typosquatting_technique
Agent_tesla
Cratedepression

IOCs:
Domain: 14
Hash: 45
File: 11
Path: 1
Url: 1
IP: 1
Email: 1

Softs:
chrome, discord

Algorithms:
zip

Languages:
python, rust
#ParsedReport
01-09-2022

No Honor Among Thieves - Prynt Stealers Backdoor Exposed. Key Points

https://www.zscaler.com/blogs/security-research/no-honor-among-thieves-prynt-stealers-backdoor-exposed

Threats:
Prynt_stealer
Asyncrat_rat
Stormkitty_stealer
Loda_rat
Njrat_rat
Quasar_rat
Cobian_rat
Binder
Netstat_tool

Industry:
Entertainment, Financial

IOCs:
IP: 1
Url: 4
Domain: 6
File: 9
Hash: 10
Path: 1

Softs:
telegram

Win API:
RtlSetProcessIsCritical, SetThreadExecutionState

Languages:
autoit

Links:
https://github.com/threatlabz/iocs/tree/main/pryntstealer
https://github.com/NYAN-x-CAT/AsyncRAT-C-Sharp
https://github.com/NYAN-x-CAT/AsyncRAT-C-Sharp/blob/master/AsyncRAT-C%23/Client/Settings.cs
https://github.com/swagkarna/StormKitty/
#ParsedReport
02-09-2022

Buzzing in the Background: BumbleBee, a New Modular Backdoor Evolved From BookWorm. Introduction

https://www.trendmicro.com/en_us/research/22/i/buzzing-in-the-background-bumblebee-a-new-modular-backdoor-evolv.html

Threats:
Bumblebee
Bookworm
Beacon
Trojan.win32.multicom.ztic
Trojan.win32.regload.zti
Backdoor.win32.bumbleb.ztic
Dll_sideloading_technique
Process_injection_technique

Industry:
Government

Geo:
Asia, Taiwan, Chinese, China, Asian

TTPs:
Tactics: 7
Technics: 15

IOCs:
File: 11
Path: 2
Registry: 2
Hash: 9
Url: 2

Softs:
windows service

Algorithms:
crc, rc4, xor
#ParsedReport
02-09-2022

Zanubis: New Android Banking Trojan spotted in the wild

https://blog.cyble.com/2022/09/02/zanubis-new-android-banking-trojan

Threats:
Zanubis
Hydra
Ermac
Bratarat

Industry:
Financial

Geo:
Dubai, Georgia, India, Peruvian, Australia, Peru, Singapore

TTPs:
Tactics: 3
Technics: 9

IOCs:
File: 18
Url: 1
Hash: 3

Softs:
android

Functions:
onAccessibilityEvent
#ParsedReport
03-09-2022

No Honor Among Thieves - Prynt Stealers Backdoor Exposed. Key Points

https://www.zscaler.com/blogs/security-research/no-honor-among-thieves-prynt-stealers-backdoor-exposed

Threats:
Asyncrat_rat
Stormkitty_stealer
Loda_rat
Njrat_rat
Quasar_rat
Cobian_rat
Binder
Netstat_tool

Industry:
Financial, Entertainment

IOCs:
IP: 1
Url: 4
Domain: 6
File: 9
Hash: 10
Path: 1

Softs:
telegram

Win API:
RtlSetProcessIsCritical, SetThreadExecutionState

Languages:
autoit

Links:
https://github.com/threatlabz/iocs/tree/main/pryntstealer
https://github.com/NYAN-x-CAT/AsyncRAT-C-Sharp/blob/master/AsyncRAT-C%23/Client/Settings.cs
https://github.com/NYAN-x-CAT/AsyncRAT-C-Sharp
https://github.com/swagkarna/StormKitty/
#ParsedReport
03-09-2022

SafeBreach Labs Researchers Uncover New Remote Access Trojan (RAT). CodeRAT Overview

https://www.safebreach.com/resources/blog/remote-access-trojan-coderat

Threats:
Coderat
Robothief
Antidebugging_technique

Industry:
Media, Government, E-commerce

Geo:
Iranian, Tehran, Irans, Iran

IOCs:
File: 9
Hash: 5

Softs:
microsoft powerpoint, microsoft word, windows media player, android, egram grou, microsoft office, visual studio, ram.org/bo, instagram, telegram

Functions:
BossWatch, CheckBoss

Win API:
CryptUnprotectData

Languages:
python

Platforms:
x86

YARA: Found

Links:
https://github.com/MrModed/DWM
#ParsedReport
03-09-2022

Crypto miners latest techniques

https://cybersecurity.att.com/blogs/labs-research/crypto-miners-latest-techniques

Threats:
Alien

Industry:
Iot

Geo:
Mexican

TTPs:
Tactics: 8
Technics: 22

IOCs:
Registry: 3
Path: 10
Domain: 3
File: 5
Hash: 7

Softs:
windows service, microsoft excel, windows defender

Win API:
CmRccService, CmRcService
#ParsedReport
03-09-2022

Sharkbot is back in Google Play

https://blog.fox-it.com/2022/09/02/sharkbot-is-back-in-google-play

Actors/Campaigns:
Fakeupdates

Threats:
Sharkbot

Industry:
Financial

Geo:
Poland, Spain, America, Austria, Australia, Italy, Germany

IOCs:
Url: 4
Hash: 2
IP: 1
Domain: 2

Softs:
android

Algorithms:
base64, rc4
#ParsedReport
03-09-2022

TTPs #8 : Operation GWISIN -. TTPS #8: Operation gwisin -custom ransomware attack strategy analysis

https://thorcert.notion.site/TTPs-8-Operation-GWISIN-c3483353d20241b3a313fa4a8726302a

Threats:
Gwisin
Process_injection_technique
Nmap_tool
Winrm_tool
Dumplsass_tool
Netstat_tool
Mimikatz

Geo:
Korea, Korean

TTPs:
Tactics: 11
Technics: 29

IOCs:
File: 16
Path: 1
Registry: 1
IP: 1

Softs:
curl, bcdedit

Algorithms:
aes, base64, rc4, rsa-aes

Languages:
php, visual_basic
#ParsedReport
03-09-2022

PLAY Ransomware

https://chuongdong.com/reverse%20engineering/2022/09/03/PLAYRansomware

Threats:
Playcrypt
Cobalt_strike
Systembc
Adfind_tool
Dll_injection_technique
Rook

IOCs:
Hash: 2

Softs:
winscp

Algorithms:
aes-cbc, aes, xor, rsa-aes, cbc, aes-gcm

Functions:
traversal, ReadMe, PLAY

Win API:
VirtualAlloc, GetDiskFreeSpaceExW, FindNextVolumeW, BCryptEncrypt, CreateThread, BCryptGenRandom, BCryptOpenAlgorithmProvider, FindFirstVolumeW, FindFirstFileW, MoveFileW, WinMain, BCryptSetProperty, GetDriveTypeW, ReadFile, SetVolumeMountPointW, SetFilePointerEx, WNetGetUniversalNameW, FindNextFileW, Sleep, BCryptExportKey, BCryptImportKeyPair, WriteFile, BCryptGenerateSymmetricKey, GetVolumePathNamesForVolumeNameW

Links:
https://github.com/cdong1012/IDAPython-Malware-Scripts/blob/master/PLAY/script.py
https://github.com/cdong1012/IDAPython-Malware-Scripts/blob/master/PLAY/API\_resolve.py
#ParsedReport
04-09-2022

EvilProxy Phishing-as-a-Service with MFA Bypass Emerged in Dark Web

https://resecurity.com/blog/article/evilproxy-phishing-as-a-service-with-mfa-bypass-emerged-in-dark-web

Actors/Campaigns:
Bec

Threats:
Evilproxy
Moloch

Industry:
Financial, E-commerce

IOCs:
Domain: 4

Softs:
telegram, docker, instagram

Platforms:
apple
#ParsedReport
05-09-2022

HWP File Disguised as Personal Profile Form (OLE Object)

https://asec.ahnlab.com/en/38479

Threats:
Process_hollowing_technique
Trojan/win.agent.c5228370

Industry:
Financial

CVEs:
CVE-2018-15982 [Vulners]
Vulners: Score: 10.0, CVSS: 5.9,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- adobe flash player (le31.0.0.153, le31.0.0.153, le31.0.0.153, le31.0.0.153)
- redhat enterprise linux desktop (6.0)
- redhat enterprise linux workstation (6.0)
- redhat enterprise linux server (6.0)
- adobe flash player installer (le31.0.0.108)
have more...

IOCs:
File: 10
Url: 4
Path: 1
Hash: 7
#technique

EvilnoVNC is a Ready to go Phishing Platform.

Unlike other phishing techniques, EvilnoVNC allows 2FA bypassing by using a real browser over a noVNC connection.

In addition, this tool allows us to see in real time all of the victim's actions, access to their downloaded files and the entire browser profile, including cookies, saved passwords, browsing history and much more.
https://github.com/JoelGMSec/EvilnoVNC
#technique

Elevator allows to bypass the UAC and spawn an elevated process with full administrator privileges. This is done by abusing the behaviour of the RPC server that implements the UAC feature, as demonstrated by James Forshaw in his article Calling Local Windows RPC Servers from .NET. The tool does not require to drop an extra DLL or write to the Windows Registry (as is often the case with other UAC bypass techniques), and it has been successfully tested on Windows Server 2016, Windows Server 2019 and Windows 10 (it probably works on other versions of Windows).

https://github.com/Kudaes/Elevator
#ParsedReport
06-09-2022

Pro-Russian Group Targeting Ukraine Supporters with DDoS Attacks

https://decoded.avast.io/martinchlumecky/bobik/?utm_source=rss&utm_medium=rss&utm_campaign=bobik

Actors/Campaigns:
Noname057
It_army
Killnet

Threats:
Bobiks
Redline_stealer

Industry:
Education, Logistic, Government, Transport, Aerospace, Financial, Telco, Petroleum, Energy

Geo:
Russian, Romania, Italy, Asia, Estonia, American, Polish, Americas, Poland, Romanian, Russia, Lithuania, Norway, Finland, Latvia, Brazil, Ukraines, Ukraine, India, Ukrainian

IOCs:
File: 9
IP: 4

Softs:
nginx, ubuntu, telegram

Languages:
python

Links:
https://github.com/avast/ioc/blob/master/Bobik/targets.xlsx
https://github.com/avast/ioc/tree/master/Bobik/decryptor.py
https://github.com/avast/ioc/tree/master/Bobik
#ParsedReport
06-09-2022

DangerousSavanna: Two-year long campaign targets financial institutions in French-speaking Africa

https://research.checkpoint.com/2022/dangeroussavanna-two-year-long-campaign-targets-financial-institutions-in-french-speaking-africa

Threats:
Dangeroussavanna
Metasploit_tool
Poshc2
Dwservice_tool
Asyncrat_rat
Amsi_bypass_technique
Junk_code_technique
Meterpreter_tool
Backstab_tool

Industry:
Financial

Geo:
Cameroon, Morocco, French, Africa, African, Senegal, Togo

TTPs:
Tactics: 2
Technics: 0

IOCs:
File: 15
Url: 1
Path: 6
Hash: 57
Domain: 7
IP: 9

Softs:
windows subsystem for linux, process explorer

Algorithms:
aes, zip

Win API:
AmsiScanBuffer, EtwEventWrite, SetWindowsHookExW

Platforms:
intel

Links:
https://github.com/nettitude/PoshC2
https://github.com/rapid7/metasploit-framework
https://github.com/MalwareCantFly/Vba2Graph
https://github.com/Yaxser/Backstab
https://github.com/nettitude/PoshC2\_Shellcode
https://github.com/Porchetta-Industries/CrackMapExec
https://github.com/nettitude/PoshC2/blob/master/resources/modules/Stage2-Core.ps1
https://github.com/NYAN-x-CAT/AsyncRAT-C-Sharp
https://github.com/ZephrFish/PoshC2\_Python/blob/master/Modules/Inject-Shellcode.ps1
https://github.com/dwservice