#ParsedReport
02-09-2022
Buzzing in the Background: BumbleBee, a New Modular Backdoor Evolved From BookWorm. Introduction
https://www.trendmicro.com/en_us/research/22/i/buzzing-in-the-background-bumblebee-a-new-modular-backdoor-evolv.html
Threats:
Bumblebee
Bookworm
Beacon
Trojan.win32.multicom.ztic
Trojan.win32.regload.zti
Backdoor.win32.bumbleb.ztic
Dll_sideloading_technique
Process_injection_technique
Industry:
Government
Geo:
Asia, Taiwan, Chinese, China, Asian
TTPs:
Tactics: 7
Technics: 15
IOCs:
File: 11
Path: 2
Registry: 2
Hash: 9
Url: 2
Softs:
windows service
Algorithms:
crc, rc4, xor
02-09-2022
Buzzing in the Background: BumbleBee, a New Modular Backdoor Evolved From BookWorm. Introduction
https://www.trendmicro.com/en_us/research/22/i/buzzing-in-the-background-bumblebee-a-new-modular-backdoor-evolv.html
Threats:
Bumblebee
Bookworm
Beacon
Trojan.win32.multicom.ztic
Trojan.win32.regload.zti
Backdoor.win32.bumbleb.ztic
Dll_sideloading_technique
Process_injection_technique
Industry:
Government
Geo:
Asia, Taiwan, Chinese, China, Asian
TTPs:
Tactics: 7
Technics: 15
IOCs:
File: 11
Path: 2
Registry: 2
Hash: 9
Url: 2
Softs:
windows service
Algorithms:
crc, rc4, xor
Trend Micro
BumbleBee a New Modular Backdoor Evolved From BookWorm
In March 2021, we investigated a backdoor with a unique modular architecture and called it BumbleBee due to a string embedded in the malware. However, in our recent investigations, we have discovered a controller application that expands its capabilities.
#ParsedReport
02-09-2022
Zanubis: New Android Banking Trojan spotted in the wild
https://blog.cyble.com/2022/09/02/zanubis-new-android-banking-trojan
Threats:
Zanubis
Hydra
Ermac
Bratarat
Industry:
Financial
Geo:
Dubai, Georgia, India, Peruvian, Australia, Peru, Singapore
TTPs:
Tactics: 3
Technics: 9
IOCs:
File: 18
Url: 1
Hash: 3
Softs:
android
Functions:
onAccessibilityEvent
02-09-2022
Zanubis: New Android Banking Trojan spotted in the wild
https://blog.cyble.com/2022/09/02/zanubis-new-android-banking-trojan
Threats:
Zanubis
Hydra
Ermac
Bratarat
Industry:
Financial
Geo:
Dubai, Georgia, India, Peruvian, Australia, Peru, Singapore
TTPs:
Tactics: 3
Technics: 9
IOCs:
File: 18
Url: 1
Hash: 3
Softs:
android
Functions:
onAccessibilityEvent
#ParsedReport
03-09-2022
No Honor Among Thieves - Prynt Stealers Backdoor Exposed. Key Points
https://www.zscaler.com/blogs/security-research/no-honor-among-thieves-prynt-stealers-backdoor-exposed
Threats:
Asyncrat_rat
Stormkitty_stealer
Loda_rat
Njrat_rat
Quasar_rat
Cobian_rat
Binder
Netstat_tool
Industry:
Financial, Entertainment
IOCs:
IP: 1
Url: 4
Domain: 6
File: 9
Hash: 10
Path: 1
Softs:
telegram
Win API:
RtlSetProcessIsCritical, SetThreadExecutionState
Languages:
autoit
Links:
03-09-2022
No Honor Among Thieves - Prynt Stealers Backdoor Exposed. Key Points
https://www.zscaler.com/blogs/security-research/no-honor-among-thieves-prynt-stealers-backdoor-exposed
Threats:
Asyncrat_rat
Stormkitty_stealer
Loda_rat
Njrat_rat
Quasar_rat
Cobian_rat
Binder
Netstat_tool
Industry:
Financial, Entertainment
IOCs:
IP: 1
Url: 4
Domain: 6
File: 9
Hash: 10
Path: 1
Softs:
telegram
Win API:
RtlSetProcessIsCritical, SetThreadExecutionState
Languages:
autoit
Links:
https://github.com/threatlabz/iocs/tree/main/pryntstealerhttps://github.com/NYAN-x-CAT/AsyncRAT-C-Sharp/blob/master/AsyncRAT-C%23/Client/Settings.cshttps://github.com/NYAN-x-CAT/AsyncRAT-C-Sharphttps://github.com/swagkarna/StormKitty/Zscaler
Prynt Stealer’s Backdoor Exposed | Zscaler Blog
Prynt Stealer shares codebase with AsyncRAT and StormKitty. DarkEye and WorldWind are virtually identical to Prynt Stealer.
#ParsedReport
03-09-2022
SafeBreach Labs Researchers Uncover New Remote Access Trojan (RAT). CodeRAT Overview
https://www.safebreach.com/resources/blog/remote-access-trojan-coderat
Threats:
Coderat
Robothief
Antidebugging_technique
Industry:
Media, Government, E-commerce
Geo:
Iranian, Tehran, Irans, Iran
IOCs:
File: 9
Hash: 5
Softs:
microsoft powerpoint, microsoft word, windows media player, android, egram grou, microsoft office, visual studio, ram.org/bo, instagram, telegram
Functions:
BossWatch, CheckBoss
Win API:
CryptUnprotectData
Languages:
python
Platforms:
x86
YARA: Found
Links:
03-09-2022
SafeBreach Labs Researchers Uncover New Remote Access Trojan (RAT). CodeRAT Overview
https://www.safebreach.com/resources/blog/remote-access-trojan-coderat
Threats:
Coderat
Robothief
Antidebugging_technique
Industry:
Media, Government, E-commerce
Geo:
Iranian, Tehran, Irans, Iran
IOCs:
File: 9
Hash: 5
Softs:
microsoft powerpoint, microsoft word, windows media player, android, egram grou, microsoft office, visual studio, ram.org/bo, instagram, telegram
Functions:
BossWatch, CheckBoss
Win API:
CryptUnprotectData
Languages:
python
Platforms:
x86
YARA: Found
Links:
https://github.com/MrModed/DWMSafeBreach
SafeBreach Uncovers New Remote Access Trojan (RAT)
Dubbed CodeRAT, the new RAT is used in attacks targeting Farsi-speaking code developers using a Microsoft Dynamic Data Exchange (DDE) exploit.
#ParsedReport
03-09-2022
Crypto miners latest techniques
https://cybersecurity.att.com/blogs/labs-research/crypto-miners-latest-techniques
Threats:
Alien
Industry:
Iot
Geo:
Mexican
TTPs:
Tactics: 8
Technics: 22
IOCs:
Registry: 3
Path: 10
Domain: 3
File: 5
Hash: 7
Softs:
windows service, microsoft excel, windows defender
Win API:
CmRccService, CmRcService
03-09-2022
Crypto miners latest techniques
https://cybersecurity.att.com/blogs/labs-research/crypto-miners-latest-techniques
Threats:
Alien
Industry:
Iot
Geo:
Mexican
TTPs:
Tactics: 8
Technics: 22
IOCs:
Registry: 3
Path: 10
Domain: 3
File: 5
Hash: 7
Softs:
windows service, microsoft excel, windows defender
Win API:
CmRccService, CmRcService
LevelBlue
Crypto miners’ latest techniques
An exploration of the newest methods used by crypto miners to exploit systems, enhancing threat awareness.
#ParsedReport
03-09-2022
Another Ransomware For Linux Likely In Development
https://www.uptycs.com/blog/another-ransomware-for-linux-likely-in-development
Threats:
Babuk
IOCs:
Hash: 1
Url: 1
Functions:
pthread_create, fcntl
YARA: Found
03-09-2022
Another Ransomware For Linux Likely In Development
https://www.uptycs.com/blog/another-ransomware-for-linux-likely-in-development
Threats:
Babuk
IOCs:
Hash: 1
Url: 1
Functions:
pthread_create, fcntl
YARA: Found
Uptycs
Another Ransomware for Linux Likely in Development
New discovery by the Uptycs Threat Research Team of Executable and Linkable Format (ELF) ransomware by ransomware group DarkAngels.
#ParsedReport
02-09-2022
Cloudflare Pages Misused in a Phishing Campaign Against Indian Banking Customers
https://cloudsek.com/threatintelligence/cloudflare-pages-misused-in-a-phishing-campaign-against-indian-banking-customers/?utm_source=rss&utm_medium=rss&utm_campaign=cloudflare-pages-misused-in-a-phishing-campaign-against-indian-banking-customers
Industry:
Financial
Geo:
Indian, India
02-09-2022
Cloudflare Pages Misused in a Phishing Campaign Against Indian Banking Customers
https://cloudsek.com/threatintelligence/cloudflare-pages-misused-in-a-phishing-campaign-against-indian-banking-customers/?utm_source=rss&utm_medium=rss&utm_campaign=cloudflare-pages-misused-in-a-phishing-campaign-against-indian-banking-customers
Industry:
Financial
Geo:
Indian, India
Cloudsek
Cloudflare Pages Misused in a Phishing Campaign Against Indian Banking Customers | Threat Intelligence | CloudSEK
CloudSEK’s uncovered yet another improvised modus operandi used by threat actors to target banking customers in India through a phishing campaign.
#ParsedReport
03-09-2022
Sharkbot is back in Google Play
https://blog.fox-it.com/2022/09/02/sharkbot-is-back-in-google-play
Actors/Campaigns:
Fakeupdates
Threats:
Sharkbot
Industry:
Financial
Geo:
Poland, Spain, America, Austria, Australia, Italy, Germany
IOCs:
Url: 4
Hash: 2
IP: 1
Domain: 2
Softs:
android
Algorithms:
base64, rc4
03-09-2022
Sharkbot is back in Google Play
https://blog.fox-it.com/2022/09/02/sharkbot-is-back-in-google-play
Actors/Campaigns:
Fakeupdates
Threats:
Sharkbot
Industry:
Financial
Geo:
Poland, Spain, America, Austria, Australia, Italy, Germany
IOCs:
Url: 4
Hash: 2
IP: 1
Domain: 2
Softs:
android
Algorithms:
base64, rc4
Fox-IT International blog
Sharkbot is back in Google Play
Authored by Alberto Segura (main author) and Mike Stokkel (co-author) Introduction After we discovered in February 2022 the SharkBotDropper in Google Play posing as a fake Android antivirus and cle…
#ParsedReport
03-09-2022
TTPs #8 : Operation GWISIN -. TTPS #8: Operation gwisin -custom ransomware attack strategy analysis
https://thorcert.notion.site/TTPs-8-Operation-GWISIN-c3483353d20241b3a313fa4a8726302a
Threats:
Gwisin
Process_injection_technique
Nmap_tool
Winrm_tool
Dumplsass_tool
Netstat_tool
Mimikatz
Geo:
Korea, Korean
TTPs:
Tactics: 11
Technics: 29
IOCs:
File: 16
Path: 1
Registry: 1
IP: 1
Softs:
curl, bcdedit
Algorithms:
aes, base64, rc4, rsa-aes
Languages:
php, visual_basic
03-09-2022
TTPs #8 : Operation GWISIN -. TTPS #8: Operation gwisin -custom ransomware attack strategy analysis
https://thorcert.notion.site/TTPs-8-Operation-GWISIN-c3483353d20241b3a313fa4a8726302a
Threats:
Gwisin
Process_injection_technique
Nmap_tool
Winrm_tool
Dumplsass_tool
Netstat_tool
Mimikatz
Geo:
Korea, Korean
TTPs:
Tactics: 11
Technics: 29
IOCs:
File: 16
Path: 1
Registry: 1
IP: 1
Softs:
curl, bcdedit
Algorithms:
aes, base64, rc4, rsa-aes
Languages:
php, visual_basic
Notion
Notion | Where teams and agents work together
A collaborative AI workspace, built on your company context. Build and orchestrate agents right alongside your team's projects, meetings, and connected apps.
#ParsedReport
03-09-2022
PLAY Ransomware
https://chuongdong.com/reverse%20engineering/2022/09/03/PLAYRansomware
Threats:
Playcrypt
Cobalt_strike
Systembc
Adfind_tool
Dll_injection_technique
Rook
IOCs:
Hash: 2
Softs:
winscp
Algorithms:
aes-cbc, aes, xor, rsa-aes, cbc, aes-gcm
Functions:
traversal, ReadMe, PLAY
Win API:
VirtualAlloc, GetDiskFreeSpaceExW, FindNextVolumeW, BCryptEncrypt, CreateThread, BCryptGenRandom, BCryptOpenAlgorithmProvider, FindFirstVolumeW, FindFirstFileW, MoveFileW, WinMain, BCryptSetProperty, GetDriveTypeW, ReadFile, SetVolumeMountPointW, SetFilePointerEx, WNetGetUniversalNameW, FindNextFileW, Sleep, BCryptExportKey, BCryptImportKeyPair, WriteFile, BCryptGenerateSymmetricKey, GetVolumePathNamesForVolumeNameW
Links:
03-09-2022
PLAY Ransomware
https://chuongdong.com/reverse%20engineering/2022/09/03/PLAYRansomware
Threats:
Playcrypt
Cobalt_strike
Systembc
Adfind_tool
Dll_injection_technique
Rook
IOCs:
Hash: 2
Softs:
winscp
Algorithms:
aes-cbc, aes, xor, rsa-aes, cbc, aes-gcm
Functions:
traversal, ReadMe, PLAY
Win API:
VirtualAlloc, GetDiskFreeSpaceExW, FindNextVolumeW, BCryptEncrypt, CreateThread, BCryptGenRandom, BCryptOpenAlgorithmProvider, FindFirstVolumeW, FindFirstFileW, MoveFileW, WinMain, BCryptSetProperty, GetDriveTypeW, ReadFile, SetVolumeMountPointW, SetFilePointerEx, WNetGetUniversalNameW, FindNextFileW, Sleep, BCryptExportKey, BCryptImportKeyPair, WriteFile, BCryptGenerateSymmetricKey, GetVolumePathNamesForVolumeNameW
Links:
https://github.com/cdong1012/IDAPython-Malware-Scripts/blob/master/PLAY/script.pyhttps://github.com/cdong1012/IDAPython-Malware-Scripts/blob/master/PLAY/API\_resolve.pyChuong Dong
PLAY Ransomware
Malware Analysis Report - PLAY Ransomware
#ParsedReport
04-09-2022
EvilProxy Phishing-as-a-Service with MFA Bypass Emerged in Dark Web
https://resecurity.com/blog/article/evilproxy-phishing-as-a-service-with-mfa-bypass-emerged-in-dark-web
Actors/Campaigns:
Bec
Threats:
Evilproxy
Moloch
Industry:
Financial, E-commerce
IOCs:
Domain: 4
Softs:
telegram, docker, instagram
Platforms:
apple
04-09-2022
EvilProxy Phishing-as-a-Service with MFA Bypass Emerged in Dark Web
https://resecurity.com/blog/article/evilproxy-phishing-as-a-service-with-mfa-bypass-emerged-in-dark-web
Actors/Campaigns:
Bec
Threats:
Evilproxy
Moloch
Industry:
Financial, E-commerce
IOCs:
Domain: 4
Softs:
telegram, docker, instagram
Platforms:
apple
#ParsedReport
04-09-2022
. LilithJester
https://www.antiy.cn/research/notice&report/research_report/20220902.html
Threats:
Lilith_jester
Lilith_rat
Jester_stealer
Trojan/win32.botnet
TTPs:
Tactics: 4
Technics: 0
IOCs:
File: 5
Hash: 1
IP: 1
Algorithms:
zip, base64, aes
Platforms:
x64
04-09-2022
. LilithJester
https://www.antiy.cn/research/notice&report/research_report/20220902.html
Threats:
Lilith_jester
Lilith_rat
Jester_stealer
Trojan/win32.botnet
TTPs:
Tactics: 4
Technics: 0
IOCs:
File: 5
Hash: 1
IP: 1
Algorithms:
zip, base64, aes
Platforms:
x64
www.antiy.cn
Lilith僵尸网络及其背后的Jester黑客团伙跟进分析
安天CERT捕获到了Jester黑客团伙开发售卖的Lilith僵尸网络。该僵尸网络除了具备该团伙开发售卖的窃密木马、剪贴板劫持器、挖矿木马等恶意代码的功能外,还增加了持久化及远控功能,对用户造成机密数据泄露、虚拟财产损失、系统资源耗尽等威胁,安天智甲终端防御系统(简称IEP)可实现对该僵尸网络程序的有效查杀,安天探海威胁检测系统(简称PTD)能够实现对该僵尸网络C2通信的精准检测。
#ParsedReport
05-09-2022
HWP File Disguised as Personal Profile Form (OLE Object)
https://asec.ahnlab.com/en/38479
Threats:
Process_hollowing_technique
Trojan/win.agent.c5228370
Industry:
Financial
CVEs:
CVE-2018-15982 [Vulners]
Vulners: Score: 10.0, CVSS: 5.9,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- adobe flash player (le31.0.0.153, le31.0.0.153, le31.0.0.153, le31.0.0.153)
- redhat enterprise linux desktop (6.0)
- redhat enterprise linux workstation (6.0)
- redhat enterprise linux server (6.0)
- adobe flash player installer (le31.0.0.108)
have more...
IOCs:
File: 10
Url: 4
Path: 1
Hash: 7
05-09-2022
HWP File Disguised as Personal Profile Form (OLE Object)
https://asec.ahnlab.com/en/38479
Threats:
Process_hollowing_technique
Trojan/win.agent.c5228370
Industry:
Financial
CVEs:
CVE-2018-15982 [Vulners]
Vulners: Score: 10.0, CVSS: 5.9,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- adobe flash player (le31.0.0.153, le31.0.0.153, le31.0.0.153, le31.0.0.153)
- redhat enterprise linux desktop (6.0)
- redhat enterprise linux workstation (6.0)
- redhat enterprise linux server (6.0)
- adobe flash player installer (le31.0.0.108)
have more...
IOCs:
File: 10
Url: 4
Path: 1
Hash: 7
ASEC
HWP File Disguised as Personal Profile Form (OLE Object) - ASEC
The ASEC analysis team has recently identified a malicious HWP file that exploits OLE objects and flash vulnerabilities. The file uses a malicious URL identified in 2020. This URL contains a flash vulnerability (CVE-2018-15982) file, which requires users…
#technique
EvilnoVNC is a Ready to go Phishing Platform.
Unlike other phishing techniques, EvilnoVNC allows 2FA bypassing by using a real browser over a noVNC connection.
In addition, this tool allows us to see in real time all of the victim's actions, access to their downloaded files and the entire browser profile, including cookies, saved passwords, browsing history and much more.
https://github.com/JoelGMSec/EvilnoVNC
EvilnoVNC is a Ready to go Phishing Platform.
Unlike other phishing techniques, EvilnoVNC allows 2FA bypassing by using a real browser over a noVNC connection.
In addition, this tool allows us to see in real time all of the victim's actions, access to their downloaded files and the entire browser profile, including cookies, saved passwords, browsing history and much more.
https://github.com/JoelGMSec/EvilnoVNC
GitHub
GitHub - JoelGMSec/EvilnoVNC: Ready to go Phishing Platform
Ready to go Phishing Platform. Contribute to JoelGMSec/EvilnoVNC development by creating an account on GitHub.
#technique
Elevator allows to bypass the UAC and spawn an elevated process with full administrator privileges. This is done by abusing the behaviour of the RPC server that implements the UAC feature, as demonstrated by James Forshaw in his article Calling Local Windows RPC Servers from .NET. The tool does not require to drop an extra DLL or write to the Windows Registry (as is often the case with other UAC bypass techniques), and it has been successfully tested on Windows Server 2016, Windows Server 2019 and Windows 10 (it probably works on other versions of Windows).
https://github.com/Kudaes/Elevator
Elevator allows to bypass the UAC and spawn an elevated process with full administrator privileges. This is done by abusing the behaviour of the RPC server that implements the UAC feature, as demonstrated by James Forshaw in his article Calling Local Windows RPC Servers from .NET. The tool does not require to drop an extra DLL or write to the Windows Registry (as is often the case with other UAC bypass techniques), and it has been successfully tested on Windows Server 2016, Windows Server 2019 and Windows 10 (it probably works on other versions of Windows).
https://github.com/Kudaes/Elevator
GitHub
GitHub - Kudaes/Elevator: UAC bypass by abusing RPC and debug objects.
UAC bypass by abusing RPC and debug objects. Contribute to Kudaes/Elevator development by creating an account on GitHub.
#ParsedReport
06-09-2022
Pro-Russian Group Targeting Ukraine Supporters with DDoS Attacks
https://decoded.avast.io/martinchlumecky/bobik/?utm_source=rss&utm_medium=rss&utm_campaign=bobik
Actors/Campaigns:
Noname057
It_army
Killnet
Threats:
Bobiks
Redline_stealer
Industry:
Education, Logistic, Government, Transport, Aerospace, Financial, Telco, Petroleum, Energy
Geo:
Russian, Romania, Italy, Asia, Estonia, American, Polish, Americas, Poland, Romanian, Russia, Lithuania, Norway, Finland, Latvia, Brazil, Ukraines, Ukraine, India, Ukrainian
IOCs:
File: 9
IP: 4
Softs:
nginx, ubuntu, telegram
Languages:
python
Links:
06-09-2022
Pro-Russian Group Targeting Ukraine Supporters with DDoS Attacks
https://decoded.avast.io/martinchlumecky/bobik/?utm_source=rss&utm_medium=rss&utm_campaign=bobik
Actors/Campaigns:
Noname057
It_army
Killnet
Threats:
Bobiks
Redline_stealer
Industry:
Education, Logistic, Government, Transport, Aerospace, Financial, Telco, Petroleum, Energy
Geo:
Russian, Romania, Italy, Asia, Estonia, American, Polish, Americas, Poland, Romanian, Russia, Lithuania, Norway, Finland, Latvia, Brazil, Ukraines, Ukraine, India, Ukrainian
IOCs:
File: 9
IP: 4
Softs:
nginx, ubuntu, telegram
Languages:
python
Links:
https://github.com/avast/ioc/blob/master/Bobik/targets.xlsx
https://github.com/avast/ioc/tree/master/Bobik/decryptor.py
https://github.com/avast/ioc/tree/master/BobikAvast Threat Labs
Pro-Russian Group Targeting Ukraine Supporters with DDoS Attacks - Avast Threat Labs
It has now been six months since the war in Ukraine began. Since then, pro-Russian and pro-Ukrainian hacker groups, like KillNet, Anonymous, IT Army of Ukraine, Legion Spetsnaz RF, have carried out cyberattacks. A lesser-known group called NoName057(16) is…
#ParsedReport
06-09-2022
DangerousSavanna: Two-year long campaign targets financial institutions in French-speaking Africa
https://research.checkpoint.com/2022/dangeroussavanna-two-year-long-campaign-targets-financial-institutions-in-french-speaking-africa
Threats:
Dangeroussavanna
Metasploit_tool
Poshc2
Dwservice_tool
Asyncrat_rat
Amsi_bypass_technique
Junk_code_technique
Meterpreter_tool
Backstab_tool
Industry:
Financial
Geo:
Cameroon, Morocco, French, Africa, African, Senegal, Togo
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 15
Url: 1
Path: 6
Hash: 57
Domain: 7
IP: 9
Softs:
windows subsystem for linux, process explorer
Algorithms:
aes, zip
Win API:
AmsiScanBuffer, EtwEventWrite, SetWindowsHookExW
Platforms:
intel
Links:
06-09-2022
DangerousSavanna: Two-year long campaign targets financial institutions in French-speaking Africa
https://research.checkpoint.com/2022/dangeroussavanna-two-year-long-campaign-targets-financial-institutions-in-french-speaking-africa
Threats:
Dangeroussavanna
Metasploit_tool
Poshc2
Dwservice_tool
Asyncrat_rat
Amsi_bypass_technique
Junk_code_technique
Meterpreter_tool
Backstab_tool
Industry:
Financial
Geo:
Cameroon, Morocco, French, Africa, African, Senegal, Togo
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 15
Url: 1
Path: 6
Hash: 57
Domain: 7
IP: 9
Softs:
windows subsystem for linux, process explorer
Algorithms:
aes, zip
Win API:
AmsiScanBuffer, EtwEventWrite, SetWindowsHookExW
Platforms:
intel
Links:
https://github.com/nettitude/PoshC2https://github.com/rapid7/metasploit-frameworkhttps://github.com/MalwareCantFly/Vba2Graphhttps://github.com/Yaxser/Backstabhttps://github.com/nettitude/PoshC2\_Shellcodehttps://github.com/Porchetta-Industries/CrackMapExechttps://github.com/nettitude/PoshC2/blob/master/resources/modules/Stage2-Core.ps1https://github.com/NYAN-x-CAT/AsyncRAT-C-Sharphttps://github.com/ZephrFish/PoshC2\_Python/blob/master/Modules/Inject-Shellcode.ps1https://github.com/dwserviceCheck Point Research
DangerousSavanna: Two-year long campaign targets financial institutions in French-speaking Africa - Check Point Research
Introduction Recent studies show that more than 85% of financial institutions in Central and Western Africa have repeatedly been victimized in multiple, damaging cyberattacks. In a quarter of these cases, intrusions into network systems resulted in the worst…
#ParsedReport
06-09-2022
Shikitega - New stealthy malware targeting Linux
https://cybersecurity.att.com/blogs/labs-research/shikitega-new-stealthy-malware-targeting-linux
Threats:
Shikitega
Meterpreter_tool
Metasploit_tool
Mettle
Botenago
Enemybot
Xmrig_miner
Industry:
Iot
CVEs:
CVE-2021-3493 [Vulners]
Vulners: Score: 7.2, CVSS: 4.1,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- canonical ubuntu linux (<18.04, <20.04, <20.10)
CVE-2021-4034 [Vulners]
Vulners: Score: 7.2, CVSS: 4.4,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- polkit project polkit (*)
- redhat enterprise linux desktop (7.0)
- redhat enterprise linux workstation (7.0)
- redhat enterprise linux for scientific computing (7.0)
- redhat enterprise linux server (7.0, 6.0)
have more...
TTPs:
Tactics: 4
Technics: 5
IOCs:
Domain: 2
Hash: 24
Softs:
ntab serv, unix, crontab
Algorithms:
xor, shikata_ga_nai
Links:
06-09-2022
Shikitega - New stealthy malware targeting Linux
https://cybersecurity.att.com/blogs/labs-research/shikitega-new-stealthy-malware-targeting-linux
Threats:
Shikitega
Meterpreter_tool
Metasploit_tool
Mettle
Botenago
Enemybot
Xmrig_miner
Industry:
Iot
CVEs:
CVE-2021-3493 [Vulners]
Vulners: Score: 7.2, CVSS: 4.1,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- canonical ubuntu linux (<18.04, <20.04, <20.10)
CVE-2021-4034 [Vulners]
Vulners: Score: 7.2, CVSS: 4.4,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- polkit project polkit (*)
- redhat enterprise linux desktop (7.0)
- redhat enterprise linux workstation (7.0)
- redhat enterprise linux for scientific computing (7.0)
- redhat enterprise linux server (7.0, 6.0)
have more...
TTPs:
Tactics: 4
Technics: 5
IOCs:
Domain: 2
Hash: 24
Softs:
ntab serv, unix, crontab
Algorithms:
xor, shikata_ga_nai
Links:
https://github.com/rapid7/mettleLevelBlue
Shikitega - New stealthy malware targeting Linux
Insights into Shikitega, the new stealthy malware targeting Linux systems, highlighting its risks and behaviors.
👍1
#ParsedReport
06-09-2022
Play Ransomware's Attack Playbook Unmasks it as Another Hive Affiliate like Nokoyawa
https://www.trendmicro.com/en_us/research/22/i/play-ransomware-s-attack-playbook-unmasks-it-as-another-hive-aff.html
Threats:
Playcrypt
Nokoyawa
Adfind_tool
Nekto
Cobalt_strike
Coroxy
Systembc
Gmer_tool
Pchunter_tool
Hive
Quantum_locker
Conti
Beacon
Emotet
Svcready_loader
Lolbin
Mimikatz
Process_hacker_tool
Iobit_tool
Powertool_tool
Wevtutil_tool
Empire_loader
Nltest_tool
Bloodhound_tool
Trojan.win64.privicmd.yxchw
Ransom.win32.playde.a
Ransom.win32.playde.yxchjt
Ransom.win32.playde.yachwt
Ransom.win32.playde.yachp
Industry:
Government
Geo:
Brazil, Spain, Netherlands, India, America, American, Hungary, Argentina
CVEs:
CVE-2018-13379 [Vulners]
Vulners: Score: 5.0, CVSS: 3.2,
Vulners: Exploitation: True
X-Force: Risk: 7.5
X-Force: Patch: Official fix
Soft:
- fortinet fortios (le6.0.4, le5.6.7)
CVE-2020-12812 [Vulners]
Vulners: Score: 7.5, CVSS: 2.6,
Vulners: Exploitation: True
X-Force: Risk: 5.3
X-Force: Patch: Official fix
Soft:
- fortinet fortios (<6.2.4, 6.4.0, <6.0.10)
TTPs:
Tactics: 10
Technics: 0
IOCs:
File: 2
Path: 5
Url: 4
Email: 1
Hash: 20
IP: 2
Softs:
windows defender, psexec, active directory, local security authority, sysinternals, winscp
Algorithms:
base64
Functions:
ReadMe
Languages:
php
Links:
06-09-2022
Play Ransomware's Attack Playbook Unmasks it as Another Hive Affiliate like Nokoyawa
https://www.trendmicro.com/en_us/research/22/i/play-ransomware-s-attack-playbook-unmasks-it-as-another-hive-aff.html
Threats:
Playcrypt
Nokoyawa
Adfind_tool
Nekto
Cobalt_strike
Coroxy
Systembc
Gmer_tool
Pchunter_tool
Hive
Quantum_locker
Conti
Beacon
Emotet
Svcready_loader
Lolbin
Mimikatz
Process_hacker_tool
Iobit_tool
Powertool_tool
Wevtutil_tool
Empire_loader
Nltest_tool
Bloodhound_tool
Trojan.win64.privicmd.yxchw
Ransom.win32.playde.a
Ransom.win32.playde.yxchjt
Ransom.win32.playde.yachwt
Ransom.win32.playde.yachp
Industry:
Government
Geo:
Brazil, Spain, Netherlands, India, America, American, Hungary, Argentina
CVEs:
CVE-2018-13379 [Vulners]
Vulners: Score: 5.0, CVSS: 3.2,
Vulners: Exploitation: True
X-Force: Risk: 7.5
X-Force: Patch: Official fix
Soft:
- fortinet fortios (le6.0.4, le5.6.7)
CVE-2020-12812 [Vulners]
Vulners: Score: 7.5, CVSS: 2.6,
Vulners: Exploitation: True
X-Force: Risk: 5.3
X-Force: Patch: Official fix
Soft:
- fortinet fortios (<6.2.4, 6.4.0, <6.0.10)
TTPs:
Tactics: 10
Technics: 0
IOCs:
File: 2
Path: 5
Url: 4
Email: 1
Hash: 20
IP: 2
Softs:
windows defender, psexec, active directory, local security authority, sysinternals, winscp
Algorithms:
base64
Functions:
ReadMe
Languages:
php
Links:
https://github.com/gentilkiwi/mimikatzhttps://github.com/carlospolop/PEASS-ngTrend Micro
Play Ransomware Attack Playbook Similar to that of Hive, Nokoyawa
Play is a new ransomware that takes a page out of Hive and Nokoyawa's playbook. The many similarities among them indicate that Play, like Nokoyawa, are operated by the same people.
#ParsedReport
06-09-2022
Dragon News Blog. Mythic Case Study: Assessing Common Offensive Security Tools
https://team-cymru.com/blog/2022/09/06/mythic-case-study-assessing-common-offensive-security-tools
Threats:
Mythic_c2_tool
Cobalt_strike
Sliver_tool
Rengine_tool
Beacon
Bazarbackdoor
Conti
Athena_botnet
Tetanus
Process_injection_technique
Timestomp_technique
Dll_sideloading_technique
Geo:
Pakistan, Pakistani, Turkey
TTPs:
Tactics: 1
Technics: 16
IOCs:
Domain: 6
IP: 16
Softs:
zoom, macos
Languages:
python
Links:
06-09-2022
Dragon News Blog. Mythic Case Study: Assessing Common Offensive Security Tools
https://team-cymru.com/blog/2022/09/06/mythic-case-study-assessing-common-offensive-security-tools
Threats:
Mythic_c2_tool
Cobalt_strike
Sliver_tool
Rengine_tool
Beacon
Bazarbackdoor
Conti
Athena_botnet
Tetanus
Process_injection_technique
Timestomp_technique
Dll_sideloading_technique
Geo:
Pakistan, Pakistani, Turkey
TTPs:
Tactics: 1
Technics: 16
IOCs:
Domain: 6
IP: 16
Softs:
zoom, macos
Languages:
python
Links:
https://github.com/yogeshojha/rengine
https://github.com/BishopFox/sliver#ParsedReport
06-09-2022
Adversaries Actively Utilizing PowerShell Empire. Reference
https://blog.cyble.com/2022/09/06/adversaries-actively-utilizing-powershell-empire
Actors/Campaigns:
Turla
Shell_crew
Muddywater
Axiom
Apt33
Fin10
Threats:
Empire_loader
Watering_hole_technique
Process_injection_technique
Geo:
Australia, Georgia, Dubai, Singapore, India
TTPs:
Tactics: 3
Technics: 3
IOCs:
File: 1
Hash: 10
Softs:
android, windows powershell, net framework
Algorithms:
base64
Languages:
php
Links:
06-09-2022
Adversaries Actively Utilizing PowerShell Empire. Reference
https://blog.cyble.com/2022/09/06/adversaries-actively-utilizing-powershell-empire
Actors/Campaigns:
Turla
Shell_crew
Muddywater
Axiom
Apt33
Fin10
Threats:
Empire_loader
Watering_hole_technique
Process_injection_technique
Geo:
Australia, Georgia, Dubai, Singapore, India
TTPs:
Tactics: 3
Technics: 3
IOCs:
File: 1
Hash: 10
Softs:
android, windows powershell, net framework
Algorithms:
base64
Languages:
php
Links:
https://github.com/EmpireProject/EmpireCyble
Cyble - Adversaries Actively Utilizing PowerShell Empire
Cyble Research & Intelligence Labs (CRIL) analyses the red teaming tool PowerShell Empire being actively used by attackers for cyberattacks.