CTT Report Hub
3.42K subscribers
9.87K photos
6 videos
67 files
13.5K links
Threat Intelligence Report Hub
Download Telegram
#ParsedReport
04-09-2022

EvilProxy Phishing-as-a-Service with MFA Bypass Emerged in Dark Web

https://resecurity.com/blog/article/evilproxy-phishing-as-a-service-with-mfa-bypass-emerged-in-dark-web

Actors/Campaigns:
Bec

Threats:
Evilproxy
Moloch

Industry:
Financial, E-commerce

IOCs:
Domain: 4

Softs:
telegram, docker, instagram

Platforms:
apple
#ParsedReport
05-09-2022

HWP File Disguised as Personal Profile Form (OLE Object)

https://asec.ahnlab.com/en/38479

Threats:
Process_hollowing_technique
Trojan/win.agent.c5228370

Industry:
Financial

CVEs:
CVE-2018-15982 [Vulners]
Vulners: Score: 10.0, CVSS: 5.9,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- adobe flash player (le31.0.0.153, le31.0.0.153, le31.0.0.153, le31.0.0.153)
- redhat enterprise linux desktop (6.0)
- redhat enterprise linux workstation (6.0)
- redhat enterprise linux server (6.0)
- adobe flash player installer (le31.0.0.108)
have more...

IOCs:
File: 10
Url: 4
Path: 1
Hash: 7
#technique

EvilnoVNC is a Ready to go Phishing Platform.

Unlike other phishing techniques, EvilnoVNC allows 2FA bypassing by using a real browser over a noVNC connection.

In addition, this tool allows us to see in real time all of the victim's actions, access to their downloaded files and the entire browser profile, including cookies, saved passwords, browsing history and much more.
https://github.com/JoelGMSec/EvilnoVNC
#technique

Elevator allows to bypass the UAC and spawn an elevated process with full administrator privileges. This is done by abusing the behaviour of the RPC server that implements the UAC feature, as demonstrated by James Forshaw in his article Calling Local Windows RPC Servers from .NET. The tool does not require to drop an extra DLL or write to the Windows Registry (as is often the case with other UAC bypass techniques), and it has been successfully tested on Windows Server 2016, Windows Server 2019 and Windows 10 (it probably works on other versions of Windows).

https://github.com/Kudaes/Elevator
#ParsedReport
06-09-2022

Pro-Russian Group Targeting Ukraine Supporters with DDoS Attacks

https://decoded.avast.io/martinchlumecky/bobik/?utm_source=rss&utm_medium=rss&utm_campaign=bobik

Actors/Campaigns:
Noname057
It_army
Killnet

Threats:
Bobiks
Redline_stealer

Industry:
Education, Logistic, Government, Transport, Aerospace, Financial, Telco, Petroleum, Energy

Geo:
Russian, Romania, Italy, Asia, Estonia, American, Polish, Americas, Poland, Romanian, Russia, Lithuania, Norway, Finland, Latvia, Brazil, Ukraines, Ukraine, India, Ukrainian

IOCs:
File: 9
IP: 4

Softs:
nginx, ubuntu, telegram

Languages:
python

Links:
https://github.com/avast/ioc/blob/master/Bobik/targets.xlsx
https://github.com/avast/ioc/tree/master/Bobik/decryptor.py
https://github.com/avast/ioc/tree/master/Bobik
#ParsedReport
06-09-2022

DangerousSavanna: Two-year long campaign targets financial institutions in French-speaking Africa

https://research.checkpoint.com/2022/dangeroussavanna-two-year-long-campaign-targets-financial-institutions-in-french-speaking-africa

Threats:
Dangeroussavanna
Metasploit_tool
Poshc2
Dwservice_tool
Asyncrat_rat
Amsi_bypass_technique
Junk_code_technique
Meterpreter_tool
Backstab_tool

Industry:
Financial

Geo:
Cameroon, Morocco, French, Africa, African, Senegal, Togo

TTPs:
Tactics: 2
Technics: 0

IOCs:
File: 15
Url: 1
Path: 6
Hash: 57
Domain: 7
IP: 9

Softs:
windows subsystem for linux, process explorer

Algorithms:
aes, zip

Win API:
AmsiScanBuffer, EtwEventWrite, SetWindowsHookExW

Platforms:
intel

Links:
https://github.com/nettitude/PoshC2
https://github.com/rapid7/metasploit-framework
https://github.com/MalwareCantFly/Vba2Graph
https://github.com/Yaxser/Backstab
https://github.com/nettitude/PoshC2\_Shellcode
https://github.com/Porchetta-Industries/CrackMapExec
https://github.com/nettitude/PoshC2/blob/master/resources/modules/Stage2-Core.ps1
https://github.com/NYAN-x-CAT/AsyncRAT-C-Sharp
https://github.com/ZephrFish/PoshC2\_Python/blob/master/Modules/Inject-Shellcode.ps1
https://github.com/dwservice
#ParsedReport
06-09-2022

Shikitega - New stealthy malware targeting Linux

https://cybersecurity.att.com/blogs/labs-research/shikitega-new-stealthy-malware-targeting-linux

Threats:
Shikitega
Meterpreter_tool
Metasploit_tool
Mettle
Botenago
Enemybot
Xmrig_miner

Industry:
Iot

CVEs:
CVE-2021-3493 [Vulners]
Vulners: Score: 7.2, CVSS: 4.1,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- canonical ubuntu linux (<18.04, <20.04, <20.10)

CVE-2021-4034 [Vulners]
Vulners: Score: 7.2, CVSS: 4.4,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- polkit project polkit (*)
- redhat enterprise linux desktop (7.0)
- redhat enterprise linux workstation (7.0)
- redhat enterprise linux for scientific computing (7.0)
- redhat enterprise linux server (7.0, 6.0)
have more...

TTPs:
Tactics: 4
Technics: 5

IOCs:
Domain: 2
Hash: 24

Softs:
ntab serv, unix, crontab

Algorithms:
xor, shikata_ga_nai

Links:
https://github.com/rapid7/mettle
👍1
#ParsedReport
06-09-2022

Play Ransomware's Attack Playbook Unmasks it as Another Hive Affiliate like Nokoyawa

https://www.trendmicro.com/en_us/research/22/i/play-ransomware-s-attack-playbook-unmasks-it-as-another-hive-aff.html

Threats:
Playcrypt
Nokoyawa
Adfind_tool
Nekto
Cobalt_strike
Coroxy
Systembc
Gmer_tool
Pchunter_tool
Hive
Quantum_locker
Conti
Beacon
Emotet
Svcready_loader
Lolbin
Mimikatz
Process_hacker_tool
Iobit_tool
Powertool_tool
Wevtutil_tool
Empire_loader
Nltest_tool
Bloodhound_tool
Trojan.win64.privicmd.yxchw
Ransom.win32.playde.a
Ransom.win32.playde.yxchjt
Ransom.win32.playde.yachwt
Ransom.win32.playde.yachp

Industry:
Government

Geo:
Brazil, Spain, Netherlands, India, America, American, Hungary, Argentina

CVEs:
CVE-2018-13379 [Vulners]
Vulners: Score: 5.0, CVSS: 3.2,
Vulners: Exploitation: True
X-Force: Risk: 7.5
X-Force: Patch: Official fix
Soft:
- fortinet fortios (le6.0.4, le5.6.7)

CVE-2020-12812 [Vulners]
Vulners: Score: 7.5, CVSS: 2.6,
Vulners: Exploitation: True
X-Force: Risk: 5.3
X-Force: Patch: Official fix
Soft:
- fortinet fortios (<6.2.4, 6.4.0, <6.0.10)


TTPs:
Tactics: 10
Technics: 0

IOCs:
File: 2
Path: 5
Url: 4
Email: 1
Hash: 20
IP: 2

Softs:
windows defender, psexec, active directory, local security authority, sysinternals, winscp

Algorithms:
base64

Functions:
ReadMe

Languages:
php

Links:
https://github.com/gentilkiwi/mimikatz
https://github.com/carlospolop/PEASS-ng
#ParsedReport
06-09-2022

Dragon News Blog. Mythic Case Study: Assessing Common Offensive Security Tools

https://team-cymru.com/blog/2022/09/06/mythic-case-study-assessing-common-offensive-security-tools

Threats:
Mythic_c2_tool
Cobalt_strike
Sliver_tool
Rengine_tool
Beacon
Bazarbackdoor
Conti
Athena_botnet
Tetanus
Process_injection_technique
Timestomp_technique
Dll_sideloading_technique

Geo:
Pakistan, Pakistani, Turkey

TTPs:
Tactics: 1
Technics: 16

IOCs:
Domain: 6
IP: 16

Softs:
zoom, macos

Languages:
python

Links:
https://github.com/yogeshojha/rengine
https://github.com/BishopFox/sliver
#ParsedReport
06-09-2022

Adversaries Actively Utilizing PowerShell Empire. Reference

https://blog.cyble.com/2022/09/06/adversaries-actively-utilizing-powershell-empire

Actors/Campaigns:
Turla
Shell_crew
Muddywater
Axiom
Apt33
Fin10

Threats:
Empire_loader
Watering_hole_technique
Process_injection_technique

Geo:
Australia, Georgia, Dubai, Singapore, India

TTPs:
Tactics: 3
Technics: 3

IOCs:
File: 1
Hash: 10

Softs:
android, windows powershell, net framework

Algorithms:
base64

Languages:
php

Links:
https://github.com/EmpireProject/Empire
#ParsedReport
06-09-2022

Mirai Variant MooBot Targeting D-Link Devices

https://unit42.paloaltonetworks.com/moobot-d-link-devices

Threats:
Mirai
Moobot

Industry:
Iot

Geo:
Japanese, Japan

CVEs:
CVE-2022-28958 [Vulners]
Vulners: Score: 7.5, CVSS: 4.1,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Unavailable
Soft:
- dlink dir-816l firmware (206b01)

CVE-2018-6530 [Vulners]
Vulners: Score: 10.0, CVSS: 8.3,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- d-link dir-860l firmware (lea1_fw110b04)
- d-link dir-865l firmware (lereva_firmware_patch_1.08.b01)
- d-link dir-868l firmware (lea1_fw112b04)
- d-link dir-880l firmware (lereva_firmware_patch_1.08b04)

CVE-2022-26258 [Vulners]
Vulners: Score: 7.5, CVSS: 4.8,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.3
X-Force: Patch: Unavailable
Soft:
- dlink dir-820l firmware (1.05)

CVE-2015-2051 [Vulners]
Vulners: Score: 10.0, CVSS: 8.6,
Vulners: Exploitation: True
X-Force: Risk: 10
X-Force: Patch: Official fix
Soft:
- d-link dir-645 firmware (le1.04b12)


IOCs:
IP: 1
Hash: 13
Domain: 2
Url: 14

Softs:
android

Algorithms:
exhibit

Languages:
php

Platforms:
arm
#ParsedReport
06-09-2022

The Ares Banking Trojan Learns Old Tricks: Adds the Defunct Qakbot DGA. Key Points

https://www.zscaler.com/blogs/security-research/ares-banking-trojan-learns-old-tricks-adds-defunct-qakbot-dga

Threats:
Ares_rat
Qakbot
Kronos

Industry:
Financial

Geo:
Mexico

IOCs:
File: 2
Hash: 2
Url: 1

Algorithms:
crc, prng

Win API:
NtFreeVirtualMemory, NtSetInformationFile, NtUnmapViewOfSection, NtEnumerateValueKey, NtDebugActiveProcess, NtQueryKey, NtQueryObject, RtlFreeAnsiString, NtDuplicateObject, NtQueryInformationProcess, NtWriteVirtualMemory, NtQueryValueKey, NtQueryDirectoryFile, NtClose, NtDelayExecution, NtSuspendThread, lstrlenA, RtlDeregisterWaitEx, RtlInitUnicodeString, RtlAnsiStringToUnicodeString, NtMapViewOfSection, NtCreateFile, NtSetContextThread, NtOpenFile, RtlCreateUserThread, NtOpenProcess, NtQueryInformationFile, NtResumeThread, RtlFreeUnicodeString, NtGetContextThread, RtlRandomEx, RtlUnicodeStringToAnsiString, NtTerminateThread, RtlRegisterWait, NtDeleteFile, NtWriteFile, RtlCompareUnicodeString, NtReadVirtualMemory, NtQuerySystemInformationEx, NtQueryInformationThread, RtlInitAnsiString, lstrcatA, NtQueryVirtualMemory, NtAllocateVirtualMemory, NtOpenEvent, NtCreateKey, NtSetValueKey, NtDeleteValueKey, NtProtectVirtualMemory, NtCreateSection

Languages:
python, javascript

Links:
https://github.com/threatlabz/tools/tree/main/ares
https://github.com/Dan611/QakBot-DGA/blob/master/qakbot\_dga.c
https://github.com/threatlabz/iocs/tree/main/ares
#ParsedReport
06-09-2022

Spyware Campaign Targeting The Uyghur Community

https://blog.cyble.com/2022/09/05/spyware-campaign-targeting-the-uyghur-community

Industry:
Financial, Government

Geo:
China, Georgia, India, Asia, Singapore, Dubai, Australia

TTPs:
Tactics: 4
Technics: 5

IOCs:
File: 1
Hash: 1

Softs:
android
#ParsedReport
06-09-2022

SafeBreach Labs Researchers Uncover New Remote Access Trojan (RAT). CodeRAT Overview

https://www.safebreach.com/resources/blog/remote-access-trojan-coderat

Threats:
Coderat
Robothief
Antidebugging_technique

Industry:
Media, Government, E-commerce

Geo:
Irans, Iranian, Tehran, Iran

IOCs:
File: 9
Hash: 5

Softs:
android, microsoft office, microsoft word, microsoft powerpoint, instagram, windows media player, visual studio, telegram

Functions:
BossWatch, CheckBoss

Win API:
CryptUnprotectData

Languages:
python

Platforms:
x86

YARA: Found

Links:
https://github.com/MrModed/DWM
#ParsedReport
06-09-2022

APTEvilnum. APT organization Evilnum launched a new round of network attacks on online transactions

https://mp.weixin.qq.com/s/1KIFSc3R5WrMklidXWSBaw

Actors/Campaigns:
Evilnum
Darkcasino

Threats:
Tron
Darkme
Agent_tesla
Formbook

Industry:
Entertainment, Financial

TTPs:
Tactics: 1
Technics: 0

IOCs:
File: 21
Domain: 3
Hash: 47
Url: 1
#ParsedReport
06-09-2022

What Is Redeemer Ransomware and How Does It Spread: A Technical Analysis

https://cloudsek.com/what-is-redeemer-ransomware-and-how-does-it-spread-a-technical-analysis

Threats:
Redeemer
Pandora
Wevtutil_tool
Yourcyanide

Industry:
Financial

TTPs:
Tactics: 1
Technics: 0

IOCs:
File: 45
Path: 1
Hash: 2

Softs:
sqlagent, ntrtscan, dbsnmp, sqlbrowser, vssadmin, pccntmon, onenote, thebat, powerpnt, wordpad, encsvc, winlogon, thebat64

Algorithms:
base64, aes-256

Functions:
ReadMe, FindFirstFile, FindNextFile, SetFileAttributes

Win API:
ShellExecuteW, GetLogicalDrives, ShowWindow, SHGetFolderPath
#ParsedReport
07-09-2022

Mirai Variant MooBot Targets RCE Vulnerabilities in D-Link Routers

https://socradar.io/moobot-targets-rce-vulnerabilities-in-d-link-routers

Threats:
Mirai
Moobot
Deadbolt

Industry:
Financial

Geo:
American

CVEs:
CVE-2022-28958 [Vulners]
Vulners: Score: 7.5, CVSS: 4.1,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Unavailable
Soft:
- dlink dir-816l firmware (206b01)

CVE-2022-26258 [Vulners]
Vulners: Score: 7.5, CVSS: 4.8,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.3
X-Force: Patch: Unavailable
Soft:
- dlink dir-820l firmware (1.05)

CVE-2018-6530 [Vulners]
Vulners: Score: 10.0, CVSS: 8.3,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- d-link dir-860l firmware (lea1_fw110b04)
- d-link dir-865l firmware (lereva_firmware_patch_1.08.b01)
- d-link dir-868l firmware (lea1_fw112b04)
- d-link dir-880l firmware (lereva_firmware_patch_1.08b04)

CVE-2015-2051 [Vulners]
Vulners: Score: 10.0, CVSS: 8.6,
Vulners: Exploitation: True
X-Force: Risk: 10
X-Force: Patch: Official fix
Soft:
- d-link dir-645 firmware (le1.04b12)


IOCs:
File: 2
Domain: 1
Url: 14
Hash: 13

Softs:
tiktok

Functions:
GetDeviceSettings
#ParsedReport
07-09-2022

Initial access broker repurposing techniques in targeted attacks against Ukraine

https://blog.google/threat-analysis-group/initial-access-broker-repurposing-techniques-in-targeted-attacks-against-ukraine

Actors/Campaigns:
Wizard_spider (motivation: government_sponsored, financially_motivated)
Fin12

Threats:
Conti
Icedid
Anchormail
Lackeybuilder_tool
Trickbot
Cobalt_strike
Ettersilent_tool
Follina_vuln

Industry:
Healthcare, Government, Retail, Financial, Ngo

Geo:
Russian, Italy, India, Ukraine, Ukrainian

CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: 3.4,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...

IOCs:
Url: 16
Hash: 3
File: 6
Domain: 9
Email: 2
IP: 2

Algorithms:
zip
#ParsedReport
07-09-2022

Sharkbot is back in Google Play

https://research.nccgroup.com/2022/09/06/sharkbot-is-back-in-google-play

Actors/Campaigns:
Fakeupdates

Threats:
Sharkbot

Industry:
Financial

Geo:
Poland, Austria, Spain, America, Germany, Australia, Italy

IOCs:
Url: 4
Hash: 2
IP: 1
Domain: 2

Softs:
android

Algorithms:
rc4, base64