#ParsedReport
06-09-2022
Pro-Russian Group Targeting Ukraine Supporters with DDoS Attacks
https://decoded.avast.io/martinchlumecky/bobik/?utm_source=rss&utm_medium=rss&utm_campaign=bobik
Actors/Campaigns:
Noname057
It_army
Killnet
Threats:
Bobiks
Redline_stealer
Industry:
Education, Logistic, Government, Transport, Aerospace, Financial, Telco, Petroleum, Energy
Geo:
Russian, Romania, Italy, Asia, Estonia, American, Polish, Americas, Poland, Romanian, Russia, Lithuania, Norway, Finland, Latvia, Brazil, Ukraines, Ukraine, India, Ukrainian
IOCs:
File: 9
IP: 4
Softs:
nginx, ubuntu, telegram
Languages:
python
Links:
06-09-2022
Pro-Russian Group Targeting Ukraine Supporters with DDoS Attacks
https://decoded.avast.io/martinchlumecky/bobik/?utm_source=rss&utm_medium=rss&utm_campaign=bobik
Actors/Campaigns:
Noname057
It_army
Killnet
Threats:
Bobiks
Redline_stealer
Industry:
Education, Logistic, Government, Transport, Aerospace, Financial, Telco, Petroleum, Energy
Geo:
Russian, Romania, Italy, Asia, Estonia, American, Polish, Americas, Poland, Romanian, Russia, Lithuania, Norway, Finland, Latvia, Brazil, Ukraines, Ukraine, India, Ukrainian
IOCs:
File: 9
IP: 4
Softs:
nginx, ubuntu, telegram
Languages:
python
Links:
https://github.com/avast/ioc/blob/master/Bobik/targets.xlsx
https://github.com/avast/ioc/tree/master/Bobik/decryptor.py
https://github.com/avast/ioc/tree/master/BobikAvast Threat Labs
Pro-Russian Group Targeting Ukraine Supporters with DDoS Attacks - Avast Threat Labs
It has now been six months since the war in Ukraine began. Since then, pro-Russian and pro-Ukrainian hacker groups, like KillNet, Anonymous, IT Army of Ukraine, Legion Spetsnaz RF, have carried out cyberattacks. A lesser-known group called NoName057(16) isโฆ
#ParsedReport
06-09-2022
DangerousSavanna: Two-year long campaign targets financial institutions in French-speaking Africa
https://research.checkpoint.com/2022/dangeroussavanna-two-year-long-campaign-targets-financial-institutions-in-french-speaking-africa
Threats:
Dangeroussavanna
Metasploit_tool
Poshc2
Dwservice_tool
Asyncrat_rat
Amsi_bypass_technique
Junk_code_technique
Meterpreter_tool
Backstab_tool
Industry:
Financial
Geo:
Cameroon, Morocco, French, Africa, African, Senegal, Togo
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 15
Url: 1
Path: 6
Hash: 57
Domain: 7
IP: 9
Softs:
windows subsystem for linux, process explorer
Algorithms:
aes, zip
Win API:
AmsiScanBuffer, EtwEventWrite, SetWindowsHookExW
Platforms:
intel
Links:
06-09-2022
DangerousSavanna: Two-year long campaign targets financial institutions in French-speaking Africa
https://research.checkpoint.com/2022/dangeroussavanna-two-year-long-campaign-targets-financial-institutions-in-french-speaking-africa
Threats:
Dangeroussavanna
Metasploit_tool
Poshc2
Dwservice_tool
Asyncrat_rat
Amsi_bypass_technique
Junk_code_technique
Meterpreter_tool
Backstab_tool
Industry:
Financial
Geo:
Cameroon, Morocco, French, Africa, African, Senegal, Togo
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 15
Url: 1
Path: 6
Hash: 57
Domain: 7
IP: 9
Softs:
windows subsystem for linux, process explorer
Algorithms:
aes, zip
Win API:
AmsiScanBuffer, EtwEventWrite, SetWindowsHookExW
Platforms:
intel
Links:
https://github.com/nettitude/PoshC2https://github.com/rapid7/metasploit-frameworkhttps://github.com/MalwareCantFly/Vba2Graphhttps://github.com/Yaxser/Backstabhttps://github.com/nettitude/PoshC2\_Shellcodehttps://github.com/Porchetta-Industries/CrackMapExechttps://github.com/nettitude/PoshC2/blob/master/resources/modules/Stage2-Core.ps1https://github.com/NYAN-x-CAT/AsyncRAT-C-Sharphttps://github.com/ZephrFish/PoshC2\_Python/blob/master/Modules/Inject-Shellcode.ps1https://github.com/dwserviceCheck Point Research
DangerousSavanna: Two-year long campaign targets financial institutions in French-speaking Africa - Check Point Research
Introduction Recent studies show that more than 85% of financial institutions in Central and Western Africa have repeatedly been victimized in multiple, damaging cyberattacks. In a quarter of these cases, intrusions into network systems resulted in the worstโฆ
#ParsedReport
06-09-2022
Shikitega - New stealthy malware targeting Linux
https://cybersecurity.att.com/blogs/labs-research/shikitega-new-stealthy-malware-targeting-linux
Threats:
Shikitega
Meterpreter_tool
Metasploit_tool
Mettle
Botenago
Enemybot
Xmrig_miner
Industry:
Iot
CVEs:
CVE-2021-3493 [Vulners]
Vulners: Score: 7.2, CVSS: 4.1,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- canonical ubuntu linux (<18.04, <20.04, <20.10)
CVE-2021-4034 [Vulners]
Vulners: Score: 7.2, CVSS: 4.4,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- polkit project polkit (*)
- redhat enterprise linux desktop (7.0)
- redhat enterprise linux workstation (7.0)
- redhat enterprise linux for scientific computing (7.0)
- redhat enterprise linux server (7.0, 6.0)
have more...
TTPs:
Tactics: 4
Technics: 5
IOCs:
Domain: 2
Hash: 24
Softs:
ntab serv, unix, crontab
Algorithms:
xor, shikata_ga_nai
Links:
06-09-2022
Shikitega - New stealthy malware targeting Linux
https://cybersecurity.att.com/blogs/labs-research/shikitega-new-stealthy-malware-targeting-linux
Threats:
Shikitega
Meterpreter_tool
Metasploit_tool
Mettle
Botenago
Enemybot
Xmrig_miner
Industry:
Iot
CVEs:
CVE-2021-3493 [Vulners]
Vulners: Score: 7.2, CVSS: 4.1,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- canonical ubuntu linux (<18.04, <20.04, <20.10)
CVE-2021-4034 [Vulners]
Vulners: Score: 7.2, CVSS: 4.4,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- polkit project polkit (*)
- redhat enterprise linux desktop (7.0)
- redhat enterprise linux workstation (7.0)
- redhat enterprise linux for scientific computing (7.0)
- redhat enterprise linux server (7.0, 6.0)
have more...
TTPs:
Tactics: 4
Technics: 5
IOCs:
Domain: 2
Hash: 24
Softs:
ntab serv, unix, crontab
Algorithms:
xor, shikata_ga_nai
Links:
https://github.com/rapid7/mettleLevelBlue
Shikitega - New stealthy malware targeting Linux
Insights into Shikitega, the new stealthy malware targeting Linux systems, highlighting its risks and behaviors.
๐1
#ParsedReport
06-09-2022
Play Ransomware's Attack Playbook Unmasks it as Another Hive Affiliate like Nokoyawa
https://www.trendmicro.com/en_us/research/22/i/play-ransomware-s-attack-playbook-unmasks-it-as-another-hive-aff.html
Threats:
Playcrypt
Nokoyawa
Adfind_tool
Nekto
Cobalt_strike
Coroxy
Systembc
Gmer_tool
Pchunter_tool
Hive
Quantum_locker
Conti
Beacon
Emotet
Svcready_loader
Lolbin
Mimikatz
Process_hacker_tool
Iobit_tool
Powertool_tool
Wevtutil_tool
Empire_loader
Nltest_tool
Bloodhound_tool
Trojan.win64.privicmd.yxchw
Ransom.win32.playde.a
Ransom.win32.playde.yxchjt
Ransom.win32.playde.yachwt
Ransom.win32.playde.yachp
Industry:
Government
Geo:
Brazil, Spain, Netherlands, India, America, American, Hungary, Argentina
CVEs:
CVE-2018-13379 [Vulners]
Vulners: Score: 5.0, CVSS: 3.2,
Vulners: Exploitation: True
X-Force: Risk: 7.5
X-Force: Patch: Official fix
Soft:
- fortinet fortios (le6.0.4, le5.6.7)
CVE-2020-12812 [Vulners]
Vulners: Score: 7.5, CVSS: 2.6,
Vulners: Exploitation: True
X-Force: Risk: 5.3
X-Force: Patch: Official fix
Soft:
- fortinet fortios (<6.2.4, 6.4.0, <6.0.10)
TTPs:
Tactics: 10
Technics: 0
IOCs:
File: 2
Path: 5
Url: 4
Email: 1
Hash: 20
IP: 2
Softs:
windows defender, psexec, active directory, local security authority, sysinternals, winscp
Algorithms:
base64
Functions:
ReadMe
Languages:
php
Links:
06-09-2022
Play Ransomware's Attack Playbook Unmasks it as Another Hive Affiliate like Nokoyawa
https://www.trendmicro.com/en_us/research/22/i/play-ransomware-s-attack-playbook-unmasks-it-as-another-hive-aff.html
Threats:
Playcrypt
Nokoyawa
Adfind_tool
Nekto
Cobalt_strike
Coroxy
Systembc
Gmer_tool
Pchunter_tool
Hive
Quantum_locker
Conti
Beacon
Emotet
Svcready_loader
Lolbin
Mimikatz
Process_hacker_tool
Iobit_tool
Powertool_tool
Wevtutil_tool
Empire_loader
Nltest_tool
Bloodhound_tool
Trojan.win64.privicmd.yxchw
Ransom.win32.playde.a
Ransom.win32.playde.yxchjt
Ransom.win32.playde.yachwt
Ransom.win32.playde.yachp
Industry:
Government
Geo:
Brazil, Spain, Netherlands, India, America, American, Hungary, Argentina
CVEs:
CVE-2018-13379 [Vulners]
Vulners: Score: 5.0, CVSS: 3.2,
Vulners: Exploitation: True
X-Force: Risk: 7.5
X-Force: Patch: Official fix
Soft:
- fortinet fortios (le6.0.4, le5.6.7)
CVE-2020-12812 [Vulners]
Vulners: Score: 7.5, CVSS: 2.6,
Vulners: Exploitation: True
X-Force: Risk: 5.3
X-Force: Patch: Official fix
Soft:
- fortinet fortios (<6.2.4, 6.4.0, <6.0.10)
TTPs:
Tactics: 10
Technics: 0
IOCs:
File: 2
Path: 5
Url: 4
Email: 1
Hash: 20
IP: 2
Softs:
windows defender, psexec, active directory, local security authority, sysinternals, winscp
Algorithms:
base64
Functions:
ReadMe
Languages:
php
Links:
https://github.com/gentilkiwi/mimikatzhttps://github.com/carlospolop/PEASS-ngTrend Micro
Play Ransomware Attack Playbook Similar to that of Hive, Nokoyawa
Play is a new ransomware that takes a page out of Hive and Nokoyawa's playbook. The many similarities among them indicate that Play, like Nokoyawa, are operated by the same people.
#ParsedReport
06-09-2022
Dragon News Blog. Mythic Case Study: Assessing Common Offensive Security Tools
https://team-cymru.com/blog/2022/09/06/mythic-case-study-assessing-common-offensive-security-tools
Threats:
Mythic_c2_tool
Cobalt_strike
Sliver_tool
Rengine_tool
Beacon
Bazarbackdoor
Conti
Athena_botnet
Tetanus
Process_injection_technique
Timestomp_technique
Dll_sideloading_technique
Geo:
Pakistan, Pakistani, Turkey
TTPs:
Tactics: 1
Technics: 16
IOCs:
Domain: 6
IP: 16
Softs:
zoom, macos
Languages:
python
Links:
06-09-2022
Dragon News Blog. Mythic Case Study: Assessing Common Offensive Security Tools
https://team-cymru.com/blog/2022/09/06/mythic-case-study-assessing-common-offensive-security-tools
Threats:
Mythic_c2_tool
Cobalt_strike
Sliver_tool
Rengine_tool
Beacon
Bazarbackdoor
Conti
Athena_botnet
Tetanus
Process_injection_technique
Timestomp_technique
Dll_sideloading_technique
Geo:
Pakistan, Pakistani, Turkey
TTPs:
Tactics: 1
Technics: 16
IOCs:
Domain: 6
IP: 16
Softs:
zoom, macos
Languages:
python
Links:
https://github.com/yogeshojha/rengine
https://github.com/BishopFox/sliver#ParsedReport
06-09-2022
Adversaries Actively Utilizing PowerShell Empire. Reference
https://blog.cyble.com/2022/09/06/adversaries-actively-utilizing-powershell-empire
Actors/Campaigns:
Turla
Shell_crew
Muddywater
Axiom
Apt33
Fin10
Threats:
Empire_loader
Watering_hole_technique
Process_injection_technique
Geo:
Australia, Georgia, Dubai, Singapore, India
TTPs:
Tactics: 3
Technics: 3
IOCs:
File: 1
Hash: 10
Softs:
android, windows powershell, net framework
Algorithms:
base64
Languages:
php
Links:
06-09-2022
Adversaries Actively Utilizing PowerShell Empire. Reference
https://blog.cyble.com/2022/09/06/adversaries-actively-utilizing-powershell-empire
Actors/Campaigns:
Turla
Shell_crew
Muddywater
Axiom
Apt33
Fin10
Threats:
Empire_loader
Watering_hole_technique
Process_injection_technique
Geo:
Australia, Georgia, Dubai, Singapore, India
TTPs:
Tactics: 3
Technics: 3
IOCs:
File: 1
Hash: 10
Softs:
android, windows powershell, net framework
Algorithms:
base64
Languages:
php
Links:
https://github.com/EmpireProject/EmpireCyble
Cyble - Adversaries Actively Utilizing PowerShell Empire
Cyble Research & Intelligence Labs (CRIL) analyses the red teaming tool PowerShell Empire being actively used by attackers for cyberattacks.
#ParsedReport
06-09-2022
Mirai Variant MooBot Targeting D-Link Devices
https://unit42.paloaltonetworks.com/moobot-d-link-devices
Threats:
Mirai
Moobot
Industry:
Iot
Geo:
Japanese, Japan
CVEs:
CVE-2022-28958 [Vulners]
Vulners: Score: 7.5, CVSS: 4.1,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Unavailable
Soft:
- dlink dir-816l firmware (206b01)
CVE-2018-6530 [Vulners]
Vulners: Score: 10.0, CVSS: 8.3,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- d-link dir-860l firmware (lea1_fw110b04)
- d-link dir-865l firmware (lereva_firmware_patch_1.08.b01)
- d-link dir-868l firmware (lea1_fw112b04)
- d-link dir-880l firmware (lereva_firmware_patch_1.08b04)
CVE-2022-26258 [Vulners]
Vulners: Score: 7.5, CVSS: 4.8,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.3
X-Force: Patch: Unavailable
Soft:
- dlink dir-820l firmware (1.05)
CVE-2015-2051 [Vulners]
Vulners: Score: 10.0, CVSS: 8.6,
Vulners: Exploitation: True
X-Force: Risk: 10
X-Force: Patch: Official fix
Soft:
- d-link dir-645 firmware (le1.04b12)
IOCs:
IP: 1
Hash: 13
Domain: 2
Url: 14
Softs:
android
Algorithms:
exhibit
Languages:
php
Platforms:
arm
06-09-2022
Mirai Variant MooBot Targeting D-Link Devices
https://unit42.paloaltonetworks.com/moobot-d-link-devices
Threats:
Mirai
Moobot
Industry:
Iot
Geo:
Japanese, Japan
CVEs:
CVE-2022-28958 [Vulners]
Vulners: Score: 7.5, CVSS: 4.1,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Unavailable
Soft:
- dlink dir-816l firmware (206b01)
CVE-2018-6530 [Vulners]
Vulners: Score: 10.0, CVSS: 8.3,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- d-link dir-860l firmware (lea1_fw110b04)
- d-link dir-865l firmware (lereva_firmware_patch_1.08.b01)
- d-link dir-868l firmware (lea1_fw112b04)
- d-link dir-880l firmware (lereva_firmware_patch_1.08b04)
CVE-2022-26258 [Vulners]
Vulners: Score: 7.5, CVSS: 4.8,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.3
X-Force: Patch: Unavailable
Soft:
- dlink dir-820l firmware (1.05)
CVE-2015-2051 [Vulners]
Vulners: Score: 10.0, CVSS: 8.6,
Vulners: Exploitation: True
X-Force: Risk: 10
X-Force: Patch: Official fix
Soft:
- d-link dir-645 firmware (le1.04b12)
IOCs:
IP: 1
Hash: 13
Domain: 2
Url: 14
Softs:
android
Algorithms:
exhibit
Languages:
php
Platforms:
arm
Unit 42
Mirai Variant MooBot Targeting D-Link Devices
Attackers are leveraging known vulnerabilities in D-Link devices to deliver MooBot, a Mirai variant, potentially leading to further DDoS attacks.
#ParsedReport
06-09-2022
[TA505\] TA505 Group's TeslaGun In-Depth Analysis
https://www.prodaft.com/resource/detail/ta505-ta505-groups-tesla-gun-depth-analysis
Actors/Campaigns:
Ta505 (motivation: financially_motivated)
06-09-2022
[TA505\] TA505 Group's TeslaGun In-Depth Analysis
https://www.prodaft.com/resource/detail/ta505-ta505-groups-tesla-gun-depth-analysis
Actors/Campaigns:
Ta505 (motivation: financially_motivated)
Prodaft
[TA505] TA505 Group's TeslaGun In-Depth Analysis - PRODAFT
Prodaft is a cyber threat intelligence company helping organizations to mitigate cyber threats. Our expert engineers put forth proactive defense mechanisms to safeguard your business from cyber attacks.
#ParsedReport
06-09-2022
The Ares Banking Trojan Learns Old Tricks: Adds the Defunct Qakbot DGA. Key Points
https://www.zscaler.com/blogs/security-research/ares-banking-trojan-learns-old-tricks-adds-defunct-qakbot-dga
Threats:
Ares_rat
Qakbot
Kronos
Industry:
Financial
Geo:
Mexico
IOCs:
File: 2
Hash: 2
Url: 1
Algorithms:
crc, prng
Win API:
NtFreeVirtualMemory, NtSetInformationFile, NtUnmapViewOfSection, NtEnumerateValueKey, NtDebugActiveProcess, NtQueryKey, NtQueryObject, RtlFreeAnsiString, NtDuplicateObject, NtQueryInformationProcess, NtWriteVirtualMemory, NtQueryValueKey, NtQueryDirectoryFile, NtClose, NtDelayExecution, NtSuspendThread, lstrlenA, RtlDeregisterWaitEx, RtlInitUnicodeString, RtlAnsiStringToUnicodeString, NtMapViewOfSection, NtCreateFile, NtSetContextThread, NtOpenFile, RtlCreateUserThread, NtOpenProcess, NtQueryInformationFile, NtResumeThread, RtlFreeUnicodeString, NtGetContextThread, RtlRandomEx, RtlUnicodeStringToAnsiString, NtTerminateThread, RtlRegisterWait, NtDeleteFile, NtWriteFile, RtlCompareUnicodeString, NtReadVirtualMemory, NtQuerySystemInformationEx, NtQueryInformationThread, RtlInitAnsiString, lstrcatA, NtQueryVirtualMemory, NtAllocateVirtualMemory, NtOpenEvent, NtCreateKey, NtSetValueKey, NtDeleteValueKey, NtProtectVirtualMemory, NtCreateSection
Languages:
python, javascript
Links:
06-09-2022
The Ares Banking Trojan Learns Old Tricks: Adds the Defunct Qakbot DGA. Key Points
https://www.zscaler.com/blogs/security-research/ares-banking-trojan-learns-old-tricks-adds-defunct-qakbot-dga
Threats:
Ares_rat
Qakbot
Kronos
Industry:
Financial
Geo:
Mexico
IOCs:
File: 2
Hash: 2
Url: 1
Algorithms:
crc, prng
Win API:
NtFreeVirtualMemory, NtSetInformationFile, NtUnmapViewOfSection, NtEnumerateValueKey, NtDebugActiveProcess, NtQueryKey, NtQueryObject, RtlFreeAnsiString, NtDuplicateObject, NtQueryInformationProcess, NtWriteVirtualMemory, NtQueryValueKey, NtQueryDirectoryFile, NtClose, NtDelayExecution, NtSuspendThread, lstrlenA, RtlDeregisterWaitEx, RtlInitUnicodeString, RtlAnsiStringToUnicodeString, NtMapViewOfSection, NtCreateFile, NtSetContextThread, NtOpenFile, RtlCreateUserThread, NtOpenProcess, NtQueryInformationFile, NtResumeThread, RtlFreeUnicodeString, NtGetContextThread, RtlRandomEx, RtlUnicodeStringToAnsiString, NtTerminateThread, RtlRegisterWait, NtDeleteFile, NtWriteFile, RtlCompareUnicodeString, NtReadVirtualMemory, NtQuerySystemInformationEx, NtQueryInformationThread, RtlInitAnsiString, lstrcatA, NtQueryVirtualMemory, NtAllocateVirtualMemory, NtOpenEvent, NtCreateKey, NtSetValueKey, NtDeleteValueKey, NtProtectVirtualMemory, NtCreateSection
Languages:
python, javascript
Links:
https://github.com/threatlabz/tools/tree/main/areshttps://github.com/Dan611/QakBot-DGA/blob/master/qakbot\_dga.chttps://github.com/threatlabz/iocs/tree/main/aresZscaler
Ares Banking Trojan adds the old Qakbot DGA | Zscaler
Zscaler ThreatLabz observed that the Ares banking trojan introduced a DGA, similar to Qakbot's. Find out more about it!
#ParsedReport
06-09-2022
Spyware Campaign Targeting The Uyghur Community
https://blog.cyble.com/2022/09/05/spyware-campaign-targeting-the-uyghur-community
Industry:
Financial, Government
Geo:
China, Georgia, India, Asia, Singapore, Dubai, Australia
TTPs:
Tactics: 4
Technics: 5
IOCs:
File: 1
Hash: 1
Softs:
android
06-09-2022
Spyware Campaign Targeting The Uyghur Community
https://blog.cyble.com/2022/09/05/spyware-campaign-targeting-the-uyghur-community
Industry:
Financial, Government
Geo:
China, Georgia, India, Asia, Singapore, Dubai, Australia
TTPs:
Tactics: 4
Technics: 5
IOCs:
File: 1
Hash: 1
Softs:
android
#ParsedReport
06-09-2022
SafeBreach Labs Researchers Uncover New Remote Access Trojan (RAT). CodeRAT Overview
https://www.safebreach.com/resources/blog/remote-access-trojan-coderat
Threats:
Coderat
Robothief
Antidebugging_technique
Industry:
Media, Government, E-commerce
Geo:
Irans, Iranian, Tehran, Iran
IOCs:
File: 9
Hash: 5
Softs:
android, microsoft office, microsoft word, microsoft powerpoint, instagram, windows media player, visual studio, telegram
Functions:
BossWatch, CheckBoss
Win API:
CryptUnprotectData
Languages:
python
Platforms:
x86
YARA: Found
Links:
06-09-2022
SafeBreach Labs Researchers Uncover New Remote Access Trojan (RAT). CodeRAT Overview
https://www.safebreach.com/resources/blog/remote-access-trojan-coderat
Threats:
Coderat
Robothief
Antidebugging_technique
Industry:
Media, Government, E-commerce
Geo:
Irans, Iranian, Tehran, Iran
IOCs:
File: 9
Hash: 5
Softs:
android, microsoft office, microsoft word, microsoft powerpoint, instagram, windows media player, visual studio, telegram
Functions:
BossWatch, CheckBoss
Win API:
CryptUnprotectData
Languages:
python
Platforms:
x86
YARA: Found
Links:
https://github.com/MrModed/DWMSafeBreach
SafeBreach Uncovers New Remote Access Trojan (RAT)
Dubbed CodeRAT, the new RAT is used in attacks targeting Farsi-speaking code developers using a Microsoft Dynamic Data Exchange (DDE) exploit.
#ParsedReport
06-09-2022
APTEvilnum. APT organization Evilnum launched a new round of network attacks on online transactions
https://mp.weixin.qq.com/s/1KIFSc3R5WrMklidXWSBaw
Actors/Campaigns:
Evilnum
Darkcasino
Threats:
Tron
Darkme
Agent_tesla
Formbook
Industry:
Entertainment, Financial
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 21
Domain: 3
Hash: 47
Url: 1
06-09-2022
APTEvilnum. APT organization Evilnum launched a new round of network attacks on online transactions
https://mp.weixin.qq.com/s/1KIFSc3R5WrMklidXWSBaw
Actors/Campaigns:
Evilnum
Darkcasino
Threats:
Tron
Darkme
Agent_tesla
Formbook
Industry:
Entertainment, Financial
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 21
Domain: 3
Hash: 47
Url: 1
Weixin Official Accounts Platform
APT็ป็ปEvilnumๅ่ตทๆฐไธ่ฝฎ้ๅฏนๅจ็บฟไบคๆ็็ฝ็ปๆปๅป
่ฟๆ๏ผ็ปฟ็็งๆไผๅฝฑๅฎ้ชๅฎคๆ่ทๅฐไธ็ณปๅไบ็ธๅ
ณ่็้้ฑผๆปๅปๆดปๅจใ็ป่ฟๅๆ๏ผไผๅฝฑๅฎ้ชๅฎค็กฎ่ฎค่ฟไบๆดปๅจๆฅ่ชAPT็ป็ปEvilnum๏ผๆฏ่ฏฅ็ป็ป่ฟๆ็ฝ็ปๆปๅป่กๅจDarkCasino็ๅปถ็ปญใ
#ParsedReport
06-09-2022
What Is Redeemer Ransomware and How Does It Spread: A Technical Analysis
https://cloudsek.com/what-is-redeemer-ransomware-and-how-does-it-spread-a-technical-analysis
Threats:
Redeemer
Pandora
Wevtutil_tool
Yourcyanide
Industry:
Financial
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 45
Path: 1
Hash: 2
Softs:
sqlagent, ntrtscan, dbsnmp, sqlbrowser, vssadmin, pccntmon, onenote, thebat, powerpnt, wordpad, encsvc, winlogon, thebat64
Algorithms:
base64, aes-256
Functions:
ReadMe, FindFirstFile, FindNextFile, SetFileAttributes
Win API:
ShellExecuteW, GetLogicalDrives, ShowWindow, SHGetFolderPath
06-09-2022
What Is Redeemer Ransomware and How Does It Spread: A Technical Analysis
https://cloudsek.com/what-is-redeemer-ransomware-and-how-does-it-spread-a-technical-analysis
Threats:
Redeemer
Pandora
Wevtutil_tool
Yourcyanide
Industry:
Financial
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 45
Path: 1
Hash: 2
Softs:
sqlagent, ntrtscan, dbsnmp, sqlbrowser, vssadmin, pccntmon, onenote, thebat, powerpnt, wordpad, encsvc, winlogon, thebat64
Algorithms:
base64, aes-256
Functions:
ReadMe, FindFirstFile, FindNextFile, SetFileAttributes
Win API:
ShellExecuteW, GetLogicalDrives, ShowWindow, SHGetFolderPath
Cloudsek
What Is Redeemer Ransomware and How Does It Spread: A Technical Analysis | CloudSEK
#ParsedReport
07-09-2022
Mirai Variant MooBot Targets RCE Vulnerabilities in D-Link Routers
https://socradar.io/moobot-targets-rce-vulnerabilities-in-d-link-routers
Threats:
Mirai
Moobot
Deadbolt
Industry:
Financial
Geo:
American
CVEs:
CVE-2022-28958 [Vulners]
Vulners: Score: 7.5, CVSS: 4.1,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Unavailable
Soft:
- dlink dir-816l firmware (206b01)
CVE-2022-26258 [Vulners]
Vulners: Score: 7.5, CVSS: 4.8,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.3
X-Force: Patch: Unavailable
Soft:
- dlink dir-820l firmware (1.05)
CVE-2018-6530 [Vulners]
Vulners: Score: 10.0, CVSS: 8.3,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- d-link dir-860l firmware (lea1_fw110b04)
- d-link dir-865l firmware (lereva_firmware_patch_1.08.b01)
- d-link dir-868l firmware (lea1_fw112b04)
- d-link dir-880l firmware (lereva_firmware_patch_1.08b04)
CVE-2015-2051 [Vulners]
Vulners: Score: 10.0, CVSS: 8.6,
Vulners: Exploitation: True
X-Force: Risk: 10
X-Force: Patch: Official fix
Soft:
- d-link dir-645 firmware (le1.04b12)
IOCs:
File: 2
Domain: 1
Url: 14
Hash: 13
Softs:
tiktok
Functions:
GetDeviceSettings
07-09-2022
Mirai Variant MooBot Targets RCE Vulnerabilities in D-Link Routers
https://socradar.io/moobot-targets-rce-vulnerabilities-in-d-link-routers
Threats:
Mirai
Moobot
Deadbolt
Industry:
Financial
Geo:
American
CVEs:
CVE-2022-28958 [Vulners]
Vulners: Score: 7.5, CVSS: 4.1,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Unavailable
Soft:
- dlink dir-816l firmware (206b01)
CVE-2022-26258 [Vulners]
Vulners: Score: 7.5, CVSS: 4.8,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.3
X-Force: Patch: Unavailable
Soft:
- dlink dir-820l firmware (1.05)
CVE-2018-6530 [Vulners]
Vulners: Score: 10.0, CVSS: 8.3,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- d-link dir-860l firmware (lea1_fw110b04)
- d-link dir-865l firmware (lereva_firmware_patch_1.08.b01)
- d-link dir-868l firmware (lea1_fw112b04)
- d-link dir-880l firmware (lereva_firmware_patch_1.08b04)
CVE-2015-2051 [Vulners]
Vulners: Score: 10.0, CVSS: 8.6,
Vulners: Exploitation: True
X-Force: Risk: 10
X-Force: Patch: Official fix
Soft:
- d-link dir-645 firmware (le1.04b12)
IOCs:
File: 2
Domain: 1
Url: 14
Hash: 13
Softs:
tiktok
Functions:
GetDeviceSettings
SOCRadarยฎ Cyber Intelligence Inc.
Mirai Variant MooBot Targets RCE Vulnerabilities in D-Link Routers
MooBot botnet is back for new attacks. The variant of the Mirai malware started a new campaign last month to exploit critical vulnerabilities.
#ParsedReport
07-09-2022
Initial access broker repurposing techniques in targeted attacks against Ukraine
https://blog.google/threat-analysis-group/initial-access-broker-repurposing-techniques-in-targeted-attacks-against-ukraine
Actors/Campaigns:
Wizard_spider (motivation: government_sponsored, financially_motivated)
Fin12
Threats:
Conti
Icedid
Anchormail
Lackeybuilder_tool
Trickbot
Cobalt_strike
Ettersilent_tool
Follina_vuln
Industry:
Healthcare, Government, Retail, Financial, Ngo
Geo:
Russian, Italy, India, Ukraine, Ukrainian
CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: 3.4,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...
IOCs:
Url: 16
Hash: 3
File: 6
Domain: 9
Email: 2
IP: 2
Algorithms:
zip
07-09-2022
Initial access broker repurposing techniques in targeted attacks against Ukraine
https://blog.google/threat-analysis-group/initial-access-broker-repurposing-techniques-in-targeted-attacks-against-ukraine
Actors/Campaigns:
Wizard_spider (motivation: government_sponsored, financially_motivated)
Fin12
Threats:
Conti
Icedid
Anchormail
Lackeybuilder_tool
Trickbot
Cobalt_strike
Ettersilent_tool
Follina_vuln
Industry:
Healthcare, Government, Retail, Financial, Ngo
Geo:
Russian, Italy, India, Ukraine, Ukrainian
CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: 3.4,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...
IOCs:
Url: 16
Hash: 3
File: 6
Domain: 9
Email: 2
IP: 2
Algorithms:
zip
Google
Initial access broker repurposing techniques in targeted attacks against Ukraine
Describing activities of a crime group attacking Ukraine.
#ParsedReport
07-09-2022
Sharkbot is back in Google Play
https://research.nccgroup.com/2022/09/06/sharkbot-is-back-in-google-play
Actors/Campaigns:
Fakeupdates
Threats:
Sharkbot
Industry:
Financial
Geo:
Poland, Austria, Spain, America, Germany, Australia, Italy
IOCs:
Url: 4
Hash: 2
IP: 1
Domain: 2
Softs:
android
Algorithms:
rc4, base64
07-09-2022
Sharkbot is back in Google Play
https://research.nccgroup.com/2022/09/06/sharkbot-is-back-in-google-play
Actors/Campaigns:
Fakeupdates
Threats:
Sharkbot
Industry:
Financial
Geo:
Poland, Austria, Spain, America, Germany, Australia, Italy
IOCs:
Url: 4
Hash: 2
IP: 1
Domain: 2
Softs:
android
Algorithms:
rc4, base64
NCC Group Research Blog
Sharkbot is back in Google Play
Authored by Alberto Segura (main author) and Mike Stokkel (co-author) Editorโs note: This post was originally published on the Fox-IT blog. Introduction After we discovered in February โฆ
#ParsedReport
07-09-2022
. Distributed phishing site disguised as a domestic groupware login site
https://asec.ahnlab.com/ko/38676
Geo:
Korean, Korea
IOCs:
File: 2
Url: 10
Languages:
javascript
07-09-2022
. Distributed phishing site disguised as a domestic groupware login site
https://asec.ahnlab.com/ko/38676
Geo:
Korean, Korea
IOCs:
File: 2
Url: 10
Languages:
javascript
ASEC BLOG
๊ตญ๋ด ๊ทธ๋ฃน์จ์ด ๋ก๊ทธ์ธ ์ฌ์ดํธ๋ก ์์ฅํ ํผ์ฑ ์ฌ์ดํธ ์ ํฌ - ASEC BLOG
ASEC ๋ถ์ํ์์๋ ๊ตญ๋ด๋ฟ๋ง ์๋๋ผ ํด์ธ์์ ์ ํฌ ์ค์ธ ๋ค์ํ ์
์ฑ์ฝ๋๋ฅผ ์์งํ๊ธฐ ์ํด ํ๋ํ์ ๊ตฌ์ถํ๊ณ ์๋ค. ์ด ํ๋ํ์ ํผ์ฑ ๋ฉ์ผ๋ ๊ฐ์ด ์์งํ๋๋ฐ ์ต๊ทผ 8์๋ถํฐ ํ๊ตญ ๊ณ์ ์๋ง ์ง์์ ์ผ๋ก ์ ํฌ ์ค์ธ ํ๊ตญ ํ๊ฒํ ํผ์ฑ ๋ฉ์ผ์ ํฌ์ฐฉํ์๋ค. ํด๋น ํผ์ฑ ์ฌ์ดํธ๋ ๊ตญ๋ด ๊ทธ๋ฃน์จ์ด์ ๋ก๊ทธ์ธ ์ฌ์ดํธ๋ฅผ ์์ฅํ ๊ฒ์ผ๋ก ๊ตญ๋ด์์ 2500๊ฑด ์ด์ ํด๋น ์ฌ์ดํธ์ ์ ๊ทผํ ์ด๋ ฅ์ด ํ์ธ๋์๋ค. ๋ฐ๋ผ์ ์ฌ์ฉ์๋ ๊ทธ๋ฃน์จ์ด ์ฌ์ดํธ์ ๋ก๊ทธ์ธ ์ ๊ฐ๋ณํ ์ฃผ์๊ฐ ํ์ํ๋ค. ํด๋น ํผ์ฑโฆ
#ParsedReport
07-09-2022
Worok: The big picture
https://www.welivesecurity.com/2022/09/06/worok-big-picture
Actors/Campaigns:
Worok (motivation: cyber_espionage)
Ta428
Threats:
Clrload
Powheartbeat
Pngload
Proxyshell_vuln
Shadowpad
Mimikatz
Earthworm_tool
Regeorg
Nbtscan_tool
Industry:
Telco, Energy, Financial, Government, Maritime
Geo:
Asia, Ukraine, Africa
CVEs:
CVE-2021-34523 [Vulners]
Vulners: Score: 7.5, CVSS: 3.4,
Vulners: Exploitation: True
X-Force: Risk: 9
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2013, 2019, 2016, 2016, 2019)
TTPs:
Tactics: 10
Technics: 28
IOCs:
Path: 13
Registry: 1
Hash: 23
IP: 3
File: 1
Domain: 2
Algorithms:
cbc, xor, base64, gzip, des
Functions:
GetUrl, Windows, CLRCreateInstance
Win API:
CorBindToRuntimeEx
Platforms:
x86
Links:
07-09-2022
Worok: The big picture
https://www.welivesecurity.com/2022/09/06/worok-big-picture
Actors/Campaigns:
Worok (motivation: cyber_espionage)
Ta428
Threats:
Clrload
Powheartbeat
Pngload
Proxyshell_vuln
Shadowpad
Mimikatz
Earthworm_tool
Regeorg
Nbtscan_tool
Industry:
Telco, Energy, Financial, Government, Maritime
Geo:
Asia, Ukraine, Africa
CVEs:
CVE-2021-34523 [Vulners]
Vulners: Score: 7.5, CVSS: 3.4,
Vulners: Exploitation: True
X-Force: Risk: 9
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2013, 2019, 2016, 2016, 2019)
TTPs:
Tactics: 10
Technics: 28
IOCs:
Path: 13
Registry: 1
Hash: 23
IP: 3
File: 1
Domain: 2
Algorithms:
cbc, xor, base64, gzip, des
Functions:
GetUrl, Windows, CLRCreateInstance
Win API:
CorBindToRuntimeEx
Platforms:
x86
Links:
https://github.com/charlesroelli/nbtscanhttps://github.com/sensepost/reGeorghttps://github.com/eset/malware-ioc/tree/master/worokWeLiveSecurity
Worok: The big picture
ESET Research has uncovered Worok, a new cyberespionage group that targets high-profile organizations based in Asia and operating in various sectors.
#ParsedReport
07-09-2022
Bumblebee Returns with New Infection Technique
https://blog.cyble.com/2022/09/07/bumblebee-returns-with-new-infection-technique
Threats:
Bumblebee
Powersploit
Bazarbackdoor
Beacon
Dll_sideloading_technique
Process_injection_technique
Geo:
Australia, Singapore, Dubai, Georgia, India
TTPs:
Tactics: 4
Technics: 10
IOCs:
File: 3
Path: 1
Hash: 5
Algorithms:
gzip, base64
Win API:
Decompress, ShowWindow
Links:
07-09-2022
Bumblebee Returns with New Infection Technique
https://blog.cyble.com/2022/09/07/bumblebee-returns-with-new-infection-technique
Threats:
Bumblebee
Powersploit
Bazarbackdoor
Beacon
Dll_sideloading_technique
Process_injection_technique
Geo:
Australia, Singapore, Dubai, Georgia, India
TTPs:
Tactics: 4
Technics: 10
IOCs:
File: 3
Path: 1
Hash: 5
Algorithms:
gzip, base64
Win API:
Decompress, ShowWindow
Links:
https://github.com/PowerShellMafia/PowerSploit/blob/master/CodeExecution/Invoke-ReflectivePEInjection.ps1https://github.com/PowerShellMafia/PowerSploitCyble
Cyble - Bumblebee Returns With New Infection Technique
Cyble Research & Intelligence Labs analyzes a new infection chain of the Bumblebee loader malware being distributed via spam campaigns.
#ParsedReport
07-09-2022
MagicRAT: Lazarus latest gateway into victim networks
http://blog.talosintelligence.com/2022/09/lazarus-magicrat.html
Actors/Campaigns:
Lazarus
Bytetiger
Threats:
Magicrat
Tiger_rat
Kisa
Bespoke
Dtrack_rat
Vsingle
Tiger_downloader
Skeleton_operation
Industry:
Government
Geo:
Korean, Korea
TTPs:
IOCs:
File: 5
Hash: 10
IP: 5
Url: 6
Softs:
vmware horizon
Algorithms:
base64
Links:
07-09-2022
MagicRAT: Lazarus latest gateway into victim networks
http://blog.talosintelligence.com/2022/09/lazarus-magicrat.html
Actors/Campaigns:
Lazarus
Bytetiger
Threats:
Magicrat
Tiger_rat
Kisa
Bespoke
Dtrack_rat
Vsingle
Tiger_downloader
Skeleton_operation
Industry:
Government
Geo:
Korean, Korea
TTPs:
IOCs:
File: 5
Hash: 10
IP: 5
Url: 6
Softs:
vmware horizon
Algorithms:
base64
Links:
https://github.com/Cisco-Talos/osquery\_queries/blob/master/win\_malware/magicrat\_file\_artifact.yamlCisco Talos Blog
MagicRAT: Lazarusโ latest gateway into victim networks
Cisco Talos has discovered a new remote access trojan (RAT) we're calling "MagicRAT," developed and operated by the Lazarus APT group, which the U.S. government believes is a North Korean state-sponsored actor.
#ParsedReport
07-09-2022
ASEC (20220829 \~ 20220904). ASEC Weekly Malware Statistics (20220829 \~ 20220904)
https://asec.ahnlab.com/ko/38557
Threats:
Cloudeye
Postealer
Formbook
Agent_tesla
Remcos_rat
Nanocore_rat
Azorult
Clipboard_grabbing_technique
Lokibot_stealer
Industry:
Transport, Financial
Geo:
Korea
IOCs:
File: 26
Url: 17
Domain: 4
IP: 3
Email: 6
Softs:
nsis installer, discord
Languages:
visual_basic, php
07-09-2022
ASEC (20220829 \~ 20220904). ASEC Weekly Malware Statistics (20220829 \~ 20220904)
https://asec.ahnlab.com/ko/38557
Threats:
Cloudeye
Postealer
Formbook
Agent_tesla
Remcos_rat
Nanocore_rat
Azorult
Clipboard_grabbing_technique
Lokibot_stealer
Industry:
Transport, Financial
Geo:
Korea
IOCs:
File: 26
Url: 17
Domain: 4
IP: 3
Email: 6
Softs:
nsis installer, discord
Languages:
visual_basic, php
ASEC BLOG
ASEC ์ฃผ๊ฐ ์
์ฑ์ฝ๋ ํต๊ณ (20220829 ~ 20220904) - ASEC BLOG
ASEC ๋ถ์ํ์์๋ ASEC ์๋ ๋ถ์ ์์คํ
RAPIT ์ ํ์ฉํ์ฌ ์๋ ค์ง ์
์ฑ์ฝ๋๋ค์ ๋ํ ๋ถ๋ฅ ๋ฐ ๋์์ ์งํํ๊ณ ์๋ค. ๋ณธ ํฌ์คํ
์์๋ 2022๋
8์ 29์ผ ์์์ผ๋ถํฐ 9์ 4์ผ ์ผ์์ผ๊น์ง ํ ์ฃผ๊ฐ ์์ง๋ ์
์ฑ์ฝ๋์ ํต๊ณ๋ฅผ ์ ๋ฆฌํ๋ค. ๋๋ถ๋ฅ ์์ผ๋ก๋ ์ธํฌ์คํธ๋ฌ๊ฐ 45.9%๋ก 1์๋ฅผ ์ฐจ์งํ์์ผ๋ฉฐ, ๊ทธ ๋ค์์ผ๋ก๋ ๋ค์ด๋ก๋ ์
์ฑ์ฝ๋๊ฐ 28.1%, ๋ฐฑ๋์ด 18.5%, ๋์ฌ์จ์ด 6.2%, ์ฝ์ธ๋ง์ด๋ ๋ฐ ๋ฑ
ํน ์
์ฑ์ฝ๋๊ฐ ๊ฐ๊ฐ 0.7%๋ก ์ง๊ณ๋์๋ค. Topโฆ