#ParsedReport
06-09-2022
[TA505\] TA505 Group's TeslaGun In-Depth Analysis
https://www.prodaft.com/resource/detail/ta505-ta505-groups-tesla-gun-depth-analysis
Actors/Campaigns:
Ta505 (motivation: financially_motivated)
06-09-2022
[TA505\] TA505 Group's TeslaGun In-Depth Analysis
https://www.prodaft.com/resource/detail/ta505-ta505-groups-tesla-gun-depth-analysis
Actors/Campaigns:
Ta505 (motivation: financially_motivated)
Prodaft
[TA505] TA505 Group's TeslaGun In-Depth Analysis - PRODAFT
Prodaft is a cyber threat intelligence company helping organizations to mitigate cyber threats. Our expert engineers put forth proactive defense mechanisms to safeguard your business from cyber attacks.
#ParsedReport
06-09-2022
The Ares Banking Trojan Learns Old Tricks: Adds the Defunct Qakbot DGA. Key Points
https://www.zscaler.com/blogs/security-research/ares-banking-trojan-learns-old-tricks-adds-defunct-qakbot-dga
Threats:
Ares_rat
Qakbot
Kronos
Industry:
Financial
Geo:
Mexico
IOCs:
File: 2
Hash: 2
Url: 1
Algorithms:
crc, prng
Win API:
NtFreeVirtualMemory, NtSetInformationFile, NtUnmapViewOfSection, NtEnumerateValueKey, NtDebugActiveProcess, NtQueryKey, NtQueryObject, RtlFreeAnsiString, NtDuplicateObject, NtQueryInformationProcess, NtWriteVirtualMemory, NtQueryValueKey, NtQueryDirectoryFile, NtClose, NtDelayExecution, NtSuspendThread, lstrlenA, RtlDeregisterWaitEx, RtlInitUnicodeString, RtlAnsiStringToUnicodeString, NtMapViewOfSection, NtCreateFile, NtSetContextThread, NtOpenFile, RtlCreateUserThread, NtOpenProcess, NtQueryInformationFile, NtResumeThread, RtlFreeUnicodeString, NtGetContextThread, RtlRandomEx, RtlUnicodeStringToAnsiString, NtTerminateThread, RtlRegisterWait, NtDeleteFile, NtWriteFile, RtlCompareUnicodeString, NtReadVirtualMemory, NtQuerySystemInformationEx, NtQueryInformationThread, RtlInitAnsiString, lstrcatA, NtQueryVirtualMemory, NtAllocateVirtualMemory, NtOpenEvent, NtCreateKey, NtSetValueKey, NtDeleteValueKey, NtProtectVirtualMemory, NtCreateSection
Languages:
python, javascript
Links:
06-09-2022
The Ares Banking Trojan Learns Old Tricks: Adds the Defunct Qakbot DGA. Key Points
https://www.zscaler.com/blogs/security-research/ares-banking-trojan-learns-old-tricks-adds-defunct-qakbot-dga
Threats:
Ares_rat
Qakbot
Kronos
Industry:
Financial
Geo:
Mexico
IOCs:
File: 2
Hash: 2
Url: 1
Algorithms:
crc, prng
Win API:
NtFreeVirtualMemory, NtSetInformationFile, NtUnmapViewOfSection, NtEnumerateValueKey, NtDebugActiveProcess, NtQueryKey, NtQueryObject, RtlFreeAnsiString, NtDuplicateObject, NtQueryInformationProcess, NtWriteVirtualMemory, NtQueryValueKey, NtQueryDirectoryFile, NtClose, NtDelayExecution, NtSuspendThread, lstrlenA, RtlDeregisterWaitEx, RtlInitUnicodeString, RtlAnsiStringToUnicodeString, NtMapViewOfSection, NtCreateFile, NtSetContextThread, NtOpenFile, RtlCreateUserThread, NtOpenProcess, NtQueryInformationFile, NtResumeThread, RtlFreeUnicodeString, NtGetContextThread, RtlRandomEx, RtlUnicodeStringToAnsiString, NtTerminateThread, RtlRegisterWait, NtDeleteFile, NtWriteFile, RtlCompareUnicodeString, NtReadVirtualMemory, NtQuerySystemInformationEx, NtQueryInformationThread, RtlInitAnsiString, lstrcatA, NtQueryVirtualMemory, NtAllocateVirtualMemory, NtOpenEvent, NtCreateKey, NtSetValueKey, NtDeleteValueKey, NtProtectVirtualMemory, NtCreateSection
Languages:
python, javascript
Links:
https://github.com/threatlabz/tools/tree/main/areshttps://github.com/Dan611/QakBot-DGA/blob/master/qakbot\_dga.chttps://github.com/threatlabz/iocs/tree/main/aresZscaler
Ares Banking Trojan adds the old Qakbot DGA | Zscaler
Zscaler ThreatLabz observed that the Ares banking trojan introduced a DGA, similar to Qakbot's. Find out more about it!
#ParsedReport
06-09-2022
Spyware Campaign Targeting The Uyghur Community
https://blog.cyble.com/2022/09/05/spyware-campaign-targeting-the-uyghur-community
Industry:
Financial, Government
Geo:
China, Georgia, India, Asia, Singapore, Dubai, Australia
TTPs:
Tactics: 4
Technics: 5
IOCs:
File: 1
Hash: 1
Softs:
android
06-09-2022
Spyware Campaign Targeting The Uyghur Community
https://blog.cyble.com/2022/09/05/spyware-campaign-targeting-the-uyghur-community
Industry:
Financial, Government
Geo:
China, Georgia, India, Asia, Singapore, Dubai, Australia
TTPs:
Tactics: 4
Technics: 5
IOCs:
File: 1
Hash: 1
Softs:
android
#ParsedReport
06-09-2022
SafeBreach Labs Researchers Uncover New Remote Access Trojan (RAT). CodeRAT Overview
https://www.safebreach.com/resources/blog/remote-access-trojan-coderat
Threats:
Coderat
Robothief
Antidebugging_technique
Industry:
Media, Government, E-commerce
Geo:
Irans, Iranian, Tehran, Iran
IOCs:
File: 9
Hash: 5
Softs:
android, microsoft office, microsoft word, microsoft powerpoint, instagram, windows media player, visual studio, telegram
Functions:
BossWatch, CheckBoss
Win API:
CryptUnprotectData
Languages:
python
Platforms:
x86
YARA: Found
Links:
06-09-2022
SafeBreach Labs Researchers Uncover New Remote Access Trojan (RAT). CodeRAT Overview
https://www.safebreach.com/resources/blog/remote-access-trojan-coderat
Threats:
Coderat
Robothief
Antidebugging_technique
Industry:
Media, Government, E-commerce
Geo:
Irans, Iranian, Tehran, Iran
IOCs:
File: 9
Hash: 5
Softs:
android, microsoft office, microsoft word, microsoft powerpoint, instagram, windows media player, visual studio, telegram
Functions:
BossWatch, CheckBoss
Win API:
CryptUnprotectData
Languages:
python
Platforms:
x86
YARA: Found
Links:
https://github.com/MrModed/DWMSafeBreach
SafeBreach Uncovers New Remote Access Trojan (RAT)
Dubbed CodeRAT, the new RAT is used in attacks targeting Farsi-speaking code developers using a Microsoft Dynamic Data Exchange (DDE) exploit.
#ParsedReport
06-09-2022
APTEvilnum. APT organization Evilnum launched a new round of network attacks on online transactions
https://mp.weixin.qq.com/s/1KIFSc3R5WrMklidXWSBaw
Actors/Campaigns:
Evilnum
Darkcasino
Threats:
Tron
Darkme
Agent_tesla
Formbook
Industry:
Entertainment, Financial
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 21
Domain: 3
Hash: 47
Url: 1
06-09-2022
APTEvilnum. APT organization Evilnum launched a new round of network attacks on online transactions
https://mp.weixin.qq.com/s/1KIFSc3R5WrMklidXWSBaw
Actors/Campaigns:
Evilnum
Darkcasino
Threats:
Tron
Darkme
Agent_tesla
Formbook
Industry:
Entertainment, Financial
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 21
Domain: 3
Hash: 47
Url: 1
Weixin Official Accounts Platform
APT组织Evilnum发起新一轮针对在线交易的网络攻击
近期,绿盟科技伏影实验室捕获到一系列互相关联的钓鱼攻击活动。经过分析,伏影实验室确认这些活动来自APT组织Evilnum,是该组织近期网络攻击行动DarkCasino的延续。
#ParsedReport
06-09-2022
What Is Redeemer Ransomware and How Does It Spread: A Technical Analysis
https://cloudsek.com/what-is-redeemer-ransomware-and-how-does-it-spread-a-technical-analysis
Threats:
Redeemer
Pandora
Wevtutil_tool
Yourcyanide
Industry:
Financial
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 45
Path: 1
Hash: 2
Softs:
sqlagent, ntrtscan, dbsnmp, sqlbrowser, vssadmin, pccntmon, onenote, thebat, powerpnt, wordpad, encsvc, winlogon, thebat64
Algorithms:
base64, aes-256
Functions:
ReadMe, FindFirstFile, FindNextFile, SetFileAttributes
Win API:
ShellExecuteW, GetLogicalDrives, ShowWindow, SHGetFolderPath
06-09-2022
What Is Redeemer Ransomware and How Does It Spread: A Technical Analysis
https://cloudsek.com/what-is-redeemer-ransomware-and-how-does-it-spread-a-technical-analysis
Threats:
Redeemer
Pandora
Wevtutil_tool
Yourcyanide
Industry:
Financial
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 45
Path: 1
Hash: 2
Softs:
sqlagent, ntrtscan, dbsnmp, sqlbrowser, vssadmin, pccntmon, onenote, thebat, powerpnt, wordpad, encsvc, winlogon, thebat64
Algorithms:
base64, aes-256
Functions:
ReadMe, FindFirstFile, FindNextFile, SetFileAttributes
Win API:
ShellExecuteW, GetLogicalDrives, ShowWindow, SHGetFolderPath
Cloudsek
What Is Redeemer Ransomware and How Does It Spread: A Technical Analysis | CloudSEK
#ParsedReport
07-09-2022
Mirai Variant MooBot Targets RCE Vulnerabilities in D-Link Routers
https://socradar.io/moobot-targets-rce-vulnerabilities-in-d-link-routers
Threats:
Mirai
Moobot
Deadbolt
Industry:
Financial
Geo:
American
CVEs:
CVE-2022-28958 [Vulners]
Vulners: Score: 7.5, CVSS: 4.1,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Unavailable
Soft:
- dlink dir-816l firmware (206b01)
CVE-2022-26258 [Vulners]
Vulners: Score: 7.5, CVSS: 4.8,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.3
X-Force: Patch: Unavailable
Soft:
- dlink dir-820l firmware (1.05)
CVE-2018-6530 [Vulners]
Vulners: Score: 10.0, CVSS: 8.3,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- d-link dir-860l firmware (lea1_fw110b04)
- d-link dir-865l firmware (lereva_firmware_patch_1.08.b01)
- d-link dir-868l firmware (lea1_fw112b04)
- d-link dir-880l firmware (lereva_firmware_patch_1.08b04)
CVE-2015-2051 [Vulners]
Vulners: Score: 10.0, CVSS: 8.6,
Vulners: Exploitation: True
X-Force: Risk: 10
X-Force: Patch: Official fix
Soft:
- d-link dir-645 firmware (le1.04b12)
IOCs:
File: 2
Domain: 1
Url: 14
Hash: 13
Softs:
tiktok
Functions:
GetDeviceSettings
07-09-2022
Mirai Variant MooBot Targets RCE Vulnerabilities in D-Link Routers
https://socradar.io/moobot-targets-rce-vulnerabilities-in-d-link-routers
Threats:
Mirai
Moobot
Deadbolt
Industry:
Financial
Geo:
American
CVEs:
CVE-2022-28958 [Vulners]
Vulners: Score: 7.5, CVSS: 4.1,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Unavailable
Soft:
- dlink dir-816l firmware (206b01)
CVE-2022-26258 [Vulners]
Vulners: Score: 7.5, CVSS: 4.8,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.3
X-Force: Patch: Unavailable
Soft:
- dlink dir-820l firmware (1.05)
CVE-2018-6530 [Vulners]
Vulners: Score: 10.0, CVSS: 8.3,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- d-link dir-860l firmware (lea1_fw110b04)
- d-link dir-865l firmware (lereva_firmware_patch_1.08.b01)
- d-link dir-868l firmware (lea1_fw112b04)
- d-link dir-880l firmware (lereva_firmware_patch_1.08b04)
CVE-2015-2051 [Vulners]
Vulners: Score: 10.0, CVSS: 8.6,
Vulners: Exploitation: True
X-Force: Risk: 10
X-Force: Patch: Official fix
Soft:
- d-link dir-645 firmware (le1.04b12)
IOCs:
File: 2
Domain: 1
Url: 14
Hash: 13
Softs:
tiktok
Functions:
GetDeviceSettings
SOCRadar® Cyber Intelligence Inc.
Mirai Variant MooBot Targets RCE Vulnerabilities in D-Link Routers
MooBot botnet is back for new attacks. The variant of the Mirai malware started a new campaign last month to exploit critical vulnerabilities.
#ParsedReport
07-09-2022
Initial access broker repurposing techniques in targeted attacks against Ukraine
https://blog.google/threat-analysis-group/initial-access-broker-repurposing-techniques-in-targeted-attacks-against-ukraine
Actors/Campaigns:
Wizard_spider (motivation: government_sponsored, financially_motivated)
Fin12
Threats:
Conti
Icedid
Anchormail
Lackeybuilder_tool
Trickbot
Cobalt_strike
Ettersilent_tool
Follina_vuln
Industry:
Healthcare, Government, Retail, Financial, Ngo
Geo:
Russian, Italy, India, Ukraine, Ukrainian
CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: 3.4,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...
IOCs:
Url: 16
Hash: 3
File: 6
Domain: 9
Email: 2
IP: 2
Algorithms:
zip
07-09-2022
Initial access broker repurposing techniques in targeted attacks against Ukraine
https://blog.google/threat-analysis-group/initial-access-broker-repurposing-techniques-in-targeted-attacks-against-ukraine
Actors/Campaigns:
Wizard_spider (motivation: government_sponsored, financially_motivated)
Fin12
Threats:
Conti
Icedid
Anchormail
Lackeybuilder_tool
Trickbot
Cobalt_strike
Ettersilent_tool
Follina_vuln
Industry:
Healthcare, Government, Retail, Financial, Ngo
Geo:
Russian, Italy, India, Ukraine, Ukrainian
CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: 3.4,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...
IOCs:
Url: 16
Hash: 3
File: 6
Domain: 9
Email: 2
IP: 2
Algorithms:
zip
Google
Initial access broker repurposing techniques in targeted attacks against Ukraine
Describing activities of a crime group attacking Ukraine.
#ParsedReport
07-09-2022
Sharkbot is back in Google Play
https://research.nccgroup.com/2022/09/06/sharkbot-is-back-in-google-play
Actors/Campaigns:
Fakeupdates
Threats:
Sharkbot
Industry:
Financial
Geo:
Poland, Austria, Spain, America, Germany, Australia, Italy
IOCs:
Url: 4
Hash: 2
IP: 1
Domain: 2
Softs:
android
Algorithms:
rc4, base64
07-09-2022
Sharkbot is back in Google Play
https://research.nccgroup.com/2022/09/06/sharkbot-is-back-in-google-play
Actors/Campaigns:
Fakeupdates
Threats:
Sharkbot
Industry:
Financial
Geo:
Poland, Austria, Spain, America, Germany, Australia, Italy
IOCs:
Url: 4
Hash: 2
IP: 1
Domain: 2
Softs:
android
Algorithms:
rc4, base64
NCC Group Research Blog
Sharkbot is back in Google Play
Authored by Alberto Segura (main author) and Mike Stokkel (co-author) Editor’s note: This post was originally published on the Fox-IT blog. Introduction After we discovered in February …
#ParsedReport
07-09-2022
. Distributed phishing site disguised as a domestic groupware login site
https://asec.ahnlab.com/ko/38676
Geo:
Korean, Korea
IOCs:
File: 2
Url: 10
Languages:
javascript
07-09-2022
. Distributed phishing site disguised as a domestic groupware login site
https://asec.ahnlab.com/ko/38676
Geo:
Korean, Korea
IOCs:
File: 2
Url: 10
Languages:
javascript
ASEC BLOG
국내 그룹웨어 로그인 사이트로 위장한 피싱 사이트 유포 - ASEC BLOG
ASEC 분석팀에서는 국내뿐만 아니라 해외에서 유포 중인 다양한 악성코드를 수집하기 위해 허니팟을 구축하고 있다. 이 허니팟은 피싱 메일도 같이 수집하는데 최근 8월부터 한국 계정에만 지속적으로 유포 중인 한국 타겟형 피싱 메일을 포착하였다. 해당 피싱 사이트는 국내 그룹웨어의 로그인 사이트를 위장한 것으로 국내에서 2500건 이상 해당 사이트에 접근한 이력이 확인되었다. 따라서 사용자는 그룹웨어 사이트에 로그인 시 각별한 주의가 필요하다. 해당 피싱…
#ParsedReport
07-09-2022
Worok: The big picture
https://www.welivesecurity.com/2022/09/06/worok-big-picture
Actors/Campaigns:
Worok (motivation: cyber_espionage)
Ta428
Threats:
Clrload
Powheartbeat
Pngload
Proxyshell_vuln
Shadowpad
Mimikatz
Earthworm_tool
Regeorg
Nbtscan_tool
Industry:
Telco, Energy, Financial, Government, Maritime
Geo:
Asia, Ukraine, Africa
CVEs:
CVE-2021-34523 [Vulners]
Vulners: Score: 7.5, CVSS: 3.4,
Vulners: Exploitation: True
X-Force: Risk: 9
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2013, 2019, 2016, 2016, 2019)
TTPs:
Tactics: 10
Technics: 28
IOCs:
Path: 13
Registry: 1
Hash: 23
IP: 3
File: 1
Domain: 2
Algorithms:
cbc, xor, base64, gzip, des
Functions:
GetUrl, Windows, CLRCreateInstance
Win API:
CorBindToRuntimeEx
Platforms:
x86
Links:
07-09-2022
Worok: The big picture
https://www.welivesecurity.com/2022/09/06/worok-big-picture
Actors/Campaigns:
Worok (motivation: cyber_espionage)
Ta428
Threats:
Clrload
Powheartbeat
Pngload
Proxyshell_vuln
Shadowpad
Mimikatz
Earthworm_tool
Regeorg
Nbtscan_tool
Industry:
Telco, Energy, Financial, Government, Maritime
Geo:
Asia, Ukraine, Africa
CVEs:
CVE-2021-34523 [Vulners]
Vulners: Score: 7.5, CVSS: 3.4,
Vulners: Exploitation: True
X-Force: Risk: 9
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2013, 2019, 2016, 2016, 2019)
TTPs:
Tactics: 10
Technics: 28
IOCs:
Path: 13
Registry: 1
Hash: 23
IP: 3
File: 1
Domain: 2
Algorithms:
cbc, xor, base64, gzip, des
Functions:
GetUrl, Windows, CLRCreateInstance
Win API:
CorBindToRuntimeEx
Platforms:
x86
Links:
https://github.com/charlesroelli/nbtscanhttps://github.com/sensepost/reGeorghttps://github.com/eset/malware-ioc/tree/master/worokWeLiveSecurity
Worok: The big picture
ESET Research has uncovered Worok, a new cyberespionage group that targets high-profile organizations based in Asia and operating in various sectors.
#ParsedReport
07-09-2022
Bumblebee Returns with New Infection Technique
https://blog.cyble.com/2022/09/07/bumblebee-returns-with-new-infection-technique
Threats:
Bumblebee
Powersploit
Bazarbackdoor
Beacon
Dll_sideloading_technique
Process_injection_technique
Geo:
Australia, Singapore, Dubai, Georgia, India
TTPs:
Tactics: 4
Technics: 10
IOCs:
File: 3
Path: 1
Hash: 5
Algorithms:
gzip, base64
Win API:
Decompress, ShowWindow
Links:
07-09-2022
Bumblebee Returns with New Infection Technique
https://blog.cyble.com/2022/09/07/bumblebee-returns-with-new-infection-technique
Threats:
Bumblebee
Powersploit
Bazarbackdoor
Beacon
Dll_sideloading_technique
Process_injection_technique
Geo:
Australia, Singapore, Dubai, Georgia, India
TTPs:
Tactics: 4
Technics: 10
IOCs:
File: 3
Path: 1
Hash: 5
Algorithms:
gzip, base64
Win API:
Decompress, ShowWindow
Links:
https://github.com/PowerShellMafia/PowerSploit/blob/master/CodeExecution/Invoke-ReflectivePEInjection.ps1https://github.com/PowerShellMafia/PowerSploitCyble
Cyble - Bumblebee Returns With New Infection Technique
Cyble Research & Intelligence Labs analyzes a new infection chain of the Bumblebee loader malware being distributed via spam campaigns.
#ParsedReport
07-09-2022
MagicRAT: Lazarus latest gateway into victim networks
http://blog.talosintelligence.com/2022/09/lazarus-magicrat.html
Actors/Campaigns:
Lazarus
Bytetiger
Threats:
Magicrat
Tiger_rat
Kisa
Bespoke
Dtrack_rat
Vsingle
Tiger_downloader
Skeleton_operation
Industry:
Government
Geo:
Korean, Korea
TTPs:
IOCs:
File: 5
Hash: 10
IP: 5
Url: 6
Softs:
vmware horizon
Algorithms:
base64
Links:
07-09-2022
MagicRAT: Lazarus latest gateway into victim networks
http://blog.talosintelligence.com/2022/09/lazarus-magicrat.html
Actors/Campaigns:
Lazarus
Bytetiger
Threats:
Magicrat
Tiger_rat
Kisa
Bespoke
Dtrack_rat
Vsingle
Tiger_downloader
Skeleton_operation
Industry:
Government
Geo:
Korean, Korea
TTPs:
IOCs:
File: 5
Hash: 10
IP: 5
Url: 6
Softs:
vmware horizon
Algorithms:
base64
Links:
https://github.com/Cisco-Talos/osquery\_queries/blob/master/win\_malware/magicrat\_file\_artifact.yamlCisco Talos Blog
MagicRAT: Lazarus’ latest gateway into victim networks
Cisco Talos has discovered a new remote access trojan (RAT) we're calling "MagicRAT," developed and operated by the Lazarus APT group, which the U.S. government believes is a North Korean state-sponsored actor.
#ParsedReport
07-09-2022
ASEC (20220829 \~ 20220904). ASEC Weekly Malware Statistics (20220829 \~ 20220904)
https://asec.ahnlab.com/ko/38557
Threats:
Cloudeye
Postealer
Formbook
Agent_tesla
Remcos_rat
Nanocore_rat
Azorult
Clipboard_grabbing_technique
Lokibot_stealer
Industry:
Transport, Financial
Geo:
Korea
IOCs:
File: 26
Url: 17
Domain: 4
IP: 3
Email: 6
Softs:
nsis installer, discord
Languages:
visual_basic, php
07-09-2022
ASEC (20220829 \~ 20220904). ASEC Weekly Malware Statistics (20220829 \~ 20220904)
https://asec.ahnlab.com/ko/38557
Threats:
Cloudeye
Postealer
Formbook
Agent_tesla
Remcos_rat
Nanocore_rat
Azorult
Clipboard_grabbing_technique
Lokibot_stealer
Industry:
Transport, Financial
Geo:
Korea
IOCs:
File: 26
Url: 17
Domain: 4
IP: 3
Email: 6
Softs:
nsis installer, discord
Languages:
visual_basic, php
ASEC BLOG
ASEC 주간 악성코드 통계 (20220829 ~ 20220904) - ASEC BLOG
ASEC 분석팀에서는 ASEC 자동 분석 시스템 RAPIT 을 활용하여 알려진 악성코드들에 대한 분류 및 대응을 진행하고 있다. 본 포스팅에서는 2022년 8월 29일 월요일부터 9월 4일 일요일까지 한 주간 수집된 악성코드의 통계를 정리한다. 대분류 상으로는 인포스틸러가 45.9%로 1위를 차지하였으며, 그 다음으로는 다운로더 악성코드가 28.1%, 백도어 18.5%, 랜섬웨어 6.2%, 코인마이너 및 뱅킹 악성코드가 각각 0.7%로 집계되었다. Top…
Кажется, pornhub запустил краудсорсинговую кампанию )))
https://www.malwarebytes.com/blog/news/2022/09/sextortionists-used-mobile-malware-to-steal-nude-videos-contact-lists-from-victims
https://www.malwarebytes.com/blog/news/2022/09/sextortionists-used-mobile-malware-to-steal-nude-videos-contact-lists-from-victims
Malwarebytes
Sextortionists used mobile malware to steal nude videos, contact lists from victims
In an international police action supported by Interpol, law enforcement agencies have uncovered and dismantled an international sextortion ring.
#ParsedReport
08-09-2022
THREAT ANALYSIS REPORT: PlugX RAT Loader Evolution
https://www.cybereason.com/blog/threat-analysis-report-plugx-rat-loader-evolution
Actors/Campaigns:
Emissary_panda
Threats:
Plugx_rat
Dll_sideloading_technique
Proxylogon_exploit
Thor
Industry:
Aerospace, Government
Geo:
China, Belarus, Ukrainian, Asia, Russia, Asian
TTPs:
Tactics: 6
Technics: 0
IOCs:
Hash: 18
File: 3
Algorithms:
rc4
Win API:
GetSystemTime, VirtualFree, VirtualProtect, LoadLibraryA, GetProcAddress, VirtualAlloc, NtGlobalFlag, ExitThread, RtlDecompressBuffer
08-09-2022
THREAT ANALYSIS REPORT: PlugX RAT Loader Evolution
https://www.cybereason.com/blog/threat-analysis-report-plugx-rat-loader-evolution
Actors/Campaigns:
Emissary_panda
Threats:
Plugx_rat
Dll_sideloading_technique
Proxylogon_exploit
Thor
Industry:
Aerospace, Government
Geo:
China, Belarus, Ukrainian, Asia, Russia, Asian
TTPs:
Tactics: 6
Technics: 0
IOCs:
Hash: 18
File: 3
Algorithms:
rc4
Win API:
GetSystemTime, VirtualFree, VirtualProtect, LoadLibraryA, GetProcAddress, VirtualAlloc, NtGlobalFlag, ExitThread, RtlDecompressBuffer
Cybereason
THREAT ANALYSIS REPORT: PlugX RAT Loader Evolution
PlugX is a post-exploitation modular RAT (Remote Access Trojan), which is known for its multiple functionalities such as data exfiltration, keystroke grabbing, backdoor functionality, and utilizing DLL-Sideloading techniques for evading security solutions...
#ParsedReport
08-09-2022
Warning issued about Vice Society ransomware targeting the education sector
https://www.malwarebytes.com/blog/news/2022/09/authorities-issue-warning-about-vice-society-ransomware-targeting-the-education-sector
Actors/Campaigns:
Vice_society
Threats:
Medusalocker
Zeppelin
Hellokitty
Printnightmare_vuln
Empire_loader
Cobalt_strike
Systembc
Industry:
Education
Geo:
Russian
08-09-2022
Warning issued about Vice Society ransomware targeting the education sector
https://www.malwarebytes.com/blog/news/2022/09/authorities-issue-warning-about-vice-society-ransomware-targeting-the-education-sector
Actors/Campaigns:
Vice_society
Threats:
Medusalocker
Zeppelin
Hellokitty
Printnightmare_vuln
Empire_loader
Cobalt_strike
Systembc
Industry:
Education
Geo:
Russian
ThreatDown by Malwarebytes
Warning issued about Vice Society ransomware targeting the education sector - ThreatDown by Malwarebytes
The Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), and the Multi-State Information Sharing and Analysis Center (MS-ISAC) have released a joint…
#ParsedReport
08-09-2022
The Rise in Incidence of Fake e-shop Scams
https://blog.cyble.com/2022/09/08/the-rise-in-incidence-of-fake-e-shop-scams
Industry:
E-commerce, Energy, Media, Financial
Geo:
Georgia, Malaysia, Singapore, Malaysian, Australia, Dubai, Vietnam, India
TTPs:
Tactics: 5
Technics: 6
IOCs:
Url: 77
File: 1
Hash: 2
Softs:
android
08-09-2022
The Rise in Incidence of Fake e-shop Scams
https://blog.cyble.com/2022/09/08/the-rise-in-incidence-of-fake-e-shop-scams
Industry:
E-commerce, Energy, Media, Financial
Geo:
Georgia, Malaysia, Singapore, Malaysian, Australia, Dubai, Vietnam, India
TTPs:
Tactics: 5
Technics: 6
IOCs:
Url: 77
File: 1
Hash: 2
Softs:
android
#ParsedReport
08-09-2022
Microsoft investigates Iranian attacks against the Albanian government
https://www.microsoft.com/security/blog/2022/09/08/microsoft-investigates-iranian-attacks-against-the-albanian-government
Actors/Campaigns:
Dev-0861
Dev-0166
Siamesekitten
Europium
Threats:
Zerocleare_wiper
Hostile
Credential_harvesting_technique
Mimikatz
Impacket_tool
Trojan:win32/batrungoxml
Ransom:win32/eagle!msr
Trojan:win32/debitom.a
Proxylogon_exploit
Industry:
Ngo, Aerospace, Transport, Petroleum, Government, Healthcare, Telco, Energy
Geo:
Kuwait, Turkey, Irans, Albania, Tehrans, Tehran, American, Iranians, Jordan, Iran, Iranian, Israel
CVEs:
CVE-2021-26855 [Vulners]
Vulners: Score: 7.5, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 9.1
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2016, 2016, 2013, 2016, 2016, 2013, 2016, 2019, 2013, 2016, 2016, 2016, 2016, 2016, 2016, 2016, 2019, 2019, 2019, 2019, 2019, 2019, 2019, 2019)
CVE-2019-0604 [Vulners]
Vulners: Score: 7.5, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- microsoft sharepoint foundation (2013)
- microsoft sharepoint server (2019, 2010)
- microsoft sharepoint enterprise server (2016)
TTPs:
Tactics: 3
Technics: 0
IOCs:
IP: 8
File: 11
Hash: 21
Path: 8
Coin: 1
Registry: 1
Softs:
microsoft exchange, winlogon, microsoft defender, microsoft 365 defender, microsoft defender for endpoint, sharepoint server
Algorithms:
base64, zip, rc4
Functions:
rand
Win API:
SeDebugPrivilege, FindFirstVolumeW, GetOpenFileNameA, GetVolumePathNamesForVolumeNameW, CreateMutexA, SeImpersonatePrivilege, GetTokenInformation, CreateProcessWithTokenW, FindNextVolumeW, SetVolumeMountPointW, CreateDirectoryW
YARA: Found
08-09-2022
Microsoft investigates Iranian attacks against the Albanian government
https://www.microsoft.com/security/blog/2022/09/08/microsoft-investigates-iranian-attacks-against-the-albanian-government
Actors/Campaigns:
Dev-0861
Dev-0166
Siamesekitten
Europium
Threats:
Zerocleare_wiper
Hostile
Credential_harvesting_technique
Mimikatz
Impacket_tool
Trojan:win32/batrungoxml
Ransom:win32/eagle!msr
Trojan:win32/debitom.a
Proxylogon_exploit
Industry:
Ngo, Aerospace, Transport, Petroleum, Government, Healthcare, Telco, Energy
Geo:
Kuwait, Turkey, Irans, Albania, Tehrans, Tehran, American, Iranians, Jordan, Iran, Iranian, Israel
CVEs:
CVE-2021-26855 [Vulners]
Vulners: Score: 7.5, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 9.1
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2016, 2016, 2013, 2016, 2016, 2013, 2016, 2019, 2013, 2016, 2016, 2016, 2016, 2016, 2016, 2016, 2019, 2019, 2019, 2019, 2019, 2019, 2019, 2019)
CVE-2019-0604 [Vulners]
Vulners: Score: 7.5, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- microsoft sharepoint foundation (2013)
- microsoft sharepoint server (2019, 2010)
- microsoft sharepoint enterprise server (2016)
TTPs:
Tactics: 3
Technics: 0
IOCs:
IP: 8
File: 11
Hash: 21
Path: 8
Coin: 1
Registry: 1
Softs:
microsoft exchange, winlogon, microsoft defender, microsoft 365 defender, microsoft defender for endpoint, sharepoint server
Algorithms:
base64, zip, rc4
Functions:
rand
Win API:
SeDebugPrivilege, FindFirstVolumeW, GetOpenFileNameA, GetVolumePathNamesForVolumeNameW, CreateMutexA, SeImpersonatePrivilege, GetTokenInformation, CreateProcessWithTokenW, FindNextVolumeW, SetVolumeMountPointW, CreateDirectoryW
YARA: Found
Microsoft News
Microsoft investigates Iranian attacks against the Albanian government
Shortly after the destructive cyberattacks on the Albanian government in mid-July, the Microsoft Detection and Response Team (DART) was engaged to lead an investigation into the attacks.
#ParsedReport
08-09-2022
Raccoon Stealer 2.0 Malware analysis
https://any.run/cybersecurity-blog/raccoon-stealer-v2-malware-analysis/?utm_source=linkedin
Threats:
Raccoon_stealer
Recordbreaker_stealer
Follina_vuln
Industry:
Financial
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 4
Hash: 17
Registry: 1
Softs:
jaxx, tronlink, binancechain, telegram, jaxxliberty, chrome
Algorithms:
base64, xor, rc4
Functions:
x64-specific
Win API:
NtQueryInformationProcess
Languages:
python
Links:
08-09-2022
Raccoon Stealer 2.0 Malware analysis
https://any.run/cybersecurity-blog/raccoon-stealer-v2-malware-analysis/?utm_source=linkedin
Threats:
Raccoon_stealer
Recordbreaker_stealer
Follina_vuln
Industry:
Financial
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 4
Hash: 17
Registry: 1
Softs:
jaxx, tronlink, binancechain, telegram, jaxxliberty, chrome
Algorithms:
base64, xor, rc4
Functions:
x64-specific
Win API:
NtQueryInformationProcess
Languages:
python
Links:
https://github.com/mrexodia/TitanHide/commit/6a5a68a2447ad9454adfcbd9390ec05b9dcef2d6https://github.com/mrexodia/TitanHide/issues/70ANY.RUN's Cybersecurity Blog
Raccoon Stealer 2.0 Malware analysis - ANY.RUN's Cybersecurity Blog
ANY.RUN team of analytics has done a malware research of Raccoon Stealer 2.0. Check our results, including the script to extract C2 servers.