CTT Report Hub
3.42K subscribers
9.87K photos
6 videos
67 files
13.5K links
Threat Intelligence Report Hub
Download Telegram
#ParsedReport
07-09-2022

Mirai Variant MooBot Targets RCE Vulnerabilities in D-Link Routers

https://socradar.io/moobot-targets-rce-vulnerabilities-in-d-link-routers

Threats:
Mirai
Moobot
Deadbolt

Industry:
Financial

Geo:
American

CVEs:
CVE-2022-28958 [Vulners]
Vulners: Score: 7.5, CVSS: 4.1,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Unavailable
Soft:
- dlink dir-816l firmware (206b01)

CVE-2022-26258 [Vulners]
Vulners: Score: 7.5, CVSS: 4.8,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.3
X-Force: Patch: Unavailable
Soft:
- dlink dir-820l firmware (1.05)

CVE-2018-6530 [Vulners]
Vulners: Score: 10.0, CVSS: 8.3,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- d-link dir-860l firmware (lea1_fw110b04)
- d-link dir-865l firmware (lereva_firmware_patch_1.08.b01)
- d-link dir-868l firmware (lea1_fw112b04)
- d-link dir-880l firmware (lereva_firmware_patch_1.08b04)

CVE-2015-2051 [Vulners]
Vulners: Score: 10.0, CVSS: 8.6,
Vulners: Exploitation: True
X-Force: Risk: 10
X-Force: Patch: Official fix
Soft:
- d-link dir-645 firmware (le1.04b12)


IOCs:
File: 2
Domain: 1
Url: 14
Hash: 13

Softs:
tiktok

Functions:
GetDeviceSettings
#ParsedReport
07-09-2022

Initial access broker repurposing techniques in targeted attacks against Ukraine

https://blog.google/threat-analysis-group/initial-access-broker-repurposing-techniques-in-targeted-attacks-against-ukraine

Actors/Campaigns:
Wizard_spider (motivation: government_sponsored, financially_motivated)
Fin12

Threats:
Conti
Icedid
Anchormail
Lackeybuilder_tool
Trickbot
Cobalt_strike
Ettersilent_tool
Follina_vuln

Industry:
Healthcare, Government, Retail, Financial, Ngo

Geo:
Russian, Italy, India, Ukraine, Ukrainian

CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: 3.4,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...

IOCs:
Url: 16
Hash: 3
File: 6
Domain: 9
Email: 2
IP: 2

Algorithms:
zip
#ParsedReport
07-09-2022

Sharkbot is back in Google Play

https://research.nccgroup.com/2022/09/06/sharkbot-is-back-in-google-play

Actors/Campaigns:
Fakeupdates

Threats:
Sharkbot

Industry:
Financial

Geo:
Poland, Austria, Spain, America, Germany, Australia, Italy

IOCs:
Url: 4
Hash: 2
IP: 1
Domain: 2

Softs:
android

Algorithms:
rc4, base64
#ParsedReport
07-09-2022

Worok: The big picture

https://www.welivesecurity.com/2022/09/06/worok-big-picture

Actors/Campaigns:
Worok (motivation: cyber_espionage)
Ta428

Threats:
Clrload
Powheartbeat
Pngload
Proxyshell_vuln
Shadowpad
Mimikatz
Earthworm_tool
Regeorg
Nbtscan_tool

Industry:
Telco, Energy, Financial, Government, Maritime

Geo:
Asia, Ukraine, Africa

CVEs:
CVE-2021-34523 [Vulners]
Vulners: Score: 7.5, CVSS: 3.4,
Vulners: Exploitation: True
X-Force: Risk: 9
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2013, 2019, 2016, 2016, 2019)


TTPs:
Tactics: 10
Technics: 28

IOCs:
Path: 13
Registry: 1
Hash: 23
IP: 3
File: 1
Domain: 2

Algorithms:
cbc, xor, base64, gzip, des

Functions:
GetUrl, Windows, CLRCreateInstance

Win API:
CorBindToRuntimeEx

Platforms:
x86

Links:
https://github.com/charlesroelli/nbtscan
https://github.com/sensepost/reGeorg
https://github.com/eset/malware-ioc/tree/master/worok
#ParsedReport
07-09-2022

Bumblebee Returns with New Infection Technique

https://blog.cyble.com/2022/09/07/bumblebee-returns-with-new-infection-technique

Threats:
Bumblebee
Powersploit
Bazarbackdoor
Beacon
Dll_sideloading_technique
Process_injection_technique

Geo:
Australia, Singapore, Dubai, Georgia, India

TTPs:
Tactics: 4
Technics: 10

IOCs:
File: 3
Path: 1
Hash: 5

Algorithms:
gzip, base64

Win API:
Decompress, ShowWindow

Links:
https://github.com/PowerShellMafia/PowerSploit/blob/master/CodeExecution/Invoke-ReflectivePEInjection.ps1
https://github.com/PowerShellMafia/PowerSploit
#ParsedReport
07-09-2022

MagicRAT: Lazarus latest gateway into victim networks

http://blog.talosintelligence.com/2022/09/lazarus-magicrat.html

Actors/Campaigns:
Lazarus
Bytetiger

Threats:
Magicrat
Tiger_rat
Kisa
Bespoke
Dtrack_rat
Vsingle
Tiger_downloader
Skeleton_operation

Industry:
Government

Geo:
Korean, Korea

TTPs:

IOCs:
File: 5
Hash: 10
IP: 5
Url: 6

Softs:
vmware horizon

Algorithms:
base64

Links:
https://github.com/Cisco-Talos/osquery\_queries/blob/master/win\_malware/magicrat\_file\_artifact.yaml
#ParsedReport
08-09-2022

THREAT ANALYSIS REPORT: PlugX RAT Loader Evolution

https://www.cybereason.com/blog/threat-analysis-report-plugx-rat-loader-evolution

Actors/Campaigns:
Emissary_panda

Threats:
Plugx_rat
Dll_sideloading_technique
Proxylogon_exploit
Thor

Industry:
Aerospace, Government

Geo:
China, Belarus, Ukrainian, Asia, Russia, Asian

TTPs:
Tactics: 6
Technics: 0

IOCs:
Hash: 18
File: 3

Algorithms:
rc4

Win API:
GetSystemTime, VirtualFree, VirtualProtect, LoadLibraryA, GetProcAddress, VirtualAlloc, NtGlobalFlag, ExitThread, RtlDecompressBuffer
#ParsedReport
08-09-2022

The Rise in Incidence of Fake e-shop Scams

https://blog.cyble.com/2022/09/08/the-rise-in-incidence-of-fake-e-shop-scams

Industry:
E-commerce, Energy, Media, Financial

Geo:
Georgia, Malaysia, Singapore, Malaysian, Australia, Dubai, Vietnam, India

TTPs:
Tactics: 5
Technics: 6

IOCs:
Url: 77
File: 1
Hash: 2

Softs:
android
#ParsedReport
08-09-2022

Microsoft investigates Iranian attacks against the Albanian government

https://www.microsoft.com/security/blog/2022/09/08/microsoft-investigates-iranian-attacks-against-the-albanian-government

Actors/Campaigns:
Dev-0861
Dev-0166
Siamesekitten
Europium

Threats:
Zerocleare_wiper
Hostile
Credential_harvesting_technique
Mimikatz
Impacket_tool
Trojan:win32/batrungoxml
Ransom:win32/eagle!msr
Trojan:win32/debitom.a
Proxylogon_exploit

Industry:
Ngo, Aerospace, Transport, Petroleum, Government, Healthcare, Telco, Energy

Geo:
Kuwait, Turkey, Irans, Albania, Tehrans, Tehran, American, Iranians, Jordan, Iran, Iranian, Israel

CVEs:
CVE-2021-26855 [Vulners]
Vulners: Score: 7.5, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 9.1
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2016, 2016, 2013, 2016, 2016, 2013, 2016, 2019, 2013, 2016, 2016, 2016, 2016, 2016, 2016, 2016, 2019, 2019, 2019, 2019, 2019, 2019, 2019, 2019)

CVE-2019-0604 [Vulners]
Vulners: Score: 7.5, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- microsoft sharepoint foundation (2013)
- microsoft sharepoint server (2019, 2010)
- microsoft sharepoint enterprise server (2016)


TTPs:
Tactics: 3
Technics: 0

IOCs:
IP: 8
File: 11
Hash: 21
Path: 8
Coin: 1
Registry: 1

Softs:
microsoft exchange, winlogon, microsoft defender, microsoft 365 defender, microsoft defender for endpoint, sharepoint server

Algorithms:
base64, zip, rc4

Functions:
rand

Win API:
SeDebugPrivilege, FindFirstVolumeW, GetOpenFileNameA, GetVolumePathNamesForVolumeNameW, CreateMutexA, SeImpersonatePrivilege, GetTokenInformation, CreateProcessWithTokenW, FindNextVolumeW, SetVolumeMountPointW, CreateDirectoryW

YARA: Found
#ParsedReport
08-09-2022

Raccoon Stealer 2.0 Malware analysis

https://any.run/cybersecurity-blog/raccoon-stealer-v2-malware-analysis/?utm_source=linkedin

Threats:
Raccoon_stealer
Recordbreaker_stealer
Follina_vuln

Industry:
Financial

TTPs:
Tactics: 1
Technics: 0

IOCs:
File: 4
Hash: 17
Registry: 1

Softs:
jaxx, tronlink, binancechain, telegram, jaxxliberty, chrome

Algorithms:
base64, xor, rc4

Functions:
x64-specific

Win API:
NtQueryInformationProcess

Languages:
python

Links:
https://github.com/mrexodia/TitanHide/commit/6a5a68a2447ad9454adfcbd9390ec05b9dcef2d6
https://github.com/mrexodia/TitanHide/issues/70
#ParsedReport
08-09-2022

The Week in Cybersecurity: Vice Society ransomware group targets back-to-school

https://blog.reversinglabs.com/blog/the-week-in-cybersecurity-vice-society-ransomware

Actors/Campaigns:
Vice_society (motivation: cyber_criminal)

Threats:
Hellokitty
Zeppelin
Cobalt_strike
Empire_loader
Systembc
Deadbolt
Shikitega
Sunburst

Industry:
Government, Financial, Education, Iot

Geo:
Montenegro, Americas, Russia
#ParsedReport
08-09-2022

SafeBreach Labs Researchers Uncover New Remote Access Trojan (RAT). CodeRAT Overview

https://www.safebreach.com/resources/blog/remote-access-trojan-coderat

Threats:
Coderat
Robothief
Antidebugging_technique

Industry:
E-commerce, Media, Government

Geo:
Iran, Tehran, Iranian, Irans

IOCs:
File: 9
Hash: 5

Softs:
visual studio, instagram, telegram, microsoft office, egram grou, microsoft powerpoint, android, microsoft word, windows media player, ram.org/bo

Functions:
BossWatch, CheckBoss

Win API:
CryptUnprotectData

Languages:
python

Platforms:
x86

YARA: Found

Links:
https://github.com/MrModed/DWM
#ParsedReport
07-09-2022

Profiling DEV-0270: PHOSPHORUS ransomware operations

https://www.microsoft.com/security/blog/2022/09/07/profiling-dev-0270-phosphorus-ransomware-operations

Actors/Campaigns:
Phosphorus

Threats:
Lolbin
Log4shell_vuln
Minidump_tool
Impacket_tool
Mamba
Credential_stealing_technique
Lazagne
Mimikatz
Proxyshell_vuln

Industry:
Government

Geo:
Iran, Iranian

CVEs:
CVE-2021-26858 [Vulners]
Vulners: Score: 6.8, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2013, 2016, 2016, 2019, 2019)

CVE-2021-27065 [Vulners]
Vulners: Score: 6.8, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2013, 2016, 2016, 2016, 2016, 2013, 2016, 2019, 2013, 2016, 2016, 2016, 2016, 2016, 2016, 2016, 2019, 2019, 2019, 2019, 2019, 2019, 2019)

CVE-2021-26855 [Vulners]
Vulners: Score: 7.5, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 9.1
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2016, 2016, 2013, 2016, 2016, 2013, 2016, 2019, 2013, 2016, 2016, 2016, 2016, 2016, 2016, 2016, 2019, 2019, 2019, 2019, 2019, 2019, 2019, 2019)

CVE-2018-13379 [Vulners]
Vulners: Score: 5.0, CVSS: 3.2,
Vulners: Exploitation: True
X-Force: Risk: 7.5
X-Force: Patch: Official fix
Soft:
- fortinet fortios (le6.0.4, le5.6.7)

CVE-2021-26857 [Vulners]
Vulners: Score: 6.8, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2010, 2013, 2019, 2016, 2019, 2016)


TTPs:
Tactics: 8
Technics: 0

IOCs:
File: 15
Domain: 2
Registry: 2

Softs:
microsoft defender for endpoint, local security authority, bitlocker, microsoft defender, microsoft 365 defender, task scheduler, psexec

Links:
https://github.com/Azure/Azure-Sentinel/blob/master/Hunting%20Queries/Microsoft%20365%20Defender/Ransomware/DEV-0270/Email%20data%20exfiltration%20via%20PowerShell.yaml
https://github.com/Azure/Azure-Sentinel/blob/master/Detections/MultipleDataSources/Dev-0270WMICDiscoverySep2022.yaml
https://github.com/Azure/Azure-Sentinel/blob/master/Hunting%20Queries/Microsoft%20365%20Defender/Ransomware/DEV-0270/Create%20new%20user%20with%20known%20DEV-0270%20username%20and%20password.yaml
https://github.com/Azure/Azure-Sentinel/blob/master/Hunting%20Queries/Microsoft%20365%20Defender/Ransomware/DEV-0270/PowerShell%20adding%20exclusion%20path%20for%20Microsoft%20Defender%20of%20ProgramData.yaml
https://github.com/Azure/Azure-Sentinel/blob/master/Detections/MultipleDataSources/Dev-0270RegistryIOCSep2022.yaml
https://github.com/Azure/Azure-Sentinel/blob/master/Hunting%20Queries/Microsoft%20365%20Defender/Ransomware/DEV-0270/DLLHost.exe%20WMIC%20domain%20discovery.yaml
https://github.com/Azure/Azure-Sentinel/blob/master/Detections/MultipleDataSources/Dev-0270NewUserSep2022.yaml
https://github.com/Azure/Azure-Sentinel/blob/master/Hunting%20Queries/Microsoft%20365%20Defender/Ransomware/DEV-0270/Disabling%20Services%20via%20Registry.yaml
https://github.com/Azure/Azure-Sentinel/blob/master/Hunting%20Queries/Microsoft%20365%20Defender/Ransomware/DEV-0270/Modifying%20the%20registry%20to%20add%20a%20ransom%20message%20notification.yaml
https://github.com/Azure/Azure-Sentinel/blob/master/Hunting%20Queries/Microsoft%20365%20Defender/Ransomware/DEV-0270/Add%20malicious%20user%20to%20Admins%20and%20RDP%20users%20group%20via%20PowerShell.yaml
https://github.com/Azure/Azure-Sentinel/blob/master/Hunting%20Queries/Microsoft%20365%20Defender/Ransomware/DEV-0270/DLLHost.exe%20file%20creation%20via%20PowerShell.yaml
https://github.com/Azure/Azure-Sentinel/blob/master/Detections/MultipleDataSources/Dev-0270PowershellSep2022.yaml
https://github.com/SecureAuthCorp/impacket/
#ParsedReport
08-09-2022

Crimeware Trends \| Ransomware Developers Turn to Intermittent Encryption to Evade Detection

https://www.sentinelone.com/labs/crimeware-trends-ransomware-developers-turn-to-intermittent-encryption-to-evade-detection

Actors/Campaigns:
Blackcat
Qilin

Threats:
Blackbasta
Qyick
Blackcat
Playcrypt
Conti

Industry:
Healthcare, Education, Financial, Energy

Geo:
Asia, Argentina, Africa, Russian, German

IOCs:
Hash: 4

Algorithms:
chacha20, aes

Win API:
LockFile

Languages:
rust
#ParsedReport
08-09-2022

Likely Iranian Threat Actor Conducts Politically Motivated Disruptive Activity Against Albanian Government Organizations

https://www.mandiant.com/resources/blog/likely-iranian-threat-actor-conducts-politically-motivated-disruptive-activity-against

Actors/Campaigns:
Cleaver (motivation: cyber_espionage)
Axiom

Threats:
Roadsweep
Chimneysweep
Zeroclear
Dustman_wiper
Markirat
Mosesstaff
Metasploit_tool
Delf
Netstat_tool
Process_injection_technique
Timestomp_technique

Industry:
Government

Geo:
Israeli, Iran, Lebanon, Albania, Bahrain, Iranian

TTPs:
Tactics: 3
Technics: 19

IOCs:
Domain: 9
File: 12
Hash: 20
IP: 1
Path: 4
Coin: 1
Registry: 2

Softs:
telegram, windows registry, windows service

Algorithms:
rc4, base64

Functions:
GetUpdates

Win API:
FindFirstFileW, socket, FindNextFileW, GetFileSize, DeviceIoControl, GetSystemDirectoryW, GetProcAddress, LoadLibrary

Platforms:
x86

YARA: Found

Links:
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/local/bypassuac\_silentcleanup.rb