#ParsedReport
07-09-2022
Mirai Variant MooBot Targets RCE Vulnerabilities in D-Link Routers
https://socradar.io/moobot-targets-rce-vulnerabilities-in-d-link-routers
Threats:
Mirai
Moobot
Deadbolt
Industry:
Financial
Geo:
American
CVEs:
CVE-2022-28958 [Vulners]
Vulners: Score: 7.5, CVSS: 4.1,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Unavailable
Soft:
- dlink dir-816l firmware (206b01)
CVE-2022-26258 [Vulners]
Vulners: Score: 7.5, CVSS: 4.8,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.3
X-Force: Patch: Unavailable
Soft:
- dlink dir-820l firmware (1.05)
CVE-2018-6530 [Vulners]
Vulners: Score: 10.0, CVSS: 8.3,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- d-link dir-860l firmware (lea1_fw110b04)
- d-link dir-865l firmware (lereva_firmware_patch_1.08.b01)
- d-link dir-868l firmware (lea1_fw112b04)
- d-link dir-880l firmware (lereva_firmware_patch_1.08b04)
CVE-2015-2051 [Vulners]
Vulners: Score: 10.0, CVSS: 8.6,
Vulners: Exploitation: True
X-Force: Risk: 10
X-Force: Patch: Official fix
Soft:
- d-link dir-645 firmware (le1.04b12)
IOCs:
File: 2
Domain: 1
Url: 14
Hash: 13
Softs:
tiktok
Functions:
GetDeviceSettings
07-09-2022
Mirai Variant MooBot Targets RCE Vulnerabilities in D-Link Routers
https://socradar.io/moobot-targets-rce-vulnerabilities-in-d-link-routers
Threats:
Mirai
Moobot
Deadbolt
Industry:
Financial
Geo:
American
CVEs:
CVE-2022-28958 [Vulners]
Vulners: Score: 7.5, CVSS: 4.1,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Unavailable
Soft:
- dlink dir-816l firmware (206b01)
CVE-2022-26258 [Vulners]
Vulners: Score: 7.5, CVSS: 4.8,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.3
X-Force: Patch: Unavailable
Soft:
- dlink dir-820l firmware (1.05)
CVE-2018-6530 [Vulners]
Vulners: Score: 10.0, CVSS: 8.3,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- d-link dir-860l firmware (lea1_fw110b04)
- d-link dir-865l firmware (lereva_firmware_patch_1.08.b01)
- d-link dir-868l firmware (lea1_fw112b04)
- d-link dir-880l firmware (lereva_firmware_patch_1.08b04)
CVE-2015-2051 [Vulners]
Vulners: Score: 10.0, CVSS: 8.6,
Vulners: Exploitation: True
X-Force: Risk: 10
X-Force: Patch: Official fix
Soft:
- d-link dir-645 firmware (le1.04b12)
IOCs:
File: 2
Domain: 1
Url: 14
Hash: 13
Softs:
tiktok
Functions:
GetDeviceSettings
SOCRadar® Cyber Intelligence Inc.
Mirai Variant MooBot Targets RCE Vulnerabilities in D-Link Routers
MooBot botnet is back for new attacks. The variant of the Mirai malware started a new campaign last month to exploit critical vulnerabilities.
#ParsedReport
07-09-2022
Initial access broker repurposing techniques in targeted attacks against Ukraine
https://blog.google/threat-analysis-group/initial-access-broker-repurposing-techniques-in-targeted-attacks-against-ukraine
Actors/Campaigns:
Wizard_spider (motivation: government_sponsored, financially_motivated)
Fin12
Threats:
Conti
Icedid
Anchormail
Lackeybuilder_tool
Trickbot
Cobalt_strike
Ettersilent_tool
Follina_vuln
Industry:
Healthcare, Government, Retail, Financial, Ngo
Geo:
Russian, Italy, India, Ukraine, Ukrainian
CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: 3.4,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...
IOCs:
Url: 16
Hash: 3
File: 6
Domain: 9
Email: 2
IP: 2
Algorithms:
zip
07-09-2022
Initial access broker repurposing techniques in targeted attacks against Ukraine
https://blog.google/threat-analysis-group/initial-access-broker-repurposing-techniques-in-targeted-attacks-against-ukraine
Actors/Campaigns:
Wizard_spider (motivation: government_sponsored, financially_motivated)
Fin12
Threats:
Conti
Icedid
Anchormail
Lackeybuilder_tool
Trickbot
Cobalt_strike
Ettersilent_tool
Follina_vuln
Industry:
Healthcare, Government, Retail, Financial, Ngo
Geo:
Russian, Italy, India, Ukraine, Ukrainian
CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: 3.4,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...
IOCs:
Url: 16
Hash: 3
File: 6
Domain: 9
Email: 2
IP: 2
Algorithms:
zip
Google
Initial access broker repurposing techniques in targeted attacks against Ukraine
Describing activities of a crime group attacking Ukraine.
#ParsedReport
07-09-2022
Sharkbot is back in Google Play
https://research.nccgroup.com/2022/09/06/sharkbot-is-back-in-google-play
Actors/Campaigns:
Fakeupdates
Threats:
Sharkbot
Industry:
Financial
Geo:
Poland, Austria, Spain, America, Germany, Australia, Italy
IOCs:
Url: 4
Hash: 2
IP: 1
Domain: 2
Softs:
android
Algorithms:
rc4, base64
07-09-2022
Sharkbot is back in Google Play
https://research.nccgroup.com/2022/09/06/sharkbot-is-back-in-google-play
Actors/Campaigns:
Fakeupdates
Threats:
Sharkbot
Industry:
Financial
Geo:
Poland, Austria, Spain, America, Germany, Australia, Italy
IOCs:
Url: 4
Hash: 2
IP: 1
Domain: 2
Softs:
android
Algorithms:
rc4, base64
NCC Group Research Blog
Sharkbot is back in Google Play
Authored by Alberto Segura (main author) and Mike Stokkel (co-author) Editor’s note: This post was originally published on the Fox-IT blog. Introduction After we discovered in February …
#ParsedReport
07-09-2022
. Distributed phishing site disguised as a domestic groupware login site
https://asec.ahnlab.com/ko/38676
Geo:
Korean, Korea
IOCs:
File: 2
Url: 10
Languages:
javascript
07-09-2022
. Distributed phishing site disguised as a domestic groupware login site
https://asec.ahnlab.com/ko/38676
Geo:
Korean, Korea
IOCs:
File: 2
Url: 10
Languages:
javascript
ASEC BLOG
국내 그룹웨어 로그인 사이트로 위장한 피싱 사이트 유포 - ASEC BLOG
ASEC 분석팀에서는 국내뿐만 아니라 해외에서 유포 중인 다양한 악성코드를 수집하기 위해 허니팟을 구축하고 있다. 이 허니팟은 피싱 메일도 같이 수집하는데 최근 8월부터 한국 계정에만 지속적으로 유포 중인 한국 타겟형 피싱 메일을 포착하였다. 해당 피싱 사이트는 국내 그룹웨어의 로그인 사이트를 위장한 것으로 국내에서 2500건 이상 해당 사이트에 접근한 이력이 확인되었다. 따라서 사용자는 그룹웨어 사이트에 로그인 시 각별한 주의가 필요하다. 해당 피싱…
#ParsedReport
07-09-2022
Worok: The big picture
https://www.welivesecurity.com/2022/09/06/worok-big-picture
Actors/Campaigns:
Worok (motivation: cyber_espionage)
Ta428
Threats:
Clrload
Powheartbeat
Pngload
Proxyshell_vuln
Shadowpad
Mimikatz
Earthworm_tool
Regeorg
Nbtscan_tool
Industry:
Telco, Energy, Financial, Government, Maritime
Geo:
Asia, Ukraine, Africa
CVEs:
CVE-2021-34523 [Vulners]
Vulners: Score: 7.5, CVSS: 3.4,
Vulners: Exploitation: True
X-Force: Risk: 9
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2013, 2019, 2016, 2016, 2019)
TTPs:
Tactics: 10
Technics: 28
IOCs:
Path: 13
Registry: 1
Hash: 23
IP: 3
File: 1
Domain: 2
Algorithms:
cbc, xor, base64, gzip, des
Functions:
GetUrl, Windows, CLRCreateInstance
Win API:
CorBindToRuntimeEx
Platforms:
x86
Links:
07-09-2022
Worok: The big picture
https://www.welivesecurity.com/2022/09/06/worok-big-picture
Actors/Campaigns:
Worok (motivation: cyber_espionage)
Ta428
Threats:
Clrload
Powheartbeat
Pngload
Proxyshell_vuln
Shadowpad
Mimikatz
Earthworm_tool
Regeorg
Nbtscan_tool
Industry:
Telco, Energy, Financial, Government, Maritime
Geo:
Asia, Ukraine, Africa
CVEs:
CVE-2021-34523 [Vulners]
Vulners: Score: 7.5, CVSS: 3.4,
Vulners: Exploitation: True
X-Force: Risk: 9
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2013, 2019, 2016, 2016, 2019)
TTPs:
Tactics: 10
Technics: 28
IOCs:
Path: 13
Registry: 1
Hash: 23
IP: 3
File: 1
Domain: 2
Algorithms:
cbc, xor, base64, gzip, des
Functions:
GetUrl, Windows, CLRCreateInstance
Win API:
CorBindToRuntimeEx
Platforms:
x86
Links:
https://github.com/charlesroelli/nbtscanhttps://github.com/sensepost/reGeorghttps://github.com/eset/malware-ioc/tree/master/worokWeLiveSecurity
Worok: The big picture
ESET Research has uncovered Worok, a new cyberespionage group that targets high-profile organizations based in Asia and operating in various sectors.
#ParsedReport
07-09-2022
Bumblebee Returns with New Infection Technique
https://blog.cyble.com/2022/09/07/bumblebee-returns-with-new-infection-technique
Threats:
Bumblebee
Powersploit
Bazarbackdoor
Beacon
Dll_sideloading_technique
Process_injection_technique
Geo:
Australia, Singapore, Dubai, Georgia, India
TTPs:
Tactics: 4
Technics: 10
IOCs:
File: 3
Path: 1
Hash: 5
Algorithms:
gzip, base64
Win API:
Decompress, ShowWindow
Links:
07-09-2022
Bumblebee Returns with New Infection Technique
https://blog.cyble.com/2022/09/07/bumblebee-returns-with-new-infection-technique
Threats:
Bumblebee
Powersploit
Bazarbackdoor
Beacon
Dll_sideloading_technique
Process_injection_technique
Geo:
Australia, Singapore, Dubai, Georgia, India
TTPs:
Tactics: 4
Technics: 10
IOCs:
File: 3
Path: 1
Hash: 5
Algorithms:
gzip, base64
Win API:
Decompress, ShowWindow
Links:
https://github.com/PowerShellMafia/PowerSploit/blob/master/CodeExecution/Invoke-ReflectivePEInjection.ps1https://github.com/PowerShellMafia/PowerSploitCyble
Cyble - Bumblebee Returns With New Infection Technique
Cyble Research & Intelligence Labs analyzes a new infection chain of the Bumblebee loader malware being distributed via spam campaigns.
#ParsedReport
07-09-2022
MagicRAT: Lazarus latest gateway into victim networks
http://blog.talosintelligence.com/2022/09/lazarus-magicrat.html
Actors/Campaigns:
Lazarus
Bytetiger
Threats:
Magicrat
Tiger_rat
Kisa
Bespoke
Dtrack_rat
Vsingle
Tiger_downloader
Skeleton_operation
Industry:
Government
Geo:
Korean, Korea
TTPs:
IOCs:
File: 5
Hash: 10
IP: 5
Url: 6
Softs:
vmware horizon
Algorithms:
base64
Links:
07-09-2022
MagicRAT: Lazarus latest gateway into victim networks
http://blog.talosintelligence.com/2022/09/lazarus-magicrat.html
Actors/Campaigns:
Lazarus
Bytetiger
Threats:
Magicrat
Tiger_rat
Kisa
Bespoke
Dtrack_rat
Vsingle
Tiger_downloader
Skeleton_operation
Industry:
Government
Geo:
Korean, Korea
TTPs:
IOCs:
File: 5
Hash: 10
IP: 5
Url: 6
Softs:
vmware horizon
Algorithms:
base64
Links:
https://github.com/Cisco-Talos/osquery\_queries/blob/master/win\_malware/magicrat\_file\_artifact.yamlCisco Talos Blog
MagicRAT: Lazarus’ latest gateway into victim networks
Cisco Talos has discovered a new remote access trojan (RAT) we're calling "MagicRAT," developed and operated by the Lazarus APT group, which the U.S. government believes is a North Korean state-sponsored actor.
#ParsedReport
07-09-2022
ASEC (20220829 \~ 20220904). ASEC Weekly Malware Statistics (20220829 \~ 20220904)
https://asec.ahnlab.com/ko/38557
Threats:
Cloudeye
Postealer
Formbook
Agent_tesla
Remcos_rat
Nanocore_rat
Azorult
Clipboard_grabbing_technique
Lokibot_stealer
Industry:
Transport, Financial
Geo:
Korea
IOCs:
File: 26
Url: 17
Domain: 4
IP: 3
Email: 6
Softs:
nsis installer, discord
Languages:
visual_basic, php
07-09-2022
ASEC (20220829 \~ 20220904). ASEC Weekly Malware Statistics (20220829 \~ 20220904)
https://asec.ahnlab.com/ko/38557
Threats:
Cloudeye
Postealer
Formbook
Agent_tesla
Remcos_rat
Nanocore_rat
Azorult
Clipboard_grabbing_technique
Lokibot_stealer
Industry:
Transport, Financial
Geo:
Korea
IOCs:
File: 26
Url: 17
Domain: 4
IP: 3
Email: 6
Softs:
nsis installer, discord
Languages:
visual_basic, php
ASEC BLOG
ASEC 주간 악성코드 통계 (20220829 ~ 20220904) - ASEC BLOG
ASEC 분석팀에서는 ASEC 자동 분석 시스템 RAPIT 을 활용하여 알려진 악성코드들에 대한 분류 및 대응을 진행하고 있다. 본 포스팅에서는 2022년 8월 29일 월요일부터 9월 4일 일요일까지 한 주간 수집된 악성코드의 통계를 정리한다. 대분류 상으로는 인포스틸러가 45.9%로 1위를 차지하였으며, 그 다음으로는 다운로더 악성코드가 28.1%, 백도어 18.5%, 랜섬웨어 6.2%, 코인마이너 및 뱅킹 악성코드가 각각 0.7%로 집계되었다. Top…
Кажется, pornhub запустил краудсорсинговую кампанию )))
https://www.malwarebytes.com/blog/news/2022/09/sextortionists-used-mobile-malware-to-steal-nude-videos-contact-lists-from-victims
https://www.malwarebytes.com/blog/news/2022/09/sextortionists-used-mobile-malware-to-steal-nude-videos-contact-lists-from-victims
Malwarebytes
Sextortionists used mobile malware to steal nude videos, contact lists from victims
In an international police action supported by Interpol, law enforcement agencies have uncovered and dismantled an international sextortion ring.
#ParsedReport
08-09-2022
THREAT ANALYSIS REPORT: PlugX RAT Loader Evolution
https://www.cybereason.com/blog/threat-analysis-report-plugx-rat-loader-evolution
Actors/Campaigns:
Emissary_panda
Threats:
Plugx_rat
Dll_sideloading_technique
Proxylogon_exploit
Thor
Industry:
Aerospace, Government
Geo:
China, Belarus, Ukrainian, Asia, Russia, Asian
TTPs:
Tactics: 6
Technics: 0
IOCs:
Hash: 18
File: 3
Algorithms:
rc4
Win API:
GetSystemTime, VirtualFree, VirtualProtect, LoadLibraryA, GetProcAddress, VirtualAlloc, NtGlobalFlag, ExitThread, RtlDecompressBuffer
08-09-2022
THREAT ANALYSIS REPORT: PlugX RAT Loader Evolution
https://www.cybereason.com/blog/threat-analysis-report-plugx-rat-loader-evolution
Actors/Campaigns:
Emissary_panda
Threats:
Plugx_rat
Dll_sideloading_technique
Proxylogon_exploit
Thor
Industry:
Aerospace, Government
Geo:
China, Belarus, Ukrainian, Asia, Russia, Asian
TTPs:
Tactics: 6
Technics: 0
IOCs:
Hash: 18
File: 3
Algorithms:
rc4
Win API:
GetSystemTime, VirtualFree, VirtualProtect, LoadLibraryA, GetProcAddress, VirtualAlloc, NtGlobalFlag, ExitThread, RtlDecompressBuffer
Cybereason
THREAT ANALYSIS REPORT: PlugX RAT Loader Evolution
PlugX is a post-exploitation modular RAT (Remote Access Trojan), which is known for its multiple functionalities such as data exfiltration, keystroke grabbing, backdoor functionality, and utilizing DLL-Sideloading techniques for evading security solutions...
#ParsedReport
08-09-2022
Warning issued about Vice Society ransomware targeting the education sector
https://www.malwarebytes.com/blog/news/2022/09/authorities-issue-warning-about-vice-society-ransomware-targeting-the-education-sector
Actors/Campaigns:
Vice_society
Threats:
Medusalocker
Zeppelin
Hellokitty
Printnightmare_vuln
Empire_loader
Cobalt_strike
Systembc
Industry:
Education
Geo:
Russian
08-09-2022
Warning issued about Vice Society ransomware targeting the education sector
https://www.malwarebytes.com/blog/news/2022/09/authorities-issue-warning-about-vice-society-ransomware-targeting-the-education-sector
Actors/Campaigns:
Vice_society
Threats:
Medusalocker
Zeppelin
Hellokitty
Printnightmare_vuln
Empire_loader
Cobalt_strike
Systembc
Industry:
Education
Geo:
Russian
ThreatDown by Malwarebytes
Warning issued about Vice Society ransomware targeting the education sector - ThreatDown by Malwarebytes
The Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), and the Multi-State Information Sharing and Analysis Center (MS-ISAC) have released a joint…
#ParsedReport
08-09-2022
The Rise in Incidence of Fake e-shop Scams
https://blog.cyble.com/2022/09/08/the-rise-in-incidence-of-fake-e-shop-scams
Industry:
E-commerce, Energy, Media, Financial
Geo:
Georgia, Malaysia, Singapore, Malaysian, Australia, Dubai, Vietnam, India
TTPs:
Tactics: 5
Technics: 6
IOCs:
Url: 77
File: 1
Hash: 2
Softs:
android
08-09-2022
The Rise in Incidence of Fake e-shop Scams
https://blog.cyble.com/2022/09/08/the-rise-in-incidence-of-fake-e-shop-scams
Industry:
E-commerce, Energy, Media, Financial
Geo:
Georgia, Malaysia, Singapore, Malaysian, Australia, Dubai, Vietnam, India
TTPs:
Tactics: 5
Technics: 6
IOCs:
Url: 77
File: 1
Hash: 2
Softs:
android
#ParsedReport
08-09-2022
Microsoft investigates Iranian attacks against the Albanian government
https://www.microsoft.com/security/blog/2022/09/08/microsoft-investigates-iranian-attacks-against-the-albanian-government
Actors/Campaigns:
Dev-0861
Dev-0166
Siamesekitten
Europium
Threats:
Zerocleare_wiper
Hostile
Credential_harvesting_technique
Mimikatz
Impacket_tool
Trojan:win32/batrungoxml
Ransom:win32/eagle!msr
Trojan:win32/debitom.a
Proxylogon_exploit
Industry:
Ngo, Aerospace, Transport, Petroleum, Government, Healthcare, Telco, Energy
Geo:
Kuwait, Turkey, Irans, Albania, Tehrans, Tehran, American, Iranians, Jordan, Iran, Iranian, Israel
CVEs:
CVE-2021-26855 [Vulners]
Vulners: Score: 7.5, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 9.1
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2016, 2016, 2013, 2016, 2016, 2013, 2016, 2019, 2013, 2016, 2016, 2016, 2016, 2016, 2016, 2016, 2019, 2019, 2019, 2019, 2019, 2019, 2019, 2019)
CVE-2019-0604 [Vulners]
Vulners: Score: 7.5, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- microsoft sharepoint foundation (2013)
- microsoft sharepoint server (2019, 2010)
- microsoft sharepoint enterprise server (2016)
TTPs:
Tactics: 3
Technics: 0
IOCs:
IP: 8
File: 11
Hash: 21
Path: 8
Coin: 1
Registry: 1
Softs:
microsoft exchange, winlogon, microsoft defender, microsoft 365 defender, microsoft defender for endpoint, sharepoint server
Algorithms:
base64, zip, rc4
Functions:
rand
Win API:
SeDebugPrivilege, FindFirstVolumeW, GetOpenFileNameA, GetVolumePathNamesForVolumeNameW, CreateMutexA, SeImpersonatePrivilege, GetTokenInformation, CreateProcessWithTokenW, FindNextVolumeW, SetVolumeMountPointW, CreateDirectoryW
YARA: Found
08-09-2022
Microsoft investigates Iranian attacks against the Albanian government
https://www.microsoft.com/security/blog/2022/09/08/microsoft-investigates-iranian-attacks-against-the-albanian-government
Actors/Campaigns:
Dev-0861
Dev-0166
Siamesekitten
Europium
Threats:
Zerocleare_wiper
Hostile
Credential_harvesting_technique
Mimikatz
Impacket_tool
Trojan:win32/batrungoxml
Ransom:win32/eagle!msr
Trojan:win32/debitom.a
Proxylogon_exploit
Industry:
Ngo, Aerospace, Transport, Petroleum, Government, Healthcare, Telco, Energy
Geo:
Kuwait, Turkey, Irans, Albania, Tehrans, Tehran, American, Iranians, Jordan, Iran, Iranian, Israel
CVEs:
CVE-2021-26855 [Vulners]
Vulners: Score: 7.5, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 9.1
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2016, 2016, 2013, 2016, 2016, 2013, 2016, 2019, 2013, 2016, 2016, 2016, 2016, 2016, 2016, 2016, 2019, 2019, 2019, 2019, 2019, 2019, 2019, 2019)
CVE-2019-0604 [Vulners]
Vulners: Score: 7.5, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- microsoft sharepoint foundation (2013)
- microsoft sharepoint server (2019, 2010)
- microsoft sharepoint enterprise server (2016)
TTPs:
Tactics: 3
Technics: 0
IOCs:
IP: 8
File: 11
Hash: 21
Path: 8
Coin: 1
Registry: 1
Softs:
microsoft exchange, winlogon, microsoft defender, microsoft 365 defender, microsoft defender for endpoint, sharepoint server
Algorithms:
base64, zip, rc4
Functions:
rand
Win API:
SeDebugPrivilege, FindFirstVolumeW, GetOpenFileNameA, GetVolumePathNamesForVolumeNameW, CreateMutexA, SeImpersonatePrivilege, GetTokenInformation, CreateProcessWithTokenW, FindNextVolumeW, SetVolumeMountPointW, CreateDirectoryW
YARA: Found
Microsoft News
Microsoft investigates Iranian attacks against the Albanian government
Shortly after the destructive cyberattacks on the Albanian government in mid-July, the Microsoft Detection and Response Team (DART) was engaged to lead an investigation into the attacks.
#ParsedReport
08-09-2022
Raccoon Stealer 2.0 Malware analysis
https://any.run/cybersecurity-blog/raccoon-stealer-v2-malware-analysis/?utm_source=linkedin
Threats:
Raccoon_stealer
Recordbreaker_stealer
Follina_vuln
Industry:
Financial
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 4
Hash: 17
Registry: 1
Softs:
jaxx, tronlink, binancechain, telegram, jaxxliberty, chrome
Algorithms:
base64, xor, rc4
Functions:
x64-specific
Win API:
NtQueryInformationProcess
Languages:
python
Links:
08-09-2022
Raccoon Stealer 2.0 Malware analysis
https://any.run/cybersecurity-blog/raccoon-stealer-v2-malware-analysis/?utm_source=linkedin
Threats:
Raccoon_stealer
Recordbreaker_stealer
Follina_vuln
Industry:
Financial
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 4
Hash: 17
Registry: 1
Softs:
jaxx, tronlink, binancechain, telegram, jaxxliberty, chrome
Algorithms:
base64, xor, rc4
Functions:
x64-specific
Win API:
NtQueryInformationProcess
Languages:
python
Links:
https://github.com/mrexodia/TitanHide/commit/6a5a68a2447ad9454adfcbd9390ec05b9dcef2d6https://github.com/mrexodia/TitanHide/issues/70ANY.RUN's Cybersecurity Blog
Raccoon Stealer 2.0 Malware analysis - ANY.RUN's Cybersecurity Blog
ANY.RUN team of analytics has done a malware research of Raccoon Stealer 2.0. Check our results, including the script to extract C2 servers.
#ParsedReport
08-09-2022
The Week in Cybersecurity: Vice Society ransomware group targets back-to-school
https://blog.reversinglabs.com/blog/the-week-in-cybersecurity-vice-society-ransomware
Actors/Campaigns:
Vice_society (motivation: cyber_criminal)
Threats:
Hellokitty
Zeppelin
Cobalt_strike
Empire_loader
Systembc
Deadbolt
Shikitega
Sunburst
Industry:
Government, Financial, Education, Iot
Geo:
Montenegro, Americas, Russia
08-09-2022
The Week in Cybersecurity: Vice Society ransomware group targets back-to-school
https://blog.reversinglabs.com/blog/the-week-in-cybersecurity-vice-society-ransomware
Actors/Campaigns:
Vice_society (motivation: cyber_criminal)
Threats:
Hellokitty
Zeppelin
Cobalt_strike
Empire_loader
Systembc
Deadbolt
Shikitega
Sunburst
Industry:
Government, Financial, Education, Iot
Geo:
Montenegro, Americas, Russia
ReversingLabs
The Week in Cybersecurity: Vice Society ransomware group targets back-to-school
This week: Vice Society ransomware group targets America’s education sector, the U.S. government’s new position on software supply chain security, and more.
#ParsedReport
08-09-2022
(Magniber) (*.cpl -> *.jse) 9/8. Magniber Ransomware Change ( *.cpl-> *.jse) -9/8
https://asec.ahnlab.com/ko/38706
Threats:
Magniber
Typosquatting_technique
IOCs:
File: 2
Hash: 1
Softs:
chrome
Algorithms:
zip
08-09-2022
(Magniber) (*.cpl -> *.jse) 9/8. Magniber Ransomware Change ( *.cpl-> *.jse) -9/8
https://asec.ahnlab.com/ko/38706
Threats:
Magniber
Typosquatting_technique
IOCs:
File: 2
Hash: 1
Softs:
chrome
Algorithms:
zip
ASEC
매그니베르(Magniber) 랜섬웨어 변경(*.cpl -> *.jse) – 9/8일자 - ASEC
7월 20일에 MSI 형식에서 CPL 형식으로 유포방식을 변경한 이후, 8월 중순 이후부터 유포가 잠시 주춤한 것으로 확인되고 있었다. 지속적으로 변화 상황을 모니터링 하던 중, 2022년 9월 8일부터는 유포 방식이 *.CPL (DLL형식)에서 *.JSE (스크립트) 형태로 변경된 것을 확인하였다. 매그니베르 랜섬웨어는 국내 사용자에 가장 큰 피해를 주는 랜섬웨어 중 하나로 활발하게 유포되고 있고, 백신의 탐지를 우회하기 위한 […]
#ParsedReport
08-09-2022
SafeBreach Labs Researchers Uncover New Remote Access Trojan (RAT). CodeRAT Overview
https://www.safebreach.com/resources/blog/remote-access-trojan-coderat
Threats:
Coderat
Robothief
Antidebugging_technique
Industry:
E-commerce, Media, Government
Geo:
Iran, Tehran, Iranian, Irans
IOCs:
File: 9
Hash: 5
Softs:
visual studio, instagram, telegram, microsoft office, egram grou, microsoft powerpoint, android, microsoft word, windows media player, ram.org/bo
Functions:
BossWatch, CheckBoss
Win API:
CryptUnprotectData
Languages:
python
Platforms:
x86
YARA: Found
Links:
08-09-2022
SafeBreach Labs Researchers Uncover New Remote Access Trojan (RAT). CodeRAT Overview
https://www.safebreach.com/resources/blog/remote-access-trojan-coderat
Threats:
Coderat
Robothief
Antidebugging_technique
Industry:
E-commerce, Media, Government
Geo:
Iran, Tehran, Iranian, Irans
IOCs:
File: 9
Hash: 5
Softs:
visual studio, instagram, telegram, microsoft office, egram grou, microsoft powerpoint, android, microsoft word, windows media player, ram.org/bo
Functions:
BossWatch, CheckBoss
Win API:
CryptUnprotectData
Languages:
python
Platforms:
x86
YARA: Found
Links:
https://github.com/MrModed/DWMSafeBreach
SafeBreach Uncovers New Remote Access Trojan (RAT)
Dubbed CodeRAT, the new RAT is used in attacks targeting Farsi-speaking code developers using a Microsoft Dynamic Data Exchange (DDE) exploit.
#ParsedReport
07-09-2022
Profiling DEV-0270: PHOSPHORUS ransomware operations
https://www.microsoft.com/security/blog/2022/09/07/profiling-dev-0270-phosphorus-ransomware-operations
Actors/Campaigns:
Phosphorus
Threats:
Lolbin
Log4shell_vuln
Minidump_tool
Impacket_tool
Mamba
Credential_stealing_technique
Lazagne
Mimikatz
Proxyshell_vuln
Industry:
Government
Geo:
Iran, Iranian
CVEs:
CVE-2021-26858 [Vulners]
Vulners: Score: 6.8, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2013, 2016, 2016, 2019, 2019)
CVE-2021-27065 [Vulners]
Vulners: Score: 6.8, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2013, 2016, 2016, 2016, 2016, 2013, 2016, 2019, 2013, 2016, 2016, 2016, 2016, 2016, 2016, 2016, 2019, 2019, 2019, 2019, 2019, 2019, 2019)
CVE-2021-26855 [Vulners]
Vulners: Score: 7.5, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 9.1
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2016, 2016, 2013, 2016, 2016, 2013, 2016, 2019, 2013, 2016, 2016, 2016, 2016, 2016, 2016, 2016, 2019, 2019, 2019, 2019, 2019, 2019, 2019, 2019)
CVE-2018-13379 [Vulners]
Vulners: Score: 5.0, CVSS: 3.2,
Vulners: Exploitation: True
X-Force: Risk: 7.5
X-Force: Patch: Official fix
Soft:
- fortinet fortios (le6.0.4, le5.6.7)
CVE-2021-26857 [Vulners]
Vulners: Score: 6.8, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2010, 2013, 2019, 2016, 2019, 2016)
TTPs:
Tactics: 8
Technics: 0
IOCs:
File: 15
Domain: 2
Registry: 2
Softs:
microsoft defender for endpoint, local security authority, bitlocker, microsoft defender, microsoft 365 defender, task scheduler, psexec
Links:
07-09-2022
Profiling DEV-0270: PHOSPHORUS ransomware operations
https://www.microsoft.com/security/blog/2022/09/07/profiling-dev-0270-phosphorus-ransomware-operations
Actors/Campaigns:
Phosphorus
Threats:
Lolbin
Log4shell_vuln
Minidump_tool
Impacket_tool
Mamba
Credential_stealing_technique
Lazagne
Mimikatz
Proxyshell_vuln
Industry:
Government
Geo:
Iran, Iranian
CVEs:
CVE-2021-26858 [Vulners]
Vulners: Score: 6.8, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2013, 2016, 2016, 2019, 2019)
CVE-2021-27065 [Vulners]
Vulners: Score: 6.8, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2013, 2016, 2016, 2016, 2016, 2013, 2016, 2019, 2013, 2016, 2016, 2016, 2016, 2016, 2016, 2016, 2019, 2019, 2019, 2019, 2019, 2019, 2019)
CVE-2021-26855 [Vulners]
Vulners: Score: 7.5, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 9.1
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2016, 2016, 2013, 2016, 2016, 2013, 2016, 2019, 2013, 2016, 2016, 2016, 2016, 2016, 2016, 2016, 2019, 2019, 2019, 2019, 2019, 2019, 2019, 2019)
CVE-2018-13379 [Vulners]
Vulners: Score: 5.0, CVSS: 3.2,
Vulners: Exploitation: True
X-Force: Risk: 7.5
X-Force: Patch: Official fix
Soft:
- fortinet fortios (le6.0.4, le5.6.7)
CVE-2021-26857 [Vulners]
Vulners: Score: 6.8, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2010, 2013, 2019, 2016, 2019, 2016)
TTPs:
Tactics: 8
Technics: 0
IOCs:
File: 15
Domain: 2
Registry: 2
Softs:
microsoft defender for endpoint, local security authority, bitlocker, microsoft defender, microsoft 365 defender, task scheduler, psexec
Links:
https://github.com/Azure/Azure-Sentinel/blob/master/Hunting%20Queries/Microsoft%20365%20Defender/Ransomware/DEV-0270/Email%20data%20exfiltration%20via%20PowerShell.yamlhttps://github.com/Azure/Azure-Sentinel/blob/master/Detections/MultipleDataSources/Dev-0270WMICDiscoverySep2022.yamlhttps://github.com/Azure/Azure-Sentinel/blob/master/Hunting%20Queries/Microsoft%20365%20Defender/Ransomware/DEV-0270/Create%20new%20user%20with%20known%20DEV-0270%20username%20and%20password.yamlhttps://github.com/Azure/Azure-Sentinel/blob/master/Hunting%20Queries/Microsoft%20365%20Defender/Ransomware/DEV-0270/PowerShell%20adding%20exclusion%20path%20for%20Microsoft%20Defender%20of%20ProgramData.yamlhttps://github.com/Azure/Azure-Sentinel/blob/master/Detections/MultipleDataSources/Dev-0270RegistryIOCSep2022.yamlhttps://github.com/Azure/Azure-Sentinel/blob/master/Hunting%20Queries/Microsoft%20365%20Defender/Ransomware/DEV-0270/DLLHost.exe%20WMIC%20domain%20discovery.yamlhttps://github.com/Azure/Azure-Sentinel/blob/master/Detections/MultipleDataSources/Dev-0270NewUserSep2022.yamlhttps://github.com/Azure/Azure-Sentinel/blob/master/Hunting%20Queries/Microsoft%20365%20Defender/Ransomware/DEV-0270/Disabling%20Services%20via%20Registry.yamlhttps://github.com/Azure/Azure-Sentinel/blob/master/Hunting%20Queries/Microsoft%20365%20Defender/Ransomware/DEV-0270/Modifying%20the%20registry%20to%20add%20a%20ransom%20message%20notification.yamlhttps://github.com/Azure/Azure-Sentinel/blob/master/Hunting%20Queries/Microsoft%20365%20Defender/Ransomware/DEV-0270/Add%20malicious%20user%20to%20Admins%20and%20RDP%20users%20group%20via%20PowerShell.yamlhttps://github.com/Azure/Azure-Sentinel/blob/master/Hunting%20Queries/Microsoft%20365%20Defender/Ransomware/DEV-0270/DLLHost.exe%20file%20creation%20via%20PowerShell.yamlhttps://github.com/Azure/Azure-Sentinel/blob/master/Detections/MultipleDataSources/Dev-0270PowershellSep2022.yamlhttps://github.com/SecureAuthCorp/impacket/Microsoft News
Profiling DEV-0270: PHOSPHORUS’ ransomware operations
Microsoft threat intelligence teams have been tracking multiple ransomware campaigns tied to DEV-0270, also known as Nemesis Kitten, a sub-group of Iranian actor PHOSPHORUS.
#ParsedReport
08-09-2022
Crimeware Trends \| Ransomware Developers Turn to Intermittent Encryption to Evade Detection
https://www.sentinelone.com/labs/crimeware-trends-ransomware-developers-turn-to-intermittent-encryption-to-evade-detection
Actors/Campaigns:
Blackcat
Qilin
Threats:
Blackbasta
Qyick
Blackcat
Playcrypt
Conti
Industry:
Healthcare, Education, Financial, Energy
Geo:
Asia, Argentina, Africa, Russian, German
IOCs:
Hash: 4
Algorithms:
chacha20, aes
Win API:
LockFile
Languages:
rust
08-09-2022
Crimeware Trends \| Ransomware Developers Turn to Intermittent Encryption to Evade Detection
https://www.sentinelone.com/labs/crimeware-trends-ransomware-developers-turn-to-intermittent-encryption-to-evade-detection
Actors/Campaigns:
Blackcat
Qilin
Threats:
Blackbasta
Qyick
Blackcat
Playcrypt
Conti
Industry:
Healthcare, Education, Financial, Energy
Geo:
Asia, Argentina, Africa, Russian, German
IOCs:
Hash: 4
Algorithms:
chacha20, aes
Win API:
LockFile
Languages:
rust
SentinelOne
Crimeware Trends | Ransomware Developers Turn to Intermittent Encryption to Evade Detection
Partially encrypting victims' files improves ransomware speed and aids evasion. First seen in LockFile, the technique is now being widely adopted.
#ParsedReport
08-09-2022
Likely Iranian Threat Actor Conducts Politically Motivated Disruptive Activity Against Albanian Government Organizations
https://www.mandiant.com/resources/blog/likely-iranian-threat-actor-conducts-politically-motivated-disruptive-activity-against
Actors/Campaigns:
Cleaver (motivation: cyber_espionage)
Axiom
Threats:
Roadsweep
Chimneysweep
Zeroclear
Dustman_wiper
Markirat
Mosesstaff
Metasploit_tool
Delf
Netstat_tool
Process_injection_technique
Timestomp_technique
Industry:
Government
Geo:
Israeli, Iran, Lebanon, Albania, Bahrain, Iranian
TTPs:
Tactics: 3
Technics: 19
IOCs:
Domain: 9
File: 12
Hash: 20
IP: 1
Path: 4
Coin: 1
Registry: 2
Softs:
telegram, windows registry, windows service
Algorithms:
rc4, base64
Functions:
GetUpdates
Win API:
FindFirstFileW, socket, FindNextFileW, GetFileSize, DeviceIoControl, GetSystemDirectoryW, GetProcAddress, LoadLibrary
Platforms:
x86
YARA: Found
Links:
08-09-2022
Likely Iranian Threat Actor Conducts Politically Motivated Disruptive Activity Against Albanian Government Organizations
https://www.mandiant.com/resources/blog/likely-iranian-threat-actor-conducts-politically-motivated-disruptive-activity-against
Actors/Campaigns:
Cleaver (motivation: cyber_espionage)
Axiom
Threats:
Roadsweep
Chimneysweep
Zeroclear
Dustman_wiper
Markirat
Mosesstaff
Metasploit_tool
Delf
Netstat_tool
Process_injection_technique
Timestomp_technique
Industry:
Government
Geo:
Israeli, Iran, Lebanon, Albania, Bahrain, Iranian
TTPs:
Tactics: 3
Technics: 19
IOCs:
Domain: 9
File: 12
Hash: 20
IP: 1
Path: 4
Coin: 1
Registry: 2
Softs:
telegram, windows registry, windows service
Algorithms:
rc4, base64
Functions:
GetUpdates
Win API:
FindFirstFileW, socket, FindNextFileW, GetFileSize, DeviceIoControl, GetSystemDirectoryW, GetProcAddress, LoadLibrary
Platforms:
x86
YARA: Found
Links:
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/local/bypassuac\_silentcleanup.rbGoogle Cloud Blog
ROADSWEEP Ransomware Targets the Albanian Government | Google Cloud Blog
Mandiant identified the ROADSWEEP ransomware family which targeted the Albanian government in a politically motivated disruptive operation. Learn more.