#ParsedReport
07-09-2022
ASEC (20220829 \~ 20220904). ASEC Weekly Malware Statistics (20220829 \~ 20220904)
https://asec.ahnlab.com/ko/38557
Threats:
Cloudeye
Postealer
Formbook
Agent_tesla
Remcos_rat
Nanocore_rat
Azorult
Clipboard_grabbing_technique
Lokibot_stealer
Industry:
Transport, Financial
Geo:
Korea
IOCs:
File: 26
Url: 17
Domain: 4
IP: 3
Email: 6
Softs:
nsis installer, discord
Languages:
visual_basic, php
07-09-2022
ASEC (20220829 \~ 20220904). ASEC Weekly Malware Statistics (20220829 \~ 20220904)
https://asec.ahnlab.com/ko/38557
Threats:
Cloudeye
Postealer
Formbook
Agent_tesla
Remcos_rat
Nanocore_rat
Azorult
Clipboard_grabbing_technique
Lokibot_stealer
Industry:
Transport, Financial
Geo:
Korea
IOCs:
File: 26
Url: 17
Domain: 4
IP: 3
Email: 6
Softs:
nsis installer, discord
Languages:
visual_basic, php
ASEC BLOG
ASEC 주간 악성코드 통계 (20220829 ~ 20220904) - ASEC BLOG
ASEC 분석팀에서는 ASEC 자동 분석 시스템 RAPIT 을 활용하여 알려진 악성코드들에 대한 분류 및 대응을 진행하고 있다. 본 포스팅에서는 2022년 8월 29일 월요일부터 9월 4일 일요일까지 한 주간 수집된 악성코드의 통계를 정리한다. 대분류 상으로는 인포스틸러가 45.9%로 1위를 차지하였으며, 그 다음으로는 다운로더 악성코드가 28.1%, 백도어 18.5%, 랜섬웨어 6.2%, 코인마이너 및 뱅킹 악성코드가 각각 0.7%로 집계되었다. Top…
Кажется, pornhub запустил краудсорсинговую кампанию )))
https://www.malwarebytes.com/blog/news/2022/09/sextortionists-used-mobile-malware-to-steal-nude-videos-contact-lists-from-victims
https://www.malwarebytes.com/blog/news/2022/09/sextortionists-used-mobile-malware-to-steal-nude-videos-contact-lists-from-victims
Malwarebytes
Sextortionists used mobile malware to steal nude videos, contact lists from victims
In an international police action supported by Interpol, law enforcement agencies have uncovered and dismantled an international sextortion ring.
#ParsedReport
08-09-2022
THREAT ANALYSIS REPORT: PlugX RAT Loader Evolution
https://www.cybereason.com/blog/threat-analysis-report-plugx-rat-loader-evolution
Actors/Campaigns:
Emissary_panda
Threats:
Plugx_rat
Dll_sideloading_technique
Proxylogon_exploit
Thor
Industry:
Aerospace, Government
Geo:
China, Belarus, Ukrainian, Asia, Russia, Asian
TTPs:
Tactics: 6
Technics: 0
IOCs:
Hash: 18
File: 3
Algorithms:
rc4
Win API:
GetSystemTime, VirtualFree, VirtualProtect, LoadLibraryA, GetProcAddress, VirtualAlloc, NtGlobalFlag, ExitThread, RtlDecompressBuffer
08-09-2022
THREAT ANALYSIS REPORT: PlugX RAT Loader Evolution
https://www.cybereason.com/blog/threat-analysis-report-plugx-rat-loader-evolution
Actors/Campaigns:
Emissary_panda
Threats:
Plugx_rat
Dll_sideloading_technique
Proxylogon_exploit
Thor
Industry:
Aerospace, Government
Geo:
China, Belarus, Ukrainian, Asia, Russia, Asian
TTPs:
Tactics: 6
Technics: 0
IOCs:
Hash: 18
File: 3
Algorithms:
rc4
Win API:
GetSystemTime, VirtualFree, VirtualProtect, LoadLibraryA, GetProcAddress, VirtualAlloc, NtGlobalFlag, ExitThread, RtlDecompressBuffer
Cybereason
THREAT ANALYSIS REPORT: PlugX RAT Loader Evolution
PlugX is a post-exploitation modular RAT (Remote Access Trojan), which is known for its multiple functionalities such as data exfiltration, keystroke grabbing, backdoor functionality, and utilizing DLL-Sideloading techniques for evading security solutions...
#ParsedReport
08-09-2022
Warning issued about Vice Society ransomware targeting the education sector
https://www.malwarebytes.com/blog/news/2022/09/authorities-issue-warning-about-vice-society-ransomware-targeting-the-education-sector
Actors/Campaigns:
Vice_society
Threats:
Medusalocker
Zeppelin
Hellokitty
Printnightmare_vuln
Empire_loader
Cobalt_strike
Systembc
Industry:
Education
Geo:
Russian
08-09-2022
Warning issued about Vice Society ransomware targeting the education sector
https://www.malwarebytes.com/blog/news/2022/09/authorities-issue-warning-about-vice-society-ransomware-targeting-the-education-sector
Actors/Campaigns:
Vice_society
Threats:
Medusalocker
Zeppelin
Hellokitty
Printnightmare_vuln
Empire_loader
Cobalt_strike
Systembc
Industry:
Education
Geo:
Russian
ThreatDown by Malwarebytes
Warning issued about Vice Society ransomware targeting the education sector - ThreatDown by Malwarebytes
The Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), and the Multi-State Information Sharing and Analysis Center (MS-ISAC) have released a joint…
#ParsedReport
08-09-2022
The Rise in Incidence of Fake e-shop Scams
https://blog.cyble.com/2022/09/08/the-rise-in-incidence-of-fake-e-shop-scams
Industry:
E-commerce, Energy, Media, Financial
Geo:
Georgia, Malaysia, Singapore, Malaysian, Australia, Dubai, Vietnam, India
TTPs:
Tactics: 5
Technics: 6
IOCs:
Url: 77
File: 1
Hash: 2
Softs:
android
08-09-2022
The Rise in Incidence of Fake e-shop Scams
https://blog.cyble.com/2022/09/08/the-rise-in-incidence-of-fake-e-shop-scams
Industry:
E-commerce, Energy, Media, Financial
Geo:
Georgia, Malaysia, Singapore, Malaysian, Australia, Dubai, Vietnam, India
TTPs:
Tactics: 5
Technics: 6
IOCs:
Url: 77
File: 1
Hash: 2
Softs:
android
#ParsedReport
08-09-2022
Microsoft investigates Iranian attacks against the Albanian government
https://www.microsoft.com/security/blog/2022/09/08/microsoft-investigates-iranian-attacks-against-the-albanian-government
Actors/Campaigns:
Dev-0861
Dev-0166
Siamesekitten
Europium
Threats:
Zerocleare_wiper
Hostile
Credential_harvesting_technique
Mimikatz
Impacket_tool
Trojan:win32/batrungoxml
Ransom:win32/eagle!msr
Trojan:win32/debitom.a
Proxylogon_exploit
Industry:
Ngo, Aerospace, Transport, Petroleum, Government, Healthcare, Telco, Energy
Geo:
Kuwait, Turkey, Irans, Albania, Tehrans, Tehran, American, Iranians, Jordan, Iran, Iranian, Israel
CVEs:
CVE-2021-26855 [Vulners]
Vulners: Score: 7.5, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 9.1
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2016, 2016, 2013, 2016, 2016, 2013, 2016, 2019, 2013, 2016, 2016, 2016, 2016, 2016, 2016, 2016, 2019, 2019, 2019, 2019, 2019, 2019, 2019, 2019)
CVE-2019-0604 [Vulners]
Vulners: Score: 7.5, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- microsoft sharepoint foundation (2013)
- microsoft sharepoint server (2019, 2010)
- microsoft sharepoint enterprise server (2016)
TTPs:
Tactics: 3
Technics: 0
IOCs:
IP: 8
File: 11
Hash: 21
Path: 8
Coin: 1
Registry: 1
Softs:
microsoft exchange, winlogon, microsoft defender, microsoft 365 defender, microsoft defender for endpoint, sharepoint server
Algorithms:
base64, zip, rc4
Functions:
rand
Win API:
SeDebugPrivilege, FindFirstVolumeW, GetOpenFileNameA, GetVolumePathNamesForVolumeNameW, CreateMutexA, SeImpersonatePrivilege, GetTokenInformation, CreateProcessWithTokenW, FindNextVolumeW, SetVolumeMountPointW, CreateDirectoryW
YARA: Found
08-09-2022
Microsoft investigates Iranian attacks against the Albanian government
https://www.microsoft.com/security/blog/2022/09/08/microsoft-investigates-iranian-attacks-against-the-albanian-government
Actors/Campaigns:
Dev-0861
Dev-0166
Siamesekitten
Europium
Threats:
Zerocleare_wiper
Hostile
Credential_harvesting_technique
Mimikatz
Impacket_tool
Trojan:win32/batrungoxml
Ransom:win32/eagle!msr
Trojan:win32/debitom.a
Proxylogon_exploit
Industry:
Ngo, Aerospace, Transport, Petroleum, Government, Healthcare, Telco, Energy
Geo:
Kuwait, Turkey, Irans, Albania, Tehrans, Tehran, American, Iranians, Jordan, Iran, Iranian, Israel
CVEs:
CVE-2021-26855 [Vulners]
Vulners: Score: 7.5, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 9.1
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2016, 2016, 2013, 2016, 2016, 2013, 2016, 2019, 2013, 2016, 2016, 2016, 2016, 2016, 2016, 2016, 2019, 2019, 2019, 2019, 2019, 2019, 2019, 2019)
CVE-2019-0604 [Vulners]
Vulners: Score: 7.5, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- microsoft sharepoint foundation (2013)
- microsoft sharepoint server (2019, 2010)
- microsoft sharepoint enterprise server (2016)
TTPs:
Tactics: 3
Technics: 0
IOCs:
IP: 8
File: 11
Hash: 21
Path: 8
Coin: 1
Registry: 1
Softs:
microsoft exchange, winlogon, microsoft defender, microsoft 365 defender, microsoft defender for endpoint, sharepoint server
Algorithms:
base64, zip, rc4
Functions:
rand
Win API:
SeDebugPrivilege, FindFirstVolumeW, GetOpenFileNameA, GetVolumePathNamesForVolumeNameW, CreateMutexA, SeImpersonatePrivilege, GetTokenInformation, CreateProcessWithTokenW, FindNextVolumeW, SetVolumeMountPointW, CreateDirectoryW
YARA: Found
Microsoft News
Microsoft investigates Iranian attacks against the Albanian government
Shortly after the destructive cyberattacks on the Albanian government in mid-July, the Microsoft Detection and Response Team (DART) was engaged to lead an investigation into the attacks.
#ParsedReport
08-09-2022
Raccoon Stealer 2.0 Malware analysis
https://any.run/cybersecurity-blog/raccoon-stealer-v2-malware-analysis/?utm_source=linkedin
Threats:
Raccoon_stealer
Recordbreaker_stealer
Follina_vuln
Industry:
Financial
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 4
Hash: 17
Registry: 1
Softs:
jaxx, tronlink, binancechain, telegram, jaxxliberty, chrome
Algorithms:
base64, xor, rc4
Functions:
x64-specific
Win API:
NtQueryInformationProcess
Languages:
python
Links:
08-09-2022
Raccoon Stealer 2.0 Malware analysis
https://any.run/cybersecurity-blog/raccoon-stealer-v2-malware-analysis/?utm_source=linkedin
Threats:
Raccoon_stealer
Recordbreaker_stealer
Follina_vuln
Industry:
Financial
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 4
Hash: 17
Registry: 1
Softs:
jaxx, tronlink, binancechain, telegram, jaxxliberty, chrome
Algorithms:
base64, xor, rc4
Functions:
x64-specific
Win API:
NtQueryInformationProcess
Languages:
python
Links:
https://github.com/mrexodia/TitanHide/commit/6a5a68a2447ad9454adfcbd9390ec05b9dcef2d6https://github.com/mrexodia/TitanHide/issues/70ANY.RUN's Cybersecurity Blog
Raccoon Stealer 2.0 Malware analysis - ANY.RUN's Cybersecurity Blog
ANY.RUN team of analytics has done a malware research of Raccoon Stealer 2.0. Check our results, including the script to extract C2 servers.
#ParsedReport
08-09-2022
The Week in Cybersecurity: Vice Society ransomware group targets back-to-school
https://blog.reversinglabs.com/blog/the-week-in-cybersecurity-vice-society-ransomware
Actors/Campaigns:
Vice_society (motivation: cyber_criminal)
Threats:
Hellokitty
Zeppelin
Cobalt_strike
Empire_loader
Systembc
Deadbolt
Shikitega
Sunburst
Industry:
Government, Financial, Education, Iot
Geo:
Montenegro, Americas, Russia
08-09-2022
The Week in Cybersecurity: Vice Society ransomware group targets back-to-school
https://blog.reversinglabs.com/blog/the-week-in-cybersecurity-vice-society-ransomware
Actors/Campaigns:
Vice_society (motivation: cyber_criminal)
Threats:
Hellokitty
Zeppelin
Cobalt_strike
Empire_loader
Systembc
Deadbolt
Shikitega
Sunburst
Industry:
Government, Financial, Education, Iot
Geo:
Montenegro, Americas, Russia
ReversingLabs
The Week in Cybersecurity: Vice Society ransomware group targets back-to-school
This week: Vice Society ransomware group targets America’s education sector, the U.S. government’s new position on software supply chain security, and more.
#ParsedReport
08-09-2022
(Magniber) (*.cpl -> *.jse) 9/8. Magniber Ransomware Change ( *.cpl-> *.jse) -9/8
https://asec.ahnlab.com/ko/38706
Threats:
Magniber
Typosquatting_technique
IOCs:
File: 2
Hash: 1
Softs:
chrome
Algorithms:
zip
08-09-2022
(Magniber) (*.cpl -> *.jse) 9/8. Magniber Ransomware Change ( *.cpl-> *.jse) -9/8
https://asec.ahnlab.com/ko/38706
Threats:
Magniber
Typosquatting_technique
IOCs:
File: 2
Hash: 1
Softs:
chrome
Algorithms:
zip
ASEC
매그니베르(Magniber) 랜섬웨어 변경(*.cpl -> *.jse) – 9/8일자 - ASEC
7월 20일에 MSI 형식에서 CPL 형식으로 유포방식을 변경한 이후, 8월 중순 이후부터 유포가 잠시 주춤한 것으로 확인되고 있었다. 지속적으로 변화 상황을 모니터링 하던 중, 2022년 9월 8일부터는 유포 방식이 *.CPL (DLL형식)에서 *.JSE (스크립트) 형태로 변경된 것을 확인하였다. 매그니베르 랜섬웨어는 국내 사용자에 가장 큰 피해를 주는 랜섬웨어 중 하나로 활발하게 유포되고 있고, 백신의 탐지를 우회하기 위한 […]
#ParsedReport
08-09-2022
SafeBreach Labs Researchers Uncover New Remote Access Trojan (RAT). CodeRAT Overview
https://www.safebreach.com/resources/blog/remote-access-trojan-coderat
Threats:
Coderat
Robothief
Antidebugging_technique
Industry:
E-commerce, Media, Government
Geo:
Iran, Tehran, Iranian, Irans
IOCs:
File: 9
Hash: 5
Softs:
visual studio, instagram, telegram, microsoft office, egram grou, microsoft powerpoint, android, microsoft word, windows media player, ram.org/bo
Functions:
BossWatch, CheckBoss
Win API:
CryptUnprotectData
Languages:
python
Platforms:
x86
YARA: Found
Links:
08-09-2022
SafeBreach Labs Researchers Uncover New Remote Access Trojan (RAT). CodeRAT Overview
https://www.safebreach.com/resources/blog/remote-access-trojan-coderat
Threats:
Coderat
Robothief
Antidebugging_technique
Industry:
E-commerce, Media, Government
Geo:
Iran, Tehran, Iranian, Irans
IOCs:
File: 9
Hash: 5
Softs:
visual studio, instagram, telegram, microsoft office, egram grou, microsoft powerpoint, android, microsoft word, windows media player, ram.org/bo
Functions:
BossWatch, CheckBoss
Win API:
CryptUnprotectData
Languages:
python
Platforms:
x86
YARA: Found
Links:
https://github.com/MrModed/DWMSafeBreach
SafeBreach Uncovers New Remote Access Trojan (RAT)
Dubbed CodeRAT, the new RAT is used in attacks targeting Farsi-speaking code developers using a Microsoft Dynamic Data Exchange (DDE) exploit.
#ParsedReport
07-09-2022
Profiling DEV-0270: PHOSPHORUS ransomware operations
https://www.microsoft.com/security/blog/2022/09/07/profiling-dev-0270-phosphorus-ransomware-operations
Actors/Campaigns:
Phosphorus
Threats:
Lolbin
Log4shell_vuln
Minidump_tool
Impacket_tool
Mamba
Credential_stealing_technique
Lazagne
Mimikatz
Proxyshell_vuln
Industry:
Government
Geo:
Iran, Iranian
CVEs:
CVE-2021-26858 [Vulners]
Vulners: Score: 6.8, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2013, 2016, 2016, 2019, 2019)
CVE-2021-27065 [Vulners]
Vulners: Score: 6.8, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2013, 2016, 2016, 2016, 2016, 2013, 2016, 2019, 2013, 2016, 2016, 2016, 2016, 2016, 2016, 2016, 2019, 2019, 2019, 2019, 2019, 2019, 2019)
CVE-2021-26855 [Vulners]
Vulners: Score: 7.5, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 9.1
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2016, 2016, 2013, 2016, 2016, 2013, 2016, 2019, 2013, 2016, 2016, 2016, 2016, 2016, 2016, 2016, 2019, 2019, 2019, 2019, 2019, 2019, 2019, 2019)
CVE-2018-13379 [Vulners]
Vulners: Score: 5.0, CVSS: 3.2,
Vulners: Exploitation: True
X-Force: Risk: 7.5
X-Force: Patch: Official fix
Soft:
- fortinet fortios (le6.0.4, le5.6.7)
CVE-2021-26857 [Vulners]
Vulners: Score: 6.8, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2010, 2013, 2019, 2016, 2019, 2016)
TTPs:
Tactics: 8
Technics: 0
IOCs:
File: 15
Domain: 2
Registry: 2
Softs:
microsoft defender for endpoint, local security authority, bitlocker, microsoft defender, microsoft 365 defender, task scheduler, psexec
Links:
07-09-2022
Profiling DEV-0270: PHOSPHORUS ransomware operations
https://www.microsoft.com/security/blog/2022/09/07/profiling-dev-0270-phosphorus-ransomware-operations
Actors/Campaigns:
Phosphorus
Threats:
Lolbin
Log4shell_vuln
Minidump_tool
Impacket_tool
Mamba
Credential_stealing_technique
Lazagne
Mimikatz
Proxyshell_vuln
Industry:
Government
Geo:
Iran, Iranian
CVEs:
CVE-2021-26858 [Vulners]
Vulners: Score: 6.8, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2013, 2016, 2016, 2019, 2019)
CVE-2021-27065 [Vulners]
Vulners: Score: 6.8, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2013, 2016, 2016, 2016, 2016, 2013, 2016, 2019, 2013, 2016, 2016, 2016, 2016, 2016, 2016, 2016, 2019, 2019, 2019, 2019, 2019, 2019, 2019)
CVE-2021-26855 [Vulners]
Vulners: Score: 7.5, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 9.1
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2016, 2016, 2013, 2016, 2016, 2013, 2016, 2019, 2013, 2016, 2016, 2016, 2016, 2016, 2016, 2016, 2019, 2019, 2019, 2019, 2019, 2019, 2019, 2019)
CVE-2018-13379 [Vulners]
Vulners: Score: 5.0, CVSS: 3.2,
Vulners: Exploitation: True
X-Force: Risk: 7.5
X-Force: Patch: Official fix
Soft:
- fortinet fortios (le6.0.4, le5.6.7)
CVE-2021-26857 [Vulners]
Vulners: Score: 6.8, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2010, 2013, 2019, 2016, 2019, 2016)
TTPs:
Tactics: 8
Technics: 0
IOCs:
File: 15
Domain: 2
Registry: 2
Softs:
microsoft defender for endpoint, local security authority, bitlocker, microsoft defender, microsoft 365 defender, task scheduler, psexec
Links:
https://github.com/Azure/Azure-Sentinel/blob/master/Hunting%20Queries/Microsoft%20365%20Defender/Ransomware/DEV-0270/Email%20data%20exfiltration%20via%20PowerShell.yamlhttps://github.com/Azure/Azure-Sentinel/blob/master/Detections/MultipleDataSources/Dev-0270WMICDiscoverySep2022.yamlhttps://github.com/Azure/Azure-Sentinel/blob/master/Hunting%20Queries/Microsoft%20365%20Defender/Ransomware/DEV-0270/Create%20new%20user%20with%20known%20DEV-0270%20username%20and%20password.yamlhttps://github.com/Azure/Azure-Sentinel/blob/master/Hunting%20Queries/Microsoft%20365%20Defender/Ransomware/DEV-0270/PowerShell%20adding%20exclusion%20path%20for%20Microsoft%20Defender%20of%20ProgramData.yamlhttps://github.com/Azure/Azure-Sentinel/blob/master/Detections/MultipleDataSources/Dev-0270RegistryIOCSep2022.yamlhttps://github.com/Azure/Azure-Sentinel/blob/master/Hunting%20Queries/Microsoft%20365%20Defender/Ransomware/DEV-0270/DLLHost.exe%20WMIC%20domain%20discovery.yamlhttps://github.com/Azure/Azure-Sentinel/blob/master/Detections/MultipleDataSources/Dev-0270NewUserSep2022.yamlhttps://github.com/Azure/Azure-Sentinel/blob/master/Hunting%20Queries/Microsoft%20365%20Defender/Ransomware/DEV-0270/Disabling%20Services%20via%20Registry.yamlhttps://github.com/Azure/Azure-Sentinel/blob/master/Hunting%20Queries/Microsoft%20365%20Defender/Ransomware/DEV-0270/Modifying%20the%20registry%20to%20add%20a%20ransom%20message%20notification.yamlhttps://github.com/Azure/Azure-Sentinel/blob/master/Hunting%20Queries/Microsoft%20365%20Defender/Ransomware/DEV-0270/Add%20malicious%20user%20to%20Admins%20and%20RDP%20users%20group%20via%20PowerShell.yamlhttps://github.com/Azure/Azure-Sentinel/blob/master/Hunting%20Queries/Microsoft%20365%20Defender/Ransomware/DEV-0270/DLLHost.exe%20file%20creation%20via%20PowerShell.yamlhttps://github.com/Azure/Azure-Sentinel/blob/master/Detections/MultipleDataSources/Dev-0270PowershellSep2022.yamlhttps://github.com/SecureAuthCorp/impacket/Microsoft News
Profiling DEV-0270: PHOSPHORUS’ ransomware operations
Microsoft threat intelligence teams have been tracking multiple ransomware campaigns tied to DEV-0270, also known as Nemesis Kitten, a sub-group of Iranian actor PHOSPHORUS.
#ParsedReport
08-09-2022
Crimeware Trends \| Ransomware Developers Turn to Intermittent Encryption to Evade Detection
https://www.sentinelone.com/labs/crimeware-trends-ransomware-developers-turn-to-intermittent-encryption-to-evade-detection
Actors/Campaigns:
Blackcat
Qilin
Threats:
Blackbasta
Qyick
Blackcat
Playcrypt
Conti
Industry:
Healthcare, Education, Financial, Energy
Geo:
Asia, Argentina, Africa, Russian, German
IOCs:
Hash: 4
Algorithms:
chacha20, aes
Win API:
LockFile
Languages:
rust
08-09-2022
Crimeware Trends \| Ransomware Developers Turn to Intermittent Encryption to Evade Detection
https://www.sentinelone.com/labs/crimeware-trends-ransomware-developers-turn-to-intermittent-encryption-to-evade-detection
Actors/Campaigns:
Blackcat
Qilin
Threats:
Blackbasta
Qyick
Blackcat
Playcrypt
Conti
Industry:
Healthcare, Education, Financial, Energy
Geo:
Asia, Argentina, Africa, Russian, German
IOCs:
Hash: 4
Algorithms:
chacha20, aes
Win API:
LockFile
Languages:
rust
SentinelOne
Crimeware Trends | Ransomware Developers Turn to Intermittent Encryption to Evade Detection
Partially encrypting victims' files improves ransomware speed and aids evasion. First seen in LockFile, the technique is now being widely adopted.
#ParsedReport
08-09-2022
Likely Iranian Threat Actor Conducts Politically Motivated Disruptive Activity Against Albanian Government Organizations
https://www.mandiant.com/resources/blog/likely-iranian-threat-actor-conducts-politically-motivated-disruptive-activity-against
Actors/Campaigns:
Cleaver (motivation: cyber_espionage)
Axiom
Threats:
Roadsweep
Chimneysweep
Zeroclear
Dustman_wiper
Markirat
Mosesstaff
Metasploit_tool
Delf
Netstat_tool
Process_injection_technique
Timestomp_technique
Industry:
Government
Geo:
Israeli, Iran, Lebanon, Albania, Bahrain, Iranian
TTPs:
Tactics: 3
Technics: 19
IOCs:
Domain: 9
File: 12
Hash: 20
IP: 1
Path: 4
Coin: 1
Registry: 2
Softs:
telegram, windows registry, windows service
Algorithms:
rc4, base64
Functions:
GetUpdates
Win API:
FindFirstFileW, socket, FindNextFileW, GetFileSize, DeviceIoControl, GetSystemDirectoryW, GetProcAddress, LoadLibrary
Platforms:
x86
YARA: Found
Links:
08-09-2022
Likely Iranian Threat Actor Conducts Politically Motivated Disruptive Activity Against Albanian Government Organizations
https://www.mandiant.com/resources/blog/likely-iranian-threat-actor-conducts-politically-motivated-disruptive-activity-against
Actors/Campaigns:
Cleaver (motivation: cyber_espionage)
Axiom
Threats:
Roadsweep
Chimneysweep
Zeroclear
Dustman_wiper
Markirat
Mosesstaff
Metasploit_tool
Delf
Netstat_tool
Process_injection_technique
Timestomp_technique
Industry:
Government
Geo:
Israeli, Iran, Lebanon, Albania, Bahrain, Iranian
TTPs:
Tactics: 3
Technics: 19
IOCs:
Domain: 9
File: 12
Hash: 20
IP: 1
Path: 4
Coin: 1
Registry: 2
Softs:
telegram, windows registry, windows service
Algorithms:
rc4, base64
Functions:
GetUpdates
Win API:
FindFirstFileW, socket, FindNextFileW, GetFileSize, DeviceIoControl, GetSystemDirectoryW, GetProcAddress, LoadLibrary
Platforms:
x86
YARA: Found
Links:
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/local/bypassuac\_silentcleanup.rbGoogle Cloud Blog
ROADSWEEP Ransomware Targets the Albanian Government | Google Cloud Blog
Mandiant identified the ROADSWEEP ransomware family which targeted the Albanian government in a politically motivated disruptive operation. Learn more.
#ParsedReport
08-09-2022
Lazarus and the tale of three RATs
http://blog.talosintelligence.com/2022/09/lazarus-three-rats.html
Actors/Campaigns:
Lazarus (motivation: cyber_espionage)
Threats:
Vsingle
Yamabot
Magicrat
Bespoke
Log4shell_vuln
Dtrack_rat
Mauicrypt
Netstat_tool
Putty_tool
Plink
Impacket_tool
Credential_harvesting_technique
Mimikatz
Procdump_tool
Wevtutil_tool
Adfind_tool
Industry:
Government, Energy
Geo:
Japan, Korean, Canada, Korea, Japanese
TTPs:
Tactics: 4
Technics: 21
IOCs:
IP: 12
File: 24
Path: 13
Registry: 12
Coin: 1
Hash: 15
Url: 40
Softs:
windows defender, 3proxy, active directory, vmware horizon, vssadmin
Algorithms:
base64
Win API:
select
Languages:
golang, php, java, python
Platforms:
x86
Links:
08-09-2022
Lazarus and the tale of three RATs
http://blog.talosintelligence.com/2022/09/lazarus-three-rats.html
Actors/Campaigns:
Lazarus (motivation: cyber_espionage)
Threats:
Vsingle
Yamabot
Magicrat
Bespoke
Log4shell_vuln
Dtrack_rat
Mauicrypt
Netstat_tool
Putty_tool
Plink
Impacket_tool
Credential_harvesting_technique
Mimikatz
Procdump_tool
Wevtutil_tool
Adfind_tool
Industry:
Government, Energy
Geo:
Japan, Korean, Canada, Korea, Japanese
TTPs:
Tactics: 4
Technics: 21
IOCs:
IP: 12
File: 24
Path: 13
Registry: 12
Coin: 1
Hash: 15
Url: 40
Softs:
windows defender, 3proxy, active directory, vmware horizon, vssadmin
Algorithms:
base64
Win API:
select
Languages:
golang, php, java, python
Platforms:
x86
Links:
https://github.com/3proxy/3proxyCisco Talos Blog
Lazarus and the tale of three RATs
Cisco Talos assesses with high confidence these attacks have been conducted by the North Korean state-sponsored threat actor Lazarus Group.
#technique
Aggressorscript that turns the headless aggressor client into a (mostly) functional cobalt strike client.
https://github.com/CodeXTF2/cobaltstrike-headless
Aggressorscript that turns the headless aggressor client into a (mostly) functional cobalt strike client.
https://github.com/CodeXTF2/cobaltstrike-headless
GitHub
GitHub - CodeXTF2/cobaltstrike-headless: Aggressorscript that turns the headless aggressor client into a (mostly) functional cobalt…
Aggressorscript that turns the headless aggressor client into a (mostly) functional cobalt strike client. - CodeXTF2/cobaltstrike-headless
#ParsedReport
09-09-2022
LUNA Ransomware Attack Pattern Analysis. Key Takeaways
https://www.elastic.co/security-labs/luna-ransomware-attack-pattern
Threats:
Luna
Seth_locker
Cuba
Geo:
Switzerland
TTPs:
Tactics: 4
Technics: 0
IOCs:
File: 974
Algorithms:
base64, aes, curve25519
Win API:
NtLmSsp
Languages:
python, rust
YARA: Found
Links:
09-09-2022
LUNA Ransomware Attack Pattern Analysis. Key Takeaways
https://www.elastic.co/security-labs/luna-ransomware-attack-pattern
Threats:
Luna
Seth_locker
Cuba
Geo:
Switzerland
TTPs:
Tactics: 4
Technics: 0
IOCs:
File: 974
Algorithms:
base64, aes, curve25519
Win API:
NtLmSsp
Languages:
python, rust
YARA: Found
Links:
https://github.com/dalek-cryptography/x25519-dalek
https://github.com/elastic/protections-artifacts/blob/main/behavior/rules/defense\_evasion\_attempt\_to\_disable\_windows\_defender\_services.tomlwww.elastic.co
LUNA Ransomware Attack Pattern Analysis — Elastic Security Labs
In this research publication, we'll explore the LUNA attack pattern — a cross-platform ransomware variant.
#ParsedReport
09-09-2022
Charming Kitten: Can We Have A Meeting?
https://blog.certfa.com/posts/charming-kitten-can-we-wave-a-meeting
Actors/Campaigns:
Cleaver (motivation: cyber_espionage)
Apt42 (motivation: cyber_espionage)
Phosphorus (motivation: cyber_espionage)
Industry:
Education, Government, Financial, Healthcare
Geo:
Iraq, American, Iranian, Iran, Syria, French, France, Irans, Israel, Libya, Africa
IOCs:
Url: 3
Domain: 78
IP: 13
Email: 5
Hash: 1
Softs:
zoom
09-09-2022
Charming Kitten: Can We Have A Meeting?
https://blog.certfa.com/posts/charming-kitten-can-we-wave-a-meeting
Actors/Campaigns:
Cleaver (motivation: cyber_espionage)
Apt42 (motivation: cyber_espionage)
Phosphorus (motivation: cyber_espionage)
Industry:
Education, Government, Financial, Healthcare
Geo:
Iraq, American, Iranian, Iran, Syria, French, France, Irans, Israel, Libya, Africa
IOCs:
Url: 3
Domain: 78
IP: 13
Email: 5
Hash: 1
Softs:
zoom
Certfa
Charming Kitten: “Can We Have A Meeting?” - Certfa Lab
Our recent investigation at Certfa Lab, the APT42 has been running multiple phishing campaigns since late 2021 and some of them are ongoing and still active.
В отчетах попадаются списки виндовых сервисов, которые стопаются вредоносом. Запилил парсинг их названий. С понедельника они тоже будут извлекаться из отчетов и добавляться в сообщения в телеге.
#ParsedReport
11-09-2022
Evasive Shikitega Linux malware drops Monero cryptominer
https://www.malwarebytes.com/blog/news/2022/09/evasive-shikitega-linux-malware-drops-monero-cryptominer
Threats:
Shikitega
Alien
Mettle
Metasploit_tool
Meterpreter_tool
Xmrig_miner
Geo:
Japanese
CVEs:
CVE-2021-4034 [Vulners]
Vulners: Score: 7.2, CVSS: 4.4,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- polkit project polkit (*)
- redhat enterprise linux desktop (7.0)
- redhat enterprise linux workstation (7.0)
- redhat enterprise linux for scientific computing (7.0)
- redhat enterprise linux server (7.0, 6.0)
have more...
CVE-2021-3493 [Vulners]
Vulners: Score: 7.2, CVSS: 4.1,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- canonical ubuntu linux (<18.04, <20.04, <20.10)
Algorithms:
xor, shikata_ga_nai
11-09-2022
Evasive Shikitega Linux malware drops Monero cryptominer
https://www.malwarebytes.com/blog/news/2022/09/evasive-shikitega-linux-malware-drops-monero-cryptominer
Threats:
Shikitega
Alien
Mettle
Metasploit_tool
Meterpreter_tool
Xmrig_miner
Geo:
Japanese
CVEs:
CVE-2021-4034 [Vulners]
Vulners: Score: 7.2, CVSS: 4.4,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- polkit project polkit (*)
- redhat enterprise linux desktop (7.0)
- redhat enterprise linux workstation (7.0)
- redhat enterprise linux for scientific computing (7.0)
- redhat enterprise linux server (7.0, 6.0)
have more...
CVE-2021-3493 [Vulners]
Vulners: Score: 7.2, CVSS: 4.1,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- canonical ubuntu linux (<18.04, <20.04, <20.10)
Algorithms:
xor, shikata_ga_nai
Vulners Database
CVE-2021-4034 - vulnerability database | Vulners.com
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of p...