CTT Report Hub
3.42K subscribers
9.87K photos
6 videos
67 files
13.5K links
Threat Intelligence Report Hub
Download Telegram
#ParsedReport
08-09-2022

THREAT ANALYSIS REPORT: PlugX RAT Loader Evolution

https://www.cybereason.com/blog/threat-analysis-report-plugx-rat-loader-evolution

Actors/Campaigns:
Emissary_panda

Threats:
Plugx_rat
Dll_sideloading_technique
Proxylogon_exploit
Thor

Industry:
Aerospace, Government

Geo:
China, Belarus, Ukrainian, Asia, Russia, Asian

TTPs:
Tactics: 6
Technics: 0

IOCs:
Hash: 18
File: 3

Algorithms:
rc4

Win API:
GetSystemTime, VirtualFree, VirtualProtect, LoadLibraryA, GetProcAddress, VirtualAlloc, NtGlobalFlag, ExitThread, RtlDecompressBuffer
#ParsedReport
08-09-2022

The Rise in Incidence of Fake e-shop Scams

https://blog.cyble.com/2022/09/08/the-rise-in-incidence-of-fake-e-shop-scams

Industry:
E-commerce, Energy, Media, Financial

Geo:
Georgia, Malaysia, Singapore, Malaysian, Australia, Dubai, Vietnam, India

TTPs:
Tactics: 5
Technics: 6

IOCs:
Url: 77
File: 1
Hash: 2

Softs:
android
#ParsedReport
08-09-2022

Microsoft investigates Iranian attacks against the Albanian government

https://www.microsoft.com/security/blog/2022/09/08/microsoft-investigates-iranian-attacks-against-the-albanian-government

Actors/Campaigns:
Dev-0861
Dev-0166
Siamesekitten
Europium

Threats:
Zerocleare_wiper
Hostile
Credential_harvesting_technique
Mimikatz
Impacket_tool
Trojan:win32/batrungoxml
Ransom:win32/eagle!msr
Trojan:win32/debitom.a
Proxylogon_exploit

Industry:
Ngo, Aerospace, Transport, Petroleum, Government, Healthcare, Telco, Energy

Geo:
Kuwait, Turkey, Irans, Albania, Tehrans, Tehran, American, Iranians, Jordan, Iran, Iranian, Israel

CVEs:
CVE-2021-26855 [Vulners]
Vulners: Score: 7.5, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 9.1
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2016, 2016, 2013, 2016, 2016, 2013, 2016, 2019, 2013, 2016, 2016, 2016, 2016, 2016, 2016, 2016, 2019, 2019, 2019, 2019, 2019, 2019, 2019, 2019)

CVE-2019-0604 [Vulners]
Vulners: Score: 7.5, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- microsoft sharepoint foundation (2013)
- microsoft sharepoint server (2019, 2010)
- microsoft sharepoint enterprise server (2016)


TTPs:
Tactics: 3
Technics: 0

IOCs:
IP: 8
File: 11
Hash: 21
Path: 8
Coin: 1
Registry: 1

Softs:
microsoft exchange, winlogon, microsoft defender, microsoft 365 defender, microsoft defender for endpoint, sharepoint server

Algorithms:
base64, zip, rc4

Functions:
rand

Win API:
SeDebugPrivilege, FindFirstVolumeW, GetOpenFileNameA, GetVolumePathNamesForVolumeNameW, CreateMutexA, SeImpersonatePrivilege, GetTokenInformation, CreateProcessWithTokenW, FindNextVolumeW, SetVolumeMountPointW, CreateDirectoryW

YARA: Found
#ParsedReport
08-09-2022

Raccoon Stealer 2.0 Malware analysis

https://any.run/cybersecurity-blog/raccoon-stealer-v2-malware-analysis/?utm_source=linkedin

Threats:
Raccoon_stealer
Recordbreaker_stealer
Follina_vuln

Industry:
Financial

TTPs:
Tactics: 1
Technics: 0

IOCs:
File: 4
Hash: 17
Registry: 1

Softs:
jaxx, tronlink, binancechain, telegram, jaxxliberty, chrome

Algorithms:
base64, xor, rc4

Functions:
x64-specific

Win API:
NtQueryInformationProcess

Languages:
python

Links:
https://github.com/mrexodia/TitanHide/commit/6a5a68a2447ad9454adfcbd9390ec05b9dcef2d6
https://github.com/mrexodia/TitanHide/issues/70
#ParsedReport
08-09-2022

The Week in Cybersecurity: Vice Society ransomware group targets back-to-school

https://blog.reversinglabs.com/blog/the-week-in-cybersecurity-vice-society-ransomware

Actors/Campaigns:
Vice_society (motivation: cyber_criminal)

Threats:
Hellokitty
Zeppelin
Cobalt_strike
Empire_loader
Systembc
Deadbolt
Shikitega
Sunburst

Industry:
Government, Financial, Education, Iot

Geo:
Montenegro, Americas, Russia
#ParsedReport
08-09-2022

SafeBreach Labs Researchers Uncover New Remote Access Trojan (RAT). CodeRAT Overview

https://www.safebreach.com/resources/blog/remote-access-trojan-coderat

Threats:
Coderat
Robothief
Antidebugging_technique

Industry:
E-commerce, Media, Government

Geo:
Iran, Tehran, Iranian, Irans

IOCs:
File: 9
Hash: 5

Softs:
visual studio, instagram, telegram, microsoft office, egram grou, microsoft powerpoint, android, microsoft word, windows media player, ram.org/bo

Functions:
BossWatch, CheckBoss

Win API:
CryptUnprotectData

Languages:
python

Platforms:
x86

YARA: Found

Links:
https://github.com/MrModed/DWM
#ParsedReport
07-09-2022

Profiling DEV-0270: PHOSPHORUS ransomware operations

https://www.microsoft.com/security/blog/2022/09/07/profiling-dev-0270-phosphorus-ransomware-operations

Actors/Campaigns:
Phosphorus

Threats:
Lolbin
Log4shell_vuln
Minidump_tool
Impacket_tool
Mamba
Credential_stealing_technique
Lazagne
Mimikatz
Proxyshell_vuln

Industry:
Government

Geo:
Iran, Iranian

CVEs:
CVE-2021-26858 [Vulners]
Vulners: Score: 6.8, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2013, 2016, 2016, 2019, 2019)

CVE-2021-27065 [Vulners]
Vulners: Score: 6.8, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2013, 2016, 2016, 2016, 2016, 2013, 2016, 2019, 2013, 2016, 2016, 2016, 2016, 2016, 2016, 2016, 2019, 2019, 2019, 2019, 2019, 2019, 2019)

CVE-2021-26855 [Vulners]
Vulners: Score: 7.5, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 9.1
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2016, 2016, 2013, 2016, 2016, 2013, 2016, 2019, 2013, 2016, 2016, 2016, 2016, 2016, 2016, 2016, 2019, 2019, 2019, 2019, 2019, 2019, 2019, 2019)

CVE-2018-13379 [Vulners]
Vulners: Score: 5.0, CVSS: 3.2,
Vulners: Exploitation: True
X-Force: Risk: 7.5
X-Force: Patch: Official fix
Soft:
- fortinet fortios (le6.0.4, le5.6.7)

CVE-2021-26857 [Vulners]
Vulners: Score: 6.8, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2010, 2013, 2019, 2016, 2019, 2016)


TTPs:
Tactics: 8
Technics: 0

IOCs:
File: 15
Domain: 2
Registry: 2

Softs:
microsoft defender for endpoint, local security authority, bitlocker, microsoft defender, microsoft 365 defender, task scheduler, psexec

Links:
https://github.com/Azure/Azure-Sentinel/blob/master/Hunting%20Queries/Microsoft%20365%20Defender/Ransomware/DEV-0270/Email%20data%20exfiltration%20via%20PowerShell.yaml
https://github.com/Azure/Azure-Sentinel/blob/master/Detections/MultipleDataSources/Dev-0270WMICDiscoverySep2022.yaml
https://github.com/Azure/Azure-Sentinel/blob/master/Hunting%20Queries/Microsoft%20365%20Defender/Ransomware/DEV-0270/Create%20new%20user%20with%20known%20DEV-0270%20username%20and%20password.yaml
https://github.com/Azure/Azure-Sentinel/blob/master/Hunting%20Queries/Microsoft%20365%20Defender/Ransomware/DEV-0270/PowerShell%20adding%20exclusion%20path%20for%20Microsoft%20Defender%20of%20ProgramData.yaml
https://github.com/Azure/Azure-Sentinel/blob/master/Detections/MultipleDataSources/Dev-0270RegistryIOCSep2022.yaml
https://github.com/Azure/Azure-Sentinel/blob/master/Hunting%20Queries/Microsoft%20365%20Defender/Ransomware/DEV-0270/DLLHost.exe%20WMIC%20domain%20discovery.yaml
https://github.com/Azure/Azure-Sentinel/blob/master/Detections/MultipleDataSources/Dev-0270NewUserSep2022.yaml
https://github.com/Azure/Azure-Sentinel/blob/master/Hunting%20Queries/Microsoft%20365%20Defender/Ransomware/DEV-0270/Disabling%20Services%20via%20Registry.yaml
https://github.com/Azure/Azure-Sentinel/blob/master/Hunting%20Queries/Microsoft%20365%20Defender/Ransomware/DEV-0270/Modifying%20the%20registry%20to%20add%20a%20ransom%20message%20notification.yaml
https://github.com/Azure/Azure-Sentinel/blob/master/Hunting%20Queries/Microsoft%20365%20Defender/Ransomware/DEV-0270/Add%20malicious%20user%20to%20Admins%20and%20RDP%20users%20group%20via%20PowerShell.yaml
https://github.com/Azure/Azure-Sentinel/blob/master/Hunting%20Queries/Microsoft%20365%20Defender/Ransomware/DEV-0270/DLLHost.exe%20file%20creation%20via%20PowerShell.yaml
https://github.com/Azure/Azure-Sentinel/blob/master/Detections/MultipleDataSources/Dev-0270PowershellSep2022.yaml
https://github.com/SecureAuthCorp/impacket/
#ParsedReport
08-09-2022

Crimeware Trends \| Ransomware Developers Turn to Intermittent Encryption to Evade Detection

https://www.sentinelone.com/labs/crimeware-trends-ransomware-developers-turn-to-intermittent-encryption-to-evade-detection

Actors/Campaigns:
Blackcat
Qilin

Threats:
Blackbasta
Qyick
Blackcat
Playcrypt
Conti

Industry:
Healthcare, Education, Financial, Energy

Geo:
Asia, Argentina, Africa, Russian, German

IOCs:
Hash: 4

Algorithms:
chacha20, aes

Win API:
LockFile

Languages:
rust
#ParsedReport
08-09-2022

Likely Iranian Threat Actor Conducts Politically Motivated Disruptive Activity Against Albanian Government Organizations

https://www.mandiant.com/resources/blog/likely-iranian-threat-actor-conducts-politically-motivated-disruptive-activity-against

Actors/Campaigns:
Cleaver (motivation: cyber_espionage)
Axiom

Threats:
Roadsweep
Chimneysweep
Zeroclear
Dustman_wiper
Markirat
Mosesstaff
Metasploit_tool
Delf
Netstat_tool
Process_injection_technique
Timestomp_technique

Industry:
Government

Geo:
Israeli, Iran, Lebanon, Albania, Bahrain, Iranian

TTPs:
Tactics: 3
Technics: 19

IOCs:
Domain: 9
File: 12
Hash: 20
IP: 1
Path: 4
Coin: 1
Registry: 2

Softs:
telegram, windows registry, windows service

Algorithms:
rc4, base64

Functions:
GetUpdates

Win API:
FindFirstFileW, socket, FindNextFileW, GetFileSize, DeviceIoControl, GetSystemDirectoryW, GetProcAddress, LoadLibrary

Platforms:
x86

YARA: Found

Links:
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/local/bypassuac\_silentcleanup.rb
#ParsedReport
08-09-2022

Lazarus and the tale of three RATs

http://blog.talosintelligence.com/2022/09/lazarus-three-rats.html

Actors/Campaigns:
Lazarus (motivation: cyber_espionage)

Threats:
Vsingle
Yamabot
Magicrat
Bespoke
Log4shell_vuln
Dtrack_rat
Mauicrypt
Netstat_tool
Putty_tool
Plink
Impacket_tool
Credential_harvesting_technique
Mimikatz
Procdump_tool
Wevtutil_tool
Adfind_tool

Industry:
Government, Energy

Geo:
Japan, Korean, Canada, Korea, Japanese

TTPs:
Tactics: 4
Technics: 21

IOCs:
IP: 12
File: 24
Path: 13
Registry: 12
Coin: 1
Hash: 15
Url: 40

Softs:
windows defender, 3proxy, active directory, vmware horizon, vssadmin

Algorithms:
base64

Win API:
select

Languages:
golang, php, java, python

Platforms:
x86

Links:
https://github.com/3proxy/3proxy
#ParsedReport
09-09-2022

LUNA Ransomware Attack Pattern Analysis. Key Takeaways

https://www.elastic.co/security-labs/luna-ransomware-attack-pattern

Threats:
Luna
Seth_locker
Cuba

Geo:
Switzerland

TTPs:
Tactics: 4
Technics: 0

IOCs:
File: 974

Algorithms:
base64, aes, curve25519

Win API:
NtLmSsp

Languages:
python, rust

YARA: Found

Links:
https://github.com/dalek-cryptography/x25519-dalek
https://github.com/elastic/protections-artifacts/blob/main/behavior/rules/defense\_evasion\_attempt\_to\_disable\_windows\_defender\_services.toml
#ParsedReport
09-09-2022

Charming Kitten: Can We Have A Meeting?

https://blog.certfa.com/posts/charming-kitten-can-we-wave-a-meeting

Actors/Campaigns:
Cleaver (motivation: cyber_espionage)
Apt42 (motivation: cyber_espionage)
Phosphorus (motivation: cyber_espionage)

Industry:
Education, Government, Financial, Healthcare

Geo:
Iraq, American, Iranian, Iran, Syria, French, France, Irans, Israel, Libya, Africa

IOCs:
Url: 3
Domain: 78
IP: 13
Email: 5
Hash: 1

Softs:
zoom
В отчетах попадаются списки виндовых сервисов, которые стопаются вредоносом. Запилил парсинг их названий. С понедельника они тоже будут извлекаться из отчетов и добавляться в сообщения в телеге.
#ParsedReport
11-09-2022

Evasive Shikitega Linux malware drops Monero cryptominer

https://www.malwarebytes.com/blog/news/2022/09/evasive-shikitega-linux-malware-drops-monero-cryptominer

Threats:
Shikitega
Alien
Mettle
Metasploit_tool
Meterpreter_tool
Xmrig_miner

Geo:
Japanese

CVEs:
CVE-2021-4034 [Vulners]
Vulners: Score: 7.2, CVSS: 4.4,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- polkit project polkit (*)
- redhat enterprise linux desktop (7.0)
- redhat enterprise linux workstation (7.0)
- redhat enterprise linux for scientific computing (7.0)
- redhat enterprise linux server (7.0, 6.0)
have more...
CVE-2021-3493 [Vulners]
Vulners: Score: 7.2, CVSS: 4.1,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- canonical ubuntu linux (<18.04, <20.04, <20.10)


Algorithms:
xor, shikata_ga_nai