CTT Report Hub
3.43K subscribers
9.88K photos
6 videos
67 files
13.5K links
Threat Intelligence Report Hub
Download Telegram
#ParsedReport
08-09-2022

Likely Iranian Threat Actor Conducts Politically Motivated Disruptive Activity Against Albanian Government Organizations

https://www.mandiant.com/resources/blog/likely-iranian-threat-actor-conducts-politically-motivated-disruptive-activity-against

Actors/Campaigns:
Cleaver (motivation: cyber_espionage)
Axiom

Threats:
Roadsweep
Chimneysweep
Zeroclear
Dustman_wiper
Markirat
Mosesstaff
Metasploit_tool
Delf
Netstat_tool
Process_injection_technique
Timestomp_technique

Industry:
Government

Geo:
Israeli, Iran, Lebanon, Albania, Bahrain, Iranian

TTPs:
Tactics: 3
Technics: 19

IOCs:
Domain: 9
File: 12
Hash: 20
IP: 1
Path: 4
Coin: 1
Registry: 2

Softs:
telegram, windows registry, windows service

Algorithms:
rc4, base64

Functions:
GetUpdates

Win API:
FindFirstFileW, socket, FindNextFileW, GetFileSize, DeviceIoControl, GetSystemDirectoryW, GetProcAddress, LoadLibrary

Platforms:
x86

YARA: Found

Links:
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/local/bypassuac\_silentcleanup.rb
#ParsedReport
08-09-2022

Lazarus and the tale of three RATs

http://blog.talosintelligence.com/2022/09/lazarus-three-rats.html

Actors/Campaigns:
Lazarus (motivation: cyber_espionage)

Threats:
Vsingle
Yamabot
Magicrat
Bespoke
Log4shell_vuln
Dtrack_rat
Mauicrypt
Netstat_tool
Putty_tool
Plink
Impacket_tool
Credential_harvesting_technique
Mimikatz
Procdump_tool
Wevtutil_tool
Adfind_tool

Industry:
Government, Energy

Geo:
Japan, Korean, Canada, Korea, Japanese

TTPs:
Tactics: 4
Technics: 21

IOCs:
IP: 12
File: 24
Path: 13
Registry: 12
Coin: 1
Hash: 15
Url: 40

Softs:
windows defender, 3proxy, active directory, vmware horizon, vssadmin

Algorithms:
base64

Win API:
select

Languages:
golang, php, java, python

Platforms:
x86

Links:
https://github.com/3proxy/3proxy
#ParsedReport
09-09-2022

LUNA Ransomware Attack Pattern Analysis. Key Takeaways

https://www.elastic.co/security-labs/luna-ransomware-attack-pattern

Threats:
Luna
Seth_locker
Cuba

Geo:
Switzerland

TTPs:
Tactics: 4
Technics: 0

IOCs:
File: 974

Algorithms:
base64, aes, curve25519

Win API:
NtLmSsp

Languages:
python, rust

YARA: Found

Links:
https://github.com/dalek-cryptography/x25519-dalek
https://github.com/elastic/protections-artifacts/blob/main/behavior/rules/defense\_evasion\_attempt\_to\_disable\_windows\_defender\_services.toml
#ParsedReport
09-09-2022

Charming Kitten: Can We Have A Meeting?

https://blog.certfa.com/posts/charming-kitten-can-we-wave-a-meeting

Actors/Campaigns:
Cleaver (motivation: cyber_espionage)
Apt42 (motivation: cyber_espionage)
Phosphorus (motivation: cyber_espionage)

Industry:
Education, Government, Financial, Healthcare

Geo:
Iraq, American, Iranian, Iran, Syria, French, France, Irans, Israel, Libya, Africa

IOCs:
Url: 3
Domain: 78
IP: 13
Email: 5
Hash: 1

Softs:
zoom
В отчетах попадаются списки виндовых сервисов, которые стопаются вредоносом. Запилил парсинг их названий. С понедельника они тоже будут извлекаться из отчетов и добавляться в сообщения в телеге.
#ParsedReport
11-09-2022

Evasive Shikitega Linux malware drops Monero cryptominer

https://www.malwarebytes.com/blog/news/2022/09/evasive-shikitega-linux-malware-drops-monero-cryptominer

Threats:
Shikitega
Alien
Mettle
Metasploit_tool
Meterpreter_tool
Xmrig_miner

Geo:
Japanese

CVEs:
CVE-2021-4034 [Vulners]
Vulners: Score: 7.2, CVSS: 4.4,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- polkit project polkit (*)
- redhat enterprise linux desktop (7.0)
- redhat enterprise linux workstation (7.0)
- redhat enterprise linux for scientific computing (7.0)
- redhat enterprise linux server (7.0, 6.0)
have more...
CVE-2021-3493 [Vulners]
Vulners: Score: 7.2, CVSS: 4.1,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- canonical ubuntu linux (<18.04, <20.04, <20.10)


Algorithms:
xor, shikata_ga_nai
#ParsedReport
12-09-2022

The Curious Case of Monti Ransomware: A Real-World Doppelganger

https://blogs.blackberry.com/en/2022/09/the-curious-case-of-monti-ransomware-a-real-world-doppelganger

Threats:
Monti
Conti
Log4shell_vuln
Anydesk_tool
Cobalt_strike
Gmer_tool
Megasync_tool
Mimikatz
Passthehash_technique
Netscan_tool
Putty_tool
Babuk
Yashma
Yanluowang
Chaos

Industry:
Financial

CVEs:
CVE-2021-44228 [Vulners]
Vulners: Score: 9.3, CVSS: 4.5,
Vulners: Exploitation: True
X-Force: Risk: 10
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, <2.15.0, <2.3.1, <2.12.2)
- siemens sppa-t3000 ses3000 firmware (*)
- siemens logo\! soft comfort (*)
- siemens spectrum power 4 (4.70, 4.70, <4.70, 4.70)
- siemens siveillance control pro (*)
have more...

TTPs:
Tactics: 2
Technics: 0

IOCs:
File: 9
Domain: 2
Hash: 7

Softs:
esxi, vmware horizon, chrome, active directory, internet explorer, psexec, winscp, local security authority

Algorithms:
xor, base64


YARA: Found

Links:
https://github.com/sadshade/veeam-creds
#ParsedReport
12-09-2022

THREAT ANALYSIS REPORT: PlugX RAT Loader Evolution

https://www.cybereason.com/blog/threat-analysis-report-plugx-rat-loader-evolution

Actors/Campaigns:
Emissary_panda

Threats:
Plugx_rat
Dll_sideloading_technique
Proxylogon_exploit
Thor

Industry:
Aerospace, Government

Geo:
Asia, Belarus, China, Ukrainian, Asian, Russia

TTPs:
Tactics: 6
Technics: 0

IOCs:
Hash: 18
File: 3

Algorithms:
rc4

Win API:
GetSystemTime, VirtualProtect, NtGlobalFlag, GetProcAddress, LoadLibraryA, VirtualAlloc, VirtualFree, ExitThread, RtlDecompressBuffer
#ParsedReport
12-09-2022

BRONZE PRESIDENT Targets Government Officials

https://www.secureworks.com/blog/bronze-president-targets-government-officials

Actors/Campaigns:
Red_delta (motivation: government_sponsored)

Threats:
Plugx_rat
Cobalt_strike

Industry:
Government

Geo:
Ukraine, Myanmar, Chinese, America, Vietnam, Suriname, China

IOCs:
File: 10
Hash: 112
IP: 3

Softs:
opera, avastbrowser

Algorithms:
xor

Win API:
GetCommandLineW, EnumThreadWindows, CheckRemoteDebuggerPresent
#ParsedReport
12-09-2022

BUGHATCH Malware Analysis. Key takeaways

https://www.elastic.co/security-labs/bughatch-malware-analysis

Threats:
Bughatch
Cuba
Termite
Process_injection_technique
Mimikatz

TTPs:
Tactics: 4
Technics: 0

IOCs:
Hash: 5
File: 4
Path: 1

Softs:
visual studio

Algorithms:
xor, base64

Functions:
CreateThread, RemoveEntryRecvLinkedList

Win API:
VirtualAlloc, WaitForSingleObject, CreateThread, Sleep, SeDebugPrivilege, QueryPerformanceCounter, GetIpAddrTable, AllocateAndInitializeSid, CheckTokenMembership, OpenProcessToken, have more...

Languages:
python

YARA: Found

Links:
https://github.com/elastic/protections-artifacts/blob/main/yara/rules/Windows\_Trojan\_Bughatch.yar
#technique

In this blogpost we demonstrate an attack on the integrity of Sysmon which generates a minimal amount of observable events making this attack difficult to detect in environments where no additional security products are installed.

https://codewhitesec.blogspot.com/2022/09/attacks-on-sysmon-revisited-sysmonente.html
#ParsedReport
13-09-2022

Look What You Made Me Do: TA453 Uses Multi-Persona Impersonation to Capitalize on FOMO

https://www.proofpoint.com/us/blog/threat-insight/ta453-uses-multi-persona-impersonation-capitalize-fomo

Actors/Campaigns:
Cleaver (motivation: cyber_espionage)
Phosphorus
Apt42
Cosmic_lynx

Threats:
Credential_harvesting_technique

Industry:
Education, Healthcare

Geo:
Israel, Russia

IOCs:
File: 5
Hash: 2
Domain: 2

Softs:
telegram
#ParsedReport
13-09-2022

Phishing Campaign targets Japanese tax payers

https://blog.cyble.com/2022/09/13/phishing-campaign-targets-japanese-tax-payers

Actors/Campaigns:
Roaming_mantis

Threats:
Fakecop
Mantis_botnet

Industry:
Financial

Geo:
Japan, Singapore, Georgia, India, China, Australia, Japanese, Dubai

TTPs:
Tactics: 7
Technics: 10

IOCs:
Url: 57
File: 1
Hash: 1

Softs:
android
#ParsedReport
13-09-2022

Rise in XorDdos: A deeper look at the stealthy DDoS malware targeting Linux devices

https://www.microsoft.com/security/blog/2022/05/19/rise-in-xorddos-a-deeper-look-at-the-stealthy-ddos-malware-targeting-linux-devices

Threats:
Xorddos
Tsunami_botnet
Xmrig_miner
Netstat_tool

Industry:
Iot

TTPs:
Tactics: 3
Technics: 0

IOCs:
File: 3
Url: 1
Domain: 2
Hash: 19

Softs:
microsoft 365 defender, microsoft defender for endpoint, curl, sudo, unix, microsoft edge, microsoft defender

Algorithms:
xor, crc

Functions:
fork, setsid, signal, dec_conf, readlink, the, unhide, IOCTL, tcp4_seq_show, tcp6_seq_show, have more...

Platforms:
intel

Links:
https://github.com/jermeyyy/rooty
https://github.com/mncoppola/suterusu
#ParsedReport
13-09-2022

OriginLogger: A Look at Agent Teslas Successor

https://unit42.paloaltonetworks.com/originlogger

Threats:
Originlogger
Agent_tesla
Reflectiveloader
Snip3_crypter
Atrium

Industry:
Financial

Geo:
German

IOCs:
Hash: 10
File: 16
IP: 5
Domain: 6
Path: 1
Url: 4

Softs:
discord, instagram, microsoft word, chrome, telegram

Algorithms:
zip, xor


Languages:
csharp, php

Links:
https://github.com/de4dot/de4dot
https://github.com/NYAN-x-CAT/CSharp-RunPE/blob/master/RunPE/RunPE.cs