В отчетах попадаются списки виндовых сервисов, которые стопаются вредоносом. Запилил парсинг их названий. С понедельника они тоже будут извлекаться из отчетов и добавляться в сообщения в телеге.
#ParsedReport
11-09-2022
Evasive Shikitega Linux malware drops Monero cryptominer
https://www.malwarebytes.com/blog/news/2022/09/evasive-shikitega-linux-malware-drops-monero-cryptominer
Threats:
Shikitega
Alien
Mettle
Metasploit_tool
Meterpreter_tool
Xmrig_miner
Geo:
Japanese
CVEs:
CVE-2021-4034 [Vulners]
Vulners: Score: 7.2, CVSS: 4.4,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- polkit project polkit (*)
- redhat enterprise linux desktop (7.0)
- redhat enterprise linux workstation (7.0)
- redhat enterprise linux for scientific computing (7.0)
- redhat enterprise linux server (7.0, 6.0)
have more...
CVE-2021-3493 [Vulners]
Vulners: Score: 7.2, CVSS: 4.1,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- canonical ubuntu linux (<18.04, <20.04, <20.10)
Algorithms:
xor, shikata_ga_nai
11-09-2022
Evasive Shikitega Linux malware drops Monero cryptominer
https://www.malwarebytes.com/blog/news/2022/09/evasive-shikitega-linux-malware-drops-monero-cryptominer
Threats:
Shikitega
Alien
Mettle
Metasploit_tool
Meterpreter_tool
Xmrig_miner
Geo:
Japanese
CVEs:
CVE-2021-4034 [Vulners]
Vulners: Score: 7.2, CVSS: 4.4,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- polkit project polkit (*)
- redhat enterprise linux desktop (7.0)
- redhat enterprise linux workstation (7.0)
- redhat enterprise linux for scientific computing (7.0)
- redhat enterprise linux server (7.0, 6.0)
have more...
CVE-2021-3493 [Vulners]
Vulners: Score: 7.2, CVSS: 4.1,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- canonical ubuntu linux (<18.04, <20.04, <20.10)
Algorithms:
xor, shikata_ga_nai
Vulners Database
CVE-2021-4034 - vulnerability database | Vulners.com
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of p...
#ParsedReport
12-09-2022
The Curious Case of Monti Ransomware: A Real-World Doppelganger
https://blogs.blackberry.com/en/2022/09/the-curious-case-of-monti-ransomware-a-real-world-doppelganger
Threats:
Monti
Conti
Log4shell_vuln
Anydesk_tool
Cobalt_strike
Gmer_tool
Megasync_tool
Mimikatz
Passthehash_technique
Netscan_tool
Putty_tool
Babuk
Yashma
Yanluowang
Chaos
Industry:
Financial
CVEs:
CVE-2021-44228 [Vulners]
Vulners: Score: 9.3, CVSS: 4.5,
Vulners: Exploitation: True
X-Force: Risk: 10
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, <2.15.0, <2.3.1, <2.12.2)
- siemens sppa-t3000 ses3000 firmware (*)
- siemens logo\! soft comfort (*)
- siemens spectrum power 4 (4.70, 4.70, <4.70, 4.70)
- siemens siveillance control pro (*)
have more...
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 9
Domain: 2
Hash: 7
Softs:
esxi, vmware horizon, chrome, active directory, internet explorer, psexec, winscp, local security authority
Algorithms:
xor, base64
YARA: Found
Links:
12-09-2022
The Curious Case of Monti Ransomware: A Real-World Doppelganger
https://blogs.blackberry.com/en/2022/09/the-curious-case-of-monti-ransomware-a-real-world-doppelganger
Threats:
Monti
Conti
Log4shell_vuln
Anydesk_tool
Cobalt_strike
Gmer_tool
Megasync_tool
Mimikatz
Passthehash_technique
Netscan_tool
Putty_tool
Babuk
Yashma
Yanluowang
Chaos
Industry:
Financial
CVEs:
CVE-2021-44228 [Vulners]
Vulners: Score: 9.3, CVSS: 4.5,
Vulners: Exploitation: True
X-Force: Risk: 10
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, <2.15.0, <2.3.1, <2.12.2)
- siemens sppa-t3000 ses3000 firmware (*)
- siemens logo\! soft comfort (*)
- siemens spectrum power 4 (4.70, 4.70, <4.70, 4.70)
- siemens siveillance control pro (*)
have more...
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 9
Domain: 2
Hash: 7
Softs:
esxi, vmware horizon, chrome, active directory, internet explorer, psexec, winscp, local security authority
Algorithms:
xor, base64
YARA: Found
Links:
https://github.com/sadshade/veeam-credsBlackBerry
The Curious Case of “Monti” Ransomware: A Real-World Doppelganger
While working a recent ransomware incident, BlackBerry identified a group whose name and TTPs mimicked the long-standing, popular ransomware crew Conti. Furthermore, the encryptor payload used in the attack was taken from the original group and modified for…
#ParsedReport
12-09-2022
THREAT ANALYSIS REPORT: PlugX RAT Loader Evolution
https://www.cybereason.com/blog/threat-analysis-report-plugx-rat-loader-evolution
Actors/Campaigns:
Emissary_panda
Threats:
Plugx_rat
Dll_sideloading_technique
Proxylogon_exploit
Thor
Industry:
Aerospace, Government
Geo:
Asia, Belarus, China, Ukrainian, Asian, Russia
TTPs:
Tactics: 6
Technics: 0
IOCs:
Hash: 18
File: 3
Algorithms:
rc4
Win API:
GetSystemTime, VirtualProtect, NtGlobalFlag, GetProcAddress, LoadLibraryA, VirtualAlloc, VirtualFree, ExitThread, RtlDecompressBuffer
12-09-2022
THREAT ANALYSIS REPORT: PlugX RAT Loader Evolution
https://www.cybereason.com/blog/threat-analysis-report-plugx-rat-loader-evolution
Actors/Campaigns:
Emissary_panda
Threats:
Plugx_rat
Dll_sideloading_technique
Proxylogon_exploit
Thor
Industry:
Aerospace, Government
Geo:
Asia, Belarus, China, Ukrainian, Asian, Russia
TTPs:
Tactics: 6
Technics: 0
IOCs:
Hash: 18
File: 3
Algorithms:
rc4
Win API:
GetSystemTime, VirtualProtect, NtGlobalFlag, GetProcAddress, LoadLibraryA, VirtualAlloc, VirtualFree, ExitThread, RtlDecompressBuffer
Cybereason
THREAT ANALYSIS REPORT: PlugX RAT Loader Evolution
PlugX is a post-exploitation modular RAT (Remote Access Trojan), which is known for its multiple functionalities such as data exfiltration, keystroke grabbing, backdoor functionality, and utilizing DLL-Sideloading techniques for evading security solutions...
#ParsedReport
12-09-2022
BRONZE PRESIDENT Targets Government Officials
https://www.secureworks.com/blog/bronze-president-targets-government-officials
Actors/Campaigns:
Red_delta (motivation: government_sponsored)
Threats:
Plugx_rat
Cobalt_strike
Industry:
Government
Geo:
Ukraine, Myanmar, Chinese, America, Vietnam, Suriname, China
IOCs:
File: 10
Hash: 112
IP: 3
Softs:
opera, avastbrowser
Algorithms:
xor
Win API:
GetCommandLineW, EnumThreadWindows, CheckRemoteDebuggerPresent
12-09-2022
BRONZE PRESIDENT Targets Government Officials
https://www.secureworks.com/blog/bronze-president-targets-government-officials
Actors/Campaigns:
Red_delta (motivation: government_sponsored)
Threats:
Plugx_rat
Cobalt_strike
Industry:
Government
Geo:
Ukraine, Myanmar, Chinese, America, Vietnam, Suriname, China
IOCs:
File: 10
Hash: 112
IP: 3
Softs:
opera, avastbrowser
Algorithms:
xor
Win API:
GetCommandLineW, EnumThreadWindows, CheckRemoteDebuggerPresent
Secureworks
BRONZE PRESIDENT Targets Government Officials
The likely Chinese government-sponsored threat group uses decoy documents and PlugX malware to compromise targets.
#ParsedReport
12-09-2022
BUGHATCH Malware Analysis. Key takeaways
https://www.elastic.co/security-labs/bughatch-malware-analysis
Threats:
Bughatch
Cuba
Termite
Process_injection_technique
Mimikatz
TTPs:
Tactics: 4
Technics: 0
IOCs:
Hash: 5
File: 4
Path: 1
Softs:
visual studio
Algorithms:
xor, base64
Functions:
CreateThread, RemoveEntryRecvLinkedList
Win API:
VirtualAlloc, WaitForSingleObject, CreateThread, Sleep, SeDebugPrivilege, QueryPerformanceCounter, GetIpAddrTable, AllocateAndInitializeSid, CheckTokenMembership, OpenProcessToken, have more...
Languages:
python
YARA: Found
Links:
12-09-2022
BUGHATCH Malware Analysis. Key takeaways
https://www.elastic.co/security-labs/bughatch-malware-analysis
Threats:
Bughatch
Cuba
Termite
Process_injection_technique
Mimikatz
TTPs:
Tactics: 4
Technics: 0
IOCs:
Hash: 5
File: 4
Path: 1
Softs:
visual studio
Algorithms:
xor, base64
Functions:
CreateThread, RemoveEntryRecvLinkedList
Win API:
VirtualAlloc, WaitForSingleObject, CreateThread, Sleep, SeDebugPrivilege, QueryPerformanceCounter, GetIpAddrTable, AllocateAndInitializeSid, CheckTokenMembership, OpenProcessToken, have more...
Languages:
python
YARA: Found
Links:
https://github.com/elastic/protections-artifacts/blob/main/yara/rules/Windows\_Trojan\_Bughatch.yarwww.elastic.co
BUGHATCH Malware Analysis — Elastic Security Labs
Elastic Security has performed a deep technical analysis of the BUGHATCH malware. This includes capabilities as well as defensive countermeasures.
#technique
Massayo is a small proof-of-concept Rust library based on UnhookingPOC, which removes AV/EDR hooks in a given system DLL.
https://github.com/thiagopeixoto/massayo
Massayo is a small proof-of-concept Rust library based on UnhookingPOC, which removes AV/EDR hooks in a given system DLL.
https://github.com/thiagopeixoto/massayo
GitHub
GitHub - thiagopeixoto/massayo: Massayo is a small proof-of-concept Rust library which removes AV/EDR hooks in a given system DLL
Massayo is a small proof-of-concept Rust library which removes AV/EDR hooks in a given system DLL - thiagopeixoto/massayo
#technique
https://www.secureworks.com/research/azure-active-directory-pass-through-authentication-flaws
https://www.secureworks.com/research/azure-active-directory-pass-through-authentication-flaws
Sophos
Azure Active Directory Pass-Through Authentication Flaws
In May 2022, Sophos® Counter Threat Unit™ (CTU) researchers analyzed how the protocols used by Pass-Through Authentication could be exploited.
#technique
In this blogpost we demonstrate an attack on the integrity of Sysmon which generates a minimal amount of observable events making this attack difficult to detect in environments where no additional security products are installed.
https://codewhitesec.blogspot.com/2022/09/attacks-on-sysmon-revisited-sysmonente.html
In this blogpost we demonstrate an attack on the integrity of Sysmon which generates a minimal amount of observable events making this attack difficult to detect in environments where no additional security products are installed.
https://codewhitesec.blogspot.com/2022/09/attacks-on-sysmon-revisited-sysmonente.html
Blogspot
CODE WHITE | Blog: Attacks on Sysmon Revisited - SysmonEnte
In this blogpost we demonstrate an attack on the integrity of Sysmon which generates a minimal amount of observable events making this attac...
#ParsedReport
13-09-2022
Look What You Made Me Do: TA453 Uses Multi-Persona Impersonation to Capitalize on FOMO
https://www.proofpoint.com/us/blog/threat-insight/ta453-uses-multi-persona-impersonation-capitalize-fomo
Actors/Campaigns:
Cleaver (motivation: cyber_espionage)
Phosphorus
Apt42
Cosmic_lynx
Threats:
Credential_harvesting_technique
Industry:
Education, Healthcare
Geo:
Israel, Russia
IOCs:
File: 5
Hash: 2
Domain: 2
Softs:
telegram
13-09-2022
Look What You Made Me Do: TA453 Uses Multi-Persona Impersonation to Capitalize on FOMO
https://www.proofpoint.com/us/blog/threat-insight/ta453-uses-multi-persona-impersonation-capitalize-fomo
Actors/Campaigns:
Cleaver (motivation: cyber_espionage)
Phosphorus
Apt42
Cosmic_lynx
Threats:
Credential_harvesting_technique
Industry:
Education, Healthcare
Geo:
Israel, Russia
IOCs:
File: 5
Hash: 2
Domain: 2
Softs:
telegram
Proofpoint
TA453 Uses Impersonation to Capitalize on FOMO | Proofpoint US
In 2022, TA453 used multi-persona impersonation to turn FOMO into a cybersecurity risk. Proofpoint details the FOMO cyber-attack, what it is, how it works, and more.
#ParsedReport
13-09-2022
. Risk reminder about the large -scale dissemination of the "demon thief" the stolen Trojan horse
https://www.antiy.cn/research/notice&report/research_report/20220913.html
Threats:
Sandbox_evasion_technique
Geo:
China, Malaysia
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 49
Path: 14
File: 18
Registry: 2
IP: 1
Domain: 3
Url: 45
Softs:
foxmail
Algorithms:
aes, base64, zip
Platforms:
intel, x86
13-09-2022
. Risk reminder about the large -scale dissemination of the "demon thief" the stolen Trojan horse
https://www.antiy.cn/research/notice&report/research_report/20220913.html
Threats:
Sandbox_evasion_technique
Geo:
China, Malaysia
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 49
Path: 14
File: 18
Registry: 2
IP: 1
Domain: 3
Url: 45
Softs:
foxmail
Algorithms:
aes, base64, zip
Platforms:
intel, x86
www.antiy.cn
关于“魔盗”窃密木马大规模传播的风险提示
近期,CNCERT和安天联合监测到一批伪装成CorelDraw、Notepad++、IDA Pro、WinHex等多款实用软件进行传播的窃密木马。通过跟踪监测发现其每日上线境内肉鸡数(以IP数计算)最多已超过1.3万,由于该窃密木马会收集浏览器书签、邮箱账户等信息,故我们将命名为“魔盗”。
#ParsedReport
13-09-2022
Phishing Campaign targets Japanese tax payers
https://blog.cyble.com/2022/09/13/phishing-campaign-targets-japanese-tax-payers
Actors/Campaigns:
Roaming_mantis
Threats:
Fakecop
Mantis_botnet
Industry:
Financial
Geo:
Japan, Singapore, Georgia, India, China, Australia, Japanese, Dubai
TTPs:
Tactics: 7
Technics: 10
IOCs:
Url: 57
File: 1
Hash: 1
Softs:
android
13-09-2022
Phishing Campaign targets Japanese tax payers
https://blog.cyble.com/2022/09/13/phishing-campaign-targets-japanese-tax-payers
Actors/Campaigns:
Roaming_mantis
Threats:
Fakecop
Mantis_botnet
Industry:
Financial
Geo:
Japan, Singapore, Georgia, India, China, Australia, Japanese, Dubai
TTPs:
Tactics: 7
Technics: 10
IOCs:
Url: 57
File: 1
Hash: 1
Softs:
android
Cyble
Cyble - Phishing Campaign Targets Japanese Tax Payers
Cyble, Research & Intelligence Labs analyzes the National Tax Agency Phishing Campaign targeting Japanese taxpayers.
#ParsedReport
13-09-2022
TikTok Breached by BlueHornet
https://cyberint.com/blog/research/tiktok-breached-by-bluehornet
Actors/Campaigns:
Bluehornet
Industry:
Government
Geo:
Iran, Belarus, American, Usa, Chinese, Korea, China, Russia
Softs:
tiktok, wechat
13-09-2022
TikTok Breached by BlueHornet
https://cyberint.com/blog/research/tiktok-breached-by-bluehornet
Actors/Campaigns:
Bluehornet
Industry:
Government
Geo:
Iran, Belarus, American, Usa, Chinese, Korea, China, Russia
Softs:
tiktok, wechat
Cyberint
TikTok Breached by BlueHornet
The breach of the popular social network TikTok occurred, revealing 1.7 billion records and relations to another popular Chinese app - WeChat
#ParsedReport
13-09-2022
Rise in XorDdos: A deeper look at the stealthy DDoS malware targeting Linux devices
https://www.microsoft.com/security/blog/2022/05/19/rise-in-xorddos-a-deeper-look-at-the-stealthy-ddos-malware-targeting-linux-devices
Threats:
Xorddos
Tsunami_botnet
Xmrig_miner
Netstat_tool
Industry:
Iot
TTPs:
Tactics: 3
Technics: 0
IOCs:
File: 3
Url: 1
Domain: 2
Hash: 19
Softs:
microsoft 365 defender, microsoft defender for endpoint, curl, sudo, unix, microsoft edge, microsoft defender
Algorithms:
xor, crc
Functions:
fork, setsid, signal, dec_conf, readlink, the, unhide, IOCTL, tcp4_seq_show, tcp6_seq_show, have more...
Platforms:
intel
Links:
13-09-2022
Rise in XorDdos: A deeper look at the stealthy DDoS malware targeting Linux devices
https://www.microsoft.com/security/blog/2022/05/19/rise-in-xorddos-a-deeper-look-at-the-stealthy-ddos-malware-targeting-linux-devices
Threats:
Xorddos
Tsunami_botnet
Xmrig_miner
Netstat_tool
Industry:
Iot
TTPs:
Tactics: 3
Technics: 0
IOCs:
File: 3
Url: 1
Domain: 2
Hash: 19
Softs:
microsoft 365 defender, microsoft defender for endpoint, curl, sudo, unix, microsoft edge, microsoft defender
Algorithms:
xor, crc
Functions:
fork, setsid, signal, dec_conf, readlink, the, unhide, IOCTL, tcp4_seq_show, tcp6_seq_show, have more...
Platforms:
intel
Links:
https://github.com/jermeyyy/rooty
https://github.com/mncoppola/suterusuMicrosoft News
Rise in XorDdos: A deeper look at the stealthy DDoS malware targeting Linux devices
Observing a 254% increase in activity over the last six months from a versatile Linux trojan called XorDdos, the Microsoft 365 Defender research team provides in-depth analysis into this stealthy malware's capabilities and key infection signs.
#ParsedReport
13-09-2022
OriginLogger: A Look at Agent Teslas Successor
https://unit42.paloaltonetworks.com/originlogger
Threats:
Originlogger
Agent_tesla
Reflectiveloader
Snip3_crypter
Atrium
Industry:
Financial
Geo:
German
IOCs:
Hash: 10
File: 16
IP: 5
Domain: 6
Path: 1
Url: 4
Softs:
discord, instagram, microsoft word, chrome, telegram
Algorithms:
zip, xor
Languages:
csharp, php
Links:
13-09-2022
OriginLogger: A Look at Agent Teslas Successor
https://unit42.paloaltonetworks.com/originlogger
Threats:
Originlogger
Agent_tesla
Reflectiveloader
Snip3_crypter
Atrium
Industry:
Financial
Geo:
German
IOCs:
Hash: 10
File: 16
IP: 5
Domain: 6
Path: 1
Url: 4
Softs:
discord, instagram, microsoft word, chrome, telegram
Algorithms:
zip, xor
Languages:
csharp, php
Links:
https://github.com/de4dot/de4dot
https://github.com/NYAN-x-CAT/CSharp-RunPE/blob/master/RunPE/RunPE.csUnit 42
OriginLogger: A Look at Agent Tesla’s Successor
We provide an overview of the OriginLogger keylogger, including info on a dropper lure and OriginLogger’s configuration and infrastructure.
#ParsedReport
13-09-2022
New Wave of Espionage Activity Targets Asian Governments
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/espionage-asia-governments
Actors/Campaigns:
Red_delta
Axiom
Threats:
Shadowpad
Dll_sideloading_technique
Nbtscan_tool
Tcping_tool
Fastreverseproxy_tool
Fscan_tool
Ladon_tool
Mimikatz
Procdump_tool
Ntdsutil_tool
Process_injection_technique
Proxylogon_exploit
Eternalblue_vuln
Plugx_rat
Trochilus_rat
Quasar_rat
Passview_tool
Powersploit
Powerview
Industry:
Government, Telco, Education, Financial, Aerospace
Geo:
Asian, Asia
CVEs:
CVE-2020-1472 [Vulners]
Vulners: Score: 9.3, CVSS: 3.8,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2)
- microsoft windows server 2012 (-, r2)
- microsoft windows server 2016 (-, 1903, 1909, 2004)
- microsoft windows server 2019 (-)
- fedoraproject fedora (31, 32, 33)
have more...
CVE-2021-26855 [Vulners]
Vulners: Score: 7.5, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 9.1
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2016, 2016, 2013, 2016, 2016, 2013, 2016, 2019, 2013, 2016, 2016, 2016, 2016, 2016, 2016, 2016, 2019, 2019, 2019, 2019, 2019, 2019, 2019, 2019)
IOCs:
File: 25
Hash: 33
Path: 2
IP: 7
Registry: 1
Softs:
psexec, active directory, local security authority
Links:
13-09-2022
New Wave of Espionage Activity Targets Asian Governments
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/espionage-asia-governments
Actors/Campaigns:
Red_delta
Axiom
Threats:
Shadowpad
Dll_sideloading_technique
Nbtscan_tool
Tcping_tool
Fastreverseproxy_tool
Fscan_tool
Ladon_tool
Mimikatz
Procdump_tool
Ntdsutil_tool
Process_injection_technique
Proxylogon_exploit
Eternalblue_vuln
Plugx_rat
Trochilus_rat
Quasar_rat
Passview_tool
Powersploit
Powerview
Industry:
Government, Telco, Education, Financial, Aerospace
Geo:
Asian, Asia
CVEs:
CVE-2020-1472 [Vulners]
Vulners: Score: 9.3, CVSS: 3.8,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2)
- microsoft windows server 2012 (-, r2)
- microsoft windows server 2016 (-, 1903, 1909, 2004)
- microsoft windows server 2019 (-)
- fedoraproject fedora (31, 32, 33)
have more...
CVE-2021-26855 [Vulners]
Vulners: Score: 7.5, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 9.1
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2016, 2016, 2013, 2016, 2016, 2013, 2016, 2019, 2013, 2016, 2016, 2016, 2016, 2016, 2016, 2016, 2019, 2019, 2019, 2019, 2019, 2019, 2019, 2019)
IOCs:
File: 25
Hash: 33
Path: 2
IP: 7
Registry: 1
Softs:
psexec, active directory, local security authority
Links:
https://github.com/k8gege/LadonGoSecurity
New Wave of Espionage Activity Targets Asian Governments
Governments and state-owned organizations are the latest targets of a well-established threat actor.
#ParsedReport
13-09-2022
Chiseling In: Lorenz Ransomware Group Cracks MiVoice And Calls Back For Free
https://arcticwolf.com/resources/blog/lorenz-ransomware-chiseling-in
Threats:
Lorenz
Lolbin
Chisel_tool
Crackmapexec_tool
Minidump_tool
Dumplsass_tool
Netstat_tool
Industry:
Iot
Geo:
China, Mexico
CVEs:
CVE-2022-29499 [Vulners]
Vulners: Score: 10.0, CVSS: 5.1,
Vulners: Exploitation: True
X-Force: Risk: 7.3
X-Force: Patch: Official fix
Soft:
- mitel mivoice connect (le22.20.2300.0)
TTPs:
Tactics: 11
Technics: 23
IOCs:
IP: 9
File: 12
Hash: 2
Url: 2
Path: 3
Registry: 1
Softs:
bitlocker, esxi, curl, openssl, local security authority, windows error reporting, task scheduler
Algorithms:
aes-256, base64
Languages:
php
YARA: Found
SIGMA: Found
Links:
13-09-2022
Chiseling In: Lorenz Ransomware Group Cracks MiVoice And Calls Back For Free
https://arcticwolf.com/resources/blog/lorenz-ransomware-chiseling-in
Threats:
Lorenz
Lolbin
Chisel_tool
Crackmapexec_tool
Minidump_tool
Dumplsass_tool
Netstat_tool
Industry:
Iot
Geo:
China, Mexico
CVEs:
CVE-2022-29499 [Vulners]
Vulners: Score: 10.0, CVSS: 5.1,
Vulners: Exploitation: True
X-Force: Risk: 7.3
X-Force: Patch: Official fix
Soft:
- mitel mivoice connect (le22.20.2300.0)
TTPs:
Tactics: 11
Technics: 23
IOCs:
IP: 9
File: 12
Hash: 2
Url: 2
Path: 3
Registry: 1
Softs:
bitlocker, esxi, curl, openssl, local security authority, windows error reporting, task scheduler
Algorithms:
aes-256, base64
Languages:
php
YARA: Found
SIGMA: Found
Links:
https://github.com/SigmaHQ/sigma/blob/b24e7ae9846f53cbbf61adad72f17af317c860a4/rules/windows/process\_creation/proc\_creation\_win\_powershell\_cmdline\_convertto\_securestring.yml
https://github.com/jpillora/chisel
https://github.com/Porchetta-Industries/CrackMapExec
https://github.com/SigmaHQ/sigma/blob/a80c29a7c2e2e500a1a532db2a2a8bd69bd4a63d/rules/windows/registry\_event/sysmon\_powershell\_as\_service.yml
https://github.com/Hackndo/lsassy
https://github.com/NVISOsecurity/sigma-public/blob/master/rules/windows/builtin/win\_atsvc\_task.yml
https://github.com/SigmaHQ/sigma/blob/master/rules/windows/sysmon/sysmon\_accessing\_winapi\_in\_powershell\_credentials\_dumping.yml
https://github.com/SigmaHQ/sigma/blob/1e16ed00905a496cbc3b0a1a03d4c2f6f4b63de2/rules/windows/process\_creation/proc\_creation\_win\_crackmapexec\_patterns.yml
https://github.com/rtkwlf/wolf-tools/blob/main/threat-intelligence/lorenz-ransomware-chiseling-in/lorenz-yara.yar
https://github.com/rtkwlf/wolf-tools/blob/main/threat-intelligence/lorenz-ransomware-chiseling-in/lorenz-suricata.rules
https://github.com/SigmaHQ/sigma
https://github.com/SigmaHQ/sigma/blob/ab814cbc408234eddf538bc893fcbe00c32ca2e9/rules/windows/process\_creation/win\_susp\_comsvcs\_procdump.ymlArctic Wolf
Lorenz Ransomware Group Cracks MiVoice | Arctic Wolf
Learn about Arctic Wolf Lab’s recent investigation into a Lorenz ransomware intrusion which leveraged a Mitel MiVoice VOIP appliance vulnerability for initial access and Microsoft’s BitLocker Drive Encryption for data encryption.
#technique
A cross platform C2/post-exploitation framework implementation by Rust.
https://github.com/b23r0/Heroinn
A cross platform C2/post-exploitation framework implementation by Rust.
https://github.com/b23r0/Heroinn
GitHub
GitHub - b23r0/Heroinn: A cross platform C2/post-exploitation framework.
A cross platform C2/post-exploitation framework. Contribute to b23r0/Heroinn development by creating an account on GitHub.
#technique
Caching the Un-cacheables - Abusing URL Parser Confusions (Web Cache Poisoning Technique)
https://nokline.github.io/bugbounty/2022/09/02/Glassdoor-Cache-Poisoning.html
Caching the Un-cacheables - Abusing URL Parser Confusions (Web Cache Poisoning Technique)
https://nokline.github.io/bugbounty/2022/09/02/Glassdoor-Cache-Poisoning.html
#ParsedReport
14-09-2022
ASEC Weekly Malware Statistics (August 29th, 2022 September 4th, 2022)
https://asec.ahnlab.com/en/38739
Threats:
Cloudeye
Formbook
Agent_tesla
Remcos_rat
Nanocore_rat
Clipboard_grabbing_technique
Lokibot_stealer
Industry:
Financial
Geo:
Korea
IOCs:
Url: 17
File: 15
Domain: 4
IP: 3
Email: 6
Softs:
nsis installer, discord
Languages:
php, visual_basic
14-09-2022
ASEC Weekly Malware Statistics (August 29th, 2022 September 4th, 2022)
https://asec.ahnlab.com/en/38739
Threats:
Cloudeye
Formbook
Agent_tesla
Remcos_rat
Nanocore_rat
Clipboard_grabbing_technique
Lokibot_stealer
Industry:
Financial
Geo:
Korea
IOCs:
Url: 17
File: 15
Domain: 4
IP: 3
Email: 6
Softs:
nsis installer, discord
Languages:
php, visual_basic
ASEC BLOG
ASEC Weekly Malware Statistics (August 29th, 2022 – September 4th, 2022) - ASEC BLOG
The ASEC analysis team is using the ASEC automatic analysis system RAPIT to categorize and respond to known malware. This post will list weekly statistics collected from August 29th, 2022 (Monday) to September 4th, 2022 (Sunday). For the main category, info…
#ParsedReport
14-09-2022
Phishing Websites Disguised as Korean Groupware Login Website Being Distributed
https://asec.ahnlab.com/en/38786
Geo:
Korean, Korea
IOCs:
Url: 6
Languages:
javascript
14-09-2022
Phishing Websites Disguised as Korean Groupware Login Website Being Distributed
https://asec.ahnlab.com/en/38786
Geo:
Korean, Korea
IOCs:
Url: 6
Languages:
javascript
ASEC BLOG
Phishing Websites Disguised as Korean Groupware Login Website Being Distributed - ASEC BLOG
The ASEC analysis team has been building a honeypot to collect various malware strains that are being distributed both in Korea and overseas. The honeypot also collects phishing emails and recently caught one targeting Korean users, which was being distributed…