CTT Report Hub
3.43K subscribers
9.88K photos
6 videos
67 files
13.5K links
Threat Intelligence Report Hub
Download Telegram
#ParsedReport
12-09-2022

The Curious Case of Monti Ransomware: A Real-World Doppelganger

https://blogs.blackberry.com/en/2022/09/the-curious-case-of-monti-ransomware-a-real-world-doppelganger

Threats:
Monti
Conti
Log4shell_vuln
Anydesk_tool
Cobalt_strike
Gmer_tool
Megasync_tool
Mimikatz
Passthehash_technique
Netscan_tool
Putty_tool
Babuk
Yashma
Yanluowang
Chaos

Industry:
Financial

CVEs:
CVE-2021-44228 [Vulners]
Vulners: Score: 9.3, CVSS: 4.5,
Vulners: Exploitation: True
X-Force: Risk: 10
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, <2.15.0, <2.3.1, <2.12.2)
- siemens sppa-t3000 ses3000 firmware (*)
- siemens logo\! soft comfort (*)
- siemens spectrum power 4 (4.70, 4.70, <4.70, 4.70)
- siemens siveillance control pro (*)
have more...

TTPs:
Tactics: 2
Technics: 0

IOCs:
File: 9
Domain: 2
Hash: 7

Softs:
esxi, vmware horizon, chrome, active directory, internet explorer, psexec, winscp, local security authority

Algorithms:
xor, base64


YARA: Found

Links:
https://github.com/sadshade/veeam-creds
#ParsedReport
12-09-2022

THREAT ANALYSIS REPORT: PlugX RAT Loader Evolution

https://www.cybereason.com/blog/threat-analysis-report-plugx-rat-loader-evolution

Actors/Campaigns:
Emissary_panda

Threats:
Plugx_rat
Dll_sideloading_technique
Proxylogon_exploit
Thor

Industry:
Aerospace, Government

Geo:
Asia, Belarus, China, Ukrainian, Asian, Russia

TTPs:
Tactics: 6
Technics: 0

IOCs:
Hash: 18
File: 3

Algorithms:
rc4

Win API:
GetSystemTime, VirtualProtect, NtGlobalFlag, GetProcAddress, LoadLibraryA, VirtualAlloc, VirtualFree, ExitThread, RtlDecompressBuffer
#ParsedReport
12-09-2022

BRONZE PRESIDENT Targets Government Officials

https://www.secureworks.com/blog/bronze-president-targets-government-officials

Actors/Campaigns:
Red_delta (motivation: government_sponsored)

Threats:
Plugx_rat
Cobalt_strike

Industry:
Government

Geo:
Ukraine, Myanmar, Chinese, America, Vietnam, Suriname, China

IOCs:
File: 10
Hash: 112
IP: 3

Softs:
opera, avastbrowser

Algorithms:
xor

Win API:
GetCommandLineW, EnumThreadWindows, CheckRemoteDebuggerPresent
#ParsedReport
12-09-2022

BUGHATCH Malware Analysis. Key takeaways

https://www.elastic.co/security-labs/bughatch-malware-analysis

Threats:
Bughatch
Cuba
Termite
Process_injection_technique
Mimikatz

TTPs:
Tactics: 4
Technics: 0

IOCs:
Hash: 5
File: 4
Path: 1

Softs:
visual studio

Algorithms:
xor, base64

Functions:
CreateThread, RemoveEntryRecvLinkedList

Win API:
VirtualAlloc, WaitForSingleObject, CreateThread, Sleep, SeDebugPrivilege, QueryPerformanceCounter, GetIpAddrTable, AllocateAndInitializeSid, CheckTokenMembership, OpenProcessToken, have more...

Languages:
python

YARA: Found

Links:
https://github.com/elastic/protections-artifacts/blob/main/yara/rules/Windows\_Trojan\_Bughatch.yar
#technique

In this blogpost we demonstrate an attack on the integrity of Sysmon which generates a minimal amount of observable events making this attack difficult to detect in environments where no additional security products are installed.

https://codewhitesec.blogspot.com/2022/09/attacks-on-sysmon-revisited-sysmonente.html
#ParsedReport
13-09-2022

Look What You Made Me Do: TA453 Uses Multi-Persona Impersonation to Capitalize on FOMO

https://www.proofpoint.com/us/blog/threat-insight/ta453-uses-multi-persona-impersonation-capitalize-fomo

Actors/Campaigns:
Cleaver (motivation: cyber_espionage)
Phosphorus
Apt42
Cosmic_lynx

Threats:
Credential_harvesting_technique

Industry:
Education, Healthcare

Geo:
Israel, Russia

IOCs:
File: 5
Hash: 2
Domain: 2

Softs:
telegram
#ParsedReport
13-09-2022

Phishing Campaign targets Japanese tax payers

https://blog.cyble.com/2022/09/13/phishing-campaign-targets-japanese-tax-payers

Actors/Campaigns:
Roaming_mantis

Threats:
Fakecop
Mantis_botnet

Industry:
Financial

Geo:
Japan, Singapore, Georgia, India, China, Australia, Japanese, Dubai

TTPs:
Tactics: 7
Technics: 10

IOCs:
Url: 57
File: 1
Hash: 1

Softs:
android
#ParsedReport
13-09-2022

Rise in XorDdos: A deeper look at the stealthy DDoS malware targeting Linux devices

https://www.microsoft.com/security/blog/2022/05/19/rise-in-xorddos-a-deeper-look-at-the-stealthy-ddos-malware-targeting-linux-devices

Threats:
Xorddos
Tsunami_botnet
Xmrig_miner
Netstat_tool

Industry:
Iot

TTPs:
Tactics: 3
Technics: 0

IOCs:
File: 3
Url: 1
Domain: 2
Hash: 19

Softs:
microsoft 365 defender, microsoft defender for endpoint, curl, sudo, unix, microsoft edge, microsoft defender

Algorithms:
xor, crc

Functions:
fork, setsid, signal, dec_conf, readlink, the, unhide, IOCTL, tcp4_seq_show, tcp6_seq_show, have more...

Platforms:
intel

Links:
https://github.com/jermeyyy/rooty
https://github.com/mncoppola/suterusu
#ParsedReport
13-09-2022

OriginLogger: A Look at Agent Teslas Successor

https://unit42.paloaltonetworks.com/originlogger

Threats:
Originlogger
Agent_tesla
Reflectiveloader
Snip3_crypter
Atrium

Industry:
Financial

Geo:
German

IOCs:
Hash: 10
File: 16
IP: 5
Domain: 6
Path: 1
Url: 4

Softs:
discord, instagram, microsoft word, chrome, telegram

Algorithms:
zip, xor


Languages:
csharp, php

Links:
https://github.com/de4dot/de4dot
https://github.com/NYAN-x-CAT/CSharp-RunPE/blob/master/RunPE/RunPE.cs
#ParsedReport
13-09-2022

New Wave of Espionage Activity Targets Asian Governments

https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/espionage-asia-governments

Actors/Campaigns:
Red_delta
Axiom

Threats:
Shadowpad
Dll_sideloading_technique
Nbtscan_tool
Tcping_tool
Fastreverseproxy_tool
Fscan_tool
Ladon_tool
Mimikatz
Procdump_tool
Ntdsutil_tool
Process_injection_technique
Proxylogon_exploit
Eternalblue_vuln
Plugx_rat
Trochilus_rat
Quasar_rat
Passview_tool
Powersploit
Powerview

Industry:
Government, Telco, Education, Financial, Aerospace

Geo:
Asian, Asia

CVEs:
CVE-2020-1472 [Vulners]
Vulners: Score: 9.3, CVSS: 3.8,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2)
- microsoft windows server 2012 (-, r2)
- microsoft windows server 2016 (-, 1903, 1909, 2004)
- microsoft windows server 2019 (-)
- fedoraproject fedora (31, 32, 33)
have more...
CVE-2021-26855 [Vulners]
Vulners: Score: 7.5, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 9.1
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2016, 2016, 2013, 2016, 2016, 2013, 2016, 2019, 2013, 2016, 2016, 2016, 2016, 2016, 2016, 2016, 2019, 2019, 2019, 2019, 2019, 2019, 2019, 2019)


IOCs:
File: 25
Hash: 33
Path: 2
IP: 7
Registry: 1

Softs:
psexec, active directory, local security authority

Links:
https://github.com/k8gege/LadonGo
#ParsedReport
13-09-2022

Chiseling In: Lorenz Ransomware Group Cracks MiVoice And Calls Back For Free

https://arcticwolf.com/resources/blog/lorenz-ransomware-chiseling-in

Threats:
Lorenz
Lolbin
Chisel_tool
Crackmapexec_tool
Minidump_tool
Dumplsass_tool
Netstat_tool

Industry:
Iot

Geo:
China, Mexico

CVEs:
CVE-2022-29499 [Vulners]
Vulners: Score: 10.0, CVSS: 5.1,
Vulners: Exploitation: True
X-Force: Risk: 7.3
X-Force: Patch: Official fix
Soft:
- mitel mivoice connect (le22.20.2300.0)


TTPs:
Tactics: 11
Technics: 23

IOCs:
IP: 9
File: 12
Hash: 2
Url: 2
Path: 3
Registry: 1

Softs:
bitlocker, esxi, curl, openssl, local security authority, windows error reporting, task scheduler

Algorithms:
aes-256, base64

Languages:
php

YARA: Found
SIGMA: Found

Links:
https://github.com/SigmaHQ/sigma/blob/b24e7ae9846f53cbbf61adad72f17af317c860a4/rules/windows/process\_creation/proc\_creation\_win\_powershell\_cmdline\_convertto\_securestring.yml
https://github.com/jpillora/chisel
https://github.com/Porchetta-Industries/CrackMapExec
https://github.com/SigmaHQ/sigma/blob/a80c29a7c2e2e500a1a532db2a2a8bd69bd4a63d/rules/windows/registry\_event/sysmon\_powershell\_as\_service.yml
https://github.com/Hackndo/lsassy
https://github.com/NVISOsecurity/sigma-public/blob/master/rules/windows/builtin/win\_atsvc\_task.yml
https://github.com/SigmaHQ/sigma/blob/master/rules/windows/sysmon/sysmon\_accessing\_winapi\_in\_powershell\_credentials\_dumping.yml
https://github.com/SigmaHQ/sigma/blob/1e16ed00905a496cbc3b0a1a03d4c2f6f4b63de2/rules/windows/process\_creation/proc\_creation\_win\_crackmapexec\_patterns.yml
https://github.com/rtkwlf/wolf-tools/blob/main/threat-intelligence/lorenz-ransomware-chiseling-in/lorenz-yara.yar
https://github.com/rtkwlf/wolf-tools/blob/main/threat-intelligence/lorenz-ransomware-chiseling-in/lorenz-suricata.rules
https://github.com/SigmaHQ/sigma
https://github.com/SigmaHQ/sigma/blob/ab814cbc408234eddf538bc893fcbe00c32ca2e9/rules/windows/process\_creation/win\_susp\_comsvcs\_procdump.yml
#technique

Caching the Un-cacheables - Abusing URL Parser Confusions (Web Cache Poisoning Technique)

https://nokline.github.io/bugbounty/2022/09/02/Glassdoor-Cache-Poisoning.html
#ParsedReport
14-09-2022

ASEC Weekly Malware Statistics (August 29th, 2022 September 4th, 2022)

https://asec.ahnlab.com/en/38739

Threats:
Cloudeye
Formbook
Agent_tesla
Remcos_rat
Nanocore_rat
Clipboard_grabbing_technique
Lokibot_stealer

Industry:
Financial

Geo:
Korea

IOCs:
Url: 17
File: 15
Domain: 4
IP: 3
Email: 6

Softs:
nsis installer, discord

Languages:
php, visual_basic
#ParsedReport
14-09-2022

A Post-exploitation Look at Coinminers Abusing WebLogic Vulnerabilities

https://www.trendmicro.com/en_us/research/22/i/a-post-exploitation-look-at-coinminers-abusing-weblogic-vulnerab.html

Threats:
Kinsing_miner

CVEs:
CVE-2020-14882 [Vulners]
Vulners: Score: 10.0, CVSS: 3.3,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- oracle weblogic server (12.1.3.0.0, 10.3.6.0.0, 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0)


TTPs:
Tactics: 1
Technics: 9

IOCs:
Url: 15
Hash: 2
IP: 3

Softs:
docker, curl

Algorithms:
base64

Languages:
java