#ParsedReport
12-09-2022
BUGHATCH Malware Analysis. Key takeaways
https://www.elastic.co/security-labs/bughatch-malware-analysis
Threats:
Bughatch
Cuba
Termite
Process_injection_technique
Mimikatz
TTPs:
Tactics: 4
Technics: 0
IOCs:
Hash: 5
File: 4
Path: 1
Softs:
visual studio
Algorithms:
xor, base64
Functions:
CreateThread, RemoveEntryRecvLinkedList
Win API:
VirtualAlloc, WaitForSingleObject, CreateThread, Sleep, SeDebugPrivilege, QueryPerformanceCounter, GetIpAddrTable, AllocateAndInitializeSid, CheckTokenMembership, OpenProcessToken, have more...
Languages:
python
YARA: Found
Links:
12-09-2022
BUGHATCH Malware Analysis. Key takeaways
https://www.elastic.co/security-labs/bughatch-malware-analysis
Threats:
Bughatch
Cuba
Termite
Process_injection_technique
Mimikatz
TTPs:
Tactics: 4
Technics: 0
IOCs:
Hash: 5
File: 4
Path: 1
Softs:
visual studio
Algorithms:
xor, base64
Functions:
CreateThread, RemoveEntryRecvLinkedList
Win API:
VirtualAlloc, WaitForSingleObject, CreateThread, Sleep, SeDebugPrivilege, QueryPerformanceCounter, GetIpAddrTable, AllocateAndInitializeSid, CheckTokenMembership, OpenProcessToken, have more...
Languages:
python
YARA: Found
Links:
https://github.com/elastic/protections-artifacts/blob/main/yara/rules/Windows\_Trojan\_Bughatch.yarwww.elastic.co
BUGHATCH Malware Analysis — Elastic Security Labs
Elastic Security has performed a deep technical analysis of the BUGHATCH malware. This includes capabilities as well as defensive countermeasures.
#technique
Massayo is a small proof-of-concept Rust library based on UnhookingPOC, which removes AV/EDR hooks in a given system DLL.
https://github.com/thiagopeixoto/massayo
Massayo is a small proof-of-concept Rust library based on UnhookingPOC, which removes AV/EDR hooks in a given system DLL.
https://github.com/thiagopeixoto/massayo
GitHub
GitHub - thiagopeixoto/massayo: Massayo is a small proof-of-concept Rust library which removes AV/EDR hooks in a given system DLL
Massayo is a small proof-of-concept Rust library which removes AV/EDR hooks in a given system DLL - thiagopeixoto/massayo
#technique
https://www.secureworks.com/research/azure-active-directory-pass-through-authentication-flaws
https://www.secureworks.com/research/azure-active-directory-pass-through-authentication-flaws
Sophos
Azure Active Directory Pass-Through Authentication Flaws
In May 2022, Sophos® Counter Threat Unit™ (CTU) researchers analyzed how the protocols used by Pass-Through Authentication could be exploited.
#technique
In this blogpost we demonstrate an attack on the integrity of Sysmon which generates a minimal amount of observable events making this attack difficult to detect in environments where no additional security products are installed.
https://codewhitesec.blogspot.com/2022/09/attacks-on-sysmon-revisited-sysmonente.html
In this blogpost we demonstrate an attack on the integrity of Sysmon which generates a minimal amount of observable events making this attack difficult to detect in environments where no additional security products are installed.
https://codewhitesec.blogspot.com/2022/09/attacks-on-sysmon-revisited-sysmonente.html
Blogspot
CODE WHITE | Blog: Attacks on Sysmon Revisited - SysmonEnte
In this blogpost we demonstrate an attack on the integrity of Sysmon which generates a minimal amount of observable events making this attac...
#ParsedReport
13-09-2022
Look What You Made Me Do: TA453 Uses Multi-Persona Impersonation to Capitalize on FOMO
https://www.proofpoint.com/us/blog/threat-insight/ta453-uses-multi-persona-impersonation-capitalize-fomo
Actors/Campaigns:
Cleaver (motivation: cyber_espionage)
Phosphorus
Apt42
Cosmic_lynx
Threats:
Credential_harvesting_technique
Industry:
Education, Healthcare
Geo:
Israel, Russia
IOCs:
File: 5
Hash: 2
Domain: 2
Softs:
telegram
13-09-2022
Look What You Made Me Do: TA453 Uses Multi-Persona Impersonation to Capitalize on FOMO
https://www.proofpoint.com/us/blog/threat-insight/ta453-uses-multi-persona-impersonation-capitalize-fomo
Actors/Campaigns:
Cleaver (motivation: cyber_espionage)
Phosphorus
Apt42
Cosmic_lynx
Threats:
Credential_harvesting_technique
Industry:
Education, Healthcare
Geo:
Israel, Russia
IOCs:
File: 5
Hash: 2
Domain: 2
Softs:
telegram
Proofpoint
TA453 Uses Impersonation to Capitalize on FOMO | Proofpoint US
In 2022, TA453 used multi-persona impersonation to turn FOMO into a cybersecurity risk. Proofpoint details the FOMO cyber-attack, what it is, how it works, and more.
#ParsedReport
13-09-2022
. Risk reminder about the large -scale dissemination of the "demon thief" the stolen Trojan horse
https://www.antiy.cn/research/notice&report/research_report/20220913.html
Threats:
Sandbox_evasion_technique
Geo:
China, Malaysia
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 49
Path: 14
File: 18
Registry: 2
IP: 1
Domain: 3
Url: 45
Softs:
foxmail
Algorithms:
aes, base64, zip
Platforms:
intel, x86
13-09-2022
. Risk reminder about the large -scale dissemination of the "demon thief" the stolen Trojan horse
https://www.antiy.cn/research/notice&report/research_report/20220913.html
Threats:
Sandbox_evasion_technique
Geo:
China, Malaysia
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 49
Path: 14
File: 18
Registry: 2
IP: 1
Domain: 3
Url: 45
Softs:
foxmail
Algorithms:
aes, base64, zip
Platforms:
intel, x86
www.antiy.cn
关于“魔盗”窃密木马大规模传播的风险提示
近期,CNCERT和安天联合监测到一批伪装成CorelDraw、Notepad++、IDA Pro、WinHex等多款实用软件进行传播的窃密木马。通过跟踪监测发现其每日上线境内肉鸡数(以IP数计算)最多已超过1.3万,由于该窃密木马会收集浏览器书签、邮箱账户等信息,故我们将命名为“魔盗”。
#ParsedReport
13-09-2022
Phishing Campaign targets Japanese tax payers
https://blog.cyble.com/2022/09/13/phishing-campaign-targets-japanese-tax-payers
Actors/Campaigns:
Roaming_mantis
Threats:
Fakecop
Mantis_botnet
Industry:
Financial
Geo:
Japan, Singapore, Georgia, India, China, Australia, Japanese, Dubai
TTPs:
Tactics: 7
Technics: 10
IOCs:
Url: 57
File: 1
Hash: 1
Softs:
android
13-09-2022
Phishing Campaign targets Japanese tax payers
https://blog.cyble.com/2022/09/13/phishing-campaign-targets-japanese-tax-payers
Actors/Campaigns:
Roaming_mantis
Threats:
Fakecop
Mantis_botnet
Industry:
Financial
Geo:
Japan, Singapore, Georgia, India, China, Australia, Japanese, Dubai
TTPs:
Tactics: 7
Technics: 10
IOCs:
Url: 57
File: 1
Hash: 1
Softs:
android
Cyble
Cyble - Phishing Campaign Targets Japanese Tax Payers
Cyble, Research & Intelligence Labs analyzes the National Tax Agency Phishing Campaign targeting Japanese taxpayers.
#ParsedReport
13-09-2022
TikTok Breached by BlueHornet
https://cyberint.com/blog/research/tiktok-breached-by-bluehornet
Actors/Campaigns:
Bluehornet
Industry:
Government
Geo:
Iran, Belarus, American, Usa, Chinese, Korea, China, Russia
Softs:
tiktok, wechat
13-09-2022
TikTok Breached by BlueHornet
https://cyberint.com/blog/research/tiktok-breached-by-bluehornet
Actors/Campaigns:
Bluehornet
Industry:
Government
Geo:
Iran, Belarus, American, Usa, Chinese, Korea, China, Russia
Softs:
tiktok, wechat
Cyberint
TikTok Breached by BlueHornet
The breach of the popular social network TikTok occurred, revealing 1.7 billion records and relations to another popular Chinese app - WeChat
#ParsedReport
13-09-2022
Rise in XorDdos: A deeper look at the stealthy DDoS malware targeting Linux devices
https://www.microsoft.com/security/blog/2022/05/19/rise-in-xorddos-a-deeper-look-at-the-stealthy-ddos-malware-targeting-linux-devices
Threats:
Xorddos
Tsunami_botnet
Xmrig_miner
Netstat_tool
Industry:
Iot
TTPs:
Tactics: 3
Technics: 0
IOCs:
File: 3
Url: 1
Domain: 2
Hash: 19
Softs:
microsoft 365 defender, microsoft defender for endpoint, curl, sudo, unix, microsoft edge, microsoft defender
Algorithms:
xor, crc
Functions:
fork, setsid, signal, dec_conf, readlink, the, unhide, IOCTL, tcp4_seq_show, tcp6_seq_show, have more...
Platforms:
intel
Links:
13-09-2022
Rise in XorDdos: A deeper look at the stealthy DDoS malware targeting Linux devices
https://www.microsoft.com/security/blog/2022/05/19/rise-in-xorddos-a-deeper-look-at-the-stealthy-ddos-malware-targeting-linux-devices
Threats:
Xorddos
Tsunami_botnet
Xmrig_miner
Netstat_tool
Industry:
Iot
TTPs:
Tactics: 3
Technics: 0
IOCs:
File: 3
Url: 1
Domain: 2
Hash: 19
Softs:
microsoft 365 defender, microsoft defender for endpoint, curl, sudo, unix, microsoft edge, microsoft defender
Algorithms:
xor, crc
Functions:
fork, setsid, signal, dec_conf, readlink, the, unhide, IOCTL, tcp4_seq_show, tcp6_seq_show, have more...
Platforms:
intel
Links:
https://github.com/jermeyyy/rooty
https://github.com/mncoppola/suterusuMicrosoft News
Rise in XorDdos: A deeper look at the stealthy DDoS malware targeting Linux devices
Observing a 254% increase in activity over the last six months from a versatile Linux trojan called XorDdos, the Microsoft 365 Defender research team provides in-depth analysis into this stealthy malware's capabilities and key infection signs.
#ParsedReport
13-09-2022
OriginLogger: A Look at Agent Teslas Successor
https://unit42.paloaltonetworks.com/originlogger
Threats:
Originlogger
Agent_tesla
Reflectiveloader
Snip3_crypter
Atrium
Industry:
Financial
Geo:
German
IOCs:
Hash: 10
File: 16
IP: 5
Domain: 6
Path: 1
Url: 4
Softs:
discord, instagram, microsoft word, chrome, telegram
Algorithms:
zip, xor
Languages:
csharp, php
Links:
13-09-2022
OriginLogger: A Look at Agent Teslas Successor
https://unit42.paloaltonetworks.com/originlogger
Threats:
Originlogger
Agent_tesla
Reflectiveloader
Snip3_crypter
Atrium
Industry:
Financial
Geo:
German
IOCs:
Hash: 10
File: 16
IP: 5
Domain: 6
Path: 1
Url: 4
Softs:
discord, instagram, microsoft word, chrome, telegram
Algorithms:
zip, xor
Languages:
csharp, php
Links:
https://github.com/de4dot/de4dot
https://github.com/NYAN-x-CAT/CSharp-RunPE/blob/master/RunPE/RunPE.csUnit 42
OriginLogger: A Look at Agent Tesla’s Successor
We provide an overview of the OriginLogger keylogger, including info on a dropper lure and OriginLogger’s configuration and infrastructure.
#ParsedReport
13-09-2022
New Wave of Espionage Activity Targets Asian Governments
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/espionage-asia-governments
Actors/Campaigns:
Red_delta
Axiom
Threats:
Shadowpad
Dll_sideloading_technique
Nbtscan_tool
Tcping_tool
Fastreverseproxy_tool
Fscan_tool
Ladon_tool
Mimikatz
Procdump_tool
Ntdsutil_tool
Process_injection_technique
Proxylogon_exploit
Eternalblue_vuln
Plugx_rat
Trochilus_rat
Quasar_rat
Passview_tool
Powersploit
Powerview
Industry:
Government, Telco, Education, Financial, Aerospace
Geo:
Asian, Asia
CVEs:
CVE-2020-1472 [Vulners]
Vulners: Score: 9.3, CVSS: 3.8,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2)
- microsoft windows server 2012 (-, r2)
- microsoft windows server 2016 (-, 1903, 1909, 2004)
- microsoft windows server 2019 (-)
- fedoraproject fedora (31, 32, 33)
have more...
CVE-2021-26855 [Vulners]
Vulners: Score: 7.5, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 9.1
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2016, 2016, 2013, 2016, 2016, 2013, 2016, 2019, 2013, 2016, 2016, 2016, 2016, 2016, 2016, 2016, 2019, 2019, 2019, 2019, 2019, 2019, 2019, 2019)
IOCs:
File: 25
Hash: 33
Path: 2
IP: 7
Registry: 1
Softs:
psexec, active directory, local security authority
Links:
13-09-2022
New Wave of Espionage Activity Targets Asian Governments
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/espionage-asia-governments
Actors/Campaigns:
Red_delta
Axiom
Threats:
Shadowpad
Dll_sideloading_technique
Nbtscan_tool
Tcping_tool
Fastreverseproxy_tool
Fscan_tool
Ladon_tool
Mimikatz
Procdump_tool
Ntdsutil_tool
Process_injection_technique
Proxylogon_exploit
Eternalblue_vuln
Plugx_rat
Trochilus_rat
Quasar_rat
Passview_tool
Powersploit
Powerview
Industry:
Government, Telco, Education, Financial, Aerospace
Geo:
Asian, Asia
CVEs:
CVE-2020-1472 [Vulners]
Vulners: Score: 9.3, CVSS: 3.8,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2)
- microsoft windows server 2012 (-, r2)
- microsoft windows server 2016 (-, 1903, 1909, 2004)
- microsoft windows server 2019 (-)
- fedoraproject fedora (31, 32, 33)
have more...
CVE-2021-26855 [Vulners]
Vulners: Score: 7.5, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 9.1
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2016, 2016, 2013, 2016, 2016, 2013, 2016, 2019, 2013, 2016, 2016, 2016, 2016, 2016, 2016, 2016, 2019, 2019, 2019, 2019, 2019, 2019, 2019, 2019)
IOCs:
File: 25
Hash: 33
Path: 2
IP: 7
Registry: 1
Softs:
psexec, active directory, local security authority
Links:
https://github.com/k8gege/LadonGoSecurity
New Wave of Espionage Activity Targets Asian Governments
Governments and state-owned organizations are the latest targets of a well-established threat actor.
#ParsedReport
13-09-2022
Chiseling In: Lorenz Ransomware Group Cracks MiVoice And Calls Back For Free
https://arcticwolf.com/resources/blog/lorenz-ransomware-chiseling-in
Threats:
Lorenz
Lolbin
Chisel_tool
Crackmapexec_tool
Minidump_tool
Dumplsass_tool
Netstat_tool
Industry:
Iot
Geo:
China, Mexico
CVEs:
CVE-2022-29499 [Vulners]
Vulners: Score: 10.0, CVSS: 5.1,
Vulners: Exploitation: True
X-Force: Risk: 7.3
X-Force: Patch: Official fix
Soft:
- mitel mivoice connect (le22.20.2300.0)
TTPs:
Tactics: 11
Technics: 23
IOCs:
IP: 9
File: 12
Hash: 2
Url: 2
Path: 3
Registry: 1
Softs:
bitlocker, esxi, curl, openssl, local security authority, windows error reporting, task scheduler
Algorithms:
aes-256, base64
Languages:
php
YARA: Found
SIGMA: Found
Links:
13-09-2022
Chiseling In: Lorenz Ransomware Group Cracks MiVoice And Calls Back For Free
https://arcticwolf.com/resources/blog/lorenz-ransomware-chiseling-in
Threats:
Lorenz
Lolbin
Chisel_tool
Crackmapexec_tool
Minidump_tool
Dumplsass_tool
Netstat_tool
Industry:
Iot
Geo:
China, Mexico
CVEs:
CVE-2022-29499 [Vulners]
Vulners: Score: 10.0, CVSS: 5.1,
Vulners: Exploitation: True
X-Force: Risk: 7.3
X-Force: Patch: Official fix
Soft:
- mitel mivoice connect (le22.20.2300.0)
TTPs:
Tactics: 11
Technics: 23
IOCs:
IP: 9
File: 12
Hash: 2
Url: 2
Path: 3
Registry: 1
Softs:
bitlocker, esxi, curl, openssl, local security authority, windows error reporting, task scheduler
Algorithms:
aes-256, base64
Languages:
php
YARA: Found
SIGMA: Found
Links:
https://github.com/SigmaHQ/sigma/blob/b24e7ae9846f53cbbf61adad72f17af317c860a4/rules/windows/process\_creation/proc\_creation\_win\_powershell\_cmdline\_convertto\_securestring.yml
https://github.com/jpillora/chisel
https://github.com/Porchetta-Industries/CrackMapExec
https://github.com/SigmaHQ/sigma/blob/a80c29a7c2e2e500a1a532db2a2a8bd69bd4a63d/rules/windows/registry\_event/sysmon\_powershell\_as\_service.yml
https://github.com/Hackndo/lsassy
https://github.com/NVISOsecurity/sigma-public/blob/master/rules/windows/builtin/win\_atsvc\_task.yml
https://github.com/SigmaHQ/sigma/blob/master/rules/windows/sysmon/sysmon\_accessing\_winapi\_in\_powershell\_credentials\_dumping.yml
https://github.com/SigmaHQ/sigma/blob/1e16ed00905a496cbc3b0a1a03d4c2f6f4b63de2/rules/windows/process\_creation/proc\_creation\_win\_crackmapexec\_patterns.yml
https://github.com/rtkwlf/wolf-tools/blob/main/threat-intelligence/lorenz-ransomware-chiseling-in/lorenz-yara.yar
https://github.com/rtkwlf/wolf-tools/blob/main/threat-intelligence/lorenz-ransomware-chiseling-in/lorenz-suricata.rules
https://github.com/SigmaHQ/sigma
https://github.com/SigmaHQ/sigma/blob/ab814cbc408234eddf538bc893fcbe00c32ca2e9/rules/windows/process\_creation/win\_susp\_comsvcs\_procdump.ymlArctic Wolf
Lorenz Ransomware Group Cracks MiVoice | Arctic Wolf
Learn about Arctic Wolf Lab’s recent investigation into a Lorenz ransomware intrusion which leveraged a Mitel MiVoice VOIP appliance vulnerability for initial access and Microsoft’s BitLocker Drive Encryption for data encryption.
#technique
A cross platform C2/post-exploitation framework implementation by Rust.
https://github.com/b23r0/Heroinn
A cross platform C2/post-exploitation framework implementation by Rust.
https://github.com/b23r0/Heroinn
GitHub
GitHub - b23r0/Heroinn: A cross platform C2/post-exploitation framework.
A cross platform C2/post-exploitation framework. Contribute to b23r0/Heroinn development by creating an account on GitHub.
#technique
Caching the Un-cacheables - Abusing URL Parser Confusions (Web Cache Poisoning Technique)
https://nokline.github.io/bugbounty/2022/09/02/Glassdoor-Cache-Poisoning.html
Caching the Un-cacheables - Abusing URL Parser Confusions (Web Cache Poisoning Technique)
https://nokline.github.io/bugbounty/2022/09/02/Glassdoor-Cache-Poisoning.html
#ParsedReport
14-09-2022
ASEC Weekly Malware Statistics (August 29th, 2022 September 4th, 2022)
https://asec.ahnlab.com/en/38739
Threats:
Cloudeye
Formbook
Agent_tesla
Remcos_rat
Nanocore_rat
Clipboard_grabbing_technique
Lokibot_stealer
Industry:
Financial
Geo:
Korea
IOCs:
Url: 17
File: 15
Domain: 4
IP: 3
Email: 6
Softs:
nsis installer, discord
Languages:
php, visual_basic
14-09-2022
ASEC Weekly Malware Statistics (August 29th, 2022 September 4th, 2022)
https://asec.ahnlab.com/en/38739
Threats:
Cloudeye
Formbook
Agent_tesla
Remcos_rat
Nanocore_rat
Clipboard_grabbing_technique
Lokibot_stealer
Industry:
Financial
Geo:
Korea
IOCs:
Url: 17
File: 15
Domain: 4
IP: 3
Email: 6
Softs:
nsis installer, discord
Languages:
php, visual_basic
ASEC BLOG
ASEC Weekly Malware Statistics (August 29th, 2022 – September 4th, 2022) - ASEC BLOG
The ASEC analysis team is using the ASEC automatic analysis system RAPIT to categorize and respond to known malware. This post will list weekly statistics collected from August 29th, 2022 (Monday) to September 4th, 2022 (Sunday). For the main category, info…
#ParsedReport
14-09-2022
Phishing Websites Disguised as Korean Groupware Login Website Being Distributed
https://asec.ahnlab.com/en/38786
Geo:
Korean, Korea
IOCs:
Url: 6
Languages:
javascript
14-09-2022
Phishing Websites Disguised as Korean Groupware Login Website Being Distributed
https://asec.ahnlab.com/en/38786
Geo:
Korean, Korea
IOCs:
Url: 6
Languages:
javascript
ASEC BLOG
Phishing Websites Disguised as Korean Groupware Login Website Being Distributed - ASEC BLOG
The ASEC analysis team has been building a honeypot to collect various malware strains that are being distributed both in Korea and overseas. The honeypot also collects phishing emails and recently caught one targeting Korean users, which was being distributed…
#ParsedReport
14-09-2022
Fake URL Authentication
https://labs.k7computing.com/index.php/fake-url-authentication
Threats:
Hajime
Industry:
Iot
IOCs:
Url: 6
Softs:
instagram
Algorithms:
base64
14-09-2022
Fake URL Authentication
https://labs.k7computing.com/index.php/fake-url-authentication
Threats:
Hajime
Industry:
Iot
IOCs:
Url: 6
Softs:
Algorithms:
base64
K7 Labs
Fake URL Authentication - K7 Labs
In this internet era, we consume Giga Bytes (GBs) of data everyday, which includes surfing the internet, streaming videos, online […]
#ParsedReport
14-09-2022
A Post-exploitation Look at Coinminers Abusing WebLogic Vulnerabilities
https://www.trendmicro.com/en_us/research/22/i/a-post-exploitation-look-at-coinminers-abusing-weblogic-vulnerab.html
Threats:
Kinsing_miner
CVEs:
CVE-2020-14882 [Vulners]
Vulners: Score: 10.0, CVSS: 3.3,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- oracle weblogic server (12.1.3.0.0, 10.3.6.0.0, 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0)
TTPs:
Tactics: 1
Technics: 9
IOCs:
Url: 15
Hash: 2
IP: 3
Softs:
docker, curl
Algorithms:
base64
Languages:
java
14-09-2022
A Post-exploitation Look at Coinminers Abusing WebLogic Vulnerabilities
https://www.trendmicro.com/en_us/research/22/i/a-post-exploitation-look-at-coinminers-abusing-weblogic-vulnerab.html
Threats:
Kinsing_miner
CVEs:
CVE-2020-14882 [Vulners]
Vulners: Score: 10.0, CVSS: 3.3,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- oracle weblogic server (12.1.3.0.0, 10.3.6.0.0, 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0)
TTPs:
Tactics: 1
Technics: 9
IOCs:
Url: 15
Hash: 2
IP: 3
Softs:
docker, curl
Algorithms:
base64
Languages:
java
Trend Micro
A Post-exploitation Look at Coinminers Abusing WebLogic Vulnerabilities
This blog entry details how Trend Micro Cloud One™ – Workload Security and Trend Micro Vision One™ effectively detected and blocked the abuse of the CVE-2020-14882 WebLogic vulnerability in affected endpoints.
#ParsedReport
14-09-2022
Loader Malware Emotet is Now Led by Quantum and BlackCat
https://socradar.io/loader-malware-emotet-is-now-led-by-quantum-and-blackcat
Threats:
Emotet
Quantum_locker
Blackcat
Lampion
Conti
Cobalt_strike
Beacon
Process_injection_technique
Industry:
Financial
Geo:
Russian, Ukrainian
TTPs:
Tactics: 1
Technics: 24
Languages:
visual_basic
14-09-2022
Loader Malware Emotet is Now Led by Quantum and BlackCat
https://socradar.io/loader-malware-emotet-is-now-led-by-quantum-and-blackcat
Threats:
Emotet
Quantum_locker
Blackcat
Lampion
Conti
Cobalt_strike
Beacon
Process_injection_technique
Industry:
Financial
Geo:
Russian, Ukrainian
TTPs:
Tactics: 1
Technics: 24
Languages:
visual_basic
SOCRadar® Cyber Intelligence Inc.
Loader Malware Emotet is Now Led by Quantum and BlackCat - SOCRadar® Cyber Intelligence Inc.
Emotet (also known as SpmTools) is a sophisticated, modular banking trojan. Emotetmostly serves as a downloader or dropper of other banking trojans. It
#ParsedReport
14-09-2022
You never walk alone: The SideWalk backdoor gets a Linux variant
https://www.welivesecurity.com/2022/09/14/you-never-walk-alone-sidewalk-backdoor-linux-variant
Actors/Campaigns:
Sparklinggoblin
Axiom
Fishmonger
Threats:
Sidewalk
Dead_drop_technique
Stageclients
Specter_rat
Cobalt_strike
Crosswalk
Plugx_rat
Shadowpad
Spyder
Industry:
Education
Geo:
Ukraine, Asia
TTPs:
Tactics: 4
Technics: 4
IOCs:
IP: 2
Hash: 3
Path: 1
Domain: 1
Algorithms:
chacha20, exhibit
Win API:
VirtualAlloc
Links:
14-09-2022
You never walk alone: The SideWalk backdoor gets a Linux variant
https://www.welivesecurity.com/2022/09/14/you-never-walk-alone-sidewalk-backdoor-linux-variant
Actors/Campaigns:
Sparklinggoblin
Axiom
Fishmonger
Threats:
Sidewalk
Dead_drop_technique
Stageclients
Specter_rat
Cobalt_strike
Crosswalk
Plugx_rat
Shadowpad
Spyder
Industry:
Education
Geo:
Ukraine, Asia
TTPs:
Tactics: 4
Technics: 4
IOCs:
IP: 2
Hash: 3
Path: 1
Domain: 1
Algorithms:
chacha20, exhibit
Win API:
VirtualAlloc
Links:
https://github.com/eset/malware-ioc/tree/master/sparklinggoblinWeLiveSecurity
You never walk alone: The SideWalk backdoor gets a Linux variant
ESET researchers have uncovered another tool in the already extensive arsenal of the SparklingGoblin APT group: a Linux variant of the SideWalk backdoor.
#ParsedReport
14-09-2022
OriginLogger
https://1275.ru/ioc/668/originlogger/?from=rss
Threats:
Originlogger
Agent_tesla
Snake_keylogger
Purecrypter
IOCs:
IP: 3
Hash: 5
Softs:
discord
14-09-2022
OriginLogger
https://1275.ru/ioc/668/originlogger/?from=rss
Threats:
Originlogger
Agent_tesla
Snake_keylogger
Purecrypter
IOCs:
IP: 3
Hash: 5
Softs:
discord
SEC-1275-1
OriginLogger - SEC-1275-1
OriginLogger - 4 марта 2019 года один из самых известных кейлоггеров, используемых преступниками, под названием Agent Tesla закрыл магазин из-за юридических проблем. В