CTT Report Hub
3.43K subscribers
9.9K photos
6 videos
67 files
13.5K links
Threat Intelligence Report Hub
Download Telegram
#technique

In this blogpost we demonstrate an attack on the integrity of Sysmon which generates a minimal amount of observable events making this attack difficult to detect in environments where no additional security products are installed.

https://codewhitesec.blogspot.com/2022/09/attacks-on-sysmon-revisited-sysmonente.html
#ParsedReport
13-09-2022

Look What You Made Me Do: TA453 Uses Multi-Persona Impersonation to Capitalize on FOMO

https://www.proofpoint.com/us/blog/threat-insight/ta453-uses-multi-persona-impersonation-capitalize-fomo

Actors/Campaigns:
Cleaver (motivation: cyber_espionage)
Phosphorus
Apt42
Cosmic_lynx

Threats:
Credential_harvesting_technique

Industry:
Education, Healthcare

Geo:
Israel, Russia

IOCs:
File: 5
Hash: 2
Domain: 2

Softs:
telegram
#ParsedReport
13-09-2022

Phishing Campaign targets Japanese tax payers

https://blog.cyble.com/2022/09/13/phishing-campaign-targets-japanese-tax-payers

Actors/Campaigns:
Roaming_mantis

Threats:
Fakecop
Mantis_botnet

Industry:
Financial

Geo:
Japan, Singapore, Georgia, India, China, Australia, Japanese, Dubai

TTPs:
Tactics: 7
Technics: 10

IOCs:
Url: 57
File: 1
Hash: 1

Softs:
android
#ParsedReport
13-09-2022

Rise in XorDdos: A deeper look at the stealthy DDoS malware targeting Linux devices

https://www.microsoft.com/security/blog/2022/05/19/rise-in-xorddos-a-deeper-look-at-the-stealthy-ddos-malware-targeting-linux-devices

Threats:
Xorddos
Tsunami_botnet
Xmrig_miner
Netstat_tool

Industry:
Iot

TTPs:
Tactics: 3
Technics: 0

IOCs:
File: 3
Url: 1
Domain: 2
Hash: 19

Softs:
microsoft 365 defender, microsoft defender for endpoint, curl, sudo, unix, microsoft edge, microsoft defender

Algorithms:
xor, crc

Functions:
fork, setsid, signal, dec_conf, readlink, the, unhide, IOCTL, tcp4_seq_show, tcp6_seq_show, have more...

Platforms:
intel

Links:
https://github.com/jermeyyy/rooty
https://github.com/mncoppola/suterusu
#ParsedReport
13-09-2022

OriginLogger: A Look at Agent Teslas Successor

https://unit42.paloaltonetworks.com/originlogger

Threats:
Originlogger
Agent_tesla
Reflectiveloader
Snip3_crypter
Atrium

Industry:
Financial

Geo:
German

IOCs:
Hash: 10
File: 16
IP: 5
Domain: 6
Path: 1
Url: 4

Softs:
discord, instagram, microsoft word, chrome, telegram

Algorithms:
zip, xor


Languages:
csharp, php

Links:
https://github.com/de4dot/de4dot
https://github.com/NYAN-x-CAT/CSharp-RunPE/blob/master/RunPE/RunPE.cs
#ParsedReport
13-09-2022

New Wave of Espionage Activity Targets Asian Governments

https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/espionage-asia-governments

Actors/Campaigns:
Red_delta
Axiom

Threats:
Shadowpad
Dll_sideloading_technique
Nbtscan_tool
Tcping_tool
Fastreverseproxy_tool
Fscan_tool
Ladon_tool
Mimikatz
Procdump_tool
Ntdsutil_tool
Process_injection_technique
Proxylogon_exploit
Eternalblue_vuln
Plugx_rat
Trochilus_rat
Quasar_rat
Passview_tool
Powersploit
Powerview

Industry:
Government, Telco, Education, Financial, Aerospace

Geo:
Asian, Asia

CVEs:
CVE-2020-1472 [Vulners]
Vulners: Score: 9.3, CVSS: 3.8,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2)
- microsoft windows server 2012 (-, r2)
- microsoft windows server 2016 (-, 1903, 1909, 2004)
- microsoft windows server 2019 (-)
- fedoraproject fedora (31, 32, 33)
have more...
CVE-2021-26855 [Vulners]
Vulners: Score: 7.5, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 9.1
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2016, 2016, 2013, 2016, 2016, 2013, 2016, 2019, 2013, 2016, 2016, 2016, 2016, 2016, 2016, 2016, 2019, 2019, 2019, 2019, 2019, 2019, 2019, 2019)


IOCs:
File: 25
Hash: 33
Path: 2
IP: 7
Registry: 1

Softs:
psexec, active directory, local security authority

Links:
https://github.com/k8gege/LadonGo
#ParsedReport
13-09-2022

Chiseling In: Lorenz Ransomware Group Cracks MiVoice And Calls Back For Free

https://arcticwolf.com/resources/blog/lorenz-ransomware-chiseling-in

Threats:
Lorenz
Lolbin
Chisel_tool
Crackmapexec_tool
Minidump_tool
Dumplsass_tool
Netstat_tool

Industry:
Iot

Geo:
China, Mexico

CVEs:
CVE-2022-29499 [Vulners]
Vulners: Score: 10.0, CVSS: 5.1,
Vulners: Exploitation: True
X-Force: Risk: 7.3
X-Force: Patch: Official fix
Soft:
- mitel mivoice connect (le22.20.2300.0)


TTPs:
Tactics: 11
Technics: 23

IOCs:
IP: 9
File: 12
Hash: 2
Url: 2
Path: 3
Registry: 1

Softs:
bitlocker, esxi, curl, openssl, local security authority, windows error reporting, task scheduler

Algorithms:
aes-256, base64

Languages:
php

YARA: Found
SIGMA: Found

Links:
https://github.com/SigmaHQ/sigma/blob/b24e7ae9846f53cbbf61adad72f17af317c860a4/rules/windows/process\_creation/proc\_creation\_win\_powershell\_cmdline\_convertto\_securestring.yml
https://github.com/jpillora/chisel
https://github.com/Porchetta-Industries/CrackMapExec
https://github.com/SigmaHQ/sigma/blob/a80c29a7c2e2e500a1a532db2a2a8bd69bd4a63d/rules/windows/registry\_event/sysmon\_powershell\_as\_service.yml
https://github.com/Hackndo/lsassy
https://github.com/NVISOsecurity/sigma-public/blob/master/rules/windows/builtin/win\_atsvc\_task.yml
https://github.com/SigmaHQ/sigma/blob/master/rules/windows/sysmon/sysmon\_accessing\_winapi\_in\_powershell\_credentials\_dumping.yml
https://github.com/SigmaHQ/sigma/blob/1e16ed00905a496cbc3b0a1a03d4c2f6f4b63de2/rules/windows/process\_creation/proc\_creation\_win\_crackmapexec\_patterns.yml
https://github.com/rtkwlf/wolf-tools/blob/main/threat-intelligence/lorenz-ransomware-chiseling-in/lorenz-yara.yar
https://github.com/rtkwlf/wolf-tools/blob/main/threat-intelligence/lorenz-ransomware-chiseling-in/lorenz-suricata.rules
https://github.com/SigmaHQ/sigma
https://github.com/SigmaHQ/sigma/blob/ab814cbc408234eddf538bc893fcbe00c32ca2e9/rules/windows/process\_creation/win\_susp\_comsvcs\_procdump.yml
#technique

Caching the Un-cacheables - Abusing URL Parser Confusions (Web Cache Poisoning Technique)

https://nokline.github.io/bugbounty/2022/09/02/Glassdoor-Cache-Poisoning.html
#ParsedReport
14-09-2022

ASEC Weekly Malware Statistics (August 29th, 2022 September 4th, 2022)

https://asec.ahnlab.com/en/38739

Threats:
Cloudeye
Formbook
Agent_tesla
Remcos_rat
Nanocore_rat
Clipboard_grabbing_technique
Lokibot_stealer

Industry:
Financial

Geo:
Korea

IOCs:
Url: 17
File: 15
Domain: 4
IP: 3
Email: 6

Softs:
nsis installer, discord

Languages:
php, visual_basic
#ParsedReport
14-09-2022

A Post-exploitation Look at Coinminers Abusing WebLogic Vulnerabilities

https://www.trendmicro.com/en_us/research/22/i/a-post-exploitation-look-at-coinminers-abusing-weblogic-vulnerab.html

Threats:
Kinsing_miner

CVEs:
CVE-2020-14882 [Vulners]
Vulners: Score: 10.0, CVSS: 3.3,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- oracle weblogic server (12.1.3.0.0, 10.3.6.0.0, 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0)


TTPs:
Tactics: 1
Technics: 9

IOCs:
Url: 15
Hash: 2
IP: 3

Softs:
docker, curl

Algorithms:
base64

Languages:
java
#ParsedReport
14-09-2022

Loader Malware Emotet is Now Led by Quantum and BlackCat

https://socradar.io/loader-malware-emotet-is-now-led-by-quantum-and-blackcat

Threats:
Emotet
Quantum_locker
Blackcat
Lampion
Conti
Cobalt_strike
Beacon
Process_injection_technique

Industry:
Financial

Geo:
Russian, Ukrainian

TTPs:
Tactics: 1
Technics: 24

Languages:
visual_basic
#ParsedReport
14-09-2022

You never walk alone: The SideWalk backdoor gets a Linux variant

https://www.welivesecurity.com/2022/09/14/you-never-walk-alone-sidewalk-backdoor-linux-variant

Actors/Campaigns:
Sparklinggoblin
Axiom
Fishmonger

Threats:
Sidewalk
Dead_drop_technique
Stageclients
Specter_rat
Cobalt_strike
Crosswalk
Plugx_rat
Shadowpad
Spyder

Industry:
Education

Geo:
Ukraine, Asia

TTPs:
Tactics: 4
Technics: 4

IOCs:
IP: 2
Hash: 3
Path: 1
Domain: 1

Algorithms:
chacha20, exhibit

Win API:
VirtualAlloc

Links:
https://github.com/eset/malware-ioc/tree/master/sparklinggoblin