#ParsedReport
13-09-2022
OriginLogger: A Look at Agent Teslas Successor
https://unit42.paloaltonetworks.com/originlogger
Threats:
Originlogger
Agent_tesla
Reflectiveloader
Snip3_crypter
Atrium
Industry:
Financial
Geo:
German
IOCs:
Hash: 10
File: 16
IP: 5
Domain: 6
Path: 1
Url: 4
Softs:
discord, instagram, microsoft word, chrome, telegram
Algorithms:
zip, xor
Languages:
csharp, php
Links:
13-09-2022
OriginLogger: A Look at Agent Teslas Successor
https://unit42.paloaltonetworks.com/originlogger
Threats:
Originlogger
Agent_tesla
Reflectiveloader
Snip3_crypter
Atrium
Industry:
Financial
Geo:
German
IOCs:
Hash: 10
File: 16
IP: 5
Domain: 6
Path: 1
Url: 4
Softs:
discord, instagram, microsoft word, chrome, telegram
Algorithms:
zip, xor
Languages:
csharp, php
Links:
https://github.com/de4dot/de4dot
https://github.com/NYAN-x-CAT/CSharp-RunPE/blob/master/RunPE/RunPE.csUnit 42
OriginLogger: A Look at Agent Tesla’s Successor
We provide an overview of the OriginLogger keylogger, including info on a dropper lure and OriginLogger’s configuration and infrastructure.
#ParsedReport
13-09-2022
New Wave of Espionage Activity Targets Asian Governments
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/espionage-asia-governments
Actors/Campaigns:
Red_delta
Axiom
Threats:
Shadowpad
Dll_sideloading_technique
Nbtscan_tool
Tcping_tool
Fastreverseproxy_tool
Fscan_tool
Ladon_tool
Mimikatz
Procdump_tool
Ntdsutil_tool
Process_injection_technique
Proxylogon_exploit
Eternalblue_vuln
Plugx_rat
Trochilus_rat
Quasar_rat
Passview_tool
Powersploit
Powerview
Industry:
Government, Telco, Education, Financial, Aerospace
Geo:
Asian, Asia
CVEs:
CVE-2020-1472 [Vulners]
Vulners: Score: 9.3, CVSS: 3.8,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2)
- microsoft windows server 2012 (-, r2)
- microsoft windows server 2016 (-, 1903, 1909, 2004)
- microsoft windows server 2019 (-)
- fedoraproject fedora (31, 32, 33)
have more...
CVE-2021-26855 [Vulners]
Vulners: Score: 7.5, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 9.1
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2016, 2016, 2013, 2016, 2016, 2013, 2016, 2019, 2013, 2016, 2016, 2016, 2016, 2016, 2016, 2016, 2019, 2019, 2019, 2019, 2019, 2019, 2019, 2019)
IOCs:
File: 25
Hash: 33
Path: 2
IP: 7
Registry: 1
Softs:
psexec, active directory, local security authority
Links:
13-09-2022
New Wave of Espionage Activity Targets Asian Governments
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/espionage-asia-governments
Actors/Campaigns:
Red_delta
Axiom
Threats:
Shadowpad
Dll_sideloading_technique
Nbtscan_tool
Tcping_tool
Fastreverseproxy_tool
Fscan_tool
Ladon_tool
Mimikatz
Procdump_tool
Ntdsutil_tool
Process_injection_technique
Proxylogon_exploit
Eternalblue_vuln
Plugx_rat
Trochilus_rat
Quasar_rat
Passview_tool
Powersploit
Powerview
Industry:
Government, Telco, Education, Financial, Aerospace
Geo:
Asian, Asia
CVEs:
CVE-2020-1472 [Vulners]
Vulners: Score: 9.3, CVSS: 3.8,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2)
- microsoft windows server 2012 (-, r2)
- microsoft windows server 2016 (-, 1903, 1909, 2004)
- microsoft windows server 2019 (-)
- fedoraproject fedora (31, 32, 33)
have more...
CVE-2021-26855 [Vulners]
Vulners: Score: 7.5, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 9.1
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2016, 2016, 2013, 2016, 2016, 2013, 2016, 2019, 2013, 2016, 2016, 2016, 2016, 2016, 2016, 2016, 2019, 2019, 2019, 2019, 2019, 2019, 2019, 2019)
IOCs:
File: 25
Hash: 33
Path: 2
IP: 7
Registry: 1
Softs:
psexec, active directory, local security authority
Links:
https://github.com/k8gege/LadonGoSecurity
New Wave of Espionage Activity Targets Asian Governments
Governments and state-owned organizations are the latest targets of a well-established threat actor.
#ParsedReport
13-09-2022
Chiseling In: Lorenz Ransomware Group Cracks MiVoice And Calls Back For Free
https://arcticwolf.com/resources/blog/lorenz-ransomware-chiseling-in
Threats:
Lorenz
Lolbin
Chisel_tool
Crackmapexec_tool
Minidump_tool
Dumplsass_tool
Netstat_tool
Industry:
Iot
Geo:
China, Mexico
CVEs:
CVE-2022-29499 [Vulners]
Vulners: Score: 10.0, CVSS: 5.1,
Vulners: Exploitation: True
X-Force: Risk: 7.3
X-Force: Patch: Official fix
Soft:
- mitel mivoice connect (le22.20.2300.0)
TTPs:
Tactics: 11
Technics: 23
IOCs:
IP: 9
File: 12
Hash: 2
Url: 2
Path: 3
Registry: 1
Softs:
bitlocker, esxi, curl, openssl, local security authority, windows error reporting, task scheduler
Algorithms:
aes-256, base64
Languages:
php
YARA: Found
SIGMA: Found
Links:
13-09-2022
Chiseling In: Lorenz Ransomware Group Cracks MiVoice And Calls Back For Free
https://arcticwolf.com/resources/blog/lorenz-ransomware-chiseling-in
Threats:
Lorenz
Lolbin
Chisel_tool
Crackmapexec_tool
Minidump_tool
Dumplsass_tool
Netstat_tool
Industry:
Iot
Geo:
China, Mexico
CVEs:
CVE-2022-29499 [Vulners]
Vulners: Score: 10.0, CVSS: 5.1,
Vulners: Exploitation: True
X-Force: Risk: 7.3
X-Force: Patch: Official fix
Soft:
- mitel mivoice connect (le22.20.2300.0)
TTPs:
Tactics: 11
Technics: 23
IOCs:
IP: 9
File: 12
Hash: 2
Url: 2
Path: 3
Registry: 1
Softs:
bitlocker, esxi, curl, openssl, local security authority, windows error reporting, task scheduler
Algorithms:
aes-256, base64
Languages:
php
YARA: Found
SIGMA: Found
Links:
https://github.com/SigmaHQ/sigma/blob/b24e7ae9846f53cbbf61adad72f17af317c860a4/rules/windows/process\_creation/proc\_creation\_win\_powershell\_cmdline\_convertto\_securestring.yml
https://github.com/jpillora/chisel
https://github.com/Porchetta-Industries/CrackMapExec
https://github.com/SigmaHQ/sigma/blob/a80c29a7c2e2e500a1a532db2a2a8bd69bd4a63d/rules/windows/registry\_event/sysmon\_powershell\_as\_service.yml
https://github.com/Hackndo/lsassy
https://github.com/NVISOsecurity/sigma-public/blob/master/rules/windows/builtin/win\_atsvc\_task.yml
https://github.com/SigmaHQ/sigma/blob/master/rules/windows/sysmon/sysmon\_accessing\_winapi\_in\_powershell\_credentials\_dumping.yml
https://github.com/SigmaHQ/sigma/blob/1e16ed00905a496cbc3b0a1a03d4c2f6f4b63de2/rules/windows/process\_creation/proc\_creation\_win\_crackmapexec\_patterns.yml
https://github.com/rtkwlf/wolf-tools/blob/main/threat-intelligence/lorenz-ransomware-chiseling-in/lorenz-yara.yar
https://github.com/rtkwlf/wolf-tools/blob/main/threat-intelligence/lorenz-ransomware-chiseling-in/lorenz-suricata.rules
https://github.com/SigmaHQ/sigma
https://github.com/SigmaHQ/sigma/blob/ab814cbc408234eddf538bc893fcbe00c32ca2e9/rules/windows/process\_creation/win\_susp\_comsvcs\_procdump.ymlArctic Wolf
Lorenz Ransomware Group Cracks MiVoice | Arctic Wolf
Learn about Arctic Wolf Lab’s recent investigation into a Lorenz ransomware intrusion which leveraged a Mitel MiVoice VOIP appliance vulnerability for initial access and Microsoft’s BitLocker Drive Encryption for data encryption.
#technique
A cross platform C2/post-exploitation framework implementation by Rust.
https://github.com/b23r0/Heroinn
A cross platform C2/post-exploitation framework implementation by Rust.
https://github.com/b23r0/Heroinn
GitHub
GitHub - b23r0/Heroinn: A cross platform C2/post-exploitation framework.
A cross platform C2/post-exploitation framework. Contribute to b23r0/Heroinn development by creating an account on GitHub.
#technique
Caching the Un-cacheables - Abusing URL Parser Confusions (Web Cache Poisoning Technique)
https://nokline.github.io/bugbounty/2022/09/02/Glassdoor-Cache-Poisoning.html
Caching the Un-cacheables - Abusing URL Parser Confusions (Web Cache Poisoning Technique)
https://nokline.github.io/bugbounty/2022/09/02/Glassdoor-Cache-Poisoning.html
#ParsedReport
14-09-2022
ASEC Weekly Malware Statistics (August 29th, 2022 September 4th, 2022)
https://asec.ahnlab.com/en/38739
Threats:
Cloudeye
Formbook
Agent_tesla
Remcos_rat
Nanocore_rat
Clipboard_grabbing_technique
Lokibot_stealer
Industry:
Financial
Geo:
Korea
IOCs:
Url: 17
File: 15
Domain: 4
IP: 3
Email: 6
Softs:
nsis installer, discord
Languages:
php, visual_basic
14-09-2022
ASEC Weekly Malware Statistics (August 29th, 2022 September 4th, 2022)
https://asec.ahnlab.com/en/38739
Threats:
Cloudeye
Formbook
Agent_tesla
Remcos_rat
Nanocore_rat
Clipboard_grabbing_technique
Lokibot_stealer
Industry:
Financial
Geo:
Korea
IOCs:
Url: 17
File: 15
Domain: 4
IP: 3
Email: 6
Softs:
nsis installer, discord
Languages:
php, visual_basic
ASEC BLOG
ASEC Weekly Malware Statistics (August 29th, 2022 – September 4th, 2022) - ASEC BLOG
The ASEC analysis team is using the ASEC automatic analysis system RAPIT to categorize and respond to known malware. This post will list weekly statistics collected from August 29th, 2022 (Monday) to September 4th, 2022 (Sunday). For the main category, info…
#ParsedReport
14-09-2022
Phishing Websites Disguised as Korean Groupware Login Website Being Distributed
https://asec.ahnlab.com/en/38786
Geo:
Korean, Korea
IOCs:
Url: 6
Languages:
javascript
14-09-2022
Phishing Websites Disguised as Korean Groupware Login Website Being Distributed
https://asec.ahnlab.com/en/38786
Geo:
Korean, Korea
IOCs:
Url: 6
Languages:
javascript
ASEC BLOG
Phishing Websites Disguised as Korean Groupware Login Website Being Distributed - ASEC BLOG
The ASEC analysis team has been building a honeypot to collect various malware strains that are being distributed both in Korea and overseas. The honeypot also collects phishing emails and recently caught one targeting Korean users, which was being distributed…
#ParsedReport
14-09-2022
Fake URL Authentication
https://labs.k7computing.com/index.php/fake-url-authentication
Threats:
Hajime
Industry:
Iot
IOCs:
Url: 6
Softs:
instagram
Algorithms:
base64
14-09-2022
Fake URL Authentication
https://labs.k7computing.com/index.php/fake-url-authentication
Threats:
Hajime
Industry:
Iot
IOCs:
Url: 6
Softs:
Algorithms:
base64
K7 Labs
Fake URL Authentication - K7 Labs
In this internet era, we consume Giga Bytes (GBs) of data everyday, which includes surfing the internet, streaming videos, online […]
#ParsedReport
14-09-2022
A Post-exploitation Look at Coinminers Abusing WebLogic Vulnerabilities
https://www.trendmicro.com/en_us/research/22/i/a-post-exploitation-look-at-coinminers-abusing-weblogic-vulnerab.html
Threats:
Kinsing_miner
CVEs:
CVE-2020-14882 [Vulners]
Vulners: Score: 10.0, CVSS: 3.3,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- oracle weblogic server (12.1.3.0.0, 10.3.6.0.0, 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0)
TTPs:
Tactics: 1
Technics: 9
IOCs:
Url: 15
Hash: 2
IP: 3
Softs:
docker, curl
Algorithms:
base64
Languages:
java
14-09-2022
A Post-exploitation Look at Coinminers Abusing WebLogic Vulnerabilities
https://www.trendmicro.com/en_us/research/22/i/a-post-exploitation-look-at-coinminers-abusing-weblogic-vulnerab.html
Threats:
Kinsing_miner
CVEs:
CVE-2020-14882 [Vulners]
Vulners: Score: 10.0, CVSS: 3.3,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- oracle weblogic server (12.1.3.0.0, 10.3.6.0.0, 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0)
TTPs:
Tactics: 1
Technics: 9
IOCs:
Url: 15
Hash: 2
IP: 3
Softs:
docker, curl
Algorithms:
base64
Languages:
java
Trend Micro
A Post-exploitation Look at Coinminers Abusing WebLogic Vulnerabilities
This blog entry details how Trend Micro Cloud One™ – Workload Security and Trend Micro Vision One™ effectively detected and blocked the abuse of the CVE-2020-14882 WebLogic vulnerability in affected endpoints.
#ParsedReport
14-09-2022
Loader Malware Emotet is Now Led by Quantum and BlackCat
https://socradar.io/loader-malware-emotet-is-now-led-by-quantum-and-blackcat
Threats:
Emotet
Quantum_locker
Blackcat
Lampion
Conti
Cobalt_strike
Beacon
Process_injection_technique
Industry:
Financial
Geo:
Russian, Ukrainian
TTPs:
Tactics: 1
Technics: 24
Languages:
visual_basic
14-09-2022
Loader Malware Emotet is Now Led by Quantum and BlackCat
https://socradar.io/loader-malware-emotet-is-now-led-by-quantum-and-blackcat
Threats:
Emotet
Quantum_locker
Blackcat
Lampion
Conti
Cobalt_strike
Beacon
Process_injection_technique
Industry:
Financial
Geo:
Russian, Ukrainian
TTPs:
Tactics: 1
Technics: 24
Languages:
visual_basic
SOCRadar® Cyber Intelligence Inc.
Loader Malware Emotet is Now Led by Quantum and BlackCat - SOCRadar® Cyber Intelligence Inc.
Emotet (also known as SpmTools) is a sophisticated, modular banking trojan. Emotetmostly serves as a downloader or dropper of other banking trojans. It
#ParsedReport
14-09-2022
You never walk alone: The SideWalk backdoor gets a Linux variant
https://www.welivesecurity.com/2022/09/14/you-never-walk-alone-sidewalk-backdoor-linux-variant
Actors/Campaigns:
Sparklinggoblin
Axiom
Fishmonger
Threats:
Sidewalk
Dead_drop_technique
Stageclients
Specter_rat
Cobalt_strike
Crosswalk
Plugx_rat
Shadowpad
Spyder
Industry:
Education
Geo:
Ukraine, Asia
TTPs:
Tactics: 4
Technics: 4
IOCs:
IP: 2
Hash: 3
Path: 1
Domain: 1
Algorithms:
chacha20, exhibit
Win API:
VirtualAlloc
Links:
14-09-2022
You never walk alone: The SideWalk backdoor gets a Linux variant
https://www.welivesecurity.com/2022/09/14/you-never-walk-alone-sidewalk-backdoor-linux-variant
Actors/Campaigns:
Sparklinggoblin
Axiom
Fishmonger
Threats:
Sidewalk
Dead_drop_technique
Stageclients
Specter_rat
Cobalt_strike
Crosswalk
Plugx_rat
Shadowpad
Spyder
Industry:
Education
Geo:
Ukraine, Asia
TTPs:
Tactics: 4
Technics: 4
IOCs:
IP: 2
Hash: 3
Path: 1
Domain: 1
Algorithms:
chacha20, exhibit
Win API:
VirtualAlloc
Links:
https://github.com/eset/malware-ioc/tree/master/sparklinggoblinWeLiveSecurity
You never walk alone: The SideWalk backdoor gets a Linux variant
ESET researchers have uncovered another tool in the already extensive arsenal of the SparklingGoblin APT group: a Linux variant of the SideWalk backdoor.
#ParsedReport
14-09-2022
OriginLogger
https://1275.ru/ioc/668/originlogger/?from=rss
Threats:
Originlogger
Agent_tesla
Snake_keylogger
Purecrypter
IOCs:
IP: 3
Hash: 5
Softs:
discord
14-09-2022
OriginLogger
https://1275.ru/ioc/668/originlogger/?from=rss
Threats:
Originlogger
Agent_tesla
Snake_keylogger
Purecrypter
IOCs:
IP: 3
Hash: 5
Softs:
discord
SEC-1275-1
OriginLogger - SEC-1275-1
OriginLogger - 4 марта 2019 года один из самых известных кейлоггеров, используемых преступниками, под названием Agent Tesla закрыл магазин из-за юридических проблем. В
#ParsedReport
14-09-2022
Emotet Botnet IOCs - Part 13
https://1275.ru/ioc/666/emotet-botnet-iocs-part-12-2/?from=rss
Threats:
Emotet
Cobalt_strike
IOCs:
IP: 5
Hash: 18
Algorithms:
zip
Platforms:
x64
14-09-2022
Emotet Botnet IOCs - Part 13
https://1275.ru/ioc/666/emotet-botnet-iocs-part-12-2/?from=rss
Threats:
Emotet
Cobalt_strike
IOCs:
IP: 5
Hash: 18
Algorithms:
zip
Platforms:
x64
SEC-1275-1
Emotet Botnet IOCs - Part 13 - SEC-1275-1
Emotet Botnet IOCs - Part 13 - Emotet, который ранее был уничтожен усилиями Интерпола и Евроюста, вновь активизировался с ноября 2021 года. В мае этого года DFIR стал свидетелем
#ParsedReport
14-09-2022
SEARCH. Iranian Attackers Upgrade Social Engineering Tactics
https://www.proofpoint.com/us/newsroom/news/iranian-attackers-upgrade-social-engineering-tactics
Actors/Campaigns:
Cleaver
Cosmic_lynx
Bec
Industry:
Education
Geo:
Russia, Iranian, Irans, Iran
Softs:
telegram
14-09-2022
SEARCH. Iranian Attackers Upgrade Social Engineering Tactics
https://www.proofpoint.com/us/newsroom/news/iranian-attackers-upgrade-social-engineering-tactics
Actors/Campaigns:
Cleaver
Cosmic_lynx
Bec
Industry:
Education
Geo:
Russia, Iranian, Irans, Iran
Softs:
telegram
Decipher
Iranian Attackers Upgrade Social Engineering Tactics
Iranian threat actor TA453 has been sending spear-phishing emails that impersonate real individuals from Western foreign policy research institutions.
#ParsedReport
14-09-2022
Opsec Mistakes Reveal COBALT MIRAGE Threat Actors
https://www.secureworks.com/blog/opsec-mistakes-reveal-cobalt-mirage-threat-actors
Actors/Campaigns:
Cobalt_mirage (motivation: cyber_espionage)
Oilrig
Dnspionage
Phosphorus
Agrius
Blackshadow
Threats:
Mirage
Proxyshell_vuln
Rana
Mosesstaff
Industry:
Financial, Government
Geo:
Irans, Iran, Iranian, Iranians, Israel
CVEs:
CVE-2021-31207 [Vulners]
Vulners: Score: 6.5, CVSS: 1.7,
Vulners: Exploitation: True
X-Force: Risk: 6.6
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2013, 2019, 2016, 2016, 2019)
CVE-2021-34473 [Vulners]
Vulners: Score: 10.0, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 9.1
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2013, 2019, 2016, 2016, 2019)
CVE-2021-34523 [Vulners]
Vulners: Score: 7.5, CVSS: 3.4,
Vulners: Exploitation: True
X-Force: Risk: 9
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2013, 2019, 2016, 2016, 2019)
IOCs:
File: 1
IP: 3
Hash: 1
Softs:
bitlocker, telegram, android
Win Services:
gupdate
Links:
14-09-2022
Opsec Mistakes Reveal COBALT MIRAGE Threat Actors
https://www.secureworks.com/blog/opsec-mistakes-reveal-cobalt-mirage-threat-actors
Actors/Campaigns:
Cobalt_mirage (motivation: cyber_espionage)
Oilrig
Dnspionage
Phosphorus
Agrius
Blackshadow
Threats:
Mirage
Proxyshell_vuln
Rana
Mosesstaff
Industry:
Financial, Government
Geo:
Irans, Iran, Iranian, Iranians, Israel
CVEs:
CVE-2021-31207 [Vulners]
Vulners: Score: 6.5, CVSS: 1.7,
Vulners: Exploitation: True
X-Force: Risk: 6.6
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2013, 2019, 2016, 2016, 2019)
CVE-2021-34473 [Vulners]
Vulners: Score: 10.0, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 9.1
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2013, 2019, 2016, 2016, 2019)
CVE-2021-34523 [Vulners]
Vulners: Score: 7.5, CVSS: 3.4,
Vulners: Exploitation: True
X-Force: Risk: 9
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2013, 2019, 2016, 2016, 2019)
IOCs:
File: 1
IP: 3
Hash: 1
Softs:
bitlocker, telegram, android
Win Services:
gupdate
Links:
https://github.com/fatedier/frpSecureworks
Opsec Mistakes Reveal COBALT MIRAGE Threat Actors
Artifacts exposed personas and companies associated with the Iranian threat group.
#ParsedReport
14-09-2022
Lorenz Ransomware Group IOCs
https://1275.ru/ioc/669/lorenz-ransomware-group-iocs/?from=rss
Threats:
Lorenz
Lolbin
Lokilocker
Hive
Avoslocker
Evilnominatus
Geo:
Mexico, China, Usa
CVEs:
CVE-2022-29499 [Vulners]
Vulners: Score: 10.0, CVSS: 5.1,
Vulners: Exploitation: True
X-Force: Risk: 7.3
X-Force: Patch: Official fix
Soft:
- mitel mivoice connect (le22.20.2300.0)
IOCs:
IP: 7
Hash: 2
Softs:
bitlocker, esxi
14-09-2022
Lorenz Ransomware Group IOCs
https://1275.ru/ioc/669/lorenz-ransomware-group-iocs/?from=rss
Threats:
Lorenz
Lolbin
Lokilocker
Hive
Avoslocker
Evilnominatus
Geo:
Mexico, China, Usa
CVEs:
CVE-2022-29499 [Vulners]
Vulners: Score: 10.0, CVSS: 5.1,
Vulners: Exploitation: True
X-Force: Risk: 7.3
X-Force: Patch: Official fix
Soft:
- mitel mivoice connect (le22.20.2300.0)
IOCs:
IP: 7
Hash: 2
Softs:
bitlocker, esxi
SEC-1275-1
Lorenz Ransomware Group IOCs - SEC-1275-1
Lorenz Ransomware Group IOCs - Команда Arctic Wolf Labs недавно исследовала вторжение вымогательского ПО Lorenz, которое использовало уязвимость в устройстве Mitel MiVoice VoIP
На правах рекламы :)
https://cisoclub.ru/rst-cloud-i-security-vision-obedinili-ekspertizu-dlya-rassledovaniya-i-reagirovaniya-na-inczidenty-kiberbezopasnosti/
https://cisoclub.ru/rst-cloud-i-security-vision-obedinili-ekspertizu-dlya-rassledovaniya-i-reagirovaniya-na-inczidenty-kiberbezopasnosti/
CISOCLUB
RST Cloud и Security Vision объединили экспертизу для расследования и реагирования на инциденты кибербезопасности
Интеграция продуктов RST Cloud и Security Vision позволит заказчикам использовать в процессах киберразведки и инцидент-менеджмента расширенную актуальную базу индикаторов на основе более чем 260 открытых источников. Компания RST Cloud, поставщик индикаторов…
#ParsedReport
14-09-2022
Fake Security App Found Abusing Japanese Payment System. How Do victims install this malware?
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/fake-security-app-found-abusing-japanese-payment-system
Threats:
Emotet
Dexter
Industry:
Financial
Geo:
France, Japanese, Japan
IOCs:
Domain: 1
Hash: 6
Softs:
chrome, instagram, android
Languages:
golang
14-09-2022
Fake Security App Found Abusing Japanese Payment System. How Do victims install this malware?
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/fake-security-app-found-abusing-japanese-payment-system
Threats:
Emotet
Dexter
Industry:
Financial
Geo:
France, Japanese, Japan
IOCs:
Domain: 1
Hash: 6
Softs:
chrome, instagram, android
Languages:
golang
McAfee Blog
Fake Security App Found Abuses Japanese Payment System | McAfee Blog
Authored by SangRyol Ryu and Yukihiro Okutomi McAfee’s Mobile Research team recently analyzed new malware targeting mobile payment users in Japan. The
#ParsedReport
15-09-2022
Change in Magniber Ransomware (*.cpl *.jse) September 8th
https://asec.ahnlab.com/en/38808
Threats:
Magniber
Typosquatting_technique
Geo:
Korean
IOCs:
Hash: 1
Softs:
chrome
Algorithms:
zip
15-09-2022
Change in Magniber Ransomware (*.cpl *.jse) September 8th
https://asec.ahnlab.com/en/38808
Threats:
Magniber
Typosquatting_technique
Geo:
Korean
IOCs:
Hash: 1
Softs:
chrome
Algorithms:
zip
ASEC
Change in Magniber Ransomware (*.cpl → *.jse) – September 8th - ASEC
Change in Magniber Ransomware (*.cpl → *.jse) – September 8th ASEC
#ParsedReport
15-09-2022
JPCERT/CC Eyes
https://blogs.jpcert.or.jp/en/2022/09/bigip-exploit.html
Actors/Campaigns:
Blacktech
Threats:
Hipid
Plead
Bifrose
Industry:
Iot
Geo:
Usa, Japanese
CVEs:
CVE-2022-1388 [Vulners]
Vulners: Score: 7.5, CVSS: 3.8,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- f5 big-ip access policy manager (le11.6.5, le12.1.6, <16.1.2.2, <15.1.5.1, <14.1.4.6, <13.1.5)
- f5 big-ip advanced firewall manager (le11.6.5, le12.1.6, <15.1.5.1, <14.1.4.6, <13.1.5, <16.1.2.2)
- f5 big-ip analytics (le11.6.5, le12.1.6, <16.1.2.2, <15.1.5.1, <14.1.4.6, <13.1.5)
- f5 big-ip application acceleration manager (le11.6.5, le12.1.6, <16.1.2.2, <15.1.5.1, <14.1.4.6, <13.1.5)
- f5 big-ip application security manager (le11.6.5, le12.1.6, <16.1.2.2, <15.1.5.1, <14.1.4.6, <13.1.5)
have more...
IOCs:
Hash: 3
Softs:
big-ip
Algorithms:
rc4, base32
Languages:
javascript
Platforms:
x64, arm
15-09-2022
JPCERT/CC Eyes
https://blogs.jpcert.or.jp/en/2022/09/bigip-exploit.html
Actors/Campaigns:
Blacktech
Threats:
Hipid
Plead
Bifrose
Industry:
Iot
Geo:
Usa, Japanese
CVEs:
CVE-2022-1388 [Vulners]
Vulners: Score: 7.5, CVSS: 3.8,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- f5 big-ip access policy manager (le11.6.5, le12.1.6, <16.1.2.2, <15.1.5.1, <14.1.4.6, <13.1.5)
- f5 big-ip advanced firewall manager (le11.6.5, le12.1.6, <15.1.5.1, <14.1.4.6, <13.1.5, <16.1.2.2)
- f5 big-ip analytics (le11.6.5, le12.1.6, <16.1.2.2, <15.1.5.1, <14.1.4.6, <13.1.5)
- f5 big-ip application acceleration manager (le11.6.5, le12.1.6, <16.1.2.2, <15.1.5.1, <14.1.4.6, <13.1.5)
- f5 big-ip application security manager (le11.6.5, le12.1.6, <16.1.2.2, <15.1.5.1, <14.1.4.6, <13.1.5)
have more...
IOCs:
Hash: 3
Softs:
big-ip
Algorithms:
rc4, base32
Languages:
javascript
Platforms:
x64, arm
JPCERT/CC Eyes
F5 BIG-IP Vulnerability (CVE-2022-1388) Exploited by BlackTech - JPCERT/CC Eyes
Around May 2022, JPCERT/CC confirmed an attack activity against Japanese organizations that exploited F5 BIG-IP vulnerability (CVE-2022-1388). The targeted organizations have confirmed that data in BIG-IP has been compromised. We consider that this attack…
#ParsedReport
15-09-2022
EvilProxy IOCs
https://1275.ru/ioc/670/evilproxy-iocs/?from=rss
Threats:
Evilproxy
Moloch
Industry:
Financial
IOCs:
IP: 3
Softs:
cpanel
15-09-2022
EvilProxy IOCs
https://1275.ru/ioc/670/evilproxy-iocs/?from=rss
Threats:
Evilproxy
Moloch
Industry:
Financial
IOCs:
IP: 3
Softs:
cpanel
SEC-1275-1
EvilProxy IOCs - SEC-1275-1
EvilProxy IOCs - После недавнего взлома Twilio, приведшего к утечке кодов 2FA (OTP), киберпреступники продолжают совершенствовать свой арсенал атак для организации