CTT Report Hub
3.43K subscribers
9.9K photos
6 videos
67 files
13.5K links
Threat Intelligence Report Hub
Download Telegram
#ParsedReport
13-09-2022

Chiseling In: Lorenz Ransomware Group Cracks MiVoice And Calls Back For Free

https://arcticwolf.com/resources/blog/lorenz-ransomware-chiseling-in

Threats:
Lorenz
Lolbin
Chisel_tool
Crackmapexec_tool
Minidump_tool
Dumplsass_tool
Netstat_tool

Industry:
Iot

Geo:
China, Mexico

CVEs:
CVE-2022-29499 [Vulners]
Vulners: Score: 10.0, CVSS: 5.1,
Vulners: Exploitation: True
X-Force: Risk: 7.3
X-Force: Patch: Official fix
Soft:
- mitel mivoice connect (le22.20.2300.0)


TTPs:
Tactics: 11
Technics: 23

IOCs:
IP: 9
File: 12
Hash: 2
Url: 2
Path: 3
Registry: 1

Softs:
bitlocker, esxi, curl, openssl, local security authority, windows error reporting, task scheduler

Algorithms:
aes-256, base64

Languages:
php

YARA: Found
SIGMA: Found

Links:
https://github.com/SigmaHQ/sigma/blob/b24e7ae9846f53cbbf61adad72f17af317c860a4/rules/windows/process\_creation/proc\_creation\_win\_powershell\_cmdline\_convertto\_securestring.yml
https://github.com/jpillora/chisel
https://github.com/Porchetta-Industries/CrackMapExec
https://github.com/SigmaHQ/sigma/blob/a80c29a7c2e2e500a1a532db2a2a8bd69bd4a63d/rules/windows/registry\_event/sysmon\_powershell\_as\_service.yml
https://github.com/Hackndo/lsassy
https://github.com/NVISOsecurity/sigma-public/blob/master/rules/windows/builtin/win\_atsvc\_task.yml
https://github.com/SigmaHQ/sigma/blob/master/rules/windows/sysmon/sysmon\_accessing\_winapi\_in\_powershell\_credentials\_dumping.yml
https://github.com/SigmaHQ/sigma/blob/1e16ed00905a496cbc3b0a1a03d4c2f6f4b63de2/rules/windows/process\_creation/proc\_creation\_win\_crackmapexec\_patterns.yml
https://github.com/rtkwlf/wolf-tools/blob/main/threat-intelligence/lorenz-ransomware-chiseling-in/lorenz-yara.yar
https://github.com/rtkwlf/wolf-tools/blob/main/threat-intelligence/lorenz-ransomware-chiseling-in/lorenz-suricata.rules
https://github.com/SigmaHQ/sigma
https://github.com/SigmaHQ/sigma/blob/ab814cbc408234eddf538bc893fcbe00c32ca2e9/rules/windows/process\_creation/win\_susp\_comsvcs\_procdump.yml
#technique

Caching the Un-cacheables - Abusing URL Parser Confusions (Web Cache Poisoning Technique)

https://nokline.github.io/bugbounty/2022/09/02/Glassdoor-Cache-Poisoning.html
#ParsedReport
14-09-2022

ASEC Weekly Malware Statistics (August 29th, 2022 September 4th, 2022)

https://asec.ahnlab.com/en/38739

Threats:
Cloudeye
Formbook
Agent_tesla
Remcos_rat
Nanocore_rat
Clipboard_grabbing_technique
Lokibot_stealer

Industry:
Financial

Geo:
Korea

IOCs:
Url: 17
File: 15
Domain: 4
IP: 3
Email: 6

Softs:
nsis installer, discord

Languages:
php, visual_basic
#ParsedReport
14-09-2022

A Post-exploitation Look at Coinminers Abusing WebLogic Vulnerabilities

https://www.trendmicro.com/en_us/research/22/i/a-post-exploitation-look-at-coinminers-abusing-weblogic-vulnerab.html

Threats:
Kinsing_miner

CVEs:
CVE-2020-14882 [Vulners]
Vulners: Score: 10.0, CVSS: 3.3,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- oracle weblogic server (12.1.3.0.0, 10.3.6.0.0, 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0)


TTPs:
Tactics: 1
Technics: 9

IOCs:
Url: 15
Hash: 2
IP: 3

Softs:
docker, curl

Algorithms:
base64

Languages:
java
#ParsedReport
14-09-2022

Loader Malware Emotet is Now Led by Quantum and BlackCat

https://socradar.io/loader-malware-emotet-is-now-led-by-quantum-and-blackcat

Threats:
Emotet
Quantum_locker
Blackcat
Lampion
Conti
Cobalt_strike
Beacon
Process_injection_technique

Industry:
Financial

Geo:
Russian, Ukrainian

TTPs:
Tactics: 1
Technics: 24

Languages:
visual_basic
#ParsedReport
14-09-2022

You never walk alone: The SideWalk backdoor gets a Linux variant

https://www.welivesecurity.com/2022/09/14/you-never-walk-alone-sidewalk-backdoor-linux-variant

Actors/Campaigns:
Sparklinggoblin
Axiom
Fishmonger

Threats:
Sidewalk
Dead_drop_technique
Stageclients
Specter_rat
Cobalt_strike
Crosswalk
Plugx_rat
Shadowpad
Spyder

Industry:
Education

Geo:
Ukraine, Asia

TTPs:
Tactics: 4
Technics: 4

IOCs:
IP: 2
Hash: 3
Path: 1
Domain: 1

Algorithms:
chacha20, exhibit

Win API:
VirtualAlloc

Links:
https://github.com/eset/malware-ioc/tree/master/sparklinggoblin
#ParsedReport
14-09-2022

Opsec Mistakes Reveal COBALT MIRAGE Threat Actors

https://www.secureworks.com/blog/opsec-mistakes-reveal-cobalt-mirage-threat-actors

Actors/Campaigns:
Cobalt_mirage (motivation: cyber_espionage)
Oilrig
Dnspionage
Phosphorus
Agrius
Blackshadow

Threats:
Mirage
Proxyshell_vuln
Rana
Mosesstaff

Industry:
Financial, Government

Geo:
Irans, Iran, Iranian, Iranians, Israel

CVEs:
CVE-2021-31207 [Vulners]
Vulners: Score: 6.5, CVSS: 1.7,
Vulners: Exploitation: True
X-Force: Risk: 6.6
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2013, 2019, 2016, 2016, 2019)

CVE-2021-34473 [Vulners]
Vulners: Score: 10.0, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 9.1
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2013, 2019, 2016, 2016, 2019)

CVE-2021-34523 [Vulners]
Vulners: Score: 7.5, CVSS: 3.4,
Vulners: Exploitation: True
X-Force: Risk: 9
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2013, 2019, 2016, 2016, 2019)


IOCs:
File: 1
IP: 3
Hash: 1

Softs:
bitlocker, telegram, android

Win Services:
gupdate

Links:
https://github.com/fatedier/frp
#ParsedReport
14-09-2022

Lorenz Ransomware Group IOCs

https://1275.ru/ioc/669/lorenz-ransomware-group-iocs/?from=rss

Threats:
Lorenz
Lolbin
Lokilocker
Hive
Avoslocker
Evilnominatus

Geo:
Mexico, China, Usa

CVEs:
CVE-2022-29499 [Vulners]
Vulners: Score: 10.0, CVSS: 5.1,
Vulners: Exploitation: True
X-Force: Risk: 7.3
X-Force: Patch: Official fix
Soft:
- mitel mivoice connect (le22.20.2300.0)


IOCs:
IP: 7
Hash: 2

Softs:
bitlocker, esxi
#ParsedReport
15-09-2022

Change in Magniber Ransomware (*.cpl *.jse) September 8th

https://asec.ahnlab.com/en/38808

Threats:
Magniber
Typosquatting_technique

Geo:
Korean

IOCs:
Hash: 1

Softs:
chrome

Algorithms:
zip
#ParsedReport
15-09-2022

JPCERT/CC Eyes

https://blogs.jpcert.or.jp/en/2022/09/bigip-exploit.html

Actors/Campaigns:
Blacktech

Threats:
Hipid
Plead
Bifrose

Industry:
Iot

Geo:
Usa, Japanese

CVEs:
CVE-2022-1388 [Vulners]
Vulners: Score: 7.5, CVSS: 3.8,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- f5 big-ip access policy manager (le11.6.5, le12.1.6, <16.1.2.2, <15.1.5.1, <14.1.4.6, <13.1.5)
- f5 big-ip advanced firewall manager (le11.6.5, le12.1.6, <15.1.5.1, <14.1.4.6, <13.1.5, <16.1.2.2)
- f5 big-ip analytics (le11.6.5, le12.1.6, <16.1.2.2, <15.1.5.1, <14.1.4.6, <13.1.5)
- f5 big-ip application acceleration manager (le11.6.5, le12.1.6, <16.1.2.2, <15.1.5.1, <14.1.4.6, <13.1.5)
- f5 big-ip application security manager (le11.6.5, le12.1.6, <16.1.2.2, <15.1.5.1, <14.1.4.6, <13.1.5)
have more...

IOCs:
Hash: 3

Softs:
big-ip

Algorithms:
rc4, base32

Languages:
javascript

Platforms:
x64, arm