CTT Report Hub
3.38K subscribers
9.26K photos
6 videos
67 files
12.9K links
Threat Intelligence Report Hub
Download Telegram
#ParsedReport
23-10-2022

Alert (AA22-294A)

https://us-cert.cisa.gov/ncas/alerts/aa22-294a

Threats:
Daixin
Passthehash_technique
Babuk
Daxin

Industry:
Financial, Iot, Healthcare

Geo:
Canada, Australia

TTPs:
Tactics: 7
Technics: 10

IOCs:
Hash: 5

Softs:
esxi, rclonean

Links:
https://github.com/cisagov/cset/releases/tag/v10.3.0.0
#ParsedReport
24-10-2022

BYOVD. Rajarus attack group's malware infection case that disables vaccine programs with BYOVD techniques

https://asec.ahnlab.com/ko/40495

Actors/Campaigns:
Lazarus

Threats:
Byovd_technique
Watering_hole_technique
Lazardoor
Lazarshell
Lazarloader
Trojan/win.agent
Putty_tool
Plink

Industry:
Chemical

Geo:
Korea

CVEs:
CVE-2021-26606 [Vulners]
Vulners: Score: 10.0, CVSS: 3.0,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- dreamsecurity magicline4nx.exe (le1.0.0.17)


IOCs:
Hash: 16
IP: 13
Url: 1
File: 6
#ParsedReport
24-10-2022

Multiple RCE Vulnerabilities Affecting Veeam Backup & Replication

https://cloudsek.com/threatintelligence/multiple-rce-vulnerabilities-affecting-veeam-backup-replication/?utm_source=rss&utm_medium=rss&utm_campaign=multiple-rce-vulnerabilities-affecting-veeam-backup-replication

Threats:
Empire_loader
Monti
Yanluowang

CVEs:
CVE-2022-26501 [Vulners]
Vulners: Score: 10.0, CVSS: 2.0,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- veeam backup \& replication (<10.0.1.4854, 10.0.1.4854, 10.0.1.4854, 10.0.1.4854, 10.0.1.4854, <11.0.1.1261, 11.0.1.1261, 11.0.1.1261, 11.0.1.1261, 11.0.1.1261)

CVE-2022-26500 [Vulners]
Vulners: Score: 6.5, CVSS: 7.4,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- veeam backup \& replication (9.5.0.1536, 9.5.4.2615, <10.0.1.4854, 10.0.1.4854, 10.0.1.4854, 10.0.1.4854, 10.0.1.4854, <11.0.1.1261, 11.0.1.1261, 11.0.1.1261, 11.0.1.1261, 11.0.1.1261)

CVE-2022-26504 [Vulners]
Vulners: Score: 9.0, CVSS: 7.4,
Vulners: Exploitation: Unknown
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- veeam backup \& replication (9.5.0.1536, 9.5.4.2615, <10.0.1.4854, 10.0.1.4854, 10.0.1.4854, 10.0.1.4854, 10.0.1.4854, <11.0.1.1261, 11.0.1.1261, 11.0.1.1261, 11.0.1.1261, 11.0.1.1261)


TTPs:
Tactics: 3
Technics: 0

IOCs:
File: 3
Hash: 3
IP: 1

Softs:
hyper-v

Languages:
python

Links:
https://github.com/sadshade/veeam-creds
#ParsedReport
25-10-2022

Analysis on Attack Techniques and Cases Using RDP

https://asec.ahnlab.com/en/40394

Actors/Campaigns:
Darkside
Kimsuky

Threats:
Lokilocker
Lockbit
Plink
Conti
Appleseed
Reverserdp_technique
Avemaria_rat
Htran
Mimikatz_tool
Passthehash_technique
Trojan/win.agent.c5245646
Trojan/bat.agent.sc183591
Malware/win.generic.c4933135
Bazarbackdoor

Geo:
Korean

TTPs:
Tactics: 1
Technics: 0

IOCs:
Registry: 4
File: 6
IP: 1
Hash: 3
Url: 1

Softs:
remote desktop services, psexec, ms-sql

Functions:
CreateHiddenAccount

Languages:
golang

Platforms:
x64

Links:
https://github.com/wgpsec/CreateHiddenAccount
#ParsedReport
25-10-2022

ASEC Weekly Malware Statistics (October 10th, 2022 October 16th, 2022)

https://asec.ahnlab.com/en/40526

Threats:
Smokeloader
Agent_tesla
Cloudeye
Formbook
Remcos_rat
Nanocore_rat
Beamwinhttp_loader
Garbage_cleaner
Clipboard_grabbing_technique

Industry:
Transport

Geo:
Korea

IOCs:
File: 15
Domain: 10
IP: 3
Email: 5
Url: 20

Softs:
discord, nsis installer

Languages:
visual_basic, php
#ParsedReport
25-10-2022

. Analysis of the attack activity of the remote control Trojan by forging the Chinese version of the Telegram website

https://www.antiy.cn/research/notice&report/research_report/20221024.html

Threats:
Gh0st_rat
Process_injection_technique

Geo:
Chinese

TTPs:
Tactics: 4
Technics: 0

IOCs:
File: 16
Domain: 14
Hash: 6

Softs:
telegram, windows defender, windows installer

Win API:
MessageBox

Platforms:
x86, intel
#ParsedReport
25-10-2022

LV Ransomware Exploits ProxyShell in Attack on a Jordan-based Company. Overview

https://www.trendmicro.com/en_us/research/22/j/lv-ransomware-exploits-proxyshell-in-attack.html

Threats:
Lv_ransomware
Proxyshell_vuln
Revil
Proxylogon_exploit
Mimikatz_tool
Netscan_tool
Systembc
Ransom.win32.lvran.ymcikt
Trojan.bat.lvran.ymcil
Ransom.win32.lvran.ymcik
Trojan.win32.lvran.ymcil
Trojan.win32.frs.vsnw0ci22
Trojan.win32.frs.vsnw04j22

Industry:
Government

Geo:
German, Jordan

CVEs:
CVE-2021-34473 [Vulners]
Vulners: Score: 10.0, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 9.1
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2013, 2019, 2016, 2016, 2019)

CVE-2021-27065 [Vulners]
Vulners: Score: 6.8, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2013, 2016, 2016, 2016, 2016, 2013, 2016, 2019, 2013, 2016, 2016, 2016, 2016, 2016, 2016, 2016, 2019, 2019, 2019, 2019, 2019, 2019, 2019)

CVE-2021-31207 [Vulners]
Vulners: Score: 6.5, CVSS: 1.7,
Vulners: Exploitation: True
X-Force: Risk: 6.6
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2013, 2019, 2016, 2016, 2019)

CVE-2021-26855 [Vulners]
Vulners: Score: 7.5, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 9.1
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2016, 2016, 2013, 2016, 2016, 2013, 2016, 2019, 2013, 2016, 2016, 2016, 2016, 2016, 2016, 2016, 2019, 2019, 2019, 2019, 2019, 2019, 2019, 2019)

CVE-2021-34523 [Vulners]
Vulners: Score: 7.5, CVSS: 3.4,
Vulners: Exploitation: True
X-Force: Risk: 9
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2013, 2019, 2016, 2016, 2019)


IOCs:
IP: 8
File: 3
Hash: 13

Softs:
microsoft exchange

Algorithms:
rc4
#ParsedReport
25-10-2022

The Anatomy of Wiper Malware, Part 4: Less Common Helper Techniques

https://www.crowdstrike.com/blog/the-anatomy-of-wiper-malware-part-4

Actors/Campaigns:
Agrius

Threats:
Meteor_wiper
Hermeticwiper
Isaacwiper
Killdisk
Doublezero
Apostle
Sierras
Stonedrill_wiper
Petya
Ordinypt
Disttrack
Whispergate
Israbye
Zerocleare_wiper
Dustman_wiper

Geo:
Tokyo, Ukraine

TTPs:
Tactics: 1
Technics: 0

IOCs:
File: 4
Path: 5
Command: 22
Registry: 1
Hash: 39

Softs:
bcdedit, active directory

Functions:
OpenSCManager, OpenService, InitiateSystemShutdownEx

Win API:
ControlService, GetDiskFreeSpaceExW, DsRoleGetPrimaryDomainInformation, NetUnjoinDomain, ExitWindowsEx, NtRaiseHardError, Sleep
#ParsedReport
25-10-2022

From RM3 to LDR4: URSNIF Leaves Banking Fraud Behind

https://www.mandiant.com/resources/blog/rm3-ldr4-ursnif-banking-fraud

Actors/Campaigns:
Shathak

Threats:
Gozi
Cutwail
Hancitor
Serpent
Beacon
Trickbot
Emotet
Icedid
Carberp

Industry:
Financial, Telco

Geo:
Russia, Italy, Oceania

TTPs:
Tactics: 1
Technics: 0

IOCs:
File: 11
Path: 1
Registry: 1
Domain: 28
Hash: 28
IP: 31

Softs:
internet explorer, microsoft word, chrome

Algorithms:
aes-256, cbc, aes, crc-32, xor, prng, base64

Win API:
DllRegisterServer, QueueUserAPC

Platforms:
x86, x64

YARA: Found
#ParsedReport
25-10-2022

Dual Malware Infection Targets Cryptocurrency Users

https://blog.cyble.com/2022/10/25/dual-malware-infection-targets-cryptocurrency-users

Threats:
Tron
Process_injection_technique

Industry:
Energy, Financial

Geo:
Singapore, Dubai, Australia, America, India, Georgia

TTPs:
Tactics: 6
Technics: 15

IOCs:
File: 6
Path: 3
Command: 4
Url: 2
Domain: 1
Coin: 7
Hash: 3

Softs:
windows defender, task scheduler, zcash

Algorithms:
base64

Functions:
GetClipBoardData, OpenClipBoard, EmptyClipBoard, SetClipBoard

Win API:
BitBlt, CopyFileA

Languages:
visual_basic
Twitter:
864 твитта с индикаторами за сутки (медиана)
871 уникальных индикатора за сутки (ip, domain, url, hash)
Если смотреть по всем источникам с начала 2022 года, то уникальных:
ip: 1,3М
domain: 943K
url: 828K
hash: 1,2K
Это уже после очистки, расчета скоринга и прибивания тех, у кого score = 0.
#ParsedReport
27-10-2022

CoinMiner Being Installed on Vulnerable Apache Tomcat Web Server

https://asec.ahnlab.com/en/40673

Threats:
Meterpreter_tool
Xmrig_miner
Dropper/win.miner.c5283988
Trojan/vbs.runner.sc184041

Industry:
Healthcare

Geo:
Korean

IOCs:
File: 5
Url: 5
Domain: 1
Coin: 1
Hash: 7

Softs:
task scheduler

Algorithms:
base64