CTT Report Hub
3.21K subscribers
7.88K photos
6 videos
67 files
11.6K links
Threat Intelligence Report Hub
https://cyberthreat.tech
ООО Технологии киберугроз
Contact: @nikolaiav
Download Telegram
#ParsedReport
14-11-2022

Koxic. KOXIC ransomware domestic distribution

https://asec.ahnlab.com/ko/41837

Threats:
Koxic
Revil
Upx_tool
Ransomware/win.koxiccrypt.r533926
Deathransom
Trojan/win.generic.c4963639
Ransom/mdp.delete.m2117
Malware/mdp.behavior.m2771
Ransom/mdp.decoy.m4475

Geo:
Korea

IOCs:
File: 31
Registry: 4
Command: 3
Hash: 3

Softs:
mysql

Algorithms:
aes, cbc

Functions:
CreateFileMappingW

Win API:
SeBackupPrivilege, SeRestorePrivilege, SeManageVolumePrivilege, SeTakeOwnershipPrivilege, MoveFileExW, reateFileMappingW, ViewOfFile

Win Services:
SQLWriter, MSSQLServerOLAPService, MSSQLSERVER, MSSQL$SQLEXPRESS, ReportServer

Platforms:
intel
#ParsedReport
14-11-2022

Kitten.gif: Meet the Sabbath Ransomware Affiliate Program, Again

https://www.mandiant.com/resources/blog/sabbath-ransomware-affiliate

Actors/Campaigns:
Unc2190 (motivation: information_theft)

Threats:
Cobalt_strike
Beacon
Rollcoast
Themida_tool
Redrum
Process_injection_technique

Industry:
Government, Financial, Education, Healthcare

Geo:
Armenia, Germany, Slovakia, Russian, Belarus, Kyrgyzstan, Ukraine, Kenya, Africa, Ukrainian, India, Malta, Indonesian, Malaysia, Albania, Azerbaijan, Croatia, Canada, Belarusian, Latvia, Norway, Pakistan, Macedonia, Uzbekistan, Iran, Thailand, Kazakhstan, Estonia, Tajikistan, Turkey, Vietnam, Indonesia, Georgia, Azerbaijani, Turkish, Turkmenistan, Lithuania, Russia, Slovenia, Sweden, Vietnamese

TTPs:
Tactics: 7
Technics: 17

IOCs:
File: 1
Url: 2
IP: 6
Hash: 20

Algorithms:
aes

Languages:
java

Platforms:
x64

YARA: Found
#ParsedReport
14-11-2022

XDSpy APT. XDSPY APT organization recently analyzed the attack activity of the Russian Ministry of Defense

https://mp.weixin.qq.com/s/cW2Evf6Nqb3fhQ7ntnKHsA

Threats:
Xdspy

Industry:
Government

Geo:
Belarusian, Russian

TTPs:
Tactics: 1
Technics: 0

IOCs:
File: 1
Path: 2
Hash: 14
Url: 7

Softs:
internet explorer

Algorithms:
rc4, base64

Functions:
InternetExplorer

Win API:
WaitForSingleObject

Platforms:
x86
#ParsedReport
14-11-2022

Sysdig TRT uncovers massive cryptomining operation leveraging GitHub Actions

https://sysdig.com/blog/massive-cryptomining-operation-github-actions

Actors/Campaigns:
Purpleurchin
Oceanlotus (motivation: cyber_espionage)
Teamtnt

Threats:
Xmrig_miner
Onyx

Industry:
Financial

TTPs:
Tactics: 2
Technics: 0

IOCs:
Coin: 2
File: 4
IP: 6
Hash: 1

Softs:
docker, ubuntu, curl, "docker, mysql

Functions:
OpenVPN

Languages:
python, php

Links:
https://github.com/newtondev/no-dev-fee-stratum-proxy
https://github.com/jordansissel/xdotool
https://github.com/pricing
#ParsedReport
14-11-2022

Typhon Reborn With New Capabilities

https://unit42.paloaltonetworks.com/typhon-reborn-stealer

Threats:
Typhon_reborn
Typhon_stealer

IOCs:
File: 4
Hash: 2

Softs:
telegram, google chrome, microsoft edge, chrome, coin98

Functions:
MeltSelf
#ParsedReport
15-11-2022

DTrack activity targeting Europe and Latin America

https://securelist.com/dtrack-targeting-europe-latin-america/107798

Actors/Campaigns:
Lazarus (motivation: financially_motivated)

Threats:
Dtrack_rat
Process_hollowing_technique

Industry:
Telco, Education, Chemical, Financial

Geo:
Switzerland, Italy, Brazil, Turkey, Mexico, America, India, Germany

IOCs:
File: 1
Domain: 4
Hash: 2

Algorithms:
rc4
#ParsedReport
15-11-2022

ASEC (20221107 \~ 20221113). ASEC Weekly Malware Statistics (20221107 \~ 20221113)

https://asec.ahnlab.com/ko/41981

Actors/Campaigns:
Ta505

Threats:
Emotet
Qakbot
Trickbot
Agent_tesla
Azorult
Smokeloader
Smokerloader
Amadey
Lockbit
Gandcrab
Clop
Cloudeye
Postealer
Formbook
Remcos_rat
Nanocore_rat

Industry:
Financial, Transport

Geo:
Korea

IOCs:
File: 23
Url: 8
Email: 5
Domain: 7

Softs:
discord, nsis installer

Algorithms:
zip

Languages:
visual_basic
#ParsedReport
15-11-2022

Exploring Modifications in New Mirai Botnet Clones

https://www.nozominetworks.com/blog/exploring-modifications-in-new-mirai-botnet-clones

Threats:
Mirai
Bashlite
Darknexus_botnet

Industry:
Iot

CVEs:
CVE-2017-17215 [Vulners]
Vulners: Score: 6.5, CVSS: 6.1,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Unavailable
Soft:
- huawei hg532 firmware (-)


Algorithms:
xor

Links:
http://1.%09https/github.com/jgamblin/Mirai-Source-Code/blob/master/mirai/bot/table.c#L16
#ParsedReport
15-11-2022

Phishing Campaign Targeting Indonesian BRI Bank Using SMS Stealer

https://blog.cyble.com/2022/11/15/phishing-campaign-targeting-indonesian-bri-bank-using-sms-stealer

Threats:
Sms_stealer
Smseye_stealer

Industry:
Financial

Geo:
Dubai, Georgia, Singapore, Australia, Indonesian, Indonesia, India

TTPs:
Tactics: 6
Technics: 7

IOCs:
Url: 15
Hash: 4
File: 1

Softs:
android, telegram

Languages:
php, kotlin

Links:
https://github.com/AbyssalArmy/SmsEye
#ParsedReport
15-11-2022

Billbug: State-sponsored Actor Targets Cert Authority, Government Agencies in Multiple Asian Countries

https://symantec-enterprise-blogs.security.com/threat-intelligence/espionage-asia-governments-cert-authority

Actors/Campaigns:
Dragonfish (motivation: information_theft, cyber_espionage)

Threats:
Hannotog
Sagerunex
Adfind_tool
Nbtscan_tool
Stowaway_tool
Cobalt_strike

Industry:
Government

Geo:
Asia, Asian

IOCs:
File: 5
Command: 2
Hash: 23

Softs:
active directory

Algorithms:
xor, aes-256-cbc, zip, rc4

Win API:
WinHttpGetIEProxyConfigForCurrentUser
#ParsedReport
16-11-2022

DAGON LOCKER Ransomware Being Distributed

https://asec.ahnlab.com/en/42037

Threats:
Dagon_locker
Quantum_locker
Mount_locker
Ransom/mdp.behavior.m1171
Ransom/mdp.behavior.m1946

Geo:
Korean, Korea

IOCs:
Hash: 2
File: 3

Algorithms:
rsa-2048, chacha20

Win API:
GetCommandLineW, GetDriveTypeW, CryptImportKey, CryptEncrypt

Win Services:
agntsvc

Platforms:
x64
#ParsedReport
16-11-2022

ASEC Weekly Malware Statistics (November 7th, 2022 November 13th, 2022)

https://asec.ahnlab.com/en/42068

Threats:
Emotet
Qakbot
Trickbot
Icedid
Agent_tesla
Smokeloader
Amadey
Lockbit
Cloudeye
Formbook
Remcos_rat
Nanocore_rat

Industry:
Financial

Geo:
Korea

IOCs:
Url: 8
Email: 5
File: 11
Domain: 7

Softs:
discord, nsis installer

Languages:
visual_basic
#ParsedReport
16-11-2022

A Comprehensive Look at Emotets Fall 2022 Return

https://www.proofpoint.com/us/blog/threat-insight/comprehensive-look-emotets-fall-2022-return

Actors/Campaigns:
Mummyspider

Threats:
Emotet
Icedid
Bumblebee
Xmrig_miner
Xmr_miner
Cobalt_strike
Qakbot

Geo:
Spanish, Greece, Spain, Italy, Mexico, French, Germany, Portuguese, Japan, Brazil, Japanese, France, German, Italian

IOCs:
File: 2
Hash: 2
Domain: 1

Softs:
microsoft office

Algorithms:
zip, xor

Functions:
CreateTimerQueueEx
#ParsedReport
16-11-2022

New RapperBot Campaign We Know What You Bruting for this Time

https://www.fortinet.com/blog/threat-research/new-rapperbot-campaign-ddos-attacks

Threats:
Rapperbot
Mirai
Tcpsynflood_technique
Tcpackflood_technique
Tcpstomp_technique
Satori
Bashlite
Hostile

Industry:
Iot

IOCs:
File: 1
Hash: 7
Url: 16
IP: 1

Softs:
curl

Platforms:
arm, mips, intel
#ParsedReport
16-11-2022

BATLOADER: The Evasive Downloader Malware. Executive Summary

https://blogs.vmware.com/security/2022/11/batloader-the-evasive-downloader-malware.html

Threats:
Batloader
Nikki
Conti
Log4shell_vuln
Atera_tool
Z_loader
Zeus
Teamviewer_tool
Nsudo_tool
Syncro_tool
Gozi
Arkei_stealer
Vidar_stealer
Cobalt_strike

Industry:
Financial

CVEs:
CVE-2013-3900 [Vulners]
Vulners: Score: 7.6, CVSS: 4.5,
Vulners: Exploitation: True
X-Force: Risk: 9.3
X-Force: Patch: Official fix
Soft:
- microsoft windows xp (-, -)
- microsoft windows server 2008 (r2, -)
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 21h2, 20h2, 21h1, 1909, 1809)
- microsoft windows 8.1 (-)
have more...
CVE-2020-1599 [Vulners]
Vulners: Score: 2.1, CVSS: 1.9,
Vulners: Exploitation: True
X-Force: Risk: 5.5
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (-, 20h2, 1607, 1803, 1809, 1903, 1909, 2004)
- microsoft windows 7 (-)
- microsoft windows 8.1 (-)
- microsoft windows rt 8.1 (-)
- microsoft windows server 2008 (-, r2)
have more...

TTPs:
Tactics: 1
Technics: 0

IOCs:
Url: 1
IP: 1
Domain: 4
File: 4
Hash: 72
Path: 8
Command: 1

Softs:
windows installer, zoom, discord, windows defender, ide bcded,

Platforms:
x86