home.social

#solarmarker — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #solarmarker, aggregated by home.social.

fetched live
  1. It is common for malware to be signed with code signing certificates.

    How is this possible? Impostors receive the cert directly and sign malware.

    In this blog-post, we look at 100 certs used by #Solarmarker malware to learn more.

    squiblydoo.blog/2024/05/13/imp

  2. eSentire described two incidents today:

    Attack chains, IOC and Yara rules provided.

    #threatintel #IOC #Xworm #phishing #SolarMarker #PyInstaller

  3. eSentire described two incidents today:

    Attack chains, IOC and Yara rules provided.

    #threatintel #IOC #Xworm #phishing #SolarMarker #PyInstaller

  4. Technical Analysis of DarkVNC

    DarkVNC is a hidden utility based on VNC technology, used for stealthy remote access. It was advertised in 2016 and received updates until 2017. DarkVNC has been used by threat actors associated with IcedID and SolarMarker campaigns. This analysis focuses on a DarkVNC sample that uses 'vncdll64.dll' for exporting functions. It generates a unique ID to send to the C2 server along with system info. DarkVNC can search for and manipulate windows related to the desktop environment. It can also control the state of devices like keyboard and mouse, and block user input. The malware gathers details on the Chrome browser install and runs cmd prompts. Detection and prevention controls like EDR solutions and training programs are recommended.

    Pulse ID: 65d348c6927ea8aae1bee945
    Pulse Link: otx.alienvault.com/pulse/65d34
    Pulse Author: AlienVault
    Created: 2024-02-19 12:25:42

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #OTX #OpenThreatExchange #InfoSec #bot #CyberSecurity #Malware #Windows #VNC #RAT #Browser #Chrome #IcedID #SolarMarker #EDR #AlienVault

  5. Low Detection #SolarMarker #Infostealer
    #EV #SIGNED LAABAI LTD

    This signing name was abused previously by SolarMarker, except it was under a different certificate provider. Most likely the impostor that registered it registered the same name with multiple certificate providers. (See my blog post on this type of behavior if it sounds unfamiliar to you: squiblydoo.blog/2023/05/12/cer)

    C2: 146.70.40.228
    C2: 212.237.217.133

    VT: virustotal.com/gui/file/a01144

    MB: bazaar.abuse.ch/sample/fd83469

    Backdoor: bazaar.abuse.ch/sample/b44f87a

  6. Dug into the #solarmarker #infostealer the past two months and built out this infograph describing the attack chain. Major credit is due to @th3_protoCOL for Intel on this, and definitely read up on squibblydoo's blog post on the malware family as they describe the attack chain fantastically.
    squiblydoo.blog/2022/09/27/sol