Decrypting the #SolarMarker payload with #Malcat
Go to PS1 -> Select Base64 of payload -> Decode Base64 and open in new file -> use AES Key and IV from the PowerShell to decrypt. -> Click to see contents of GZipped file. Done.
Confirmed as SolarMarker on MalwareBazaar.
Using @HuntressLabs MDR for Microsoft 365 makes defensive work easy af ✉️🛡️
Telemetry proved user usually authenticated from Texas 🇺🇸
Yet, we'd seen anomalous authentications from 🇬🇭 and 🇺🇦
So, we temporarily disabled the account and issued the partner a report 💪
Case from @HuntressLabs worked with @phish_y
w3wp.exe launches some suspicious commands along with the executable "Zero.ux.tmp" then creates a new account "Windows" and adds it the local admin as well as opening up RDP
🧵1/2
More #OneNote#Qakbot blowing up @HuntressLabs EDR
https://t.co/ke06N0u852 -->> `O P E N .wsf` via Wscript
Stores encoded Pwsh in HKCU\SOFTWARE\, subkeys `arsenatesHousing` & `Underweft`
Adds drive exclusion to Defender
143.198.63[.]241 for DLL
rundll32 Upcurled.dll, RS32
My teammmate @xorJosh searched the wallet address:
47bYnmg3z3A9UChkAg2odbLF7qn5AWXRohwaZdYa8QSfdCtvy3c2Dme8CwzpjiihoA6hfg4TL1EVyGda3sKq7taz2u4NvLU
First payment 719 Days Ago
Last payment 22 Hrs Ago
Total Xmr Paid 5.10870709