A WMI subscription named "Realtek" started a 12 KB backdoor at 19:50, and it never exited. It read its C2 domain by counting spaces in a fake desktop.ini, then called a domain its operator stopped paying for in July 2021.
It kept trying for 11 months.
Read more -> https://t.co/z7SSDdpWAq
Found some very common adware quietly killing antivirus products. Then we found an unregistered update domain, and anyone with $10 could have pushed any payload to 25,000+ endpoints, AV already disabled.
So we registered it first.
https://t.co/WMSaym7yOu
Big thanks to @_rdowd
Microsoft Defender researchers observed attackers using yet another evasion approach to the ClickFix technique: Asking targets to run a command that executes a custom DNS lookup and parses the `Name:` response to receive the next-stage payload for execution.
@curi0usJack Seems pretty decent to me. Requires active management tho. Muting all pol keywords and irrelevant mainstream garbage, etc. Engaging on quality sources to tune algo.
I get more actionable info from here than most of the 6 fig platforms out there.
@luke92881@s1dhy@SquiblydooBlog@andrewdanis@banthisguy9349@struppigel Seeing several associated files under same signer:
Uninstall.exe
7zipinstall.exe
7z.exe
7zG.exe
Also observed same wild network traffic.
Connections to hero-sms and smshero domains.
Anybody nail down the sms piece yet?
From 2020-2024, I tracked the SolarMarker malware, and in 2024, monitored a self-infection for months to learn their actions-on-objectives: on-device fraud.
I didn't publish the details of my months long investigation until now. Check the link the the attached comment.
@SquiblydooBlog@struppigel@InvokeReversing Similar activity from PDF themed apps turbofixpdf, effortlesspdf, and Manual Reader themed apps usermanualsonline, allmanualsreader, manualreaderpro, getmanualviewer, openmymanual. Node.exe launches malicious js files
Many using same api.(RandomNumCharString).com format C2 URLs
@DanLinnaeus I fail to see how this is indicative of any desire by the subject to associate with potentially questionable entities rather than simply evidence of PRC's widespread infiltration and influence across US society in general.