TF-MAL-jar.verblecon
📛 Threat Title
Malware family: Verblecon
Description
ThreatFox malware family `jar.verblecon`. Printable name: Verblecon.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
jar.verblecon
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/jar.verblecon
IOC database
- Type
- domain
- Value
jar.verblecon- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-jar.verblecon
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/jar.verblecon
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:advisory.eventussecurity.com
Unknown attacker may not be aware of the potential capabilities of the malware they are utilising because they are using a sophisticated and strong new malware loader in very simple and low-reward attacks. The Trojan. Verblecon malware is being utilised in attacks that seem to have as their ultimate objective the installation of bitcoin miners on compromised machines. There are also hints that ...
-
web:malpedia.caad.fkie.fraunhofer.de
This malware seems to be used for attacks installing cryptocurrency miners on infected machines. Other indicators leads to the assumption that attackers may also use this malware for other purposes (e.g. stealing access tokens for Discord chat app). Symantec describes this malware as complex and powerful: The malware is loaded as a server-side polymorphic JAR file.
-
web:malwaretips.com
Security researchers are warning of a relatively new malware loader, that they track as Verblecon , which is sufficiently complex and powerful for ransomware and espionage attacks, although it is currently used for low-reward attacks. Verblecon was spotted earlier this year and the known samples...
-
web:support.trellix.com
The malware , known as Verblecon , was discovered in early 2022 and is loaded as a server-side polymorphic JAR file. The malware performs a range of anti-analysis tasks by checking directories and files, the machine's MAC address, running processes, and registry entries for signs of virtual or sandbox environments.
-
web:www.bleepingcomputer.com
Security researchers are warning of a relatively new malware loader, that they track as Verblecon , which is sufficiently complex and powerful for ransomware and espionage attacks, although it is ...
-
web:www.breachsense.com
Complete malware remediation now requires addressing both the infected endpoint and the stolen authentication data. Your malware incident response playbook must account for both.
-
web:www.broadcom.com
New malware dubbed Verblecon has been used in recently discovered attacks distributing cryptocurrency mining software onto the infected machines. There have also been some indications that the attackers may be stealing Discord tokens and using these to advertise trojanized videogame applications.
-
web:www.cyclonis.com
The Verblecon Malware is designed to load other malicious payload onto the infected device, while managing to bypass various security measures and feature. The criminals are using the Verblecon Malware in combination with a wide range of threats, such as cryptocurrency miners or even ransomware. The first samples of the Verblecon Malware can be traced back to the start of 2022, so it seems ...
-
web:www.pcrisk.com
What is Verblecon ? STEP 1. Manual removal of Verblecon malware . STEP 2. Check if your computer is clean. How to remove malware manually? Manual malware removal is a complicated task - usually it is best to allow antivirus or anti- malware programs to do this automatically. To remove this malware we recommend using Combo Cleaner Antivirus for ...
-
web:www.security.com
The malware , Trojan. Verblecon , is being used in attacks that appear to have installing cryptocurrency miners on infected machines as their end goal. There are some indications the attacker may also be interested in stealing access tokens for chat app Discord.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.