s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-jar.verblecon

📛 Threat Title

Malware family: Verblecon

Category: Verblecon First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `jar.verblecon`. Printable name: Verblecon.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain jar.verblecon VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/jar.verblecon

IOC database

Type
domain
Value
jar.verblecon
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-jar.verblecon

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/jar.verblecon

References (1)

Remediations (10)

  • web:advisory.eventussecurity.com

    Unknown attacker may not be aware of the potential capabilities of the malware they are utilising because they are using a sophisticated and strong new malware loader in very simple and low-reward attacks. The Trojan. Verblecon malware is being utilised in attacks that seem to have as their ultimate objective the installation of bitcoin miners on compromised machines. There are also hints that ...

  • web:malpedia.caad.fkie.fraunhofer.de

    This malware seems to be used for attacks installing cryptocurrency miners on infected machines. Other indicators leads to the assumption that attackers may also use this malware for other purposes (e.g. stealing access tokens for Discord chat app). Symantec describes this malware as complex and powerful: The malware is loaded as a server-side polymorphic JAR file.

  • web:malwaretips.com

    Security researchers are warning of a relatively new malware loader, that they track as Verblecon , which is sufficiently complex and powerful for ransomware and espionage attacks, although it is currently used for low-reward attacks. Verblecon was spotted earlier this year and the known samples...

  • web:support.trellix.com

    The malware , known as Verblecon , was discovered in early 2022 and is loaded as a server-side polymorphic JAR file. The malware performs a range of anti-analysis tasks by checking directories and files, the machine's MAC address, running processes, and registry entries for signs of virtual or sandbox environments.

  • web:www.bleepingcomputer.com

    Security researchers are warning of a relatively new malware loader, that they track as Verblecon , which is sufficiently complex and powerful for ransomware and espionage attacks, although it is ...

  • web:www.breachsense.com

    Complete malware remediation now requires addressing both the infected endpoint and the stolen authentication data. Your malware incident response playbook must account for both.

  • web:www.broadcom.com

    New malware dubbed Verblecon has been used in recently discovered attacks distributing cryptocurrency mining software onto the infected machines. There have also been some indications that the attackers may be stealing Discord tokens and using these to advertise trojanized videogame applications.

  • web:www.cyclonis.com

    The Verblecon Malware is designed to load other malicious payload onto the infected device, while managing to bypass various security measures and feature. The criminals are using the Verblecon Malware in combination with a wide range of threats, such as cryptocurrency miners or even ransomware. The first samples of the Verblecon Malware can be traced back to the start of 2022, so it seems ...

  • web:www.pcrisk.com

    What is Verblecon ? STEP 1. Manual removal of Verblecon malware . STEP 2. Check if your computer is clean. How to remove malware manually? Manual malware removal is a complicated task - usually it is best to allow antivirus or anti- malware programs to do this automatically. To remove this malware we recommend using Combo Cleaner Antivirus for ...

  • web:www.security.com

    The malware , Trojan. Verblecon , is being used in attacks that appear to have installing cryptocurrency miners on infected machines as their end goal. There are some indications the attacker may also be interested in stealing access tokens for chat app Discord.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.