Signed Executable Potentially Related to TrickBot and Lazarus Group Activity
released on 2019-12-17 @ 08:52:41 PM
The malware is possibly related to TrickBot Group and Lazarus Group activity recently reported by Vitali Kremez. The executable is a Sectigo-signed ApacheBench binary template for meterpreter, which is signed by BlueMarble GmbH. The sample establishes a reverse HTTPS connection to the C2 91.121.89[.]129. Recently discovered samples include the following Sectigo-signers LIT-DAN UKIS UAB, PAMMA DE d.o.o., and VITA-DE d.o.o.