Malware Analysis Capcut fake stealer

Status
Not open for further replies.
Kaspersky is too good. Another fake game stealer using the same method(app.asar). Downloaded from itch.io, it's actually on the "New & Popular" page. On VT, Kaspersky caught it again :D



-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------

Another one, Avast Miss:
View attachment 277174View attachment 277175



-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------

Quasar, caught by Avast(powershell):
View attachment 277176




@SeriousHoax @silversurfer

Kaspersky : 3/3
DeepInstinct : 2/3 ( the discord Trojan passed without reaction, one was recognized by the AI and another was blocked from behaving)
F-Secure : 1/3

Capture d’écran 2023-07-15 123404.png


Exploit PowerShell blocked (Medieval Cracked.exe)
Capture d’écran 2023-07-15 123444.png

Capture d’écran 2023-07-15 123517.png

SUD to Avira
 
itch.io is a mess. seems easier to get infected there than on a piracy site. on the new & popular page there are currently two "games" that are the epsilon stealer. I reported the page(which hosts TBMSetup) to itch.io yesterday, but it still seems to be up.


-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
1."RabbitCheecks":

2.PNG

-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------

2."TBMSetup" (this is the sample from yesterday, not taken down by itch.io):

1.PNG
 
Last edited:
itch.io is a mess. seems easier to get infected there than on a piracy site. on the new & popular page there are currently two "games" that are the epsilon stealer. I reported the page(which hosts TBMSetup) to itch.io yesterday, but it still seems to be up.


-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
1."RabbitCheecks":

View attachment 277216

-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------

2."TBMSetup" (this is the sample from yesterday, not taken down by itch.io):

View attachment 277215
Both detected by Harmony and Kaspersky PDM
 
How are the policies configured?
Anti-Bot configured on hold:
Anti-malware: disabled size limit and disabled skip scanning of archives and non-executables.
URL filtering: enabled for all apps
Scripts scanning in web pages enabled
All detections configured on “prevent” (low-confidence as well).
Experimental Machine Learning Models: not enabled
Early Availability: not enrolled
Firewall: Disabled blocking of IPV6 traffic; enabled Hotspot usage; Remote Desktop Security on standard; Disabled Truted Zone; Disabled logging of cleanup rule
Application Control:
App Scan performed on C:/
Rules configured by folder to terminate the following completely:
  • Cmd
  • PowerShell
  • Conhost
  • Openconsole
  • Wscript
  • Cscript
Disabled internet connectivity for majority of the LOLBins here: LOLBAS
 
1."RabbitCheecks":
-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------

2."TBMSetup"
2023-07-16_11-05-20.png


2023-07-16_11-00-53.png


:rolleyes:
 
itch.io is a mess. seems easier to get infected there than on a piracy site. on the new & popular page there are currently two "games" that are the epsilon stealer. I reported the page(which hosts TBMSetup) to itch.io yesterday, but it still seems to be up.


-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
1."RabbitCheecks":

View attachment 277216

-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------

2."TBMSetup" (this is the sample from yesterday, not taken down by itch.io):

View attachment 277215

Kaspersky :
1) detected UDS:Trojan-PWS.Win32.Disco
2) detected PDM:Trojan.Win32.Generic
 
"RabbitCheecks.exe" stole data with no reaction from Bitdefender TS.
bd1.png
The other one "TBMSetup" had no reaction from BD either, but don't know if it stole. The first one don't delete remnants from temp but the second one deletes everything I think and I wasn't quick enough to see it.
 
Last edited:
According to Kaspersky, it's another Discord's password stealer
Yeah, same thing. It's not needed to test this one. I just shared here to show that there are so many of these spreading around. AV vendors need to find a way to detect this. Looks like most of them aren't even aware of these stealers.
 
Status
Not open for further replies.