Malware Analysis Capcut fake stealer

Status
Not open for further replies.
"RabbitCheecks.exe" stole data with no reaction from Bitdefender TS.
View attachment 277219
The other one "TBMSetup" had no reaction from BD either, but don't know if it stole. The first one don't delete remnants from temp but the second one deletes everything I think and I wasn't quick enough to see it.

BTS just updated its threat engine to v7.94981. Can you check whether it still detects?
 
Last edited:
  • Like
Reactions: Trident
Last edited by a moderator:
#stealer

This one is a Ransomware. Detected by MD and ESET's LiveGuard. If LiveGuard is not available, then it can't detect or stop encryption. But now it's known to ESET cloud due to the LiveGuard's verdict so will be detected on all ESET systems.
 
Some hours ago, I just decided to re-analyze (longer runtime, etc.) on Hybrid:
The analysis extracted a known ransomware file
Source: https://www.hybrid-analysis.com/sam...d843e9c4d3a0a57ee046/64b782a0587dc92c0202b299

I would try to test this sample in VMware 17 Pro against Bitdefender Free. If still undetected on static... I will add details and screenshots later ;)

At the time of my test, BD has no signatures, static: 0/1 - dynamic: 1*/1

Sample immediately blocked without removal this time 🤷‍♂️ I tried to execute this sample again for several times but keep blocked only even after 10 minutes. No files encrypted!

new#1.png
 
Last edited:
Some hours ago, I just decided to re-analyze (longer runtime, etc.) on Hybrid:

Source: https://www.hybrid-analysis.com/sam...d843e9c4d3a0a57ee046/64b782a0587dc92c0202b299

I would try to test this sample in VMware 17 Pro against Bitdefender Free. If still undetected on static... I will add details and screenshots later ;)

At the time of my test, BD has no signatures, static: 0/1 - dynamic: 1*/1

Sample immediately blocked without removal this time 🤷‍♂️ I tried to execute this sample again for several times but keep blocked only even after 10 minutes. No files encrypted!

View attachment 277301
I had the same behavior on BDTS. Blocked but not removed :unsure:
What has it encrypted?
Image files, doc files, zip files, etc.
 
Update for my test with Bitdefender Free: VM was in suspended mode, I tried to check again, finally BD removed this sample to quarantine, detection named: Trojan.GenericKD...

q#1.png

Note: This will be my last post for testing samples, we all have to respect the new rules:
 
Status
Not open for further replies.