Malware News Sweet Minecraft Mods – The Dark Tale of SugarSMP Scam, Malware & Extortion

Khushal

Level 15
Thread author
Verified
Top Poster
Well-known
Apr 4, 2024
722
4,526
1,369
related earlier MalwareTips post

Gdata expert and his allies have an interesting blogpost for all of us.
IoCs contain FUD VT files or only one detection which is shocking.


@TuxTalk will be proud of Gdata's research. Thanks @rifteyy for his contribution.

 
Kaspersky strikes again.
 

Attachments

  • Capture.JPG
    Capture.JPG
    90.6 KB · Views: 74
I found these notable:
  1. The sugarsmp[.]com website is only one month old. I hope I won't want something bad enough to risk working with such a site.
  2. Apparently, the download file was changed back to a non-malware mod; a tactic we also saw with the 7-Zip manager's malware sites (which actually had aged long-registration domains; were they hacked?).
  3. They used a hacked reputable mod developer's Reddit account to convince the moderators to take down malware warnings. Oops, social engineering works everywhere.
 
It's even down

PING sugarsmp.com(2606:4700:3035::ac43:cbd0 (2606:4700:3035::ac43:cbd0)) 56 data bytes
64 bytes from 2606:4700:3035::ac43:cbd0 (2606:4700:3035::ac43:cbd0): icmp_seq=1 ttl=55 time=2.30 ms
64 bytes from 2606:4700:3035::ac43:cbd0 (2606:4700:3035::ac43:cbd0): icmp_seq=2 ttl=55 time=2.40 ms
64 bytes from 2606:4700:3035::ac43:cbd0 (2606:4700:3035::ac43:cbd0): icmp_seq=3 ttl=55 time=2.49 ms

--- sugarsmp.com ping statistics ---
3 packets transmitted, 3 received, 0% packet loss, time 2003ms
rtt min/avg/max/mdev = 2.301/2.394/2.486/0.075 ms

1000014516.png
 
PING sugarsmp.com(2606:4700:3035::ac43:cbd0 (2606:4700:3035::ac43:cbd0)) 56 data bytes
64 bytes from 2606:4700:3035::ac43:cbd0 (2606:4700:3035::ac43:cbd0): icmp_seq=1 ttl=55 time=2.30 ms
64 bytes from 2606:4700:3035::ac43:cbd0 (2606:4700:3035::ac43:cbd0): icmp_seq=2 ttl=55 time=2.40 ms
64 bytes from 2606:4700:3035::ac43:cbd0 (2606:4700:3035::ac43:cbd0): icmp_seq=3 ttl=55 time=2.49 ms

--- sugarsmp.com ping statistics ---
3 packets transmitted, 3 received, 0% packet loss, time 2003ms
rtt min/avg/max/mdev = 2.301/2.394/2.486/0.075 ms

View attachment 296381
Agree, not down, just blocked?