vx-underground

vx-underground

@vxunderground · Twitter ·

> be me > get email > "smelly, is this malware?" > "someone sent this to our offices at work" > "its trying to infect people at offices" > ok cool > get file > download > look inside > 23,000 line vbs file > lol ok > xor encoded each individual character > mildly annoying > bonk bonk > downloads file from enviamais-dot-store > downloads "destenticador".py > lol ok > download > look inside > obfuscated python > not very good obfuscation > downloads .zip file > "N3d5XpZbsd5juio".zip > extracts .zip > .zip contains .msi file > lol ok > download .zip, get .msi > look inside > all files inside installer stripped > f1, f2, f3, f4, f5, f6 > lol ok > check installer actions > f6 is "winsqre".exe > actually renamed autoit loader > lol ok > f6 (autoit) reads f4 (autoit scripts) > look at f4 > obfuscated autoit > takes a bunch of gunk to make another file > chunk1, chunk2, etc > add them together > another autoit file > ??? ok bro how far as we gonna go? > look inside at new file > autoit file scans machine for stuff > looks stuff > "FIBANK - Iniciar a sessão" > "InternetBankingCAIXA" > "GerenciadorCaixaGerenciadorFinanceiroCaixa" > idk what this means > if finds thingies, references other files inside msi > ??? were looking back to the .msi installer ??? > autoit script loads f1 > RtlDecompressFragment > o ok its a compressed .exe > decompress file > look inside > DELPHI FILE > look inside > delphi does stuff > delphi decrypts ANOTHER FILE and runs it > ANOTHER DELPHI FILE dude, what in the fuck is this shit? .vbs -> .zip -> .msi (files 1 - 6) .msi_file6 -> msi_file4 .msi_file4 -> autoitscript autoitscript -> .exe .exe -> msi_file5

Post media