Brad · @malware_traffic
1961 followers · 67 posts · Server infosec.exchange

2022-12-29 (Thursday) - Getting ready to shut down for the evening, and I wanted to try one more time.

This time I set up my Windows lab computer as a Brazil host with Portuguese language.

I saw aanother Google ad, this time to a fake AnyDesk page at computer-remote[.]site.

This time the malware was an variant (/#OkiStealer/#MarsStealer/whatever its morphed into now).

Download link: hxxps://computer-remote[.]site/download.php

Download link redirects to aip file hosted on Dropbox at: hxxps://dl.dropboxusercontent[.]com/s/hpkf0my15vts98l/SetupMain.zip?dl=0

Couldn't get the full zip uploaded to Malware Bazaar, because it was too big. Got it sent to VirusTotal, though.

- virustotal.com/gui/file/501830

51.8 MB zip download, containing a bunch of crap and a 624 MB Windows EXE file.

I carved the extracted EXE to remove the padding, and the carved sample is available at: bazaar.abuse.ch/sample/2e25487

Analysis of the carved EXE:

- tria.ge/221230-fk3mgaa
- app.any.run/tasks/80236e10-611

Even though my host was set up for Brazil Portuguese, the fake AnyDesk page and downloaded malware were in English.

#arkeistealer #vidar

Last updated 2 years ago