@krutonium@social.treehouse.systems
2026-09-21 20:18 UTC
@unnick@booping.synth.download @5225225@furry.engineer
Okay so!
Yes, Malware.
It's a classic Dropper.
It sets up in %LOCALAPPDATA%\java
Downloads the URL https://dev7.devmicro7.workers.dev - MALWARE - /zips/ffe1daf85c721574.zip
Extracts the zip to that first folder and deletes it
Checks for %LOCALAPPDATA%\java\java\bin\javaw.exe and %LOCALAPPDATA%\java\services.jar
If it finds both, it executes it via cmd - cmd.exe /c start "" "java\bin\javaw.exe" -jar "services.jar"
I'm taking apart the stage 2 now as well.
Replies (1)
-
@krutonium@social.treehouse.systems 2026-09-21 20:24
@unnick@booping.synth.download @5225225@furry.engineer This looks like it's copying all your browser cookies and session files to an sqlite db and sending it to an attacker, I think? But yeah if this is someone you know, contact them some other way and tell them they need to 1. Clean this up but 2. and more importantly, change every password they have from a different machine.