Elektrine lite

← Feed

@krutonium@social.treehouse.systems

2026-09-21 20:18 UTC

@unnick@booping.synth.download @5225225@furry.engineer Okay so! Yes, Malware. It's a classic Dropper. It sets up in %LOCALAPPDATA%\java Downloads the URL https://dev7.devmicro7.workers.dev - MALWARE - /zips/ffe1daf85c721574.zip Extracts the zip to that first folder and deletes it Checks for %LOCALAPPDATA%\java\java\bin\javaw.exe and %LOCALAPPDATA%\java\services.jar If it finds both, it executes it via cmd - cmd.exe /c start "" "java\bin\javaw.exe" -jar "services.jar" I'm taking apart the stage 2 now as well.

Replies (1)

  • @unnick@booping.synth.download @5225225@furry.engineer This looks like it's copying all your browser cookies and session files to an sqlite db and sending it to an attacker, I think? But yeah if this is someone you know, contact them some other way and tell them they need to 1. Clean this up but 2. and more importantly, change every password they have from a different machine.

    Open ##4797207