Elektrine lite

← Feed

@krutonium@social.treehouse.systems

2026-09-21 20:13 UTC

@unnick@booping.synth.download Do me a favor and see if you can report https://dev7.devmicro7.workers.dev/ to their host for hosting malware. @5225225@furry.engineer Maybe different infra in use? But yeah same idea.

Replies (1)

  • @unnick@booping.synth.download @5225225@furry.engineer Okay so! Yes, Malware. It's a classic Dropper. It sets up in %LOCALAPPDATA%\java Downloads the URL https://dev7.devmicro7.workers.dev - MALWARE - /zips/ffe1daf85c721574.zip Extracts the zip to that first folder and deletes it Checks for %LOCALAPPDATA%\java\java\bin\javaw.exe and %LOCALAPPDATA%\java\services.jar If it finds both, it executes it via cmd - cmd.exe /c start "" "java\bin\javaw.exe" -jar "services.jar" I'm taking apart the stage 2 now as well.

    Open ##4797208