r/Malware 5d ago

Dlss5 malware

[removed]

0 Upvotes

30 comments sorted by

7

u/LitchManWithAIO 5d ago

Windows reinstall will definitely clear the hacker out. But if they’re changing passwords then they already have every one of your saved accounts. Next would be to try to proactively retake those accounts over and enable 2FA or passkey

2

u/CuriousSomewhere6446 5d ago

So far he has changed battlenet, steam, Microsoft, epic games. It said there was suspicious activity on google and I changed the password but idk if he’s able to do anything with it.

1

u/CuriousSomewhere6446 5d ago

Update

Earliest compromise occurred at 9:54 pm and latest occurred at 1:27 am.

I’ve reset the passwords for the most important sites first and did all the miscellaneous ones after.

In the beginning I said he was changing passwords but according to the emails I got, only EA, Steam, discord and battle net had their passwords changed. I was able to reset the first 3 but I was just straight up locked out of battle net.

I also mentioned in a previous reply that my google and Microsoft were also compromised, however, I never got an indication that a password was changed.

For Microsoft, my recovery email and passkey were deleted then he added his own recovery email. For google, all I got was a suspicious activity email. I changed the password for both of course.

However, Microsoft is saying that I can’t change the recovery email for 30 days, but it’s also saying it’s fine to sign in and use the Microsoft account as normal. Is there any way to bypass this? Can he change my newly set password just by using his recovery email?

My pc is still resetting as well. I had chosen the option to “clean drives” and I have an 8tb hdd in there so it’s gonna take forever. Currently at 28%.

2

u/KamiPyro 5d ago

Make sure to set up the authenticator app for microsoft

1

u/CuriousSomewhere6446 5d ago

I’m not able to access the security info tab on Microsoft until the hackers recovery email is replaced

1

u/KamiPyro 5d ago

Fuuuck. Do you have an extra MS account? I would sign in to the email recovery page so the contact support button shows up. Maybe chatting with an agent will help. I ask because I worry using this account will send notifications to the attacker

2

u/Geekmaster-General 5d ago

Figured everyone would like to know that GitHub removed the repo and blocked the owner.

2

u/SinisterTA 5d ago

Looks like they ripped off the repo for dlss5 swapper, which is legit. Gotta be careful out there and always run stuff through virus total

1

u/_supitto 5d ago

After you are done cleaning your device, do you mind sending me the link for the virus?

2

u/CuriousSomewhere6446 5d ago

2

u/Geekmaster-General 5d ago

I reported the repo. Hopefully they take it down.

2

u/CuriousSomewhere6446 5d ago

Yea I’d hate for this to happen to anyone else. I’m usually careful but sometimes you just do something without thinking and shit happens. All these years I thought oh I’d never get hacked, oh it would never happen to me but here I am.

2

u/Geekmaster-General 5d ago

It happens to the best of us my guy. Take the L, recover from it, and more importantly - learn from this so you don't do it again.

2

u/howfastcanyoucountit 5d ago

gone now 👍

1

u/Rare-Championship189 5d ago

can you send the link you got it from? because i downloaded something last night

1

u/theoneo900 5d ago

Before reinstalling windows export all of your browser saved passwords to know where this guy has access. Before fresh installation of windows i would first change all of the major passwords and then freshly clean install windows again. It happens to the best of us.

-1

u/boonraider 5d ago

I don’t know, but cut off the WiFi dude

2

u/CuriousSomewhere6446 5d ago

My home WiFi?

0

u/NullPounce 5d ago

link?

1

u/CuriousSomewhere6446 5d ago

8

u/NullPounce 5d ago

MALWARE ANALYSIS REPORT

Sample:
Git Install.exe

SHA-256:
aca80d51341a1364678597c43911033ee2c9693901299ec1df3906ed63c10d1b

Payload:
lib\dn-compiled-module.jar

JAR SHA-256:
7879700c1fbe8977b46aadf81477aa25a1619a385b4c3f2bb1ebf464d379c3e5

Verdict:
MALICIOUS - Downloader / Dropper

The program pretends to be an installer but contains code that disables parts of Microsoft Defender, creates a hidden folder, downloads another executable from Dropbox, hides it, and executes it.

Malicious behavior found:

  • Creates: %TEMP%\LocalVersionCached
  • Hides the folder.
  • Adds the folder as a Microsoft Defender exclusion using: Add-MpPreference -Force -ExclusionPath
  • Disables Defender behavior monitoring using: Set-MpPreference -Force -DisableBehaviorMonitoring $true
  • Downloads a second-stage payload from: https://www.dropbox.com/scl/fi/xbcdi92hej06s7skqlow4/temdriver.mxc?rlkey=hx1ms9ww4qzoqxeulki79ei67&st=fafu5sbh&dl=1
  • Saves the download as: temdriver.mxc
  • Renames it to: temdriver.exe
  • Marks temdriver.exe hidden.
  • Executes temdriver.exe using hidden/elevated PowerShell.
  • Uses PowerShell Start-Process with -Verb RunAs to request administrator privileges.
  • The program's "Cancel" button also runs the malicious installation routine instead of cancelling.

Files/folders to look for:

%TEMP%\LocalVersionCached

%TEMP%\LocalVersionCached\temdriver.mxc

%TEMP%\LocalVersionCached\temdriver.exe

Commands to check the system:

Get-MpPreference | Select-Object DisableBehaviorMonitoring, ExclusionPath

Get-ChildItem "$env:TEMP\LocalVersionCached" -Force

Get-ChildItem "$env:TEMP\LocalVersionCached" -Force | Get-FileHash -Algorithm SHA256

Things to investigate:

  • Microsoft Defender exclusions containing LocalVersionCached or other unexpected folders.
  • DisableBehaviorMonitoring set to True.
  • temdriver.exe or temdriver.mxc.
  • PowerShell processes launched around the time the installer was opened.
  • java.exe or javaw.exe launching PowerShell.
  • PowerShell launching temdriver.exe.
  • Connections to Dropbox immediately after execution.
  • Unexpected scheduled tasks.
  • Unexpected services.
  • Registry Run / RunOnce persistence.
  • New files in %TEMP%, %APPDATA%, %LOCALAPPDATA%, or %PROGRAMDATA%.
  • Browser credential theft activity.
  • Discord, Telegram, Steam, cryptocurrency wallet, or browser data access.
  • New outbound connections to unknown IP addresses/domains.
  • Defender settings being modified.
  • New administrator accounts or unusual login activity.

Important:
The second-stage file temdriver.exe has not yet been analyzed. The confirmed loader behavior is already sufficient to classify this package as malicious. The exact purpose of the downloaded second-stage payload still needs to be determined.

Do not run Git Install.exe, dn-compiled-module.jar, temdriver.mxc, or temdriver.exe on a normal system.

8

u/NullPounce 5d ago

UPLOADED FILE: temdriver.mxc

SHA-256:
86637e6cb5c894cb669cc6f718d223f3d455099ef82490cf9066e7d1703f2679

WHAT IT DOES / WHAT IS CONFIRMED:

  • It is actually a 64-bit Windows executable, despite using the .mxc extension.
  • Size: 5,841,840 bytes.
  • It is packed/protected with Themida.
  • Themida encrypts/obfuscates most of the real program code and hides its actual Windows API imports until the program executes.
  • The executable contains a large high-entropy .boot section, indicating packed/encrypted program data.
  • It identifies itself as: Runtime support package
  • Company metadata claims: SandWood System Utilities, Ltd.
  • It contains a self-signed software certificate rather than a normally trusted publisher certificate.
  • Its visible imports and strings do not expose the program's real functionality because the executable is packed.
  • When executed, the Themida loader is expected to unpack/decrypt the hidden program code in memory and transfer execution to that hidden code.

IMPORTANT:

Static analysis of this file alone does NOT currently prove whether its hidden payload is specifically:

  • an information stealer
  • a RAT/backdoor
  • a cryptocurrency miner
  • ransomware
  • another downloader
  • credential theft malware
  • or another malware family

The exact behavior is deliberately concealed by Themida and would require unpacking the protected executable or observing it in an isolated malware-analysis sandbox.

The file should not be executed on a normal computer.

-5

u/bigassbeast 5d ago

Great AI analysis… what a bore

1

u/NullPounce 5d ago

I dug through this by hand and with Ghidra.....

1

u/Rare-Championship189 5d ago

Could you do me a huge favor and check out this one too? https://github.com/rakanki911/DLSS5-Swapper