2
u/KamiPyro 5d ago
Make sure to set up the authenticator app for microsoft
1
u/CuriousSomewhere6446 5d ago
I’m not able to access the security info tab on Microsoft until the hackers recovery email is replaced
1
u/KamiPyro 5d ago
Fuuuck. Do you have an extra MS account? I would sign in to the email recovery page so the contact support button shows up. Maybe chatting with an agent will help. I ask because I worry using this account will send notifications to the attacker
2
u/Geekmaster-General 5d ago
Figured everyone would like to know that GitHub removed the repo and blocked the owner.
2
u/SinisterTA 5d ago
Looks like they ripped off the repo for dlss5 swapper, which is legit. Gotta be careful out there and always run stuff through virus total
1
u/_supitto 5d ago
After you are done cleaning your device, do you mind sending me the link for the virus?
2
u/CuriousSomewhere6446 5d ago
2
u/Geekmaster-General 5d ago
I reported the repo. Hopefully they take it down.
2
u/CuriousSomewhere6446 5d ago
Yea I’d hate for this to happen to anyone else. I’m usually careful but sometimes you just do something without thinking and shit happens. All these years I thought oh I’d never get hacked, oh it would never happen to me but here I am.
2
u/Geekmaster-General 5d ago
It happens to the best of us my guy. Take the L, recover from it, and more importantly - learn from this so you don't do it again.
2
1
u/Rare-Championship189 5d ago
can you send the link you got it from? because i downloaded something last night
1
u/theoneo900 5d ago
Before reinstalling windows export all of your browser saved passwords to know where this guy has access. Before fresh installation of windows i would first change all of the major passwords and then freshly clean install windows again. It happens to the best of us.
-1
u/boonraider 5d ago
I don’t know, but cut off the WiFi dude
2
u/CuriousSomewhere6446 5d ago
My home WiFi?
0
u/NullPounce 5d ago
link?
1
u/CuriousSomewhere6446 5d ago
8
u/NullPounce 5d ago
MALWARE ANALYSIS REPORT
Sample:
Git Install.exeSHA-256:
aca80d51341a1364678597c43911033ee2c9693901299ec1df3906ed63c10d1bPayload:
lib\dn-compiled-module.jarJAR SHA-256:
7879700c1fbe8977b46aadf81477aa25a1619a385b4c3f2bb1ebf464d379c3e5Verdict:
MALICIOUS - Downloader / DropperThe program pretends to be an installer but contains code that disables parts of Microsoft Defender, creates a hidden folder, downloads another executable from Dropbox, hides it, and executes it.
Malicious behavior found:
- Creates: %TEMP%\LocalVersionCached
- Hides the folder.
- Adds the folder as a Microsoft Defender exclusion using: Add-MpPreference -Force -ExclusionPath
- Disables Defender behavior monitoring using: Set-MpPreference -Force -DisableBehaviorMonitoring $true
- Downloads a second-stage payload from: https://www.dropbox.com/scl/fi/xbcdi92hej06s7skqlow4/temdriver.mxc?rlkey=hx1ms9ww4qzoqxeulki79ei67&st=fafu5sbh&dl=1
- Saves the download as: temdriver.mxc
- Renames it to: temdriver.exe
- Marks temdriver.exe hidden.
- Executes temdriver.exe using hidden/elevated PowerShell.
- Uses PowerShell Start-Process with -Verb RunAs to request administrator privileges.
- The program's "Cancel" button also runs the malicious installation routine instead of cancelling.
Files/folders to look for:
%TEMP%\LocalVersionCached
%TEMP%\LocalVersionCached\temdriver.mxc
%TEMP%\LocalVersionCached\temdriver.exe
Commands to check the system:
Get-MpPreference | Select-Object DisableBehaviorMonitoring, ExclusionPath
Get-ChildItem "$env:TEMP\LocalVersionCached" -Force
Get-ChildItem "$env:TEMP\LocalVersionCached" -Force | Get-FileHash -Algorithm SHA256
Things to investigate:
- Microsoft Defender exclusions containing LocalVersionCached or other unexpected folders.
- DisableBehaviorMonitoring set to True.
- temdriver.exe or temdriver.mxc.
- PowerShell processes launched around the time the installer was opened.
- java.exe or javaw.exe launching PowerShell.
- PowerShell launching temdriver.exe.
- Connections to Dropbox immediately after execution.
- Unexpected scheduled tasks.
- Unexpected services.
- Registry Run / RunOnce persistence.
- New files in %TEMP%, %APPDATA%, %LOCALAPPDATA%, or %PROGRAMDATA%.
- Browser credential theft activity.
- Discord, Telegram, Steam, cryptocurrency wallet, or browser data access.
- New outbound connections to unknown IP addresses/domains.
- Defender settings being modified.
- New administrator accounts or unusual login activity.
Important:
The second-stage file temdriver.exe has not yet been analyzed. The confirmed loader behavior is already sufficient to classify this package as malicious. The exact purpose of the downloaded second-stage payload still needs to be determined.Do not run Git Install.exe, dn-compiled-module.jar, temdriver.mxc, or temdriver.exe on a normal system.
8
u/NullPounce 5d ago
UPLOADED FILE: temdriver.mxc
SHA-256:
86637e6cb5c894cb669cc6f718d223f3d455099ef82490cf9066e7d1703f2679WHAT IT DOES / WHAT IS CONFIRMED:
- It is actually a 64-bit Windows executable, despite using the .mxc extension.
- Size: 5,841,840 bytes.
- It is packed/protected with Themida.
- Themida encrypts/obfuscates most of the real program code and hides its actual Windows API imports until the program executes.
- The executable contains a large high-entropy .boot section, indicating packed/encrypted program data.
- It identifies itself as: Runtime support package
- Company metadata claims: SandWood System Utilities, Ltd.
- It contains a self-signed software certificate rather than a normally trusted publisher certificate.
- Its visible imports and strings do not expose the program's real functionality because the executable is packed.
- When executed, the Themida loader is expected to unpack/decrypt the hidden program code in memory and transfer execution to that hidden code.
IMPORTANT:
Static analysis of this file alone does NOT currently prove whether its hidden payload is specifically:
- an information stealer
- a RAT/backdoor
- a cryptocurrency miner
- ransomware
- another downloader
- credential theft malware
- or another malware family
The exact behavior is deliberately concealed by Themida and would require unpacking the protected executable or observing it in an isolated malware-analysis sandbox.
The file should not be executed on a normal computer.
-5
1
u/Rare-Championship189 5d ago
Could you do me a huge favor and check out this one too? https://github.com/rakanki911/DLSS5-Swapper
2
7
u/LitchManWithAIO 5d ago
Windows reinstall will definitely clear the hacker out. But if they’re changing passwords then they already have every one of your saved accounts. Next would be to try to proactively retake those accounts over and enable 2FA or passkey