The SonicWall Capture Labs Threat Research Team have recently come across malware that appears to be targeting the Minecraft gaming community. Rather than encrypting files and holding them ransom for a fee, the aim of the malware is to simply delete files from the system without any possibility of recovery.
Infection Cycle:
The origin of the file is an attachment hosted on discordapp.com:
hxxps://cdn.discordapp.com/attachments/548593284985913388/548622096075325441/The_power_of_hentai.exe
The link is still live at the time of writing.
Upon execution the malware iterates through files on the system and overwrites them with the following text file:
It creates %SystemDrive%\memes\Idiot.exe and executes it.
Idiot.exe downloads a gif file from the following link:
hxxps://cdn.discordapp.com/attachments/548593284985913388/548621341654515783/despacito.gif
It then causes the following windows to pop up in a random fashion showing the gif above of an animated figure dancing in celebration:
The text file leads one to believe that the malware is aimed at a particular group of people in the Minecraft gaming community. Strings for "Minecraft" can also be seen throughout the executable file:
SonicWALL Capture Labs provides protection against this threat via the following signatures:
Share This Article
An Article By
An Article By
Security News
Security News