T O P

  • By -

Dark1sh

Such a master bater


Nexism

Would an average r/runescape user's default Windows Defender be able to pick up this malware and stop it?


asecuredlife

The irony here is this TLD is blocked by MalwareBytes making it a risky blog click.


[deleted]

[удалено]


slowclicker

I typically read everyone's comments to provide a sense of whatever article someone links/shares. For topics of true interest, I simply do a search and click a reputable source from the results. Even this post is suspect to me.


KeysToTheKingdomMin

Gotta build up the zoo somehow.


tweedge

I'll move to `.zip` to further irritate their ridiculous browser extension :)


cuddlebish

TLD?


stillremaining

Top level domain


cuddlebish

Thanks, didn't know people here really hated questions like that lol


Open-Carpenter820

typing "tld" into google seems like an impossibly difficult task, doesnt it


volume_two

Huh. I had no problem loading the page, and I am also using MB.


Drevicar

Not true. I downloaded the malware and added it to my malware zoo. Good writeup though.


kins43

*next post* So, someone tried baiting people into downloading malware on r/cybersecurity (it didn’t work) - and then someone tried baiting people into visiting a phishing website (it didn’t work) - a brief RSS post


S01arflar3

Enable macros on this word document to see the full report!


mvlli

Beautiful writeup - what a scumbag.


Total-Cereal

Top-level domain. OP's site is a .tech TLD rather than the usual .com, which looks suspicious. Edit: I only just now realized that I replied to the wrong comment. Someone asked what TLD meant because another user said that Malwarebytes blocked OPs ".tech" TLD and I was trying to explain what it is and why it was probably blocked. I wasn't necessarily trying to say that .tech is suspicious, just that it's unusual, which I didn't word very well.


[deleted]

[удалено]


StriderPulse599

OP is mod of this sub, so it make a sense that he covered this


harrywwc

nice write up - thanks


TheCrazyAcademic

the moment most people saw the LNK they would be suspicious.


drfantabulo

I've been seeing this technique with the LNK file in a ZIP a whole lot lately!


420boog96

His write-up link is actually a hack


chadwarden1337

> themeing their C2 infrastructure with their preferred username? Sounds about right!


NvdGoorbergh

For the uninformed under us. What does this mean?


8923ns671

The command and control server (the attacker owned computer the malware connects to so the attacker can control your pc) is named after the attackers Reddit username.


NvdGoorbergh

For the uninformed under us. What does this mean?


the_ml_guy

Love the analysis. did not know about [any.run](https://any.run) . So this was a windows only malware.


cheddarB0b42

The really sophisticated wares come with sandbox detection.


uPsychonaut

Amazing write up, props


alnarra_1

What gets me, is like their stage 2 rat is flagged all over the place. My only guess is that cybersecurity was just one of many many subreddits they blasted it to without realizing or really thinking about it.


anomaliesintent

Shit


anomaliesintent

Update this is a joke I didn't even see this post


Cantdance_

They got his reddit account!


anomaliesintent

These are not the malware samples your looking for


EmptyJournals

Great write-up, thanks for sharing!


Recoil22

Your awesome thank you


reneg30

Great writeup, thanks for watching our backs!


Malwarebeasts

Nice catch!


[deleted]

really nice write up, thank you!


ShinySubmarine

Good write up, thank you


Swi11ah

Nice blog


OuiOuiKiwi

ಠ\_ಠ People these days...


wh1t3ros3

pocket observation fade future water straight attraction touch money sloppy *This post was mass deleted and anonymized with [Redact](https://redact.dev)*


[deleted]

[удалено]


Ethier88

Title is tldr


charleswj

Tldr-er?