FlightSimLabs Alleged Malware Analysis

Photo credit to crankyrecursion

UPDATE 19/02/2018 1200z

UPDATE 19/02/2018 2100z

  • test.exe is invoked
  • The output (usernames and passwords) is dumped to a file called log.txt
  • The additional base64.exe in the tmp directory encodes the log.txt file
  • The encoded data is sent using HTTP to a LogHandler3.ashx endpoint
Fraudulent serial invocation. Photo credit to Fidus InfoSec
  • test.exe is NOT invoked
  • Your usernames and passwords are not retrieved or processed by FSLabs
Legitimate serial flow. Photo credit to Fidus InfoSec

UPDATE 19/02/2018 2211z

MEDIA LINKS

Software Engineer

Love podcasts or audiobooks? Learn on the go with our new app.

Recommended from Medium

What do you get(need) to get a crypto community manager job ?

Big Data Security

Web Application Penetration Testing

$RARE Tokenomics Governance Proposals

Cryowar Aidrops — Distribution Details

EOS Audit+ Blue Paper

Jailbreak iOS 14.1

Plutos Network AMM structure for trading Synthetics

Luke Gorman

Luke Gorman

Software Engineer

More from Medium

Your Last Phishing Attack

Like Cryptojackers to Honey

The Future of Cyber Attacks

AD Series | DC Sync Attacks