Could you let me know the url where they hosted the file? And if they gave you a password, could you let me know that as well so I can see the domain they are using and try to get it taken down
JordanPlayz158
Recent community posts
I don't think it should but you can always check your startup folder just to be safe. Also could you by chance send me the file and/or password? I found one of the new sites they use but they have it password protected and this time, they didn't provide the password on the page so I can't access the executable or see the domain they are exporting the data to (so I can report it to the domain registrar's and such)
Just be careful, the initial payload, the setup is what steals your cookies, discord token, a screenshot of your screen, wallets (I assume crypto wallets by the file name), and apparently it... might try to download your desktop, documents, etc when looking at the files it creates/created then it also has a nodejs app which acts as a persistent rat, it is in your appdata temp, has the nodejs icon, it is run via the open vbs script and that is opened/called by a vbs script in your startup folder, so while it is easy to disable once you figure it out, it is not something you want to risk getting infected with either