> be me
> get dm from malwrhunterteam
> "smelly, i found goop"
> wtf i love goop (malware)
> he didn't actually say that
> i'm only saying that for consistency
> "Found a fake POS update domain, I can't remember the last time I heard malware specifically targeting a POS system"
> "smica83 saved it, uploaded it to MalwareBazaar"
> ok
> download file
> look inside
> POS_System_Update.msi
> open in Orca
> tool used for examining .msi installer thingies
> .msi extracts .dll from itself
> executes function inside .msi called EdgeUpdateMain
> image 1
> open in Ida
> lots of string stuff
> registers machine based off of stuff
> sends request to fake POS website
> toastposupdate(.)com
> expects specific user-agent to connect
> opbZMeJMJZmmveM7Nnck3g
> image 2
> can accept commands from web server
> can "db_dump", "ram_scrape", "intercept"
> db_dump dumps everything from POS DB
> ram_scrape pulls credit-cards out of memory
> intercept looks for other POS terminals
> image 3
This code is strange because it isn't obfuscated at all. Additionally, it is inconsistent with some of its functionality. In some segments it used the WinAPI to perform web requests with WinHTTPConnect, WinHTTPOpenRequest, WinHTTPSendRequest. In other instances, it uses cURL from the system environment with the POST parameter.
This payload also has code in place for stealing chrome credentials. It also has another .exe embedded in it.
This is very silly goop. It is designed to target ToastPOS, which is used for restaurants. I'm curious how these individuals learned the internals of ToastPOS to develop malware which would work against it.
Post #9502
4.03K



- ❤ 69
- 🔥 16
- 🤔 11
- 🎉 1