> be me
> get dm
> "smelly, i found goop"
> wtf i love goop (malware)
> weird .vbs file sent
> "RateConfirmation.vbs"
> hmmm
> download
> look inside
> shrimple file loader
> downloads "grape" .zip from funny domain
> download grape zip file
> NodeJS electron goop
> masquerading as Grape Electron
> weird project on GitHub, legit tho
> weird outdated thingie called ChatGrape
> last update 5 years ago
> ???
> exact same source code as ChatGrape on GitHub
> index.js (start of program) modified
> does malware stuff
> launches ChatGrape regularly afterward
> malware appears to try targeting UniWays
> small to medium size company
> freight and transportation company
> covers 48/50 states in US (no alaska or hawaii)
> hmmm
> see C2
> uniwaysllc(.)com
> code sent POST request to C2
> code waits for response
> hmmmm weird
> try to manually contact C2
> nothing happens
> try again
> nothing happens
> looks like malware operator manually reviewing incoming connections
wtf? is this goop is targeting freight and transportation companies? thats awfully suspicious because last time on dragon ball z (if youve been paying attention to my goop posts) we saw a very, very similar goop doing masquerading targeting freight and transportation companies.
this is the 2nd mystery goop weve seen targeting this type of company, except this time the malware has gotten a little smarter and (potentially) manually reviews incoming connections to ensure its the actual target and not reverse engineers. clever clever goop
tell us your secrets mystery threat group attacking transportation companies in the united states. who are you and why do you need to know what truckers are delivering
rate confirmation (loader):
4f342ccb8005a82bed93d9a3c18aab45d32590ffa34834b789229f736889cf56
masqueraded grape:
e8a7ea884593cd26adecbbf602846b2cbd9bd1ec420ebd78c1bf7a64dbf73912
grape modified index.js (payload):
b6c75b53e37e37f743457d10f24fa3f7c51d6e2adc50e68b9c9aebb21c5303c5
pic unrelated
Post #9506
1.92K

- ❤ 43
- 🤯 6
- 👏 2
- 🤔 1