Distributed via Steam chat, hxxp://screenjpeg.tech/pictures291.jpg.
Looks like the malware swaps steam trade links to the crooks account to steal steam items, the original file name was "pictures291.scr".
Interesting strings.
Looks like the malware swaps steam trade links to the crooks account to steal steam items, the original file name was "pictures291.scr".
Interesting strings.
Code: Select all
Drops into directory C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Templates\steamerrorreporter.exe and injects into RegAsm.exe0x380ea95 (118): D:\asd\php\steam_complex\New_steal\new_steal_no_proxy\14ver -original(pubg+??????????)\SteamStealer\obj\Release\vv.pdb
0x2880274 (120): rare,mythical,legendary,immortal,arcana,ancient,tool,unusual
0x2880308 (120): rare,mythical,legendary,immortal,arcana,ancient,tool,unusual
Attachments
infected
(602.24 KiB) Downloaded 37 times
(602.24 KiB) Downloaded 37 times