Post
Topic
Board Meta
Re: Report Malware and Suspicious Links here so Mods can take Action !
by
Lafu
on 25/11/2024, 19:13:37 UTC
And there is also a very new Fake Ann Thread with an Website Link where you have an Malware download Link for an Wallet for NeuroCoin !

The Fake Github was just created last week !

Fake Github : github.com/NeuroCN/Neuro-Coin

Fake Wallet download on the Webpage :
Code:
https://neuro-quick.net/Neurocoin-windows.zip

If you download that Wallet and install and start it a lot of things will be happen:

Files that will be droped
Code:
StartupProfileData-Interactive
powershell.exe.log
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0\UsageLogs\RegAsm.exe.log
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\tempup.url
C:\Users\user\Documents\20241125\PowerShell_transcript.216041.TFCkXrPs.20241125014905.txt

On top of that its full of Malware and Trojan shit:
Code:
Zenbox flags this file as: MALWARE TROJAN EVADER RAT

Drops script at startup location
Bad Opsec Defaults Sacrificial Processes With Improper Arguments
Dot net compiler compiles file from suspicious location
Suspicious DNS Query for IP Lookup Service APIs
PowerShell Script Run in AppData
Startup Folder File Write

ET MALWARE Observed Malicious SSL Cert (Quasar CnC)
ET MALWARE Generic AsyncRAT Style SSL Cert
ET INFO External IP Lookup Domain in DNS Lookup
SURICATA STREAM excessive retransmissions

Win64:Evo-gen [Trj]
Source : https://www.virustotal.com/gui/file/beecb007c7ad7cd6de76765a0c536eb51a9080095a510d52df21ba39b8d9c480/behavior

Account : Neuro_Coin  <--- Please ban or Lock that Account and delete the Thread
The Account was just created 6 days ago.

Fake Ann Thread :  [ANN] NeuroCoin | AI Integration | Future of Smart Finance
This Thread is self-moderated as always from the Hackers

NEURO WALLET
Code:
Website:https://neuro-quick.net
GitHub:https://github.com/NeuroCN

This post is also a reference for the Github Report !