#π Python Malware?
41 messages Β· Page 1 of 1 (latest)
@pallid sand
Remember to:
- Ask your Python question, not if you can ask or if there's an expert who can help.
- Show a code sample as text (rather than a screenshot) and the error message, if you've got one.
- Explain what you expect to happen and what actually happens.
:warning: Do not pip install anything that isn't related to your question, especially if asked to over DMs.
Hello. I just started my device and I found a script ( https://paste.pythondiscord.com/UMHQ ) in my autostart. It was a .pyw file. Do I have malware? Notice that it asked for a app to execute the script on startup meaning I dont think it acutally ran
Please help fast since I got really important data on this device.
it looks like it's a malware named Tsunami (also known under the names Muhstik, Radiation and Amnesia) that you can read up on if you google "tsunami malware", preferably using your phone or other device
everything about this screams "malware" to me
Uhh well what did it do if it executed? Any ideas if it stole cookies, passwords, logins, files? Used my webcam or mic?
: (
there are no guaranties that it hasn't run on startup on your device, so i would be really careful
And most importantly. Did it ran? How could I check?
Hmm okay
that can be very hard to know
it seems to set up a windows defender exception, so maybe check if that's in place?
A few days ago sth popped up there but I removed it from there. Sth with temp folder and I deleted that folder then too
if it did pop up, then it sounds like it ran
it looks like it also drops files in other places then its randomly named folder
for example a file named Runtime Broker.exe under %APPDATA%\Microsoft\Windows\Applications\ and %LOCALAPPDATA%\Microsoft\Windows\Applications\
it also downloads and installs other stuff from the internet, it can be more or less anything and can be put just about anywhere on the computer, i would not trust that computer for anything anymore
i downloads and runs stuff from one or more of the 1000 obfuscated urls included in the script
I dont even have a Applications folder there
only these
If you go into that startup location, what was the write date? Most of the links are dead for the C2.
This malware is typically distributed via interaction with scripts that have been obfuscated via a freely available tool.
There is a video on this here:
https://www.youtube.com/watch?v=xoOfxz5w-p0
https://jh.live/n8n || Build automated workflows between applications, and integrate JavaScript or Python code whenever you need to -- with n8n! https://jh.live/n8n
Free Cybersecurity Education and Ethical Hacking with John Hammond
π§JOIN MY NEWSLETTER β‘ https://jh.live/email
πSUPPORT THE CHANNEL β‘ https://jh.live/patreon
π€ SPONSOR THE CHANNEL β‘...
Yesterday 4 p.m.
...
.
Imma run a full malware scan using Windows Defender
Probably best to do a reinstall from a USB created on a different trusted machine
Yea I guess imma do that too. Im just happy that they ig dont have webcam access. Deinstalled the drivers for em when I installed windows
Get a camera guard
I will π
Or electrical tape
Ye
Do u think it infected my device? Like it was not possible to run in autostart since there was no exe or executable stuff like that
sound from the room and whatever is displayed on the screen or stored on your system might still be at risk
a python script is executable if you have a python installed or otherwise executable
It was a .pyw file
On autostart it asked what app to use to run it
okay, then it probably had a problem finding the python executable that time
but to end up in there it must have executed at least once before or something else did and put it there
ye
damn, nice job with that de-obfuscation script
This help channel has been closed. Feel free to create a new post in #1035199133436354600. To maximize your chances of getting a response, check out this guide on asking good questions.