Skip to content
View in the app

A better way to browse. Learn more.

Kaspersky Support Forum

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

游戏libEGL.dll存在挖矿病毒

技术细节:

  • 恶意文件: libEGL.dll

  • 大小差异: 约 525 KB(正常合法的该文件通常为 377 KB 左右)。

  • SHA256: 8bacb2082eb37fd7aed5bb6a7fc766d9937d9f3ed926ae82420d37af754a216c

行为特征:

  1. 在 C:\Users\用户名\AppData\Local\syscacheapp 生成文件夹。

  2. 释放一个名为 cacheapp64.exe 的超大文件(约 750 MB)特征: GCC/MinGW 编译,高熵值。及大量伪装 DLL。

  3. 通过修改注册表 HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell 实现自启动。

当前检出:
VirusTotal 上仅火绒 (Huorong) 和瑞星 (Rising) 报毒

下载信息:
链接: [https://files.catbox.moe/jmn65o.7z]
压缩包结构: 1.7z 内含 libEGL.7z (样本) 和 附件.7z (截图与结构说明)。
密码: 123

 

链接:

https://metadefender.com/results/file/bzI1MTIyOHM0RHlFWkdCazQ4emVMdGdZM2w

https://www.virustotal.com/gui/file/021b7a9269bc251e66c4de170c7e81e7e9df482c386c84b7db6e86e986dcda10

https://www.virustotal.com/gui/file/8bacb2082eb37fd7aed5bb6a7fc766d9937d9f3ed926ae82420d37af754a216c

 

已经发给*****@*****.tld了,因为不知道会不会有回复,所以发个贴子

Featured Replies

感谢您的技术分析 我的电脑上同样存在该木马软件 当时被卡巴斯基检测到了 但是我当时无法确定 并没有处理 甚至直到目前该木马还存留在我的电脑上

 

image.thumb.png.fe86a10765701bb480f851d4494166d5.pngimage.thumb.png.ea59ffc644d54fbc27d3e62ad495fd95.png

  • Author

目前可以确定出现在免费(盗版)发放dlsite游戏的渠道里,包括著名的anime-sharing/hentai-share/ggbases

不排除是供应链投毒

rpgmaker系列引擎/TyranoScript引擎的游戏

28 minutes ago, inbox said:

目前可以确定出现在免费(盗版)发放dlsite游戏的渠道里,包括著名的anime-sharing/hentai-share/ggbases

不排除是供应链投毒

rpgmaker系列引擎/TyranoScript引擎的游戏

嗯 我就是这样中招的 在一个小时前我尝试了去dlsite中下载对应的体验版似乎并没有被卡巴侦测到 正常运行 下图是直接运行被感染的游戏

image.thumb.png.014c5bdaa4acaa3b859655bd4f4e330f.png

 

以及

稍微分析了下可以确定是木马了

 libEGL.dll 仅为loader 实际上 它释放出来的

cacheapp64.exe 第二层的loader 该执行文件会检测虚拟环境包括
x32dbg x64dbg ida64 x86_64-SSE4-AVX2 wireshark processhacker
 netstat netmon tcpview filemon regmon 
以及检测 “VirtualBox Shared Folders” 文件夹估计是检测虚拟机

 

当环境通过之后才会释放真正的毒

image.thumb.png.85c6570ea8fdb21f3f12a338ead85d7e.png

主要是不知道这玩意有没有把我的密码给偷了

以及目前卡巴斯基并不会把这个loader给删掉

image.thumb.png.997e6ad8dcd1a98af6c173add1233f52.png

 

Edited by JustMe_1337

第二层的密钥值为 wggadpqdxcsknazotxorwzkjnjldvvil

前天我在win11家庭版运行了游戏exe文件并被安装了cacheapp.exe,起初我不知道这个游戏有病毒,所以游玩结束后我卸载了游戏,期间并没有发现电脑有异常。昨天电脑未启动。到今天了解到这件事后我打开电脑手动删除了syscacheapp这个文件夹并清空回收站。执行win安全中心的全盘扫描和火绒的全盘扫描,未发现异常。重启后文件也没有再生。不知道是不是因为病毒无法攻击win11系统?

  • Author

document/tech/vir_report/1897

Edited by inbox

  • Author

H已经出报告了

  • 3 weeks later...

上报样本请发邮件到 *****@*****.tld,并且在邮件中附上你的激活码,不然不会受理你的请求。主题写漏报,如果是误报写误报。叫他们发ftp给你上报漏报或者误报样本。邮件有回复,这里没回复,这里的版本知道主不是卡巴斯基员工,什么都不是。不建议在https://opentip.kaspersky.com/。提交样本,没回复

被发光了,邮件地址是下图这个

 

PixPin_2026-01-21_07-46-43.jpg.1ff4e7f49768bdc79d2dec70cbb6837e.jpg

Edited by 啊松s

  • The topic was locked
Guest
This topic is now closed to further replies.

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.