Jump to content
Update to the Latest Version for Smooth VPN Performance ×

[Malware Reporting] Cryptominer disguised as libEGL.dll spreading via RPGMaker/TyranoScript games (Low Detection)


Recommended Posts

Posted

Hello,

I am writing to report a malicious sample currently circulating in pirated game distribution channels. It masquerades as the legitimate libEGL.dll file but contains a cryptocurrency miner.

Currently, it has a very low detection rate on VirusTotal (detected only by Huorong and Rising), and it bypasses most major AV engines.

Technical Details:

  • Malicious File: libEGL.dll

  • File Size: Approximately 525 KB (Note: Legitimate versions are typically around 377 KB).

  • SHA256: 8bacb2082eb37fd7aed5bb6a7fc766d9937d9f3ed926ae82420d37af754a216c

Behavioral Analysis:

  1. File Dropping:

    • Creates a directory at: C:\Users\%USERNAME%\AppData\Local\syscacheapp.

    • Drops a large executable named cacheapp64.exe (approx. 750 MB).

    • Characteristics of dropped file: Compiled with GCC/MinGW, extremely high entropy (packed/obfuscated), accompanied by numerous fake DLLs.

  2. Persistence:

    • Achieves auto-start by modifying the Registry:

    • Key: HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell

Distribution & Context:

  • Vector: Confirmed presence in unauthorized/pirated releases of games (specifically those using RPGMaker or TyranoScript engines).

  • Sources: Widely distributed via major sharing communities such as anime-sharing, hentai-share, and ggbases.

  • Origin: The widespread nature suggests a potential "supply chain" poisoning within the upper-level crack/distribution groups.

Sample Download:

  • Link: [ https://files.catbox.moe/jmn65o.7z ]

  • Password: 123

  • Archive Structure: 1.7z contains libEGL.7z (The malware sample) and Attachment.7z (Screenshots and structural analysis).

Please analyze this sample and update the database.

Thank you.

 

https://metadefender.com/results/file/bzI1MTIyOHM0RHlFWkdCazQ4emVMdGdZM2w

https://www.virustotal.com/gui/file/021b7a9269bc251e66c4de170c7e81e7e9df482c386c84b7db6e86e986dcda10

https://www.virustotal.com/gui/file/8bacb2082eb37fd7aed5bb6a7fc766d9937d9f3ed926ae82420d37af754a216c

https://forum.kaspersky.com/topic/游戏libegldll存在挖矿病毒-57734/

 

 

 

  • The topic was locked
Guest
This topic is now closed to further replies.


×
×
  • Create New...