Jump to content

Possible Undetected Discord Stealer getting past Kaspersky


Recommended Posts

I was looking around on this forum: https://malwaretips.com/threads/suspicious-game.124193/

There is a suspicious game getting past Opentip, Kaspersky's Scanner, and Behavioral detection. People have analyzed it and said that is a discord stealer that steals your discord token however it pops up a error which may mean its not doing its thing.

I dont know where to submit things - I submitted on Opentip, but every time I've done that no one has ever responded back to me. 

Link to comment
Share on other sites

harlan4096

Welcome to Kaspersky Community.

 

I can confirm that I also tried to send several times that sample of around 67MB, not exceeding the KOTIP (limit of 256MB), and I got a warning via email reply, that I exceeded the limit ?‍♂️

Quote

 

Your message wasn't delivered to anyone because it's too large. The limit is 51 MB. Your message is 92 MB.

newvirus @ kaspersky . com

Your message couldn't be sent because it's too large.

 

It seems KOTIP sent the sample via old method via that email address... weird ?

Link to comment
Share on other sites

harlan4096

I've already reported via that email, adding a link to the malware from my own private MEGA cloud service, I hope they reply me.

Link to comment
Share on other sites

harlan4096
Quote

 

Hello,

New malicious software was found in the attached file.
Trojan-PSW.Win32.DiscoStealer.ah
Its detection will be included in the next update.
Thank you for your help.

Best regards,
Igor, Malware Analyst, Kaspersky
39A/3 Leningradskoe Shosse, Moscow, 125212, Russia Tel./Fax: + 7 (495) 797 8700 http://www.kaspersky.com https://securelist.com
https://opentip.kaspersky.com/ - get insights about suspicious files, hashes, URLs, IP addresses or domain names

 

image.thumb.png.d1d8464bf39d6c85a751dc3a737c78e5.png

Link to comment
Share on other sites

9 hours ago, harlan4096 said:

image.thumb.png.d1d8464bf39d6c85a751dc3a737c78e5.png

Where did you send it so I know where to incase I need to report something. I emailed it to them and never got a response.

Link to comment
Share on other sites

Oh, you sent it via opentip?

Can you also report this website ageostealer.wtf
Its the website this strain of stealer uses.

Link to comment
Share on other sites

harlan4096

Did You read it? It seems not... No, I did not send via KOTIP, I sent with the old way, still working, via email, but not attaching directly the file but adding a link to download it (compressed with password "infected").

Link to comment
Share on other sites

3 minutes ago, harlan4096 said:

Did You read it? It seems not... No, I did not send via KOTIP, I sent with the old way, still working, via email, but not attaching directly the file but adding a link to download it (compressed with password "infected").

Oh cool, wonder why they didnt respond to me. Maybe I attached it in a weird way.

Link to comment
Share on other sites

harlan4096

No, there is an issue with KOTIP and malware files bigger than 51MB, this one has 67MB, so I also could not send it... anyway it's true that I got a warning reply by email. Check Your SPAM folder.

Link to comment
Share on other sites

35 minutes ago, harlan4096 said:

No, there is an issue with KOTIP and malware files bigger than 51MB, this one has 67MB, so I also could not send it... anyway it's true that I got a warning reply by email. Check Your SPAM folder.

Yeah I saw. I sent it via email and I did get a warning reply

  • Like 1
Link to comment
Share on other sites

I found another one and sent it via email aswell, lets hope they respond back.
Not sure if its a issue that the download is a Triage link but that does work.

Edited by Xeno
  • Like 1
Link to comment
Share on other sites

38 minutes ago, harlan4096 said:

Without the sample file We can't report...

Here is the two sample that has no detection on VT...

Password is infected.

Link to comment
Share on other sites

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now


×
×
  • Create New...