"100 days free trial, no payment needed" SCAM SERVER

Popup - ModEmpire

Owners:
Distributor#4980 (UID: 920349326285348963)
Whythohuhd#3993 (UID: 923708867500720160)
zfay#7613 (UID: 925775024147800204)
BreakerxDrip#3046 (UID: 920844735659249684)
Curr#8909 (UID: 920844761491964024)

Associated Discord Bot - esther50#9229 (UID: 925776438878158888, from the BOOMTV server)

VirusTotal - VirusTotal - File - 507e05af5c1db81cfa00f74fabc52c805888527fbc019f436bdfd140e551b670

VirusTotal after converting to .ZIP - VirusTotal - File - 4dd88f9cfbedf4c842ba684cc2124ffee6fd4f111ffb4877f0bbcf62c1d5412b

Program in action - CheatLauncher.zip (MD5: 6DBE8F37020D1724B123167049872299) - Interactive analysis - ANY.RUN

Program contains several trojans, including AgentTesla, Kryptik, MSILZilla, SusGen & ZemsilF.

1 Like

i will take a look at it