I made a game, try it!

A friend asked me to try his “games”
[color=#FF00]Link (Dangerous): https://cdn.discordapp.com/attachments/985644068300275782/985645135050186782/StarShooter.exe[/color]
Scan results: VirusTotal
Extra Info:
https://www.aht.li/3717549/starshooter.png

15 min later he deleted his post and all the servers he was on

1 Like

image

1 Like

ANY.RUN
A DNS query returned me an ip :

My skills don’t go any further, but I want to dig it…

It sends back stuff to Discord, so my guess is that he has C2 server and his skiddish malware is using Webhooks.

Screenshot 2023-05-30 201216