
Fake OnlyFans MALWARE: Remcos Infostealer VBScript Stager
Source: YouTube · John Hammond · published Jun 22, 2023 · 17:23
The video analyzes a malware sample delivered via a fake photo archive that contains Visual Basic scripts designed to drop Remcos RAT (Remote Access Trojan) 0:00-0:03.
Key Takeaways:
• The "vb.trogen.zip" file contains directories that appear to hold photos but actually contain malicious Windows executables 0:08-0:15
• The malware uses extensive Visual Basic scripts with obfuscation techniques like string manipulation and hex encoding to hide malicious code 1:01-1:06
• After deobfuscation, the malware checks system architecture and registers a DLL to drop Remcos RAT, which connects to a command-and-control server 12:12-12:25
• This malware campaign appears to be part of a larger scheme using fake adult content (Lana Rhodes/OnlyFans) to lure victims into executing the malware 15:04-15:19
The analyst demonstrates how dynamic sandboxing tools like Any.Run can quickly reveal malware behavior that might be missed in static analysis alone 5:38-5:40.
Sources:
- 0:00-0:03 Introduction to the malware sample
- 0:08-0:15 Malware directory structure analysis
- 1:01-1:06 Visual Basic script obfuscation techniques
- 12:12-12:25 Remcos RAT execution and connection
- 15:04-15:19 Campaign context and lure tactics
- 5:38-5:40 Dynamic analysis with sandbox tools
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Malware Analysis. Commonly maps to: Security Operations, Security Architecture and Engineering. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
I have this file vb.trogen.zip and it was sent to me in an email allegedly containing some malware I have extracted this archive and there are a couple other directories that came from it one subfolder called one the other called two and inside of both of these directories are seemingly the same contents but they are photos of Lana Rhodes Elena Rhodes I don't know how to pronounce that one uh granted uh that has its own affiliation and Association but in each of those directories if we actually drill down into one and two these are not what they say they are these aren't photos and this single quote file is actually an executable it is a Windows binary for x64 and it is an executable that we could dig into the very very same in the second directory if I run file on each of those again the …