JakeTheDog420

Members
  • Content Count

    30
  • Last visited

Posts posted by JakeTheDog420


  1. Thanks for sharing this OP


    WARNING: File is infected!!!

    RAT INSIDE.

     

    Rat Process Name: Synaptics.exe

    Infected Domains: xred.moo.com (5.88.36.138:1199), freedns.afraid.org (204.140.20.21:80, 50.23.197.94)

    Registry Values Modified: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run (C:\ProgramData\Synaptics\Synaptics.exe added)

    Files Created: C:\ProgramData\Synaptics\Synaptics.exe

    Original File (Netflix EA) / Referenced Info : C:\Users\Logan\Downloads\Compressed\WindowsApp1 - Copy\obj\Debug\Netflix EA.pdb

     

    Synaptics.exe connects back to a CnC server.

    https://app.any.run/tasks/8162ee22-2a62-421c-ab7d-a3e47c4e2423