Jump to content

Strange case - can you be a second set of eyes?


Recommended Posts

Hi I'm cybertr0nian,

This is my first post here, I read the forum rules, still hope I understood them correctly.
It's gonna be a long one, bear with me. :)

I'm a cybersecurity enthusiast trying to switch careers and get into cybersecurity.
So I've taken a lot of effort into building my knowledge (made a lot of progress, but still ongoing) and learning new things.

I hope there are some really experienced guys here that may share a little bit of their perspective.

I have a healthy level of paranoia when it comes to cybersecurity, I know we have to of course stay mindful of false positives and the like and not jump to conclusions.
Still I'm posting this to share my thought process and perhaps you can help me verify if my thoughts are correct here.

Background of the issue

I seldom play online games these days, usually on a cloud system separate from my main system.
I was trying to be social for once ;) as a friend invited me to play a game online, yet my steering wheel was not recognized by my cloud VM.
Usually it is, but this time it malfunctioned (not correctly forwarding the drivers) and it was taking to long so I thought okay for once I'll install on my local machine.

So I installed Steam and the game Assetto Corsa (an old racing simulator several friends play, it has forgiving system requirements).

My friend told me there is a mod that's really useful, he and all the other guys are using this constantly to improve the graphics and
add in-game content. I'm familiar with playing modded games from back in my high school days, so I thought okay why not, even though I'm usually skeptical
of deviating from the source game due to security considerations.

So I downloaded the Assetto Corsa "Content Manager" an executable file. I scanned it thoroughly with ESET Internet Security 17.2.8.0 and MalwareBytes Premium.
No issues were detected. So far so good.

The Content Manager seemed to work fine and made the game run more efficient (skipping unnecessary credits etc).

So what happened then?

Consequently, while running and interacting with Content Manager all of the sudden I get several popups showing up (ESET was set to Balanced detection & protection settings at the time),
see the images I attached below.

Trojan1.thumb.png.64dcd212bd27b5728716e4ed8c34577b.pngTrojan2.thumb.png.3e06833aa3e78c5c6ee7af29d31cbc98.pngTrojan3.thumb.png.189e1d5c8b2024b83272833a01fec079.png

Trojan4.thumb.png.9d352e1ab4b6291878e725af5d3199d8.png

I'm aware of course you guys can't support MalwareBytes, but just adding it for reference so you see not just ESET but both Endpoint Protections are noticing malicious/abnormal behavior here, adding to my hypothesis that this is malicious.

I investigated further into these IP addresses it seems to connect to. I didn't do them all yet but at least the one ESET found appears to be malicious according to Virustotal. See below.

Trojan5.thumb.png.c6e6a8e712256f9503d12fa6ab102124.png

Furthermore, the IP addresses Malwarebytes found seem to connect to Tencent Cloud Computing and appear to connect to a command & control server!
That report of it being a C2 server os from July 2024, so fairly recent this year! What the heck. I just wanted to play a stupid game..

Trojan6.thumb.png.80cf168a8ace81560aa5f600d82f8e72.png

What else happened?

As you can imagine at this point, I was beginning to feel mildly uneasy.
I checked the Task manager for strange processes and I was shocked to see that, while I NEVER use Microsoft Edge, there were 7 Edge processes running all of the sudden.
As time progressed (~10 minutes) this increased to 24 processes, see image below. What the heck?Trojan7.thumb.png.e7ff721e5efad64c1299d8dd36c9dc6c.png

How did I remediate?

Fortunately I always run a back-up every so many days.

1. The first thing I did was delete the Content Manager.exe (it was the only file). As well as the entire Steam folder. I also disconnected the internet connection.

2. I scanned the entire system at this point, both with ESET and MalwareBytes with aggressive detection settings. But everything seemed to be okay, no detections.

3. I assumed as there only seem to have been made connections made outwards (that were blocked by ESET and MalwareBytes) that there is likely no malware present.
Still, that Edge process thing remains weird.

4. So be sure I wiped my C:\ drive, did a full disk encryption and then wiped it again. So absolutely nothing remains, as it is encrypted and the encryption keys are then deleted.
I also have a second drive. But this case I think refers to a Trojan and I believe they can't self replicate like a virus does (correct me if I'm wrong, but the lack of detections seems that the executable was the main file doing the connecting.)

5. I restored the C drive from a state weeks back and everything is running smoothly again with minimal loss of data.
The Edge process thing has not reoccurred.

My question to you is, is my reasoning correct here? At first I thought false positive, but I still thought let's investigate.. And then all the above showed up.

Thanks for reading this far and for your thoughts on this matter.

Have a great day!

--Cybertr0nian

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...