Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I uploaded several of these virus-infected archives to VirusTotal. In each archive, under the “Network Communication” section, the virus makes requests to three resources: a GET request to a website to retrieve IP information, a POST request to a Polygon RPC node (drpc), and a POST request to what appears to be the virus creator’s server. I can only assume that the scheme is designed to steal cryptocurrency.
 help



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: