This all started after logging on with a friend ready to play games together (Arc Raiders).
Yet, somehow he was getting a lower FPS (Frames Per Second) count than normal and his game began to stutter.
At this point, I didn’t suspect anything. It wasn’t rare for him to forget to close another application or to never turn off his computer.
However, this time he took longer to resolve the problem: 1 min became two, then five, then ten.
Becoming impatient I asked him if he had downloaded anything on his computer recently.
And then the truth came out.
He downloaded cheats (for Roblox of all things). In his Words, “why not, they’re free”.
Already knowing what to expect, I ask him to open Task Manager.
And there it was, a random process maxing out his memory.
After some protesting, he gave in to my demands and ran a virus scanner, revealing the trojan he just unleashed on his computer. But of course, not before sending me a sample to take apart.
Below were my findings.
boxgroovyhands.exe
This seems like the classic "Getting Settled In" behaviour. Creating processes, covering up tracks, and discovering its new home.
** This isn't the first time I've reverse engineered malware, but since I began, I always learn a new trick to add to my future projects.
This is the first time I've seen the "time delay" method of obfuscation.
More discovery;I'm suprised it used a shotgun method finding files. Searching through commonly known directories until it finds a match.