{"id":227464,"date":"2026-03-18T11:21:55","date_gmt":"2026-03-18T18:21:55","guid":{"rendered":"https:\/\/www.mcafee.com\/blogs\/?p=227464"},"modified":"2026-03-18T11:21:55","modified_gmt":"2026-03-18T18:21:55","slug":"ai-written-malware-vibe-coded-campaign","status":"publish","type":"post","link":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ai-written-malware-vibe-coded-campaign\/","title":{"rendered":"AI Wrote This Malware: Dissecting the Insides of a Vibe-Coded Malware Campaign"},"content":{"rendered":"<p style=\"text-align: center;\"><em><span class=\"TextRun SCXW153759336 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW153759336 BCX0\">Authored by Aayush Tyagi\u00a0<\/span><\/span><span class=\"EOP SCXW153759336 BCX0\" data-ccp-props=\"{}\">\u00a0<\/span><\/em><\/p>\n<h2 aria-level=\"2\"><span data-contrast=\"none\">Background<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h2>\n<p><span data-contrast=\"auto\">The term \u2018Vibe coding,\u2019 first coined back in February of 2025 by OpenAI researchers, has exploded across digital platforms. With hundreds of articles and YouTube Videos discussing the dangers of Vibe coding and warning the internet about the rise of \u201cVibe Coders\u201d, while others labelled it as the fundamental shift in software development and the future of coding. <\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\"><strong>Vibe\u00a0Coding\u00a0is\u00a0an approach\u00a0where the\u00a0AI does\u00a0heavy\u00a0lifting, rather than the user<\/strong>. Instead of manually writing code or implementing algorithms, users describe their intent through text-based\u00a0prompt,\u00a0and the LLMs\u00a0respond\u00a0with\u00a0fully functional code\u00a0and\u00a0explanation.\u00a0Unsurprisingly, the internet is now flooded with guides on the best LLMs and prompts to generate \u201cperfect\u201d code.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Given the ease of generating fully functional code,\u00a0McAfee Labs\u00a0has\u00a0also seen a rise in vibe-coded malware. In these campaigns, certain components\u00a0of the kill chain\u00a0contain\u00a0AI-generated code, significantly reducing the effort\u00a0and knowledge\u00a0required\u00a0to execute new malware\u00a0campaigns.\u00a0This shift not only makes malware campaigns more scalable but also lowers the barrier to entry for new malware authors.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h2 aria-level=\"2\"><span data-contrast=\"none\">Executive summary<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h2>\n<p><span data-contrast=\"auto\">In January 2026,\u00a0<strong>McAfee Labs\u00a0observed\u00a0443\u00a0malicious\u00a0zip\u00a0files<\/strong> impersonating a wide range of software, including AI image generators and voice-changing tools, stock-market trading utilities, game mods and modding\u00a0tools, game hacks,\u00a0graphics card\u00a0and USB\u00a0drivers,\u00a0ransomware\u00a0decryptors,\u00a0VPNs,\u00a0emulators, and even infostealer, cookie-stealer, and backdoor malware, to infect users.\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\"><strong>Across the\u00a0440+ zip files, we\u00a0observed\u00a048\u00a0unique\u00a0malicious\u00a0WinUpdateHelper.dll\u00a0variants<\/strong>, responsible for the infections. <\/span><span data-contrast=\"auto\">McAfee\u00a0has been\u00a0detecting variants\u00a0of this threat\u00a0since\u00a0December\u00a02024,\u00a0although the vibe coding\u00a0observed\u00a0in certain components appears to be a recent addition.\u00a0These files are distributed through various legitimate\u00a0content delivery network (CDN)\u00a0services and file-hosting websites, such as Discord,\u00a0SourceForge,\u00a0FOSSHub, and MediaFire, to name a few. Another website that was actively delivering this malware was\u00a0mydofiles[.]com.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Here, the attackers implement volume-driven malware distribution techniques to infect as many users as possible.\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<figure id=\"attachment_227465\" aria-describedby=\"caption-attachment-227465\" style=\"width: 1024px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"size-large wp-image-227465\" src=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure1-1024x525.png\" alt=\"Figure 1: Attack Vector \" width=\"1024\" height=\"525\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure1-1024x525.png 1024w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure1-300x154.png 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure1-768x394.png 768w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure1-1536x787.png 1536w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure1-205x105.png 205w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure1.png 1584w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption id=\"caption-attachment-227465\" class=\"wp-caption-text\"><em>Figure 1: Attack Vector<\/em><\/figcaption><\/figure>\n<p><span data-contrast=\"auto\">This attack begins\u00a0when\u00a0users\u00a0surf\u00a0the internet looking for\u00a0tools and\u00a0software\u00a0that promise to simplify their tasks.\u00a0Instead,\u00a0they encounter\u00a0trojanized\u00a0zip files.\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">We discovered over 100 URLs actively spreading this malware, of which approximately 61 were hosted on Discord, 17 on\u00a0SourceForge, and 15 on\u00a0mydofiles[.]com.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">On running the\u00a0executable,\u00a0it loads a malicious\u00a0WinUpdateHelper.dll\u00a0file,\u00a0which\u00a0redirects the user to file-hosting websites, under the\u00a0disguise\u00a0that they are missing\u00a0crucial dependencies and\u00a0tricks\u00a0them\u00a0into installing\u00a0unrelated software, which is a distraction. Meanwhile,\u00a0the\u00a0DLL\u00a0has already requested and executed a malicious PowerShell script\u00a0from a\u00a0command-and-control (C2)\u00a0server.\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">This script\u00a0infects the user\u2019s\u00a0system\u00a0and\u00a0downloads\u00a0additional\u00a0mining software,\u00a0and\u00a0abuses\u00a0the system\u2019s resources,\u00a0or\u00a0it\u00a0downloads\u00a0additional\u00a0payloads such as\u00a0<\/span><i><span data-contrast=\"auto\">SalatStealer<\/span><\/i><span data-contrast=\"auto\">\u00a0or\u00a0<\/span><i><span data-contrast=\"auto\">Mesh Agent<\/span><\/i><span data-contrast=\"auto\">, depending on the\u00a0WinUpdateHelper.dll\u00a0sample which infected the user.\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">In this PowerShell script,\u00a0the presence of explanatory comments and\u00a0structured\u00a0sections strongly\u00a0indicates\u00a0the use\u00a0of\u00a0LLM models to generate this code.\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Read more\u00a0about\u00a0this\u00a0in\u00a0the\u00a0<\/span><em><strong>Using AI to generate malware?<\/strong><\/em><span data-contrast=\"auto\"> section below. <\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">So far,\u00a0we\u2019ve\u00a0observed\u00a0the mining of\u00a0<\/span><span data-contrast=\"auto\">Ravencoin<\/span><b><span data-contrast=\"auto\">,\u00a0<\/span><\/b><span data-contrast=\"auto\">Zephyr,\u00a0Monero, Bitcoin\u00a0Gold,\u00a0Ergo,\u00a0<\/span><span data-contrast=\"auto\">and<\/span><b><span data-contrast=\"auto\">\u00a0<\/span><\/b><span data-contrast=\"auto\">Clore<\/span><b><span data-contrast=\"auto\">\u00a0<\/span><\/b><span data-contrast=\"auto\">cryptocurrencies.\u00a0<\/span><b><span data-contrast=\"auto\">\u00a0\u00a0<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Due to the presence of hardcoded Bitcoin wallet credentials within these malware samples, we were able to trace on-chain transactions and\u00a0identify\u00a0wallets\u00a0containing\u00a0over $4,500\u00a0USD that are part of this campaign.\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Since most of the mining activity targets privacy-focused cryptocurrencies such as Zephyr,\u00a0<\/span><span data-contrast=\"auto\">Ravencoin<\/span><span data-contrast=\"auto\">\u00a0and Monero,\u00a0the real\u00a0financial impact\u00a0is likely\u00a0to be nearly\u00a0double the amount\u00a0identified\u00a0through Bitcoin tracing alone.\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h2 aria-level=\"2\"><span data-contrast=\"none\">Geographical Prevalence<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h2>\n<div class=\"wp-block-image\">\n<figure id=\"attachment_227480\" aria-describedby=\"caption-attachment-227480\" style=\"width: 963px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wpa-warning wpa-image-missing-alt wp-image-227480 size-full\" src=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure2.png\" alt=\"Figure\u00a02:\u00a0Geographical Prevalence\u202f\u00a0\" width=\"963\" height=\"524\" data-warning=\"Missing alt text\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure2.png 963w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure2-300x163.png 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure2-768x418.png 768w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure2-205x112.png 205w\" sizes=\"auto, (max-width: 963px) 100vw, 963px\" \/><figcaption id=\"caption-attachment-227480\" class=\"wp-caption-text\"><em>Figure\u00a02:\u00a0Geographical Prevalence\u202f\u00a0<\/em><\/figcaption><\/figure>\n<\/div>\n<p><span data-contrast=\"auto\">This malware campaign has\u00a0specifically targeted users in the following\u00a0counties,\u00a0ranked by\u00a0prevalence: The\u00a0United States of America,\u00a0followed by United Kingdom, India, Brazil, France,\u00a0Canada,\u00a0Australia.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h2><span data-contrast=\"none\">Bottom Line<\/span><\/h2>\n<p><span data-contrast=\"auto\">The availability of LLMs capable of generating code instantly, combined with the widespread accessibility of technical knowledge, has created a low-effort, high-reward environment,\u00a0making malware deployment increasingly accessible.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">At McAfee Labs, we have been doing\u00a0hard work\u00a0so that you\u00a0don\u2019t\u00a0need to worry. But it always helps to be informed\u00a0and\u00a0educated\u00a0on the latest threat\u00a0that steps into the threat landscape.\u00a0<\/span><br \/>\n<span data-contrast=\"auto\">We will continue\u00a0monitoring\u00a0these\u00a0campaigns to ensure our customers\u00a0remain\u00a0informed and protected across platforms.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h2 aria-level=\"2\"><span data-contrast=\"none\">Technical Analysis\u202f<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h2>\n<h3 aria-level=\"2\"><span data-contrast=\"none\">Impersonated Applications<\/span><\/h3>\n<p aria-level=\"2\"><span data-contrast=\"auto\">Here we see\u00a0malware distribution at a large scale\u00a0and\u00a0by analyzing\u00a0the filenames of\u00a0these\u00a0ZIP archives, we can\u00a0infer to\u00a0the users that are being targeted.\u00a0These are some of the names\u00a0we\u2019ve\u00a0witnessed\u00a0in the wild.<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/p>\n<figure id=\"attachment_227495\" aria-describedby=\"caption-attachment-227495\" style=\"width: 1024px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"size-large wp-image-227495\" src=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure3-1024x100.png\" alt=\"Figure 3: Malware Impersonating gaming software \" width=\"1024\" height=\"100\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure3-1024x100.png 1024w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure3-300x29.png 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure3-768x75.png 768w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure3-205x20.png 205w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure3.png 1244w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption id=\"caption-attachment-227495\" class=\"wp-caption-text\"><em>Figure 3: Malware Impersonating gaming software<\/em><\/figcaption><\/figure>\n<p><span data-contrast=\"auto\">The attackers\u00a0are actively\u00a0impersonating\u00a0video game cheats and game mods\u00a0for popular\u00a0titles,\u00a0and\u00a0well-known\u00a0script executors for Roblox, such as Delta Executor and Solara\u00a0as seen above.\u00a0<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/p>\n<figure id=\"attachment_227510\" aria-describedby=\"caption-attachment-227510\" style=\"width: 1024px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"size-large wp-image-227510\" src=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure4-1024x146.png\" alt=\"Figure 4: Malware Impersonating tools,\u00a0malware\u00a0and\u00a0drivers\u00a0\" width=\"1024\" height=\"146\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure4-1024x146.png 1024w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure4-300x43.png 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure4-768x110.png 768w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure4-205x29.png 205w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure4.png 1297w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption id=\"caption-attachment-227510\" class=\"wp-caption-text\"><em>Figure 4: Malware Impersonating tools,\u00a0malware\u00a0and\u00a0drivers<\/em><\/figcaption><\/figure>\n<p><span data-contrast=\"auto\">Names such\u00a0as\u00a0Panther-Stealer and\u00a0Zerotrace-Stealer\u00a0indicate\u00a0that\u00a0even\u00a0users looking for malware on the internet are not safe either,\u00a0reinforcing the notion that there is truly no honor among thieves.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">The campaign also\u00a0leverages\u00a0drivers and AI-themed tools as part of its lure portfolio\u00a0among other tools.\u00a0Interestingly,\u00a0we see the name \u2018DeepSeek.zip\u2019,\u00a0where\u00a0attackers are exploiting\u00a0a\u00a0prominent\u00a0LLM model,\u00a0DeepSeek.\u00a0McAfee had\u00a0encountered\u00a0these types of attacks\u00a0in early 2025\u00a0and covered them extensively.\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><strong>Read the\u00a0previous\u00a0blog here:\u00a0<a href=\"https:\/\/www.mcafee.com\/blogs\/internet-security\/deepseek-or-deep-threat-how-hackers-are-using-ai-hype-to-deliver-malware\/\" target=\"_blank\" rel=\"noopener\">Look Before You Leap: Imposter DeepSeek Software Seek Gullible Users<\/a>\u00a0\u00a0<\/strong><\/p>\n<h3><span data-contrast=\"none\">Stage 1 Payload\u00a0\u2013\u00a0Misleading Installation\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/h3>\n<p><span data-contrast=\"auto\">Once the user downloads\u00a0the\u00a0ZIP archive\u00a0from Discord or any other\u00a0website. They get the following set of files.<\/span><\/p>\n<figure id=\"attachment_227525\" aria-describedby=\"caption-attachment-227525\" style=\"width: 688px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-227525\" src=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure5.png\" alt=\"Figure\u00a05:\u00a0Files\u00a0within the zip archive.\u00a0\" width=\"688\" height=\"574\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure5.png 688w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure5-300x250.png 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure5-155x129.png 155w\" sizes=\"auto, (max-width: 688px) 100vw, 688px\" \/><figcaption id=\"caption-attachment-227525\" class=\"wp-caption-text\">Figure\u00a05:\u00a0Files\u00a0within the zip archive.<\/figcaption><\/figure>\n<p><span data-contrast=\"auto\">Here, the executable named \u2018<\/span><b><span data-contrast=\"auto\">gta-5-online-mod-menu.exe<\/span><\/b><span data-contrast=\"auto\">\u2019\u00a0(Highlighted in Blue)\u00a0is a\u00a0legitimate and\u00a0clean\u00a0file.\u00a0Whereas\u00a0the file named \u2018<\/span><b><span data-contrast=\"auto\">WinUpdateHelper.dll<\/span><\/b><span data-contrast=\"auto\">\u2019 (Highlighted in Red)\u00a0is\u00a0malicious.\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<figure id=\"attachment_227540\" aria-describedby=\"caption-attachment-227540\" style=\"width: 978px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-227540\" src=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure6.png\" alt=\"Figure 6:\u00a0Command\u00a0Prompt misinforming\u00a0the user\u00a0\" width=\"978\" height=\"430\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure6.png 978w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure6-300x132.png 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure6-768x338.png 768w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure6-205x90.png 205w\" sizes=\"auto, (max-width: 978px) 100vw, 978px\" \/><figcaption id=\"caption-attachment-227540\" class=\"wp-caption-text\"><em>Figure 6: Command Prompt misinforming the user<\/em><\/figcaption><\/figure>\n<p><span data-contrast=\"auto\">On executing \u2018<\/span><b><span data-contrast=\"auto\">gta-5-online-mod-menu.exe\u2019<\/span><\/b><span data-contrast=\"auto\">,\u00a0the\u00a0malicious DLL is loaded.\u00a0The\u00a0user\u00a0is informed\u00a0that they are missing\u00a0dependencies,\u00a0and\u00a0they\u2019re\u00a0redirected to the following URL\u00a0via default browser.\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><b><span data-contrast=\"auto\">hxxps:\/\/igk[.]filexspace.com\/getfile\/XKQLPSK?title=DependencyCore&amp;tracker=gta-5-online-mod-menu<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Here,\u00a0within the URL, a tracker variable is\u00a0used\u00a0to\u00a0identify\u00a0which\u00a0malware has infected the user. In this instance, it was\u00a0\u2018gta-5-online-mod-menu\u2019.\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<figure id=\"attachment_227555\" aria-describedby=\"caption-attachment-227555\" style=\"width: 932px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-227555\" src=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure7.png\" alt=\"Figure\u00a07:\u00a0Website prompting users to download dependencycore.zip\u00a0\" width=\"932\" height=\"687\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure7.png 932w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure7-300x221.png 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure7-768x566.png 768w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure7-175x129.png 175w\" sizes=\"auto, (max-width: 932px) 100vw, 932px\" \/><figcaption id=\"caption-attachment-227555\" class=\"wp-caption-text\"><em>Figure\u00a07:\u00a0Website prompting users to download dependencycore.zip<\/em><\/figcaption><\/figure>\n<p><span data-contrast=\"auto\">Dependecycore.zip\u00a0is a setup\u00a0file.\u00a0On execution, it installs unrelated 3<\/span><span data-contrast=\"auto\">rd<\/span><span data-contrast=\"auto\">\u00a0party software on the\u00a0victim\u2019s\u00a0system.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<figure id=\"attachment_227570\" aria-describedby=\"caption-attachment-227570\" style=\"width: 1024px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"size-large wp-image-227570\" src=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure8-1024x422.png\" alt=\"Figure\u00a08:\u00a0Files dropped by Dependecycore.zip in\u00a0temp\u00a0folder\u00a0\" width=\"1024\" height=\"422\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure8-1024x422.png 1024w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure8-300x124.png 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure8-768x316.png 768w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure8-1536x633.png 1536w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure8-205x84.png 205w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure8.png 1729w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption id=\"caption-attachment-227570\" class=\"wp-caption-text\"><em>Figure\u00a08:\u00a0Files dropped by Dependecycore.zip in\u00a0temp\u00a0folder<\/em><\/figcaption><\/figure>\n<p><span data-contrast=\"auto\">In this instance,\u00a0iTop\u00a0Easy Desktop was installed.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">This\u00a0unwanted\u00a0installation\u00a0is meant to\u00a0subvert users\u2019 attention. As,\u00a0the\u00a0WinUpdateHelper.dll\u00a0has already connected to the C2 server\u00a0and infected the system.\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h3><span data-contrast=\"none\">Stage 1 Payload\u00a0\u2013\u00a0Malicious Functionality\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/h3>\n<p><span data-contrast=\"auto\">Once the redirection code is executed, the\u00a0malware executes the malicious code.\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<figure id=\"attachment_227585\" aria-describedby=\"caption-attachment-227585\" style=\"width: 959px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-227585\" src=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure9.png\" alt=\"Figure\u00a09: Malicious code within\u00a0WinUpdateHelper.dll\u00a0\" width=\"959\" height=\"258\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure9.png 959w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure9-300x81.png 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure9-768x207.png 768w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure9-205x55.png 205w\" sizes=\"auto, (max-width: 959px) 100vw, 959px\" \/><figcaption id=\"caption-attachment-227585\" class=\"wp-caption-text\"><em>Figure\u00a09: Malicious code within\u00a0WinUpdateHelper.dll<\/em><\/figcaption><\/figure>\n<p><span data-contrast=\"auto\">In the above\u00a0code\u00a0snippet,\u00a0which is present in\u00a0the WinUpdateHelper.dll, we can see that a new service has been created under the name \u201c<\/span><b><span data-contrast=\"auto\">Microsoft Console Host<\/span><\/b><span data-contrast=\"auto\">\u201d to make it appear to be benign (Highlighted in Red). The parameters passed to this service ensure that it executes at system boot. This is done to maintain persistence in the system.<\/span><\/p>\n<p><span data-contrast=\"auto\">The service executes a PowerShell\u00a0command\u00a0that dynamically generates the C2 domain\u00a0using the UNIX time stamp.\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Using the following code,\u00a0<\/span><br \/>\n<b><span data-contrast=\"auto\">$([Math]::Floor([DateTimeOffset]::UtcNow.ToUnixTimeSeconds() \/ 5000000) * 5000000).xyz<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">It\u00a0generates a domain\u00a0name\u00a0that changes\u00a0once\u00a0every\u00a05,000,000 seconds or 58 days.\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">The latest C2 domain\u00a0we\u2019ve\u00a0discovered\u00a0that is up and running is\u00a0<\/span><br \/>\n<b><span data-contrast=\"auto\">1770000000[.]xyz\/script?id=fA9zQk2L0M&amp;tag=WinUpdateHelper<\/span><\/b><\/p>\n<p><span data-contrast=\"auto\">During\u00a0our\u00a0analysis we\u00a0observed\u00a0the following domain\u00a0<\/span><br \/>\n<b><span data-contrast=\"auto\">1765000000[.]xyz\/script?id=fA9zQk2L0M&amp;tag=WinUpdateHelper,\u00a0<\/span><\/b><span data-contrast=\"auto\">which is present in the following images.\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Here the\u00a0<\/span><b><span data-contrast=\"auto\">id=fA9zQk2L0M<\/span><\/b><span data-contrast=\"auto\">\u00a0is\u00a0randomly\u00a0generated, to\u00a0uniquely\u00a0identify\u00a0the\u00a0user\u00a0and\u00a0<\/span><b><span data-contrast=\"auto\">tag=WinUpdateHelper\u00a0<\/span><\/b><span data-contrast=\"auto\">is used to\u00a0identify\u00a0the malware campaign.\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">The\u00a0malware connects to the\u00a0above-mentioned\u00a0C2\u00a0server to download\u00a0a PowerShell\u00a0script and\u00a0execute\u00a0it in memory. This fileless execution ensures\u00a0improved evasion against\u00a0signature-based detections.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h3><span data-contrast=\"none\">Stage 2 Payload \u2013 PowerShell Script\u00a0<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true}\">\u00a0<\/span><\/h3>\n<figure id=\"attachment_227600\" aria-describedby=\"caption-attachment-227600\" style=\"width: 1024px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"size-large wp-image-227600\" src=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure10-1024x525.png\" alt=\"Figure\u00a010: PowerShell downloaded from the C2 server\u00a0\" width=\"1024\" height=\"525\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure10-1024x525.png 1024w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure10-300x154.png 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure10-768x394.png 768w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure10-205x105.png 205w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure10.png 1284w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption id=\"caption-attachment-227600\" class=\"wp-caption-text\"><em>Figure\u00a010: PowerShell downloaded from the C2 server<\/em><\/figcaption><\/figure>\n<p><span data-contrast=\"auto\">It is funny to note here, that the\u00a0first comment\u00a0of this script says\u00a0<\/span><b><span data-contrast=\"auto\">\u201c# I am forever sorry\u201d\u00a0<\/span><\/b><span data-contrast=\"auto\">which\u00a0indicates\u00a0that\u00a0the\u00a0attacks do carry some guilt\u00a0regarding\u00a0their actions, but not enough to\u00a0stop\u00a0the campaign. We found similar comments, such as\u00a0<\/span><b><span data-contrast=\"auto\">\u201c# sorry lol\u201d<\/span><\/b><span data-contrast=\"auto\">,\u00a0across multiple PowerShell scripts we\u00a0discovered.\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">The first set of commands (Highlighted in Green) are used to delete windows services and scheduled tasks. This is done to remove older or conflicting persistence mechanisms and to avoid duplicate miners from running on the same system.\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">The second set of commands (Highlighted in Red) are\u00a0registry modifications, that adds\u00a0<\/span><b><span data-contrast=\"auto\">\u201cC:\\ProgramData\u201d<\/span><\/b><span data-contrast=\"auto\">\u00a0to\u00a0Windows Defender exclusion paths.\u00a0That is,\u00a0ProgramData\u00a0Folder\u00a0won\u2019t\u00a0be scanned by Windows Defender\u00a0anymore. This exclusion allows malware to drop\u00a0additional\u00a0payloads\u00a0to disk, without the\u00a0risk\u00a0of them being detected and removed.\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">The third set of commands (Highlighted in Blue)\u00a0does exactly that.\u00a0It downloads\u00a0the\u00a0next level payload from the URL\u00a0<\/span><b><span data-contrast=\"auto\">\u201chxxps:\/\/1765000000[.]xyz\/download\/xbhgjahddaa&#8221;\u00a0<\/span><\/b><span data-contrast=\"auto\">and stored it\u00a0at this path\u00a0<\/span><b><span data-contrast=\"auto\">\u201cC:\\ProgramData\\fontdrvhost.exe\u201d<\/span><\/b><span data-contrast=\"auto\">.<\/span><\/p>\n<p><span data-contrast=\"auto\">Again the name\u00a0<\/span><b><span data-contrast=\"auto\">\u2018fontdrvhost.exe\u2019<\/span><\/b><span data-contrast=\"auto\">\u00a0imitates a legitimate Windows binary, to masquerade its true intent.\u00a0After the download, the file is\u00a0decoded\u00a0using a simple arithmetic\u00a0decryption routine. This provides protection\u00a0against static signature detection and network detection.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">The payload\u00a0is\u00a0an XMRIG\u00a0miner\u00a0sample.\u00a0In the next command, the miner is\u00a0initialized and executed.\u00a0Here, we see the\u00a0miner connecting to\u00a0\u201c<\/span><b><span data-contrast=\"auto\">solo-zeph.2miners.com:4444<\/span><\/b><span data-contrast=\"auto\">\u201d and start CPU based\u00a0<\/span><b><span data-contrast=\"auto\">Zephyr coin<\/span><\/b><span data-contrast=\"auto\">\u00a0mining\u00a0using the following wallet address:<\/span><b><span data-contrast=\"auto\"> \u2018ZEPHsCY4zbcHGgz2U8PvkEjkWjopuPurPNv8nnSFnM5MN8hBas8kBN4ho<\/span><\/b><b><span data-contrast=\"auto\">NKmc7uMRfUQh4Fc9AHyGxL6NFARnc217m2vYgbKxf\u2019<\/span><\/b><span data-contrast=\"auto\">.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<figure id=\"attachment_227615\" aria-describedby=\"caption-attachment-227615\" style=\"width: 1024px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"size-large wp-image-227615\" src=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure11-1024x381.png\" alt=\"Figure\u00a011: PowerShell downloaded from the C2 server continued\u00a0\u00a0\" width=\"1024\" height=\"381\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure11-1024x381.png 1024w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure11-300x112.png 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure11-768x286.png 768w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure11-205x76.png 205w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure11.png 1225w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption id=\"caption-attachment-227615\" class=\"wp-caption-text\">Figure 11: PowerShell downloaded from the C2 server continued<\/figcaption><\/figure>\n<p><span data-contrast=\"auto\">In the second half of the script, we see another miner being\u00a0set up\u00a0and executed\u00a0using the same technique\u00a0(Highlighted in Red).\u00a0This time\u00a0the file is stored as\u00a0<\/span><b><span data-contrast=\"auto\">\u201cRuntimeBroker.exe\u201d\u00a0<\/span><\/b><span data-contrast=\"auto\">in the\u00a0ProgramData\u00a0folder.\u00a0The miner is connecting to\u00a0<\/span><b><span data-contrast=\"auto\">\u201csolo-rvn.2miners.com:7070\u201d\u00a0<\/span><\/b><span data-contrast=\"auto\">to mine\u00a0<\/span><b><span data-contrast=\"auto\">Ravencoin\u00a0<\/span><\/b><span data-contrast=\"auto\">and\u00a0it\u00a0is\u00a0using\u00a0the system\u2019s\u00a0GPU instead of the CPU for mining\u00a0(Highlighted in Blue).\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">This is the wallet address used for mining in this instance <\/span><b><span data-contrast=\"auto\">\u2018bc1q9a59scnfwkdlm6wlcu5w76zm2uesjrqdy4fr8r\u2019.\u00a0<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Hence,\u00a0we see a dual coin-mining\u00a0deployment\u00a0infrastructure\u00a0utilizing\u00a0both CPU and GPU\u00a0resources\u00a0to\u00a0optimize\u00a0mining efficiency.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h2 aria-level=\"2\"><span data-contrast=\"none\">Bitcoin?\u00a0<\/span><span data-contrast=\"none\">Interesting&#8230;\u00a0<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h2>\n<p><span data-contrast=\"auto\">What is interesting here is that attackers have used a bitcoin\u00a0wallet address for mining\u00a0Ravencoin, which\u00a0indicates\u00a0they are\u00a0using multi-coin pools for mining.\u00a0The attackers are using the\u00a0victims&#8217;\u00a0machine to mine\u00a0Ravencoin\u00a0and\u00a0automatically\u00a0convert\u00a0the mining rewards to\u00a0Bitcoin before\u00a0the\u00a0payout.\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">This is done for a variety of reasons, such as, bitcoin offers higher liquidity and has\u00a0broader acceptance, but most importantly,\u00a0Ravencoin\u00a0is computationally easier and economically\u00a0viable\u00a0to mine on victim\u2019s system.\u00a0Bitcoin\u00a0requires specialized\u00a0ASIC hardware\u00a0for profitable mining\u00a0and\u00a0attempting\u00a0to mine Bitcoin directly on infected systems would generate negligible returns.\u00a0We\u2019ve\u00a0seen the same\u00a0behaviour\u00a0in multiple samples.\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">This is\u00a0a\u00a0smoking gun.\u00a0Unlike Zephyr coin\u00a0or Monero,\u00a0Bitcoin\u2019s blockchain is fully traceable.\u00a0Every Satoshi, the smallest unit of Bitcoin,\u00a0can be traced across the blockchain from the moment it was mined to its current holder.\u00a0From there, it becomes easy to\u00a0determine\u00a0how much cryptocurrency the threat actor is receiving.\u00a0More on this later.\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h2 aria-level=\"2\"><span data-contrast=\"none\">Anti-Analysis Techniques<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h2>\n<p><span data-contrast=\"auto\">The attackers\u00a0have\u00a0meticulously designed the campaign and\u00a0have\u00a0implemented various anti-analysis techniques to\u00a0thwart researchers.\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">The PowerShell\u00a0script\u00a0we\u2019ve\u00a0seen\u00a0above\u00a0is responsible for\u00a0downloading and\u00a0initializing the coin miner samples.\u00a0It is only accessible\u00a0via PowerShell.\u00a0If we try to access the server via\u00a0Curl, we get the following response.\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<figure id=\"attachment_227630\" aria-describedby=\"caption-attachment-227630\" style=\"width: 560px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-227630\" src=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure12.png\" alt=\"Figure 12:\u00a0301 Response from the server\u00a0\" width=\"560\" height=\"177\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure12.png 560w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure12-300x95.png 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure12-205x65.png 205w\" sizes=\"auto, (max-width: 560px) 100vw, 560px\" \/><figcaption id=\"caption-attachment-227630\" class=\"wp-caption-text\"><em>Figure 12:\u00a0301 Response from the server<\/em><\/figcaption><\/figure>\n<p><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;335551550&quot;:2,&quot;335551620&quot;:2}\">\u00a0<\/span><span data-contrast=\"auto\">This\u00a0indicates\u00a0that the server is actively\u00a0monitoring\u00a0the\u00a0User-Agent\u00a0of\u00a0incoming\u00a0requests\u00a0and deploys the payload only when the request originates from PowerShell.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-ccp-props=\"{}\">\u00a0<\/span><span data-contrast=\"auto\">Similarly, the URLs\u00a0embedded within\u00a0the PowerShell script that\u00a0download\u00a0the\u00a0next\u00a0payload\u00a0are unique to\u00a0each\u00a0victim and\u00a0remain\u00a0active for 60 seconds.\u00a0After that, they return a 404 Not Found error.\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<figure id=\"attachment_227645\" aria-describedby=\"caption-attachment-227645\" style=\"width: 484px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-227645\" src=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure13.png\" alt=\"Figure 13:\u00a0URLs within the PowerShell\u00a0\" width=\"484\" height=\"69\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure13.png 484w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure13-300x43.png 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure13-205x29.png 205w\" sizes=\"auto, (max-width: 484px) 100vw, 484px\" \/><figcaption id=\"caption-attachment-227645\" class=\"wp-caption-text\"><em>Figure 13: URLs within the PowerShell<\/em><\/figcaption><\/figure>\n<p><span data-contrast=\"auto\">These techniques are meant to\u00a0confuse and\u00a0disorient researchers, making the analysis difficult.\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h2 aria-level=\"2\"><span data-contrast=\"none\">Using AI to generate malware?\u00a0<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h2>\n<p><span data-contrast=\"auto\">While working\u00a0on this malware campaign, we came across over 440 unique zip files.\u00a0These same zip files were\u00a0distributed\u00a0with over 1700 different names, targeting various software.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Across these\u00a0440 zip files, we noticed\u00a048 unique variants of\u00a0WinUpdateHelper.dll.\u00a0These 48 files can be\u00a0clustered\u00a0together into\u00a017\u00a0distinct kill chains, each\u00a0featuring\u00a0their own\u00a0C2\u00a0infrastructure,\u00a0misleading installation setups,\u00a0second-stage PowerShell scripts\u00a0and final payloads,\u00a0yet the\u00a0cryptocurrency wallet credentials\u00a0remain\u00a0similar.\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">In the above technical analysis,\u00a0we\u2019ve\u00a0only covered 1 kill chain.\u00a0Yet, across these 17 kill chains,\u00a0we\u2019ve\u00a0noticed the\u00a0flow remain the same.\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<figure id=\"attachment_227660\" aria-describedby=\"caption-attachment-227660\" style=\"width: 1024px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"size-large wp-image-227660\" src=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure14-1024x434.png\" alt=\"Figure 14:\u00a0PowerShell Script with LLM-Generated Comments\u00a0\" width=\"1024\" height=\"434\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure14-1024x434.png 1024w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure14-300x127.png 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure14-768x326.png 768w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure14-205x87.png 205w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure14.png 1450w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption id=\"caption-attachment-227660\" class=\"wp-caption-text\"><em>Figure 14:\u00a0PowerShell Script with LLM-Generated Comments<\/em><\/figcaption><\/figure>\n<blockquote><p><span data-contrast=\"auto\">Across multiple second stage payloads, we\u00a0encounter\u00a0multiple comments such as\u00a0the following,\u00a0embedded\u00a0within the code:<\/span><\/p>\n<p><b><span data-contrast=\"auto\"># === Create and execute run.bat in C:\\ProgramData ===<\/span><\/b><\/p>\n<p><b><span data-contrast=\"auto\">::\u00a0This batch file:<\/span><\/b><\/p>\n<p><b><span data-contrast=\"auto\">::\u00a0&#8211; Creates the hidden folder C:\\ProgramData\\cvtres if it\u00a0doesn&#8221;t\u00a0exist (using CMD\u00a0attrib\u00a0for hidden + system)<\/span><\/b><\/p>\n<p><b><span data-contrast=\"auto\">::\u00a0&#8211; Downloads cvtres.exe from your GitHub URL<\/span><\/b><\/p>\n<p><b><span data-contrast=\"auto\">::\u00a0&#8211; Saves it to C:\\ProgramData\\cvtres\\cvtres.exe<\/span><\/b><\/p>\n<p><b><span data-contrast=\"auto\">::\u00a0&#8211; Executes it\u00a0immediately<\/span><\/b><\/p>\n<p><b><span data-contrast=\"auto\">::\u00a0&#8211; Runs completely hidden\/minimized (no window visible)<\/span><\/b><\/p><\/blockquote>\n<p><span data-contrast=\"auto\">The presence of such explanatory-style comments\u00a0indicates\u00a0that large language models were\u00a0likely used\u00a0during the development of these scripts.\u00a0Especially, the\u00a0comment \u201c<\/span><b><span data-contrast=\"auto\">Downloads cvtres.exe from your GitHub URL\u201d,\u00a0<\/span><\/b><span data-contrast=\"auto\">where \u2018<\/span><b><span data-contrast=\"auto\">Your GitHub URL<\/span><\/b><span data-contrast=\"auto\">\u2019 refers to the threat actor\u2019s GitHub repository that is hosting the\u00a0malware,\u00a0which\u00a0indicates\u00a0potential vibe coding.\u00a0<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<h2 aria-level=\"2\"><span data-contrast=\"none\">Tracking Bitcoin Across the Blockchain<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h2>\n<p><span data-contrast=\"auto\">During analysis of\u00a0this malware campaign, we came across\u00a0few\u00a0instances where the final payload\u00a0was\u00a0Infostealer malware.\u00a0In most cases it was coin miner samples.\u00a0<\/span><br \/>\n<span data-contrast=\"auto\">In these cases, we\u00a0encountered\u00a0wallet credentials and mining pool URLs\u00a0for several alternative cryptocurrencies\u00a0such as\u00a0<\/span><span data-contrast=\"auto\">Ravencoin<\/span><b><span data-contrast=\"auto\">,\u00a0<\/span><\/b><span data-contrast=\"auto\">Zephyr,\u00a0Monero, which\u00a0aren\u2019t\u00a0traceable.\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Fortunately, we came across 7 bitcoin wallets that are part of this malware campaign and are actively receiving mined cryptocurrency.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<blockquote><p><b><span data-contrast=\"auto\">bc1q9a59scnfwkdlm6wlcu5w76zm2uesjrqdy4fr8r\u00a0\u00a0\u00a0\u00a0 bc1q7cpwxjatrtpa29u85tayvggs67f6fxwyggm8kd<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><b><span data-contrast=\"auto\">bc1qyy0cv8snz7zqummg0yucdfzpxv2a5syu7xzsdq\u00a0\u00a0\u00a0 bc1qxhp6mn0h7k9r89w8amalqjn38t4j5yaa7t89rp<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><b><span data-contrast=\"auto\">bc1qxnkkpnuhydckmpx8fmkp73e38dfed93uhfh68l\u00a0\u00a0\u00a0 bc1qrtztxnqnjk9q4d5hupnla245c7620ncj3tzp7h<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><b><span data-contrast=\"auto\">bc1q97yd574m9znar99fa0u799rvm55tnjzkw9l33w<\/span><\/b><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p><\/blockquote>\n<p><span data-contrast=\"auto\">As\u00a0of\u00a0writing this blog, these wallets\u00a0contain\u00a0Bitcoin valued at approximately $4,536.20 USD.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<div class=\"wp-block-image\">\n<figure id=\"attachment_227675\" aria-describedby=\"caption-attachment-227675\" style=\"width: 922px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wpa-warning wpa-image-missing-alt wp-image-227675 size-full\" src=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure15.png\" alt=\"Figure 15:\u00a0Wallet Snapshot\u00a0displaying the total value\u00a0\u00a0\" width=\"922\" height=\"637\" data-warning=\"Missing alt text\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure15.png 922w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure15-300x207.png 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure15-768x531.png 768w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2026\/03\/figure15-187x129.png 187w\" sizes=\"auto, (max-width: 922px) 100vw, 922px\" \/><figcaption id=\"caption-attachment-227675\" class=\"wp-caption-text\"><em>Figure 15:\u00a0Wallet Snapshot\u00a0displaying the total value\u00a0\u00a0<\/em><\/figcaption><\/figure>\n<\/div>\n<p><span data-contrast=\"auto\">These wallets have seen regular withdrawals,\u00a0with\u00a0total\u00a0funds\u00a0received amounting to\u00a0approximately $11,497.7\u00a0USD.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h2 aria-level=\"2\"><span data-contrast=\"none\">McAfee Coverage<\/span><span data-contrast=\"none\">\u202f<\/span><\/h2>\n<p aria-level=\"2\"><span data-contrast=\"auto\">McAfee has extensive coverage\u00a0for this\u00a0Coinminer\u00a0Malware Campaign.\u00a0We\u2019re\u00a0proactively covering new\u00a0samples\u00a0observed\u00a0in the wild.<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Trojan:Win\/Phishing.AP<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Trojan:Script\/Coinminer.AT<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Trojan:Win\/Dropper.AT<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h2 aria-level=\"2\"><span data-contrast=\"none\">Indicator of Compromise(s)<\/span><\/h2>\n<table style=\"font-weight: 400; height: 12550px;\" width=\"622\" data-tablestyle=\"MsoTableGrid\" data-tablelook=\"1536\" aria-rowcount=\"193\">\n<tbody>\n<tr aria-rowindex=\"1\">\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">File Type<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">SHA256\/URLs<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">File Name<\/span><\/b><span data-ccp-props=\"{&quot;335559731&quot;:720}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"2\">\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">SHA256<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">94de957259c8e23f635989dd793cd<\/span><\/p>\n<p><span data-contrast=\"none\">fd058883834672b2c8ac0a3e80784fce819<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">WinUpdateHelper.dll<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"3\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">db8afdafbe39637fec3572829dd0a<\/span><\/p>\n<p><span data-contrast=\"none\">1a2f00c9b50f947f1eb544ede75e499dca7<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">WinUpdateHelper.dll<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"4\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">f15098661d99a436c460f8a6f839<\/span><\/p>\n<p><span data-contrast=\"none\">a6903aebd2d8f1445c3bccfc9bf64868f3b0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">WinUpdateHelper.dll<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"5\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">3abf66e0a886ec0454d0382369dd6<\/span><\/p>\n<p><span data-contrast=\"none\">d23c036c0dd5d413093c16c43c72b8ccb0b<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">WinUpdateHelper.dll<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"6\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">767b63d11cee8cfb401a9b72d7bcc<\/span><\/p>\n<p><span data-contrast=\"none\">a23b949149f2a9d7456e6e16553afcef169<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">WinUpdateHelper.dll<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"7\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">12850f78fc497e845e9bf9f10314c4ecc<\/span><\/p>\n<p><span data-contrast=\"none\">6a659dcd90e79ef5bd357004021ba78<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">WinUpdateHelper.dll<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"8\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">0a8a58d18adc86977b7386416c6be8db<\/span><\/p>\n<p><span data-contrast=\"none\">850a3384949b6750a6c6b2136138684a<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">WinUpdateHelper.dll<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"9\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">1a60852904ff9c710cd754fa187ce58cb18c69<\/span><\/p>\n<p><span data-contrast=\"none\">e35ea4962a8639953abe380f64<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">WinUpdateHelper.dll<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"10\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">4ab63b5ccd60dfd66c7510d1b3bc1f45f0<\/span><\/p>\n<p><span data-contrast=\"none\">c31c2d4c16b63b523d05ccac3fcb9d<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">WinUpdateHelper.dll<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"11\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">1390e61a45dd81fa245a3078a3b305<\/span><\/p>\n<p><span data-contrast=\"none\">e3c7cdeb5fa1e63d9daca22096b699f9e8<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">WinUpdateHelper.dll<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"12\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">a0c3de95e5bf84cb616fe1ee1791e96ff57<\/span><\/p>\n<p><span data-contrast=\"none\">53778b36201610e6730d025a6cb12<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">WinUpdateHelper.dll<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"13\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">ea65298d8d8ce4b868511a1026f8657abcc<\/span><\/p>\n<p><span data-contrast=\"none\">6b2e333854f4fc1bd498463b24084<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">WinUpdateHelper.dll<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"14\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">6ea34fd213674f31a83c0eee2fb521303d2<\/span><\/p>\n<p><span data-contrast=\"none\">a7c23e324bbdfa1a8edd7b6b6b6f1<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">WinUpdateHelper.dll<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"15\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">7bec5e37777e6a2ca50e765b07e8cb<\/span><\/p>\n<p><span data-contrast=\"none\">65e88f4822ab19d98c32f1c69444228e5c<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">WinUpdateHelper.dll<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"16\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">64c96f0251363aaf35c3709c134aab52b9<\/span><\/p>\n<p><span data-contrast=\"none\">81508b0ce9445e42774d151e43686b<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">WinUpdateHelper.dll<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"17\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">393f6c6b307aecfe46acc603da812cc17f<\/span><\/p>\n<p><span data-contrast=\"none\">0ebf24b66632660a2e533dfa4f463f<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">WinUpdateHelper.dll<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"18\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">94077065d049e821803986316408b<\/span><\/p>\n<p><span data-contrast=\"none\">82edad43fcd5a154f6807b4382eece705c3<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">WinUpdateHelper.dll<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"19\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">a206ff592aea155d2bb42231afc3f060<\/span><\/p>\n<p><span data-contrast=\"none\">494ffa8f3de8f25aaf8881639c500b44<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">WinUpdateHelper.dll<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"20\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">cb2eebf27def80261eef6b80d898e06<\/span><\/p>\n<p><span data-contrast=\"none\">f443294371463accd45ca24ce132fad98<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">WinUpdateHelper.dll<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"21\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">3fea0a031ffd78c8d08f6499c2bbc<\/span><\/p>\n<p><span data-contrast=\"none\">6a9edac5dc88b9ba224921f8f142e5a9adb<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">WinUpdateHelper.dll<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"22\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">4fe5d461aaa752b94d016ca4e742e<\/span><\/p>\n<p><span data-contrast=\"none\">02d30d3d4848a32787ce3564b5393017d77<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">WinUpdateHelper.dll<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"23\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">04399f9f3ef87d8dd15556628532a84<\/span><\/p>\n<p><span data-contrast=\"none\">d63d628eaae0ed81166d6efbee428cdba<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">WinUpdateHelper.dll<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"24\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">dd37cd62fa18af798018a706f20a91a537f<\/span><\/p>\n<p><span data-contrast=\"none\">0993f0254a0c84d64097c6480afb2<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">WinUpdateHelper.dll<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"25\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">1d85ffe28d065780c9327078941cb76<\/span><\/p>\n<p><span data-contrast=\"none\">2915<\/span><span data-contrast=\"none\">c69c69012303e45eee44c092f8046<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">WinUpdateHelper.dll<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"26\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">86e14dd0ab29ee0eab21874811b7e4<\/span><\/p>\n<p><span data-contrast=\"none\">50d609f<\/span><span data-contrast=\"none\">eb606f77206627b62cccbd58afa<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">WinUpdateHelper.dll<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"27\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">17704d58fb9c4e68c54a56fa97cd32599<\/span><\/p>\n<p><span data-contrast=\"none\">792d00<\/span><span data-contrast=\"none\">da53691b8bdb58e49296b7feb<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">WinUpdateHelper.dll<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"28\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">491019e31af8f1489aea8d4c0f9816<\/span><\/p>\n<p><span data-contrast=\"none\">813698def0<\/span><span data-contrast=\"none\">301a2abb88e5248b37753d2b<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">WinUpdateHelper.dll<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"29\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">c0ab89c3d9c7b9a04df5169eb175d517<\/span><\/p>\n<p><span data-contrast=\"none\">3c6<\/span><span data-contrast=\"none\">de08a4ef3674cd6d7f9a925d63151<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">WinUpdateHelper.dll<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"30\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">df0ca0f15926964040bb43978f97faccc0<\/span><\/p>\n<p><span data-contrast=\"none\">0bae5f6a00d8bd7d105d8c7d32efb1<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">WinUpdateHelper.dll<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"31\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">e40f2628b2981226b1afe16c1cf3796b94<\/span><\/p>\n<p><span data-contrast=\"none\">82b2ac070adac999707fc09909327c<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">WinUpdateHelper.dll<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"32\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">f6093084196acded1179d3a1466908beb<\/span><\/p>\n<p><span data-contrast=\"none\">966dceaba03e1dfeb02a2628fdb0423<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">WinUpdateHelper.dll<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"33\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">fcc512630ee95d3f4c31e3aabc75ad2e29<\/span><\/p>\n<p><span data-contrast=\"none\">dfacb4d4bcce7a12abe9a516979dbd<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">WinUpdateHelper.dll<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"34\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">fe02d8d7a6b8f66624b238665d63094<\/span><\/p>\n<p><span data-contrast=\"none\">a2bcd19c44a3f9c449788cadbb1b741a6<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">WinUpdateHelper.dll<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"35\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">1967f6f42710b43506a0784a28ca8785a<\/span><\/p>\n<p><span data-contrast=\"none\">f91b84dfa8629ec5be92be8eec564c6<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">WinUpdateHelper.dll<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"36\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">5280b0ecb6c7246db84a9b194f5c85cc3<\/span><\/p>\n<p><span data-contrast=\"none\">03c028475900b558306fdd4e51f4fc3<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">WinUpdateHelper.dll<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"37\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">ce06d83adb53c8b9d240202193ca4c04d<\/span><\/p>\n<p><span data-contrast=\"none\">0163994dad707aed0f0e67fdd2a42fe<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">WinUpdateHelper.dll<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"38\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">13976bdc28d3b3ae88ed92fcf49ff9e083b<\/span><\/p>\n<p><span data-contrast=\"none\">0ce5fd53e60680df00cd92bdfb33b<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">WinUpdateHelper.dll<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"39\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">4135754b26dfac10cd19dcf6e03677b53<\/span><\/p>\n<p><span data-contrast=\"none\">7244cf69fdce9c4138589e59449b443<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">WinUpdateHelper.dll<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"40\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">7d69eca36c0f69b3007cdbf908f15545<\/span><\/p>\n<p><span data-contrast=\"none\">e95611acf4bad8b9e30e54687a6d33bb<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">WinUpdateHelper.dll<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"41\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">085dc279b422d761729374b01eae1e2<\/span><\/p>\n<p><span data-contrast=\"none\">2375ef9538a6c4bc7cc35e8a812450f93<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">WinUpdateHelper.dll<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"42\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">99ff2045d1377db7342420160eb254b7<\/span><\/p>\n<p><span data-contrast=\"none\">b09cc4ce41a97b6bf0ec4d3f65d9ede6<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">WinUpdateHelper.dll<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"43\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">396f397099a459f3adeba057788aa3d3488<\/span><\/p>\n<p><span data-contrast=\"none\">2eea7d1665c828449f205a86dc80f<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">WinUpdateHelper.dll<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"44\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">908d35e6afd90da2e7c71cf82c8a61b5534<\/span><\/p>\n<p><span data-contrast=\"none\">10ca920e67dba1bae35c2b6b19bad<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">WinUpdateHelper.dll<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"45\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">7029d68969814f1473e4e4a22abd4be8<\/span><\/p>\n<p><span data-contrast=\"none\">5678a03bbe4c0f6194f3b7e421872ab3<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">WinUpdateHelper.dll<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"46\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">d3ba17aa83748c539c75cee7eedb03a4<\/span><\/p>\n<p><span data-contrast=\"none\">83<\/span><span data-contrast=\"none\">f2e86af10b69da3f0c8e549f014ac3<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">WinUpdateHelper.dll<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"47\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">d758820962ead89d5eaf7e45930a5eb<\/span><\/p>\n<p><span data-contrast=\"none\">6ab<\/span><span data-contrast=\"none\">11d5508988087faf84d8d7524408f1<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">WinUpdateHelper.dll<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"48\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">e863f45099f3dc057a5aee5990fabfb4<\/span><\/p>\n<p><span data-contrast=\"none\">e8ea8849cd5bc895092ff0a305a3f85d<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">WinUpdateHelper.dll<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"49\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">0db26e9a1213d09521fc0dbfe15f807c9<\/span><\/p>\n<p><span data-contrast=\"none\">960f62bc1cf4071001f58f210c53e9c<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">WinUpdateHelper.dll<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"50\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">94de957259c8e23f635989dd793cdfd<\/span><\/p>\n<p><span data-contrast=\"none\">058883834672b2c8ac0a3e80784fce819<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">WinUpdateHelper.dll<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"51\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"52\">\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">C2 URLs\u00a0<\/span><\/b><span data-ccp-props=\"{&quot;469777462&quot;:[915],&quot;469777927&quot;:[0],&quot;469777928&quot;:[1]}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">hxxp:\/\/85[.]235[.]75[.]242\/script[.]ps11<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:278}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"53\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">hxxp:\/\/41[.]216[.]188[.]184\/downloads\/loader[.]ps1\u00a0<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:278}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"54\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">hxxp:\/\/46[.]151[.]182[.]238:6969\/script\u00a0<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:278}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"55\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">hxxps:\/\/mydofiles[.]com\/script[.]ps1<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:278}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"56\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">hxxp:\/\/45[.]141[.]119[.]191\/jjj[.]txt\u00a0<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:278}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"57\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">hxxps:\/\/getthishasg[.]live\/cz8wl3k[.]php?<\/span><\/p>\n<p><span data-contrast=\"none\">cnv_id=cee43wfhqb7b81&amp;payout=1\u00a0<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:278}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"58\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">hxxps:\/\/gocrazy[.]gg\/script?id=fA9z<\/span><\/p>\n<p><span data-contrast=\"none\">Qk2L0M`&amp;tag=schtasks<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:278}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"59\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">hxxps:\/\/dystoria[.]cc\/mon<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:278}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"60\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">hxxp:\/\/85[.]235[.]75[.]242\/script[.]ps1<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:278}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"61\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">hxxps:\/\/github[.]com\/dextamoggan4-sudo\/<\/span><\/p>\n<p><span data-contrast=\"none\">shineex\/releases\/download\/python\/script[.]ps1<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:278}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"62\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">hxxp:\/\/45[.]141[.]119[.]191\/gg[.]txt<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:278}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"63\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">hxxps:\/\/codeberg[.]org\/Yesdev123\/<\/span><\/p>\n<p><span data-contrast=\"none\">load\/raw\/branch\/main\/testfile[.]txt<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:278}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"64\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">hxxp:\/\/45[.]141[.]119[.]191\/jjjj[.]tt<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:278}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"65\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">hxxps:\/\/kenovn[.]net\/script<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:278}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"66\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">hxxps:\/\/1765000000[.]xyz\/script?<\/span><\/p>\n<p><span data-contrast=\"none\">id=fA9zQk2L0M&amp;tag=WinUpdateHelper<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:278}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"67\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">hxxp:\/\/46[.]151[.]182[.]238:6969\/scrpt<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:278}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"68\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">hxxp:\/\/46[.]151[.]182[.]238:6969\/script<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:278}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"69\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">hxxps:\/\/cutt[.]ly\/ke0WRr70<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:278}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"70\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">hxxps:\/\/cutt[.]ly\/pe0WRidw<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:278}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"71\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">hxxps:\/\/1770000000[.]xyz\/script?id<\/span><\/p>\n<p><span data-contrast=\"none\">=fA9zQk2L0M&amp;tag=WinUpdateHelper<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:278}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"72\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">hxxp:\/\/150[.]241[.]64[.]28\/panfish\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"73\">\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">Final Payload URLs<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">hxxps:\/\/github[.]com\/gaescmo-ai\/justin\/<\/span><\/p>\n<p><span data-contrast=\"none\">releases\/download\/son\/xmrig[.]exe<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:278}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"74\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">hxxps:\/\/github[.]com\/gaescmo-ai\/justin\/<\/span><\/p>\n<p><span data-contrast=\"none\">releases\/download\/son\/ethminer[.]exe<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:278}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"75\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">hxxp:\/\/41[.]216[.]188[.]184\/downloads<\/span><\/p>\n<p><span data-contrast=\"none\">\/windows-service[.]zip\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"76\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">hxxp:\/\/46[.]151[.]182[.]238:6969\/exe\/rat[.]exe<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"77\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">hxxp:\/\/46[.]151[.]182[.]238:6969\/exe\/miner[.]exe<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"78\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">hxxp:\/\/46[.]151[.]182[.]238:6969\/exe\/titledetector[.]exe<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:278}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"79\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">hxxps:\/\/github[.]com\/jimbrock44\/filezilla2025\/<\/span><\/p>\n<p><span data-contrast=\"none\">raw\/refs\/heads\/main\/sc[.]msi<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:278}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"80\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">hxxps:\/\/github[.]com\/softwarelouv\/software\/<\/span><\/p>\n<p><span data-contrast=\"none\">raw\/refs\/heads\/main\/scvhosts[.]exe<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:278}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"81\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">hxxps:\/\/github[.]com\/softwarelouv\/software\/<\/span><\/p>\n<p><span data-contrast=\"none\">raw\/refs\/heads\/main\/cvtres[.]exe<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:278}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"82\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">hxxp:\/\/109[.]120[.]177[.]217:8082\/download<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:278}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"83\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">hxxp:\/\/45[.]141[.]119[.]191\/fontdrvhost[.]exe<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:278}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"84\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">hxxps:\/\/codeberg[.]org\/Yesdev123\/load\/raw\/<\/span><\/p>\n<p><span data-contrast=\"none\">branch\/main\/source[.]exe<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:278}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"85\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">hxxps:\/\/1765000000[.]xyz\/download\/xbhgjahddaa<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:278}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"86\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">hxxps:\/\/1765000000[.]xyz\/download\/ebhgjahddaa<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:278}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"87\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">hxxp:\/\/46[.]151[.]182[.]238:6969\/autoexec<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:278}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"88\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">hxxp:\/\/62[.]113[.]112[.]203\/adm[.]exe<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:278}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"89\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">hxxps:\/\/evilmods[.]com\/api\/nothingtoseehere[.]exe<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:278}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"90\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">hxxps:\/\/evilmods[.]com\/api\/nothingbeme[.]exe<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"91\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">hxxps:\/\/evilmods[.]com\/DependencyCore2<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"92\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">hxxps:\/\/evilmods[.]com\/DependencyCore<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"93\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"94\">\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">Unwanted Installers<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">CD1B15644BF0D7CBF270E8F21CEAE5E6<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">Dependecycore.zip<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"95\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">7d18257b55588bccb52159d261f9cd7f<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">Dependecycore.zip<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"96\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">A518FB6B9D2689737CE668675EEDE98F<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">iTop\u00a0Easy Desktop<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"97\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">E3BB21152BA90990E3CCBC1A05842F8B<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">Opera Installer<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"98\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">A6BC4C6A58AC533D3DB5F96D24DDE0EF<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">Docs Helper Setup<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"99\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">FA24733F5A6A6F44D0E65D7D98B84AA6<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">Windows Manager<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"100\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">CDB67B1C54903F223F7DCCA14AEA67DF<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">eld4.exe<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"101\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"102\">\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">Final Payloads<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">e07a76cc4258c6b4b3f85451ea2174d5<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">xmrig.exe<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"103\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">d32395a3a340e033e11bd89acddaa9cd<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">ethminer.exe<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"104\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">14f1de874c78221e7b6889af7463de69<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">WindowsService.exe<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"105\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">47c8731b2526613e1e3bc61a88680cd0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">rat.exe<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"106\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">fbac126407b5735583dac5ea7cf519b3<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">SalatStealer<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"107\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">4dc93730ebe04a9b508a9f9dae74ae09<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">miner.exe\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"108\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">90e10b510144719613b1017abe227b87<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">titledetector.exe<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"109\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">8dadf8a4b77a340fcbb402789f9a07db<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">agent<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"110\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">4c8e8e2fdc23bb7b24e6b410eb69fb4a<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">scvhosts.exe<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"111\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">79ea41812bd3310e11fc95403504f048<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">sc.msi<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"112\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">1b1bd2783d4e8d1c2d444ffa8689677b<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">cvtres.exe<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"113\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">16b70d148b66c20c709b7eed70100a96<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">source.exe<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"114\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">e2af5595c9a0b7feaa9291b405d4c991<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">XMRIG\u00a0_Miner<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"115\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">b133229ed0be8788c84a975656a7339c<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">CoinMiner<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"116\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">754b581c7e3593446f0a06852031564a<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">MeshAgent<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"117\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">a7400236ffab02ae5af5c9a0f61e7300<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">NiceHash\u00a0Miner<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"118\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">d7d34c0559b3f6ba70be089e4cc6172c\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">lolMiner<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"119\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"120\">\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">PowerShell Scripts<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">02a4d24d0cdaa6f9a3ecf4b71e3f2eec<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"121\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">2a153877acc9270406d676403e999490<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"122\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">77f491c1c50e224d0c61ed608445d8a9<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"123\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">c60a3307d21840d1e15ee78b07d3eb04<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"124\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">d17b85de54d0c438c092c1e889b8c63f<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"125\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">e35c04a7c31f8641757374404edea395<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"126\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">fa8b5b5a302c0e353f4983973cf4b37e<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"127\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">d2ad87a1fd1e8812c5ba4b259de4f885<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"128\">\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">Wallet Address<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">46NgyMUVMf6Xzsao9XR<\/span><\/p>\n<p><span data-contrast=\"none\">C6BTjJpj<\/span><span data-contrast=\"none\">UJFfA12F8<\/span><span data-contrast=\"none\">BPmD<\/span><\/p>\n<p><span data-contrast=\"none\">86Y7biz4gZdjCWsSXMUZ<\/span><span data-contrast=\"none\">o<\/span><\/p>\n<p><span data-contrast=\"none\">mtuUs8crujryAvhRFMyvhzb<\/span><\/p>\n<p><span data-contrast=\"none\">s6naMKucHFi<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><b><span data-contrast=\"none\">Monero (XMR) wallet address<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"129\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">RJe6FfyoWDq6M4i3b17LxvjdT2fSNTLTYA<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><b><span data-contrast=\"none\">Ravencoin\u00a0(RVN) wallet address<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"130\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">ZEPHsCY4zbcHGgz2U8<\/span><\/p>\n<p><span data-contrast=\"none\">PvkEjkWjop<\/span><span data-contrast=\"none\">uPurPNv8nnSFn<\/span><\/p>\n<p><span data-contrast=\"none\">M5MN8hBas8kBN4hoo<\/span><span data-contrast=\"none\">NKmc7uMRfU<\/span><\/p>\n<p><span data-contrast=\"none\">Qh4Fc9AHyGxL6NFARnc217m2vYgbKxf<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><b><span data-contrast=\"none\">Zephyr (ZEPH) wallet address<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"131\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">bc1qyy0cv8snz7zqummg0yucd<\/span><\/p>\n<p><span data-contrast=\"none\">fzpxv2a5syu7xzsdq<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><b><span data-contrast=\"none\">Bitcoin (BTC) address<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"132\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">bc1q7cpwxjatrtpa29u85tayvggs<\/span><\/p>\n<p><span data-contrast=\"none\">67f6fxwyggm8kd<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><b><span data-contrast=\"none\">Bitcoin (BTC) address<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"133\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">bc1qxhp6mn0h7k9r89w8amalqj<\/span><\/p>\n<p><span data-contrast=\"none\">n38t4j5yaa7t89rp<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><b><span data-contrast=\"none\">Bitcoin (BTC) address<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"134\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">bc1qxnkkpnuhydckmpx8fmkp73e3<\/span><\/p>\n<p><span data-contrast=\"none\">8dfed93uhfh68l<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><b><span data-contrast=\"none\">Bitcoin (BTC) address<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"135\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">bc1qrtztxnqnjk9q4d5hupnla245c762<\/span><\/p>\n<p><span data-contrast=\"none\">0ncj3tzp7h<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><b><span data-contrast=\"none\">Bitcoin (BTC) address<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"136\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">bc1q9a59scnfwkdlm6wlcu5w76zm2<\/span><\/p>\n<p><span data-contrast=\"none\">uesjrqdy4fr8r<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><b><span data-contrast=\"none\">Bitcoin (BTC) address<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"137\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">bc1q97yd574m9znar99fa0u799rvm<\/span><\/p>\n<p><span data-contrast=\"none\">55tnjzkw9l33w<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><b><span data-contrast=\"none\">Bitcoin (BTC) address<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"138\">\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">URL Distributing Malware<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">http:\/\/www[.]mydofiles[.]com\/<\/span><\/p>\n<p><span data-contrast=\"none\">MultiClicker[.]zip<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"139\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">http:\/\/www[.]mydofiles[.]com\/<\/span><\/p>\n<p><span data-contrast=\"none\">ProCheatsInstaller[.]zip<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"140\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">http:\/\/www[.]mydofiles[.]com\/<\/span><\/p>\n<p><span data-contrast=\"none\">RobloxCheatEngine[.]zip<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"141\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">http:\/\/www[.]mydofiles[.]com\/<\/span><\/p>\n<p><span data-contrast=\"none\">ST-Bot[.]zip<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"142\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">https:\/\/sourceforge[.]net\/projects\/<\/span><\/p>\n<p><span data-contrast=\"none\">delta-executor-fo<\/span><span data-contrast=\"none\">r-<\/span><span data-contrast=\"none\">pc\/files\/latest\/download<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"143\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">https:\/\/ixpeering[.]dl[.]sourceforge[.]net\/project\/<\/span><\/p>\n<p><span data-contrast=\"none\">delta-executor-<\/span><span data-contrast=\"none\">for-pc\/DeltaExecutor[.]zip?viasf=1<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"144\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">https:\/\/sourceforge[.]net\/projects\/<\/span><\/p>\n<p><span data-contrast=\"none\">delta-executor-for-pc\/files\/<\/span><span data-contrast=\"none\">DeltaExecutor[.]zip\/download<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"145\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">https:\/\/cdn[.]discordapp[.]com\/<\/span><\/p>\n<p><span data-contrast=\"none\">attachments\/1436383055471185961\/<\/span><\/p>\n<p><span data-contrast=\"none\">1454995091423887442\/Keyser[.]zip?<\/span><\/p>\n<p><span data-contrast=\"none\">ex=6953c606&amp;is=69527486&amp;hm=<\/span><\/p>\n<p><span data-contrast=\"none\">e3ba56d122cc6b6228d787d29c6b5db31<\/span><\/p>\n<p><span data-contrast=\"none\">709fd16be119fa8d3a09d92cb0291e4&amp;<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"146\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">https:\/\/cdn[.]discordapp[.]com\/attachments\/<\/span><\/p>\n<p><span data-contrast=\"none\">1436746541669945409\/1454995359754358875\/<\/span><\/p>\n<p><span data-contrast=\"none\">Matcha[.]zip?<\/span><span data-contrast=\"none\">ex=6953c646&amp;is=695274c6&amp;hm=<\/span><\/p>\n<p><span data-contrast=\"none\">1bae58927d0bcd6a1971b604644035ad938c1d535<\/span><\/p>\n<p><span data-contrast=\"none\">61f7d4e951fdf5454d52f8d&amp;<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"147\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">https:\/\/cdn[.]discordapp[.]com\/<\/span><\/p>\n<p><span data-contrast=\"none\">attachments\/1437009916224209018\/<\/span><\/p>\n<p><span data-contrast=\"none\">1454995174328500318\/CheatLoverz[.]zip?<\/span><\/p>\n<p><span data-contrast=\"none\">ex=69531d5a&amp;is=6951cbda&amp;hm=<\/span><\/p>\n<p><span data-contrast=\"none\">f1ac26bebf4394c43cbf21ed531f5dfdf7<\/span><\/p>\n<p><span data-contrast=\"none\">d31f30853b126611c1a39b970b81bc&amp;<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"148\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">https:\/\/cdn[.]discordapp[.]com\/attachments\/<\/span><\/p>\n<p><span data-contrast=\"none\">1438966596222849134\/<\/span><span data-contrast=\"none\">1454995223171170386\/<\/span><\/p>\n<p><span data-contrast=\"none\">Complex[.]zip?ex=69531d65&amp;is=6951cbe5&amp;hm<\/span><span data-contrast=\"none\">=<\/span><\/p>\n<p><span data-contrast=\"none\">b66d9539c0d487fc63125982db773e42eee01dfc<\/span><\/p>\n<p><span data-contrast=\"none\">4bc5a28dc1a7a773134a7bc6&amp;<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"149\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">https:\/\/cdn[.]discordapp[.]com\/attachments\/<\/span><\/p>\n<p><span data-contrast=\"none\">1438966596222849134\/<\/span><span data-contrast=\"none\">1454995223171170386\/<\/span><\/p>\n<p><span data-contrast=\"none\">Complex[.]zip?ex=6953c625&amp;is=695274a5&amp;hm=<\/span><\/p>\n<p><span data-contrast=\"none\">0d6ba0e247e275a9824a838969ee06452e188310<\/span><\/p>\n<p><span data-contrast=\"none\">c434c5d852141bfad3eedff2&amp;<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"150\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">https:\/\/cdndownloads[.]com\/<\/span><\/p>\n<p><span data-contrast=\"none\">download?clickid=277af8wcia4d4b<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"151\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">https:\/\/cdndownloads[.]com\/<\/span><\/p>\n<p><span data-contrast=\"none\">download?clickid=53ba0myoj8p617<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"152\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">https:\/\/download[.]fosshub[.]com\/Protected\/<\/span><\/p>\n<p><span data-contrast=\"none\">expiretime=1735860643;badurl=aHR<\/span><span data-contrast=\"none\">0cHM6L<\/span><\/p>\n<p><span data-contrast=\"none\">y93d3cuZm9zc2h1Yi5jb20vQnVsay1DcmFwLVV<\/span><\/p>\n<p><span data-contrast=\"none\">uaW5zdGFsbGVyLmh0bWw=\/db8e43d6<\/span><span data-contrast=\"none\">6065d<\/span><\/p>\n<p><span data-contrast=\"none\">d656635ff00c50d96369d2fc4dddad18f52c5d00<\/span><\/p>\n<p><span data-contrast=\"none\">05f868649b8\/5b964d315dc7e865ea596350\/67<\/span><\/p>\n<p><span data-contrast=\"none\">3508bbeeeee<\/span><span data-contrast=\"none\">d04938b399f\/BCUninstaller_5<\/span><\/p>\n<p><span data-contrast=\"none\">[.]8[.]2_setup[.]exe<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"153\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">https:\/\/download[.]fosshub[.]com\/<\/span><\/p>\n<p><span data-contrast=\"none\">Protected\/<\/span><span data-contrast=\"none\">expiretime=<\/span><span data-contrast=\"none\">1738877220;<\/span><\/p>\n<p><span data-contrast=\"none\">badurl=aHR0cHM6Ly93d3cuZm9z<\/span><\/p>\n<p><span data-contrast=\"none\">c2h1Yi5jb20vQnVsay1DcmFwLVVu<\/span><\/p>\n<p><span data-contrast=\"none\">aW5zdGFsbG<\/span><span data-contrast=\"none\">VyLmh0bWw=\/bd26<\/span><\/p>\n<p><span data-contrast=\"none\">b0ced684ddb98f194568d7<\/span><span data-contrast=\"none\">f05c<\/span><span data-contrast=\"none\">819<\/span><\/p>\n<p><span data-contrast=\"none\">71932a5bfb323e<\/span><span data-contrast=\"none\">d73296940dd8ec74d\/<\/span><\/p>\n<p><span data-contrast=\"none\">5b964d315dc7e865ea596350\/673508bb<\/span><\/p>\n<p><span data-contrast=\"none\">eeeeed04938b399f\/BCUninstaller_5[.]8[.]<\/span><\/p>\n<p><span data-contrast=\"none\">2_setup[.]exe<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"154\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"155\">\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">Malicious ZIPs<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">001cdd8e978b8233a958cfb81b202<\/span><\/p>\n<p><span data-contrast=\"none\">72a5d3a9c53ce2eb9dda28f0755f95f3e14<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">bluetoothCore.zip\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"156\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">00226d16b97c2a2201ca806491f5a6df<\/span><\/p>\n<p><span data-contrast=\"none\">3650a70c19e82b791740aaef7cf93e72<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">octet-stream\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"157\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">00d70985e5e73cba934ffc7b886cea5df<\/span><\/p>\n<p><span data-contrast=\"none\">2d9f04c72b80f1e653ae709910666da<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">FreeFireForPC.zip\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"158\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">0165aa283b6dd66db66d5865907e75<\/span><\/p>\n<p><span data-contrast=\"none\">3acc68b894fc8086bffe106ac3d550d0df<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">AIVoiceChanger.zip\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"159\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">020b6449605713404d9ea6bd332df47<\/span><\/p>\n<p><span data-contrast=\"none\">f815663f239b39c368208158b1411efb2<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">r6s-multi.zip\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"160\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">04d3477a22a0693c3278c5a86f9c882<\/span><\/p>\n<p><span data-contrast=\"none\">89a7ccc2565cb61f8a78c9b269666baff<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">EZFN.zip\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"161\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">054d2da6e959466490cb0c3cdc2acb9<\/span><\/p>\n<p><span data-contrast=\"none\">602e47ac56b977a3d365b4d1728eb2dd5<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">download\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"162\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">057121dd0ecbb242f7a26ec277249614<\/span><\/p>\n<p><span data-contrast=\"none\">7ae2ec2ee03abd6e79a2bfb5a6ac60e9<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">demonCore.zip\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"163\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">063d5400db74f7e064141e3cb9bdc6e<\/span><\/p>\n<p><span data-contrast=\"none\">71fec88956560de94c280cf59bbc65c78<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">Nihon-Executor.zip\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"164\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">3be99fb0b3bcaa125583bd1763537216<\/span><\/p>\n<p><span data-contrast=\"none\">34c090233dd018e56cd3fa8ac89c3aee<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">Panther-Stealer.zip\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"165\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">07aa31bd8b220f79acd6b26accfb84ab<\/span><\/p>\n<p><span data-contrast=\"none\">6b67f1e6b1baa57ad2f48c5db6771ec5<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">DeltaExecutor.zip\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"166\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">1097bc1ed1dd2e46f65fe16f18f431a1539<\/span><\/p>\n<p><span data-contrast=\"none\">cf73f97599aec2b81d1ad07f2e485<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">gta-5-online-mod-menu.zip\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"167\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">112c08db627e759a499ab96e7964425f7<\/span><\/p>\n<p><span data-contrast=\"none\">21fda8b56029e15ab27c762bf1d91cc<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">DeltaExecutor.zip\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"168\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">113c38d3c1b6d6a87bc99dcfda4020245<\/span><\/p>\n<p><span data-contrast=\"none\">47ecdbdc1d7577a4c0cb3a88569582a<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">Fortnite-External.zip\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"169\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">116760f2d7d0b138a2d62683bc08d4620<\/span><\/p>\n<p><span data-contrast=\"none\">87dbd278e491177ae9c978e1fddb1a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">roblox-multi.zip\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"170\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">11b129c8373b6621343dbfe837e21c016f6<\/span><\/p>\n<p><span data-contrast=\"none\">fe1f9bdbb2a40283c15cc046fd0ba<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">Matcha.rar\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"171\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">1217e31084df1dbe3fb37cd2b0c65bc70ec2<\/span><\/p>\n<p><span data-contrast=\"none\">0278ab11471f0adafe845ed482d9<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">roblox-counter-blox-multi.zip\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"172\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">12e5890426baa26062077ec41d407ddfcd<\/span><\/p>\n<p><span data-contrast=\"none\">8df88480cce6308c0b4064530e767f<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">AIAutoClicker.zip\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"173\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">1366f9bf45a11fed9ec6a2f40a571f273661523<\/span><\/p>\n<p><span data-contrast=\"none\">3567c3d91bb1b09916bf5068c<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">demonCore.zip\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"174\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">140c985db532c9085b2de4adcc885a67199dac2<\/span><\/p>\n<p><span data-contrast=\"none\">c36a465afd7a2655b4f797b17<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">TheExecutor.zip\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"175\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">14df8e6e7aadab0866e1a7b17adb247014343f5e31<\/span><\/p>\n<p><span data-contrast=\"none\">43249e78a6846051b1e620<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">AIVoiceChanger.zip\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"176\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">152914827e68584725b0890a46d62e45122789<\/span><\/p>\n<p><span data-contrast=\"none\">d1341e50f134b586aa7e139d3c<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">TemuForPC.zip\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"177\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">179e55bb20de0def4f9a5272397a11b7<\/span><\/p>\n<p><span data-contrast=\"none\">cb5b4c55a24539da22720f64738a95eb<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">AutoClicker.zip\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"178\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">17e0302f15475a90e807550ea4abe57f<\/span><\/p>\n<p><span data-contrast=\"none\">e75a3630fbcc6d9b8feec4c645b7c31b<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">Roblox-Injector.zip\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"179\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">17eff164be5859f8ed5b4c4d9969f9384<\/span><\/p>\n<p><span data-contrast=\"none\">523f4ac9a8bd1b6e73ee2ea7d1761e2<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">1vqckj.zip\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"180\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">188148aae3bdf973ba88b387db68feae<\/span><\/p>\n<p><span data-contrast=\"none\">da58daf3a70477766ac34f3b125651a9<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">Roblox-MMap-Injector.zip\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"181\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">19c6d61936af8a650eebe50b7a21260<\/span><\/p>\n<p><span data-contrast=\"none\">cbc365cb09e27b9104a095eda3dbc85a9<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">release-delta-executor.zip\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"182\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">1aa12327f111d30f0a973070e2a941322b0<\/span><\/p>\n<p><span data-contrast=\"none\">7710b9c90c02b0c5c0eda26c902cc<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">DeltaExecutor.zip\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"183\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">1baea27d6148bf630d85c28b24d5aa91<\/span><\/p>\n<p><span data-contrast=\"none\">14ad32800d10f2977acecd7845275ecf<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">Osiris.zip\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"184\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">1cdd70b8b8aac60584f17b9396c5f8086<\/span><\/p>\n<p><span data-contrast=\"none\">105c92e630fcb81649d395c461c71f9<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">TLifeForPC.zip\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"185\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">1db8d6d66ab97ed3e1415a02b356a05d8<\/span><\/p>\n<p><span data-contrast=\"none\">ec846d69e5fa533f443b8d5d29949ef<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">ProExt.zip\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"186\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">206265f971c6b6bea2b74ceef0ec1417e79<\/span><\/p>\n<p><span data-contrast=\"none\">54d2cb83261ffa1b63f82964e5792<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">Lo4f-Malware.zip\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"187\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">347601eae5851ef7a6cf5a6b7f93ae6078<\/span><\/p>\n<p><span data-contrast=\"none\">969bafd191f6a8812a20fa6bf43996<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">pubg-cheat.zip\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"188\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">35aa1d44c71bdac70faa11b51fc29c13348e<\/span><\/p>\n<p><span data-contrast=\"none\">99cf981faa7119861df3ab7e50ba<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">Complex.zip\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"189\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">36b339f53a8bf65b030bedf5ad3bfde04eb<\/span><\/p>\n<p><span data-contrast=\"none\">dad3b150ec75ebb77f4a4b3c0cdd7<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">HWIDSpoofer.zip\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"190\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">37aead580cea7b82a1e76cb642a9269b9a<\/span><\/p>\n<p><span data-contrast=\"none\">d1dcdb60f36660e59ee5f8e00cc7b8<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">AIVoiceChanger.zip\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"191\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">42b0ba7953a014a56a27c07cb8c97c0109<\/span><\/p>\n<p><span data-contrast=\"none\">a1b38b78f34f230ea356f9403007ee<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">sony-playstation-vita-emulator.zip\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"192\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">3a02d75900ba42443c40667182711584b<\/span><\/p>\n<p><span data-contrast=\"none\">83844911fdf212747b1e087269d3632<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">FortniteDev.zip\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"193\">\n<td data-celllook=\"0\"><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">3dafa158ccb63f989aaab41541ea9c02d2cf1a<\/span><\/p>\n<p><span data-contrast=\"none\">2b5f50c5a7b98abc1bcadd73f1<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"none\">r6-multi.zip\u00a0<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n","protected":false},"excerpt":{"rendered":"<p>Authored by Aayush Tyagi\u00a0\u00a0 Background\u00a0 The term \u2018Vibe coding,\u2019 first coined back in February of 2025 by OpenAI researchers, has&#8230;<\/p>\n","protected":false},"author":695,"featured_media":192031,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[10661,13,1838,442],"tags":[],"coauthors":[4136],"class_list":["post-227464","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-internet-security","category-privacy-identity-protection","category-mobile-security","category-mcafee-labs"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v25.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>AI Wrote This Malware: Dissecting the Insides of a Vibe-Coded Malware Campaign | McAfee Blog<\/title>\n<meta name=\"description\" content=\"McAfee Labs analyzes a malware campaign using AI-assisted code and fake software downloads. Learn how 440+ malicious ZIP files spread coin miners, infostealers, and other threats.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"AI Wrote This Malware: Dissecting the Insides of a Vibe-Coded Malware Campaign | McAfee Blog\" \/>\n<meta property=\"og:description\" content=\"McAfee Labs analyzes a malware campaign using AI-assisted code and fake software downloads. Learn how 440+ malicious ZIP files spread coin miners, infostealers, and other threats.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ai-written-malware-vibe-coded-campaign\/\" \/>\n<meta property=\"og:site_name\" content=\"McAfee Blog\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/McAfee\/\" \/>\n<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/McAfee\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-03-18T18:21:55+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2017\/06\/300x200_Blog_051524.png\" \/>\n\t<meta property=\"og:image:width\" content=\"300\" \/>\n\t<meta property=\"og:image:height\" content=\"200\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"McAfee Labs\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@McAfee_Labs\" \/>\n<meta name=\"twitter:site\" content=\"@McAfee\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"McAfee Labs\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"25 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ai-written-malware-vibe-coded-campaign\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ai-written-malware-vibe-coded-campaign\/\"},\"author\":{\"name\":\"McAfee Labs\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/86f325fa6532a017d06d6b49a2f3b1ad\"},\"headline\":\"AI Wrote This Malware: Dissecting the Insides of a Vibe-Coded Malware Campaign\",\"datePublished\":\"2026-03-18T18:21:55+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ai-written-malware-vibe-coded-campaign\/\"},\"wordCount\":5082,\"publisher\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ai-written-malware-vibe-coded-campaign\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2017\/06\/300x200_Blog_051524.png\",\"articleSection\":[\"Internet Security\",\"Privacy &amp; Identity Protection\",\"Mobile Security\",\"McAfee Labs\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ai-written-malware-vibe-coded-campaign\/\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ai-written-malware-vibe-coded-campaign\/\",\"name\":\"AI Wrote This Malware: Dissecting the Insides of a Vibe-Coded Malware Campaign | McAfee Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ai-written-malware-vibe-coded-campaign\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ai-written-malware-vibe-coded-campaign\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2017\/06\/300x200_Blog_051524.png\",\"datePublished\":\"2026-03-18T18:21:55+00:00\",\"description\":\"McAfee Labs analyzes a malware campaign using AI-assisted code and fake software downloads. Learn how 440+ malicious ZIP files spread coin miners, infostealers, and other threats.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ai-written-malware-vibe-coded-campaign\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ai-written-malware-vibe-coded-campaign\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ai-written-malware-vibe-coded-campaign\/#primaryimage\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2017\/06\/300x200_Blog_051524.png\",\"contentUrl\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2017\/06\/300x200_Blog_051524.png\",\"width\":300,\"height\":200},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ai-written-malware-vibe-coded-campaign\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Blog\",\"item\":\"https:\/\/www.mcafee.com\/blogs\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Other Blogs\",\"item\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"McAfee Labs\",\"item\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/\"},{\"@type\":\"ListItem\",\"position\":4,\"name\":\"AI Wrote This Malware: Dissecting the Insides of a Vibe-Coded Malware Campaign\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#website\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/\",\"name\":\"McAfee Blog\",\"description\":\"Internet Security News\",\"publisher\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.mcafee.com\/blogs\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#organization\",\"name\":\"McAfee\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/02\/mcafee-logo.png\",\"contentUrl\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/02\/mcafee-logo.png\",\"width\":1286,\"height\":336,\"caption\":\"McAfee\"},\"image\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/McAfee\/\",\"https:\/\/x.com\/McAfee\",\"https:\/\/www.linkedin.com\/company\/mcafee\/\",\"https:\/\/www.youtube.com\/McAfee\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/86f325fa6532a017d06d6b49a2f3b1ad\",\"name\":\"McAfee Labs\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/image\/af947d76ffbef8521094b476cf8050c3\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2017\/07\/Social-Media-PF-Logo-Pic-300x300-2-96x96.jpg\",\"contentUrl\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2017\/07\/Social-Media-PF-Logo-Pic-300x300-2-96x96.jpg\",\"caption\":\"McAfee Labs\"},\"description\":\"McAfee Labs is one of the leading sources for threat research, threat intelligence, and cybersecurity thought leadership. See our blog posts below for more information.\",\"sameAs\":[\"https:\/\/www.linkedin.com\/company\/mcafee\/\",\"https:\/\/www.facebook.com\/McAfee\/\",\"https:\/\/x.com\/McAfee_Labs\"],\"url\":\"https:\/\/www.mcafee.com\/blogs\/author\/mcafee-labs\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"AI Wrote This Malware: Dissecting the Insides of a Vibe-Coded Malware Campaign | McAfee Blog","description":"McAfee Labs analyzes a malware campaign using AI-assisted code and fake software downloads. Learn how 440+ malicious ZIP files spread coin miners, infostealers, and other threats.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"og_locale":"en_US","og_type":"article","og_title":"AI Wrote This Malware: Dissecting the Insides of a Vibe-Coded Malware Campaign | McAfee Blog","og_description":"McAfee Labs analyzes a malware campaign using AI-assisted code and fake software downloads. Learn how 440+ malicious ZIP files spread coin miners, infostealers, and other threats.","og_url":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ai-written-malware-vibe-coded-campaign\/","og_site_name":"McAfee Blog","article_publisher":"https:\/\/www.facebook.com\/McAfee\/","article_author":"https:\/\/www.facebook.com\/McAfee\/","article_published_time":"2026-03-18T18:21:55+00:00","og_image":[{"width":300,"height":200,"url":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2017\/06\/300x200_Blog_051524.png","type":"image\/png"}],"author":"McAfee Labs","twitter_card":"summary_large_image","twitter_creator":"@McAfee_Labs","twitter_site":"@McAfee","twitter_misc":{"Written by":"McAfee Labs","Est. reading time":"25 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ai-written-malware-vibe-coded-campaign\/#article","isPartOf":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ai-written-malware-vibe-coded-campaign\/"},"author":{"name":"McAfee Labs","@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/86f325fa6532a017d06d6b49a2f3b1ad"},"headline":"AI Wrote This Malware: Dissecting the Insides of a Vibe-Coded Malware Campaign","datePublished":"2026-03-18T18:21:55+00:00","mainEntityOfPage":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ai-written-malware-vibe-coded-campaign\/"},"wordCount":5082,"publisher":{"@id":"https:\/\/www.mcafee.com\/blogs\/#organization"},"image":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ai-written-malware-vibe-coded-campaign\/#primaryimage"},"thumbnailUrl":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2017\/06\/300x200_Blog_051524.png","articleSection":["Internet Security","Privacy &amp; Identity Protection","Mobile Security","McAfee Labs"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ai-written-malware-vibe-coded-campaign\/","url":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ai-written-malware-vibe-coded-campaign\/","name":"AI Wrote This Malware: Dissecting the Insides of a Vibe-Coded Malware Campaign | McAfee Blog","isPartOf":{"@id":"https:\/\/www.mcafee.com\/blogs\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ai-written-malware-vibe-coded-campaign\/#primaryimage"},"image":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ai-written-malware-vibe-coded-campaign\/#primaryimage"},"thumbnailUrl":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2017\/06\/300x200_Blog_051524.png","datePublished":"2026-03-18T18:21:55+00:00","description":"McAfee Labs analyzes a malware campaign using AI-assisted code and fake software downloads. Learn how 440+ malicious ZIP files spread coin miners, infostealers, and other threats.","breadcrumb":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ai-written-malware-vibe-coded-campaign\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ai-written-malware-vibe-coded-campaign\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ai-written-malware-vibe-coded-campaign\/#primaryimage","url":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2017\/06\/300x200_Blog_051524.png","contentUrl":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2017\/06\/300x200_Blog_051524.png","width":300,"height":200},{"@type":"BreadcrumbList","@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ai-written-malware-vibe-coded-campaign\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https:\/\/www.mcafee.com\/blogs\/"},{"@type":"ListItem","position":2,"name":"Other Blogs","item":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/"},{"@type":"ListItem","position":3,"name":"McAfee Labs","item":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/"},{"@type":"ListItem","position":4,"name":"AI Wrote This Malware: Dissecting the Insides of a Vibe-Coded Malware Campaign"}]},{"@type":"WebSite","@id":"https:\/\/www.mcafee.com\/blogs\/#website","url":"https:\/\/www.mcafee.com\/blogs\/","name":"McAfee Blog","description":"Internet Security News","publisher":{"@id":"https:\/\/www.mcafee.com\/blogs\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.mcafee.com\/blogs\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.mcafee.com\/blogs\/#organization","name":"McAfee","url":"https:\/\/www.mcafee.com\/blogs\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/logo\/image\/","url":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/02\/mcafee-logo.png","contentUrl":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/02\/mcafee-logo.png","width":1286,"height":336,"caption":"McAfee"},"image":{"@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/McAfee\/","https:\/\/x.com\/McAfee","https:\/\/www.linkedin.com\/company\/mcafee\/","https:\/\/www.youtube.com\/McAfee"]},{"@type":"Person","@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/86f325fa6532a017d06d6b49a2f3b1ad","name":"McAfee Labs","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/image\/af947d76ffbef8521094b476cf8050c3","url":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2017\/07\/Social-Media-PF-Logo-Pic-300x300-2-96x96.jpg","contentUrl":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2017\/07\/Social-Media-PF-Logo-Pic-300x300-2-96x96.jpg","caption":"McAfee Labs"},"description":"McAfee Labs is one of the leading sources for threat research, threat intelligence, and cybersecurity thought leadership. See our blog posts below for more information.","sameAs":["https:\/\/www.linkedin.com\/company\/mcafee\/","https:\/\/www.facebook.com\/McAfee\/","https:\/\/x.com\/McAfee_Labs"],"url":"https:\/\/www.mcafee.com\/blogs\/author\/mcafee-labs\/"}]}},"_links":{"self":[{"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/posts\/227464","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/users\/695"}],"replies":[{"embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/comments?post=227464"}],"version-history":[{"count":8,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/posts\/227464\/revisions"}],"predecessor-version":[{"id":227795,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/posts\/227464\/revisions\/227795"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/media\/192031"}],"wp:attachment":[{"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/media?parent=227464"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/categories?post=227464"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/tags?post=227464"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/coauthors?post=227464"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}