PULSE NAME
Gamers get ready: under the guise of cheats and mods, scammers distribute Trojan.Scavenger for the theft of cryptocurrency and passwords.
WHITE PetrP.73 2025-07-23 Modified: 2025-07-23
43
IOCs
MEDIUM VOLUME
Dr. Web has identified a family of malicious Trojans known as ScaveNger, which are designed to target Windows users to steal sensitive information related to cryptocurrencies and password managers. These Trojans employ the DLL Search Order Hijacking technique to infect systems, using legitimate applications as vectors for deployment. This method involves placing malicious DLLs in locations prioritized by Windows for library searches, ensuring the malicious code is executed as part of the legitimate application. The infection process with Trojan.Scavenger is multi-layered and begins with Trojan loaders, which can arrive on target systems through various means, including pirated software from torrent sites. For instance, Trojan.Scavenger.1 poses as a DLL named umpdc.dll and typically spreads alongside games, such as Oblivion Remastered. Once activated, it retrieves additional malicious modules like Trojan.Scavenger.2 and subsequently Trojan.Scavenger.3 and Trojan.Scavenger.4.
Indicators of Compromise (9 / 43 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 083e5042e7e2118b37f09b337071d1f8 MD5 of 3a02aacce9653958e1b11523ec3f618e5e2f11e7 2025-07-23
FileHash-MD5 19acc6fc9bfb0bb1bfb6179fc37ff5b0 MD5 of 60fca6ad18c8574f5234fdd47963d6fb9a6e113e 2025-07-23
FileHash-MD5 1dd86ff47ea589fa748832a007e52645 MD5 of fe612df1ae5fba63ca4eaeb880e9f14b1061636b 2025-07-23
FileHash-MD5 3134c94ffbc5ee53f76e12d88e8d964d MD5 of a77271854d70ac119552ab830eb266e94cc8b9cc 2025-07-23
FileHash-MD5 4cad308528929a8d20143c8f634cfba8 MD5 of 739d4a37831d94b35b5140e7acdee6e75d3279f1 2025-07-23
FileHash-MD5 53f2dcb0bdfcdcd9ac868e6737ea5d5f MD5 of dcf9a4a81ec24b8d171fb2c6b5a6f374253748e5 2025-07-23
FileHash-MD5 572fe515ccb3a0068bc641725f8e3ef9 MD5 of 9f5d1dbb2cd31b2af97e14b8781ea035a4869194 2025-07-23
FileHash-MD5 b3157d0334170ec5d4e22db77717a2b9 2025-07-23
FileHash-MD5 fb2799e1d76a5897bcc2675e90f22869 MD5 of 96708c84e07d058b5f0012666e565617907add99 2025-07-23