← Back to Pulse Feed
PULSE DETAIL
近期,火绒威胁情报中心针对SeanPalia样本的分析发现,这是一款伪装为正常 Electron桌面程序运行的信息窃取木马。样本启动后,会通过main.js加载经过bytenode 编译的decrypted_payload.jsc,并以运行时恢复方式释放主payload。随后,程序会先结束抓包、调试和逆向分析工具,并批量关闭浏览器进程以释放数据库文件锁;之后通过系统性扫描浏览器、Discord、桌面钱包与浏览器钱包扩展等高价值目标,读取Login Data、Web Data、Cookies、History、Bookmarks、Local Storage/leveldb 等本地敏感数据,同时恢复Local State中的Chromium密钥并解密受保护的数据。
Indicators of Compromise (6)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-SHA256 | 55e80a984d85bc95cd3b5ac2678e478b966001b270398b0147e7314e9a2126ad | — | 2026-05-11 | |
| FileHash-SHA256 | 5fdf4e276b126b3388711800b38c4cca86bd323fe0ee34c3b0a79f0449f942f1 | — | 2026-05-11 | |
| FileHash-SHA256 | be219a47bb2adb65aa02cde88baaa9bee4041e846b4b32ba05921f7c078323d9 | — | 2026-05-11 | |
| FileHash-SHA256 | ed8ee2d144c7e65f178e49fddeb5fc403f783578dd7e16fc3fad479d3d1f9572 | — | 2026-05-11 | |
| URL | https://api.hypercoreengine.com/sender-moss | — | 2026-05-11 | |
| hostname | api.hypercoreengine.com | — | 2026-05-11 |
References (1)