Automatically translated.View original post

Beware of the fake FileZilla web.

Beware of fake FileZilla web. Download instead of using software, but malware instead.

FileZilla may be another familiar tool of those who work on websites or networks that require the uploading or downloading of files through the FTP protocol, and that has become another target for hackers to seduce those who work with networks and websites with malware spoofing.

According to a report by the official website of the anti-malware developer, Malwarebytes has mentioned the detection of a fake Filezilla website used to spread a 3.69.5 version of the FileZilla software installation file with malware embedded inside. The malware is intended to steal the victim's FTP system access password, as well as to act as the back door of the system, or Backdoor, so that the hackers behind it can log in to the victim's system later. This malware software is released through a fake website named similar to the real FileZilla website, such as filezilla-project [.] live, and this malware-contaminated software is not called fake software. This is because it takes the file of the real portable version 3.69.5 of the FileZilla software, but one malware DLL file has been added.

For real FileZilla, two DLL files are used. This is a DLL file that is a unique library of FileZilla like libfilezilla-500.dll and 3-69-5 dll, but there is no version .dll file, which is a Windows Version API file, which is usually contained within the System folder of Windows (C: WindowsSystem32), not a file associated with FileZilla.

The research team was able to detect a number of DLL files. In this part, Windows will check the software folder that contains the necessary DLL files and then check the Windows system folder. In the first phase, it will load DLL files, system libraries like IPHLPAPI.DLL and POWRPROF.dll. Of course, there is no way to find them in the software folder, so the results will be answered. The first return is NAME NOT FOUND or not found, and Windows will load the file from the system folder instead.

But the version .dll file was detected inside the software folder, so it was loaded instead of loading the normal version .dll file from the system folder. The file was verified by the research team and found that it was a file of malware. But what the malware mixed up the software made a mistake was that the malware was programmed to load the version _ origin.dll file, a file that took the normal version .dll that should be loaded from the system folder to name the DLL Proxy technique to allow the software to load the function that should be normal while the malware code was running in parallel, but the research team received that the file was not inserted, causing the software to malfunction. Until able to catch the wrong

In the field of malware DLL file operation, it starts by checking whether the malware is currently running under Virtual Machine or Sandbox replication, before releasing the real malware file (Payload) using various Behavioural Check techniques such as BIOS version check, Virtual Box register number, Memory Allocation etc.

After checking the operating environment and finding everything safe, the malware contacts the control server (C2 or Command and Control) by sending an HTTPS Request to Cloudflare's Public Resolver by sending it to the URL.

https: / / 1 [.] 1.1.1 / dns-query? name = welcome. sup0v3 [.] com & type = A

This is a technique called DNS-over-HTTPS or DOH that avoids being detected by the enterprise DNS Monitor. After the Resolver converts the value into the domain of the C2 server, the Loader malware returns the call back to the C2 server. According to the research team, the memory analysis method has led to the detection of the Configuration embedded in the Runtime section.

{

"Tag": "tbs,"

"referrer": "dll,"

"callback": ""

}

In addition to the DOH Call Back method, the malware also contacts the IP number 95.216.51.236 via TCP port number 31415, a non-standard port on Hetzner's host service to provide a second channel to contact C2 servers. In addition, the use of this channel allows traffic with general information to break through firewall protection.

When analyzing the malware's behavior, it was found that the malware, in addition to having the ability to steal the password entered by the victim on the software to upload FTP files, also detected the ability to insert the malware's own code into the Process Injection, created persistence on the victim's system with a Registry modification, so that the malware can be restarted at any time, as well as detected that it may be transmitted by encryption. It is called a very versatile malware.

# Trending # Lemon 8 Howtoo # lemon 8 diary # freedomhack # filrzilla

3/28 Edited to

... Read moreจากประสบการณ์ส่วนตัวที่เคยใช้ FileZilla ในการส่งไฟล์ไปยังเซิร์ฟเวอร์เว็บไซต์ พบว่าการดาวน์โหลดโปรแกรมจากแหล่งที่ไม่น่าเชื่อถืออาจก่อให้เกิดความเสี่ยงร้ายแรงอย่างมาก เพราะมัลแวร์ที่ซ่อนอยู่ในไฟล์ติดตั้งแม้จะเป็นรุ่นพกพาที่เหมือนกับของแท้ แต่จะฝังไฟล์ DLL ที่แอบส่งข้อมูลกลับไปยังเซิร์ฟเวอร์ของแฮกเกอร์ โดยเฉพาะไฟล์ version.dll ที่เป็นไฟล์ของมัลแวร์ ตัวนี้ผมเองไม่เคยเห็นใน FileZilla เวอร์ชันจริงเลย การตรวจสอบง่ายๆ คือถ้าดาวน์โหลดมาแล้วพบไฟล์ version.dll อยู่ในโฟลเดอร์เดียวกับไฟล์หลัก (filezilla.exe) ให้สงสัยทันทีครับ เพราะ FileZilla ของแท้จะมีแต่ libfilezilla-50.dll และ libfzclient-private-3-69-5.dll เท่านั้น ไฟล์ DLL ที่เป็น Windows Version API ปกติจะอยู่ในโฟลเดอร์ระบบไม่ใช่โฟลเดอร์โปรแกรม นอกจากนี้ วิธีโหลดไฟล์จากเว็บไซต์ปลอมมักจะใช้ชื่อที่คล้ายกัน เช่นใช้ domain ที่ใกล้เคียงกับของแท้ เช่น filezilla-project.live ซึ่งเป็นกลยุทธ์หลอกลวงให้ผู้ใช้คลิกเพราะคิดว่าเป็นเว็บทางการ แนะนำให้ดาวน์โหลดซอฟต์แวร์จากเว็บไซต์อย่างเป็นทางการเท่านั้น เพื่อความปลอดภัย มัลแวร์ชนิดนี้มีเทคนิคขั้นสูง เช่น ตรวจสอบว่ารันบน Sandbox หรือ Virtual Machine เพื่อหลีกเลี่ยงการถูกวิเคราะห์ และใช้เทคโนโลยี DNS-over-HTTPS (DOH) ในการสื่อสารกับเซิร์ฟเวอร์ควบคุม ทำให้ผู้ดูแลระบบยากในการตรวจจับ พฤติกรรมแฝงตัวแบบนี้ทำให้มัลแวร์มีความทนทานสูง และอาจเข้าถึงข้อมูลสำคัญอย่างรหัสผ่าน FTP หรือเปิดช่องทางหลังบ้านให้แฮกเกอร์เข้าใช้งานระบบได้ เคล็ดลับการป้องกันที่ผมปฏิบัติอยู่คือ หลีกเลี่ยงการดาวน์โหลดโปรแกรมจากเว็บที่ไม่น่าไว้ใจ ติดตั้งโปรแกรมแอนตี้มัลแวร์เวอร์ชันล่าสุด และสังเกตพฤติกรรมโปรแกรม เช่น หากพบว่าโปรแกรมทำงานผิดปกติ หรือมีไฟล์แปลกปลอมในโฟลเดอร์โปรแกรม ควรลบทิ้งและติดตั้งใหม่จากเว็บไซต์ทางการทันที สุดท้าย การรักษาความปลอดภัยของระบบ FTP ยังขึ้นอยู่กับการตั้งรหัสผ่านที่แข็งแรงและใช้การยืนยันตัวตนหลายขั้นตอนถ้าเป็นไปได้ เพราะแม้แต่อุปกรณ์ที่ปลอดภัยก็อาจตกเป็นเป้าหมายของแฮกเกอร์ที่ใช้มัลแวร์ขั้นสูงนี้ได้เสมอ ด้วยความระมัดระวังและความรู้ที่ถูกต้อง ผู้ใช้งานจะสามารถปกป้องตัวเองจากมัลแวร์ FileZilla ปลอมนี้ได้อย่างมีประสิทธิภาพมากขึ้น

Related posts

Zilla is here too!
Thought I would post this so everyone would be sure and recognize Zilla if you were looking for her from another app. #zilla #godzilla #chatter #malinois #belgianmalinois
ZillaTheMal

ZillaTheMal

298 likes

Heartbreaking Detail about Zoey 😲
Animation Odyssey

Animation Odyssey

371 likes

Zilla and her microplastics
It’s her favorite! Sound from chill.cat.guy on TT #godzilla #zilla #malinois #belgianmalinois #funnydogs
ZillaTheMal

ZillaTheMal

46 likes

Zilla Fatu!!!!
GCW!!!! #wrestling #wwe #gcw #wweraw #fyp
RyyanTD

RyyanTD

127 likes

WTF is this Ninja Young Thug on?! 🤣🤣🤣 #youngthug #ninja
Empress Eshe Obasi

Empress Eshe Obasi

1 like

SaraZilla is back
Famous Brazilian singer and tattoo artist
Hotsauce aka Hot Sexy Sauce

Hotsauce aka Hot Sexy Sauce

28 likes

Replying to @Lovelly Made Creations Starting a tshirt business from scratch. You dont not have to have a EIN for businesses that are Sole Proprietorship but I found it convenient to have. #tshirtbusiness #tshirtbusinesstips #startingabusiness #startingabusinessadvice
Tanee Egan

Tanee Egan

34 likes

You can rebuild without destroying everything. Change doesn’t have to be dramatic. It just has to be real 🍾🥂
Zilla The Captain

Zilla The Captain

3 likes

Jey and ZILLA
@Jey Uso @ZILLA FATU #fyp
✨💜Řøşę💜✨

✨💜Řøşę💜✨

138 likes

A Bible page showing Jeremiah 28-29, with the phrase "GOD'S NOT DONE WITH YOU YET" written vertically in colorful, outlined letters, referencing Jeremiah 29:11.
A Bible page displaying Psalm 33-34, featuring an ice cream cone drawing with "TASTE & SEE THAT THE LORD IS GOOD!" written on it, highlighting Psalm 34:8.
A Bible page showing John 13-14, with "JESUS IS THE ONLY WAY" written in purple, outlined letters, accompanied by a drawing of a "ONE WAY!" road sign.
Bible Journaling. 🩷
Found these on Pinterest, added my own spin to them and added them to my journaling bible.
Mrs.Ivey

Mrs.Ivey

5 likes

My journey taught me that strength isn’t always loud 🍾🥂
Zilla The Captain

Zilla The Captain

1 like

beware of living in Colorado!

beware of living in Colorado!

3 likes

#Foodstamps #IncomeTaxes #2026 #NoTrolling #YallLook
SaboBlakkAzz

SaboBlakkAzz

8 likes

schematics is crazy 😭 #fuslie #streamer #fyp #trending #viral
Leslie

Leslie

1 like

HOT GIRL PROBLEMZ
GLAMZILLA

GLAMZILLA

20 likes

This is my old suit I call it missi zilla
This one is from the invention so strong it will, but I make it super strong. It’s made with nuclear system from her skin. She’s very powerful, but that’s why I call her.
magic man 2.0

magic man 2.0

23 likes

Your ambition depends on you. No one else can start it or maintain it. Stay focused, avoid doubt and distraction. Work hard and stay consistent until your effort makes a real impact on the world 🍾🥂
Zilla The Captain

Zilla The Captain

1 like

Justen Byrd

Justen Byrd

11 likes

MEGAZILLA 7.3 Cobra
Jalopy Jeff Sutton

Jalopy Jeff Sutton

263 likes

BERNARDZILLA!
#dogsoflemon8woof #dogsoflemon8 #dogs #dog #lifestyle El Paso
The Introvert Whisperer

The Introvert Whisperer

6 likes

"Slothzilla" Eremotherium
Colin Diggins presents Slothzilla, Eremotherium, the greatest of the Ground Sloths. #megafauna #prehistoric #houston museum
Houston Museum NS

Houston Museum NS

10 likes

Megazilla 2.0 7.3l Supercharged V8 Crate Motor
Jalopy Jeff Sutton

Jalopy Jeff Sutton

150 likes

Zilla Fatu at WWE Raw!
While he may not be signed, Zilla still consistently supports his family at WWE events! #WWE #wrestlingtiktok #prowrestling #wwefan #wrestletok #wwechampionship #wweentrance #wweraw #smackdown #wwe2k24 #wwetiktok
Regularj0e28

Regularj0e28

3 likes

Bowserzilla: Koopa Kaiju Rampage!
#bowser #godzilla #supermariobros #mariokart #fanart
Luna Rae 🌙🌹

Luna Rae 🌙🌹

10 likes

Foreclosure hacks
#besttodoit #itsthescience #realtorlife #engageeducateempower
Johnna Johnson

Johnna Johnson

1 like

Shoutout @Glamnetic x @GLAMZILLA 💘💘💘 💅🏼 How to apply press on nails: 1. Size nails and set them to the side 2. Apply Cuticle Gel 3. Push back cuticles 4. File nails (make sure there’s no skin on the sides of the nail or shine on nail plate) 5. Trim nails if necessary 6. Wip
Kolini

Kolini

1 like

Anime Zillakami Speeddrawing
Pencil Anime Drawing of rapper Zillakami sped up #sketching #drawings #traditionalart #artistsoflemon8 #sketch
SadJoke

SadJoke

18 likes

How to find out who follows you back on TikTok? #themoreyouknow #whofollowsyou #tipsandtricks #howto #followerstiktok #following #teachingontiktok #educational
sylwia_with_w_

sylwia_with_w_

1 like

A kiss from Catzilla 💋
Happy Valentines Day! ❤️ #catvalentinevibes😻💖✨ #valentines #cats #kiss
Catzilla_and_friends

Catzilla_and_friends

52 likes

##🪴stayhigh247🪴 #DA🦍OG🕶️GORILLAZ🦍 #🇲🇽 AZTECAWARRIORS🇲🇽 #😈coast2coast🌎familias🦍 #demonios💀demonias💋 #🇨🇱S🦍O🥷🏻T🇨🇱 #🌓circleoflove🌓 #🇲🇽kompaz😈empire🇲🇽 #⛓️‍💥PENITENTIARY🕸️FAMILY⛓️
Founder👑KingBluntzilla🇵🇷

Founder👑KingBluntzilla🇵🇷

1 like

Replying to @baabyzilla I would LOVE to have a live DJ at one of my Perreo Y Power fitness events. It would literally be a dream. It would have to be a woman DJ though
Lemon8er

Lemon8er

0 likes

🚨 Parents, beware 🚨 I’m beyond upset right now. Today my 3-year-old son came home from daycare with his nails painted pink — without my consent. No one asked me. No phone call. No text. No permission. As a parent, I believe we have the right to decide what’s done to our children, no matter how “sma
prettygurlvxbes__

prettygurlvxbes__

1 like

Codzilla boat ride🚤💦
If you ever ride the Codzilla in Boston… SIT IN THE BACK 💦So much fun, but PSA: don’t wear makeup 😭 I got off that boat with a bare face, no lashes, salty , ashy skin lol! #dateday #fypシ゚viral #summervibes #littlethings #lemon8challenge
ImshainaJꨄ

ImshainaJꨄ

12 likes

GLUTE DAY AT HOME featuring GLUTEZILLA
GLUTES AT HOME featuring GLUTEZILLA by The X Bands! I am a big fan of this band because it's versatile and you can take it with you! Now I'm still learning how to use it better, but I'm getting better than I was at first (YOU CAN WATCH MY FIRST TIME TRYING IT ON MY YOUTUBE CHANNEL B
Kalias Queen

Kalias Queen

25 likes

Laughtzilla is about to go off on the Panthers 💥
This guy's going to be a wrecking ball once he gets more comfortable with his new line mates 🔥 #leafs #nhl #hockey #funnyvideo #memesdaily
LeafsLexi 🇨🇦

LeafsLexi 🇨🇦

9 likes

##🪴stayhigh247🪴 #DA🦍OG🕶️GORILLAZ🦍 #🇲🇽 AZTECAWARRIORS🇲🇽 #😈coast2coast🌎familias🦍 #demonios💀demonias💋 #🇨🇱S🦍O🥷🏻T🇨🇱 #🌓circleoflove🌓 #🇲🇽kompaz😈empire🇲🇽 #⛓️‍💥PENITENTIARY🕸️FAMILY⛓️
Founder👑KingBluntzilla🇵🇷

Founder👑KingBluntzilla🇵🇷

1 like

milo matchazilla
We know the milo dinosaur is a childhood classic, but here at Matcha.com, we go bigger and better for our Matchazillas! 🦖 Ingredients - 7 tbsp Milo, divided - 2 tsp Matcha.com matcha - 1 tsp condensed milk - 1/3 cup milk - 1/2 cup hot water, divided - ice cubes Instructions — Dissolve
matcha.com

matcha.com

86 likes

See more