Automatically translated.View original post

Watch out for fake Telegram web.

Beware Fake Telegram Web, Instantly Download Instant Instant Instant Instant Instant Instant Instant Instant Instant Instant Instant Instant Instant Instant Instant Instant Instant Instant Instant Instant Install Install Install Install Instant Instant Instant Instant Instant Instant Instant Instant Instant Instant Instant Instant Instant Instant Instant Instant Instant Instant Instant Instant Inst

One of the most popular chat applications used by people who wanted data security would not escape Telegram, and it was used to emit malware on victims.

According to a report by the website, Cyberpress has mentioned the detection of a malware in the form of memory (In-Memory) through a fake Telegram website. This website is called telegram [.] com (observed to be different from the actual website used .org). The website is almost exactly the same as the genuine Telegram website, and the victim is persuaded to download a file that claims to be a file for the installation of the Telegram application. The file is called tsetup-x64.6.exe, which is also similar to the installation file of the genuine application, so that the victim is usually not Eh, mind.

But after running to install the application successfully, it will lead to the embedding of complex multi-stage Infection malware, starting with a Command to detect certain processes, such as 0tray.exe, to determine if the machine has Anti-Virus installed on it, and a PowerShell script to add every System Drive to the Exclusion List of Windows Defender, so that the malware can run conveniently without being detected on the excluded drive.

After that, the malware runs a malware DLL file called AutoRecoverDat.dll through rundll32.exe, which is a tool for running Windows-built DLL files to decode the last payload from an XML file called GPUCache.xml, create an Executable file in Portable Executable (PE) via Runtime, and then run directly on memory.

When running on memory successfully, the malware will make contact with the control server (C2 or Command and Control) located on the IP number 27.50.59.77 via port 18852. The IP number has a part to do with the domain of the fake application - jiijua [.] com, telegrgam [.] com, telefgram [.] com, and tejlegram [.] com. This connection will allow hackers to send commands, update new payloads, and ensure that they are always contacted for malware commands (Persustent) through the channel to ultimately take control of the victim's machine.

# Trending # Lemon 8 Howtoo # lemon 8 diary # telegram # freedomhack

4/12 Edited to

... Read moreถ้าถามว่า “Telegram อันตรายไหม?” จากที่เจอบ่อย ๆ คำตอบคือ โดยตัวแอป Telegram เองไม่ได้อันตรายเป็นพิเศษ แต่ความเสี่ยงมักมาจาก “การโหลดผิดที่” โดยเฉพาะการเจอเว็บปลอมที่หน้าตาเหมือนของจริง แล้วหลอกให้เราดาวน์โหลดไฟล์ติดตั้งที่แฝงมัลแวร์ (บางเคสเป็นแบบรันบนหน่วยความจำ/in-memory ทำให้จับยากขึ้น) สิ่งที่ฉันใช้เช็กทุกครั้งก่อนโหลด 1) ดูโดเมนให้ชัด: Telegram ของจริงคือ telegram.org ถ้าเจอเป็น .com หรือสะกดเพี้ยน ๆ (เช่นมีตัวอักษรเกิน/สลับตำแหน่ง) ให้ถอยทันที เพราะนี่เป็นรูปแบบฟิชชิงที่พบบ่อยมาก 2) อย่าคลิกลิงก์จากโฆษณา/โพสต์สุ่ม: หลายคนกดจากผลค้นหาที่เป็นโฆษณา หรือจากลิงก์ที่ถูกส่งต่อในแชท แล้วไปจบที่เว็บเลียนแบบ 3) โหลดจากแหล่งทางการ: บนมือถือให้โหลดจาก App Store/Google Play ส่วนพีซีให้ไปจากหน้าเว็บทางการของ Telegram เท่านั้น และหลีกเลี่ยงไฟล์ .exe จากเว็บที่ไม่มั่นใจ ทำไมเว็บปลอมถึงน่ากลัว? เพราะมันมักทำเหมือน “ติดตั้ง Telegram ให้จริง ๆ” เพื่อให้เราไม่เอะใจ แต่เบื้องหลังอาจมีมัลแวร์แบบหลายขั้นตอน (multi‑stage) แอบทำงาน เช่น ซ่อนเพย์โหลดไว้ในไฟล์ที่ดูไม่น่าสงสัย (บางรายงานพูดถึงการฝังในไฟล์ XML) แล้วค่อยโหลดขึ้นหน่วยความจำโดยตรง จากนั้นอาจพยายามปรับการตั้งค่าความปลอดภัยของเครื่อง หรือเชื่อมต่อออกไปหาเซิร์ฟเวอร์ควบคุม (C2) เพื่อรับคำสั่งเพิ่มเติม สัญญาณเตือนที่ควรระวังหลังเผลอติดตั้ง - เครื่องเริ่มช้าผิดปกติ ทั้งที่เพิ่งติดตั้งแอปแชท - มีโปรเซสแปลก ๆ หรือมีการเรียกใช้คำสั่ง/สคริปต์แบบผิดธรรมชาติ - Windows Defender แจ้งเตือน หรือการตั้งค่าความปลอดภัย/รายการยกเว้น (exclusion) เปลี่ยนไปโดยไม่รู้ตัว - มีทราฟฟิกออกไปยังไอพี/พอร์ตแปลก ๆ (ถ้าใช้องค์กรที่มีเครื่องมือมอนิเตอร์จะเห็นชัด) ถ้าเผลอโหลดจากเว็บปลอมแล้วควรทำอะไร - ตัดเน็ตก่อน (กันการเชื่อมต่อไป C2) - ถอนการติดตั้งไฟล์/โปรแกรมที่เพิ่งลง และสแกนด้วย Windows Security/แอนตี้ไวรัสที่เชื่อถือได้แบบ Full scan - ตรวจรายการ Startup/Task Scheduler และโปรแกรมที่รันอัตโนมัติ - เปลี่ยนรหัสผ่านบัญชีสำคัญ ๆ (อีเมล/ธนาคาร/โซเชียล) โดยทำจาก “เครื่องที่มั่นใจว่าสะอาด” สรุปสั้น ๆ: Telegram ไม่ได้อันตรายเพราะเป็น Telegram แต่อันตรายเพราะ “เว็บปลอม/ลิงก์ปลอม” ที่หลอกให้โหลดไฟล์ติดตั้งค่ะ ถ้าจำแค่ว่าให้โหลดจากแหล่งทางการและเช็กโดเมน telegram.org ให้ชัวร์ ก็ลดความเสี่ยงได้มาก

Related posts

GANA CON TELEGRAM
#ganadesdecasa #monetize #generaingresosdesdecasa #marketingdigital
Aprende a monetizar con Yura

Aprende a monetizar con Yura

22 likes

EL SOLAR nuevo grupo de Telegram. Juega y gana.
EL SOLAR necesitamos los primeros 50 competidores 🎲para dar comienzo a nuestra competencia. Donde siempre hay 1 ganador. Join us and invite your friends and family. Gana dinero 💰
El Solar

El Solar

2 likes

An aerial view of a city at dusk or dawn, featuring a vibrant orange and red sky over a landscape of buildings with illuminated windows and streetlights. The horizon shows a hazy glow.
telegram Spam:
guys with America phone numbers, do you know what kind of girls, are those who are spamming telegram with text messages constantly, using American phone numbers ?I asked few of them how did they get an American number while in Cambodia, they didn't answer . are they what I think they are ??
Sam Masoud

Sam Masoud

0 likes

See more