Personal experience regarding an interview that ended in a scam

2024-12-03 sohay666

https://sohay666.github.io/article/en/reversing-scam-interview-base-on-js-project.html

Thumbnail for Personal experience regarding an interview that ended in a scam

A fake remote job interview led the victim to clone and run a Node.js project containing obfuscated malicious JavaScript. The code collected host details and targeted sensitive data from Solana wallet configuration, Exodus, browser credential stores, Chrome and Brave profiles, macOS Keychain, and application configuration files. Dynamic analysis showed staged downloads from 86.104.74.51:1224, including a backdoor/dropper, a browser-focused malware component whose payload URL was XOR-obfuscated with the key !!!HappyPenguin1950!!!, and a keylogger component. The keylogger watched for browser processes, checked for crypto-wallet mnemonic material, and posted captured data to 95.164.7.171:8637/api/clip, making the case useful for tracking interview-themed developer targeting and credential-theft tradecraft.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 86.104.74.51 2024-12-03 2025-11-13
IPv4 95.164.7.171 2024-10-14 2025-07-26
IPv4 23.254.229.101 2024-12-03 2025-04-25
URL https://pastebin.com/raw/suEqUQ… 2024-12-03 2024-12-03

Related Reports

2025-02-20 • 50% Match
#BeaverTail #InvisibleFerret #DeceptiveDevelopment #T1027.013 #T1082 #T1119 #T1059.003 #T1140 #T1005 #T1587.001 #T1041 #T1608.001 #T1071.001 #T1115 #T1083 #T1056.001 #T1059.006 #T1059.007 #T1204.002 #T1566.003 #T1555.003 #T1124 #T1583.003 #T1552.001 #T1585.001 #T1219 #T1133 #T1571 #T1564.001 #T1016 #T1074.001 #T1657 #T1071.002 #T1021.001 #T1614 #T1555.001 #T1217 #T1095 #T1025 #T1010 #T1560.002 #T1030 #T1567.004 #T1564.003
Shares tags: BeaverTail, InvisibleFerret
« Back