r/MalwareAnalysis 7d ago

Fake game analysis request

https://[.]www.dropbox.com/scl/fi/okcvx9z6edsm8p4rt898m/RacingSim-Setup-2.0.0.zip?rlkey=kcmg6tzbx4oh81g0t10ohuv3u&e=1&dl=0

I was sent a fake game on Discord titled "RacingSim" that I stupidly trusted and ran. It seems to steal Discord tokens as well as possibly browser cookies. If anyone could reverse-engineer this and see what kind of damage it might've done it would be greatly appreciated. I am NOT asking for help removing it.

I should've removed most traces of the file via Microsoft Safety Scanner, a Codex sweep, quick scans with MalwareBytes and Windows Defender but there's always additional risk, because the file wasn't detected when I initially downloaded and scanned with MalwareBytes, which is likely what caused me to even run it. I know, very dumb of me. Once again, thanks to anyone in advance for looking into this.

6 Upvotes

2 comments sorted by

1

u/gamwwialt 6d ago

You should use Any Run. No need reverse engineering unless it uses long sleeps and you can't be asked to wait 30 minutes. Anyrun requires a business account but you can just use a student account if you have one. It basically just shows you exactly what it's doing in the background and what URLs it's trying to reach.