• About WordPress
    • WordPress.org
    • Documentation
    • Learn WordPress
    • Support
    • Feedback
Skip to content
May 26, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
  • Home
  • News
  • Malware
  • SocketPlayer malware could evade the sandbox mechanism
  • Malware

SocketPlayer malware could evade the sandbox mechanism

Ddos June 12, 2018 4 minutes read
SocketPlayer malware
A recent report from G Data stated that the recently discovered remote-access SocketPlayer malware is using a particular library, socket.io, “This particular library was designed for use in web applications that require real-time communication between two parties and which are reliant of bi-directional communication” that allows operators to interact with infected devices “without needing it to take the first step“.
The SocketPlayer backdoor differs from most bank trojans, backdoors, and keyloggers that use typical one-way communication systems. By using the socket.io library, real-time two-way communication between applications can be achieved. According to this feature, malware handlers no longer need to wait for the infected device to initiate communications, the attacker can contact the infected computer.
Allegedly, the backdoor SocketPlayer once installed successfully on the compromised machine can receive the operator’s commands and perform various operations such as sniffing, screenshots, grabbing and running code. The researchers also found that SocketPlayer can also selectively use other functions, for example, like a keylogger, although there is no actual keylogger function in the back door. At present, it seems that there has been no specific use.
The backdoor SocketPlayer infection path starts with the downloader’s sandbox detection. If it passes the test, the downloader downloads an executable file and decrypts it, and then uses the Invoke method to run the decryption program in memory.
The called program will create a socket connection for the host (Host is http://93.104.208.17:5156/socket.io), at the same time, create a registry key that implements persistence. Next check if there is a Process Handler/Folder, if not, you need to create one. After that, you also need to create an autostart key with the value “Handler”. Also, SocketPlayer downloads another downloadable SocketPlayer executable that decrypts and runs in memory.
G Data’s security researchers discovered two variants of the SocketPlayer backdoor during the study:
  • Thefirst variant is a ~100KB file which does exactly what a typical downloader does – downloading a file
    and executing it.
  • Same as variant 1, there is also an old version and a new version. Both versions have a similar initial routine as in 2. Initial routine. The old version only uses the C:\Users\USERNAME\Music path and downloads the data from hxxp://173.249.39.7:1337/uploads/excutbls/ with the filename specified via socket.io from the
    server.
Security researchers noticed a series of changes between the two variants of SocketPlayer, including:
  • The c2 port has changed from 3000 to 7218
  • The file location changed from C:\Users\USERNAME\Music\Player\Player.exe to
    C:\Users\USERNAME\Music\Media Player\Player.exe
  • The information that is sent in the initial routine changed a bit. In the old version[1] the
    author sends the string “,1.1,1” to the c2. In the new version the program sends “,1.2,1”,
    telling the c2 that the new version runs on the machine.
  • To the commands Fdrive,fdir,smfdir,procs,prockil,gtscreen and kylgs the variable susrid is
    added to be sent to the server. This is done to identify the infected systems better.
  • The functionality stscrnpercnt is added. This feature assists the gtscreen function to set the
    quality of the image.
  • The gtscreen function additionally to the susrid also sends the computer name with the
    picture.
  • The storage location of upldex is changed to
    C:\Users\User\AppData\Roaming\Microsoft\Windows\Templates. An autostart key to the
    registry is added. The downloaded file is also executed.
  • The kylgs function also switched to use the above path to read the file klsetup.txt.
  • The destt function additionally checks if the following path and files are available. If so, it
    deletes them. C:\Users\USERNAME\AppData\Roaming\Process Handler
    C:\Users\USERNAME\AppData\Roaming\Process Handler\Handler.exe,
    C:\Users\User\AppData\Roaming\Microsoft\Windows\Templates\Image.exe and
    C:\Users\User\AppData\Roaming\Microsoft\Windows\Templates\Media.exe.
The report shows that a sample of known malware was distributed through an Indian website, but it is unclear how the back door spreads. However, whether the site was used for infection or just for mirroring, it is clear that the malware has not been noticed for a long time.
Source, Image: gdatasoftware
Rate this post

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram

Related posts:

  1. Copybara Fraud Campaign Leverages On-Device Fraud and Social Engineering Tactics
  2. Typosquat Campaign Targets Puppeteer Users: Researcher Warns of Malware in npm Packages
  3. Dark Web Alert: Genesis Market Returns with Stealthy Browser Extension Attack
  4. Interlock Ransomware Strikes: A New Strain Is Wrecking Havoc in North America and Europe
  5. Eternidade Stealer: New Python WhatsApp Worm Uses IMAP Email for Covert C2 and Brazilian Bank Overlays
Tags: SocketPlayer malware

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚑

Get notified instantly when a Proof of Concept (PoC) exploit is published.

πŸ”

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

πŸ“Š

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

πŸ”΄ Live Critical Threats

  • CVE-2026-42773CVSS 9.3
    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
  • CVE-2026-42774CVSS 9.3
    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
  • CVE-2026-9478CVSS 9.8
    A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the...
  • CVE-2026-9477CVSS 9.8
    A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This issue...
  • CVE-2026-9476CVSS 9.8
    A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the...
  • CVE-2026-9475CVSS 9.8
    A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This affects the function...
  • CVE-2026-9458CVSS 9.8
    A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is...
  • CVE-2026-9457CVSS 9.8
    A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. The affected element is...
  • CVE-2026-9456CVSS 9.8
    A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function...
  • CVE-2026-9455CVSS 9.8
    A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects...
Powered by CVE WATCHTOWER

Recent Zero-Day Vulnerabilities

  • Exploited in the Wild: Critical OWA Spoofing Flaw (CVE-2026-42897) Hits On-Premises Exchange Servers
  • Exploited in the Wild: Maximum CVSS 10 SD-WAN Flaw (CVE-2026-20182) Grants Admin Control
  • Exploited in the Wild: Critical 9.8 CVSS RCE Hits Canon GUARDIANWALL MailSuite
  • Exploit Code Released: Public PoC Dumps for Windows BitLocker Bypass and SYSTEM Elevation Zero-Days
  • Exploited in the Wild: “Dirty Frag” Linux Vulnerability Grants Instant Root Access
  • Under Active Attack: Ivanti EPMM Zero-Day Exploited in the Wild via Harvested Admin Credentials
Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    Copyright Daily CyberSecurity Β© All rights reserved.