Skip to content
October 10, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Malware
  • SocketPlayer malware could evade the sandbox mechanism
  • Malware

SocketPlayer malware could evade the sandbox mechanism

Do Son June 12, 2018 4 minutes read
SocketPlayer malware
Add Daily CyberSecurity as a preferred source on Google
A recent report from G Data stated that the recently discovered remote-access SocketPlayer malware is using a particular library, socket.io, “This particular library was designed for use in web applications that require real-time communication between two parties and which are reliant of bi-directional communication” that allows operators to interact with infected devices “without needing it to take the first step“.
The SocketPlayer backdoor differs from most bank trojans, backdoors, and keyloggers that use typical one-way communication systems. By using the socket.io library, real-time two-way communication between applications can be achieved. According to this feature, malware handlers no longer need to wait for the infected device to initiate communications, the attacker can contact the infected computer.
Allegedly, the backdoor SocketPlayer once installed successfully on the compromised machine can receive the operator’s commands and perform various operations such as sniffing, screenshots, grabbing and running code. The researchers also found that SocketPlayer can also selectively use other functions, for example, like a keylogger, although there is no actual keylogger function in the back door. At present, it seems that there has been no specific use.
The backdoor SocketPlayer infection path starts with the downloader’s sandbox detection. If it passes the test, the downloader downloads an executable file and decrypts it, and then uses the Invoke method to run the decryption program in memory.
The called program will create a socket connection for the host (Host is http://93.104.208.17:5156/socket.io), at the same time, create a registry key that implements persistence. Next check if there is a Process Handler/Folder, if not, you need to create one. After that, you also need to create an autostart key with the value “Handler”. Also, SocketPlayer downloads another downloadable SocketPlayer executable that decrypts and runs in memory.
G Data’s security researchers discovered two variants of the SocketPlayer backdoor during the study:
  • Thefirst variant is a ~100KB file which does exactly what a typical downloader does – downloading a file
    and executing it.
  • Same as variant 1, there is also an old version and a new version. Both versions have a similar initial routine as in 2. Initial routine. The old version only uses the C:\Users\USERNAME\Music path and downloads the data from hxxp://173.249.39.7:1337/uploads/excutbls/ with the filename specified via socket.io from the
    server.
Security researchers noticed a series of changes between the two variants of SocketPlayer, including:
  • The c2 port has changed from 3000 to 7218
  • The file location changed from C:\Users\USERNAME\Music\Player\Player.exe to
    C:\Users\USERNAME\Music\Media Player\Player.exe
  • The information that is sent in the initial routine changed a bit. In the old version[1] the
    author sends the string β€œ,1.1,1” to the c2. In the new version the program sends β€œ,1.2,1”,
    telling the c2 that the new version runs on the machine.
  • To the commands Fdrive,fdir,smfdir,procs,prockil,gtscreen and kylgs the variable susrid is
    added to be sent to the server. This is done to identify the infected systems better.
  • The functionality stscrnpercnt is added. This feature assists the gtscreen function to set the
    quality of the image.
  • The gtscreen function additionally to the susrid also sends the computer name with the
    picture.
  • The storage location of upldex is changed to
    C:\Users\User\AppData\Roaming\Microsoft\Windows\Templates. An autostart key to the
    registry is added. The downloaded file is also executed.
  • The kylgs function also switched to use the above path to read the file klsetup.txt.
  • The destt function additionally checks if the following path and files are available. If so, it
    deletes them. C:\Users\USERNAME\AppData\Roaming\Process Handler
    C:\Users\USERNAME\AppData\Roaming\Process Handler\Handler.exe,
    C:\Users\User\AppData\Roaming\Microsoft\Windows\Templates\Image.exe and
    C:\Users\User\AppData\Roaming\Microsoft\Windows\Templates\Media.exe.
The report shows that a sample of known malware was distributed through an Indian website, but it is unclear how the back door spreads. However, whether the site was used for infection or just for mirroring, it is clear that the malware has not been noticed for a long time.
Source, Image:Β gdatasoftware

Related coverage

  • Keylogger Found Harvesting Credentials on Top US Bank’s Employee Store
  • Unmasking ELECTRUM: Cyber Predators of the Ukrainian Grid
  • “Cuckoo” Malware Lands on Macs, Steals Data, and Spies on Users
  • RedDelta Leverages PlugX Backdoor in State-Sponsored Espionage Campaigns
  • Palo Alto Networks: Patchwork hacker group is targeting the Indian Subcontinent
  • New Skuld Infostealer Campaign Unveiled in npm Ecosystem
Track all actively exploited CVEs →

Support Our Threat Intelligence

Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!

Buy Me a Coffee Logo Buy Me a Coffee
Select your plan
Free Pro Team

Hover over a plan to see its benefits.

Get Zero-Hour Vulnerability Alerts

Critical CVEs, CVSS scores, and PoC updates — straight to your inbox every week.

We respect your inbox. Unsubscribe anytime.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Written by
@DdoS Β· Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: SocketPlayer malware

Search

Translation

CVE ALERTS
πŸ“ˆ

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

πŸ›‘οΈ

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

πŸ™

GitHub Issues
Auto-create alert tickets without duplication.

πŸ“¬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

πŸ”€

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days β†’

🚨 Active Exploits in the Wild

  • CVE-2026-102255CVSS 10.0
    A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access...
    Admin intel📅 Updated: Oct 9, 2026
  • CVE-2026-105133CVSS 6.9
    A vulnerability was detected in Ahsay AhsayCBS up to 10.3.2. This affects the function checkSysPwd of the file...
    Admin intel📅 Updated: Oct 9, 2026
  • CVE-2023-22894CVSS 4.9
    Strapi through 4.5.5 allows attackers (with access to the admin panel) to discover sensitive user details by exploiting...
    CISA KEV📅 Added to KEV: Oct 8, 2026
  • CVE-2016-3081CVSS 8.1
    Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled,...
    CISA KEV📅 Added to KEV: Oct 8, 2026
  • CVE-2015-3306CVSS 10.0
    The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the...
    CISA KEV📅 Added to KEV: Oct 8, 2026
  • CVE-2015-5477CVSS 7.5
    named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial...
    CISA KEV📅 Added to KEV: Oct 8, 2026
  • CVE-2021-3199CVSS 9.8
    Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT...
    CISA KEV📅 Added to KEV: Oct 8, 2026
  • CVE-2026-94504CVSS 7.2
    Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the...
    Admin intel📅 Updated: Oct 7, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-93945CVSS 9.8
    Deserialization of Untrusted Data vulnerability in Axiomthemes Balance balance allows Object Injection.This issue affects Balance: from n/a through...
    📅 Updated: Oct 10, 2026
  • CVE-2026-93936CVSS 9.8
    Deserialization of Untrusted Data vulnerability in ThemeREX Group IPharm ipharm allows Object Injection.This issue affects IPharm: from n/a...
    📅 Updated: Oct 10, 2026
  • CVE-2026-93937CVSS 9.8
    Deserialization of Untrusted Data vulnerability in ThemeREX Group Hygia hygia allows Object Injection.This issue affects Hygia: from n/a...
    📅 Updated: Oct 10, 2026
  • CVE-2026-93938CVSS 9.8
    Deserialization of Untrusted Data vulnerability in ThemeREX Group Hogwords hogwords allows Object Injection.This issue affects Hogwords: from n/a...
    📅 Updated: Oct 10, 2026
  • CVE-2026-93940CVSS 9.8
    Deserialization of Untrusted Data vulnerability in ThemeREX Group Greeny greeny allows Object Injection.This issue affects Greeny: from n/a...
    📅 Updated: Oct 10, 2026
  • CVE-2026-93941CVSS 9.8
    Deserialization of Untrusted Data vulnerability in ThemeREX Group Edema edema allows Object Injection.This issue affects Edema: from n/a...
    📅 Updated: Oct 10, 2026
  • CVE-2026-93942CVSS 9.8
    Deserialization of Untrusted Data vulnerability in ThemeREX Group Dwell dwell allows Object Injection.This issue affects Dwell: from n/a...
    📅 Updated: Oct 10, 2026
  • CVE-2026-93943CVSS 9.8
    Deserialization of Untrusted Data vulnerability in ThemeREX Group Convex convex allows Object Injection.This issue affects Convex: from n/a...
    📅 Updated: Oct 10, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
Β© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.