27 éve Veletek – PC Dome / PlayDome

Gavnosource.rar

Upon execution, the malware performs several "anti-analysis" checks:

Change all passwords (starting with Email and Finance) from a different, clean device .

Typically spread via Discord, Telegram, or "leaked" source code forums under the guise of a private tool or game cheat source code. gavnosource.rar

The file is a widely discussed malware sample within the cybersecurity community, primarily recognized as a variant of the Lumma Stealer (an Information Stealer) distributed through social engineering campaigns targeting developers and gamers. Executive Summary Malware Type: InfoStealer (Lumma variant)

InfoStealers often leave "backdoors" or download additional malware (like miners). A clean OS reinstallation is the only way to be 100% certain of removal. Scans for browser extensions and desktop files related

Outbound traffic to unusual TLDs (like .pw , .icu , or .top ) which are frequently used by Lumma Stealer C2 panels.

Scans for browser extensions and desktop files related to MetaMask, Binance, Phantom, and Atomic Wallet. gavnosource.rar

Modifications to Software\Microsoft\Windows\CurrentVersion\Run to ensure the stealer runs on reboot. Remediation Steps If you have executed this file: