Super Mario 3: The Spicy Meatball Edition

Consider following on social media!

Quick note: if you’re viewing this via email, come to the site for better viewing. Enjoy!

This might be the new mushroom kingdom if things don’t get better with Mario.
Photo by Russell Butcher, please support by following @pexel.com

All might not be so one up in the mushroom kingdom. Gamers who love playing as the tubby loveable plumber hopping in and out of pipes might want to opt for playing his other games until the sewage clears.

In a nutshell, if you have downloaded Super Mario 3: Mario Forever then the game isn’t the only thing that might be running on your computer. We’re going to look at what kind of attack this is, who used it, the functionality and effects upon its release, and what are some ways you can prevent this from being your computer’s last one up.

Subscribe today to Scriptingthewhy or Mario will beat you with a spicy meatball!
Photo by Pixabay, please support by following @pexel.com

The Attack

One-upping everyone to speed who is unfamiliar with the loveable plumber, his brother Luigi, the Princess Peach, and everyone in the mushroom kingdom, Mario is a popular platformer game that was released in 1985 on the home console Nintendo Entertainment System or widely known as NES under the title “Super Mario Bros.”

The objective of the game was to rescue the chronically kidnapped Princess Peach from the overgrown-I-don’t-know-how-this-relationship-would-work-because-his-a-lizard-and-she’s-a-human King Bowser. Just know a long story short there are some questionable motives on all parties, but Mario goes on a massive trip to rescue her time and time again. And one of those times was the Super Mario 3: Mario Forever game.

For those who may not know, Mario Forever is a fan-made game that was released in 2003 with the old-school NES side-scrolling and art style with an updated look and some new features.

Within the Super Mario game, trojan malware has been released for unsuspecting gamers with the intent to do some mining. And before you make the joke, it’s not mining with Minecraft. Minecraft has its own problems to dig through.

We may have to take a closer look when downloading files.
Photo by cottonbro studio, please support by following @pexel.com

Who Can It Be Now

Digging through research, threat actors were discovered by Cyble—a cyber threat intelligence and research company, that has spotted threat actors distributing a slightly different sample of Super Mario 3 installer.

It has been known that threat actors frequently hide malware in-game installers and since Mario is a highly popular gaming franchise this makes the perfect attack vector for threat actors.

Just when you thought Mario couldn’t plunge himself deeper into your wallet. Thanks a lot Nintendo.

Enjoy the read so far? Why don’t you consider subscribing so you can keep up to date?

Derek: Z-Daddy, you mean like the malware piggy backs like this?
Z-Daddy: That Derek but in this version there’s two spicy meatballs.
Photo by Pexels User, please support by following @pexel.com

The Sinking Feeling

Appearances of Mario Forever, the trojan edition, have been thought to be seen circulating on gaming forums, and social media outlets, and appearing high up on search results. In this attack, there are three portions.

The first installs the Mario game and the other two secretly creep into the victim’s AppData directory during the installation. Once this process is complete, the installer fires up the XMR and the SupremeBot mining client. All the information about the victim’s machine is collected and sent to a mining server to begin the mining process.

A quick thing to note, XMR which is better known as Monero, is a mining program used by cybercriminals for crypto-jacking. In short, it makes use of the CPU (Central Processing Unit) to mine for Monero coins, the irony. The file for Monero will appear as “java.exe”. While this happens, SupremeBot, which will appear as a file named “atom.exe”, creates a copy of itself and places it in a hidden folder of the game’s installation directory.

Afterward, hiding under the name of a legitimate process, a scheduled task is created to run the copy every 15 minutes indefinitely. The first process is stopped, and the original file is deleted, this is done to avoid detection. Once that is completed, the malware sets up a connection with the C2 (Command and Control) server, here is where the collected data is transmitted, information about the client is registered, and the configuration for mining Monero is run.

SupremeBot then receives the payload from the C2 server in the form of a file named ‘wime.exe.’ This final file is called Umbral Stealer (UmS)—an information stealer programmed in C# designed to steal from infected Windows devices. All the information stored in web browsers such as, but not limited to, stored passwords, cookies, session tokens, crypto wallets, credentials, and authentication tokens for Discord, Minecraft, Roblox, and Telegram.

UmS can also create screenshots of the desktop, gain control of the webcam, and other media devices and collect local data before exiting to the C2 server. If that wasn’t enough, UmS can bypass the Windows Defender if tamper protection isn’t enabled.

If not enabled, UmS will add itself to Defender’s exclusion list, this means if it wasn’t on the welcome list before, it is now. UmS will also configure Windows host files to hinder communication with antivirus products rendering them ineffective. Just when you thought having a little security couldn’t get any smaller.

So, do I… squat to get into the pipe or…what? How do I protect Mario anyway?
Photo by cottonbro studio, please support by following @pexel.com

The Prevention

Any gamer will tell you that it’s hard to keep Mario completely safe while traversing Mushroom World on his never-ending quest to rescue Princess Peach. Many know it takes a couple of hits to cost Mario a life, but it only takes one for your computer.

A few ways to defend are downloading from official sources as third-party sources could have malware. It is best to frequently scan any downloads before running them on your computer.

Always make sure your antivirus software is up to date. If you feel as though you may have downloaded an infected version of Mario Forever, then you should scan your computer and remove anything detected.

If found, you should prioritize what is most important and change all passwords to any logins such as personal, banking, emails, and financial immediately. Keep your information safe and let Mario be the one running around in a panic.

Yea, I’ll just wait until this whole thing blows over. I’ll help Mario with his mushroom addiction later.
Photo by Anurag Sharma, please support by following @pexel.com

Made it this far and found this to be entertaining? Then a big thanks to you and please show your support by cracking a like, sharing this with whomever, scripting a comment, or plug-in to follow.

Would like to give sincere thanks to current followers and subscribers, your support and actions mean a lot and has a play in the creation of each script.

Do you feel like there is something I may have missed on Monero, SupremeBot, or Umbral Stealer? Script a comment below.

Hounds & The Morris Worm

Consider following on social media!

Quick note: if you’re viewing this via email, come to the site for better viewing. Enjoy!

man in dress shirt on the phone.
What do you mean “it’s illegal to drop a toaster onto Eric head”?
It’s not a crime if it was for science.
Photo by Andrea Piacquadio, please support by following @pexel.com

Outside of the longing to conduct social experiments, a popular one is dropping a toaster atop your co-worker’s head to test gravity and ensure it still works. You could say the internet has and can take us places we never thought possible.

We can go to many locations, stay in touch with people close and far, and have the ability to get our digital hands on anything provided we have the coin. So, with all the good, what’s the bad? Well, the bad is, again being able to get your digital hands-on certain items, most of which could be questionable, if you have the coin.

I mean, it shouldn’t be that easy but here we are. One of which is someone mails you a flash drive saying “Hot Nudes, your spouse will never know. Don’t worry.” You should worry and never put the flash drive into your system because your spouse will know when the computer starts acting wonky and a virus begins to run rampant on your machine and very soon, your network. Again, five minutes of fun could have you rooted, and I’ll go over how.

dog in greyscale.
I know that I am a cute dog. I do know what you want but I want you to know something. I have a particular set of teeth; I will find you… and I will bite you.
Photo by Sedat Ozdemir, please support by following @pexel.com

Capture and Release

Have you ever watched The Simpsons and heard the famous line from Mr. Burns, “Release the hounds”? If you haven’t here’s a brief overview, Mr. Burns is mainly an evil rich guy who employs Homer and a few of his friends, and when the mood strikes, he will tell his assistant Mr. Smithers to release the hounds to chase Homer off.

So in a sense, what every corporate boss wants to do but legal reasons stop them. I use this phrase because it’s symbolic of what happens after releasing a virus or what it is actual name is a worm. Computer worms are a subset of trojan malware that can self-replicate from one computer to another and eventually spread through a network without human intervention.

The original name was The Morris Worm, named after Robert Tappan Morris. Robert being a simple student at Cornell University created this worm with the intention to gauge the size of the precursor internet of the time “ARPANET” (Advanced Research Projects Agency Network)– the first public computer network mainly used for academics and research.

However, this testing resulted in a denial-of-service (DoS) for 60,000 machines back in 1988. But the fun doesn’t stop there, the United States v. Morris 1991, resulting Morris being the first convicted under the 1986 Computer Fraud and Abuse Act having a nice price tag of three years in prison, 400 hours of community service, and finally paying a fine of $10,000. This may have you thinking twice about trying to view spicy pictures of kittens on your family computer.

man holding 2 paint brushes
I think I caught Covid from this one last time.
Photo by Andrea Piacquadio, please support by following @pexel.com

Vectors of Infection

A worm, how is it different from a virus? Worms, as mentioned earlier, tend to be able to self-replicate and spread throughout linked computers and then onto the network.

Viruses, on the other hand, tend to be attached to files or programs and hide until transferred elsewhere unknowingly. So if you wanted this in nightclub terms, worms are crabs and viruses are herpes.

Some of the vectors used for infection are emails, file sharing, instant messaging, smartphones, flash drives, and if it’s connected to the internet in some fashion, game over man could be heard from everyone on your contact list and pretty much around the world. The six degrees of separation would no longer exist if a worm were never quarantined and dealt with.  

Enjoy the read so far? Why don’t you consider subscribing so you can keep up to date?

person in medieval armor
She said bring protection…girl just you wait. I got all the protection.
Photo by PhotoMIX Company, please support by following @pexel.com

Keeping safe via Updates

So, how would you be able to tell if you have a computer worm running around making its wormy babies on your PC (Personal Computer)? Some signs are files making like a deadbeat parent and just disappearing (I’m not going to single out deadbeat fathers, there are deadbeat mothers too).

Your computer begins to run slower close to sluggish, this could be caused by the worm taking up memory as it spreads leading to a large amount of free space being taken up. So at this point, you may be thinking “Wow this suck, I want to see spicy pictures of kittens, but I don’t want crabs.”

Well, you’re in luck, and don’t let your spouse know that Z-Daddy told you this. Some ways to prevent catching a worm or “crabs”, Deadliest Catch, staying away from downloading from unknown sources, verifying with your contacts if something is sent from them, keeping the operating system up to date, and having antivirus software and making sure that’s up to date as well.

Morris may have created a monster that caused a decent amount of chaos and was the first person to get freshly smacked with the Computer Fraud and Abuse Act (CFAA) but went on to cofound the online store Viaweb and later funded firm Y Combinator. So every cloud has a silver lining.

Mark: So what I got from this script is that I can create a virus open my own business.
Tina: That’s not what he meant Mark, stop skimming and actually read.
Photo by Anna Shvets, please support by following @pexel.com

Made it this far and found this to be entertaining? Then a big thanks to you and please show your support by cracking a like, sharing this with whomever, scripting a comment, or plug-in to follow.

Would like to give sincere thanks to current followers and subscribers, your support and actions mean a lot and has a play in the creation of each script.

Figure there’s some information I missed on computer worms. Scripted a comment below.

The M.S. You Didn’t Know About

Consider following on social media!

Quick note: if you’re viewing this via email, come to the site for better viewing. Enjoy!

I might not be able to magic money into your bank account but subbing to Scriptingthewhy can help keep it there.
Photo by Viniclus Vieira ft, please support by following @pexel.com

Threat actors have been trying to find ways into your wallet and it seems like they might have found the perfect product to do so. It is fairly known that threat actors want what’s in your wallet and they have attempted through numerous means to reap the benefits of your hard labor.

Although this time, they might have found the perfect product to do just that with the dark web market best-seller. We are going to look at what kind of attack this is, who is using it, its functionality and effects upon release, and some ways you could prevent all the precious items in your wallet from mystically disappearing.  

The dark web isn’t as dark as you think, shady business is done in the light too.
Photo by Elti Meshau, please support by following @pexel.com

The Attack

If you are unfamiliar with the dark web, this is the digital underground nightclub for threat actors and others of the like. Here you can link up with like-minded individuals and purchase items anonymously.

Whether it’s legal or not depends on its nature and its intended use. Now with the addition of Mystical Stealer (MS) being the latest malware product on the market, that nightclub just turned up the bass.

No, this isn’t a play on Mac Stealer and it’s more of a problem as you’ll come to find.

I’m cranking up music like rising gas prices.
Photo by Gaby Tenda, please support by following @pexel.com

Who Can It Be Now

While this Digital Underground nightclub is currently popping, hackers are doing the Humpty dance in their victim’s bank accounts. MS is considered to be a malware-as-a-service due to being priced at USD 150 a month with the option of opting for a tri-monthly payment of USD 390. But like with inflation, gas prices, and MSs popularity the creator is looking to raise those price tags. It’s mind-blowing how criminals have a budget in mind for mucking up the budget of others. Never meet your hero kids.

The creator of MS, who still hasn’t been named, is receiving praise for his product. So much so that the creator has opened the floor on forums requesting any suggestions to improve the product. This raises concern because a threat actor is a developing problem but threat actors working together in numbers can be a developing nightmare.

Enjoy the read so far? Why don’t you consider subscribing so you can keep up to date?

Don’t judge a book by its cover, I’m actually monitoring your network and before you ask, no, I don’t get paid enough for this.
Photo by Tima Miroshnichenko, please support by following @pexel.com

The Sinking Feeling

Speaking of developing nightmares, MS can find its way onto many versions of the Windows OS (Operating System). This ranges from Windows XP to 11 and it doesn’t need any dependencies so tracking its whereabouts is difficult.

MS also checks the environment to ensure it’s not in a sandbox—this is an environment that simulates another computer and other OS can be used within the environment, MS checks for this before it begins its infiltration.

It does this by checking the CPUID, the CPUID is what it sounds like when you break it down. CPU is the Central Processing Unit; ID is the Identification so in a nutshell this malware is checking under the hood to see what you’re running baby. It’s a little checking up the skirt action being done here.

Once in, it begins its operation by inserting itself into the memory to avoid detection and begins to make use of system calls for compromising targets. This is done to ensure that no trace is left on the hard disk during the exfiltration process.

After a target is chosen, malware is released for it to encrypt and transmit. The data is transmitted all the while client authentication is never needed. The malware has the bonus of being created without the need to use third-party libraries and has the enhanced functionality to parser from a self-written browser. It’s almost like the Tesla of malware, except it doesn’t crash on auto-drive.

Malware! We know you’re here!
Photo by Faruk Tokluoglu, please support by following @pexel.com

The Prevention

Now, while threat actors need money, we’re sure you do too. There are some ways to help prevent MS from two-stepping its way into your system. Ensuring your antivirus software is up to date as this will be patched regularly to reduce the risk of infection.

For business owners who have employees. providing awareness training for your employees can help lower the risk of systems becoming infected. Incorporating an incident and response plan as part of your playbook will help as this prepares for an “in case” scenario.

Mystical Stealer has already proven to be a threat so treating it lightly may see things go up in thin air and as times are getting harder, it’s clear that no one wants that.

Prisoner: How’d you know I was going to be there?
Guard: We read a few scripts.
Prisoner: Curse that meddling Scriptingthewhy.
Photo by Ron Lach, please support by following @pexel.com

Made it this far and found this to be entertaining? Then a big thanks to you and please show your support by cracking a like, sharing this with whomever, scripting a comment, or plug-in to follow.

Would like to give sincere thanks to current followers and subscribers, your support and actions mean a lot and has a play in the creation of each script.

Do you feel like there is something I may have missed on Mystical Stealer? Script a comment below.