A partner CERT handed us a sinkholed copy of a relay used against a Corvane Aerospace laptop. The victim opened a ZIP from a fake Nimbus Manticore careers portal. Before the sinkhole took the domain, the relay logged three check-in attempts. The attached capture holds all three, straight off the wire.
Open
MiniBrowse relay recovered from a sinkholed host
Evidence
Live relay
A live, non-sinkholed copy of the same relay answers at this host, port 9190,
endpoint /checkin. Nothing here needs a real infected host or a real
browser. Read the capture, work out what the implant sends and expects back, and
reproduce it yourself against the live relay.
Public reporting on this family states it aborts on an HTTP 200 response and proceeds only otherwise. All three sessions in the capture came back 200.
Recovered from the same host: MiniJunk's single-byte XOR key for this build is
84. It applies once the live relay stops answering 200.