While specific hashes can vary due to polymorphic packing, these are common traits for the 2022-10-31 variant: Onusman_update.exe (inside the ZIP).
Scans for browser extensions and local files related to cryptocurrency wallets (e.g., MetaMask, Binance). Onusman_2022-10-31_update.zip
Steals saved passwords, cookies, and autofill data from Chrome, Firefox, Edge, and Brave. While specific hashes can vary due to polymorphic
If the file was executed, assume all credentials stored on that machine are compromised. Change passwords for email, banking, and corporate accounts from a clean device. Binance). Steals saved passwords
Disconnect the affected machine from the network immediately.
The file is associated with a specific campaign involving the Onusman (also known as OnuSman or OnuSman-Stealer) malware . This particular update surfaced around late October 2022, primarily targeting Windows environments to exfiltrate sensitive data. Executive Summary
Looks like you haven't made a choice yet.