ALERT!
Click here to register with a few steps and explore all our cool stuff we have to offer!

Jump to content



Photo

Chaos Ransomware Builder V4 - Cleaned by ObbedCode


  • Please log in to reply
Chaos Ransomware Builder V4 - Cleaned by ObbedCode

#1

ObbedCode
ObbedCode
    Offline
    352
    Rep
    2170
    Likes

    Anti-Virus

Posts: 2050
Threads: 68
Joined: Nov 03, 2017
Credits: 0

Six years registered
#1

To clean the file we have to rename a .DLL to .EXE and modify some sus IL Code.

Removed the Original .exe that is just a virus :(

 

Note I cleaned the File, You Can analyze the file for yourself in DnSpy

Still Run everything in a Controlled Environment. My version is the Fully Cleaned Version.

 

 Even has the Decryptor in the same Folder

  

Person Spreading Malware:

Spoiler

 

Original Report:

 

Spoiler

 

===================================================================

DOWNLOAD

===================================================================

Password: Chaos46366


Upload.ee

Hidden Content
You'll be able to see the hidden content once you reply to this topic or

Please Login or Register to see this Hidden Content

.

 

Anonfile

Hidden Content
You'll be able to see the hidden content once you reply to this topic or

Please Login or Register to see this Hidden Content

.

 

Zippyshare

Hidden Content
You'll be able to see the hidden content once you reply to this topic or

Please Login or Register to see this Hidden Content

.

 

Mirror Ace

Hidden Content
You'll be able to see the hidden content once you reply to this topic or

Please Login or Register to see this Hidden Content

.

 

===================================================================

SCREENSHOTS

===================================================================

 

Spoiler

 

Original Analysis:

(Still always run EVERYTHING in Sandbox / Virtual Machine)

 

Stub SRC:

Please Login or Register to see this Hidden Content

 

VT:

Please Login or Register to see this Hidden Content

HB:

Please Login or Register to see this Hidden Content

 

Please Login or Register to see this Hidden Content


Edited by ObbedCode, 28 November 2022 - 06:09 AM.

  • 11

++

~~  Much Love From ObbedCode  ~~

Always RUN Files in a Sandbox / Virtual Machine 

 

bQKFo6Z.png


#2

Cat
Cat
    Offline
    650
    Rep
    1809
    Likes

    got your tongue?

Posts: 1639
Threads: 654
Joined: Jan 19, 2015
Credits: 26

Eight years registered
#2

Good work as always


  • 0

Posted Image


#3

ShockQ
ShockQ
    Offline
    8
    Rep
    172
    Likes

    LOADS SELLER

  • PipPipPipPip
Posts: 125
Threads: 40
Joined: Apr 29, 2022
Credits: 0

Deal with caution
User has an open scam report.
User has joined recently.
Make sure to use a MiddleMan.
One year registered
#3
HQ LEAK as always!

  • 0

SELLIX  - CRYPTING SERVICE

LOADS SHOP

Telegram

Show some love and leave a like!
 


#4

krizen
krizen
    Offline
    0
    Rep
    0
    Likes

    Advanced Member

  • PipPipPipPip
Posts: 115
Threads: 0
Joined: Apr 21, 2018
Credits: 0
Six years registered
#4

you never dissapoint! thank you


  • 0

#5

xcxcxcxpuss
xcxcxcxpuss
    Offline
    0
    Rep
    1
    Likes

    Member

  • PipPipPip
Posts: 45
Threads: 0
Joined: Sep 09, 2022
Credits: 0
One year registered
#5

thanks man, mad appreciated


  • 0

#6

bumlazasta
bumlazasta
    Offline
    0
    Rep
    0
    Likes

    Lurker

Posts: 3
Threads: 0
Joined: Dec 01, 2022
Credits: 0
One year registered
#6

Great work as always!


  • 0

#7

Herrengels2
Herrengels2
    Offline
    0
    Rep
    0
    Likes

    Member

Posts: 37
Threads: 0
Joined: Nov 20, 2022
Credits: 0
One year registered
#7

ty


  • 0

#8

zelus
zelus
    Offline
    -1
    Rep
    8
    Likes

    Addicted

Posts: 175
Threads: 2
Joined: Aug 17, 2017
Credits: 0
Six years registered
#8

I will be taking this for myself


  • 0

the gods do not regard Reviews gotten with Vouch Copy so i do not.


#9

recruitm
recruitm
    Offline
    0
    Rep
    0
    Likes

    Member

Posts: 43
Threads: 2
Joined: Oct 06, 2022
Credits: 0
One year registered
#9

thanks so much bro


  • 0

#10

sandyeee
sandyeee
    Offline
    0
    Rep
    0
    Likes

    Lurker

Posts: 4
Threads: 0
Joined: Dec 03, 2022
Credits: 0
One year registered
#10

hi best upload you


  • 0


 Users browsing this thread: