ALERT!
Click here to register with a few steps and explore all our cool stuff we have to offer!

Jump to content



Photo

Chaos Ransomware Builder V4 - Cleaned by ObbedCode


  • Please log in to reply
Chaos Ransomware Builder V4 - Cleaned by ObbedCode

#61

Hagoromo
Hagoromo
    Offline
    0
    Rep
    0
    Likes

    Sage of Six Paths

Posts: 103
Threads: 1
Joined: May 04, 2017
Credits: 0
Seven years registered
#61

Good work mate


  • 0

IX5FHUy.png


#62

jesusnus
jesusnus
    Offline
    0
    Rep
    0
    Likes

    New Member

  • PipPip
Posts: 22
Threads: 0
Joined: Apr 22, 2023
Credits: 0
One year registered
#62

thanks. gonna try it out now


  • 0

#63

AlterioFarto
AlterioFarto
    Offline
    0
    Rep
    0
    Likes

    Member

Posts: 71
Threads: 0
Joined: Apr 23, 2023
Credits: 0
One year registered
#63
Thanks for the work

  • 0

#64

Tinet2021
Tinet2021
    Offline
    0
    Rep
    0
    Likes

    Lurker

Posts: 1
Threads: 0
Joined: Apr 27, 2023
Credits: 0
One year registered
#64

kinda good ngl, thank you as always!


  • 0

#65

supermanman
supermanman
    Offline
    0
    Rep
    1
    Likes

    New Member

Posts: 15
Threads: 0
Joined: May 08, 2023
Credits: 0
One year registered
#65

 

To clean the file we have to rename a .DLL to .EXE and modify some sus IL Code.

Removed the Original .exe that is just a virus :(

 

Note I cleaned the File, You Can analyze the file for yourself in DnSpy

Still Run everything in a Controlled Environment. My version is the Fully Cleaned Version.

 

 Even has the Decryptor in the same Folder

  

Person Spreading Malware:

Spoiler

 

Original Report:

 

Spoiler

 

===================================================================

DOWNLOAD

===================================================================

Password: Chaos46366


Upload.ee

 

 

Anonfile

 

 

Zippyshare

 

 

Mirror Ace

 

 

===================================================================

SCREENSHOTS

===================================================================

 

Spoiler

 

Original Analysis:

(Still always run EVERYTHING in Sandbox / Virtual Machine)

 

Stub SRC:

Please Login or Register to see this Hidden Content

 

VT:

Please Login or Register to see this Hidden Content

HB:

Please Login or Register to see this Hidden Content

 

Please Login or Register to see this Hidden Content

 


  • 0

#66

kzvnnnnn
kzvnnnnn
    Offline
    0
    Rep
    0
    Likes

    Member

Posts: 40
Threads: 0
Joined: Mar 10, 2023
Credits: 0
One year registered
#66

wow, I'll take a look and come back with an update


  • 0

#67

browhatjshppn
browhatjshppn
    Offline
    0
    Rep
    0
    Likes

    New Member

Posts: 24
Threads: 0
Joined: Feb 07, 2023
Credits: 0
One year registered
#67

ty


  • 0

#68

yohuwa
yohuwa
    Offline
    0
    Rep
    0
    Likes

    Advanced Member

  • PipPipPipPip
Posts: 89
Threads: 0
Joined: Sep 08, 2022
Credits: 0
One year registered
#68

cool


  • 0

#69

yasu131
yasu131
    Offline
    0
    Rep
    0
    Likes

    Member

Posts: 36
Threads: 0
Joined: May 09, 2023
Credits: 0

One year registered
#69

good job bro thanks


  • 0

#70

xldogefu686
xldogefu686
    Offline
    0
    Rep
    0
    Likes

    Lurker

Posts: 8
Threads: 0
Joined: May 26, 2023
Credits: 0
Half year registered
#70

dsfdsfdsdsfsdf


  • 0


 Users browsing this thread: