Create an account

Very important

  • To access the important data of the forums, you must be active in each forum and especially in the leaks and database leaks section, send data and after sending the data and activity, data and important content will be opened and visible for you.
  • You will only see chat messages from people who are at or below your level.
  • More than 500,000 database leaks and millions of account leaks are waiting for you, so access and view with more activity.
  • Many important data are inactive and inaccessible for you, so open them with activity. (This will be done automatically)


Thread Rating:
  • 516 Vote(s) - 3.53 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Free | Malwarebytes Premium

#31
I think this could just be a problem with the current version of the software i think they probably patched it.
a lot of the packs I've seen for this aren't above version 3.7 (ish) .. im gonna download and old version and try to
verify this when i have the time


Here is a repack of 3.8

[To see links please register here]


Analysis of the file

[To see links please register here]


[To see links please register here]


It reported being malicious but i didn't see anything that looked to out of the ordinary i think it just reported so because of the behaviour of the repack.
I tested it and its working
Reply

#32
Quote:(06-17-2020, 11:38 PM)cyberchron Wrote:

[To see links please register here]

It reported being malicious but i didn't see anything that looked to out of the ordinary
The only thing that's of concern, Is this:
Quote:Contacts 1 domain/IP

It may well be contacting their official servers for licensing/software update purposes, but If this Is the case, I don't see why It's flagged as malicious.
Reply

#33
Quote:(06-18-2020, 06:19 AM)mothered Wrote:

[To see links please register here]

Quote: (06-17-2020, 11:38 PM)cyberchron Wrote:

[To see links please register here]

It reported being malicious but i didn't see anything that looked to out of the ordinary
The only thing that's of concern, Is this:
Quote:Contacts 1 domain/IP

It may well be contacting their official servers for licensing/software update purposes, but If this Is the case, I don't see why It's flagged as malicious.

Thats kind of what i thought as well. but this is what it connects to lol so i dunno. I don't know enough about this stuff to make an informed call. i installed it regardless so perhaps im a zombie now. feed me data
PTR IP: 3.8.3.29 - Amazon.com, Inc. (AS16509) ec2-3-8-3-29.eu-west-2.compute.amazonaws.com


ok maybe i read that log wrong.... is that the ip because it happens to be the version number of the malwarebytes hahaha so i dunno if its also just a false readout of some kind or im reading this stuff all wrong.
Reply

#34
Quote:(06-18-2020, 06:26 AM)cyberchron Wrote:

[To see links please register here]

Quote: (06-18-2020, 06:19 AM)mothered Wrote:

[To see links please register here]

Quote: (06-17-2020, 11:38 PM)cyberchron Wrote:

[To see links please register here]

It reported being malicious but i didn't see anything that looked to out of the ordinary
The only thing that's of concern, Is this:
Quote:Contacts 1 domain/IP

It may well be contacting their official servers for licensing/software update purposes, but If this Is the case, I don't see why It's flagged as malicious.

Thats kind of what i thought as well. but this is what it connects to lol so i dunno. I don't know enough about this stuff to make an informed call. i installed it regardless so perhaps im a zombie now. feed me data
PTR IP: 3.8.3.29 - Amazon.com, Inc. (AS16509) ec2-3-8-3-29.eu-west-2.compute.amazonaws.com


ok maybe i read that log wrong.... is that the ip because it happens to be the version number of the malwarebytes hahaha so i dunno if its also just a false readout of some kind or im reading this stuff all wrong.

Under (AS16509) , there's over 10 million domains hosted and 33+ million IP addresses.

It could be legit, but until It's analyzed, can't say for sure.
Reply

#35
Quote:(06-18-2020, 06:50 AM)mothered Wrote:

[To see links please register here]

Quote: (06-18-2020, 06:26 AM)cyberchron Wrote:

[To see links please register here]

Quote: (06-18-2020, 06:19 AM)mothered Wrote:

[To see links please register here]

The only thing that's of concern, Is this:

It may well be contacting their official servers for licensing/software update purposes, but If this Is the case, I don't see why It's flagged as malicious.

Thats kind of what i thought as well. but this is what it connects to lol so i dunno. I don't know enough about this stuff to make an informed call. i installed it regardless so perhaps im a zombie now. feed me data
PTR IP: 3.8.3.29 - Amazon.com, Inc. (AS16509) ec2-3-8-3-29.eu-west-2.compute.amazonaws.com


ok maybe i read that log wrong.... is that the ip because it happens to be the version number of the malwarebytes hahaha so i dunno if its also just a false readout of some kind or im reading this stuff all wrong.

Under (AS16509) , there's over 10 million domains hosted and 33+ million IP addresses.

It could be legit, but until It's analyzed, can't say for sure.

No but like look at the ip address.... and look at the version of this malwarebytes is what im saying. they are the same. I highly doubt some hacker just managed to get server address thats the same as the malwarebytes version. seems super strange to me.

IP = 3.8.3.29 && Malwarebytes Version # = 3.8.3.2965 so I mean coincidence?
Reply

#36
Quote:(06-18-2020, 07:14 AM)cyberchron Wrote:

[To see links please register here]

Quote: (06-18-2020, 06:50 AM)mothered Wrote:

[To see links please register here]

Quote: (06-18-2020, 06:26 AM)cyberchron Wrote:

[To see links please register here]

Thats kind of what i thought as well. but this is what it connects to lol so i dunno. I don't know enough about this stuff to make an informed call. i installed it regardless so perhaps im a zombie now. feed me data
PTR IP: 3.8.3.29 - Amazon.com, Inc. (AS16509) ec2-3-8-3-29.eu-west-2.compute.amazonaws.com


ok maybe i read that log wrong.... is that the ip because it happens to be the version number of the malwarebytes hahaha so i dunno if its also just a false readout of some kind or im reading this stuff all wrong.

Under (AS16509) , there's over 10 million domains hosted and 33+ million IP addresses.

It could be legit, but until It's analyzed, can't say for sure.

No but like look at the ip address.... and look at the version of this malwarebytes is what im saying. they are the same. I highly doubt some hacker just managed to get server address thats the same as the malwarebytes version. seems super strange to me.

IP = 3.8.3.29 && Malwarebytes Version # = 3.8.3.2965 so I mean coincidence?
I've understood this right from the get-go.

I'm the type who delves Into every Intricate detail, prior to making a decision on a given commodity.
Reply

#37
Quote:(06-18-2020, 07:34 AM)mothered Wrote:

[To see links please register here]

Quote: (06-18-2020, 07:14 AM)cyberchron Wrote:

[To see links please register here]

Quote: (06-18-2020, 06:50 AM)mothered Wrote:

[To see links please register here]

Under (AS16509) , there's over 10 million domains hosted and 33+ million IP addresses.

It could be legit, but until It's analyzed, can't say for sure.

No but like look at the ip address.... and look at the version of this malwarebytes is what im saying. they are the same. I highly doubt some hacker just managed to get server address thats the same as the malwarebytes version. seems super strange to me.

IP = 3.8.3.29 && Malwarebytes Version # = 3.8.3.2965 so I mean coincidence?
I've understood this right from the get-go.

I'm the type who delves Into every Intricate detail, prior to making a decision on a given commodity.

Fair enough m8 sorry for implying you weren't all there. didn't mean to offend

But since you noticed that too like what are the odds of that being legit? could the repack just put some information somewhere causing it to act like a connection or give out the reading of one or would that have to be intentional?

And is their a scenario in which people would straight up go out of their way to get a domain on a server that matches a version number just to create this type of confusion?

or I guess malwarebytes could have their reg server there maybe.?
i think i should get a legit copy and run it through that system and see what it outputs

I am so friggen intrigued by this hahahaha sorry for the million messages
I'm asking purely from an educational stand point because i don't know.
Reply



Forum Jump:


Users browsing this thread:
1 Guest(s)

©0Day  2016 - 2023 | All Rights Reserved.  Made with    for the community. Connected through