Create an account

Very important

  • To access the important data of the forums, you must be active in each forum and especially in the leaks and database leaks section, send data and after sending the data and activity, data and important content will be opened and visible for you.
  • You will only see chat messages from people who are at or below your level.
  • More than 500,000 database leaks and millions of account leaks are waiting for you, so access and view with more activity.
  • Many important data are inactive and inaccessible for you, so open them with activity. (This will be done automatically)


Thread Rating:
  • 968 Vote(s) - 3.57 Average
  • 1
  • 2
  • 3
  • 4
  • 5
[Scan Report & Debloated download]: Digital Ocean Checker by Redey (shared by Betski)

#1
Thanks to @HailHydra, this woudn't have been revealed without him notifiying me about Betski's software posts

When loading the executable, it will unpack in a folder (%appdata%), here are the files extracted by the application
[Image: QGU15XfxQD6Tk_S2D-eHIg.png]

wof.bat is where the malware gets downloaded, via this command
[Image: mnypDoNhSQ_0JvLHJOmM-Q.png]
av.bat tries to disable Windows Defender via the regedit
[Image: pUZRdH9TRMWx_JMq_VqN0w.png]
i haven't been able to decompile test.exe, however, it has a lot of detections on virustotal and browsing through it via MiTeC EXE Explorer shows a interactions with the "Downloads" folder

[To see links please register here]


[Image: ONYozkooS52GBQ9VBazlDg.png]

The file that gets downloaded (Systemas.exe) can't be downloaded anymore, so i can't go further, however, the script renames it a System32.exe, which is a supicious file name
[Image: safv3U-9S3a4uLoCGCouWw.png]

The thread was released 1 day after the edits on the application has been made (containing the malwares)
[Image: CmiO2CeMR2yl3xFY0IpWOQ.png]
[Image: rUlijW36QIKIbILU3-WdtQ.png]

here's a download link with only the standalone application:

Files (1):

Hidden Content
You must

[To see links please register here]

or

[To see links please register here]

to view this content.


[To see links please register here]

[To see links please register here]

Reply

#2
Quote:(06-07-2020, 03:27 PM)miso Wrote:

[To see links please register here]

here's a download link with only the standalone application:

Files (1):

Hidden Content
You must

[To see links please register here]

or

[To see links please register here]

to view this content.


[To see links please register here]

[To see links please register here]

Good work with extracting the standalone application.

As I've mentioned In the other thread, I've yet to come across a tool of this nature that requires Installation.
Reply

#3
Quote:(06-07-2020, 04:28 PM)mothered Wrote:

[To see links please register here]

Quote: (06-07-2020, 03:27 PM)miso Wrote:

[To see links please register here]

here's a download link with only the standalone application:

Files (1):

Hidden Content
You must

[To see links please register here]

or

[To see links please register here]

to view this content.


[To see links please register here]

[To see links please register here]

Good work with extracting the standalone application.

As I've mentioned In the other thread, I've yet to come across a tool of this nature that requires Installation.
he also shared viruses with the application (?) why don't you do anything about it?
Reply

#4
Quote:(06-07-2020, 04:40 PM)miso Wrote:

[To see links please register here]

he also shared viruses with the application (?) why don't you do anything about it?
It may well be without his knowledge that the file Is Infected, whereby It's simply obtained from a given source on the assumption that It's clean.

Prior to making a decision, I'll allow him the opportunity to reply In his defense.
Reply



Forum Jump:


Users browsing this thread:
1 Guest(s)

©0Day  2016 - 2023 | All Rights Reserved.  Made with    for the community. Connected through