Create an account

Very important

  • To access the important data of the forums, you must be active in each forum and especially in the leaks and database leaks section, send data and after sending the data and activity, data and important content will be opened and visible for you.
  • You will only see chat messages from people who are at or below your level.
  • More than 500,000 database leaks and millions of account leaks are waiting for you, so access and view with more activity.
  • Many important data are inactive and inaccessible for you, so open them with activity. (This will be done automatically)


Thread Rating:
  • 287 Vote(s) - 3.4 Average
  • 1
  • 2
  • 3
  • 4
  • 5
[Scan Report]: Instagram Free Follower Tool v1.1

#1
i coudn't find the original thread of the application, however, i've downloaded it to manually scan it

this application sends your hardware configuration to an ip (47.254.216.24:8989), checks if it is running in a VM & setups a rat on user login
[Image: w1rH44w.png]

Less important screenshots:

Hidden Content
You must

[To see links please register here]

or

[To see links please register here]

to view this content.


Setups RAT on login:
[Image: ldSeT27.png]

TcpConnection:
[Image: Cge8n0J.png]
i still have the original sample, dm me if you want it (i will not share it on 0day.red publically, don't want to get banned)

here is some tools i've made to decrypt some things, like the resources & strings

[To see links please register here]

[To see links please register here]


[To see links please register here]

[To see links please register here]

@mothered[/hide]
[/hide]
Reply

#2
Excellent analysis Indeed.

Evidently, the file Is Infected with malicious Intent. Is

[To see links please register here]

the thread It relates to?
Reply

#3
Quote:(06-06-2020, 04:39 PM)mothered Wrote:

[To see links please register here]

Excellent analysis Indeed.

Evidently, the file Is Infected with malicious Intent. Is

[To see links please register here]

the thread It relates to?
yes indeed,thanks for finding the thread back
Reply

#4
Quote:(06-06-2020, 08:39 PM)miso Wrote:

[To see links please register here]

Quote: (06-06-2020, 04:39 PM)mothered Wrote:

[To see links please register here]

Excellent analysis Indeed.

Evidently, the file Is Infected with malicious Intent. Is

[To see links please register here]

the thread It relates to?
yes indeed,thanks for finding the thread back
Just wanted to make sure prior to taking action.

I've removed It from the said thread, and action has been taken accordingly against the OP.
Once again, good work with your analytical reports.
Reply



Forum Jump:


Users browsing this thread:
1 Guest(s)

©0Day  2016 - 2023 | All Rights Reserved.  Made with    for the community. Connected through