Create an account

Very important

  • To access the important data of the forums, you must be active in each forum and especially in the leaks and database leaks section, send data and after sending the data and activity, data and important content will be opened and visible for you.
  • You will only see chat messages from people who are at or below your level.
  • More than 500,000 database leaks and millions of account leaks are waiting for you, so access and view with more activity.
  • Many important data are inactive and inaccessible for you, so open them with activity. (This will be done automatically)


Thread Rating:
  • 352 Vote(s) - 3.56 Average
  • 1
  • 2
  • 3
  • 4
  • 5
[Virus] setup_hacxx_anonymous_file_search_v4_2210634171.rar

#1
Can anyone reverse this program and find out if there is any hidden gem?
Last time i scanned a file from this source i got a command line firewall bypass...

Download:

[To see links please register here]


Virus Scan: (22/71)

[To see links please register here]

Reply

#2
I'll quote @"miso".

He's RE'd a lot of programs, so hopefully he'll do the same with this.
Reply

#3
Quote:(04-14-2020, 03:48 AM)mothered Wrote:

[To see links please register here]

I'll quote @"miso".

He's RE'd a lot of programs, so hopefully he'll do the same with this.

thanks for mentioning me

When installing, it will open a fake youtube-like webpage
extracting the installer shows a bunch of file that just have a bunch of repeated word, the only exception is with the only .exe file, which cannot be launched (file cannot be loaded in windows and ExePeInfo says it is corrupted)

I think the detections are just from the installer loading a scammy url, however, i've loaded the installer into a sandbox, when installed on a vm for example, the files my have different data except that i really doubt it)

[Image: MLEA1z9DQxS6ABy-iIlwYQ.png]
[Image: 6McjykVxQiSoH4GVGkC5nQ.png]

btw it never loads, clicking anywhere on that page makes it fullscreen, waiting a bit will redirect you into other scammy sites

tools used:
HxD, InnoExtractor, ExePeInfo, Sandboxie
Reply

#4
Ok thanks. Last time i research a file from this service i got something similar to the code below

Hidden Content
You must

[To see links please register here]

or

[To see links please register here]

to view this content.


Also are you sure you tried correctly?
In my advertiser panel i have my install which was around 2AM and nothing else.
May have virtual machine protection.
Reply

#5
Quote:(04-14-2020, 07:48 PM)miso Wrote:

[To see links please register here]

thanks for mentioning me

You're welcome, and thanks for your prompt response.
Reply

#6
Quote:(04-14-2020, 08:40 PM)hacxx Wrote:

[To see links please register here]

Ok thanks. Last time i research a file from this service i got something similar to the code below

Hidden Content
You must

[To see links please register here]

or

[To see links please register here]

to view this content.


Also are you sure you tried correctly?
In my advertiser panel i have my install which was around 2AM and nothing else.
May have virtual machine protection.

i can't run vms due to my hardware not being able to run them (it cant run shit lol)

here's the files that i've extracted from the installer:

[To see links please register here]

[To see links please register here]

Reply

#7
For some reason when i executed the file on my computer it download and executed this two installers.
- SevenZip.exe - A clone of 7Zip
- Avast.exe - Avast installer

Here is the download link:

[To see links please register here]

Reply

#8
Quote:(04-14-2020, 11:52 PM)miso Wrote:

[To see links please register here]

i can't run vms due to my hardware not being able to run them (it cant run shit lol)

VMs are predominantly CPU & Ram dependent.

What's your specs pertaining to the above? We'll move back on-topic after your reply.
Reply

#9
x64, 4GB RAM, Dual-core CPU
[Image: config.png]
Reply



Forum Jump:


Users browsing this thread:
1 Guest(s)

©0Day  2016 - 2023 | All Rights Reserved.  Made with    for the community. Connected through