The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.
Four Years of Service
Posts: 226
Threads: 107
RE: Dragon-Crypter 12-28-2021, 08:01 PM
#11
as per @
mothered Request
Direct VT :
https://www.virustotal.com/gui/file/352e.../detection
(Just doing what was asked I dont mess with this stuff ! So again all im doing is just posting what was asked by staff)
(This post was last modified: 12-28-2021, 08:04 PM by ENCRYP73D_GH05T.)
Five Years of Service
Posts: 743
Threads: 63
RE: Dragon-Crypter 12-28-2021, 08:24 PM
#12
Interesting! Can you please share what registry keys are created and modified and/or removed by the wscript? It's so fun to deobfuscate jcode and wscript, and this is the first time I've seen Neshta. I'll have to do some digging later tonight.
(This post was last modified: 12-28-2021, 08:30 PM by ConcernedCitizen.
Edit Reason: phone
)
ed25519/0x21AB6B6A6CB2C337
C87D87466FD205945CF10A3821AB6B6A6CB2C337
•
Four Years of Service
Posts: 226
Threads: 107
RE: Dragon-Crypter 12-28-2021, 08:33 PM
#13
(12-28-2021, 08:24 PM)vittring Wrote: Interesting! Can you please share what registry keys are created and modified and/or removed by the wscript? It's so fun to deobfuscate jcode and wscript, and this is the first time I've seen Neshta. I'll have to do some digging later tonight.
Yes my Good Sir No Problem It shall be uploaded soon and i will Tag you Name
working on braking it down instead of crappy VT Reg Info
software\microsoft\windows\currentversion\run\Sound Realtek Update
wscript.exe //B "C:\Users\<USER>\AppData\Roaming\Sound Realtek Update.JS"
HKCR\exefile\shell\open\command\
C:\Windows\svchost.com "%1" %*
Neshta can be serious just depends on which version the person is Trying to infect with it some are way stronger than others
(This post was last modified: 12-28-2021, 08:54 PM by ENCRYP73D_GH05T.)
•
Five Years of Service
Posts: 743
Threads: 63
RE: Dragon-Crypter 12-28-2021, 09:09 PM
#14
(12-28-2021, 08:33 PM)ENCRYP73D_GH05T Wrote: (12-28-2021, 08:24 PM)vittring Wrote: Interesting! Can you please share what registry keys are created and modified and/or removed by the wscript? It's so fun to deobfuscate jcode and wscript, and this is the first time I've seen Neshta. I'll have to do some digging later tonight.
Yes my Good Sir No Problem It shall be uploaded soon and i will Tag you Name
working on braking it down instead of crappy VT Reg Info
software\microsoft\windows\currentversion\run\Sound Realtek Update
wscript.exe //B "C:\Users\<USER>\AppData\Roaming\Sound Realtek Update.JS"
HKCR\exefile\shell\open\command\
C:\Windows\svchost.com "%1" %*
Neshta can be serious just depends on which version the person is Trying to infect with it some are way stronger than others
What I've found so far is that this sample utilizes both reverse backdoors and USB spreading. It attempts to use the realtek update functionality to call out any filesharing systems such as Windows SMB and FTP, to the originating malware sender. Exfiltration can be stopped by filtering traffic from high ports by default.
Thanks for the info, I'm on mobile so it's hard to get into more procmon and regkey stuff. This is a known malware so no need to report the hashes. This is not even customized code so I'm betting whoever created it probably installed a server into it as a way to attack others that use it. 😅
ed25519/0x21AB6B6A6CB2C337
C87D87466FD205945CF10A3821AB6B6A6CB2C337
•
Four Years of Service
Posts: 226
Threads: 107
RE: Dragon-Crypter 12-28-2021, 09:22 PM
#15
(12-28-2021, 09:09 PM)vittring Wrote: (12-28-2021, 08:33 PM)ENCRYP73D_GH05T Wrote: (12-28-2021, 08:24 PM)vittring Wrote: Interesting! Can you please share what registry keys are created and modified and/or removed by the wscript? It's so fun to deobfuscate jcode and wscript, and this is the first time I've seen Neshta. I'll have to do some digging later tonight.
Yes my Good Sir No Problem It shall be uploaded soon and i will Tag you Name
working on braking it down instead of crappy VT Reg Info
software\microsoft\windows\currentversion\run\Sound Realtek Update
wscript.exe //B "C:\Users\<USER>\AppData\Roaming\Sound Realtek Update.JS"
HKCR\exefile\shell\open\command\
C:\Windows\svchost.com "%1" %*
Neshta can be serious just depends on which version the person is Trying to infect with it some are way stronger than others
What I've found so far is that this sample utilizes both reverse backdoors and USB spreading. It attempts to use the realtek update functionality to call out any filesharing systems such as Windows SMB and FTP, to the originating malware sender. Exfiltration can be stopped by filtering traffic from high ports by default.
Thanks for the info, I'm on mobile so it's hard to get into more procmon and regkey stuff. This is a known malware so no need to report the hashes. This is not even customized code so I'm betting whoever created it probably installed a server into it as a way to attack others that use it. 😅
Biggest crap now and days in Redline Stealer -_- although if someone actually knows what thy are doing it can be hidden extremely well and become hard to detect !
But i better shut up no need to bring anymore attention or spam to this worthless thread ! although if you dig into it more please share some finding if you have the time !
it will be interesting to find more about it !
•
Fourteen Years of Service
Posts: 74,287
Threads: 317
RE: Dragon-Crypter 12-29-2021, 02:49 AM
#16
(12-28-2021, 06:52 PM)keylimehat Wrote: Virus! destroyed my VB cant install any programs or enter task manager, windows doesn't understand what EXE file is , please delete this piece of sh*t
https://postimg.cc/gallery/XJqrRZb screenshots
with respect Keylimehat
@mothered
Thanks for bringing It to my attention.
For the safety of the community, I've removed the link.