Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


Dragon-Crypter filter_list
Author
Message
RE: Dragon-Crypter #11
as per @mothered  Request

Direct VT : https://www.virustotal.com/gui/file/352e.../detection

[Image: Q8qcpXIr_t.png]

[Image: sEMr3LcI_t.png]

(Just doing what was asked I dont mess with this stuff ! So again all im doing is just posting what was asked by staff)
(This post was last modified: 12-28-2021, 08:04 PM by ENCRYP73D_GH05T.)

[+] 2 users Like ENCRYP73D_GH05T's post
Reply

RE: Dragon-Crypter #12
Interesting! Can you please share what registry keys are created and modified and/or removed by the wscript? It's so fun to deobfuscate jcode and wscript, and this is the first time I've seen Neshta. I'll have to do some digging later tonight.
(This post was last modified: 12-28-2021, 08:30 PM by ConcernedCitizen. Edit Reason: phone )
ed25519/0x21AB6B6A6CB2C337
C87D87466FD205945CF10A3821AB6B6A6CB2C337

Reply

RE: Dragon-Crypter #13
(12-28-2021, 08:24 PM)vittring Wrote: Interesting! Can you please share what registry keys are created and modified and/or removed by the wscript? It's so fun to deobfuscate jcode and wscript, and this is the first time I've seen Neshta. I'll have to do some digging later tonight.
Yes my Good Sir No Problem It shall be uploaded  soon and i will Tag you Name

working on braking it down instead of crappy VT Reg Info

software\microsoft\windows\currentversion\run\Sound Realtek Update

wscript.exe //B "C:\Users\<USER>\AppData\Roaming\Sound Realtek Update.JS"

HKCR\exefile\shell\open\command\

C:\Windows\svchost.com "%1" %*

Neshta can be serious just depends on which version the person is Trying to infect with it some are way stronger than others
(This post was last modified: 12-28-2021, 08:54 PM by ENCRYP73D_GH05T.)

Reply

RE: Dragon-Crypter #14
(12-28-2021, 08:33 PM)ENCRYP73D_GH05T Wrote:
(12-28-2021, 08:24 PM)vittring Wrote: Interesting! Can you please share what registry keys are created and modified and/or removed by the wscript? It's so fun to deobfuscate jcode and wscript, and this is the first time I've seen Neshta. I'll have to do some digging later tonight.
Yes my Good Sir No Problem It shall be uploaded  soon and i will Tag you Name

working on braking it down instead of crappy VT Reg Info

software\microsoft\windows\currentversion\run\Sound Realtek Update

wscript.exe //B "C:\Users\<USER>\AppData\Roaming\Sound Realtek Update.JS"

HKCR\exefile\shell\open\command\

C:\Windows\svchost.com "%1" %*

Neshta can be serious just depends on which version the person is Trying to infect with it some are way stronger than others

What I've found so far is that this sample utilizes both reverse backdoors and USB spreading. It attempts to use the realtek update functionality to call out any filesharing systems such as Windows SMB and FTP, to the originating malware sender. Exfiltration can be stopped by filtering traffic from high ports by default.

Thanks for the info, I'm on mobile so it's hard to get into more procmon and regkey stuff. This is a known malware so no need to report the hashes. This is not even customized code so I'm betting whoever created it probably installed a server into it as a way to attack others that use it. 😅
ed25519/0x21AB6B6A6CB2C337
C87D87466FD205945CF10A3821AB6B6A6CB2C337

Reply

RE: Dragon-Crypter #15
(12-28-2021, 09:09 PM)vittring Wrote:
(12-28-2021, 08:33 PM)ENCRYP73D_GH05T Wrote:
(12-28-2021, 08:24 PM)vittring Wrote: Interesting! Can you please share what registry keys are created and modified and/or removed by the wscript? It's so fun to deobfuscate jcode and wscript, and this is the first time I've seen Neshta. I'll have to do some digging later tonight.
Yes my Good Sir No Problem It shall be uploaded  soon and i will Tag you Name

working on braking it down instead of crappy VT Reg Info

software\microsoft\windows\currentversion\run\Sound Realtek Update

wscript.exe //B "C:\Users\<USER>\AppData\Roaming\Sound Realtek Update.JS"

HKCR\exefile\shell\open\command\

C:\Windows\svchost.com "%1" %*

Neshta can be serious just depends on which version the person is Trying to infect with it some are way stronger than others

What I've found so far is that this sample utilizes both reverse backdoors and USB spreading. It attempts to use the realtek update functionality to call out any filesharing systems such as Windows SMB and FTP, to the originating malware sender. Exfiltration can be stopped by filtering traffic from high ports by default.

Thanks for the info, I'm on mobile so it's hard to get into more procmon and regkey stuff. This is a known malware so no need to report the hashes. This is not even customized code so I'm betting whoever created it probably installed a server into it as a way to attack others that use it. 😅
Biggest crap now and days in Redline Stealer -_- although if someone actually knows what thy are doing it can be hidden extremely well and become hard to detect !
But i better shut up no need to bring anymore attention or spam to this worthless thread ! although if you dig into it more please share some finding if you have the time !
it will be interesting to find more about it !

Reply

RE: Dragon-Crypter #16
(12-28-2021, 06:52 PM)keylimehat Wrote: Virus! destroyed my VB cant install any programs or enter task manager, windows doesn't understand what EXE file is , please delete this piece of sh*t
https://postimg.cc/gallery/XJqrRZb screenshots

with respect Keylimehat

@mothered
Thanks for bringing It to my attention.

For the safety of the community, I've removed the link.
[Image: AD83g1A.png]

[+] 1 user Likes mothered's post
Reply