The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.
Seven Years of Service
Posts: 16
Threads: 16
DaRKDDoSeR 5.6c Cracked 04-19-2019, 08:53 PM
#1
[center]
![[Image: Screenshot-1.png]](https://i.postimg.cc/w3KBhVjs/Screenshot-1.png)
[/center]
[center]
DaRKDDoSeR 5.6c Cracked
DaRKDDoSeR simple tools for all kind of attack and stealing
[/center]
==========
[center]
UDP Flood
SYN FLood
HTTP attack
Slowloris attack
ARME attack
password stealing
ICQ:653580170
jabber: russianhackerclub@
Jabber.ru
Links removed- Staff.
Slowloris attack,UDP Flood,SYN FLood,HTTP attack,ARME attack,password stealing,ddos attack,ddos protection,denial of service attack,ddos mitigation,dns attack,ddos website,anti ddos
•
Six Years of Service
Posts: 16
Threads: 0
RE: DaRKDDoSeR 5.6c Cracked 05-25-2020, 07:27 PM
#2
Very cool....like to see stuff like this
•
Six Years of Service
Posts: 1,740
Threads: 502
RE: DaRKDDoSeR 5.6c Cracked 05-25-2020, 08:12 PM
#3
there is no virusscan, ill scan it later
•
Fourteen Years of Service
Posts: 74,287
Threads: 317
RE: DaRKDDoSeR 5.6c Cracked 05-25-2020, 10:04 PM
#4
(05-25-2020, 08:12 PM)miso Wrote: there is no virusscan, ill scan it later
Please do.
I can then deem whether to keep/remove the links.
•
Six Years of Service
Posts: 1,740
Threads: 502
RE: DaRKDDoSeR 5.6c Cracked 05-25-2020, 10:28 PM
#5
(05-25-2020, 10:04 PM)mothered Wrote: (05-25-2020, 08:12 PM)miso Wrote: there is no virusscan, ill scan it later
Please do.
I can then deem whether to keep/remove the links.
Failed to download, blocked by chrome, anonfile shows a virus warning
•
Fourteen Years of Service
Posts: 74,287
Threads: 317
RE: DaRKDDoSeR 5.6c Cracked 05-26-2020, 09:45 AM
#6
(05-25-2020, 10:28 PM)miso Wrote: anonfile shows a virus warning
![[Image: 0NcqART9R8eqYh6y70CAbg.png]](https://image.prntscr.com/image/0NcqART9R8eqYh6y70CAbg.png)
I get similar messages with AnonFiles, most of which are false positives.
•
Six Years of Service
Posts: 2
Threads: 0
RE: DaRKDDoSeR 5.6c Cracked 08-14-2020, 10:34 PM
#7
nice job dude keep up the good work
•
Nine Years of Service
Posts: 3,093
Threads: 132
RE: DaRKDDoSeR 5.6c Cracked 08-15-2020, 03:33 AM
#8
(08-14-2020, 10:34 PM)peshotriceps Wrote: nice job dude keep up the good work
I suggest you run it in a VM or Sandboxie. Tools in sketchy threads like this one tend to have some sort of infection. Of course, they could always be false positives. Just warning you.
•
Six Years of Service
Posts: 1,740
Threads: 502
RE: DaRKDDoSeR 5.6c Cracked 08-15-2020, 03:49 AM
#9
@
mothered , contains an malicious application, however, the main application uses it to inject itself
Code:
### Extracted files
DaRKDDoSeR_5.6c_Cracked.rar
|- DaRKDDoSeR+5.6c+Cracked
|- Backgrounds
|- "1.bmp" -> "17.bmp"
|- Icons
|- (76 icons)
|- vcl_skins
|- (131 .skn files)
|- DaRKDDoSeR.exe | Main application | Virustotal Scan [51/72]: https://www.virustotal.com/gui/file/ba72876bf978152d115b5c92d65708a56f0158dba13874e07aa15f81f0550801/detection
|- UPX.exe | UPX 3.0.0 | Virustotal Scan [2/71]: https://www.virustotal.com/gui/file/5bac20d7b5c926c52b74ad78c889c41bbd6615cf2240af391434f3f5b9a6f5fb/detection
|- login.ini
|- Stub.exe | Unused | Virustotal Scan [55/67]: https://www.virustotal.com/gui/file/f25cf98427f1aab7dd5724f80ba12b9065c323877030a4381db43692ac8ae3f9/detection
### - Stub.exe - ###
### MD:
CodeLang: Delphi
This application contains a bunch of URLs aswell as a bunch of WebClients, there is also references (from screen) to:
- "Run" (via registry)
- WindowsLive ("WindowsLive:name=*")
- SQL Lite
- Windows Update (probably isn't actually windows update, svchost.exe is the next string)
- Mozilla (probably dumps passwords & profiles (they're referenced)) | Only Mozilla
- Gets OS ("Windows NT", "Windows 2000" etc...)
this virus seems quite old since the "latest" windows version mentioned is Windows Vista, plus, most antiviruses detects it as malicious
### - DaRKDDoSeR.exe - ###
### MD:
CodeLang: Delphi
References (from strings):
- "FastMM Borland Edition"*
- "MouseZ"
- "GetMonitorInfo"
- "explorer"
- "Stub.exe"
I think that the main application injects "Stub.exe" onto the connected computer.
Fourteen Years of Service
Posts: 74,287
Threads: 317
RE: DaRKDDoSeR 5.6c Cracked 08-15-2020, 04:20 AM
#10
(08-15-2020, 03:49 AM)miso Wrote: @mothered , contains an malicious application, however, the main application uses it to inject itself
Code:
### Extracted files
DaRKDDoSeR_5.6c_Cracked.rar
|- DaRKDDoSeR+5.6c+Cracked
|- Backgrounds
|- "1.bmp" -> "17.bmp"
|- Icons
|- (76 icons)
|- vcl_skins
|- (131 .skn files)
|- DaRKDDoSeR.exe | Main application | Virustotal Scan [51/72]: https://www.virustotal.com/gui/file/ba72876bf978152d115b5c92d65708a56f0158dba13874e07aa15f81f0550801/detection
|- UPX.exe | UPX 3.0.0 | Virustotal Scan [2/71]: https://www.virustotal.com/gui/file/5bac20d7b5c926c52b74ad78c889c41bbd6615cf2240af391434f3f5b9a6f5fb/detection
|- login.ini
|- Stub.exe | Unused | Virustotal Scan [55/67]: https://www.virustotal.com/gui/file/f25cf98427f1aab7dd5724f80ba12b9065c323877030a4381db43692ac8ae3f9/detection
### - Stub.exe - ###
### MD:
CodeLang: Delphi
This application contains a bunch of URLs aswell as a bunch of WebClients, there is also references (from screen) to:
- "Run" (via registry)
- WindowsLive ("WindowsLive:name=*")
- SQL Lite
- Windows Update (probably isn't actually windows update, svchost.exe is the next string)
- Mozilla (probably dumps passwords & profiles (they're referenced)) | Only Mozilla
- Gets OS ("Windows NT", "Windows 2000" etc...)
this virus seems quite old since the "latest" windows version mentioned is Windows Vista, plus, most antiviruses detects it as malicious
### - DaRKDDoSeR.exe - ###
### MD:
CodeLang: Delphi
References (from strings):
- "FastMM Borland Edition"*
- "MouseZ"
- "GetMonitorInfo"
- "explorer"
- "Stub.exe"
I think that the main application injects "Stub.exe" onto the connected computer.
Once again, excellent work with your analysis.
I've removed all 3 download links.