RE: DaRKDDoSeR 5.6c Cracked - LORDSHIPXING - 08-15-2020
(08-15-2020, 03:49 AM)miso Wrote: @mothered , contains an malicious application, however, the main application uses it to inject itself
Code: ### Extracted files
DaRKDDoSeR_5.6c_Cracked.rar
|- DaRKDDoSeR+5.6c+Cracked
|- Backgrounds
|- "1.bmp" -> "17.bmp"
|- Icons
|- (76 icons)
|- vcl_skins
|- (131 .skn files)
|- DaRKDDoSeR.exe | Main application | Virustotal Scan [51/72]: https://www.virustotal.com/gui/file/ba72876bf978152d115b5c92d65708a56f0158dba13874e07aa15f81f0550801/detection
|- UPX.exe | UPX 3.0.0 | Virustotal Scan [2/71]: https://www.virustotal.com/gui/file/5bac20d7b5c926c52b74ad78c889c41bbd6615cf2240af391434f3f5b9a6f5fb/detection
|- login.ini
|- Stub.exe | Unused | Virustotal Scan [55/67]: https://www.virustotal.com/gui/file/f25cf98427f1aab7dd5724f80ba12b9065c323877030a4381db43692ac8ae3f9/detection
### - Stub.exe - ###
### MD:
CodeLang: Delphi
This application contains a bunch of URLs aswell as a bunch of WebClients, there is also references (from screen) to:
- "Run" (via registry)
- WindowsLive ("WindowsLive:name=*")
- SQL Lite
- Windows Update (probably isn't actually windows update, svchost.exe is the next string)
- Mozilla (probably dumps passwords & profiles (they're referenced)) | Only Mozilla
- Gets OS ("Windows NT", "Windows 2000" etc...)
this virus seems quite old since the "latest" windows version mentioned is Windows Vista, plus, most antiviruses detects it as malicious
### - DaRKDDoSeR.exe - ###
### MD:
CodeLang: Delphi
References (from strings):
- "FastMM Borland Edition"*
- "MouseZ"
- "GetMonitorInfo"
- "explorer"
- "Stub.exe"
I think that the main application injects "Stub.exe" onto the connected computer.
6666666666 Godly work @miso.
RE: DaRKDDoSeR 5.6c Cracked - miso - 08-15-2020
(08-15-2020, 04:20 AM)mothered Wrote: (08-15-2020, 03:49 AM)miso Wrote: @mothered , contains an malicious application, however, the main application uses it to inject itself
Code: ### Extracted files
DaRKDDoSeR_5.6c_Cracked.rar
|- DaRKDDoSeR+5.6c+Cracked
|- Backgrounds
|- "1.bmp" -> "17.bmp"
|- Icons
|- (76 icons)
|- vcl_skins
|- (131 .skn files)
|- DaRKDDoSeR.exe | Main application | Virustotal Scan [51/72]: https://www.virustotal.com/gui/file/ba72876bf978152d115b5c92d65708a56f0158dba13874e07aa15f81f0550801/detection
|- UPX.exe | UPX 3.0.0 | Virustotal Scan [2/71]: https://www.virustotal.com/gui/file/5bac20d7b5c926c52b74ad78c889c41bbd6615cf2240af391434f3f5b9a6f5fb/detection
|- login.ini
|- Stub.exe | Unused | Virustotal Scan [55/67]: https://www.virustotal.com/gui/file/f25cf98427f1aab7dd5724f80ba12b9065c323877030a4381db43692ac8ae3f9/detection
### - Stub.exe - ###
### MD:
CodeLang: Delphi
This application contains a bunch of URLs aswell as a bunch of WebClients, there is also references (from screen) to:
- "Run" (via registry)
- WindowsLive ("WindowsLive:name=*")
- SQL Lite
- Windows Update (probably isn't actually windows update, svchost.exe is the next string)
- Mozilla (probably dumps passwords & profiles (they're referenced)) | Only Mozilla
- Gets OS ("Windows NT", "Windows 2000" etc...)
this virus seems quite old since the "latest" windows version mentioned is Windows Vista, plus, most antiviruses detects it as malicious
### - DaRKDDoSeR.exe - ###
### MD:
CodeLang: Delphi
References (from strings):
- "FastMM Borland Edition"*
- "MouseZ"
- "GetMonitorInfo"
- "explorer"
- "Stub.exe"
I think that the main application injects "Stub.exe" onto the connected computer.
Once again, excellent work with your analysis.
I've removed all 3 download links. the application does what its supposed to do, but terribly
RE: DaRKDDoSeR 5.6c Cracked - mothered - 08-15-2020
(08-15-2020, 06:43 AM)miso Wrote: (08-15-2020, 04:20 AM)mothered Wrote: (08-15-2020, 03:49 AM)miso Wrote: @mothered , contains an malicious application, however, the main application uses it to inject itself
Code: ### Extracted files
DaRKDDoSeR_5.6c_Cracked.rar
|- DaRKDDoSeR+5.6c+Cracked
|- Backgrounds
|- "1.bmp" -> "17.bmp"
|- Icons
|- (76 icons)
|- vcl_skins
|- (131 .skn files)
|- DaRKDDoSeR.exe | Main application | Virustotal Scan [51/72]: https://www.virustotal.com/gui/file/ba72876bf978152d115b5c92d65708a56f0158dba13874e07aa15f81f0550801/detection
|- UPX.exe | UPX 3.0.0 | Virustotal Scan [2/71]: https://www.virustotal.com/gui/file/5bac20d7b5c926c52b74ad78c889c41bbd6615cf2240af391434f3f5b9a6f5fb/detection
|- login.ini
|- Stub.exe | Unused | Virustotal Scan [55/67]: https://www.virustotal.com/gui/file/f25cf98427f1aab7dd5724f80ba12b9065c323877030a4381db43692ac8ae3f9/detection
### - Stub.exe - ###
### MD:
CodeLang: Delphi
This application contains a bunch of URLs aswell as a bunch of WebClients, there is also references (from screen) to:
- "Run" (via registry)
- WindowsLive ("WindowsLive:name=*")
- SQL Lite
- Windows Update (probably isn't actually windows update, svchost.exe is the next string)
- Mozilla (probably dumps passwords & profiles (they're referenced)) | Only Mozilla
- Gets OS ("Windows NT", "Windows 2000" etc...)
this virus seems quite old since the "latest" windows version mentioned is Windows Vista, plus, most antiviruses detects it as malicious
### - DaRKDDoSeR.exe - ###
### MD:
CodeLang: Delphi
References (from strings):
- "FastMM Borland Edition"*
- "MouseZ"
- "GetMonitorInfo"
- "explorer"
- "Stub.exe"
I think that the main application injects "Stub.exe" onto the connected computer.
Once again, excellent work with your analysis.
I've removed all 3 download links. the application does what its supposed to do, but terribly Best I removed It to avoid questions and concerns.
|