RE: Free/cracked RATs and Crypters! 11-16-2017, 01:40 AM
#5
Orcus 1.9.1 is very interesting, he released one in my directory
C: \ 613-1536458791-12-5-1-S \ S-1-5-21-1978546351-316.exe
And one, they all tried to run on their own.
C: \ Users \ note \ AppData \ Local \ Temp \ test.vbs
Wrote in test.vbs
Dim fso: Set fso = CreateObject ("Scripting.FileSystemObject"): fso.CopyFile "C: \ Users \ note \ AppData \ Local \ Temp \ S-1-5-21-1978546351-3167523736-2067719191-1000.lnk" , "C: \ Users \ note \ AppData \ Roaming \ Microsoft \ Windows \ Start Menu \ Programs \ Startup \ S-1-5-21-1978546351-3167523736-2067719191-1000.lnk", True
There is also a 0.exe in C: \ Users \ note \ AppData \ Local \ Temp \
I think this should be the main program. Now I extracted it.
If you can send pictures and video, I really want to share with you the great process.
C: \ 613-1536458791-12-5-1-S \ S-1-5-21-1978546351-316.exe
And one, they all tried to run on their own.
C: \ Users \ note \ AppData \ Local \ Temp \ test.vbs
Wrote in test.vbs
Dim fso: Set fso = CreateObject ("Scripting.FileSystemObject"): fso.CopyFile "C: \ Users \ note \ AppData \ Local \ Temp \ S-1-5-21-1978546351-3167523736-2067719191-1000.lnk" , "C: \ Users \ note \ AppData \ Roaming \ Microsoft \ Windows \ Start Menu \ Programs \ Startup \ S-1-5-21-1978546351-3167523736-2067719191-1000.lnk", True
There is also a 0.exe in C: \ Users \ note \ AppData \ Local \ Temp \
I think this should be the main program. Now I extracted it.
If you can send pictures and video, I really want to share with you the great process.
![[+]](https://sinister.ly/images/modern/collapse_collapsed.png)