Login Register






The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.
Thread Rating:
  • 0 Vote(s) - 0 Average


GTA 4 Files , False Flag ?! filter_list
Author
Message
GTA 4 Files , False Flag ?! #1
Hello everyone, i had GTA 4 Cracked ,everything cool but i checked the cracks files and findout that they are sus!. for me i think its false Flag  for many reasons ,but i wanted to make sure and ask peoples who had this files before or peoples who can test better.is those DLLs safe ? considering they are made 4 years ago tho.
Files of GTA IV crack (from Prophet) : https://gofile.io/d/asGPRH  (558 kb File + i removed the .exe cracks they are safe)

Scans: https://www.virustotal.com/gui/file/d1dc.../detection

and : https://www.virustotal.com/gui/file/7527...fc/details

looking forward of your opinions.
(This post was last modified: 11-21-2020, 02:05 PM by TheMinister.)
[Image: meChCe1.png]

Reply

RE: GTA 4 Files , False Flag ?! #2
This looks like a job for @"miso" since he's skilled at analyzing files, but here are a few of my observations. If the files really are infected I suspect they've been infected with the Cerberus RAT, and have also been crypted with an open source obfuscator. Based on detections like "Gen:Variant.Cerbu.76118", "Win32:Trojan-gen", and "VirTool:Win32/Obfuscator.f5993fec" I can conclude that. And since this is a possible remote access tool, I highly doubt whoever created the RAT server is still operating with that same DNS and port.

If you've already ran the program and see nothing abnormal like files you don't remember creating, strange system processes, system slowdowns, system or program crashing on your system, it should be safe to keep using this crack. If this is or was a virus, that would be a different story since virus' spread on their own without the need for human control.

Reply

RE: GTA 4 Files , False Flag ?! #3
(11-21-2020, 07:54 PM)Drako Wrote: This looks like a job for @"miso" since he's skilled at analyzing files, but here are a few of my observations. If the files really are infected I suspect they've been infected with the Cerberus RAT, and have also been crypted with an open source obfuscator. Based on detections like "Gen:Variant.Cerbu.76118", "Win32:Trojan-gen", and "VirTool:Win32/Obfuscator.f5993fec" I can conclude that. And since this is a possible remote access tool, I highly doubt whoever created the RAT server is still operating with that same DNS and port.

If you've already ran the program and see nothing abnormal like files you don't remember creating, strange system processes, system slowdowns, system or program crashing on your system, it should be safe to keep using this crack. If this is or was a virus, that would be a different story since virus' spread on their own without the need for human control.
thanks for reply, i didn't run the program on my pc, and those DLLs are C++ i don't know how to check C++ DLLs yet . and yes your point is good this is 4 years old at least by the hash submission, rarely that the file is infected and the DNS is still running because this is Skidrow's website version since 2016. i still need a detailed opinion about those C++ DLLs.
(This post was last modified: 11-21-2020, 09:53 PM by TheMinister.)
[Image: meChCe1.png]

Reply

RE: GTA 4 Files , False Flag ?! #4
(11-21-2020, 07:54 PM)Drako Wrote: This looks like a job for @"miso" since he's skilled at analyzing files, but here are a few of my observations. If the files really are infected I suspect they've been infected with the Cerberus RAT, and have also been crypted with an open source obfuscator. Based on detections like "Gen:Variant.Cerbu.76118", "Win32:Trojan-gen", and "VirTool:Win32/Obfuscator.f5993fec" I can conclude that. And since this is a possible remote access tool, I highly doubt whoever created the RAT server is still operating with that same DNS and port.

If you've already ran the program and see nothing abnormal like files you don't remember creating, strange system processes, system slowdowns, system or program crashing on your system, it should be safe to keep using this crack. If this is or was a virus, that would be a different story since virus' spread on their own without the need for human control.

This is actually a good point. I'm certain a lot of cracked applications from 4+ years ago still work, but the malware on them is likely well past a functioning state. Not that you'd want to run the programs, but there might not be any consequences.
[Image: fSEZXPs.png]

[+] 2 users Like Dismas's post
Reply

RE: GTA 4 Files , False Flag ?! #5
can't really show concluent proof that its malicious due to the VMProtect version used, but it very likely is.

- The .exes just loads the DLLs, they arent obfuscated
- DLLs seems to check if they've been loaded with the right app.

Reply

RE: GTA 4 Files , False Flag ?! #6
(11-22-2020, 12:34 AM)miso Wrote: can't really show concluent proof that its malicious due to the VMProtect version used, but it very likely is.

- The .exes just loads the DLLs, they arent obfuscated
- DLLs seems to check if they've been loaded with the right app.
thank you for the effort miso, which app you use to read the DLLs ?
[Image: meChCe1.png]

Reply

RE: GTA 4 Files , False Flag ?! #7
(11-22-2020, 12:49 AM)TheMinister Wrote:
(11-22-2020, 12:34 AM)miso Wrote: can't really show concluent proof that its malicious due to the VMProtect version used, but it very likely is.

- The .exes just loads the DLLs, they arent obfuscated
- DLLs seems to check if they've been loaded with the right app.
thank you for  the effort miso, which app you use to read the DLLs ?
private app, can't say the name for multiple reasons

you probably can just use some hex editor or string viewer, it'll probably have the same effect
(This post was last modified: 11-22-2020, 12:52 AM by miso.)

[+] 1 user Likes miso's post
Reply

RE: GTA 4 Files , False Flag ?! #8
(11-22-2020, 12:51 AM)miso Wrote: you probably can just use some hex editor or string viewer, it'll probably have the same effect

i searched sinister.ly with no result on string viewer , any suggestion ? also no one has proof that those DLLs are meant to be bad right ?
[Image: meChCe1.png]

Reply

RE: GTA 4 Files , False Flag ?! #9
i did some digging , the game doesn't add any files in appdata or registry etc. it has suspecious IP calls and some DNS arpa calls:
239.255.255.250 port: 1900 UDP
224.0.0.251 port: 41
www.rockstargames.com
tv.rockstargames.com
DNS: DNS host : c.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
the first IP address Could be used for C&C calls at that time. use virustotal for the IPs!
[Image: meChCe1.png]

Reply

RE: GTA 4 Files , False Flag ?! #10
(11-22-2020, 08:32 PM)TheMinister Wrote: i did some digging , the game doesn't add any files in appdata or registry etc. it has suspecious IP calls and some DNS arpa calls:
239.255.255.250 port: 1900 UDP
224.0.0.251 port:  41
www.rockstargames.com
tv.rockstargames.com
DNS: DNS host : c.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
the first IP address Could be used for C&C calls at that time. use virustotal for the IPs!
heres a decent one

Reply







Users browsing this thread: 1 Guest(s)