VEGAS.Pro.15.0.0.384 07-17-2018, 01:09 AM
#1
| VEGAS.Pro.15.0.0.384 filter_list | |
RE: VEGAS.Pro.15.0.0.384 07-17-2018, 05:04 AM
#3
Patcher:
VT (41/66): https://www.virustotal.com/#/file/88178a.../detection
dup2patcher.dll:
VT (34/67): https://www.virustotal.com/#/file/690bd7.../detection
bassmod.dll:
VT (4/66): https://www.virustotal.com/#/file/844eb6.../community
7CEB9B2A0E395BD64E74381485A106AF.dll
VT (0/65): https://www.virustotal.com/#/file/125fc7.../detection
Detections are labeled as "hack tools" which is fine. The application simply drops and loads a dup2patcher.dll which is what I assume to be the thing that applies the patches. I know dup2 is a well-known patching/loader tool that goes way back. I've never actually seen a dup2 tool used in the wild but then again I don't download cracked software. I did not see any network connections, attempts at start up persistence or additional processes executed. The program seemed to be patched successfully and executed properly.
Results are inconclusive but I think it should be safe. Of course caution must be taken when downloading and using any cracked software.
VT (41/66): https://www.virustotal.com/#/file/88178a.../detection
dup2patcher.dll:
VT (34/67): https://www.virustotal.com/#/file/690bd7.../detection
bassmod.dll:
VT (4/66): https://www.virustotal.com/#/file/844eb6.../community
7CEB9B2A0E395BD64E74381485A106AF.dll
VT (0/65): https://www.virustotal.com/#/file/125fc7.../detection
Detections are labeled as "hack tools" which is fine. The application simply drops and loads a dup2patcher.dll which is what I assume to be the thing that applies the patches. I know dup2 is a well-known patching/loader tool that goes way back. I've never actually seen a dup2 tool used in the wild but then again I don't download cracked software. I did not see any network connections, attempts at start up persistence or additional processes executed. The program seemed to be patched successfully and executed properly.
Results are inconclusive but I think it should be safe. Of course caution must be taken when downloading and using any cracked software.
RE: VEGAS.Pro.15.0.0.384 07-17-2018, 05:37 AM
#4
(07-17-2018, 05:04 AM)reGEN Wrote: Patcher:
VT (41/66): https://www.virustotal.com/#/file/88178a.../detection
dup2patcher.dll:
VT (34/67): https://www.virustotal.com/#/file/690bd7.../detection
bassmod.dll:
VT (4/66): https://www.virustotal.com/#/file/844eb6.../community
7CEB9B2A0E395BD64E74381485A106AF.dll
VT (0/65): https://www.virustotal.com/#/file/125fc7.../detection
Detections are labeled as "hack tools" which is fine. The application simply drops and loads a dup2patcher.dll which is what I assume to be the thing that applies the patches. I know dup2 is a well-known patching/loader tool that goes way back. I've never actually seen a dup2 tool used in the wild but then again I don't download cracked software. I did not see any network connections, attempts at start up persistence or additional processes executed. The program seemed to be patched successfully and executed properly.
Results are inconclusive but I think it should be safe. Of course caution must be taken when downloading and using any cracked software.
Appreciate your In depth report and analysis.
It saves me from testing It and providing the online virus scan report. False positive detections can be expected, however precautionary measures must always be the first port of call and your comment sums It up.
Quote:Of course caution must be taken when downloading and using any cracked software.
Preferably use a dedicated physical machine segregated from the network, with a Guest OS (VM) running with Sandboxie Installed. All files should be executed In the latter.
RE: VEGAS.Pro.15.0.0.384 07-17-2018, 06:21 AM
#5
I try to help when it comes to software download because I love hunting for malware! Especially the rush when I find something super dodgy.
RE: VEGAS.Pro.15.0.0.384 07-17-2018, 07:38 AM
#7
(07-17-2018, 06:21 AM)reGEN Wrote: I try to help when it comes to software download because I love hunting for malware!
Judging by your posts and the context of which they're written, I've certainly come to realize your analytical approach with malicious software.
RE: VEGAS.Pro.15.0.0.384 07-17-2018, 07:52 AM
#8
(07-17-2018, 05:04 AM)reGEN Wrote: Patcher:
VT (41/66): https://www.virustotal.com/#/file/88178a.../detection
dup2patcher.dll:
VT (34/67): https://www.virustotal.com/#/file/690bd7.../detection
bassmod.dll:
VT (4/66): https://www.virustotal.com/#/file/844eb6.../community
7CEB9B2A0E395BD64E74381485A106AF.dll
VT (0/65): https://www.virustotal.com/#/file/125fc7.../detection
Detections are labeled as "hack tools" which is fine. The application simply drops and loads a dup2patcher.dll which is what I assume to be the thing that applies the patches. I know dup2 is a well-known patching/loader tool that goes way back. I've never actually seen a dup2 tool used in the wild but then again I don't download cracked software. I did not see any network connections, attempts at start up persistence or additional processes executed. The program seemed to be patched successfully and executed properly.
Results are inconclusive but I think it should be safe. Of course caution must be taken when downloading and using any cracked software.
Couldn't you try doing it in a single file or, was the size to big?
RE: VEGAS.Pro.15.0.0.384 07-17-2018, 07:58 AM
#9
(07-17-2018, 07:52 AM)Mimiakira Wrote: Couldn't you try doing it in a single file or, was the size to big?
The setup file is about 400 MB which is too big to upload to VT. The patching program (as described by the "Patcher" label) was also included which packed three other files (the DLLs). The DLLs were deobfuscated and each individually dropped into the temp path directory. So even if I uploaded the patcher by itself, AV may not have been able to detect the DLLs if they happened to be malicious.
RE: VEGAS.Pro.15.0.0.384 07-17-2018, 08:12 AM
#10
(07-17-2018, 07:58 AM)reGEN Wrote:(07-17-2018, 07:52 AM)Mimiakira Wrote: Couldn't you try doing it in a single file or, was the size to big?
The setup file is about 400 MB which is too big to upload to VT. The patching program (as described by the "Patcher" label) was also included which packed three other files (the DLLs). The DLLs were deobfuscated and each individually dropped into the temp path directory. So even if I uploaded the patcher by itself, AV may not have been able to detect the DLLs if they happened to be malicious.
Mothered said something a fair while ago but, it was regarding about uploading large files like that to the net and etc. (Since it was long time ago, I may of forgotten)
Users browsing this thread:
![[+]](https://sinister.ly/images/modern/collapse_collapsed.png)















