Login Register






Thread Rating:
  • 0 Vote(s) - 0 Average


[Virus] setup_hacxx_anonymous_file_search_v4_2210634171.rar filter_list
Author
Message
[Virus] setup_hacxx_anonymous_file_search_v4_2210634171.rar #1
Can anyone reverse this program and find out if there is any hidden gem?
Last time i scanned a file from this source i got a command line firewall bypass...

Download:
https://userscloud.com/0y7vm9ay3cua

Virus Scan: (22/71)
https://www.virustotal.com/gui/file/b0c0.../detection

Reply

RE: [Virus] setup_hacxx_anonymous_file_search_v4_2210634171.rar #2
I'll quote @"miso".

He's RE'd a lot of programs, so hopefully he'll do the same with this.
[Image: AD83g1A.png]

Reply

RE: [Virus] setup_hacxx_anonymous_file_search_v4_2210634171.rar #3
(04-14-2020, 03:48 AM)mothered Wrote: I'll quote @"miso".

He's RE'd a lot of programs, so hopefully he'll do the same with this.

thanks for mentioning me

When installing, it will open a fake youtube-like webpage
extracting the installer shows a bunch of file that just have a bunch of repeated word, the only exception is with the only .exe file, which cannot be launched (file cannot be loaded in windows and ExePeInfo says it is corrupted)

I think the detections are just from the installer loading a scammy url, however, i've loaded the installer into a sandbox, when installed on a vm for example, the files my have different data except that i really doubt it)

[Image: MLEA1z9DQxS6ABy-iIlwYQ.png]
[Image: 6McjykVxQiSoH4GVGkC5nQ.png]

btw it never loads, clicking anywhere on that page makes it fullscreen, waiting a bit will redirect you into other scammy sites

tools used:
HxD, InnoExtractor, ExePeInfo, Sandboxie
(This post was last modified: 04-14-2020, 07:57 PM by miso.)

Reply

RE: [Virus] setup_hacxx_anonymous_file_search_v4_2210634171.rar #4
Ok thanks. Last time i research a file from this service i got something similar to the code below
Code:
netsh.exe advfirewall firewall add rule name="rundll32" dir=out action=allow protocol=any program="c:\windows\rundll32.exe"

Also are you sure you tried correctly?
In my advertiser panel i have my install which was around 2AM and nothing else.
May have virtual machine protection.

Reply

RE: [Virus] setup_hacxx_anonymous_file_search_v4_2210634171.rar #5
(04-14-2020, 07:48 PM)miso Wrote: thanks for mentioning me

You're welcome, and thanks for your prompt response.
[Image: AD83g1A.png]

[+] 1 user Likes mothered's post
Reply

RE: [Virus] setup_hacxx_anonymous_file_search_v4_2210634171.rar #6
(04-14-2020, 08:40 PM)hacxx Wrote: Ok thanks. Last time i research a file from this service i got something similar to the code below
Code:
netsh.exe advfirewall firewall add rule name="rundll32" dir=out action=allow protocol=any program="c:\windows\rundll32.exe"

Also are you sure you tried correctly?
In my advertiser panel i have my install which was around 2AM and nothing else.
May have virtual machine protection.

i can't run vms due to my hardware not being able to run them (it cant run shit lol)

here's the files that i've extracted from the installer:
Download (mega.nz)
VirusTotal [1/61]

Reply

RE: [Virus] setup_hacxx_anonymous_file_search_v4_2210634171.rar #7
For some reason when i executed the file on my computer it download and executed this two installers.
- SevenZip.exe - A clone of 7Zip
- Avast.exe - Avast installer

Here is the download link:
https://mfilecloud.com/ZnZveHNqenNxX2JOU1A3

Reply

RE: [Virus] setup_hacxx_anonymous_file_search_v4_2210634171.rar #8
(04-14-2020, 11:52 PM)miso Wrote: i can't run vms due to my hardware not being able to run them (it cant run shit lol)

VMs are predominantly CPU & Ram dependent.

What's your specs pertaining to the above? We'll move back on-topic after your reply.
[Image: AD83g1A.png]

Reply

RE: [Virus] setup_hacxx_anonymous_file_search_v4_2210634171.rar #9
x64, 4GB RAM, Dual-core CPU
[Image: config.png]
(This post was last modified: 04-15-2020, 08:56 PM by miso.)

Reply







Users browsing this thread: 1 Guest(s)