Sinisterly
VEGAS.Pro.15.0.0.384 - Printable Version

+- Sinisterly (https://sinister.ly)
+-- Forum: Computers (https://sinister.ly/Forum-Computers)
+--- Forum: Software & Programs (https://sinister.ly/Forum-Software-Programs)
+--- Thread: VEGAS.Pro.15.0.0.384 (/Thread-VEGAS-Pro-15-0-0-384)

Pages: 1 2


VEGAS.Pro.15.0.0.384 - yassin2chabah - 07-17-2018

Download link

http://shortadz.net/2WhP


RE: VEGAS.Pro.15.0.0.384 - Vultra - 07-17-2018

Please provide a virus scan of the tool.


RE: VEGAS.Pro.15.0.0.384 - reGEN - 07-17-2018

Patcher:
VT (41/66): https://www.virustotal.com/#/file/88178aaf93d24faf7efbd1cbcda102ff69b48181870588ab2e5f3223a5840a3b/detection

dup2patcher.dll:
VT (34/67): https://www.virustotal.com/#/file/690bd758b01b4f21723c915ef0846a3efee61161b8b8a2cf5137fecf099e887d/detection

bassmod.dll:
VT (4/66): https://www.virustotal.com/#/file/844eb66a10b848d3a71a8c63c35f0a01550a46d2ff8503e2ca8947978b03b4d2/community

7CEB9B2A0E395BD64E74381485A106AF.dll
VT (0/65): https://www.virustotal.com/#/file/125fc74e03435b3e0ede0ff523d625d9c1fbb299286e9e2dbd1442e506150da6/detection

Detections are labeled as "hack tools" which is fine. The application simply drops and loads a dup2patcher.dll which is what I assume to be the thing that applies the patches. I know dup2 is a well-known patching/loader tool that goes way back. I've never actually seen a dup2 tool used in the wild but then again I don't download cracked software. I did not see any network connections, attempts at start up persistence or additional processes executed. The program seemed to be patched successfully and executed properly.

Results are inconclusive but I think it should be safe. Of course caution must be taken when downloading and using any cracked software.


RE: VEGAS.Pro.15.0.0.384 - mothered - 07-17-2018

(07-17-2018, 05:04 AM)reGEN Wrote: Patcher:
VT (41/66): https://www.virustotal.com/#/file/88178aaf93d24faf7efbd1cbcda102ff69b48181870588ab2e5f3223a5840a3b/detection

dup2patcher.dll:
VT (34/67): https://www.virustotal.com/#/file/690bd758b01b4f21723c915ef0846a3efee61161b8b8a2cf5137fecf099e887d/detection

bassmod.dll:
VT (4/66): https://www.virustotal.com/#/file/844eb66a10b848d3a71a8c63c35f0a01550a46d2ff8503e2ca8947978b03b4d2/community

7CEB9B2A0E395BD64E74381485A106AF.dll
VT (0/65): https://www.virustotal.com/#/file/125fc74e03435b3e0ede0ff523d625d9c1fbb299286e9e2dbd1442e506150da6/detection

Detections are labeled as "hack tools" which is fine. The application simply drops and loads a dup2patcher.dll which is what I assume to be the thing that applies the patches. I know dup2 is a well-known patching/loader tool that goes way back.  I've never actually seen a dup2 tool used in the wild but then again I don't download cracked software. I did not see any network connections, attempts at start up persistence or additional processes executed. The program seemed to be patched successfully and executed properly.

Results are inconclusive but I think it should be safe. Of course caution must be taken when downloading and using any cracked software.

Appreciate your In depth report and analysis.

It saves me from testing It and providing the online virus scan report. False positive detections can be expected, however precautionary measures must always be the first port of call and your comment sums It up.
Quote:Of course caution must be taken when downloading and using any cracked software.

Preferably use a dedicated physical machine segregated from the network, with a Guest OS (VM) running with Sandboxie Installed. All files should be executed In the latter.


RE: VEGAS.Pro.15.0.0.384 - reGEN - 07-17-2018

I try to help when it comes to software download because I love hunting for malware! Especially the rush when I find something super dodgy. Wink


RE: VEGAS.Pro.15.0.0.384 - Percent - 07-17-2018

Interesting. Thank you for sharing this. Smile


RE: VEGAS.Pro.15.0.0.384 - mothered - 07-17-2018

(07-17-2018, 06:21 AM)reGEN Wrote: I try to help when it comes to software download because I love hunting for malware!

Judging by your posts and the context of which they're written, I've certainly come to realize your analytical approach with malicious software.


RE: VEGAS.Pro.15.0.0.384 - Vultra - 07-17-2018

(07-17-2018, 05:04 AM)reGEN Wrote: Patcher:
VT (41/66): https://www.virustotal.com/#/file/88178aaf93d24faf7efbd1cbcda102ff69b48181870588ab2e5f3223a5840a3b/detection

dup2patcher.dll:
VT (34/67): https://www.virustotal.com/#/file/690bd758b01b4f21723c915ef0846a3efee61161b8b8a2cf5137fecf099e887d/detection

bassmod.dll:
VT (4/66): https://www.virustotal.com/#/file/844eb66a10b848d3a71a8c63c35f0a01550a46d2ff8503e2ca8947978b03b4d2/community

7CEB9B2A0E395BD64E74381485A106AF.dll
VT (0/65): https://www.virustotal.com/#/file/125fc74e03435b3e0ede0ff523d625d9c1fbb299286e9e2dbd1442e506150da6/detection

Detections are labeled as "hack tools" which is fine. The application simply drops and loads a dup2patcher.dll which is what I assume to be the thing that applies the patches. I know dup2 is a well-known patching/loader tool that goes way back. I've never actually seen a dup2 tool used in the wild but then again I don't download cracked software. I did not see any network connections, attempts at start up persistence or additional processes executed. The program seemed to be patched successfully and executed properly.

Results are inconclusive but I think it should be safe. Of course caution must be taken when downloading and using any cracked software.

Couldn't you try doing it in a single file or, was the size to big?


RE: VEGAS.Pro.15.0.0.384 - reGEN - 07-17-2018

(07-17-2018, 07:52 AM)Mimiakira Wrote: Couldn't you try doing it in a single file or, was the size to big?

The setup file is about 400 MB which is too big to upload to VT. The patching program (as described by the "Patcher" label) was also included which packed three other files (the DLLs). The DLLs were deobfuscated and each individually dropped into the temp path directory. So even if I uploaded the patcher by itself, AV may not have been able to detect the DLLs if they happened to be malicious.


RE: VEGAS.Pro.15.0.0.384 - Vultra - 07-17-2018

(07-17-2018, 07:58 AM)reGEN Wrote:
(07-17-2018, 07:52 AM)Mimiakira Wrote: Couldn't you try doing it in a single file or, was the size to big?

The setup file is about 400 MB which is too big to upload to VT. The patching program (as described by the "Patcher" label) was also included which  packed three other files (the DLLs). The DLLs were deobfuscated and each individually dropped into the temp path directory. So even if I uploaded the patcher by itself, AV may not have been able to detect the DLLs if they happened to be malicious.

Mothered said something a fair while ago but, it was regarding about uploading large files like that to the net and etc. (Since it was long time ago, I may of forgotten)