NordVPN PREMIUM GENERATOR V1.4 - nassimalina - 04-30-2020
NordVPN PREMIUM GENERATOR V1.4
╔═.✵.══════════╗
go to the link for download
↓↓↓
file-up.org/sfavoyudof7v
↓↓↓
virus scan report:
https://www.virustotal.com/gui/file/d921e1eec4172e2b683a2d4a36cc5cef7f6fb2f6396e2729c834745666eb3539/detection
enjoy!!
RE: NordVPN PREMIUM GENERATOR V1.4 - mothered - 04-30-2020
As with your other contributions, an online virus scan report must be provided.
RE: NordVPN PREMIUM GENERATOR V1.4 - miso - 04-30-2020
(04-30-2020, 04:52 AM)mothered Wrote: As with your other contributions, an online virus scan report must be provided. Quite suspicious scan lol
Virustotal Scan [24/72] (NordVPN PREMIUM GENERATOR V1.4.exe)
RE: NordVPN PREMIUM GENERATOR V1.4 - mothered - 04-30-2020
(04-30-2020, 04:56 AM)miso Wrote: Quite suspicious scan lol
Virustotal Scan [24/72] (NordVPN PREMIUM GENERATOR V1.4.exe) The detections are high, but unfortunately an online virus scan Is not a conclusive form of analysis, but rather an Indication of the file's contents.
(04-30-2020, 04:00 AM)nassimalina Wrote: virus scan report:
https://www.virustotal.com/gui/file/d921e1eec4172e2b683a2d4a36cc5cef7f6fb2f6396e2729c834745666eb3539/detection Do remember to scan the "executable file".
RE: NordVPN PREMIUM GENERATOR V1.4 - miso - 05-01-2020
@mothered , fake application (see below)
This application doesn't generate any accounts, it has a set list of accounts, it just pretends to create premium accounts
(i might make a source code remake in the future since the application is has just a few lines of codes)
i've made a new thread with all the accounts contained in the app here: x37 NordVPN Accounts (Unchecked, Extracted from NordVPN PREMIUM GENERATOR.exe) | Sinister.ly Thread
the application doesn't impact the user's computer in anyway
App Screenshot:
![[Image: Go-7MnFwQ2KnPwq8CV8ygA.png]](https://image.prntscr.com/image/Go-7MnFwQ2KnPwq8CV8ygA.png)
Tools Used:
- MiTeC EXE Explorer
- HxD
- Notepad
- chara.URLDumper
- chara.DeObTester
- Sandboxie
Code: [AppDetails]
App Info:
StringFileInfo [Hex] = 000004b0
FileDescription = "WindowsApp1"
Copyright = "Copyright 2018"
OriginalFileName = "NordVPN Generator.exe"
ProductName = "WindowsApp1"
FileVersion = 1.0.0.0
ProductVersion = 1.0.0.0
AssemblyVersion = 1.0.0.0
Framework = .NET Framework 4.6.1
[/AppDetails]
[chara.URLDumper]:
Found 3 Links:
https://www.facebook.com/groups/185383492115208/
http://www.youtube.com/c/AlphaCrackTMPermium
https://discordapp.com/invite/C6Wvtg7
[/chara.URLDumper]
[HOST::EXEPEINFO]:
string(AppCompiler) = "Borland Delphi ( 2.0 - 7.0 ) 1992 - www.borland.com ,
Overlay : DAFFF2... Nothing discovered"
string(LamerUnpackInfo) = "Warning : Big Unkn.Ovelay Data - over : 541,5 KB - check it or try Ripper , Not packed , try OllyDbg v2 - www.ollydbg.de or IDA v7 www.hex-rays.com or x64 debug v0024 www.x64dbg.com"
[/HOST::EXEPEINFO]:
[chara.DeObTester]:
HasObfuscator = True
ObfuscatorName = Confuser v1.9.0.0
Deobfuscators Used (2) =
[Crashed]: https://github.com/maddnias/ConfuserDeobfuscator | HOST::CONFUSERDEOBFUSCATOR(__BADIMAGEFORMAT)
[Failed]: https://github.com/0xd4d/de4dot | HOST::DE4DOT(__INVALIDTYPE) : The file isn't a .NET PE file
[/chara.DeObTester]
[AppStructure]
Form1 Info:
Elements: Button1, Button2, Timer1, PictureBox1, ProgressBar1
WindowTitle = "NordVPN PREMIUM KEY GENERATOR V1.4"
Events: Timer1_Tick, TextBox1_TextChanged, Button2_Click, Button1_Click
ClientSize = 312x534
Button2:
OnClick = Process.Start("http://www.youtube.com/c/AlphaCrackTMPermium") & Process.Start("https://www.facebook.com/groups/185383492115208/") & Process.Start("https://discordapp.com/invite/C6Wvtg7")
Font: Tahoma, Bold
FlatStyle = Flat
ForeColor = Color.Black
BackColor = Color.DodgerBlue
Text: "By Alphacrack"
Button1:
OnClick = Timer1.Start()
Font: Tahoma, Bold
FlatStyle = Flat
ForeColor = Color.Black
BackColor = Color.DodgerBlue | Hover = Color.FromArgb(26, 129, 229)
TextBox1:
ForeColor = Color.Black
BackColor = Color.DodgerBlue | Hover = Color.FromArgb(26, 129, 229)
Timer1:
Value = Unknown
[guessed_code]
{
ProgressBar1.Value += 1
If ProgressBar1.Value = maxValue Then
ProgressBar1.Value = 0
Timer1.Stop()
MessageBox.Show("Account PREMIUM ENJOY !!", "NordVPN Generator")
End If
}
[/guessed_code]
[/AppStructure]
RE: NordVPN PREMIUM GENERATOR V1.4 - mothered - 05-01-2020
(05-01-2020, 03:46 AM)miso Wrote: @mothered , fake application (see below)
This application doesn't generate any accounts, it has a set list of accounts, it just pretends to create premium accounts
(i might make a source code remake in the future since the application is has just a few lines of codes)
i've made a new thread with all the accounts contained in the app here: x37 NordVPN Accounts (Unchecked, Extracted from NordVPN PREMIUM GENERATOR.exe) | Sinister.ly Thread
the application doesn't impact the user's computer in anyway
App Screenshot:
![[Image: Go-7MnFwQ2KnPwq8CV8ygA.png]](https://image.prntscr.com/image/Go-7MnFwQ2KnPwq8CV8ygA.png)
Tools Used:
- MiTeC EXE Explorer
- HxD
- Notepad
- chara.URLDumper
- chara.DeObTester
- Sandboxie
Code: [AppDetails]
App Info:
StringFileInfo [Hex] = 000004b0
FileDescription = "WindowsApp1"
Copyright = "Copyright 2018"
OriginalFileName = "NordVPN Generator.exe"
ProductName = "WindowsApp1"
FileVersion = 1.0.0.0
ProductVersion = 1.0.0.0
AssemblyVersion = 1.0.0.0
Framework = .NET Framework 4.6.1
[/AppDetails]
[chara.URLDumper]:
Found 3 Links:
https://www.facebook.com/groups/185383492115208/
http://www.youtube.com/c/AlphaCrackTMPermium
https://discordapp.com/invite/C6Wvtg7
[/chara.URLDumper]
[HOST::EXEPEINFO]:
string(AppCompiler) = "Borland Delphi ( 2.0 - 7.0 ) 1992 - www.borland.com ,
Overlay : DAFFF2... Nothing discovered"
string(LamerUnpackInfo) = "Warning : Big Unkn.Ovelay Data - over : 541,5 KB - check it or try Ripper , Not packed , try OllyDbg v2 - www.ollydbg.de or IDA v7 www.hex-rays.com or x64 debug v0024 www.x64dbg.com"
[/HOST::EXEPEINFO]:
[chara.DeObTester]:
HasObfuscator = True
ObfuscatorName = Confuser v1.9.0.0
Deobfuscators Used (2) =
[Crashed]: https://github.com/maddnias/ConfuserDeobfuscator | HOST::CONFUSERDEOBFUSCATOR(__BADIMAGEFORMAT)
[Failed]: https://github.com/0xd4d/de4dot | HOST::DE4DOT(__INVALIDTYPE) : The file isn't a .NET PE file
[/chara.DeObTester]
[AppStructure]
Form1 Info:
Elements: Button1, Button2, Timer1, PictureBox1, ProgressBar1
WindowTitle = "NordVPN PREMIUM KEY GENERATOR V1.4"
Events: Timer1_Tick, TextBox1_TextChanged, Button2_Click, Button1_Click
ClientSize = 312x534
Button2:
OnClick = Process.Start("http://www.youtube.com/c/AlphaCrackTMPermium") & Process.Start("https://www.facebook.com/groups/185383492115208/") & Process.Start("https://discordapp.com/invite/C6Wvtg7")
Font: Tahoma, Bold
FlatStyle = Flat
ForeColor = Color.Black
BackColor = Color.DodgerBlue
Text: "By Alphacrack"
Button1:
OnClick = Timer1.Start()
Font: Tahoma, Bold
FlatStyle = Flat
ForeColor = Color.Black
BackColor = Color.DodgerBlue | Hover = Color.FromArgb(26, 129, 229)
TextBox1:
ForeColor = Color.Black
BackColor = Color.DodgerBlue | Hover = Color.FromArgb(26, 129, 229)
Timer1:
Value = Unknown
[guessed_code]
{
ProgressBar1.Value += 1
If ProgressBar1.Value = maxValue Then
ProgressBar1.Value = 0
Timer1.Stop()
MessageBox.Show("Account PREMIUM ENJOY !!", "NordVPN Generator")
End If
}
[/guessed_code]
[/AppStructure]
Excellent analysis.
So all In all, It's simply a fake tool with no malicious Intent, correct?
RE: NordVPN PREMIUM GENERATOR V1.4 - miso - 05-01-2020
(05-01-2020, 04:57 AM)mothered Wrote: (05-01-2020, 03:46 AM)miso Wrote: @mothered , fake application (see below)
This application doesn't generate any accounts, it has a set list of accounts, it just pretends to create premium accounts
(i might make a source code remake in the future since the application is has just a few lines of codes)
i've made a new thread with all the accounts contained in the app here: x37 NordVPN Accounts (Unchecked, Extracted from NordVPN PREMIUM GENERATOR.exe) | Sinister.ly Thread
the application doesn't impact the user's computer in anyway
App Screenshot:
![[Image: Go-7MnFwQ2KnPwq8CV8ygA.png]](https://image.prntscr.com/image/Go-7MnFwQ2KnPwq8CV8ygA.png)
Tools Used:
- MiTeC EXE Explorer
- HxD
- Notepad
- chara.URLDumper
- chara.DeObTester
- Sandboxie
Code: [AppDetails]
App Info:
StringFileInfo [Hex] = 000004b0
FileDescription = "WindowsApp1"
Copyright = "Copyright 2018"
OriginalFileName = "NordVPN Generator.exe"
ProductName = "WindowsApp1"
FileVersion = 1.0.0.0
ProductVersion = 1.0.0.0
AssemblyVersion = 1.0.0.0
Framework = .NET Framework 4.6.1
[/AppDetails]
[chara.URLDumper]:
Found 3 Links:
https://www.facebook.com/groups/185383492115208/
http://www.youtube.com/c/AlphaCrackTMPermium
https://discordapp.com/invite/C6Wvtg7
[/chara.URLDumper]
[HOST::EXEPEINFO]:
string(AppCompiler) = "Borland Delphi ( 2.0 - 7.0 ) 1992 - www.borland.com ,
Overlay : DAFFF2... Nothing discovered"
string(LamerUnpackInfo) = "Warning : Big Unkn.Ovelay Data - over : 541,5 KB - check it or try Ripper , Not packed , try OllyDbg v2 - www.ollydbg.de or IDA v7 www.hex-rays.com or x64 debug v0024 www.x64dbg.com"
[/HOST::EXEPEINFO]:
[chara.DeObTester]:
HasObfuscator = True
ObfuscatorName = Confuser v1.9.0.0
Deobfuscators Used (2) =
[Crashed]: https://github.com/maddnias/ConfuserDeobfuscator | HOST::CONFUSERDEOBFUSCATOR(__BADIMAGEFORMAT)
[Failed]: https://github.com/0xd4d/de4dot | HOST::DE4DOT(__INVALIDTYPE) : The file isn't a .NET PE file
[/chara.DeObTester]
[AppStructure]
Form1 Info:
Elements: Button1, Button2, Timer1, PictureBox1, ProgressBar1
WindowTitle = "NordVPN PREMIUM KEY GENERATOR V1.4"
Events: Timer1_Tick, TextBox1_TextChanged, Button2_Click, Button1_Click
ClientSize = 312x534
Button2:
OnClick = Process.Start("http://www.youtube.com/c/AlphaCrackTMPermium") & Process.Start("https://www.facebook.com/groups/185383492115208/") & Process.Start("https://discordapp.com/invite/C6Wvtg7")
Font: Tahoma, Bold
FlatStyle = Flat
ForeColor = Color.Black
BackColor = Color.DodgerBlue
Text: "By Alphacrack"
Button1:
OnClick = Timer1.Start()
Font: Tahoma, Bold
FlatStyle = Flat
ForeColor = Color.Black
BackColor = Color.DodgerBlue | Hover = Color.FromArgb(26, 129, 229)
TextBox1:
ForeColor = Color.Black
BackColor = Color.DodgerBlue | Hover = Color.FromArgb(26, 129, 229)
Timer1:
Value = Unknown
[guessed_code]
{
ProgressBar1.Value += 1
If ProgressBar1.Value = maxValue Then
ProgressBar1.Value = 0
Timer1.Stop()
MessageBox.Show("Account PREMIUM ENJOY !!", "NordVPN Generator")
End If
}
[/guessed_code]
[/AppStructure]
Excellent analysis.
So all In all, It's simply a fake tool with no malicious Intent, correct? indeed ^D^
RE: NordVPN PREMIUM GENERATOR V1.4 - mothered - 05-01-2020
(05-01-2020, 05:36 AM)miso Wrote: (05-01-2020, 04:57 AM)mothered Wrote: (05-01-2020, 03:46 AM)miso Wrote: @mothered , fake application (see below)
This application doesn't generate any accounts, it has a set list of accounts, it just pretends to create premium accounts
(i might make a source code remake in the future since the application is has just a few lines of codes)
i've made a new thread with all the accounts contained in the app here: x37 NordVPN Accounts (Unchecked, Extracted from NordVPN PREMIUM GENERATOR.exe) | Sinister.ly Thread
the application doesn't impact the user's computer in anyway
App Screenshot:
![[Image: Go-7MnFwQ2KnPwq8CV8ygA.png]](https://image.prntscr.com/image/Go-7MnFwQ2KnPwq8CV8ygA.png)
Tools Used:
- MiTeC EXE Explorer
- HxD
- Notepad
- chara.URLDumper
- chara.DeObTester
- Sandboxie
Code: [AppDetails]
App Info:
StringFileInfo [Hex] = 000004b0
FileDescription = "WindowsApp1"
Copyright = "Copyright 2018"
OriginalFileName = "NordVPN Generator.exe"
ProductName = "WindowsApp1"
FileVersion = 1.0.0.0
ProductVersion = 1.0.0.0
AssemblyVersion = 1.0.0.0
Framework = .NET Framework 4.6.1
[/AppDetails]
[chara.URLDumper]:
Found 3 Links:
https://www.facebook.com/groups/185383492115208/
http://www.youtube.com/c/AlphaCrackTMPermium
https://discordapp.com/invite/C6Wvtg7
[/chara.URLDumper]
[HOST::EXEPEINFO]:
string(AppCompiler) = "Borland Delphi ( 2.0 - 7.0 ) 1992 - www.borland.com ,
Overlay : DAFFF2... Nothing discovered"
string(LamerUnpackInfo) = "Warning : Big Unkn.Ovelay Data - over : 541,5 KB - check it or try Ripper , Not packed , try OllyDbg v2 - www.ollydbg.de or IDA v7 www.hex-rays.com or x64 debug v0024 www.x64dbg.com"
[/HOST::EXEPEINFO]:
[chara.DeObTester]:
HasObfuscator = True
ObfuscatorName = Confuser v1.9.0.0
Deobfuscators Used (2) =
[Crashed]: https://github.com/maddnias/ConfuserDeobfuscator | HOST::CONFUSERDEOBFUSCATOR(__BADIMAGEFORMAT)
[Failed]: https://github.com/0xd4d/de4dot | HOST::DE4DOT(__INVALIDTYPE) : The file isn't a .NET PE file
[/chara.DeObTester]
[AppStructure]
Form1 Info:
Elements: Button1, Button2, Timer1, PictureBox1, ProgressBar1
WindowTitle = "NordVPN PREMIUM KEY GENERATOR V1.4"
Events: Timer1_Tick, TextBox1_TextChanged, Button2_Click, Button1_Click
ClientSize = 312x534
Button2:
OnClick = Process.Start("http://www.youtube.com/c/AlphaCrackTMPermium") & Process.Start("https://www.facebook.com/groups/185383492115208/") & Process.Start("https://discordapp.com/invite/C6Wvtg7")
Font: Tahoma, Bold
FlatStyle = Flat
ForeColor = Color.Black
BackColor = Color.DodgerBlue
Text: "By Alphacrack"
Button1:
OnClick = Timer1.Start()
Font: Tahoma, Bold
FlatStyle = Flat
ForeColor = Color.Black
BackColor = Color.DodgerBlue | Hover = Color.FromArgb(26, 129, 229)
TextBox1:
ForeColor = Color.Black
BackColor = Color.DodgerBlue | Hover = Color.FromArgb(26, 129, 229)
Timer1:
Value = Unknown
[guessed_code]
{
ProgressBar1.Value += 1
If ProgressBar1.Value = maxValue Then
ProgressBar1.Value = 0
Timer1.Stop()
MessageBox.Show("Account PREMIUM ENJOY !!", "NordVPN Generator")
End If
}
[/guessed_code]
[/AppStructure]
Excellent analysis.
So all In all, It's simply a fake tool with no malicious Intent, correct? indeed ^D^
Good to read.
Thank you for your assistance.
RE: NordVPN PREMIUM GENERATOR V1.4 - miso - 05-01-2020
App Code Remade into a Visual Studio 2010, VB.NET Project, see here: [VS2010 VB.NET Project]: Fake NordVPN Account Generator (Remake) | Sinister.ly Thread
RE: NordVPN PREMIUM GENERATOR V1.4 - nanelove - 12-02-2021
thank you good work another generator
|