Sinisterly
NEW uplay checker ( last version ) - Printable Version

+- Sinisterly (https://sinister.ly)
+-- Forum: Hacking (https://sinister.ly/Forum-Hacking)
+--- Forum: Hacking Tools (https://sinister.ly/Forum-Hacking-Tools)
+--- Thread: NEW uplay checker ( last version ) (/Thread-NEW-uplay-checker-last-version)



NEW uplay checker ( last version ) - Ra-Zi - 02-16-2018

Hi !!

DOWNLOAD LINK : https://www.file-upload.com/znn4rs5emha4

SCAN REPORT : https://www.virustotal.com/#/file/a0cc0870e3f7476b69f9c1574911cc1fd5b0deb311f5b678ab51fbd7d4f20ed1/detection

Enjooy !!!


RE: NEW uplay checker ( last version ) - phyrrus9 - 02-16-2018

(02-16-2018, 06:47 PM)MrLokas1 Wrote: Hi !!

DOWNLOAD LINK : https://www.file-upload.com/znn4rs5emha4

SCAN REPORT : https://www.virustotal.com/#/file/a0cc0870e3f7476b69f9c1574911cc1fd5b0deb311f5b678ab51fbd7d4f20ed1/detection

Enjooy !!!

Whoa buddy, this thing got flagged not by one, not by two, but by TWENTY TWO of the virus scanners. This thing is at least 37% very slopily coded malware.


RE: NEW uplay checker ( last version ) - mothered - 02-17-2018

By no means Is Sanboxie a conclusive Indicator of the file's contents, but It certainly provides a better understanding In a runtime environment.
Here's the tool executed In Sandboxie.

Spoiler:
[Image: uDGZbim.png]

Spoiler:
[Image: nDIR3pR.png]


The nature of detections listed In the online virus scan report, seem consistent with malicious behavior but having said that, a lot of AVs flag false positives with similar descriptions. Pending further analysis, there Isn't anything "definitive" with malware and the like.


RE: NEW uplay checker ( last version ) - phyrrus9 - 02-17-2018

(02-17-2018, 04:23 AM)mothered Wrote: By no means Is Sanboxie a conclusive Indicator of the file's contents, but It certainly provides a better understanding In a runtime environment.
Here's the tool executed In Sandboxie.

Spoiler:
[Image: uDGZbim.png]

Spoiler:
[Image: nDIR3pR.png]


The nature of detections listed In the online virus scan report, seem consistent with malicious behavior but having said that, a lot of AVs flag false positives with similar descriptions. Pending further analysis, there Isn't anything "definitive" with malware and the like.

Despite my (albeit small) bias that this probably is malware, I'll pull down the source code and have a look. If I find anything malicious, I'll post my analasys.

EDIT: my bad, I mistook this post for another I had read today, and in fact the source code is NOT provided. I'll run it in a VM a few times, then delete the binaries and run antivirus and see if anything has been touched.


RE: NEW uplay checker ( last version ) - mothered - 02-17-2018

(02-17-2018, 04:29 AM)phyrrus9 Wrote: I'll run it in a VM a few times, then delete the binaries and run antivirus and see if anything has been touched.

I haven't the time for further analysis so If you can do that, It'll be great.

Anytime at your convenience.


RE: NEW uplay checker ( last version ) - phyrrus9 - 02-17-2018

I got one detection distinct from the original virus scan
[Image: wEISJQV.png]

Potentially useful information:
Code:
[WARN] GetSHA256: SHA - Cannot open the file: \\?\C:\Users\test\Desktop\UBrute_ShaOnKrisTof.exe [WARN] Can't get creation date of file: \\?\C:\Users\test\Desktop\UBrute_ShaOnKrisTof.exe. Error: Can't get file attributes: permission denied C:\Users\test\Desktop\UBrute_ShaOnKrisTof.exe (SHA-256: 6d8da79d05efc8a0bbc2bf2483025deeeb90c98a85e52bd03601a5b2a9a1c233) [DETECTION] Contains suspicious code HEUR/APC (Cloud) [WARNING] An error has occurred and the file was not deleted. ErrorID: 26004 [WARNING] The source file could not be found. [NOTE] The file is scheduled for deleting after reboot. [NOTE] It is recommended to restart your computer in order to finish the repair.



RE: NEW uplay checker ( last version ) - mothered - 02-17-2018

That'd be right coming from Avira. During execution, they tend to detect what others miss and along with ESET, they're one of the most difficult AVs to circumvent (runtime) when FUDing a file.

Quote:I got one detection distinct from the original virus scan

Good work. It may well be that Avira's Heuristics engine triggered the detection. It's very difficult to determine whether HEUR/APC Is consistent with anything malicious. Until deemed otherwise, I suggest all members run this In a controlled environment.


RE: NEW uplay checker ( last version ) - phyrrus9 - 02-17-2018

(02-17-2018, 05:51 AM)mothered Wrote: That'd be right coming from Avira. During execution, they tend to detect what others miss and along with ESET, they're one of the most difficult AVs to circumvent (runtime) when FUDing a file.

Quote:I got one detection distinct from the original virus scan

Good work. It may well be that Avira's Heuristics engine triggered the detection. It's very difficult to determine whether HEUR/APC Is consistent with anything malicious.

I couldn't find a whole lot of info on what that meant, my verdict: probably fine, but you should run in a sandbox or VM


RE: NEW uplay checker ( last version ) - Blink - 02-17-2018

(02-17-2018, 05:52 AM)phyrrus9 Wrote:
(02-17-2018, 05:51 AM)mothered Wrote: That'd be right coming from Avira. During execution, they tend to detect what others miss and along with ESET, they're one of the most difficult AVs to circumvent (runtime) when FUDing a file.

Quote:I got one detection distinct from the original virus scan

Good work. It may well be that Avira's Heuristics engine triggered the detection. It's very difficult to determine whether HEUR/APC Is consistent with anything malicious.

I couldn't find a whole lot of info on what that meant, my verdict: probably fine, but you should run in a sandbox or VM

You should note that many of his other posts give similar AV results. When you have stuff like this occur multiple times, it seems even more suspicious.
My verdict: If you must run it, never do so outside of a VM


RE: NEW uplay checker ( last version ) - phyrrus9 - 02-17-2018

(02-17-2018, 08:36 AM)Ender Wrote:
(02-17-2018, 05:52 AM)phyrrus9 Wrote:
(02-17-2018, 05:51 AM)mothered Wrote: That'd be right coming from Avira. During execution, they tend to detect what others miss and along with ESET, they're one of the most difficult AVs to circumvent (runtime) when FUDing a file.


Good work. It may well be that Avira's Heuristics engine triggered the detection. It's very difficult to determine whether HEUR/APC Is consistent with anything malicious.

I couldn't find a whole lot of info on what that meant, my verdict: probably fine, but you should run in a sandbox or VM

You should note that many of his other posts give similar AV results. When you have stuff like this occur multiple times, it seems even more suspicious.
My verdict: If you must run it, never do so outside of a VM

tbh that should be the case with all programs downloaded from SL. my policy for my PC is to run NOTHING unless i compiled it myself or its from someone I trust