• 🌙 Community Spirit

    Ramadan Mubarak! To honor this month, Crax has paused NSFW categories. Wishing you peace and growth!

ENCCN Ransomware Builder Cracked (1 Viewer)

Currently reading:
 ENCCN Ransomware Builder Cracked (1 Viewer)

Recently searched:

Freshhy

Member
LV
2
Joined
Jul 17, 2023
Threads
51
Likes
41
Awards
6
Credits
4,111©
Cash
0$
1716055294686


Link:

If your antivirus claims that it's a virus, it's because it is. (duh)
Disable your antivirus(es) before running to ensure that no files get deleted!


DO NOT SCAN ANY FILES IN ORDER TO PRESERVE DETECTIONS!!
 
Last edited:

zhonow

Member
LV
1
Joined
Apr 19, 2024
Threads
10
Likes
21
Awards
5
Credits
3,806©
Cash
0$
file app
checking.
file appears infected, despite it being flagged as dapato:downloader trojan (natural for a builder program), a few lots of sources also gave this a *Gen:Variant.Crypt.101241 (R)*, unsure the safety.
 

Freshhy

Member
LV
2
Joined
Jul 17, 2023
Threads
51
Likes
41
Awards
6
Credits
4,111©
Cash
0$
file app

file appears infected, despite it being flagged as dapato:downloader trojan (natural for a builder program), a few lots of sources also gave this a *Gen:Variant.Crypt.101241 (R)*, unsure the safety.
Nothing besides the way authentication is performed (and a couple strings to give myself credit) was touched. Basically we jump to logging in no matter what the input key is. Everything else was left untouched.
 
  • Like
Reactions: zhonow

zhonow

Member
LV
1
Joined
Apr 19, 2024
Threads
10
Likes
21
Awards
5
Credits
3,806©
Cash
0$
Nothing besides the way authentication is performed (and a couple strings to give myself credit) was touched. Basically we jump to logging in no matter what the input key is. Everything else was left untouched.
then i'll look on forward to research whats behind this, thanks for your honesty though
 

zhonow

Member
LV
1
Joined
Apr 19, 2024
Threads
10
Likes
21
Awards
5
Credits
3,806©
Cash
0$
Nothing besides the way authentication is performed (and a couple strings to give myself credit) was touched. Basically we jump to logging in no matter what the input key is. Everything else was left untouched.
yeah seems like my previous reply was right, uses powershell strings from temp to disable windefender and add a reg value to svchost showing persistence of a malware. I dont even wanna talk of the virustotal result>behavioral results "https://www.virustotal.com/gui/file...9c95f4c07b013a6ca8c19583abfd8ef5385/detection". this is infected mate. Whether you made this or got it from somewhere and modified it, it is infected sorry
 

zhonow

Member
LV
1
Joined
Apr 19, 2024
Threads
10
Likes
21
Awards
5
Credits
3,806©
Cash
0$
Nothing besides the way authentication is performed (and a couple strings to give myself credit) was touched. Basically we jump to logging in no matter what the input key is. Everything else was left untouched.
also before you point it out, i dont think the termination of windows defenders TAMPER service is for good. Also whats up with the fake app dropped to the windows folder called "windowssdk.exe"? since i saw it having a process in the background and dropping 2 trojans to memory
 

Create an account or login to comment

You must be a member in order to leave a comment

Create account

Create an account on our community. It's easy!

Log in

Already have an account? Log in here.

Tips
Recently searched:

Similar threads

Users who are viewing this thread

Top Bottom