0Day Forums
[Virus] setup_hacxx_anonymous_file_search_v4_2210634171.rar - Printable Version

+- 0Day Forums (https://0day.red)
+-- Forum: Hacking & Exploits (https://0day.red/Forum-Hacking-Exploits)
+--- Forum: Antivirus & Protected (https://0day.red/Forum-Antivirus-Protected)
+--- Thread: [Virus] setup_hacxx_anonymous_file_search_v4_2210634171.rar (/Thread-Virus-setup-hacxx-anonymous-file-search-v4-2210634171-rar)



[Virus] setup_hacxx_anonymous_file_search_v4_2210634171.rar - scribbler98 - 04-13-2020

Can anyone reverse this program and find out if there is any hidden gem?
Last time i scanned a file from this source i got a command line firewall bypass...

Download:

[To see links please register here]


Virus Scan: (22/71)

[To see links please register here]




RE: [Virus] setup_hacxx_anonymous_file_search_v4_2210634171.rar - lusitania737259 - 04-14-2020

I'll quote @"miso".

He's RE'd a lot of programs, so hopefully he'll do the same with this.


RE: [Virus] setup_hacxx_anonymous_file_search_v4_2210634171.rar - gurgling253778 - 04-14-2020

Quote:(04-14-2020, 03:48 AM)mothered Wrote:

[To see links please register here]

I'll quote @"miso".

He's RE'd a lot of programs, so hopefully he'll do the same with this.

thanks for mentioning me

When installing, it will open a fake youtube-like webpage
extracting the installer shows a bunch of file that just have a bunch of repeated word, the only exception is with the only .exe file, which cannot be launched (file cannot be loaded in windows and ExePeInfo says it is corrupted)

I think the detections are just from the installer loading a scammy url, however, i've loaded the installer into a sandbox, when installed on a vm for example, the files my have different data except that i really doubt it)

[Image: MLEA1z9DQxS6ABy-iIlwYQ.png]
[Image: 6McjykVxQiSoH4GVGkC5nQ.png]

btw it never loads, clicking anywhere on that page makes it fullscreen, waiting a bit will redirect you into other scammy sites

tools used:
HxD, InnoExtractor, ExePeInfo, Sandboxie


RE: [Virus] setup_hacxx_anonymous_file_search_v4_2210634171.rar - cuticle851 - 04-14-2020

Ok thanks. Last time i research a file from this service i got something similar to the code below
Hidden Content

Also are you sure you tried correctly?
In my advertiser panel i have my install which was around 2AM and nothing else.
May have virtual machine protection.


RE: [Virus] setup_hacxx_anonymous_file_search_v4_2210634171.rar - talpidae186281 - 04-14-2020

Quote:(04-14-2020, 07:48 PM)miso Wrote:

[To see links please register here]

thanks for mentioning me

You're welcome, and thanks for your prompt response.


RE: [Virus] setup_hacxx_anonymous_file_search_v4_2210634171.rar - diplostemonous297 - 04-14-2020

Quote:(04-14-2020, 08:40 PM)hacxx Wrote:

[To see links please register here]

Ok thanks. Last time i research a file from this service i got something similar to the code below
Hidden Content

Also are you sure you tried correctly?
In my advertiser panel i have my install which was around 2AM and nothing else.
May have virtual machine protection.

i can't run vms due to my hardware not being able to run them (it cant run shit lol)

here's the files that i've extracted from the installer:

[To see links please register here]

[To see links please register here]




RE: [Virus] setup_hacxx_anonymous_file_search_v4_2210634171.rar - dameron812 - 04-15-2020

For some reason when i executed the file on my computer it download and executed this two installers.
- SevenZip.exe - A clone of 7Zip
- Avast.exe - Avast installer

Here is the download link:

[To see links please register here]




RE: [Virus] setup_hacxx_anonymous_file_search_v4_2210634171.rar - spicket801350 - 04-15-2020

Quote:(04-14-2020, 11:52 PM)miso Wrote:

[To see links please register here]

i can't run vms due to my hardware not being able to run them (it cant run shit lol)

VMs are predominantly CPU & Ram dependent.

What's your specs pertaining to the above? We'll move back on-topic after your reply.


RE: [Virus] setup_hacxx_anonymous_file_search_v4_2210634171.rar - geochronometric142795 - 04-15-2020

x64, 4GB RAM, Dual-core CPU
[Image: config.png]