ALERT!
Click here to register with a few steps and explore all our cool stuff we have to offer!

Jump to content



Photo

GANG-NUKER 2.0 Cracked | DISCORD MULTI TOOL | Cleaned by ObbedCode


  • Please log in to reply
GANG-NUKER 2.0 Cracked | DISCORD MULTI TOOL | Cleaned by ObbedCode

#11

keta42
keta42
    Offline
    0
    Rep
    0
    Likes

    New Member

Posts: 17
Threads: 0
Joined: Oct 26, 2022
Credits: 0
One year registered
#11

thanks


  • 0

#12

Sznap
Sznap
    Offline
    0
    Rep
    0
    Likes

    Member

Posts: 26
Threads: 0
Joined: Oct 16, 2022
Credits: 0
One year registered
#12

GGS


  • 0

#13

tinyblushie
tinyblushie
    Offline
    0
    Rep
    0
    Likes

    Member

Posts: 74
Threads: 0
Joined: Jan 09, 2022
Credits: 0
Two years registered
#13

 

Im going to start a new thing for every infected thread , ASSUMING it has the clean BINs binded to it

I will reupload the the Content but the CLEAN Version.

Now it wont always be possible as some dont have the Binded Bins or are just plain out all infected :(

 

This Sample was Binded as a Windows .CAB or Cabinet File Upon Extraction you will get the Infected Bins and Non Infected Bins

 

Once Executed , Select option "1" enter a Random key

Once Greeted with the Logo Screen click Enter.

 

cW4YOgm.png

 

===========================================================

Downloads

===========================================================

 

Zippyshare

 

 

AnonFiles

 

 

MirrorAce

 

 

MultiUp

 

 

 

REAL VT Bin Scan:

https://www.virustot...41ddfa207177ad5

 

Clown of the Day Spreading the Coin Miner Malware goes to:

 

Spoiler

Full Analysis ON the INFECTED version

 

~ "WEXTRACT.exe" is the original file name

~ Description "Internet Explorer" (spoofed file details)

~ Its a Cabinet file so when extracting it now gives us two EXEs (Brw0C.exe) & (GANG.exe)

~ Gang.exe seems to be legit "Brw0C.exe" is not , it is also 700+ mb

~ Uses MPRESS packer

~ Runs as Admin executes Powershell

~ Drops files in the %AppData% Roaming Folder under "WindowsElements" folder

~ Files Dropped "Kapow.zip" , "DesktopSessionManager.exe" , "AntimalwareService.exe"

~ In the "Kapow" folder it has a file called "GPUMonitor.exe"

 

https://imgur.com/a/Mkf0c2n

 

Bin Scans:

Spoiler

 

cool


  • 0

#14

JanHeeftGeen
JanHeeftGeen
    Offline
    0
    Rep
    0
    Likes

    Lurker

Posts: 2
Threads: 0
Joined: Nov 01, 2022
Credits: 0
One year registered
#14

thank you


  • 0

#15

kaixxxxx
kaixxxxx
    Offline
    0
    Rep
    0
    Likes

    Member

Posts: 38
Threads: 0
Joined: Oct 28, 2022
Credits: 0

One year registered
#15

thanks bruh !!


  • 0

#16

nuxx102
nuxx102
    Offline
    0
    Rep
    0
    Likes

    Member

  • PipPipPip
Posts: 70
Threads: 0
Joined: Oct 10, 2022
Credits: 0

One year registered
#16

nice


  • 0

#17

Joeseph1234
Joeseph1234
    Offline
    0
    Rep
    0
    Likes

    Advanced Member

  • PipPipPipPip
Posts: 114
Threads: 0
Joined: Aug 07, 2022
Credits: 0
Two years registered
#17

thx bro


  • 0

#18

webdevs1
webdevs1
    Offline
    0
    Rep
    0
    Likes

    Lurker

Posts: 2
Threads: 0
Joined: Nov 07, 2022
Credits: 0
One year registered
#18

thanks for share


  • 0

#19

LoidForger
LoidForger
    Online
    261
    Rep
    777
    Likes

    777

Posts: 7040
Threads: 340
Joined: Jan 03, 2018
Credits: 0

Six years registered
#19

How is this not getting more likes XD you clearly deserve more likes :D nice job mate


  • 0

Cheap VPN, Streaming, Securities Accounts, Private Crunchyroll Accounts & Many More Starting 1$
>> Main Shop : https://loid.sellpass.io/products <<

 

9H2AXsx.gif

:pepolove:

CRAWLER | SpartanHoplite | M3GZ | Fivio | Hades | Ituriel | Stranded | renul | vaelxn | RareModz Preaux | D1NO Castiel | SolarEnergy | Ju1ceWRLD SkrippyTrojanFilmTheLegendBROLY


#20

napeya2241
napeya2241
    Offline
    0
    Rep
    0
    Likes

    Member

  • PipPipPip
Posts: 26
Threads: 0
Joined: Nov 07, 2022
Credits: 0

One year registered
#20

ty


  • 0


 Users browsing this thread: and 1 guests