ALERT!
Click here to register with a few steps and explore all our cool stuff we have to offer!

Jump to content



Photo

GANG-NUKER 2.0 Cracked | DISCORD MULTI TOOL | Cleaned by ObbedCode


  • Please log in to reply
GANG-NUKER 2.0 Cracked | DISCORD MULTI TOOL | Cleaned by ObbedCode

#441

xeenrim
xeenrim
    Offline
    0
    Rep
    0
    Likes

    Member

  • PipPipPip
Posts: 26
Threads: 0
Joined: Oct 16, 2023
Credits: 0
One year registered
#441

ty man


  • 0

#442

macauleyb55
macauleyb55
    Offline
    0
    Rep
    0
    Likes

    Advanced Member

  • PipPipPipPip
Posts: 76
Threads: 0
Joined: Dec 17, 2017
Credits: 0
Six years registered
#442

thank you so much 


  • 0

#443

dox9999
dox9999
    Offline
    0
    Rep
    0
    Likes

    New Member

  • PipPip
Posts: 24
Threads: 0
Joined: Jan 29, 2023
Credits: 0
One year registered
#443

thanks man


  • 0

#444

B3nn13s
B3nn13s
    Offline
    0
    Rep
    0
    Likes

    Lurker

Posts: 2
Threads: 0
Joined: Nov 21, 2023
Credits: 0
One year registered
#444

thank u


  • 0

#445

B3nn13s
B3nn13s
    Offline
    0
    Rep
    0
    Likes

    Lurker

Posts: 2
Threads: 0
Joined: Nov 21, 2023
Credits: 0
One year registered
#445

thank so much


  • 0

#446

dghtrhdrhdtrh
dghtrhdrhdtrh
    Offline
    0
    Rep
    0
    Likes

    New Member

Posts: 15
Threads: 0
Joined: Nov 21, 2023
Credits: 0
One year registered
#446

thanks


  • 0

#447

minowased
minowased
    Offline
    0
    Rep
    0
    Likes

    Lurker

Posts: 3
Threads: 0
Joined: Jun 10, 2023
Credits: 0
One year registered
#447

good boy


  • 0

#448

zx1f
zx1f
    Offline
    0
    Rep
    0
    Likes

    Lurker

Posts: 7
Threads: 0
Joined: Nov 25, 2023
Credits: 0
One year registered
#448

 

Im going to start a new thing for every infected thread , ASSUMING it has the clean BINs binded to it

I will reupload the the Content but the CLEAN Version.

Now it wont always be possible as some dont have the Binded Bins or are just plain out all infected :(

 

This Sample was Binded as a Windows .CAB or Cabinet File Upon Extraction you will get the Infected Bins and Non Infected Bins

 

Once Executed , Select option "1" enter a Random key

Once Greeted with the Logo Screen click Enter.

 

cW4YOgm.png

 

===========================================================

Downloads

===========================================================

 

Zippyshare

 

 

AnonFiles

 

 

MirrorAce

 

 

MultiUp

 

 

 

REAL VT Bin Scan:

https://www.virustot...41ddfa207177ad5

 

Clown of the Day Spreading the Coin Miner Malware goes to:

 

Spoiler

Full Analysis ON the INFECTED version

 

~ "WEXTRACT.exe" is the original file name

~ Description "Internet Explorer" (spoofed file details)

~ Its a Cabinet file so when extracting it now gives us two EXEs (Brw0C.exe) & (GANG.exe)

~ Gang.exe seems to be legit "Brw0C.exe" is not , it is also 700+ mb

~ Uses MPRESS packer

~ Runs as Admin executes Powershell

~ Drops files in the %AppData% Roaming Folder under "WindowsElements" folder

~ Files Dropped "Kapow.zip" , "DesktopSessionManager.exe" , "AntimalwareService.exe"

~ In the "Kapow" folder it has a file called "GPUMonitor.exe"

 

https://imgur.com/a/Mkf0c2n

 

Bin Scans:

Spoiler

 


  • 0

#449

zx1f
zx1f
    Offline
    0
    Rep
    0
    Likes

    Lurker

Posts: 7
Threads: 0
Joined: Nov 25, 2023
Credits: 0
One year registered
#449

gg


  • 0

#450

UHT
UHT
    Offline
    0
    Rep
    1
    Likes

    Addicted

  • PipPipPipPipPip
Posts: 238
Threads: 0
Joined: Mar 18, 2023
Credits: 0

One year registered
#450

Im going to start a new thing for every infected thread , ASSUMING it has the clean BINs binded to it


I will reupload the the Content but the CLEAN Version.


Now it wont always be possible as some dont have the Binded Bins or are just plain out all infected :(


 


This Sample was Binded as a Windows .CAB or Cabinet File Upon Extraction you will get the Infected Bins and Non Infected Bins


 


Once Executed , Select option "1" enter a Random key


Once Greeted with the Logo Screen click Enter.


 


cW4YOgm.png


 


===========================================================


Downloads


===========================================================


 


Zippyshare



 


AnonFiles



 


MirrorAce



 


MultiUp



 


 


REAL VT Bin Scan:


https://www.virustot...41ddfa207177ad5


 


Clown of the Day Spreading the Coin Miner Malware goes to:


 


Spoiler

Full Analysis ON the INFECTED version


 


~ "WEXTRACT.exe" is the original file name


~ Description "Internet Explorer" (spoofed file details)


~ Its a Cabinet file so when extracting it now gives us two EXEs (Brw0C.exe) & (GANG.exe)


~ Gang.exe seems to be legit "Brw0C.exe" is not , it is also 700+ mb


~ Uses MPRESS packer


~ Runs as Admin executes Powershell


~ Drops files in the %AppData% Roaming Folder under "WindowsElements" folder


~ Files Dropped "Kapow.zip" , "DesktopSessionManager.exe" , "AntimalwareService.exe"


~ In the "Kapow" folder it has a file called "GPUMonitor.exe"


 


https://imgur.com/a/Mkf0c2n


 


Bin Scans:


Spoiler

SWEEET

  • 0


 Users browsing this thread: