ALERT!
Click here to register with a few steps and explore all our cool stuff we have to offer!

Jump to content



Photo

XWORM V2.1 CRACKED - | UAC * WORM * RunPE * Clipper | Cleaned By ObbedCode


  • This topic is locked This topic is locked
XWORM V2.1 CRACKED - | UAC * WORM * RunPE * Clipper | Cleaned By ObbedCode

#51

smixo100
smixo100
    Offline
    0
    Rep
    0
    Likes

    Member

Posts: 40
Threads: 0
Joined: Dec 12, 2021
Credits: 0
Two years registered
#51

nice bro thx


  • 0

#52

pulalungageorg
pulalungageorg
    Offline
    0
    Rep
    0
    Likes

    Lurker

Posts: 5
Threads: 0
Joined: May 26, 2022
Credits: 0
Two years registered
#52

For a second I assumed it was the stub dropping in the TEMP dir from the second "builder.exe" file as that was being executed but I assumed if it was not connected to a valid server that would exit the stub, I was reversing it for a TCP Connection and realized it is using a Telegram Channel to send data to , The RAT uses a TCP Connection over a Custom Port , Telegram is not involved. So Come to find out, it was his Stealer he binded.


 


So you almost got me :< but the weird admin prompt ? , the Fake Error ? , and ofc dropping this in the %temp% folder on Disk for AVs to Scan Un-Obfuscated Code 6/10 I give it :(


Good Concept ?


 


Ps , Yes this is the CLEAN version , still run in sandbox tho . Good Practices :D


 


 


Screenshots of Program


 


Spoiler

 


====================================================


FEATURES


====================================================


 


 


 


[+] Run File From, URL / Disk / Memory / RunPE


[+] Blank Screen, Disable Win Updates, Run Shell , Invoke BSOD


[+] .NET 3.5 Installer


[+] UAC / Firewall / Taskmgr / RegEdit , Disabler + Enabler


[+] Shell / Webcam / MIC / Monitor / System Sound/ File Manager, Control


[+] TCP Connections Monitor


[+] Clipboard Manager + Password Manager


[+] Installed Programs Manager


[+] Activate Windows Option


[+] DDoS


[+] VB.NET Compiler / Google Maps


[+] Fun Functions


[+] Keylogger / Chat / File Searcher


[+] USB Spread + Bot Killer


[+] Prevent Sleep / Auto Sleep Disabler / Change Wallpaper / Message Box Popup / Delete Restore Points


[+] UAC Bypass 


[+] Coin Clipper / Swapper


[+] Ransomware 


[+] Ngrok Installer


[+] Tinynuke HVNC


[+] VNC Viewer


[+] Windows Defender , Disabler / Remover / Exclusion


[+] Startup, Registry / Folder / SCHTASKS aka Scheduled Tasks 


[+] Worm


[+] Anti Analysis


 


Thats most of it  :P 


 


====================================================


DOWNLOAD


====================================================


 


Password:


NULLED.TO


 


AnonFile



 


Zippyshare



 


Upload.ee



 


Sendspace



 


MirrorAce



 


 


Analysis of Infected File:


 


VT:


XWorm-RAT-V2.1-builder.exe => 

Please Login or Register to see this Hidden Content


win-xworm-builder => 

Please Login or Register to see this Hidden Content


 


~ Telegram Stealer Dropped in %temp% Dir under "win-xworm-builder.exe"


~ Has Basic Anti Analysis as that was part why Id assume it was cracking so it was just the stub, either way easy to Bypass "CALL => NOP" ;)


~ Telegram Chat Channel ID 2024893777


~ Steals From


 


Spoiler

 


Please Login or Register to see this Hidden Content


Please Login or Register to see this Hidden Content


Thanks for sharing

  • 0

#53

recruitm
recruitm
    Offline
    0
    Rep
    2
    Likes

    Member

Posts: 46
Threads: 2
Joined: Oct 06, 2022
Credits: 0
Two years registered
#53

thanks man


  • 0

#54

Hyderino6969
Hyderino6969
    Offline
    0
    Rep
    0
    Likes

    Lurker

Posts: 4
Threads: 0
Joined: Dec 19, 2022
Credits: 0
One year registered
#54

thank youi

 


  • 0

#55

ulce181223
ulce181223
    Offline
    0
    Rep
    0
    Likes

    New Member

Posts: 10
Threads: 0
Joined: Dec 16, 2022
Credits: 0
One year registered
#55

good job


  • 0

#56

esrefamca
esrefamca
    Offline
    0
    Rep
    0
    Likes

    Lurker

Posts: 1
Threads: 0
Joined: Dec 23, 2022
Credits: 0
One year registered
#56

ty bro


  • 0

#57

lolaylolay
lolaylolay
    Offline
    0
    Rep
    0
    Likes

    Member

Posts: 48
Threads: 0
Joined: Dec 05, 2022
Credits: 0
One year registered
#57

yuyuu


  • 0

#58

ViperZ69
ViperZ69
    Offline
    0
    Rep
    0
    Likes

    Member

Posts: 40
Threads: 1
Joined: Jul 29, 2022
Credits: 0
User has joined recently.
Make sure to use a MiddleMan.
Two years registered
#58

VERY GOOOOOOD!


  • 0

#59

z0rtgang
z0rtgang
    Offline
    0
    Rep
    0
    Likes

    Member

Posts: 29
Threads: 1
Joined: Oct 04, 2022
Credits: 0
Two years registered
#59

Thx i hope good rat

i check ,

and i tell ,

thx for your sharing


  • 0

#60

calianus
calianus
    Offline
    0
    Rep
    0
    Likes

    Lurker

Posts: 7
Threads: 0
Joined: Dec 30, 2022
Credits: 0
One year registered
#60

cool


  • 0


 Users browsing this thread: and 4 guests