o dam wow very nice HQ uploads
Chaos Ransomware Builder V4 - Cleaned by ObbedCode
#24
Posted 18 December 2022 - 01:57 AM
#25
Posted 18 December 2022 - 09:08 AM
Thanks for sharingTo clean the file we have to rename a .DLL to .EXE and modify some sus IL Code.
Removed the Original .exe that is just a virus
Note I cleaned the File, You Can analyze the file for yourself in DnSpy
Still Run everything in a Controlled Environment. My version is the Fully Cleaned Version.
Even has the Decryptor in the same Folder
Person Spreading Malware:
Spoiler
Original Report:
Spoiler
===================================================================
DOWNLOAD
===================================================================
Password: Chaos46366
Upload.ee
Anonfile
Zippyshare
Mirror Ace
===================================================================
SCREENSHOTS
===================================================================
Spoiler
Original Analysis:
(Still always run EVERYTHING in Sandbox / Virtual Machine)
Stub SRC:
VT:
HB:
#27
Posted 19 December 2022 - 11:22 PM
#28
Posted 20 December 2022 - 06:50 AM
#29
Posted 20 December 2022 - 07:25 PM
To clean the file we have to rename a .DLL to .EXE and modify some sus IL Code.
Removed the Original .exe that is just a virus
Note I cleaned the File, You Can analyze the file for yourself in DnSpy
Still Run everything in a Controlled Environment. My version is the Fully Cleaned Version.
Even has the Decryptor in the same Folder
Person Spreading Malware:
Spoiler
Original Report:
Spoiler
===================================================================
DOWNLOAD
===================================================================
Password: Chaos46366
Upload.ee
Anonfile
Zippyshare
Mirror Ace
===================================================================
SCREENSHOTS
===================================================================
Spoiler
Original Analysis:
(Still always run EVERYTHING in Sandbox / Virtual Machine)
Stub SRC:
VT:
HB:
ty
#30
Posted 23 December 2022 - 06:50 AM
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
Users browsing this thread: