What's new
  • Visit Rebornbuddy
  • Visit Resources
  • Visit API Documentation
  • Visit Downloads
  • Visit Portal
  • Visit Panda Profiles
  • Visit LLamamMagic

Beta DB and HB - infected.

Status
Not open for further replies.

Bugser

New Member
Joined
Dec 6, 2012
Messages
78
Reaction score
3
And don't say it's false positive. lol.

http://www.thebuddyforum.com/demonb...-db-build-110-tony-your-pm-indbox-full-3.html

decrypted Thumb.DB from beta demonbuddy:
https://www.virustotal.com/file/3df...4fe154df6f11c71c97b8fbe1/analysis/1355742632/
Behavioural information
URL: http://www.gtnbus.com/html_xor.jpg
TYPE: GET
UA: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US)
html_xor.jpg decrypted - https://www.virustotal.com/file/7db...54ef5a9239a261db2da8c065/analysis/1355746227/

this shit is steal diablo/guild wars 2/wow passwords (game=%s&host=%s&user=%s&pass=%s) and xor'ed by 0xAA.

Crypted program from Thumb.DB connecting to html_xor.jpg and this jpg is contains this stealer! what the fuck you doing, devs? you have rat in your team? or what? and don't say it's false positive because its NOT!
 
BthA7.png


KWZWE.png
 
Status
Not open for further replies.
Back
Top