U
U
Uncle Bogdan2021-05-30 09:33:48
Malware
Uncle Bogdan, 2021-05-30 09:33:48

What information can be found from the .text of the virus?

One person sent me a link to a Yandex disk (he is 11).
Described the program as his own antivirus.
I installed it. The exe's signature was: FlurryCheats.
It seemed strange to me, I unpacked it using 7-zip and looked through the .text file in a notepad (I don’t know if I’m doing it this way or not, I guessed it myself)
And there I scrolled through and found a few jokes:

7 File Z illa \ recentservers . xml \password\Vime World | | | | #H81:0 AV ime . G et "level" : , [ ] "rank" : %S oftware \ V ime W orld
osuuid H81:0 AOSSUIDE rrorusername : >H81:0 N ick N ame \ . vimeworld
config /\ T elegram D esktop \ tdata T elegramtdata \ T elegramsusertagsettin gskey _ dataunknownx 2 :
Failed U nknown }abcdefghijklmnopqrstu vwxyz ABCDEFGHIJKLMNOPQRSTU VWXYZ 0 1 2 3 4 5 6 7 8 9 Ethernet ( ) \ 4 4 MM / dd / yyyyh : mm Gh ttps : / / api . vimeworld. ru / user / name / 5h ttps : / / freegeoip . app/xml/\Process. txt
NAME : gS ELECTE xecutable Path , P rocess IDFROMW in 3 2 _ P rocess P rocess IDE xecutable Path \ S creen . png ЂЏ ================================================ = =
O peratingsystem :
PC user :
C lip B oard :
L aunch : Ђ“
==================================================
Screenresolution : !
C urrenttime :
HWID : w
============================================ ======
CPU :
RAM : GPU :
ЂЌ =====================================
=============
IPG eolocation :
L og D ate :
BSSID : i


Why does antivirus need minecraft password and ip address? And then I found this:

==================================================
_
============== 4 4 CALIBERSTEALER ================================== =============================
Madedby Chaos I nsurgency | lolz. guru / thanatophobia
telegram @ chaosinsurgency
W rittenexclusivelyfore ducationalpurposes ! I'm amnotresponsibleforth euseofthisprojectanda nyofitspartscode. /
: spy : NEWLOGFROM - U : person _ in _ manual _ wheelchair :
: eye : IP :
: desktop : m
=========================== = = = = = =
: key : P asswords - +
: cookie : C ookies - ?
: notepad _ spiral : A uto F ills - +
: credit _ card : CC - A
: file _ folder : Grabbed F iles - k
===================== =============
GRABBEDSOFTWARE :
D iscord
W allets
T elegram
F ile Z illa (
S team
N ord VPN
O pen VPN
P roton VPN
V ime W orld %:
N ick N ame - # :
D onate - ! :
L evel - s


And I was wondering what else can be found here? Am I just wasting my time? I still don't understand what the virus is written in, C# or C++?
Link to .txt of all this.

Answer the question

In order to leave comments, you need to log in

3 answer(s)
M
mogen, 2021-05-30
@motkot

Leave a link to the .exe. This will make it easier to study.
Your .txt file is like an encrypted binary. From this file, without a disassembler, only the lines that you found will be clear.

B
BorLaze, 2021-05-30
@BorLaze

Well, congratulations.
You installed the Trojan 44 Caliber Stealer :-)))

A
alexbprofit, 2021-05-30
@alexbprofit

This virus is taken from here:
https://github.com/Khainaaeh/44CALIBER

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question