Answer the question
In order to leave comments, you need to log in
What information can be found from the .text of the virus?
One person sent me a link to a Yandex disk (he is 11).
Described the program as his own antivirus.
I installed it. The exe's signature was: FlurryCheats.
It seemed strange to me, I unpacked it using 7-zip and looked through the .text file in a notepad (I don’t know if I’m doing it this way or not, I guessed it myself)
And there I scrolled through and found a few jokes:
7 File Z illa \ recentservers . xml \password\Vime World | | | | #H81:0 AV ime . G et "level" : , [ ] "rank" : %S oftware \ V ime W orld
osuuid H81:0 AOSSUIDE rrorusername : >H81:0 N ick N ame \ . vimeworld
config /\ T elegram D esktop \ tdata T elegramtdata \ T elegramsusertagsettin gskey _ dataunknownx 2 :
Failed U nknown }abcdefghijklmnopqrstu vwxyz ABCDEFGHIJKLMNOPQRSTU VWXYZ 0 1 2 3 4 5 6 7 8 9 Ethernet ( ) \ 4 4 MM / dd / yyyyh : mm Gh ttps : / / api . vimeworld. ru / user / name / 5h ttps : / / freegeoip . app/xml/\Process. txt
NAME : gS ELECTE xecutable Path , P rocess IDFROMW in 3 2 _ P rocess P rocess IDE xecutable Path \ S creen . png ЂЏ ================================================ = =
O peratingsystem :
PC user :
C lip B oard :
L aunch : Ђ“
==================================================
Screenresolution : !
C urrenttime :
HWID : w
============================================ ======
CPU :
RAM : GPU :
ЂЌ =====================================
=============
IPG eolocation :
L og D ate :
BSSID : i
==================================================
_
============== 4 4 CALIBERSTEALER ================================== =============================
Madedby Chaos I nsurgency | lolz. guru / thanatophobia
telegram @ chaosinsurgency
W rittenexclusivelyfore ducationalpurposes ! I'm amnotresponsibleforth euseofthisprojectanda nyofitspartscode. /
: spy : NEWLOGFROM - U : person _ in _ manual _ wheelchair :
: eye : IP :
: desktop : m
=========================== = = = = = =
: key : P asswords - +
: cookie : C ookies - ?
: notepad _ spiral : A uto F ills - +
: credit _ card : CC - A
: file _ folder : Grabbed F iles - k
===================== =============
GRABBEDSOFTWARE :
D iscord
W allets
T elegram
F ile Z illa (
S team
N ord VPN
O pen VPN
P roton VPN
V ime W orld %:
N ick N ame - # :
D onate - ! :
L evel - s
Answer the question
In order to leave comments, you need to log in
Leave a link to the .exe. This will make it easier to study.
Your .txt file is like an encrypted binary. From this file, without a disassembler, only the lines that you found will be clear.
Well, congratulations.
You installed the Trojan 44 Caliber Stealer :-)))
This virus is taken from here:
https://github.com/Khainaaeh/44CALIBER
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question