Thanat0S wrote:does anyone has panel src of 1.5 pleaseuseless, panel is under ioncube.
A forum for reverse engineering, OS internals and malware analysis
Thanat0S wrote:does anyone has panel src of 1.5 pleaseuseless, panel is under ioncube.
Xylitol wrote:ya, i know, this may work:Thanat0S wrote:does anyone has panel src of 1.5 pleaseuseless, panel is under ioncube.
Xylitol wrote:Yep, its IonCubed.Thanat0S wrote:does anyone has panel src of 1.5 pleaseuseless, panel is under ioncube.
r3shl4k1sh wrote:More BetaBot:
In attach Unpacked + dump of config:
MD5 c6ca1470501c1d885717104ca9ac51e2
MD5 4046fd4e5ddfc40548c2316d6cd289f4
MD5 c994461c69b02a63d0f1bbcd2a56ba54
From the config of c6ca1470501c1d885717104ca9ac51e2:From the config of 4046fd4e5ddfc40548c2316d6cd289f4:
- Owner: the sky daddy
- Dropped File name: svchost (win)
- C&C(s):
Code: Select allgate: sentryme.com/order.php gate: stayattentive.com/order.php
From the config of c994461c69b02a63d0f1bbcd2a56ba54:
- Owner: lavnesh (http://www.hackforums.net/member.php?ac ... uid=101982 ???)
- Dropped File name: Realtek (Realtek\Audio\Manager)
- C&C(s):
Code: Select allgate: hxxp://lpa4u.in/radioserver/order.php
- Owner: nicksasa
- Dropped File name: Magic Helper
- C&C(s):
Code: Select allgate: hxxp://imafaggot.pw/service/order.php gate: hxxp://winblowservice.hopto.org/service/order.php login: hxxp://winblowservice.hopto.org/service/login.php gate: hxxp://imtheop.redirectme.net/service/order.php login: hxxp://imtheop.redirectme.net/service/login.php
33ae38898f5635cd46ec4b0f78d3ad6b
b26d1aec219ce45b2e80769368310471
4295e49380f2c8dca61c38f811dff2cc
00f314fbd45d4930eedc6168453a9ad7
71d085cf6737ead3b92f61d85c9a221b
2427918e2745ae122ae9703e40bcd0f7
ffdf06fb9dd3f55df7920f7f4202653e
48889aeee32b3fd6cf1057ad008220e7
a3ccfd0aa0b17fd23aa9fd0d84b86c05
Thanat0S wrote:I think anyone in the scene must create a builder to this shit and stop the game to this skid.I don't think it is a good idea because of:
NO ILLEGAL CONTENT. This means: no posting warez, cracked software, or talking about how to write viruses and trojans. We do not create malware here.... which implies "we do not use malware" too.
hxxp://novemberspecials.ru/build.exe
01448a15955c3e865ea122a4e397e65d
hxxp://renterlocal.su/be/order.php
hxxp://novemberspecials.ru/files/data/