- Joined
- August 19, 2023
- Messages
- 911
- Reaction score
- 42,636
- Points
- 93
- Thread Author
- #1
For a second I assumed it was the stub dropping in the TEMP dir from the second "builder.exe" file as that was being executed but I assumed if it was not connected to a valid server that would exit the stub, I was reversing it for a TCP Connection and realized it is using a Telegram Channel to send data to , The RAT uses a TCP Connection over a Custom Port , Telegram is not involved. So Come to find out, it was his Stealer he binded.
So you almost got me :< but the weird admin prompt ? , the Fake Error ? , and ofc dropping this in the %temp% folder on Disk for AVs to Scan Un-Obfuscated Code 6/10 I give it
Good Concept ?
Ps , Yes this is the CLEAN version , still run in sandbox tho . Good Practices
Screenshots of Program
Spoiler
====================================================
FEATURES
====================================================
[+] Run File From, URL / Disk / Memory / RunPE
[+] Blank Screen, Disable Win Updates, Run Shell , Invoke BSOD
[+] .NET 3.5 Installer
[+] UAC / Firewall / Taskmgr / RegEdit , Disabler + Enabler
[+] Shell / Webcam / MIC / Monitor / System Sound/ File Manager, Control
[+] TCP Connections Monitor
[+] Clipboard Manager + Password Manager
[+] Installed Programs Manager
[+] Activate Windows Option
[+] DDoS
[+] VB.NET Compiler / Google Maps
[+] Fun Functions
[+] Keylogger / Chat / File Searcher
[+] USB Spread + Bot Killer
[+] Prevent Sleep / Auto Sleep Disabler / Change Wallpaper / Message Box Popup / Delete Restore Points
[+] UAC Bypass
[+] Coin Clipper / Swapper
[+] Ransomware
[+] Ngrok Installer
[+] Tinynuke HVNC
[+] VNC Viewer
[+] Windows Defender , Disabler / Remover / Exclusion
[+] Startup, Registry / Folder / SCHTASKS aka Scheduled Tasks
[+] Worm
[+] Anti Analysis
Thats most of it
====================================================
DOWNLOAD
====================================================
Password:
NULLED.TO
AnonFile
Zippyshare
Upload.ee
Sendspace
MirrorAce
Analysis of Infected File:
VT:
XWorm-RAT-V2.1-builder.exe => https://www.virustot...aefe66807eac93a
win-xworm-builder => https://www.virustot...e2307b80a560319
~ Telegram Stealer Dropped in %temp% Dir under "win-xworm-builder.exe"
~ Has Basic Anti Analysis as that was part why Id assume it was cracking so it was just the stub, either way easy to Bypass "CALL => NOP"
~ Telegram Chat Channel ID 2024893777
~ Steals From
Spoiler
So you almost got me :< but the weird admin prompt ? , the Fake Error ? , and ofc dropping this in the %temp% folder on Disk for AVs to Scan Un-Obfuscated Code 6/10 I give it
Good Concept ?
Ps , Yes this is the CLEAN version , still run in sandbox tho . Good Practices
Screenshots of Program
Spoiler
====================================================
FEATURES
====================================================
[+] Run File From, URL / Disk / Memory / RunPE
[+] Blank Screen, Disable Win Updates, Run Shell , Invoke BSOD
[+] .NET 3.5 Installer
[+] UAC / Firewall / Taskmgr / RegEdit , Disabler + Enabler
[+] Shell / Webcam / MIC / Monitor / System Sound/ File Manager, Control
[+] TCP Connections Monitor
[+] Clipboard Manager + Password Manager
[+] Installed Programs Manager
[+] Activate Windows Option
[+] DDoS
[+] VB.NET Compiler / Google Maps
[+] Fun Functions
[+] Keylogger / Chat / File Searcher
[+] USB Spread + Bot Killer
[+] Prevent Sleep / Auto Sleep Disabler / Change Wallpaper / Message Box Popup / Delete Restore Points
[+] UAC Bypass
[+] Coin Clipper / Swapper
[+] Ransomware
[+] Ngrok Installer
[+] Tinynuke HVNC
[+] VNC Viewer
[+] Windows Defender , Disabler / Remover / Exclusion
[+] Startup, Registry / Folder / SCHTASKS aka Scheduled Tasks
[+] Worm
[+] Anti Analysis
Thats most of it
====================================================
DOWNLOAD
====================================================
Password:
NULLED.TO
AnonFile
To see this hidden content, you must reply and react with one of the following reactions : Like
Zippyshare
To see this hidden content, you must reply and react with one of the following reactions : Like
Upload.ee
To see this hidden content, you must reply and react with one of the following reactions : Like
Sendspace
To see this hidden content, you must reply and react with one of the following reactions : Like
MirrorAce
To see this hidden content, you must reply and react with one of the following reactions : Like
Analysis of Infected File:
VT:
XWorm-RAT-V2.1-builder.exe => https://www.virustot...aefe66807eac93a
win-xworm-builder => https://www.virustot...e2307b80a560319
~ Telegram Stealer Dropped in %temp% Dir under "win-xworm-builder.exe"
~ Has Basic Anti Analysis as that was part why Id assume it was cracking so it was just the stub, either way easy to Bypass "CALL => NOP"
~ Telegram Chat Channel ID 2024893777
~ Steals From
Spoiler