Jump to content
wNNkz0r

PH Crypter [FUD 100%]

Recommended Posts

2h3v5vk.jpg

Report date: 2011-10-23 13:48:14 (GMT 1)

File name: ph-crypter-exe

File size: 55296 bytes

MD5 hash: bea57c77d5086f9bec3181eb13729b6d

SHA1 hash: 8c618d89bf077fac1f6b673d922c045ff6424dd7

Detection rate: 0 on 9 (0%)

Avast 23/10/2011 5.0

AVG 23/10/2011 10.0.0.1190

Avira AntiVir 23/10/2011 7.11.7.12

ClamAV 23/10/2011 0.97

Comodo 23/10/2011 4.0

Emsisoft 23/10/2011 5.1.0.3

F-Prot 23/10/2011 6.3.3.4884

Ikarus 23/10/2011 T31001097

TrendMicro 23/10/2011 9.200.0.1012

NU SCANATI PE VIRUS TOTAL

LINK : Download Ph_Crypter.exe for free on Filesonic.com

  • Upvote 1
Link to comment
Share on other sites

http://s288.filesonic.ro/download/2702798371/4ea405f9/a1196e23/0/1/5c55927a/0/88438a2c94bc4badad4f6cf09aecbdba6318be7f Fi?ier desc?rcat ph_crypter.exe

Nume amenin?are:

WS.Reputation.1 de la

s288.filesonic.ro

Ac?iuni de fi?ier

Fi?ier: c:\documents and settings\admin\desktop\ph_crypter.exe

Eliminat

Amprent? fi?ier - SHA:

ae4c521929bcbca4faeb0ecdc8a0f4e0661af815555c4746e2c3f2b90aca8c60

Amprent? fi?ier - MD5:

bea57c77d5086f9bec3181eb13729b6d

Link to comment
Share on other sites

  • Cand dai "Load File" nu se intampla nimic.
  • Cand dai crypt la fel.
  • Daca treci calea fisierul pe care vrei sa il cryptezi in campul acela liber gen: "C:\Documents and Settings\fmm\Desktop\gen.exe" si dai crypt nimic.

Doar din astea ati dai seama ca e facut la misto si pus pe rst pentru a, agata cativa n00bisti.

Pe langa cele de mai sus daca il deschizi se observa cum se incarca la cursorul mausului timp de cateva secunde, timp in care se executa un alt fisier presupunand ca e steal si la fiecare deschidere se trimit parolele.

Sa nu mai zic ca a pus linkul direct fara al crypta sau de a parola arhiva si asta pentru a prinde cati mai multi prosti.

Altceva:

Cand executi se poate observa in "Task Manager" ca se mai executa un fisier odata cu "Ph_Crypter.exe" si acesta fiind "540587.exe,257683.exe etc"(la fiecare deschidere numele la fiser se schimba).

Care poate fi gasit in timpul rularii a "Ph_Crypter.exe" in "C:\Documents and Settings\fmm\Local Settings\Application Data\Numar.exe"

V-am atasat o arhiva ce contine asazisul "crypter" intre mici ghilimele si micul virus ce se executa odata cu el aici.

Ph_Crypter.exe

  • Created: Today, October 23, 2011, 7:30:36 PM
  • Modified: Today, October 23, 2011, 7:30:36 PM
  • Link:
    1.novirusthanks.org
    Report date: 2011-10-23 13:48:14 (GMT 1)
    File name: ph-crypter-exe
    File size: 55296 bytes
    MD5 hash: bea57c77d5086f9bec3181eb13729b6d
    SHA1 hash: 8c618d89bf077fac1f6b673d922c045ff6424dd7
    Detection rate: 1 on 9 (11%)
    Status: INFECTED
    2.virustotal.com
    File name: Ph_Crypter.exe
    Submission date: 2011-10-23 16:55:46 (UTC)
    Current status: finished
    Result: 1/ 43 (2.3%)

540587.exe:

  • Created: Today, October 23, 2011, 7:55:00 PM
  • Modified: Today, October 23, 2011, 7:48:25 PM
  • Link:
    1.novirusthanks.org
    Report date: 2011-10-23 19:00:47 (GMT 1)
    File name: 540587-exe
    File size: 24576 bytes
    MD5 hash: 11f768219bc6357f8f603aacf301c695
    SHA1 hash: cdc9ddfda0d8845398e4b164b74fb83630164372
    Detection rate: 0 on 9 (0%)
    Status: CLEAN
    2.virustotal.com
    File name: 540587.exe
    Submission date: 2011-10-23 17:02:17 (UTC)
    Current status: finished
    Result: 2/ 43 (4.7%)

Nume:	TR/Dropper.Gen

Descoperit pe data de: 19/06/2007

Tip: Troian

Subtip: Dropper

ITW: Da

Numar infectii raportate: Scazut

Potential de raspandire: Scazut

Potential de distrugere: Scazut

Fisier static: Nu

Versiune motor de scanare: 7.04.00.34

General

Efecte secundare:

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...