kNigHt Posted February 27, 2015 Report Posted February 27, 2015 Am primit mesajul asta pe Steam:BookerDoit: Hi man,i want trade with you.My offer in screen:vk.cc/3vSUBsCheck this, and message me if you want.thx[root@x] ~/temp $ wget http://vk.cc/3vSUBs -O dubios--2015-02-27 09:13:51-- http://vk.cc/3vSUBsResolving vk.cc (vk.cc)... 95.213.4.230, 95.213.4.231, 95.213.4.232Connecting to vk.cc (vk.cc)|95.213.4.230|:80... connected.HTTP request sent, awaiting response... 302 FoundLocation: http://goo.gl/L5YY7p [following]--2015-02-27 09:13:51-- http://goo.gl/L5YY7pResolving goo.gl (goo.gl)... 216.58.209.206, 2a00:1450:400d:807::200eConnecting to goo.gl (goo.gl)|216.58.209.206|:80... connected.HTTP request sent, awaiting response... 301 Moved PermanentlyLocation: https://drive.google.com/uc?export=download&id=0B0dLlCIuGBcucTkyb1Z2Z05IVEk [following]--2015-02-27 09:13:51-- https://drive.google.com/uc?export=download&id=0B0dLlCIuGBcucTkyb1Z2Z05IVEkResolving drive.google.com (drive.google.com)... 216.58.209.206, 2a00:1450:400d:807::200eConnecting to drive.google.com (drive.google.com)|216.58.209.206|:443... connected.HTTP request sent, awaiting response... 302 Moved TemporarilyLocation: https://doc-0o-08-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/h41sk43kd5qcl4e5ue6n6jbruno0oomv/1425016800000/07539905863404628466/*/0B0dLlCIuGBcucTkyb1Z2Z05IVEk?e=download [following]Warning: wildcards not supported in HTTP.--2015-02-27 09:13:52-- https://doc-0o-08-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/h41sk43kd5qcl4e5ue6n6jbruno0oomv/1425016800000/07539905863404628466/*/0B0dLlCIuGBcucTkyb1Z2Z05IVEk?e=downloadResolving doc-0o-08-docs.googleusercontent.com (doc-0o-08-docs.googleusercontent.com)... 216.58.209.193, 2a00:1450:400d:807::2001Connecting to doc-0o-08-docs.googleusercontent.com (doc-0o-08-docs.googleusercontent.com)|216.58.209.193|:443... connected.HTTP request sent, awaiting response... 200 OKLength: 911360 (890K) [application/x-dosexec]Saving to: ‘dubios’dubios 100%[=================================================>] 890.00K --.-KB/s in 0.1s 2015-02-27 09:13:52 (7.52 MB/s) - ‘dubios’ saved [911360/911360][root@x] ~/temp $ file dubiosdubios: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS WindowsDownload "dubios":http://www30.zippyshare.com/v/gj6MrMo8/file.html Quote
robyyxx2 Posted February 27, 2015 Report Posted February 27, 2015 (edited) Este o aplicatie .Net care din pacate a fost obfuscata cu https://confuser.codeplex.com/ si este mult de lucru sa poti vedea ce face programul (cica e anti debugger).avand in vedere ca este bine criptat, mai mult ca sigur este un virus.Pune un VM si executa acolo.Edit: Compileaza proiectul asta https://github.com/UbbeLoL/ConfuserDeobfuscator cu visual basic (cu 12 ar trebuii sa functioneze) si ai program pentru deobfuscat programul "dubios" apoi descarca https://www.jetbrains.com/decompiler/ ca sa sa poti decompila si sa vezi sursa. Edited February 27, 2015 by robyyxx2 Quote