Can i request unpacked malwares?

Ask your beginner questions here.
Post Reply
User avatar
FakeAVHunter
Posts: 61
Joined: Thu Feb 01, 2018 6:20 pm
Location: Romania
Contact:

Can i request unpacked malwares?

Post by FakeAVHunter » Wed Jun 20, 2018 2:16 pm

Hello everyone today i wanna to ask a question about malware unpack requests.
I Send a question before to peform this action

User avatar
EP_X0FF
Global Moderator
Posts: 4777
Joined: Sun Mar 07, 2010 5:35 am
Location: Russian Federation
Contact:

Re: Can i request unpacked malwares?

Post by EP_X0FF » Fri Jun 22, 2018 3:33 am

Post your malware you want to unpack in password protected archive. Maybe someone will help you. However if they are protected by commercial software (VMProtect, Themida) etc - nobody want waste their time.
Ring0 - the source of inspiration

User avatar
FakeAVHunter
Posts: 61
Joined: Thu Feb 01, 2018 6:20 pm
Location: Romania
Contact:

Re: Can i request unpacked malwares?

Post by FakeAVHunter » Fri Jun 22, 2018 4:20 am

Seriously? :roll: Let's try

User avatar
FakeAVHunter
Posts: 61
Joined: Thu Feb 01, 2018 6:20 pm
Location: Romania
Contact:

Re: Can i request unpacked malwares?

Post by FakeAVHunter » Fri Jun 22, 2018 4:39 am

EP_X0FF wrote:
Fri Jun 22, 2018 3:33 am
Post your malware you want to unpack in password protected archive. Maybe someone will help you. However if they are protected by commercial software (VMProtect, Themida) etc - nobody want waste their time.
The passwords from the archived malwares that needs a unpack / fix / working correctly i had to send three zip files because the first archive was too large to upload so here we go.I Cant unpack malware / i dont taked unpacking virus malware lessons.
You do not have the required permissions to view the files attached to this post.

User avatar
EP_X0FF
Global Moderator
Posts: 4777
Joined: Sun Mar 07, 2010 5:35 am
Location: Russian Federation
Contact:

Re: Can i request unpacked malwares?

Post by EP_X0FF » Fri Jun 22, 2018 9:32 am

21d20301ed7cefab2acce9afe56dd63db594aeb98c7e596152e2a399835e0c24

Completely deobfuscated in attach. MEMORY.rar
It starts, write self-deletion bat file, executes it and crash itself with fake runtime error dialog. Why it doesn't give you anything else is because it is incredible old and everything related to it is dead.

Bullshit delphi fake av. Everything from it can be grabbed from resources (wav files, gifs, forms etc).

46e9fa0b613f821a9993d2d1d776af87357015cfadbcab59cf42a0730729f2af
is the same as first.

Deobfuscated in attach. MEMORY2.rar
Crypted and packed with UPX 3.07.

Honestly nobody interested in digging into Delphi trash fakeav's that is 4-5 years old. Waste of time.
You do not have the required permissions to view the files attached to this post.
Ring0 - the source of inspiration

User avatar
FakeAVHunter
Posts: 61
Joined: Thu Feb 01, 2018 6:20 pm
Location: Romania
Contact:

Re: Can i request unpacked malwares?

Post by FakeAVHunter » Fri Jun 22, 2018 11:44 am

EP_X0FF wrote:
Fri Jun 22, 2018 9:32 am
21d20301ed7cefab2acce9afe56dd63db594aeb98c7e596152e2a399835e0c24

Completely deobfuscated in attach. MEMORY.rar
It starts, write self-deletion bat file, executes it and crash itself with fake runtime error dialog. Why it doesn't give you anything else is because it is incredible old and everything related to it is dead.

Bullshit delphi fake av. Everything from it can be grabbed from resources (wav files, gifs, forms etc).

46e9fa0b613f821a9993d2d1d776af87357015cfadbcab59cf42a0730729f2af
is the same as first.

Deobfuscated in attach. MEMORY2.rar
Crypted and packed with UPX 3.07.

Honestly nobody interested in digging into Delphi trash fakeav's that is 4-5 years old. Waste of time.
but thanks for unpack...

Post Reply