Navigation X
ALERT
Click here to register with a few steps and explore all our cool stuff we have to offer!



   4245

If you see this in a config, DO NOT DOWNLOAD.

by Pleth - 02 March, 2023 - 11:11 PM
This post is by a banned member (sYdr1b) - Unhide
sYdr1b  
Contributor
212
Posts
93
Threads
6 Years of service
#9
"I'm not even gonna lie, this is a genius way to do this,"

this isn't new or genius at all. this has been used in many ways since nearly the beginning. using statements for redirection. renaming variables to look less sketchy. encoding urls and passing them to logging sites or to dl clippers. just goes to show people should actually pay attention to what it is they use.
This post is by a banned member (Pleth) - Unhide
This post is by a banned member (MuratSarsilmaz) - Unhide
1.563
Posts
293
Threads
4 Years of service
#11
(This post was last modified: 06 March, 2023 - 04:04 PM by MuratSarsilmaz. Edited 1 time in total.)
I always suggest everyone to deeply analyze any config he get even if config from his trustworthy friend, In this way he will not only identify stealers but also learn many ways how professionals makes configs!
This post is by a banned member (Shield) - Unhide
Shield  
Supreme
2.414
Posts
615
Threads
6 Years of service
#12
(02 March, 2023 - 11:11 PM)Pleth Wrote: Show More
[Image: k5meo9j.png]

Any time you see this in a config, it is executing a stealer. I had this happen to me and when we sat there and looked at what it did, we came back to this:
https://github.com/w4sp-book/w4sp-lab

This is what it led back to.

It will look like this:
[Image: hVNnkgA.png]

Or very similar.

I'm not even gonna lie, this is a genius way to do this, but once you run the config it (somehow) spreads to all your other configs. When you send them to anyone, the process starts again. As it is a stealer, it will steal your information. And this is one of the many reasons i suggest running configs on an RDP.

This is similar to the malicious API thing, but smarter as most people won't recognize it as anything.

Thanks for letting me know , i didnt get this config yet , what actaully it doing ?
pepeblush

[Image: output-onlinegiftools.gif]

[Image: Hb9yL5l.png]
==========
Telegram Channel
https://t.me/shieldteam1
===========
This post is by a banned member (Pleth) - Unhide

Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
or
Sign in
Already have an account? Sign in here.


Forum Jump:


Users browsing this thread: 1 Guest(s)