My Afl Strategy

#53
how many users got infected with this backdoor in this EXE !!

open run---> %temp% directory there would be directory named dclogs ...inside there would be files in [date].dc format ...open this files using notepad ....it contains all your information what you have typed using keyboard !!

After sometime it'll send all that information to author !!

See backdoor information : https://www.virustotal.com/en/file/...3a31934e6f6b1fda0372550d872fbf010f8/analysis/

1. ) NEVER RUN ANY EXE FILE BLINDLY first check with multiple AV here : www.virustotal.com

2.) NEVER TURNOFF AV AT ALL !!

3.) IF ANY CLEAN EXE asking for such restriction PM me ...I would be more happy to look into this !! :rofl:

BELIEVE IN FSF .... Search FSF in google !!
 
#55
Jiten .. I can see you are using CCP system ...... can you please share that file too ... i m in process of extracting Excel file.... will share once fully extract !! ....... meanwhile you see preview of excel code ....

-------------------------------------
------------------------------------
MultiPage1.Value = 1 'FOR FIB PAGE
00008F96 MultiPage1.Value = 0 'FOR CCP PAGE
00008FBE ccpbuyrate.Value = ActiveSheet.Range("A1").Value
00008FF6 ccpsellrate.Value = ActiveSheet.Range("A2").Value
0000904A FOR CCP PAGE
0000905E MultiPage1.Value = 1 'FOR FIB PAGE
00009086 MultiPage1.Value = 0 'FOR CCP PAGE
000090AE ccpbuyrate.Value = ActiveSheet.Range("A1").Value
000090E6 ccpsellrate.Value = ActiveSheet.Range("A2").Value
0000913A FOR FIB PAGE
0000914E MultiPage1.Value = 1 'FOR FIB PAGE
00009176 MultiPage1.Value = 0 'FOR CCP PAGE
0000919E ccpbuyrate.Value = ActiveSheet.Range("A1").Value
000091D6 ccpsellrate.Value = ActiveSheet.Range("A2").Value
hide userform when workbook is not active
0000A8C1 Private Sub Workbook_Activate()
0000A8E9 Dim uForm As Object
0000A911 On Error Resume Next
0000A931 Set uForm = CCPMAIN
0000A951 If Not uForm Is Nothing Then UserForm1.Show
0000A989 End Sub
0000A9A1 Private Sub Workbook_Deactivate()
0000A9C9 On Error Resume Next
0000A9E9 CCPMAIN.Hide
0000AA09 End Sub
0000AA21 Private Sub Workbook_Deactivate()
0000AA49 On Error Resume Next
0000AA69 CCPMAIN.Hide
0000AA89 End Sub
_________________________________________________________
-----------------------------------------------------------------
 

Relish

Well-Known Member
#59
Its original link should be posted where it is taken. By disabling AV & giving machine ID is it safe or we r not asking for hacking?
how many users got infected with this backdoor in this EXE !!

open run---> %temp% directory there would be directory named dclogs ...inside there would be files in [date].dc format ...open this files using notepad ....it contains all your information what you have typed using keyboard !!

After sometime it'll send all that information to author !!
I did't know how many read my post Thank's avii giving full details how it will happened as I did't know more but posted as warning sign :thumb:
 

Similar threads