|
You last visited: Today at 12:59
Advertisement
9d hacks
Discussion on 9d hacks within the 9Dragons forum part of the MMORPGs category.
06/24/2016, 00:14
|
#1
|
elite*gold: 0
Join Date: Nov 2007
Posts: 707
Received Thanks: 83
|
9d hacks
|
|
|
06/24/2016, 02:10
|
#2
|
elite*gold: 0
Join Date: Nov 2007
Posts: 855
Received Thanks: 519
|
I think you missed most important thing, scans.
Here they are:
Yahoo 10:
San the bai:
IE - Luyen skill:
Hack hiphop 9d:
Firefox - thien long:
Firefox New - Hack multi:
Revolution 8.3:
CheatEngine55:
NoDis73:
autoit-v3-setup:
DotNet2.0:
DotNet3.1:
DotNet3.5:
I'd still recommend to run it in sandbox.
NoDis73 virus definition(I think?):
Quote:
Description
This is a Trojan detection. Unlike viruses, Trojans do not self-replicate. They are spread manually, often under the premise that they are beneficial or wanted. The most common installation methods involve system or security exploitation, and unsuspecting users manually executing unknown programs. Distribution channels include email, malicious or hacked web pages, Internet Relay Chat (IRC), peer-to-peer networks, etc.
Aliases -
Backdoor:Win32/Daserf.A - Microsoft
Sus/Behav-1010 - Sophos
Indication of Infection
These symptoms of this detection are the files, registry, and network communication referenced in the characteristics section.
Methods of Infection
Trojans do not self-replicate. They are spread manually, often under the premise that the executable is something beneficial. Distribution channels include IRC, peer-to-peer networks, newsgroup postings, e-mail, etc.
|
Source:
|
|
|
06/24/2016, 07:44
|
#3
|
elite*gold: 0
Join Date: Nov 2007
Posts: 707
Received Thanks: 83
|
yeah true i missed that and 3 more importent files i will upload after work
thanks for scans
|
|
|
06/24/2016, 10:32
|
#4
|
elite*gold: 37
Join Date: Jan 2009
Posts: 2,545
Received Thanks: 1,036
|
Good, yer' ol' Yahoo & Firefox ♥
I'm not sure it'll work, though. I'll try to do so, tho.
|
|
|
06/24/2016, 12:18
|
#5
|
elite*gold: 0
Join Date: Dec 2013
Posts: 402
Received Thanks: 506
|
Has anyone checked the headers on these to make sure they're not crypted? Illl run some analysis on them later this evening.
|
|
|
06/24/2016, 15:11
|
#6
|
elite*gold: 37
Join Date: Jan 2009
Posts: 2,545
Received Thanks: 1,036
|
Nah, I'm just trying to config my software correctly, to make it work (somehow) @RF.
|
|
|
06/24/2016, 23:46
|
#7
|
elite*gold: 393
Join Date: Feb 2012
Posts: 342
Received Thanks: 152
|
Quote:
Originally Posted by xtJamie
Has anyone checked the headers on these to make sure they're not crypted? Illl run some analysis on them later this evening.
|
So did you have time to analyze it? Worth setting up a sandbox to download it?
|
|
|
06/25/2016, 05:49
|
#8
|
elite*gold: 0
Join Date: Jul 2010
Posts: 335
Received Thanks: 140
|
Any of these working on Awaken?
|
|
|
06/25/2016, 10:35
|
#9
|
elite*gold: 0
Join Date: Dec 2013
Posts: 402
Received Thanks: 506
|
Quote:
Originally Posted by [Arceus]
So did you have time to analyze it? Worth setting up a sandbox to download it?
|
I haven't yet. It's always worth using a sandbox for any zipped file containing random executables.
Checked the headers, none of them were packed with any malicious packer - all of them were mostly packed with the c# packer. None of them work AFAIK. No hidden processes or memory injections, no malicious ports being created for either UDP/TCP.
They're useless. They're outdated and none of the packet structures will be the same.
|
|
|
06/25/2016, 12:52
|
#10
|
elite*gold: 0
Join Date: Nov 2007
Posts: 707
Received Thanks: 83
|
you do know there is program that you need to run and set them >.<
and like i said they based on dzo files not US!
|
|
|
06/25/2016, 14:02
|
#11
|
elite*gold: 0
Join Date: Dec 2013
Posts: 402
Received Thanks: 506
|
I will take your word for it. They're incredibly old vn hacks regardless.
|
|
|
06/25/2016, 17:25
|
#12
|
elite*gold: 0
Join Date: Jan 2016
Posts: 126
Received Thanks: 7
|
Quote:
Originally Posted by witek1992
|
Where would we be without you?
|
|
|
All times are GMT +1. The time now is 13:00.
|
|