[Release] invincible , Avatar MagOpt Exploit

04/08/2017 05:46 giohyio#1
---removed---
04/08/2017 06:39 B1Q#2
???
04/08/2017 07:18 Damitsu#3
Does this work in any server?
04/08/2017 08:22 giohyio#4
yes Server accepts and servers do not accept tri im in server illusion sro work and im make Avatar9 luck
04/08/2017 08:35 3d1#5
My antivirus says thats a threat, i will consider that it IS!
04/08/2017 09:00 giohyio#6
My Virtuous Brother All illegal programs by VIRS to MBOT
04/08/2017 11:10 elmagico321#7
waow thanx man very fresh new exploit which didn't released here before like ever
04/08/2017 14:03 pushipu#8
To avoid kids (if this even work) just use this (if you don't have filter)
[Only registered and activated users can see links. Click Here To Register...]
04/08/2017 22:27 Jimmy*#9
that was released before and almost not even working
04/09/2017 02:16 KingDollar#10
serious?
is this not even related to april fool?
04/09/2017 03:21 devtekve#11
I can have confirmation that this is a malicius file (I guess it is metasploit but it is too early to tell) inside of this "proxy" and it writes two files to %AppData% : "JKSYSpkQbg.exe" and "FPewwxQAhM.exe" I will keep uyou posted, this is a threat.

Here is the source code of the program:

[Only registered and activated users can see links. Click Here To Register...]

The resources are basically Base64 string of the program, when you decrypt the base64, you get the exe basically, and there are 2 that are viruses

First file scan AxZvCDtRsA.exe which is the "proxy" but also contains malicious code: [Only registered and activated users can see links. Click Here To Register...]

The second file FPewwxQAhM.exe which seems to be a meterpreter shell: [Only registered and activated users can see links. Click Here To Register...]
04/09/2017 19:53 PortalDark#12
Thanks for the report

First, no idea how people keep posting here without a virus scan

Second, im taking a better look at home

#closed
#links removed

Sent from my SM-G930F using Tapatalk