Register for your free account! | Forgot your password?

Go Back   elitepvpers > MMORPGs > Rappelz > Rappelz Private Server
You last visited: Today at 12:00

  • Please register to post and access all features, it's quick, easy and FREE!

Advertisement



[Warning] 9.6 Source based files backdoor

Discussion on [Warning] 9.6 Source based files backdoor within the Rappelz Private Server forum part of the Rappelz category.

Reply
 
Old   #1

 
Musta²'s Avatar
 
elite*gold: 1
Join Date: May 2011
Posts: 542
Received Thanks: 424
[Warning] 9.6 Source based files backdoor

Hello all,

I've been monitoring the releases made lately, especially the one made by MohcenMaher [] closely.

I've made an analysis of it on a "disposable" server, and the results are ugly. Very ugly.



As you can see from the video, the CaptainHerlockServer.exe file is a trojan horse, for two files (1. A clean captainherlockserver.exe, 2. a file that is downloaded from the internet via a VB Script, from a file on a website on a file /captainhook.txt)

Once the said CaptainHook.exe is downloaded, it is executed and it doesn't need a rocket scientist to determine what it does then.

For anyone asking for other proofs, I'll leave links to virustotal scans made by Mohcen prior to him settling on the released on, they all connect to the same domain name and to a dynamic DNS (supposedly for the RAT connection?).

You can check the communicating files from this scan, in addition to its registry information, and determine who's involved






It is very sad how low people with talent and good skills can go, that goes to say that you should always speculate whenever download things from the internet.

Finally, I'd advise anyone who downloaded it to delete the files immediately, and clean their temp directory, in addition to performing a system-wide scan to remove any potential persistent files.

- Musta.
Musta² is offline  
Thanks
9 Users
Old 04/12/2020, 18:02   #2
 
ilyaslord36's Avatar
 
elite*gold: 0
Join Date: Oct 2012
Posts: 297
Received Thanks: 12
We want clean files server 9.6 and not infected files with viruses. We are tired of waiting you ?
ilyaslord36 is offline  
Old 04/12/2020, 18:07   #3

 
Musta²'s Avatar
 
elite*gold: 1
Join Date: May 2011
Posts: 542
Received Thanks: 424
Quote:
Originally Posted by ilyaslord36 View Post
We want clean files server 9.6 and not infected files with viruses. We are tired of waiting you ?

I don't have them, yet.
Musta² is offline  
Old 04/12/2020, 18:13   #4


 
アルカード's Avatar
 
elite*gold: 50
Join Date: Mar 2012
Posts: 1,036
Received Thanks: 428
Quote:
Originally Posted by MuStA2222 View Post

I don't have them, yet.
sad thing is that even on facebook,people are saying that first released files here are clean that don't have any backdoor...
アルカード is offline  
Old 04/12/2020, 19:59   #5

 
Musta²'s Avatar
 
elite*gold: 1
Join Date: May 2011
Posts: 542
Received Thanks: 424
Quote:
Originally Posted by アルカード View Post
sad thing is that even on facebook,people are saying that first released files here are clean that don't have any backdoor...
I tested it and I can tell there isn't suspicious with it aside from a hardcoded IP (54.64.27.223) that attempts to connect on port 5000 once the server is finished loading.

That said, I cannot confirm that the files are 100% clean and that there might not be in-game bugs and/or backdoors hardcoded in the server itself.

Here's a comparision of the same part between a 9.5.2 official server, and DoseMove's release.



Edit:
As far as the IP is concerned, I'd assume people would be safe just nulling the IP using a hex editor.
Musta² is offline  
Old 04/12/2020, 21:19   #6
 
SilentWisdom's Avatar
 
elite*gold: 0
Join Date: Jul 2015
Posts: 479
Received Thanks: 639
Talking

Quote:
Originally Posted by MuStA2222 View Post
I tested it and I can tell there isn't suspicious with it aside from a hardcoded IP (54.64.27.223) that attempts to connect on port 5000 once the server is finished loading.

That said, I cannot confirm that the files are 100% clean and that there might not be in-game bugs and/or backdoors hardcoded in the server itself.

Here's a comparision of the same part between a 9.5.2 official server, and DoseMove's release.



Edit:
As far as the IP is concerned, I'd assume people would be safe just nulling the IP using a hex editor.
This would not be an issue if lapdog @ would release source he built with, but since is Revolution worshipper all knows this will not happen.
SilentWisdom is offline  
Old 04/12/2020, 21:23   #7

 
Musta²'s Avatar
 
elite*gold: 1
Join Date: May 2011
Posts: 542
Received Thanks: 424
Quote:
Originally Posted by SilentWisdom View Post
This would not be an issue if lapdog @ would release source he built with, but since is Revolution worshipper all knows this will not happen.
a pdb file would have solved it at least, that's what I'm trying to point out here.
You can never trust a file that's missing pdb files for no obvious reason, especially if you've got a history of trying to RAT random people.
Musta² is offline  
Old 04/12/2020, 21:30   #8
 
lilnani's Avatar
 
elite*gold: 0
Join Date: Feb 2011
Posts: 597
Received Thanks: 174
Quote:
Originally Posted by SilentWisdom View Post
This would not be an issue if lapdog @ would release source he built with, but since is Revolution worshipper all knows this will not happen.
look who's talking the antichrist itself !! i'm not defending mohcen but it's not the others problems if all what you know is stealing the others codes imma sure that all what you desire right now is to steal some codes from mohcen


----
@

I'm not defending the ratted files too here but just for the public knowledge ..

If I'm correct you released a files before? no i don't remember which version .. but maybe it would be a perfect idea if you downloaded them and searched for the coordinator ip in the GS you released i'm 90% sure it's the same IP.

or just take a look at the sourcecode ..
lilnani is offline  
Old 04/12/2020, 21:30   #9
 
SilentWisdom's Avatar
 
elite*gold: 0
Join Date: Jul 2015
Posts: 479
Received Thanks: 639
Quote:
Originally Posted by MuStA2222 View Post
a pdb file would have solved it at least, that's what I'm trying to point out here.
You can never trust a file that's missing pdb files for no obvious reason, especially if you've got a history of trying to RAT random people.
They will not release pdb because this gives people too much low level information on the gs/sframe they are releasing. It would also tell us just how true a 9.6 the files are, allow us to see every edit made to the original source files and it would also clear any chance of hidden code.

They do not refuse to release it for the hidden code I think, only for the ability to know things you all don't know. So they can remain superior and talk down to you, be your saviors. This is all RevolutionTeam wants, to be your hero with lies and deceit.
SilentWisdom is offline  
Old 04/12/2020, 21:35   #10
 
Anothers's Avatar
 
elite*gold: 0
Join Date: Oct 2013
Posts: 128
Received Thanks: 108
Coordinator Server connection Same IP

I just shared it to show.
Anothers is offline  
Thanks
2 Users
Old 04/14/2020, 18:50   #11

 
sadda711's Avatar
 
elite*gold: 4
Join Date: Jan 2013
Posts: 2
Received Thanks: 0
Thanks @




















sadda711 is offline  
Old 03/07/2021, 02:38   #12
 
bubsui's Avatar
 
elite*gold: 0
Join Date: Nov 2020
Posts: 14
Received Thanks: 2
hi Musta² iam using the tool SlickEdit Pro 2020 but when i nulled it then i cant execute the gs anymore what iam doing wrong its like on the pic can you pls help me make the files clean from hidden ips and all else.

here a pic so you can see it

bubsui is offline  
Reply


Similar Threads Similar Threads
[Selling] Source FLYFF V19 CLEAN NO BACKDOOR + GAMEGUARD (client)
06/20/2015 - Flyff Trading - 0 Replies
Hello pvpers i sell a source flyff v19 clean and no backdoor and GAMEGUARD protection CLIENT NOT RELEASE ! Price: - Gameguard : 40€ - source/ressource/client + gameguard : 100€ skype: yoshiiak
[Source] New Data Folder & Remove Backdoor
03/13/2014 - 4Story - 24 Replies
Hey, kommen wir zuerst dazu wie wir den neuen Data Folder benutzen können und so die neuen Maps/Objs(außer die Interface dateien) usw. Ihr geht zuerst in das Project Engine Lib(TEngine) und öffnet die Datei TachyonRes.cpp. Dort geht ihr in die LoadObj ( die mit 4 Parametern ) und sucht dort nach file.Read( &pTEX->m_bZWrite, sizeof(BYTE)); file.Read( &pTEX->m_b2side, sizeof(BYTE)); file.Read( &pTEX->m_bUseDirLight, sizeof(BOOL));
Blessed Source backdoor
08/04/2013 - Flyff Private Server - 2 Replies
#Closed



All times are GMT +1. The time now is 12:01.


Powered by vBulletin®
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
SEO by vBSEO ©2011, Crawlability, Inc.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Support | Contact Us | FAQ | Advertising | Privacy Policy | Terms of Service | Abuse
Copyright ©2025 elitepvpers All Rights Reserved.