XWORM V2.1 CRACKED - | UAC * WORM * RunPE * Clipper | Cleaned By ObbedCode

Vendor of: Paypal & Banks Logins + Cookies
Verified Seller
Hero Member
Joined
Aug 19, 2023
Messages
911
Reaction score
36,206
Points
93
For a second I assumed it was the stub dropping in the TEMP dir from the second "builder.exe" file as that was being executed but I assumed if it was not connected to a valid server that would exit the stub, I was reversing it for a TCP Connection and realized it is using a Telegram Channel to send data to , The RAT uses a TCP Connection over a Custom Port , Telegram is not involved. So Come to find out, it was his Stealer he binded.





So you almost got me :< but the weird admin prompt ? , the Fake Error ? , and ofc dropping this in the %temp% folder on Disk for AVs to Scan Un-Obfuscated Code 6/10 I give it



Good Concept ?






Ps , Yes this is the CLEAN version , still run in sandbox tho . Good Practices









Screenshots of Program





Spoiler





====================================================


FEATURES


====================================================












[+] Run File From, URL / Disk / Memory / RunPE


[+] Blank Screen, Disable Win Updates, Run Shell , Invoke BSOD


[+] .NET 3.5 Installer


[+] UAC / Firewall / Taskmgr / RegEdit , Disabler + Enabler


[+] Shell / Webcam / MIC / Monitor / System Sound/ File Manager, Control


[+] TCP Connections Monitor


[+] Clipboard Manager + Password Manager


[+] Installed Programs Manager


[+] Activate Windows Option


[+] DDoS


[+] VB.NET Compiler / Google Maps


[+] Fun Functions


[+] Keylogger / Chat / File Searcher


[+] USB Spread + Bot Killer


[+] Prevent Sleep / Auto Sleep Disabler / Change Wallpaper / Message Box Popup / Delete Restore Points


[+] UAC Bypass


[+] Coin Clipper / Swapper


[+] Ransomware


[+] Ngrok Installer


[+] Tinynuke HVNC


[+] VNC Viewer


[+] Windows Defender , Disabler / Remover / Exclusion


[+] Startup, Registry / Folder / SCHTASKS aka Scheduled Tasks


[+] Worm


[+] Anti Analysis





Thats most of it






====================================================


DOWNLOAD


====================================================






Password:


NULLED.TO





AnonFile



To see this hidden content, you must reply and react with one of the following reactions : Like






Zippyshare




To see this hidden content, you must reply and react with one of the following reactions : Like





Upload.ee




To see this hidden content, you must reply and react with one of the following reactions : Like





Sendspace



To see this hidden content, you must reply and react with one of the following reactions : Like






MirrorAce




To see this hidden content, you must reply and react with one of the following reactions : Like








Analysis of Infected File:





VT:


XWorm-RAT-V2.1-builder.exe => https://www.virustot...aefe66807eac93a


win-xworm-builder => https://www.virustot...e2307b80a560319





~ Telegram Stealer Dropped in %temp% Dir under "win-xworm-builder.exe"


~ Has Basic Anti Analysis as that was part why Id assume it was cracking so it was just the stub, either way easy to Bypass "CALL => NOP"



~ Telegram Chat Channel ID 2024893777


~ Steals From





Spoiler





(http://imgur.com/a%2FbqXIFS6)

(http://imgur.com/a%2FlxFgPm4)
 
Reactions: xmk009, badowe8340, LC4RAT and 4 others
Advanced Member
Joined
Oct 7, 2023
Messages
287
Reaction score
23
Points
18
thanks
 
Joined
Dec 2, 2023
Messages
11
Reaction score
0
Points
1
CC
 
Joined
May 1, 2024
Messages
7
Reaction score
0
Points
1
Thanks brother
 
Member
Joined
May 5, 2024
Messages
16
Reaction score
0
Points
1
thanks
 
Member
Joined
Feb 27, 2024
Messages
40
Reaction score
2
Points
8
 

User Who Replied This Thread (Total Members: 6) Show all

  • Tags
    builder disabler manager telegram xworm