hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

White Scorpion
hi all,


i was looking for a crack for a certain program, this was not to use a program illegally, but to learn how it works (since i was not able to crack it myself)..

by this search i came across http://resource.crack-cd.com , when you press any of those links you will receive a program called assassin-254.exe. as curious as i am i ran the program. after 1 minute the program started to connect to www.dalexcars.com at port 80. When it is connected it downloads the following files to your C:\DOCUME~1\<current user>\LOCALS~1\Temp\ directory:

pony41.exe
intercooler18467.exe

if all works fine, it closes the connection, starts the above programs and terminates itself.

i have found that http://resource.crack-cd.com has the following link in their pages: http://china.dalexcars.com/assassin.html , this is where they get the program from.

unfortunately both of the downloaded programs were not downloaded correctly, they both have a size of 0 kb, otherwise i would have had more info on what these programs do.

i have done a whois on both sites and i have found that they both have the
same registration service, although they both have a different administrative contact.

i will send an email with this information to the address given for abuse, but what i would like to know, how can i make this program be known at AV programs?


if anyone would like to know more about this program, then follow this link, this is the link to the zip-file i have created which contains the program itself, both downloaded programs, a textfile with the explaination of what the program does, and the disassembled file from the original program.

i have made this announcement so that people who read this can take care of themselves and NOT run this program, since it can't be trusted!


regards
da_cash
My KAV Reports it as TrojanDownloader.WIN32.INService.i...




Partizaan
undetected by norton corp. server def 12/11/02 rev. 9
White Scorpion
well, the story gets even more weird, the abuse address is not real, at least it doesn't work, i get an error "receiver doesn't exist".


btw i am using AVG 6.0 free edition, fully updated.
KoNh
QUOTE(lepricaun @ Nov 14 2004, 08:53 PM)
btw i am using AVG 6.0 free edition, fully updated.
*



So you could get a true AV like "Kaspersky personal edition" (no am not working for'em just like it)
White Scorpion
QUOTE
So you could get a true AV like "Kaspersky personal edition" (no am not working for'em just like it)
well, to be honest, i only use AV software on the system that i download such things, normally i hate AV software and i would not use it if not absolutely necessary biggrin.gif
Eyeless
Well back to his question, just send a copy of it to your AV's company email telling them you found something undetected. Walla in the next few days, it will detect it...
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.