Jump to content
YOUR-AD-HERE
HOSTING
TOOLS
992Proxy

Locked Cobian RAT v1.0.40.7


J0k3rj0k3r

Recommended Posts

  • 8 months later...
  • 2 months later...

It is Backdoored check it >>

 

 

 

The client is connecting to pastebin.com at port 80 to import a file as bytes. Using Wireshark I was able to sniff the HTTP request.

 

 

This is the hidden content, please

 

First request:

This is the hidden content, please

Second request:

This is the hidden content, please

 

The first one is junk file, but it's also editable as pastbin.com allow the user to modify his page without changing the URL.

the second request contains encrypted data

 

Before decrypt:

[Y2hlY2tmb3J1cGRhdGUuc3l0ZXMubmV0OjU2MzUxLG1pY3JvY2NpdC5kZG5zLm5ldDo1NjM1MSw=]

 

After decrypt:

[checkforupdate.sytes.net:56351,microccit.ddns.net:56351,]

 

After tracking the hosts, it appears to be an Indonesian hacker was behind all this backdooring. The last IP to establish a valid connection to microccit.ddns.net was 223.255.227.17

 

This method isn't new, let's see a similar code to understand how it's working.

 

 

This is the hidden content, please

 

 

 

 

https://source4hacker.blogspot.ch/20...ackdoored.html

Edited by Kan3
Link to comment
Share on other sites

It is Backdoored check it >>

 

 

 

The client is connecting to pastebin.com at port 80 to import a file as bytes. Using Wireshark I was able to sniff the HTTP request.

 

 

This is the hidden content, please

 

First request:

This is the hidden content, please

Second request:

This is the hidden content, please

 

The first one is junk file, but it's also editable as pastbin.com allow the user to modify his page without changing the URL.

the second request contains encrypted data

 

Before decrypt:

[Y2hlY2tmb3J1cGRhdGUuc3l0ZXMubmV0OjU2MzUxLG1pY3JvY2NpdC5kZG5zLm5ldDo1NjM1MSw=]

 

After decrypt:

[checkforupdate.sytes.net:56351,microccit.ddns.net:56351,]

 

After tracking the hosts, it appears to be an Indonesian hacker was behind all this backdooring. The last IP to establish a valid connection to microccit.ddns.net was 223.255.227.17

 

This method isn't new, let's see a similar code to understand how it's working.

 

 

This is the hidden content, please

 

 

 

 

https://source4hacker.blogspot.ch/20...ackdoored.html

 

Yeah, its true there is a backdoored.. but for solution you can just block pastebin.com or by firewall or by host file ;)

Link to comment
Share on other sites

  • Kan3 locked this topic
On 3/21/2018 at 4:59 PM, m3tal said:

 

Yeah, its true there is a backdoored.. but for solution you can just block pastebin.com or by firewall or by host file ;)

Or use a Non backdoored  rat  -_-

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.