Jump to content
View in the app

A better way to browse. Learn more.

Tuts 4 You

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

Featured Replies

Posted

Looks like I was infected by some virus, no idea where I got it.
It's .NET
 
You have to run it like this in order to run:
adobe_flash_player.exe /00000017

 

Anyone can decompile this and find out what's doing? Looks like a custom obfuscator was used. De4Dot is cleaning it up but strings and other data is still encrypted.

 

 

Thanks!

adobe_flash_player.rar

Edited by bomblader

"Malware" lol


 


0tJj9E1.png


 


XDNG32z.png


 


Whatever protection was used, this looks like some seriously skidded shit


Pretty boring and ordinary malware, calls home, download commands, does some downloads (pay-per-click scam?), uploads stuff and other boring crap. 


 


Deobfuscate only inside VMware using this command-line:



de4dot adobe_flash_player.exe --strtyp delegate --strtok 06000195
  • Author

I think it's some kind of shitty thing that visits webpages.


 


The problem is, I have absolutely no idea where I got this. I always run executables sandboxed and it also added itself to HKLM startup (I ran the infected .exe as administrator, wtf)


 


Also, what decompiler you are using? (Sweden)


Edited by bomblader

Only you can figure out where it came from, as that information is only present on your computer. I would start with information from NTFS LastWriteTime and registry key LastWriteTime, then move on to Prefetch folder, firewall logs, browser cache and other forensic information. :) But if you deleted it already, well... tough luck!


Create an account or sign in to comment

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.