NightfallGT / Mercurial-Grabber

Grab Discord tokens, Chrome passwords and cookies, and more
426 stars 294 forks source link

nice virus #115

Open g0dly2425 opened 1 year ago

g0dly2425 commented 1 year ago

image image

ghost commented 1 year ago

Hi, I have looked into this more. The output from his builder sends stolen data to two webhooks - both yours and his, so you take the effort to distribute the malware that you """created"" and then he takes the data.

Also, I have heard that the code in this repo does not compile under visual studio, and that it is missing files, and then the releases are malicious.

I tried decompiling the builder in dnSpy but it is "processed with fody" and contains weird binaries. Detectiteasy shows it is not obfuscated and is a .net assembly

g0dly2425 commented 1 year ago

I'm not really a coder, so its a virus, right?

0xThug1337 commented 1 year ago

Hi, I have looked into this more. The output from his builder sends stolen data to two webhooks - both yours and his, so you take the effort to distribute the malware that you """created"" and then he takes the data.

Also, I have heard that the code in this repo does not compile under visual studio, and that it is missing files, and then the releases are malicious.

I tried decompiling the builder in dnSpy but it is "processed with fody" and contains weird binaries. Detectiteasy shows it is not obfuscated and is a .net assembly

Hey i just compiled it and it isn't a malware :)

0xThug1337 commented 1 year ago

It does miss some files but with basic knowledge you can bypass it

ThatRandomBeanerBeamer commented 2 months ago

I went through the source code, and everything looks fine, feel free to look though it yourself though as I may have missed something. :)