• XSS.stack #1 – первый литературный журнал от юзеров форума

Mars Stealer_V8 Panel + Builder Cracked

Пожалуйста, обратите внимание, что пользователь заблокирован
Может кто нибудь перезалить?
not sure it works, tried it and didn't hit panel
 
be careful, cracked malware got bitcoin clippers
I'm tryna see if it got backdoors tho

Feel free to drop any proof containing a clipper !!!
 
Feel free to drop any proof containing a clipper !!!
I don't have time to screen record my PC, host the video and post it on there...
People can pretty easily figure it out:

They just need to try to copy a random btc address to clipboard, and when they'll paste it on a notepad another btc address will display....
 
Пожалуйста, обратите внимание, что пользователь заблокирован
Подскажите. Может быть такое что этот кряк пересылает ещё кому-то добытые логи и как это возможно проверить?
 
Подскажите. Может быть такое что этот кряк пересылает ещё кому-то добытые логи и как это возможно проверить?
а логи стучат на панель?
я ставил, проверял, логов нету
правда функция автоудаления билда через панель, работала нормально
 
а логи стучат на панель?
я ставил, проверял, логов нету
правда функция автоудаления билда через панель, работала нормально
yes, it works. In panel and telegram too
 
I don't have time to screen record my PC, host the video and post it on there...
People can pretty easily figure it out:

They just need to try to copy a random btc address to clipboard, and when they'll paste it on a notepad another btc address will display....
From which file do you think this comes from? I have been trying to replicate but with no luck.
 
Пожалуйста, обратите внимание, что пользователь заблокирован
I have just tried to install it right now, and it seems like the panel there is no way is going to load! anyone might help checking for a couple of minute here? Thanks in advance.
chat me up , i help you
 
I have just tried to install it right now, and it seems like the panel there is no way is going to load! anyone might help checking for a couple of minute here? Thanks in advance.
If you can't see the "login.php" page then look within the PHP error.log file, mostly the error comes from the file `db.php`.
I was able to setup the web panel + build an exe and can confirm it does work.

However, I haven't tested the telegram notifications and I'm still wondering if the data exfiltration only comes into the set webpanel or gets sent also to some turkish nigger.
 
If you can't see the "login.php" page then look within the PHP error.log file, mostly the error comes from the file `db.php`.
I was able to setup the web panel + build an exe and can confirm it does work.

However, I haven't tested the telegram notifications and I'm still wondering if the data exfiltration only comes into the set webpanel or gets sent also to some turkish nigger.
telegram notifications didnt work for me.
Maybe the logs are sent to the person who cracked to software, but I just don't know how to verify this
 
telegram notifications didnt work for me.
Maybe the logs are sent to the person who cracked to software, but I just don't know how to verify this

1. Maybe you did ad config
2. Telegram Notification only send direct download link
3. Check your log in "Logs Folder" using FileZilla if you don't see them in panel view
 
Maybe the logs are sent to the person who cracked to software, but I just don't know how to verify this
Can't really tell... hopefully someone more skilled than me will check this so we can be sure there's no shady things going on.
Reversig a sample build / checking the webserver files should be enough but who knows!
 
If you can't see the "login.php" page then look within the PHP error.log file, mostly the error comes from the file `db.php`.
I was able to setup the web panel + build an exe and can confirm it does work.

However, I haven't tested the telegram notifications and I'm still wondering if the data exfiltration only comes into the set webpanel or gets sent also to some turkish nigger.
I have succussed to install the panel. All is good so far, only when i build the exe and execute it on the VM it does not shows up ? are you on a VM or your desktop ? maybe the payload is anti VM? can you please confirm ?

using as exactly as being said here before :

  1. In host, as mentioned above, enter the domain of the site where your panel is installed. Example: my.site.com or site.com
  2. In gate, enter the path to the gate, relative to the domain. If the gate is located on site.com/1.php then you need to enter /1.php in "Gate". If it lies on site.com/1/2/3/Gate.php then enter /1/2/3/Gate.php and so on.
  3. In "Code encryption pass", "Host encryption pass" and "Gate encryption pass" enter random characters UNTIL THE LIMIT
A :
so instead of the domain name, I have an IP
Example : 64.67.35.67

B: i have the gate on this following directory.
gate : 64.67.35.67/gate.php

3 : random, example :

Code encryption pass : 6CSwLt8X%aJ*cBjS^=Gyk7t6CSwLt8X%

Host encryption pass : 3g%^#bE7XNz_NW!5RJrbJYQ3g%^#bE7X

Gate encryption pass : &DG5f=n^A$Fj#2NpmJ+48&V&DG5f=n^A


am i doing something wrong ?

Thank you
 


Напишите ответ...
  • Вставить:
Прикрепить файлы
Верх