Post
Topic
Board Gambling
Re: Dyborg - FREE Primedice Bot/AutoBetter by DaNksta
by
Nixsy
on 27/01/2015, 21:02:23 UTC
[edit] The site http://www.dyborg.pw/ does not belong to the OP, this appears as someone has cloned his site and software adding a virus/trojan in the process.

I have downloaded https://www.dropbox.com/s/8z1qwjxonj1tqp0/Dyborg1.0%20PRERELEASE.zip?dl=1
from the clone http://www.dyborg.pw/

Code:
Dyborg1.0 PRERELEASE.zip
SHA256: 6a3362adc940378a28fef8982ee131f5d822972e4f572aeca9f555771a1cad94

Inside this archive there is a trojan virus.

Namely
Code:
Updater.exe
SHA256 0d5ac2ddf9d690a11e0a89df8482550cb799fe9dc080f92e9e265fdb52157873
https://malwr.com/analysis/NDZkOTI4ZmRhYzUxNGU1NjhhMDg4N2U4YjVmYmM1ODU/


Some of the hidden features of the file include

Code:
Creates a windows hook that monitors keyboard input(keylogger)
installs itself for autorun at windows startup.

Now I understand you will try to pull the wool over members eyes saying false positive ect, but a false positive would not create a know mutex for a known remote access trojan. it would also not try to connect to a no-ip address that resolves to the same ip as this malware:

https://malwr.com/analysis/MjAxNmU2ZDE5ZjUzNDhhMjljYTM0YjE3NDNhMjc3YWY/

which was found in a fake primedice hash cracker that has been spammed a lot recently in just-dice chat.

I would recommend that anyone who has used the software from http://www.dyborg.pw/ run a full scan with a reputable antivirus software.