<?xml version="1.0"?>
<rss version="2.0">
   <channel>
      <title>Malware Anaylsis by SoundDrout</title>
      <link>https://padlet.com/bluxtrv/malwareanalysis</link>
      <description>We are ded serious about this...TROJANS_NEVER_JOKE_RESPECT_THE_TROJANS</description>
      <language>en-us</language>
      <pubDate>2021-11-21 13:00:01 UTC</pubDate>
      <lastBuildDate>2025-11-23 12:42:20 UTC</lastBuildDate>
      <webMaster>hello@padlet.com</webMaster>
      <image>
         <url>https://media1.giphy.com/media/8qFUbJKXO7XiHOzy7h/giphy.gif</url>
      </image>
      <item>
         <title>Malware Anaylsis</title>
         <author>bluxtrv</author>
         <link>https://padlet.com/bluxtrv/malwareanalysis/wish/1904396516</link>
         <description><![CDATA[<div>Hi and welcome to malware anaylsis. We are anaylzing malware for hobbies. Major Sponsers: @Hyperistic Blast, @Creepster, @Sonic.exe<br>Visit: <a href="http://pccreepermalware.tilda.ws">http://pccreepermalware.tilda.ws</a></div>]]></description>
         <enclosure url="" />
         <pubDate>2021-11-21 13:24:22 UTC</pubDate>
         <guid>https://padlet.com/bluxtrv/malwareanalysis/wish/1904396516</guid>
      </item>
      <item>
         <title>1. Scorpion Virus</title>
         <author>bluxtrv</author>
         <link>https://padlet.com/bluxtrv/malwareanalysis/wish/1904403635</link>
         <description><![CDATA[<div><strong>Name: </strong>Scorpion virus<br>	<strong>Creator:</strong> Arab TEC<br>	<strong>Basic Facts:</strong> Scorpion is a dangerous <a href="https://malwiki.org/index.php?title=Ransomware">Ransomware</a> that affects <a href="https://malwiki.org/index.php?title=Microsoft_Windows">Microsoft Windows</a> systems. This ransomware was sent to the FMV series of the popular <a href="https://malwiki.org/index.php?title=Malware">malware</a> YouTuber <a href="https://www.youtube.com/channel/UCviSYAcwdnDX1UoRzAHYgNg">Siam Alam</a>.&nbsp;<br><br></div><div>	<strong>Payload:</strong> After the virus is executed it cuts to a screen saying: "Welcome to Scorpion Virus" . The screen then says: "Enter the code to unlock virus" The user will then have 3 tries to enter the code correctly. If the user doesn't enter the code correctly after three tries the virus locks the computer on the virus screen.<br><br></div><div>	<strong>Version 2:</strong> After the <a href="https://malwiki.org/index.php?title=Virus">virus</a> is executed it will restart the computer. After the user restarts, the computer starts normally. But, when the user attempts to log on, the screen will be locked and there will be a message saying:</div><div>"Welcome to Scorpion Virus"<br><br></div><div>Then the user will need to wait for a loading red bar, after that, there would be a screen with a scorpion saying:</div><div>"Scorpion is here"<br><br></div><div>Then a message saying:</div><div>'Oops! Your computer has been locked! and all your files have been encrypted! you cannot do anything, just cry!'.</div><div>Then the user will have 30 seconds to unlock the computer with a VIP Code to unlock.<br><br></div><div>If the user tries to open task manager via ctr+alt+del they will get a message saying:</div><div>"Don't try that again."<br><br></div><div><strong>Version 3:</strong> Version 3 completely changed Scorpion virus instead of resetting computer upon activation the screen cuts to a cinematic screen. First it cuts to a broken/updated T.V. screen then it cuts to the scorpion logo going down then it finally stops and is greeted with:</div><div>Welcome to Scorpion Virus<br><br></div><div>A few seconds later under that it says Your computer is died</div><div>If the user restarts the computer it cuts to a black screen despite the fact that there is nothing wrong with the registry. There are theories that it wipes out explorer.exe entirely.<br><br></div><div>	<strong>Version 3.1:</strong> Fixed grammar issues, Your computer is died -&gt; Your computer is dead</div><div><br><br></div>]]></description>
         <enclosure url="https://padlet-uploads.storage.googleapis.com/1405250442/cc96e2063f933c15c0077553008d8f5d/scorpion.jpg" />
         <pubDate>2021-11-21 13:30:58 UTC</pubDate>
         <guid>https://padlet.com/bluxtrv/malwareanalysis/wish/1904403635</guid>
      </item>
      <item>
         <title>2. 000.exe</title>
         <author>merch</author>
         <link>https://padlet.com/bluxtrv/malwareanalysis/wish/1937023701</link>
         <description><![CDATA[<div>Name: 000 executable<br>Creator: Flytech Videos<br>Basic Facts:&nbsp;<strong><br>000.exe</strong> is a <a href="https://malwiki.org/index.php?title=Virus">virus</a> that infects <a href="https://malwiki.org/index.php?title=Microsoft_Windows">Microsoft Windows</a> running Windows NT based kernels.<br><br>The website which was used to download the first version showed a blue hyperlink with green background.</div><div><br>The YouTuber <a href="https://www.youtube.com/user/TheLD3H">FlyTech Videos</a> created the first version of this virus that showed a website that automatically tried to download 000.exe, the website contains a hyperlink with a green background. After development, he made a video about it on his Windows 8 Virtual Machine and explaining its <a href="https://malwiki.org/index.php?title=Payload">payloads.<br></a><br></div><div>In mid-2016, FlyTech Videos released a video on its development stages and given a download link to download the virus. Shortly after, a YouTube user, <a href="https://www.youtube.com/user/Kikosvids1ALT">Gigabyte_Forever</a>, demonstrated on how to disinfect a Windows <a href="https://malwiki.org/index.php?title=Operating_system">operating system</a> that was affected by this type of virus.<br><br>Payload: <br>When executed, a <a href="https://malwiki.org/index.php?title=User_Account_Control">User Account Control</a> dialogue box appears (only in Windows Vista, onward) warning the user if they want to execute the program.<br><br></div><div><br>This virus uses a few <a href="https://malwiki.org/index.php?title=Payload">payloads</a> from other <a href="https://malwiki.org/index.php?title=Malware">malware</a> pieces such as <a href="https://malwiki.org/index.php?title=Maldal">Maldal</a>. When fully executed, explorer.exe gets terminated, the virus will also attempt to remove the contents inside the WindowsApps folder which contains installed Windows Universal Apps (only in Windows 8 and 10). The video clip also loops in the background. The video showcased a picture of a scary road changing color from orange, to green, to black and white, and to intense black and white.<br><br></div><div><br>During video playback, the virus disables Task Manager, change the user's Windows account name to "UR NEXT", change the default notepad icon to a custom .ico file, and reboot the user's computer once it is finished with its first payload.<br><br></div><div><br>The second payload occurs when the computer is restarted. The user will be greeted with many changes made on the user's computer which includes, the desktop wallpaper is changed, and shows an accent color black, the user's desktop is filled with "UR NEXT" Notepad files on the desktop (as it used Maldal's payloads). The default Notepad icon is changed to a red square with "UR" and "NEXT" with the former stacked on top of the latter. Opening one "UR NEXT" file, the user will see seemingly infinite lines of the words "UR NEXT".<br><br></div><div>The dialog box shown in Windows 8.1 during its second payload.</div><div><br>Once Windows is loaded, there will be a dialogue box that contains the message "run away", followed by a "run away" button. However, each second a new dialogue box with the same message appears nonstop. Clicking on the run away button closes the message.<br><br></div><div><br>If a user opens the "OPENME" (repeated name) WordPad file, the user will see the text from the file:<br><br></div><pre>YOU ARE THE NEXT,
I CAN SEE YOU


NOW ITS TOO LATE
I GOT YOU.......

YOU HAVE BEEN
WARNED

DONT LOOK BEHIND YOU
<br></pre><div><br>The name of the WordPad file is named "OPENME" (repeated name) to persuade the user to open it. Also, the file's message is that "a serial killer is behind you to stab you, that is why don't look behind you." There have been no reports of serial killers linked to this virus; this is likely just intended to frighten those with infected devices.<br><br>Removal: <strong><br>Windows 10 and Windows 8</strong></div><div><br>While the never-ending pop-ups happen, right-click on the Start button and click on "Command Prompt (Admin)". Type in the following command: <em>taskkill /f /im conhost.exe</em>. The command helps to stop the never-ending pop-ups, but not close them. After that, the Command Prompt should close. After it closed, reopen it. And then type in the following command: <em>taskkill /f /im runaway.exe</em>. The command helps to close all the pop-ups. Do not close the command prompt window.<br><br></div><div><br>From the command prompt window, type in the command: <em>cd C:/users/[the user's account name]/Desktop</em> (the user's account name can be found on C:/Users and the name of the folder with a padlock is the user's account name). And then type in: <em>del *.* /s /q</em>, but before typing in that command, make backups as the command deletes <strong>everything</strong> on the user's desktop. One way of making backups is creating a new folder on <em>Local Disk (C: or D:)</em> and naming the folder <em>My Important Desktop Files</em>. Select the users most important files on the user's desktop, the user has to press Ctrl+X on the user's keyboard, navigate to the user's <em>My Important Desktop Files</em> folder on <em>Local Disk (C: or D:)</em> and finally press Ctrl+V on the user keyboard. The transfer may take several minutes. Once the transfer is complete the user can use the command.<br><br></div><div><br>After the "UR NEXT" files are deleted in the user's desktop, navigate to the user's <em>My Important Desktop Files</em> folder on <em>Local Disk (C:/D:)</em>, press Ctrl+A on the user's keyboard and then Ctrl+X, go to the user's desktop, and then finally press Ctrl+V. Wait for the transfer to complete.<br><br></div><div><br>And then press Win+R to activate the Run box. Type in <em>%temp%</em> in the Run box and press Enter.<br><br></div><div><br>From the Temp folder, the user should see the window containing some files. From there, the user can see that it has written some files including the video used in the virus.<br><br></div><div><br>The files are:<br><br></div><ul><li>5476d0c4a7a347909c4b8a13078d4390.db</li><li>5476d0c4a7a347909c4b8a13078d4390.db....</li><li>icon.ico</li><li>one.rtf</li><li>miw.exe</li><li>sa.9NBLGGH1ZRPV_0_0010.Public.Install...</li><li>text.txt</li><li>tmpC7C1.tmp</li><li>v.mp4</li><li>wct46AB.tmp</li><li>wct81BC.tmp</li><li>wct554A.tmp</li><li>windl.bat</li><li>Windows10UpgradeVersion.txt</li><li>wmsetup.log</li></ul><div><strong><br>NOTES:<br></strong><br></div><ol><li>"icon.ico" is the "UR NEXT" icon.</li><li>"v.mp4" is the video of the virus.</li><li>"windl.bat" is the virus's code.</li></ol><div><br>Now if the user wants to, the user can delete the files in the folder except for the subfolders. The Temp folder is where all of the temporary files are located.<br><br></div><div><br>Now delete the <em>7DDA.tmp</em> folder.<br><br></div><div><br>And then create a text document. And then copy and paste the source code:<br><br></div><pre>Windows Registry Editor Version 5.00
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=-
<br></pre><div><br>And then save the document as a .reg file. Open the .reg file.<br><br></div><div><br>Right-click on the user's desktop and click on Personalize. At the Background section, click on <em>Solid color</em> and choose <em>Picture</em>. Choose the first picture, which is the very left picture. And then refresh the user's desktop. Restart the user's computer.<br><br></div><div><br>Open Task Manager and navigate to Startup. Find <em>miw.exe</em> from the process list and click on <em>Open file location</em>. And then the user will see two files from the pop-up window, <em>miw.exe </em>and <em>desktop.ini</em>. Delete the files.<br><br></div><div><br>Search "user" and open User Accounts. From here the user can change the user's username back. the user may also change the user username. Click on <em>Change your account name</em>. And in the <em>New account name</em> box type in the user's original username or the user's new username. and then click Change Name.<br><br></div><div><br>After all of it, restart for the changes to take effect.<br><br></div><div><br>To correct the "UR NEXT" icons on all TXT files, download FilesTypesMan and find TXT and then replace them in the Default Icon field of the TXT format and replace its contents with "C:\Windows\System32\imageres.dll,7".<br><br></div><div><br><br></div>]]></description>
         <enclosure url="https://i.ytimg.com/vi/nFIMy7TR7EY/maxresdefault.jpg" />
         <pubDate>2021-12-09 00:18:45 UTC</pubDate>
         <guid>https://padlet.com/bluxtrv/malwareanalysis/wish/1937023701</guid>
      </item>
      <item>
         <title>4. SparkCript</title>
         <author>creepypastavirus</author>
         <link>https://padlet.com/bluxtrv/malwareanalysis/wish/1937083791</link>
         <description><![CDATA[<div>Name: SparkCript or SparkCrypt<br>Creator: LordCracker<br>Basic Facts:&nbsp;<strong>SpartCript</strong> or <strong>SpartCrypt</strong> is a <a href="https://malwiki.org/index.php?title=Ransomware">ransomware</a> that runs on <a href="https://malwiki.org/index.php?title=Microsoft_Windows">Microsoft Windows</a>. It was discovered by S!Ri. It is part of the <a href="https://malwiki.org/index.php?title=HiddenTear">HiddenTear</a> family. It uses code of <a href="https://malwiki.org/index.php?title=Jigsaw">Jigsaw</a>, Crypto, CyberResearcher, <a href="https://malwiki.org/index.php?title=Executioner_(Ransomware)">Executioner</a>, Resurrection, and Ryzerio. It is aimed at English-speaking users. It uses a ransom note similar to <a href="https://malwiki.org/index.php?title=Phobos">Phobos</a>.<br><br>Payload:&nbsp;<strong><br>Transmission</strong></div><div><br>SpartCript is distributed by hacking through an unprotected RDP configuration, using email <a href="https://malwiki.org/index.php?title=Spam">spam</a> and malicious attachments, deceptive downloads, botnets, exploits, malicious ads, web injects, fake updates, repackaged and infected installers.<br><br><strong><br>Infection</strong></div><div><br>SpartCrypt encrypts victim's data and renames all encrypted files by adding its name, email address of its developers, victim's ID and ".Encrypted" extension to their filenames. For example, it renames "1.jpg" to "1.jpg.SpartCrypt[LordCracker@protonmail.com]-[ID-1E857D00].Encrypted", and so on. Also, it creates a text (.txt) file titled "How_To_Restore_Your_Files.txt" and displays a pop-up window, both of them contain information on how to contact SpartCrypt and other details.<br><br></div><div><br>Cyber criminals who designed SpartCrypt can be contacted via furhlordcracker@protonmail.com and phabos@cock.li email addresses. Victims have to send them the appointed unique ID and can attach up to 5 files. These cyber criminals offer to decrypt them for free.<br><br></div><div><br>After that they will name the price of a decryption, it is stated that it depends on how fast they will be contacted. Either way, they promise to send decryption tool after a payment which must be using Bitcoin cryptocurrency.<br><br></div><div><br>Text presented in SpartCrypt ransomware's pop-up window:<br><br></div><pre>All your files have been encrypted!
All your files have been encrypted due to a security problem with your PC. If you 
want to restore them, write us to the e-mail LordCracker@protonmail.com - 
Phabos@cock.li
Write this ID in the title of your message -
You have to pay for decryption in Bitcoins. The price depends on how fast you write 
to us. After payment we will send you the tool that will decrypt all your files.

Free decryption as guarantee
Before paying you can send us up to 5 files for free decryption. The total size of files 
must be less than 4Mb (non archived), and files should not contain valuable 
information. (databases,backups, large excel sheets, etc.)

How to obtain Bitcoins
The easiest way to buy bitcoins is LocalBitcoins site. You have to register, click 'Buy 
bitcoins', and select the seller by payment method and price.
hxxps://localbitcoins.com/buy_bitcoins
Also you can find other places to buy Bitcoins and beginners guide here:
hxxp://www.coindesk.com/information/how-can-i-buy-bitcoins/

Attention!
Do not rename encrypted files.
Do not try to decrypt your data using third party software, it may cause permanent 
data loss.
Decryption of your files with the help of third parties may cause increased price (they 
add their fee to our) or you can become a victim of a scam.
<br></pre><div><br>Text in How_To_Restore_Your_Files.txt:<br><br></div><pre>SpartCript


[+] All Your Files Have Been Encrypted [+]

[-] Do You Really Want To Restore Your Files?
[-] Write Us To The E-Mail : LordCracker@protonmail.com - Phabos@cock.li
[-] Write Your Unique-ID In The Title Of Your Message.
[+] Unique-ID : -
[-] You Have To Pay For Decryption In Bitcoins.
[-] The Price Depends On How Fast You Write To Us.
[-] After Payment We Will Send You The Decryption Tool
That Will Decrypt All Your Files.

----------

[+] Free Decryption As Guarantee [+]

[+] Before Paying You Can Send Us Up To 5 Files For
Free Decryption, The Total Size Of Files Must Bee Less
Than 10MB, (Non Archived) And Files Should Not Contain
Valuable Information (Databases, Backups, Large Excel
-Sheets, Etc).

----------

[-] The Easiest Way To Buy Bitcoins Is LocalBitcoins
Site : hxxps://localbitcions.com/buy_bitcoins
You Have To Register, Click 'Buy Bitcoins', And Select
The Seller By Payment Method And Price.
[-] Also You Can Find Other Places To Buy Bitcoins And
Beginners Guide Here:
hxxp://coindesk.com/information/how-can-i-buy-bitcoins

----------

[-] Do Not Rename Encrypted Files.
[-] Do Not Try To Decrypt Your Data Using Third Party
-Software, It May Cause Permanent Data Loss.
[-] Decryption Of Your Files With The Help Of Third
Parties May Cause Increased Price (They Add Their Fee
To Our) Or You Can Become A Victim Of A Scam.</pre><div><br><br></div>]]></description>
         <enclosure url="https://padlet-uploads.storage.googleapis.com/1466170122/9d23b8b80e6f4a1768ad15435d2e163f/bar.jpg" />
         <pubDate>2021-12-09 01:04:18 UTC</pubDate>
         <guid>https://padlet.com/bluxtrv/malwareanalysis/wish/1937083791</guid>
      </item>
   </channel>
</rss>
