Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 05-01-2005, 21:45
yaa
 
Posts: n/a
A small investigation of crack sites

Hello,

lately looking for sites to distribute my own releases I did some searching and noticed that an increasing number of crack sites are using cracks only to attract people in an attempt to have them download/install a series of spyware and adware apps.

At the moment I notice the following behaviors:

- download of an exe immediately started (usually recognizable by names such as readme.exe or download_plugin.exe)
- installation of a IE plugin requested
- executable added to the zip/rar (when run it will download a bunch of spyware and adware on the client machine)

Some sites however distinguish themselves for not doing anything of the above. At most they simply have annoying pop-ups.
Among these probably the best are keygen.us and mscracks.com that seem to be the most correct. Also, pinging all the sites that have proved to be more reliable it seems that they are all hosted in the same class C of IP addresses (and probably by the same host). In fact a few even share the same IP address.

Anyhow, I was wondering what do crack sites gain from spreading spyware and adware apps?


yaa

Last edited by yaa; 05-02-2005 at 00:51.
Reply With Quote
  #2  
Old 05-01-2005, 22:13
JMI JMI is offline
Leader
 
Join Date: Jan 2002
Posts: 1,627
Rept. Given: 5
Rept. Rcvd 199 Times in 99 Posts
Thanks Given: 0
Thanks Rcvd at 96 Times in 94 Posts
JMI Reputation: 100-199 JMI Reputation: 100-199
Like pop-up banners, they are generally paid something by those whose banners and/or spyware benefit from the "clicks" generated by the banners and/or the "information" gained by the spyware.

Regards,
__________________
JMI
Reply With Quote
  #3  
Old 05-04-2005, 06:19
baatazu
 
Posts: n/a
The bad thing is that most of cracks today have the spyware attached in the executable. So running the crack, it silently installs the spyware. That is why I have a copy of windows inside a Virtual PC, to apply the patch and copy the cracked exe to my original box. No worries about spywares. There are plenty of them already installed.
Reply With Quote
  #4  
Old 05-04-2005, 22:51
codeX codeX is offline
{RES} Cracker
 
Join Date: Dec 2004
Location: C:\WINDOWS\SYSTEM32
Posts: 163
Rept. Given: 1
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 3
Thanks Rcvd at 1 Time in 1 Post
codeX Reputation: 0
But I think you can trust releases from kegen.us and crack.cd.

But a good antivirus and anti spyware with latest updates will be nice.

@baatazu

I donn't think famous crack groups release spyware installers with theit cracks.
Reply With Quote
  #5  
Old 05-05-2005, 10:46
bugsome
 
Posts: n/a
cracks

use lavasoft adaware and Spybot - Search & Destroy both have different defenitions and engine .they ere the best.And some of the cracking groups inclludes spywares in a seperate exe such as crack.exe etc..make sure you read the .nfo file before running.
Reply With Quote
  #6  
Old 05-07-2005, 09:14
ntwizard
 
Posts: n/a
Lately I have seen a rash of renaming files to "known" names so people will click on them.. Thank goodness for Symantec NAV which has caught it most everytime..
Reply With Quote
  #7  
Old 05-07-2005, 13:39
bugsome
 
Posts: n/a
quick heal

use quick heal 7.03 with updated defs it detects most adware and spyware before it is even installed....
Reply With Quote
  #8  
Old 05-07-2005, 14:35
duseng duseng is offline
Friend
 
Join Date: Feb 2004
Posts: 120
Rept. Given: 9
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 1
Thanks Rcvd at 2 Times in 2 Posts
duseng Reputation: 0
Solution:
- Use Non IE Internet Browser . Firefox,Mozilla,Modified Ie Engine(not Recommended),Opera should does the best
- Use Proxy Based Filtering not Windows Title Filtering! use like AdMuncher the best so far
- Don't download from unfamous Crack/0day site. Nowaday they binded with Trojan and bunch of spyware/adware
- If u get the link from the forum.Make Sure u didn't become as the first tester.Wait until 5/6 peep tell that the file(setup+crack,patch) are ok (trojan/malicous free)!.Or u can check 'Tested' word on that topic

Last edited by duseng; 05-07-2005 at 14:42.
Reply With Quote
  #9  
Old 05-08-2005, 06:06
TGD
 
Posts: n/a
Quote:
Originally Posted by duseng
Solution:
- If u get the link from the forum.Make Sure u didn't become as the first tester.Wait until 5/6 peep tell that the file(setup+crack,patch) are ok (trojan/malicous free)!.Or u can check 'Tested' word on that topic
Hmmm... IMHO your first three ideas seem good, but the first part of the last one won't be possible. Because if it's an original post and everyone waits for 5-6 peple to test it, you'll never get the quorum because eveyone would be waiting for other 5 people to do the test...

Cheers,
TGD
Reply With Quote
  #10  
Old 05-08-2005, 06:16
nikola nikola is offline
Friend
 
Join Date: Jan 2004
Location: Your head
Posts: 115
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 0
Thanks Rcvd at 1 Time in 1 Post
nikola Reputation: 0
Just get FireFox and go to crackz.ws, cracks.am, crackdb.com, andr.net...
Reply With Quote
  #11  
Old 05-08-2005, 09:00
Vepergen
 
Posts: n/a
I suggest you using Craagle, and you won't get any trojan shit from cracksites. And of course Firefox for safe browsing.
Reply With Quote
  #12  
Old 05-09-2005, 05:09
codeX codeX is offline
{RES} Cracker
 
Join Date: Dec 2004
Location: C:\WINDOWS\SYSTEM32
Posts: 163
Rept. Given: 1
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 3
Thanks Rcvd at 1 Time in 1 Post
codeX Reputation: 0
Yes Quick Heal Xgen ( now on 2005 v7.03) does a great job. I'm using it over an year.
Nice update features and easy to crack also....

@Vepergen

In Craggle how to download crack.On selecting download no response .What to do?
Reply With Quote
  #13  
Old 05-26-2005, 12:21
Molasar Molasar is offline
VIP
 
Join Date: May 2002
Posts: 146
Rept. Given: 176
Rept. Rcvd 13 Times in 9 Posts
Thanks Given: 50
Thanks Rcvd at 10 Times in 8 Posts
Molasar Reputation: 13
Another way used to install spyware/trojans on victim PC's is that some sites offer full featured "free adult hosting", but they insert javascript code to install they malware in every web page you put in their server, one of them is www.freepimphost.com.

Most of the malware are designed to infect IE, so if you use Opera, you'll be safe.
Reply With Quote
  #14  
Old 08-11-2005, 19:15
Whiterat
 
Posts: n/a
I agree with verpergen, I often use craagle as it indexes the sites without having to physically visit them.
Also if you download a file from a 'bad' site it will warn you i.e "*WARNING* Do not run Start.exe this is sh**"
Which is a very useful warning for those nieve people in the world!

codeX: Does it list the files?
If you look in the cornor its got a status bar that'll tell you what the app is upto..Sometimes it will just sit on"Connecting" or similar, because all its doing is connecting to the http of a site, so if the sites down then it messes craagle up!

My only hate about craagle is that when you click cancel, it takes about 3 mins to stop!
Reply With Quote
  #15  
Old 08-11-2005, 19:42
Shub-Nigurrath's Avatar
Shub-Nigurrath Shub-Nigurrath is offline
VIP
 
Join Date: Mar 2004
Location: Obscure Kadath
Posts: 919
Rept. Given: 60
Rept. Rcvd 419 Times in 94 Posts
Thanks Given: 68
Thanks Rcvd at 330 Times in 100 Posts
Shub-Nigurrath Reputation: 400-499 Shub-Nigurrath Reputation: 400-499 Shub-Nigurrath Reputation: 400-499 Shub-Nigurrath Reputation: 400-499 Shub-Nigurrath Reputation: 400-499
most groups, also us for example, just for these reasons have their own ftp or http server (e.g. most times original "clean" cracks are modified adding a spyware program into the archive) where all the releases are placed. Just not immediate as a search engine, but if you are inside this world you should know where the things are or to whom ask.
__________________
Ŝħůb-Ňìĝùŕřaŧħ ₪)
There are only 10 types of people in the world: Those who understand binary, and those who don't
http://www.accessroot.com

Last edited by Shub-Nigurrath; 08-11-2005 at 19:44.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
[question]Friendly sites Storm Shadow General Discussion 2 08-23-2014 08:42
Macromedia Director MX 2004 investigation Isaaaac General Discussion 1 12-17-2008 23:28


All times are GMT +8. The time now is 03:24.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( 1998 - 2024 )