[GET] Dracony URL Harvester with footprint support

dracony2

Regular Member
Joined
Mar 5, 2010
Messages
350
Reaction score
327
Ok so this is basically same harvester as was before, but now it accepts an additional parameter - a footprint pattern.
For example if you use this pattern:
"powered by phpbb ##keyword##"
each search will be like:
"powered by phpbb cat"
"powered by phpbb dog"

so the ##keyword## is substituted with keywords from the csv file =)

Download:

Ill work on GUI tomorrow
 
Here's virustotal for .zip 1/43
Code:
virustotal.com/file-scan/report.html?id=253a0bca2f8d7cd42eee14a60f14f4172320074d253b57603606f5c5804c9ad5-1283728329

After i unzip .zip folder..i rescan for "w9xpopen.exe" & "drharvest.exe"

Here's the result for "w9xpopen.exe" 1/43

Code:
[COLOR=Red][COLOR=White][COLOR=Silver]virustotal.com/file-scan/report.html?id=bdc578de3f2694e800044a40bc7d850f063777640b198548ad2eb0372966e51d-1283728214[/COLOR][/COLOR][/COLOR]


Here's the result for"drharvest.exe" 0/43
Code:
[COLOR=Silver]virustotal.com/file-scan/report.html?id=93a1b13332a82e11648b8a5dc106930426a5ed0947aaec2903b02ef023cbb082-1283728193][/COLOR]


Use at your own risk :D


 
Last edited:
thanks, forgot to include virustotal link.
I build my app with py2exe, and i can provide sources for you to build yourself if you want.
w9xpopen.dll is a standart library.
if you find it elsewhere and rescan it with virustotal you'll get same false positive results. probably because it uses many OS functions.
 
I got a problem in dr2.zip

zip/Bredolab.A!Camelot

www (dot) trustedsource (dot) org/en/threats/malware_top

www (dot) virustotal (dot) com/file-scan/report.html?id=253a0bca2f8d7cd42eee14a60f14f4172320074d253b57603606f5c5804c9ad5-1283732471
 
0_o
i really believe its a false positive. i just checked my machine for viruses (Norton) and found nothing. What AV software are you using?
 
you have to be kidding me=\
 
Back
Top