What's new

Welcome to HvH Forum!

SignUp Now! Download Free HvH CS2/CS:GO Cheats, CFG, LUA/JS Scripts, And More!


SignUp Now!
Safe file - file was approved, and checked by Staff, and it is safe to use. Learn more about files status! Report copyright abuse!
Newbie HvHer
User ID
95630
Messages
13
Reactions
3
Level
6
Virustotal will never tell you anything with 100% accuracy, and who is spencer lol..
 
Newbie HvHer
User ID
112728
Messages
3
Reactions
0
Level
1
this is the one from RAZE's telegram, use QHIDE's from yougame. it's likely more safe than RAZE
 
Newbie HvHer
User ID
112728
Messages
3
Reactions
0
Level
1
gang, thats the behaviour chart, it shows everything the file drops and downloads :/
yes, however this executes something way deeper than virustotal or any av can detect (puts itself in the bootloader)

usually this would be fixable with windows built in tools if it wasn't completely retarded (thanks bill gate)
 
Newbie HvHer
User ID
25754
Messages
15
Reactions
0
Level
2
yall gotta wait till January for update of unk.is site and loader. :p
 

Password for .zip file is hvh.net

  • Bez_tytuu.png
    Bez_tytuu.png
    51.8 KB · Views: 86
Newbie HvHer
User ID
62092
Messages
2
Reactions
0
Level
1
View attachment 8208I might be retarded, I don't know much about analysis, but in spencers overview, theres litteraly a file thats called rat.rar :/
those things you are looking at are compressed files that were previously scanned in virustotal.

example:
download this free,
make a different rar/zip file,
name the file some random bullshit you want(in this case rat),
scan on virustotal and after its done it'll show up where you saw that rat.rar.
 
Expert HvHer
User ID
37411
Messages
66
Reactions
163
Level
15
not anymore why do you think he freeed a clean version
stop spreading false information

qhide
skeet.dll e9506cddcfcace80620ef7b5b0ebcc2b
steam.exe
afe9b68ed167f0ec45a28bd47d3054f7

raze
skeet.dll
e9506cddcfcace80620ef7b5b0ebcc2b
steam.exe
afe9b68ed167f0ec45a28bd47d3054f7

same hashes
 
Newbie HvHer
User ID
49395
Messages
4
Reactions
1
Level
4
gang, thats the behaviour chart, it shows everything the file drops and downloads :/
no its not its the execution parents section which is just files that have dropped that file before. it does not drop rat.rar, the bundled steam.exe file in rat.rar drops it. The only importance of execution parents is to show where a file has been bundled in other sandbox analysed files. All the zip and rar files basically mean nothing because that just means its a zipped file that has had the dll in it.
 
Newbie HvHer
User ID
112369
Messages
2
Reactions
1
Level
1
bro pls fix i getting crash but steam.exe saying RESZ not supported how to fix this?

pls someone help
 
Last edited:
csgo-cs2 cheeto content creatort
User ID
69452
Messages
25
Reactions
5
Level
2
no its not its the execution parents section which is just files that have dropped that file before. it does not drop rat.rar, the bundled steam.exe file in rat.rar drops it. The only importance of execution parents is to show where a file has been bundled in other sandbox analysed files. All the zip and rar files basically mean nothing because that just means its a zipped file that has had the dll in it.
the dll had RAT.dll in it, once running it, you can find these files left within your registry.
 

Create an account or login to comment

You must be a member in order to leave a comment

Create account

Create an account on our community. It's easy!

Log in

Already have an account? Log in here.

Top