Hello ToastyX,
first of all, thank you very much for your work and effort to create the CRU tool.
I would like to use the
latest version 1.5.2 and downloaded it from your site.
As always, I scanned all downloaded files via
virustotal.com before I executed them.
By this, I discovered that some of your executables are reported as "suspicious" by some scanners at virustotal.
For example the
"reset-all.exe" is flagged as "W32.AIDetectMalware" by Bkav Pro and
"Generic.Malware" by TEHTRIS.
The
"CRU.exe" is flagged as "Trojan.Malware.300983.susgen" by MaxSecure.
Most probably they are false positives.
Do you know why these engines detect these potential threads within your executables?
Additionally
filescan.io e.g. reports for
"CRU.exe" (version 1.5.2):
Code:
Malicious:
* imports APIs commonly found in keyloggers
* imports APIs used for code injection (PowerLoader)
* imports APIs used to take screenshots
--------
Unexpected was, that the
"behaviour analysis" by virustotal.com reports that
"CRU.exe" connects to the following IPs:
Code:
104.86.182.43:443 (TCP)
104.86.182.8:443 (TCP)
13.107.4.50:80 (TCP)
131.253.33.203:80 (TCP)
168.62.242.76:443 (TCP)
184.25.191.235:443 (TCP)
192.168.0.1:137 (UDP)
192.168.0.40:137 (UDP)
192.168.0.53:137 (UDP)
192.168.0.85:137 (UDP)
192.229.211.108:80 (TCP)
20.22.113.133:443 (TCP)
20.62.24.77:443 (TCP)
20.69.140.28:443 (TCP)
20.80.129.13:443 (TCP)
20.96.52.198:443 (TCP)
20.99.132.105:443 (TCP)
20.99.133.109:443 (TCP)
20.99.184.37:443 (TCP)
20.99.185.48:443 (TCP)
20.99.186.246:443 (TCP)
23.209.116.25:443 (TCP)
23.209.116.9:443 (TCP)
23.216.147.62:443 (TCP)
23.216.147.64:443 (TCP)
23.216.147.76:443 (TCP)
23.216.81.152:80 (TCP)
23.40.197.184:443 (TCP)
52.154.209.174:443 (TCP)
52.184.215.140:443 (TCP)
a83f:8110:0:0:0:0:100:0:53 (UDP)
a83f:8110:0:0:0:0:2002:0:53 (UDP)
a83f:8110:0:0:100:0:1800:0:53 (UDP)
a83f:8110:0:0:1400:1400:2800:3800:53 (UDP)
a83f:8110:0:0:1b00:100:2800:0:53 (UDP)
a83f:8110:0:0:2000:0:0:0:53 (UDP)
a83f:8110:0:0:2000:0:400:0:53 (UDP)
a83f:8110:0:0:2098:5d75:dc02:0:53 (UDP)
a83f:8110:0:0:5800:0:0:0:53 (UDP)
a83f:8110:0:0:beac:bf78:cce1:d301:53 (UDP)
a83f:8110:0:0:e600:0:0:0:53 (UDP)
a83f:8110:0:200:0:0:0:0:53 (UDP)
a83f:8110:1002:0:181e:bb90:1002:0:53 (UDP)
a83f:8110:100:ae00:ae:a6:0:0:53 (UDP)
a83f:8110:101:1ff:101:1ff:101:1ff:53 (UDP)
a83f:8110:1212:12ff:1313:13ff:1414:14ff:53 (UDP)
a83f:8110:1cad:0:c0b3:0:3c77:100:53 (UDP)
a83f:8110:202:2ff:202:2ff:202:2ff:53 (UDP)
a83f:8110:2800:1800:4000:1800:1800:100:53 (UDP)
a83f:8110:3202:0:6862:eaac:fe7f:0:53 (UDP)
a83f:8110:4747:47ff:4747:47ff:4747:47ff:53 (UDP)
a83f:8110:766b:b00:2600:0:5803:3900:53 (UDP)
a83f:8110:80a:14ff:709:13ff:409:12ff:53 (UDP)
a83f:8110:8401:0:2075:2cc:8401:0:53 (UDP)
a83f:8110:89d7:ffff:e00:0:0:0:53 (UDP)
a83f:8110:8c31:da01:beac:bf78:cce1:d301:53 (UDP)
a83f:8110:9802:100:0:a007:0:800:53 (UDP)
a83f:8110:c000:0:c800:0:0:0:53 (UDP)
a83f:8110:cc03:0:0:0:cc03:0:53 (UDP)
a83f:8110:cce1:d301:1bbb:ccef:3fc:d801:53 (UDP)
And performs the following DNS Resolutions:
Code:
fp2E7A.wpc.2BE4.phicdn.net
fp2e7a.wpc.phicdn.net
prda.aadg.msidentity.com
query.prod.cms.rt.microsoft.com
www.microsoft.com
The
"behaviour analysis" by virustotal.com reports that
"reset-all.exe" connects to the following IPs:
Code:
13.107.4.50:80 (TCP)
131.253.33.203:80 (TCP)
192.168.0.18:137 (UDP)
192.229.211.108:80 (TCP)
20.80.129.13:443 (TCP)
20.99.132.105:443 (TCP)
20.99.133.109:443 (TCP)
20.99.184.37:443 (TCP)
20.99.185.48:443 (TCP)
20.99.186.246:443 (TCP)
23.216.147.62:443 (TCP)
23.216.147.64:443 (TCP)
23.216.147.76:443 (TCP)
23.34.172.81:443 (TCP)
23.40.197.184:443 (TCP)
a83f:8110:0:0:100:0:1800:0:53 (UDP)
a83f:8110:0:0:1b00:100:2800:0:53 (UDP)
a83f:8110:0:0:4788:21:0:0:53 (UDP)
a83f:8110:0:0:700:700:2800:4000:53 (UDP)
a83f:8110:300:0:300:0:5830:24a7:53 (UDP)
a83f:8110:3ec5:559b:c930:3c06:a2b:601:53 (UDP)
a83f:8110:407:bff:205:aff:104:9ff:53 (UDP)
a83f:8110:61be:81d8:14c4:3415:eee5:572b:53 (UDP)
a83f:8110:6300:6100:7400:6900:6f00:6e00:53 (UDP)
a83f:8110:911:18ff:a12:19ff:50d:14ff:53 (UDP)
a83f:8110:ccf4:d801:346e:2282:ccf4:d801:53 (UDP)
a83f:8110:fce1:b48:324f:e6eb:b8ad:4fe4:53 (UDP)
I can't understand why these files have to connect to (so many) internet servers.
I would have expected that there's no traffic at all.
Why is this the case and what data is beeing transmitted?
It would help me a lot to understand why there's so much network traffic in order to know if it is intended like this and to know what data is received/sent from/to my computer if I use your tool.
I hope you understand these questions. Most likely you also would scan/analyse any downloaded software before executing it.
As stated above this all are most likely false positives and there's probably a good reason why your tools contact the above mentioned IPs.
I just want to understand why this is the case.
Thank you very much!
