Spybrowse – Code Developed To Steal Certain Browser Config Files (History, Preferences, Etc)
data:image/s3,"s3://crabby-images/78b4d/78b4db0c6fa56ca2273400bd18018c4e04c8fadd" alt="Spybrowse - Code Developed To Steal Certain Browser Config Files (History, Preferences, Etc) 1 spybrowse 4 img4"
Be sure to change the ftp variables throughout the code, these variables contain the username, password, & IP address of the FTP server which receives the files.
This code will do the following:
- Copy itself into the %TMP% directory & name itself ursakta.exe
- Add a registry entry to execute itself each time the user logs in
- Verify which browser the user is using (Chrome, Firefox or Brave)
- Search for files within the Chrome, Firefox, or Brave browser directories
- Create a directory on our FTP server then send the files in the browser’s directory to the FTP server
Cross Compiling with MingW on Linux
Install command with Apt:
sudo apt-get install mingw-w64
64-bit:
x86_64-w64-mingw32-gcc *input file* -o *output file* -lwininet -lversion
32-bit:
i686-w64-mingw32-gcc *input file* -o *output file* -lwininet -lversion
From Victim’s Perspective:
Registry entry:
data:image/s3,"s3://crabby-images/1e181/1e181fd6039df104ea1f5e8b0208fbe99d1fc676" alt="Spybrowse - Code Developed To Steal Certain Browser Config Files (History, Preferences, Etc) 2 spybrowse 1 img1"
File activity:
data:image/s3,"s3://crabby-images/8175c/8175c6e45269a566e0f4b982d1ca6a543493d29d" alt="Spybrowse - Code Developed To Steal Certain Browser Config Files (History, Preferences, Etc) 3 spybrowse 2 img2"
data:image/s3,"s3://crabby-images/8cbff/8cbff4a505a9de5f0ef4a8d459385d1955e50904" alt="Spybrowse - Code Developed To Steal Certain Browser Config Files (History, Preferences, Etc) 4 spybrowse 3 img3"
FTP connection:
data:image/s3,"s3://crabby-images/45276/4527644da334471bfaa6a8c51be68d85444e2cdd" alt="Spybrowse - Code Developed To Steal Certain Browser Config Files (History, Preferences, Etc) 5 spybrowse 4 img4 1"
Detection Rate:
This detection rate is after stripping the executable with strip --strip-all *filename.c*
data:image/s3,"s3://crabby-images/09613/096130c0557e2c416152362b2623019c093c7b47" alt="Spybrowse - Code Developed To Steal Certain Browser Config Files (History, Preferences, Etc) 6 spybrowse 5 img5"
Download Spybrowse
If you like the site, please consider joining the telegram channel or supporting us on Patreon using the button below.