[color=#FF00]Link (Dangerous): [/color] dwarika, http://159.223.137.224/?61e8fbd06aa56=6c51b96eb6ac96bed9985e46cbe29653&61e8fbd06aa7c=41&61e8fbd06aa7e=1_windows-10-activator-kmspico-kms-tools-microsoft-toolkit&gkss=187199&61e8fbd06aa82=2, http://fit-host.xyz/?z=41&n=Windows%2010%20Activator%20–%20KMSPico,%20KMS%20Tools,%20Microsoft%20Toolkit, https://dl.dropboxusercontent.com/s/rur8561np1y64ad/setup__pass_1234_.zip?dl=0
Scan results:
Extra Info:
URL scan: https://urlscan.io/result/779b4208-cbfa-4fb2-95b1-477c1a167a39/#summary
Clicking the “download” button sends you here: https://urlscan.io/result/779b4208-cbfa-4fb2-95b1-477c1a167a39/
Downloads some generic trojan (VirusTotal). I downloaded a lot of Malware on my VM (including this trojan), so I’m not sure which one did it, but one had closed out every open program (including explorer.exe) and made a huge fake anti-virus message LMAO.
Keep in mind that exe files come from unzipping the .zip file with the password 1234, as provided by the website.