Functions:-
- Firefox stealer:
- Apps:
- VPN:
- FTP/SSH:
- Gaming:
- CryptoWallets:
- System:
[Hidden content]
- - All chrome based browsers and profiles- All firefox based browsers and profiles
- - The traffic is encrypted
- - Configurable file grabber
- - Configurable file downloader
- - Collecting the archive into memory
- without writing any data to disk
- - AntiAnalysis (VirtualBox, SandBox,
- Host, RDP,
- Emulator, Debugger, CIS country)
- - Passwords
- - CreditCards
- - AutoFill
- - Cookies- History
- - Downloads
- - Keywords
- - Bookmarks
- Firefox stealer:
- - Passwords-
- AutoFill
- - Cookies
- - History
- - Bookmarks
- - AstraChat (accounts)- Bettergram (session)
- - Discord (session, tokens)
- - Element (session)
- - Facebook (contacts)
- - Gajim (accounts)
- - Paltalk (session)
- - Pidgin (accounts, chatlogs)
- - Psi,Psi+ (accounts)
- - RamBox (partitions)
- - Ferdi (partitions)
- - Franz (partitions)
- - Signal (session)
- - Skype (session)
- - Slack (session)
- - Spark (account)
- - Swift (accounts)
- - TeamSpeak3 (account db)
- - Telegram (session)
- - Telefuel (session)
- - Chatogram (session)
- - UWPX (session)
- - Unigram (session)
- - Viber (session, contacts)
- - WhatsApp (session)
- - Wickr Me/Pro (session,username)
- - uTox/qTox/Toxygen (username)
- - FoxMail (session)
- - MailSpring (session)
- - OperaMail (session)
- - Outlook (accounts)
- - PocoMail (session)
- - SeaMonkey (accounts, cookies)
- - Spike (session)
- - TheBat! (session)
- - Thunderbird (accounts, cookies)
- - eM Client (session)
- - Password managers:
- Dashlane (session)
- - RoboForm (session)
- - NordPass (databases)
- - 1Password (databases)
- - BitWarden (databases)
- - KeePassXC (databases)
- - KeePass2 (databases, keyfiles)
- - VeraCrypt (databases, containers)
- Apps:
- - Authy (session)
- - Docker desktop (account)
- - Git (credentials)
- - Github Desktop (session)
- - Ngrok (token)
- - OBS Studio (broadcast keys)
- - PHP-Composter (auth file)
- - Utopia Ecosystem (account containers)
- - WinAuth (container)
- - WinRar (history)
- VPN:
- - EarthVPN (account)
- - MysteriumDVPN (keystore)
- - NO-IP DUC (credentials)
- - NordVPN (accounts)
- - OpenVPN (profiles)
- - PrivateVPN (session)
- - ProtonVPN (session)
- - Proxifier (profiles)
- - SentielDVPN (keystore)
- FTP/SSH:
- - ApacheDirectoryStudio
- - CoreFTP
- - CyberDuck
- - FarManager
- - FileZilla
- - MobaXTerm
- - SnowFlake
- - TotalCmd
- - WinSCP
- - mRemoteNG
- Gaming:
- - BattleNet (account information)
- - GameCenterMailRu (account information)
- - KalypsoMedia (account)
- - Gameforge (account)
- - Origin (account information)
- - Osu! (session)
- - SA:MP (username, servers)
- - Steam (ssfn, vdf, username, apps)
- - Uplay (account information)
- - Minecraft (session tokens)
- - LavaCraft (session)
- - LoliLand (account)
- - McSkill (session)
- - RedServer (session)
- - VimeWorld (session)
- CryptoWallets:
- - ARK
- - Armory
- - AtomicWallet
- - BitPay
- - Bitcoin Knots
- - BitcoinCore
- - Bither
- - Blockstream
- - CoinWallet
- - Coinomi
- - DashCore
- - Electrum
- - Ethereum
- - Exodus
- - GreenAddress
- - Guarda
- - Jaxx
- - LitecoinCore
- - MoneroCore
- - MyMonero
- - Scatter
- - Wasabi
- - Zcash
- System:
- - Active windows screenshot
- - Appslist
- - Desktop screenshot
- - Networks (Saved, Scanning)
- - Processlist
- - Vault passwords (IE, RDP)
- - Webcam screenshot
- - Windows credential manager
[Hidden content]
nice post thx for share