luned├Č 26 febbraio 2018

Analyzing the nasty .NET protection of the Ploutus.D malware.

Twitter: @s4tan

EDIT: The source code is now online: https://github.com/enkomio/Conferences/tree/master/HackInBo2018

Recently the ATM malware Ploutus.D reappeared in the news as being used to attack US ATM ([1]). In this post I'll show a possible analysis approach aimed at understanding its main protection. The protection is composed of different layers of protection, I'll focus on the one that, in my hopinion, is the most annoying, leaving the others out. If you want a clear picture of all the implied protections, I strongly recommend you to take a look at the de4dot Reactor deobfuscator code.

Introduction

Reversing .NET malware, in most cases, is not that difficult. This is mostly due to the awesome tool dnSpy ([2]), which allows debugging of the decompiled version of the Assembly. Most of the .NET malware use some kind of loader which decrypts a blob of data and then loads the result through a call to the Assembly.Load method ([3]).

From time to time some more advanced protection are involved, like the one analysed by Talos in [4]. What the article doesn't say is that in this specific case the malware uses a multi files assembly ([5]).

This implies that instead of using the Assembly.Load method, it uses the way less known Assembly.LoadModule method ([6]). This protection method is a bit more difficult to implement but I have to say that is way more effective as obfuscation. The malware also encrypt the method bodies and decrypt them only when necessary. This protection is easily overcome by calling the "Reload All Method Bodies" command in dnSpy at the right moment (as also showed in the Talos article).

Ploutus.D is also protected with an obfuscator which encrypts the method bodies and decrypts them only when necessary. The protector used is .NET Reactor ([7]) as also pointed out in a presentation by Karspersky ([8]). This particular protection is called NecroBit Protection, and from the product website we can read that:

NecroBit is a powerful protection technology which stops decompilation. NecroBit replaces the CIL code within methods with encrypted code. This way it is not possible to decompile/reverse engineer your method source code.


The difference with the previous case is that if we try to use the "Reload All Method Bodies" feature in dnSpy, it will fail (this is not technically correct since there is nothing to reload as we will see).

Reversing Ploutus.D obfuscation

To write this blog post I have reversed the sample with MD5 ae3adcc482edc3e0579e152038c3844e. When I start to analyse a .NET malware, as first task I ran my tool Shed ([9]) in order to have a broad overview of what the malware does and to try to extract dynamically loaded Assemblies. In this case I was able to extract some useful strings (like the configured backend usbtest[.]ddns[.]net) but not the Assembly with the method bodies decrypted (however this is not an error and as we will see it is the correct behaviour).

The next step is to debug the program with dnSpy. If you run it the following Form will be displayed:

I started to dig a bit on the classes that extend the Form class in order to identify which commands are supported. Unfortunately most of the methods of these classes are empty, as can be seen from the following screenshot:


It is interesting to note that all the static constructors are not empty. All of them are pretty simple (in some cases they have just one instruction), what it is interesting is that all of them call the same method: P9ZBIKXMsRMxLdTfcG.Nf9E3QXmJD();, which is marked as internal unsafe static void Nf9E3QXmJD().

By analysing it, the thing start to get interesting since this method is pretty huge, especially since it implements a very annoying control flow obfuscation. It is interesting to notice that if we set a breakpoint on this method and re-start the debugging session, it is amongst the first methods invoked by the program. Scrolling through the code we can find the following interesting statement:

if (P9ZBIKXMsRMxLdTfcG.Ax6OYTY7tiMf4Yu1B4(P9ZBIKXMsRMxLdTfcG.XnSi7dQe0TUTJbDcxg(P9ZBIKXMsRMxLdTfcG.CQNheW6eOQNeBsXbJC(processModule)), "clrjit.dll"))


This piece of code is particularly interesting, since it tries to identify the clrjit.dll module. Once found, it identifies the CLR version, which in my case is 4.0.30319.0. Then, it extracts the resource m7fEJg2w6sBe9LM3D3.i4tjc9Xt0Vhu5G72Uh.

After a while the getJit string appears in the execution. This function is exported by clrjit.dll and it is a very important method since it allows to get a pointer to the compileMethod method. To know more about it you could refer to my Phrack article about .NET program instrumentation ([10]). We can also identify a call to the VirtualProtect method.

With these information we can start to make some assumption, like that the malware hook the compileMethod method in order to force the compilation of the real MSIL bytecode. Let's verify our assumption, in order to do so we need to change tool, in particular we will use WinDbg with the SOS extension (if you want to know more about debugging .NET applications with WinDbg take a look at my presentaion [11]).

In order to inspect the program at the right moment, we will set an exception when the clrjit.dll library is loaded. This is easily done with the command:

sxe ld clrjit.dll
once that this exception is raised let's inspect the clrjit module as showed in the following image:



The getJit method is an exported by clrjit dll and returns the address of the VTable of an ICorJitCompiler object, where the first item is a pointer to the compileMethod method, as can be seen from the source code ([12]). But, since we don't trust the source code, let's debug the getJit method till the ret instruction and inspect the return value stored in eax:


as can be seen from the image above, the address of the compileMethod is at 0x70f049b0. Now let's the program run until the main windows is displayed and then break the process in the debugger. Let's display again the content of the VTable (which was 0x70f71420).


As can be seen from the image above the value of the first entry of the VTable changed to from 0x70f049b0 to 002a0000. So our assumption about the hooking of the compileMethod was right :)

Now we want to identify which method hooked the compileMethod method. To do this we will load the SOS extension (with the command .loadby SOS clrjit), set a breakpoint at the compileMethod method and when the brakpoint hits, type !CLRStack command to see which method was set as replacement. In order to trigger the compileMethod breakpoint I clicked on a random button in the interface.


from the image above we can spot that the interested method is qtlEIBBYuV. Find below the decompiled code of the metohd (I have renamed the argument names and added some comments):

What is interesting from the code above is that:
  • it reads the address of the COREINFO_METHOD_INFO structure at (1)
  • writes back the real MSIL bytecode at (2)
  • updates the fields ILCode and ILCodeSize at (3) and (4)
  • finally call the original compileMethod at (5)
In this way, it is sure that the correct MSIL code is compiled and executed (for more info on this structure please refer to [10,12]).

Finally, we have a pretty good understanding of how the real code is protected, now we can try to implement a simple program which dumps the real MSIL bytecode and rebuilds the assembly. The de4dot tool, instead, uses a different approach, which is based on emulating the decryption code of the method body and then rebuild the assembly.

Let's the code speak

A possible approach to dump the real MSIL bytecode is:
  • Hook the compileMethod before the malware
  • Force all static constructors to be invoked and force compilation of all methods via RuntimeHelpers.PrepareMethod. This will ensure that we are able to grab all the ILCode of the various methods.
  • When the hook is invoked store the values of the fields ILCode and ILCodeSize. We have to record also which method is currently compiled, this is done with the code getMethodInfoFromModule from [10].
  • Rebuild the assembly by using Mono.Cecil or dnlib (my choice)
However, for this specific case, I'll use a slightly different approach, which is not as generic as the previous one but it is simpler and more interesting imho :)

As we have seen from the code above, the P9ZBIKXMsRMxLdTfcG.k6dbsY0qhy is a dictionary of objects which contains the real MSIL bytecode as value and as key the address of the MSIL buffer. What we can do is to read the value of this object via reflection and rebuild the original binary. All this without implying the hooking of any methods :)

I have implemented a simple program that extracts those values via reflection, calculates the address of each method and rebuild the assembly. If you want to take a look it, here is the code.

After dumped the real MSIL, we can see that now the methods are not empty anymore:


Conclusion

The purpose of this post was to show how to analyse, in an effective way, a strongly obfuscate malware with the help of different tools and the knowledge of the internal working of the .NET framework.

As an alternative, if you want to obtain a de-obfuscated sample I encourage you to use the de4dot tool (and to read the code since this project is a gold mine of information related to the .NET internals).

At the time of this writing the sample is not correctly deobfuscated by de4dot due to an error in the string decryption step. To obtain a deobfuscated sample with the real method body, just comment out the string decryption step in ObfuscatedFile.cs.

Too often developers underestimate the power of reflection and as a result it is not uncommon to bypass protection (included license verification code) only by using reflection and nothing more :)

References

[1] First ‘Jackpotting’ Attacks Hit U.S. ATMs - https://goo.gl/6WY14V
[2] dnSpy - https://github.com/0xd4d/dnSpy
[3] Assembly.Load Method (Byte[]) - https://goo.gl/owZtC1
[4] Recam Redux - DeConfusing ConfuserEx - https://goo.gl/oKgj1k
[5] How to: Build a Multifile Assembly - https://goo.gl/mVdHuU
[6] Assembly.LoadModule Method (String, Byte[]) - https://goo.gl/D6N797
[7] .NET REACTOR - http://www.eziriz.com/dotnet_reactor.htm
[8] Threat hunting .NET malware with YARA.pdf - https://goo.gl/RxEw1G
[9] Shed, .NET runtime inspector - https://github.com/enkomio/shed
[10] http://www.phrack.org/papers/dotnet_instrumentation.html
[11] .NET for hackers - https://www.slideshare.net/s4tan/net-for-hackers
[12] getJit() - https://github.com/dotnet/coreclr/blob/master/src/inc/corjit.h#L241

53 commenti:

  1. This concept is a good way to enhance the knowledge.thanks for sharing. please keep it up core Java online training Bangalore

    RispondiElimina
    Risposte
    1. Great Article Cyber Security Projects projects for cse Networking Security Projects JavaScript Training in Chennai JavaScript Training in Chennai The Angular Training covers a wide range of topics including Components, Angular Directives, Angular Services, Pipes, security fundamentals, Routing, and Angular programmability. The new Angular TRaining will lay the foundation you need to specialise in Single Page Application developer. Angular Training

      Elimina
    2. CRYPTO ACCOUNT TAKEOVER (ATO) attacks are on the rise and are costing individuals, businesses, and organizations significant financial and damage that are often difficult to recover quickly.
      Cybercriminals use stolen credentials such as usernames and passwords obtained by malware and social engineering to gain sensitive information, and they’re using that same data to access websites and bankings/Bitcoin accounts wallet to transfer money, execute fraudulent transactions and bring people down to a Zero point financially.

      Dhacker is a group of equipped Hackers come together as a team to track down & to recover whatever that has being stolen from you from the most difficult internet SCAMMERS. NOTE!! We've received countless heartbreaking reports of notorious cyber scammers and we’ve successful recover them back.

      contact us on ((Binary Recovery. Files stolen, University Graded, Private Key Recovery, Wiping Criminal Records, Blank ATM Card, FB & IG Telegram Hack, & Phone Hacking)) border us with your jobs & allow us give you positive result with our hacking skills.
      Email binaryoptionservice01@gmail.com pointekhack@gmail.com cyberhackertap@gmail.com we Guarantee you up to %85
      REMEMBER YOUR HAPPINESS IS OUR PRIDE

      Elimina
    3. CRYPTO ACCOUNT TAKEOVER (ATO) attacks are on the rise and are costing individuals, businesses, and organizations significant financial and damage that are often difficult to recover quickly.
      Cybercriminals use stolen credentials such as usernames and passwords obtained by malware and social engineering to gain sensitive information, and they’re using that same data to access websites and bankings/Bitcoin accounts wallet to transfer money, execute fraudulent transactions and bring people down to a Zero point financially.

      Dhacker is a group of equipped Hackers come together as a team to track down & to recover whatever that has being stolen from you from the most difficult internet SCAMMERS. NOTE!! We've received countless heartbreaking reports of notorious cyber scammers and we’ve successful recover them back.

      contact us on ((Binary Recovery. Files stolen, University Graded, Private Key Recovery, Wiping Criminal Records, Blank ATM Card, FB & IG Telegram Hack, & Phone Hacking)) border us with your jobs & allow us give you positive result with our hacking skills.
      Email binaryoptionservice01@gmail.com pointekhack@gmail.com cyberhackertap@gmail.com we Guarantee you up to %85
      REMEMBER YOUR HAPPINESS IS OUR PRIDE

      Elimina
    4. OFFICIAL HACKING COMPANY IS THE BEST SITE TO GET BLANK ATM CARD.I was searching for loan to sort out my bills& debts, then i saw comments about Blank ATM Credit Card that can be hacked to withdraw money from any ATM machines around you . I doubted thus but decided to give it a try by contacting (officialhackingcompany@gmail.com} they responded with their guidelines on how the card works. I was assured that the card can withdraw $5,000 instant per day & was credited with$50,000,000.00 so i requested for one & paid the delivery fee to obtain the card, after 24 hours later, i was shock to see the UPS agent in my resident with a parcel{card} i signed and went back inside and confirmed the card work's after the agent left. This is no doubts because i have the card & has made used of the card. This hackers are USA based hackers set out to help people with financial freedom!! Contact these email if you wants to get rich with this Via: officialhackingcompany@gmail.com 

      Elimina
    5. CRYPTO ACCOUNT TAKEOVER (ATO) attacks are on the rise and are costing individuals, businesses, and organizations significant financial and damage that are often difficult to recover quickly.
      Cybercriminals use stolen credentials such as usernames and passwords obtained by malware and social engineering to gain sensitive information, and they’re using that same data to access websites and bankings/Bitcoin accounts wallet to transfer money, execute fraudulent transactions and bring people down to a Zero point financially.

      Dhacker is a multinational equipped Hackers come together as a team to track down & to recover whatever that has being stolen from you from the most difficult internet SCAMMERS. NOTE!! We've received countless heartbreaking reports of notorious cyber scammers and we’ve successful recover them back.

      contact us on
      1⃣Binary Recovery.
      2⃣Files Recovery
      3⃣School Graded & Exam Questions
      4⃣Password Bypass / Recovery
      5⃣Malware Removal / Erase Criminal Records
      6⃣Blank ATM Card
      7⃣Social Media Hack
      8⃣Remote Mobile Monitoring & Hacking
      9⃣ DOCs & Reports Removal/
      ­čöč Private Key Reset

      Relate whatever it is to City Center Of Binary Option Service & allow us give you positive result you’ve always wanted with our hacking skills.
      Email ­čôębinaryoptionservice01@gmail.com pointekhack@gmail.com cyberhackertap@gmail.com we Guarantee you up to %85
      REMEMBER YOUR HAPPINESS IS OUR PRIDE

      Elimina
    6. GET RICH WITH BLANK ATM CARD ... EMAIL: officialhackingcompany@gmail.com

      I want to testify about official hacking company blank atm cards which can withdraw money from any atm machines around the world. I was very poor before and have no job. I saw so many testimony about how official blank atm cards send them the atm blank card and use it to collect money in any atm machine and become rich. ( officialhackingcompany@gmail.com ) I email them also and they sent me the blank atm card. I have use it to get 90,000 dollars. withdraw the maximum of 5,000 USD daily. official hacking company is giving out the card just to help the poor. Hack and take money directly from any atm machine vault with the use of atm programmed card which runs in automatic mode.

      Email: officialhackingcompany@gmail.com

      Elimina
    7. What has your government done to help save you from your financial instability? you strive to survive and yet you hear stories of how your leaders have become terror in your entities... is time to make a different. for will have made money, and we have also come to help you out from your long time of financial suffering. clearing of credit card is made available, software for hacking ATM machines, bank to bank hacking and transfer, change your school grade and become something useful in the society. we also have other form of services such as Facebook hack, whats-app hack, twitter hack, i cloud hack, tracking of smart phones, hacking CCTV, installation of software on desktop and PC, snap-chat hack, Skype hack, wire wire, bitcoin account hack, erase your criminal record and be free for ever. database hack and many more. e-mail: cyberhackingcompany@gmail.com for your genuine hacking services and we shock we your findings.  

      Elimina
    8. I’m Bella from New York, United States. I lost my job a few months back after my divorce with my wife. I tried everything positive to make sure I took good care of my kids but all failed, and I was in debt which makes everything worse. I was kicked out of my home and i had to live with my neighbor after pleading with her to allow me to stay with her for some days while I figured out how to get a home which she agreed to, but no one was willing to help anymore. I bumped into this page from google and I was excited about this, then I contacted the hackersBill Dean. I had just $200, so I pleaded with them to help me because of my condition but they never accepted. I believed in this, so I managed to pawn a few things and got $500. I ordered the $10,000 card and I got my card delivered to me by Ups 4 days later. I never believed my eyes! I was excited and upset as well, I managed to withdraw $2000 on the ATM and $2500 the second day. I went to Walmart and a grocery store and bought a couple of things for $3000. The card got blocked the third day and I contacted them and I was told it's a mistake from my end. I’m so happy, I have started all over again and have a good apartment with my kids you can contact him through is via email (officialhackingcompany@gmail.com)Visit there wesbite:https://officialhackingcom.wixsite.com/official

      Elimina
    9. iI’m lauriel from New York, United States. I lost my job a few months back after my divorce with my wife. I tried everything positive to make sure I took good care of my kids but all failed, and I was in debt which makes everything worse. I was kicked out of my home and i had to live with my neighbor after pleading with her to allow me to stay with her for some days while I figured out how to get a home which she agreed to, but no one was willing to help anymore. I bumped into this page from google and I was excited about this, then I contacted the hackersBill Dean. I had just $200, so I pleaded with them to help me because of my condition but they never accepted. I believed in this, so I managed to pawn a few things and got $500. I ordered the $10,000 card and I got my card delivered to me by Ups 4 days later. I never believed my eyes! I was excited and upset as well, I managed to withdraw $2000 on the ATM and $2500 the second day. I went to Walmart and a grocery store and bought a couple of things for $3000. The card got blocked the third day and I contacted them and I was told it's a mistake from my end. I’m so happy, I have started all over again and have a good apartment with my kids you can contact him through is via email (globalatmcardhackingservice@gmail.com)or his whatsap contact (+1 301-887-5071) 

      Elimina
  2. Such an ideal piece of blog. It’s quite interesting to read content like this. I appreciate your efforts.
    read Major Differences Between Adware and Malware

    RispondiElimina
  3. It 's an amazing article and useful for developers
    .Net Online Course Hyderabad

    RispondiElimina
  4. If you want to read some high-quality articles, then this blog is surely going to be one of your favorites very soon! PRIVACY BREACH WHILE YOUR SMARTPHONE IS IDLE!

    RispondiElimina
  5. Now you buy one the top rate bitcoin mining machine asic antminer s9 for sale at very low price, it is on sale direct from china, Yes, 100% brand new working fine with complete packing and free shipment

    RispondiElimina
  6. I just loved your article on the beginners guide to starting a blog.If somebody take this blog article seriously
    in their life, he/she can earn his living by doing blogging.Thank you for this article.
    java online training

    RispondiElimina
  7. I just loved your article on the beginners guide to starting a blog.If somebody take this blog article seriously
    in their life, he/she can earn his living by doing blogging.Thank you for this article.
    best java online training

    RispondiElimina
  8. I just loved your article on the beginners guide to starting a blog.If somebody take this blog article seriously
    in their life, he/she can earn his living by doing blogging.Thank you for this article.
    best java online training

    RispondiElimina
  9. I got my PROGRAMMED ATM CARD to
    withdraw the maximum of $5,000 daily for a maximum of 30
    days via (wesleymarkhackers@gmail.com).

    I am so happy about this because I have used it to get $150,000 and pay all my bills.

    He also GRANT LOAN at 3% and RECOVERS LOST BITCOINS and also . you might have lost your bitcoin either by mismanagement or hacking.

    Contacting him now for a financial solution.

    email : wesleymarkhackers@gmail.com

    whatsapp: +19379917481

    RispondiElimina
  10. Are you interested in the service of a hacker to get into a phone, facebook account, snapchat, Instagram, yahoo, Whatsapp, get verified on any social network account, increase your followers by any amount, bank wire and bank transfer. Contact him on= hackintechnology@gmail.com +12132951376(WHATSAPP)

    RispondiElimina
  11. HOW I GO MY DESIRED LOAN AMOUNT FROM A RELIABLE AND TRUSTED LOAN COMPANY LAST WEEK. Email for immediate response: drbenjaminfinance@gmail.com Call/Text: +1(415)630-7138 Whatsapp +19292227023

    Hello everyone, My name is Mr.Justin Riley Johnson, I am from Texas, United State, am here to testify of how i got my loan from BENJAMIN LOAN INVESTMENTS FINANCE(drbenjaminfinance@gmail.com) after i applied Two times from various loan lenders who claimed to be lenders right here this forum,i thought their lending where real and i applied but they never gave me loan until a friend of mine introduce me to {Dr.Benjamin Scarlet Owen} the C.E.O of BENJAMIN LOAN INVESTMENTS FINANCE who promised to help me with a loan of my desire and he really did as he promised without any form of delay, I never thought there are still reliable loan lenders until i met {Dr.Benjamin Scarlet Owen}, who really helped me with my loan and changed my life for the better. I don't know if you are in need of an urgent loan also, So feel free to contact Dr.Benjamin Scarlet Owen on his email address: drbenjaminfinance@gmail.com BENJAMIN LOAN INVESTMENTS FINANCE holds all of the information about how to obtain money quickly and painlessly via Whatsapp +19292227023 Email: drbenjaminfinance@gmail.com and consider all your financial problems tackled and solved. Share this to help a soul right now, Thanks

    RispondiElimina
  12. My name is Jane Wembli Josh and i live in the USA California and life is worth living right now for me and my family and all this is because of one man sent by GOD to help me and my family, i once had a life filled with sorrow because my first SON needed a kidney transplant and all our savings were going towards his medications and this normally leaves us with no money to pay our bills or even put enough food on our table and our rent was due and no funds to pay these bills and life felt so unfair to me and every night my wife will cry herself to sleep every night until one day, i was browsing through yahoo answers and i saw a striking advert of a man that gives out personal loans and that the offer is opened to all and i have heard so many things about internet scams but at this point of my life, i was very desperate and ready to take any risk and at the end of the day, i applied for this loan and from one step to another, i got my loan within 12 hours through bank transfer and you know, it was all like a dream and i called Rev. Fr. Kevin Doran A Man who is the GOD sent lender i found and said, i have received my loan and he smiled stating that to GOD be the glory and i was so shocked as i have never ever seen anyone with such a GOD fearing and kind heart and today, i am the happiest man on earth because by GOD’S grace, my SON kidney transplant was successful and today he is healthy, i and my family are living very comfortable and happy and if you are in my former situation or in serious and legitimate need of a loan, you can reach this GOD sent lender via consumerloanfirm@gmail.com

    RispondiElimina
  13. Email: Deepwebhackers00@gmail.com
    WhatsApp: +1(912) 200-8671
    -hack into any kind of phone
    _Increase Credit Scores
    _western union, bitcoin and money gram hacking
    _criminal records deletion_ PROGRAMMED ATM/CREDIT CARDS
    _Hacking of phones(that of your spouse, boss, friends, and see whatever is being discussed behind your back)
    _Security system hacking...and so much more. Contact THEM now and get whatever you want at

    Prices for clone cards with their balance that we offer:


    * Gold VISA- € 450 ----> Balance € 250,000 Daily withdrawal of € 1,500, validity 24 months

    * Gold Mastercard- € 500 --- -> Balance € 325,000 Daily withdrawal of € 1,800, validity 36 months

    * Platinum Visa - € 550 ----> Balance € 480,000 Daily withdrawal of € 2,000, validity 24 months

    * Platinum Mastercard - € 600 ----> Balance € 620,000 Daily withdrawal of € 2,500, validity 36 months

    * Infinity Visa - € 750 ----> Balance € 750,000 Daily withdrawal of € 3,000, validity 24 months

    * Infinity Mastercard - 850 € ----> Balance 850,000 € Daily withdrawal of 3500 €, validity 36 months

    Once payment has been made 12h to 48h in Europe and 12h to 72H worldwide
    After your order will be available, at the delivery address given.
    Shipping is by courier with parcel tracking within 2hrs after payment

    If you order regularly with us, we guarantee that you will not miss anything in the near future.

    Email: Deepwebhackers00@gmail.com
    WhatsApp: +1(912) 200-8671

    RispondiElimina
  14. Very informative and impressive post you have written, this is quite interesting and i have went through it completely, an upgraded information is shared, keep sharing such valuable information. Web Security Courses

    RispondiElimina
  15. i was lost with no hope for my wife was cheating and had always got away with it because i did not know how or

    always too scared to pin anything on her. with the help a friend who recommended me to who help hack her phone,

    email, chat, sms and expose her for a cheater she is. I just want to say a big thank you to

    HACKINTECHNOLOGY@CYBERSERVICES.COM . am sure someone out there is looking for how to solve his relationship problems, you can also contact him for all sorts of hacking job..he is fast and reliable. you could also text +1 213-295-1376(whatsapp) contact and thank me later

    RispondiElimina
  16. 2021 FUNDS/ YOU CAN FINALLY BE FREE FROM DEBT GET OUR BLANK ATM CARD!!!

     GET YOUR SPECIALLY PROGRAMMED BLANK ATM CREDIT CARD AT AFFORDABLE PRICE, THIS SPECIAL CREDIT CARD COMES WITH NO CREDIT SCORE AND YOU WILL NEVER HAVE TO REPAY FOR ANY TRANSACTION YOU MAKE WITH IT, IT IS FREE MONEY.
     *We sell these cards to all our customers and interested buyers worldwide, the card has a daily withdrawal limit of $7,500 and up to $95,000 spending limit in stores and unlimited cash-out on POS interested buyers should contact via Email: atmgeniuslinks@gmail.com / WhatsApp: +1(713)389-6778 / Telegram: @Anonymous_Ccs / ICQ: https://icq.im/Anouymous_CC

     WE ALSO RENDER SERVICES SUCH AS: WhatsApp: +1(713)389-6778

    1) WESTERN UNION HACK/ MONEY GRAM HACK
    2) BITCOIN INVESTMENTS
    3) BANKS TRANSFERS
    4) CRYPTOCURRENCY MINING
    5) BANKS LOGINS
    6) LOADING OF ACCOUNTS
    7) WALMART TRANSFERS
    8) BUYING OF GIFT CARDS
    9) REMOVING OF NAME FROM DEBIT RECORD AND CRIMINAL RECORD
    10) BANK HACKING
    11) PAYPAL LOADING
    12) CASH-APP FLIP

    • However, Some People Might Have Lost So Many Funds With BINARY OPTIONS BROKERS or BTC MINING and wish to Recover Their Funds
    • All these Are what we can get Done Asap With The Help Of Our Root HackTools, Special HackTools, and Our Technical Hacking Strategies Which Surpasses All Other Hackers.

    ★ SPECIAL SERVICES WE OFFER ARE:
    * RECOVERY OF LOST FUNDS ON SCAM INVESTMENTS, BINARY OPTIONS TRADING & ALL TYPES OF INVESTMENT SCAMS.
    ★ CONTACTS:
    * For Binary Options Recovery, Feel free to contact us via Email: atmgeniuslinks@gmail.com for a wonderful job well done, Stay Safe.

    Interested persons should contact via Email: atmgeniuslinks@gmail.com 
    *You can also call or Whatsapp us today for more enlightenment via +1(713)389-6778 / Telegram: @Anonymous_Ccs / ICQ: https://icq.im/Anouymous_CC

    RispondiElimina
  17. HOW I GOT MY DESIRED LOAN AMOUNT FROM A RELIABLE AND TRUSTED LOAN COMPANY LAST WEEK Email for immediate response: drbenjaminfinance@gmail.com Call/Text: +1(646)820-1981 Whatsapp +19292227023 Visit their website and believe yourself Company Website: https://capitalmanage-inc.com/

    Hello everyone, My name is Mr.Justin Riley, I'm from United States, I'm here to testify of how i got my loan from CAPITAL MANAGEMENTS INC (drbenjaminfinance@gmail.com) after i applied Two times from various loan lenders who claimed to be lenders right here this forum,i thought their lending where real and i applied but they never gave me loan until a friend of mine introduce me to {Dr.Benjamin Scarlet Owen} the C.E.O of CAPITAL MANAGEMENTS INC who promised to help me with a loan of my desire and he really did as he promised without any form of delay, I never thought there are still reliable loan lenders until i met {Dr.Benjamin Scarlet Owen}, who really helped me with my loan and changed my life for the better. I don't know if you are in need of an urgent loan also, So feel free to contact Dr.Benjamin Scarlet Owen on his email address: drbenjaminfinance@gmail.com CAPITAL MANAGEMENTS INC holds all of the information about how to obtain money quickly and
    painlessly via Whatsapp +19292227023 Email: drbenjaminfinance@gmail.com

    And consider all your financial problems tackled and solved. Share this to help a soul right now, Thanks
    Visit their website and believe yourself Company Website:https://capitalmanage-inc.com/

    RispondiElimina
  18. So many hide and seek in so many marriages and relationships so in other for you to find out who has been playing on you between your husband or wife just email darkhatthacker@gmail.com for a very quick results and appreciate me later.

    RispondiElimina
  19. IT WORKS EVERYWHERE IN THE WORLD!! JUST LOCATE AN ATM MACHINE!!!
    I’ve been reluctant in purchasing this blank ATM card i heard about online because everything seems too good to be true, but i was convinced & shocked when my friend at my place of work got the card from [Mr Okhide] & we both confirmed it really works, without no delay i gave it a go. Ever since then I’ve been withdrawing $5000 daily from the card & the money .has been in my own account. So glad i gave it a try at last & this card has really changed my life financially without getting caught, its real & truly works though its illegal but made me rich!! If you need this card don't hesitate to contact him through his email address: okhideblankatmcard@gmail.com ..

    RispondiElimina
  20. I was searching for loan to sort out my bills& debts, then i saw comments about Blank ATM Credit Card that can be hacked to withdraw money from any ATM machines around you . I doubted thus but decided to give it a try by contacting (smithhackingcompanyltd@gmail.com} they responded with their guidelines on how the card works. I was assured that the card can withdraw $5,000 instant per day & was credited with$50,000,000.00 so i requested for one & paid the delivery fee to obtain the card, after 24 hours later, i was shock to see the UPS agent in my resident with a parcel{card} i signed and went back inside and confirmed the card work's after the agent left. This is no doubts because i have the card & has made used of the card. This hackers are USA based hackers set out to help people with financial freedom!! Contact these email if you wants to get rich with this Via: smithhackingcompanyltd@gmail.com or WhatsApp +1(360)6370612

    RispondiElimina
  21. BE SMART AND BECOME RICH IN LESS THAN 3 DAYS....It all depends on how fast you can be to get the new PROGRAMMED blank ATM card that is capable of hacking into any ATM machine, anywhere in the world. I got to know about this BLANK ATM CARD when I was searching for job online about a month ago.. It has really changed my life for good and now I can say I'm rich and I can never be poor again. The least money I get in a month with it is about $50,000.(fifty thousand USD). Everyday I keep pumping money into my account. Though it is illegal, there is no risk of being caught, because it has been programmed in such a way that it is not traceable, it also has a technique that makes it impossible for the CCTV's to detect you.. For details on how to get yours today,email the hackers on: harrybrownn59@gmail.com Tell your loved ones too, and start to live large. That's the simple testimony of how my life changed for good... Love you all... The email address again is harrybrownn59@gmail.com

    RispondiElimina

  22. I have being hearing about this blank ATM card for a while and i never really paid any interest to it because of my doubts. Until one day i discovered a hacking guy called Mr. Oscar White, he is really good at what he is doing. Back to the point, I inquired about The Blank ATM Card. If it works or even Exist. They told me Yes and that its a card programmed for random money withdraws without being noticed and can also be used for free online purchases of any kind. This was shocking and i still had my doubts. Then i gave it a try and asked for the card and agreed to their terms and conditions. Hoping and praying it was not fake. One week later i received my card and tried with the closest ATM machine close to me, It worked like magic. I was able to withdraw up to $6000. This was unbelievable and the happiest day of my life with my girlfriend Laurel. So far i have being able to withdraw up to $78000 without any stress of being caught. I don't know why i am posting this here, i just felt this might help those of us in need of financial stability. blank ATM has really change my life. If you want to contact them, Here is the email address: oscarwhitehackersworld@gmail.com or what's-app him +1(513)-299-8247 .

    RispondiElimina
  23. Hire a personal professional hacker
    Do let anybody befuddle you,cause there are a lot of scammers claiming to be what they are not
    we’ve received bitter mails of Jobs attempts proposals from most clients with hacking issues but never get close to having them done,where client expresses annoyance or dissatisfaction of unethical behaviors of scammers, thereby wasting a lot $ in the process
    We’ve made tenacious efforts to help those who are victims of this fleas get off their traumatic feeling of loss.
    we make all hacking problems easy to solve with brilliants hackers
    ☑️Below Is A Full List Of Our Services:
    ▪️RECOVERY OF STOLEN FUNDS .
    ▪️FUNDS RECOVERY ON SCAM INVESTMENTS, BINARY OPTIONS TRADING and ALL TYPES OF SCAMS.
    ▪️WEBSITE AND DATABASE HACKING ­čĺ╗
    ▪️CREDIT REPAIR. ­čĺ│
    ▪️PHONE HACKING & CLONING
    ▪️CLEARING OF CRIMINAL RECORDS ❌
    ▪️SOCIAL MEDIA ACCOUNTS HACKING ­čô▒
    ▪️RECOVERY OF DELETED FILES ­čôĄ
    ▪️LOCATION TRACKING ­čôî
    ▪️BITCOIN MINING ⛏And lot More.
    CONTACT:
    www.alienmanhackers.xyz
    ALIENMANH4CCK@PROTONMAIL.com
    TELEGRAM: ALIENM4NHACKERS
    CALL OR TEXT: +13603603875
    SIGNAL : +16469229088

    RispondiElimina
  24. I am very happy, I'm a living testimony. I got my blank ATM card last week from Jim Lee hackers. At first when I was in doubt. Then I decided to give it a trial and to my surprise the card was delivered, I went testing it on the ATM machine. I was shocked when I used it to withdraw $1500 and now I have withdrawn $20,000 in total. The card is real, I'm so happy thank you Jim Lee hackers. If interested you can email: jimleehacker07@gmail.com

    RispondiElimina
  25. I was searching for a loan to sort out my bills & debts, then I saw comments about Blank ATM Credit Cards that can be hacked to withdraw money from any ATM machines around you . I doubted this but decided to give it a try by contacting { officialblankatmservice@gmail.com} they responded with their guidelines on how the card works. I was assured that the card can withdraw $5,000 instant per day & was credited with $50,000,000.00 so i requested for one & paid the delivery fee to obtain the card, after 24 hours later, i was shock to see the UPS agent in my resident with a parcel {card} i signed and went back inside to pick up my car key and drove to a nearest ATM machine to confirmed if the card really work to my greatest surprise it did.. This is no doubt because I have the card & have made use of the card. These hackers are UK based hackers set out to help people with financial freedom!! Contact them via email: officialblankatmservice@gmail.com or WhatsApp +447937001817 if you want to get rich.

    RispondiElimina
  26. toptan i├ž giyim tercih etmenizin sebebi kaliteyi ucuza sat─▒n alabilmektir. ├ťr├╝nler yine orjinaldir ve size sorun ya┼čatmaz. Yine de bilinen tekstil markalar─▒n─▒ tercih etmelisiniz.

    Digit├╝rk ba┼čvuru g├╝ncel adresine ho┼čgeldiniz. Hemen ba┼čvuru yaparsan─▒z an─▒nda kurulum yapmaktay─▒z.

    tutku i├ž giyim T├╝rkiye'nin ├Ânde gelen i├ž giyim markalar─▒ndan birisi olmas─▒n─▒n yan─▒ s─▒ra en ├žok satan markalardan birisidir. ├ťr├╝nleri hem ├žok kalitelidir hem de pamuk kullan─▒m─▒ daha fazlad─▒r.

    nbb s├╝tyen hem kaliteli hem de uygun fiyatl─▒ s├╝tyenler ├╝retmektedir. S├╝tyene ek olarak s├╝tyen tak─▒m─▒ ve jartiyer gibi ├╝r├╝nleri de mevcuttur. ├ľzellikle Avrupa ve Orta Do─ču'da ├žok├ža tercih edilmektedir.

    yeni inci s├╝tyen kaliteyi ucuz olarak sizlere ula┼čt─▒rmaktad─▒r. ├çok ├že┼čitli s├╝tyen varyantlar─▒ mevcuttur. i├ž giyime damga vuran markalardan biridir ve genellikle Avrupa'da ismi s─▒kl─▒kla duyulur.

    i├ž giyim ├╝r├╝nlerine her zaman dikkat etmemiz gerekmektedir. ├ťretimde kullan─▒lan malzemelerin kullan─▒m oranlar─▒, kuma┼č─▒n esnekli─či, ├žekmezlik testi gibi bir├žok unsuru ayn─▒ anda de─čerlendirerek se├žim yapmal─▒y─▒z.

    i├ž giyim bayanlar─▒n erkeklere g├Âre daha dikkatli olduklar─▒ bir aland─▒r. Erkeklere g├Âre daha ├Âzenli ve daha se├žici davran─▒rlar. Biliyorlar ki i├ž giyimde kulland─▒klar─▒ ┼čeyler kafalar─▒ndaki ve ruhlar─▒ndaki ├Âzellikleri d─▒┼ča vururlar.

    RispondiElimina
  27. Hello guys my name is Scott Mcall I wanted to share a testimony of how a good hacker help in making my life a better one I am glad I met them guys I got $15,000USD from them guys If you are interested they perform various hack and they are legit 100%
    BITCOIN HACK
    PAYPAL HACK
    BANK ACCOUNT HACK
    WESTERN UNION HACK
    BLANK HACK ETC.......

    Guys if you are interested in any of this contact them because they are very legit and I trust them visit
    Jaxononlinehackers@gmail.com
    WhatsApp: +12192714465

    Contact them today and be happy

    RispondiElimina
  28. HAVE YOU BEEN IN SEARCH FOR GENUINE HACKER'S ONLINE?. HAVE YOU LOST YOUR MONEY TO BINARY OPTION SCAM OR ANY ONLINE SCAM WHATSOEVER?. WELL, YOU HAVE FOUND REDEMPTION .

    BLANK ATM CARD :We have specially programmed BLANK ATM CARDS that can be used to hack any ATM machine, these ATM cards can be used to withdraw at the ATM or swipe, stores and outlets. We sell this BLANK CARDS to all our customers and interested buyers worldwide, the BLANK CARDS has a daily withdrawal limit of $5000 in ATM and up to $50,000 spending limit in stores. and also if you are in need of any other cyber hacking services, we are here for you at any time any day. Email :
    Email:Creditcards.atm@gmail.com
    WhatsApp: +1(539) 888-2243

    -hack into any kind of phone
    _Increase Credit Scores
    _western union, bitcoin and money gram hacking
    _criminal records deletion
    _BLANK ATM/CREDIT CARDS
    _Hacking of phones(that of your spouse, boss, friends, and see whatever is being discussed behind your back)
    _Security system hacking...and so much more. Contact THEM now and get whatever you want at
    Email:Creditcards.atm@gmail.com
    WhatsApp: +1(539) 888-2243
    You can also contact us on Telegram.
    ­čîł­čöą­čîĆ­čîÄ­čîŹ✔­čĺ░­čĺ┤­čĺÁ­čĺ­č媭čĺĚ­čôę­čô«­čôŁ­čôŹ­čôî­čôŐ­čôë­čôł

    RispondiElimina
  29. Get informations on how to catch a cheating partner without trace of being caught in the process just email and expert I have been using his services for 3 years now and I have got nothing but the best email spyexpert0@gmail.com and be among the people with good reviews about spyexpert0@gmail.com.

    RispondiElimina
  30. I hired darkhatthacker@gmail.com to hack 2 cell phones for me because have been suspecting this 2 victim’s for a while now ever since I lost my husband behold after darkhatthacker@gmail.com hacked into this 2 cell phones it came to my notice that this were my husband side chicks before he died I browsed through there cell phone remotely with the help of this hacker I found out that this 2 were the once that killed my husband just because he decided to break up with them. Am so so grateful to you darkhatthacker@gmail.com thank you so much.

    RispondiElimina
  31. Ucuz, kaliteli ve organik sosyal medya hizmetleri sat─▒n almak i├žin Ravje Medyay─▒ tercih edebilir ve sosyal medya hesaplar─▒n─▒ h─▒zla b├╝y├╝tebilirsin. Ravje Medya ile sosyal medya hesaplar─▒n─▒ organik ve ger├žek ki┼čiler ile geli┼čtirebilir, ki┼čisel ya da ticari hesaplar─▒n i├žin Ravje Medyay─▒ tercih edebilirsin. Ravje Medya internet sitesine giri┼č yapmak i├žin hemen t─▒kla: ravje.com

    ─░nstagram takip├ži sat─▒n almak i├žin Ravje Medya hizmetlerini tercih edebilir, g├╝venilir ve ger├žek takip├žilere Ravje Medya ile ula┼čabilirsin. ─░nstagram takip├ži sat─▒n almak art─▒k Ravje Medya ile olduk├ža g├╝venilir. Hemen instagram takip├ži sat─▒n almak i├žin Ravje Medyan─▒n ilgili sayfas─▒n─▒ ziyaret et: instagram takip├ži sat─▒n al

    Tiktok takip├ži sat─▒n al istiyorsan tercihini Ravje Medya yap! Ravje Medya uzman kadrosu ve profesyonel ekibi ile sizlere Tiktok takip├ži sat─▒n alma hizmetide sunmaktad─▒r. Tiktok takip├ži sat─▒n almak i├žin hemen t─▒kla: tiktok takip├ži sat─▒n al

    ─░nstagram be─čeni sat─▒n almak i├žin Ravje medya instagram be─čeni sat─▒n al sayfas─▒na giri┼č yap, h─▒zl─▒ ve kaliteli instagram be─čeni sat─▒n al: instagram be─čeni sat─▒n al

    Youtube izlenme sat─▒n al sayfas─▒ ile hemen youtube izlenme sat─▒n al! Ravje medya kalitesi ile hemen youtube izlenme sat─▒n almak i├žin t─▒klay─▒n: youtube izlenme sat─▒n al

    Twitter takip├ži sat─▒n almak istiyorsan Ravje medya twitter takip├ži sat─▒n al sayfas─▒na t─▒kla, Ravje medya g├╝vencesi ile organik twitter takip├ži sat─▒n al: twitter takip├ži sat─▒n al

    RispondiElimina
  32. You can make a video for youtube how to do it. On this site https://soclikes.com/buy-youtube-views you can get many views for your video

    RispondiElimina
  33. I was in so much debit and needed a way to clear it up because my life was in danger, then I saw comments about cloned ATM Credit Cards that can be programmed to hack into and withdraw money from any ATM machines around you . I doubted this but decided to give it a try by contacting {skylinktechnes@yahoo.com} they responded with their guidelines on how the card works. I was assured that the card can withdraw $5,000 instant per day and it had a usage limit of 12 months. So I requested one & paid the delivery fee to obtain the card, i was shocked to see the parcel{card} delivered at my doorstep. I picked it up and went back inside and confirmed the workings and genuinity of the card at the atm machine closest to me. This is no doubt because I have the card & have made use of the card countless times without any complaints. These hackers are USA based hackers set out to help people with financial freedom!! Contact these email if you wants to get rich with this Via email skylinktechnes@yahoo.com whatsapp/t: +1(213)785-1553

    RispondiElimina
  34. This is what I do first before getting into any relationship I investigate who that person really is, if she is a chronic cheat or a lair all I do first is email spyexpert0@gmail.com to gain access to her phone to know if I can truly trust her even if am out of the state. After my Investigations I got access to her phone without notifications and it happens that my girl friend has been sleeping with my dad even before I met her and after I met her she kept on doing shit with my dad but am not really pained because before I get my heart so deep in a relationship I contact spyexpert0@gmail.com first to run a phone hack to know that person very very well. All I will say is am so so proud of you spyexpert0@gmail.com you never let me down not just me but your clients also.

    RispondiElimina
  35. All thanks to Mr Anderson for helping with my profits and making my fifth withdrawal possible. I'm here to share an amazing life changing opportunity with you. its called Bitcoin / Forex trading options. it is a highly lucrative business which can earn you as much as $2,570 in a week from an initial investment of just $200. I am living proof of this great business opportunity. If anyone is interested in trading on bitcoin or any cryptocurrency and want a successful trade without losing notify Mr Anderson now.Whatsapp: (+447883246472 )
    Email: tdameritrade077@gmail.com

    RispondiElimina
  36. I was a victim of scam whereby i lost all my saving to the scammer, i was into depression cause i found myself losing my saving to a scammer all because i want to earn more. For a long time i searched for help. During this time it was not easy living. But it didn't last long as INSTANT RECOVERY came into my life and change my financial problem. He helped me recover my money from the scammer without asking for an upfront payment. If there is other ways to appreciate them more than paying their service fee which i paid after money was fully recovered to me and writing a short article about them then i will. I'm writing this out here cause of the victims who are yet to get help, victims around the world have the right to get access their help. You can reach him on ( *[INSTANTRECOVERY12]** @gmail.com)

    RispondiElimina