Flashheart
Well-Known Member
It is always wise to use a VM, I ran the executable in a temporary sandbox and I did not encounter the issues you described.So, just a heads-up... as always, I ran this mod executable in a freshly installed Windows 10 VM, on which I had installed my usual File System Monitoring suite.
I can confirm that the executable sent by the Chinese guy on Telegram does indeed contain malicious code, which makes a number of changes to your Windows settings.
One thing it does is modifies ads in browsers so that the pages display revenue-generating ads for the Chinese hacking group.
Second thing it does is modifies Startup configuration to run something that, so far as I can see, broadcasts the fact that your computer is online as well as your IP address to some external server... I'm pretty sure (though haven't had time to dig deeper) that this would allow an attacker the ability to execute malicious instructions on your computer (even if your computer is behind a router or firewall, given that it acts as a Client not a Server).
Point being: if you've run this program to FCC unlock your drone, run a PROPER AntiVirus/AntiMalware scan on your computer immediately and clean it up.
For those whom HAVEN'T run it on their machine (yet)... be sensible: run it in a VM and terminate the VM when you're done. That way, you get the benefits without the hassle of some hacker taking advantage of you and your computer(s).
I also ran this program through Virus Total and Jotti's Malware Scan and only 26 out of 71 AV vendors reported this file as infected with a virus, the majority of AV vendors did not detect a virus or malware.