Giter Site home page Giter Site logo

mercurial-grabber's Introduction

Builder Preview

preview

Features

  • Grabs Roblox cookies from Roblox Studio
  • Grabs Minecraft sessions
  • Grabs Google Chrome passwords
  • Grabs Google Chrome cookies
  • Grabs Discord token
  • Grabs victim machine info
  • Grabs Windows product key
  • Grabs IP address, geolocation
  • Grabs screenshot
  • Anti Virutal Machine
  • Anti Debug

Customization

  • Add a custom icon
  • Custom exe name

Info

Please do not use the program maliciously. This program is intended to be used for educational purposes only. Mercurial is only used to demonstrate what type of information attackers can grab from a user's computer. This is a project was created to make it easier for malware analysts or ordinary users to understand how credential grabbing works and can be used for analysis, research, reverse engineering, or review.

What is malware?

  • Malware is a term that is used for malicious software that is designed to do damage or unwanted actions to a computer system.

An explanation of this tool:

Google Chrome always store user data in the same place, so the stealer generated by Mercurial Grabber has no problem in finding it. In theory at least, this data is stored in encrypted form. However, if the malware has already penetrated the system, then its actions are done in your name.

Therefore, the malware simply finds a way to decrypt information stored on your computer (by making it seem like thie user is requesting it) . The stealer gets all your passwords and cookies.

The tool is also able to find Roblox cookies that are stored in the Windows Registry. By running the malicious .exe file, it is able to search for the Roblox cookie. The same goes for Minecraft sessions, Discord tokens, etc since it is stored in the user's computer.

Recommended tools for testing Mercurial: (when running the produced output after building)

  • Virtualbox
  • VMware
  • Process Hacker
  • VirusTotal

Tips to check if an exe file is safe:

  • Analyze the file with VirusTotal
  • Check if the exe file has a publisher
  • Check it in a sandbox
  • Monitor the file’s network activity for strange behavior

Educational Purposes Only

This tool demonstrates and makes it easy to create your own grabber. This shows what type of information attackers can grab from a victim's computer. Only use this on your own PC and do not use it on other people maliciously.

mercurial-grabber's People

Contributors

nightfallgt avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

mercurial-grabber's Issues

Not working now

It sent system info, product key and ip adress when I tried it myself. Then second time (other person), it sent ip, system info, product key, screenshot. 3rd time, ip, password, cookies, sys info and from then it only send ip and product key... :(

DO NOT DOWNLOAD THIS

I know everyone is going to be "You are retarded this is open source", but it really isn't open source. Try compiling it yourself. It won't work, many files are hidden and many dependencies can't be reinstalled. This is malware. Do not download this or open it.

How to run it.

Please tell me how i can Run The Mercurial Grabber.

Thanks

Is this grabber Legit?

Is this real? Is there viruses or tojan? I downloaded it but I do not see any exe folder.

Cookies

Hello how do i import the cookies from cookies.txt into my browser

Virus? Or Nah

I need verification from mercurial grabber users that this is legit and this is not a virus

Password.txt is empty + 1 problem too

image

You can see the size of the password file and it doesn't have any content

AND

sometime the keylogger is not sending info...like sometime it just sent only ip address and its info while the rest of the files are not sent!

Compiled exe Virus

How would you make the exe the grabber makes be undetected by the anti-virus?

Funniest shit ever what even is this shit, took me 5 seconds to reverse and find the webhook

Well some 10 year old kids on discord is having fun making servers and trying to infect people this is pretty lame

Anyway i would suggest to spam webhooks if you find someone trying to infect people with it even though they will eventually make another webhook to receive data

while true do; proxychains curl <webhook> -XPOST -d "content=YOURGAY&username=YOURGAY&avatar=YOURGAY"; done

also you can report it directly to discord...

DO NOT DOWNLOAD!

I looked through the code, of course it is flagged by Microsoft Defender because of its predatory actions but it may also be a virus, also if you do try it out don’t open the output file to test it out as you may get a virus. My thoughts are stick to your other methods, plus nobody in there right mind will open an .exe file unless there plain as dumb.

Is that a ransomware or it isnt?

Can someone tell me is that a virus or no? Because it don't let me download it and im not sure shoud i add it in non scanned folder.

Icon

i cant seem too ad an icon of my choice or at all i get the error Attempting to compile file..

Line number 0, Error Number: CS1567, 'Error generating Win32 resource: Error reading icon 'c:\Users\dumdu\Downloads\download.ico' -- The data is invalid. ;
An error has occured when trying to compile file.

how would i fix this issue

retards using this to grab stupid kids

lmao this is the funniest shit ever, all the issues are just some braindead 10 year old skids trying to log people. I just forwarded some guy's info to the fbi after he tried to get me with this. Your anti-vm & anti-debug shit doesn't even work. and if it did you can just statically analyze it, that's how retardedly stupid this is.

roblox cookie

cant find cookie
Roblox Cookie
Unable to find cookie from Roblox Studio registry
Mercurial Grabber | github.com/nightfallgt/mercurial-grabber

it says this

How do you open it?

do i need winrar or something cuz theres no app its just a bunch of configs and stuff
image
image

Anti debug and anti vm

Hey, when I only check anti VM, the grabber doesn't work. When I only check anti Debug, the grabber is working but the anti debug not if you can check this I'm not a pro to do that so thats why I do an issue

Tutorial

Need a complete tutorial on how to build or install it or something in text so others can also see i we dont know how to use

.

.

not working

currently getting a error message saying invalid resx file please fix and make this usable again

Anti debug dont work FIX

the anti debug as i have seen it doesnt work as my webhook got raided and the guy who raided it send pics of the code in the logger hahaa

Password error

Even though the pc have password, it sent a 0.00B txt file and when we download it, it says download failed

not working

When i open the Mercurial.sln i dont see the form design ( buttons etc)
and when i click start show an error, how can i fix that?
image
image
image

Download

I downloaded the zip file and extracted it, but now how do i go through the instalation?

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.