# Baseline notes — 2026-09-18 Võ Công Truyền Kỳ

Source: `C:\JXVCTK\JxVoCongTruyenKy`
Purpose: so sánh nếu AutoUpdate đẩy file mới / nhét stealer.

## Defender (đã cách ly cùng ngày)

| File | Threat | ThreatID | Severity |
|---|---|---|---|
| `_AutoVLBS\VLBS13\core.dll` | Trojan:Win32/tenga | 2147832057 | 5 |
| `_TatAntiVirut\DefenderControl\DefenderControl.exe` | HackTool:Win32/Defendercontrol!pz | 2147890903 | 4 |
| `_TatAntiVirut\DefenderControl21\dControl.exe` | HackTool:Win32/DefenderControl!MSR | 2147754900 | 4 |
| `_AutoVLBS\VLBS19\VLBS19.zip` + Dai | Tool:AndroidOS/Multiverze | 304861 | 2 (có thể FP) |

## Hash trọng yếu (trước/còn trên đĩa)

| File | SHA256 |
|---|---|
| AutoUpdateVCTK.exe | 63049DBA6D8E35387A17770B790788E630A3031E132709FE65B9069C5635D5C5 |
| KY_VCTK_CTCX_NEW.exe | e808b1b6dedb0f684880c6aeb47032efc0e63f54d5fc14c9c5f1953d025be7fe (size 15813120). Hash lúc soi đầu buổi: CB8AB6D044805A8CFF4628F252AD6F09E72358225463CCA8DF9A5B666E8E3AD6 (size 15582720) — **file đã đổi trong cùng ngày**, có thể updater. |
| winmm.dll (VLBS19Dai) | 92858E63788EF967961D7A41EE1A3051E845657A181430A00FD68D9DB6942B7C |
| VLAutoPr.exe | DBC66C16C5DDC72EB4398A80E2A34DE9E3078D0F86D12836B9D3A208F0B3D50D |
| VLHookPr.dll | 289C8C6FDDDE6F41438F66F5A3E175748EF94497F8473AF9A0229FDEC9566D15 |
| VLBS19 core.dll | E89660EC1355DBB1F3B3B08AE5828B3D59964947A267660B4AD3009CC3D8F8B2 |
| VietGuardJX.sys | 8FCF5088FFD8E0FFA20C418727A5401105052D0E38EED545710D378B08AA8CE6 |
| game.exe | 92E4F6E133745DBA22EA8F7E755CD4A2C98DC821569D3D517969FDF22CEAB8F3 |
| add.bat | 288E6389A4953DDD72A5F01AF7420FF99F62FE5A20431E637523771F3A34C8EC |

MD5 AutoUpdateVCTK.exe: B0447117EB9DB5B563F932BEBFEE69A0

## Mạng quan sát được (static)

- https://update.vctk.me/Update
- https://update.vctk.me/News.txt
- http://updatectc4.cuulongtruyenky.com/  (msvc8p.dll giả INI)
- https://vocongtruyenky.net/
- https://jxvocongtruyenky.com/
- http://congthanhchienxua.com
- http://vietguards.com

## Ghidra 12.1.3 (headless, 2026-09-18)

- AutoUpdateVCTK.exe: WinHTTP download + ShellExecute mở file local; Crypt* là hash, không CryptUnprotectData; GetAsyncKeyState(0x11)=Ctrl trong UI MFC. Không chuỗi Chrome/Discord/ví.
- VLHookPr.dll: OpenProcess(0x410) + ReadProcessMemory theo message 0x464–0x46e; hotkey Ctrl+A/B/G... trong cửa sổ game. Không CreateRemoteThread/WinHTTP.
- VLAutoPr.exe: SetWindowsHookExW trên *thread hiện tại* (WH_CBT=5, WH_MSGFILTER=-1, WH_MOUSE=7) — hook UI auto, không WH_KEYBOARD_LL toàn cục.
- core.dll VLBS19: packer, .text RWX, import LoadLibrary/GetProcAddress/VirtualAlloc — Ghidra không dịch được ruột.
- TrainJX.exe: .NET cracker `CrackVLBS13` / `CrackVLBS19v3` (WriteProcessMemory, genKeyVLBS) — crack license auto, không stealer.
- KY_VCTK_CTCX_NEW.exe: **không decompile được** — Themida/VMProtect-like (section tên trống, entropy ~8, chỉ import LoadLibraryA/GetProcAddress/ExitProcess/MessageBoxA). Lần sau nếu hash đổi = payload mới.

## Hành vi nguy hiểm còn lại (không phải stealer đã thấy)

- `add.bat` thêm exclusion Defender cho cả thư mục
- `_TatAntiVirut` (DefenderControl)
- `AutoHosts.bat` ghi đè hosts
- `Game_film.exe` / `engine.dll` HashMismatch chữ ký Kingsoft
- `VietGuardJX.sys` là GUI exe đổi đuôi, không phải kernel driver
- Updater có thể đẩy payload mới qua update.vctk.me

## File không copy nguyên bản

Binary lớn chỉ lưu hash (xem inventory). Config/script nhỏ nằm trong `configs/`. Decompile Ghidra trong `ghidra/`.
