• XSS.stack #1 – первый литературный журнал от юзеров форума

[SERVICE] Phantom Javascript file for mass spreading/spamming [FUD]

В этой теме можно использовать автоматический гарант!

Статус
Закрыто для дальнейших ответов.

AP3XX

CD-диск
Пользователь
Регистрация
31.08.2024
Сообщения
11
Реакции
0
Гарант сделки
1
Цена
$150 or $350
Контакты
telegram @WERFAULT
Note that even though the inside of protected zip files is being scanned by mail security, Phantom js dropper is guaranteed to bypass majority of mail scanners (excluding honeypot email servers, i.e email servers hosted by Google, Microsoft, and other popular email spamtraps

Features:
✅ FUD LPE (UAC Admin privilege escalation) tested successfully on 32bit & 64bit PC
✅ fileless execution for all encrypted powershell commands
✅ (Optional) Decoy pdf file (or any file u want) will be first executed to deceive the target, then your payload will be executed in the background
✅ Bypass Windows Defender
✅ Long-lasting FUD. When you spread correctly, file can remain FUD after continuously spreading to business emails for more than a week
✅ Bypass WD machine learning Behavior detection
✅ Each js file is completely unique
✅ Runtime FUD
✅ Bypass AMSI
✅ Scantime FUD
✅ target is WD however most AV are bypassed
✅ (Optional) feature to disable windows defender notification (only in the UAC version)
✅ double layer obfuscation for phantom js build which helps it last longer and more difficult to reverse by threat researchers.

Stubborn WD detection bypassed:
⚡ Wacatac detection (All variants)
⚡ Bearfoos detection (All variants)
⚡ Behavior detection (All variants)
⚡ Sabisk detection (All variants)

JS dropper Price:
6 unique builds - Only encrypted Javascript no UAC - $150
6 unique builds - encrypted Javascript + UAC (32bit & 64bit) - $350

Preview
https://ibb.co/9Z8pSY6
======================
Both js variants are not the same they have different functions & behavior

Phantom Js + UAC variant does not drop any malware directly on disk which makes it more powerful. All it does is create defender exclusion & create persistence for your file using the url u send me. So once exclusion & persistence is enabled your file must execute with admin rights no matter what

But the variant without UAC does a download & execute operation without UAC exclusion & persistence

======================

reFUD (of same file): $40
reFUD available on request

Send me dm telegram @WERFAULT

TOS:
✅ We are not responsible for how you use this product. This product is available for educational purposes only
❌ It is forbidden to send Phantom js dropper to email servers known to be spam traps. Only business emails recommended to spread
✅ Phantom js dropper must be spread to only business email with business domains & free from spam traps (if you want your file to stay FUD for long)
❌ Phantom js dropper must NEVER be downloaded directly through browser (it must be password protected in zip file). Because it is heavily obfuscated js file, browser may flag the file even when it's FUD
✅ It is recommended to use a spam trap remover tool to remove bad (spam trap) emails & NEVER spread Phantom js dropper to those bad emails
❌ It is forbidden to upload phantom js file to (free & public) file hosting services
✅ Highly recommended to host phantom js file only on Apache self hosting with your own vps
✅ Paid customers will provide their decoy file & a direct link to their payload, then get their unique js file build
✅ Highly recommend to spread phantom js inside a protected zip file for high click rate


As a bonus to customers, if you have purchased phantom js dropper twice, on your third & subsequent purchase you will get 10 unique builds instead of 6.

 
Service Update ♻️


UAC script now encrypted because of Windows defender update that caused stubborn detection.

Now FUD as before 💯💯



recommend users to refud if you need the latest build
 
Service Update ♻️

💡 All features working perfectly 💯

💡 This is one of the few products that guarantee long lasting FUD as long as you follow my spreading guide & spread correctly.

💡 According to my tests, by spreading js file FUD lasts weeks & still successfully infect PC weeks after spreading


Proof of work with latest Remcos version

 
Phantom Javascript Price Update:

8 unique builds - Only encrypted Javascript - $150
8 unique builds - encrypted Javascript + UAC (32bit & 64bit) - $350
 
Image: https://ibb.co/vC5p2rcL

Service Update ♻️

💡 New improved Phantom js last for weeks or more depending on how you spread
💡 Phantom js encryption/obfuscation has been updated
💡Powershell encryption algorithm updated to defend against latest AV updates
💡 All features working perfectly 💯
 
Service Update ♻️


💡 Highly optimized in-memory/fileless execution of powershell commands
💡 Phantom js minimal updates to ensure more stability during execution

💡 Phantom js encryption/obfuscation has been updated

💡 All other features working perfectly 💯
 
Price Update ♻️

A lot of old customers who spread a lot request price update so now you get it

Phantom encrypted Javascript Price Update:
5 unique builds - Only encrypted Javascript - $130
————————————-
5 unique builds - encrypted Javascript ➕ UAC (32bit & 64bit) - $130
15 unique builds - encrypted Javascript ➕ UAC (32bit & 64bit) - $400

Pm me on my new telegram: https://t.me/phantomproducts
 
Статус
Закрыто для дальнейших ответов.
Верх