• XSS.stack #1 – первый литературный журнал от юзеров форума

SpyWare C&C

В этой теме можно использовать автоматический гарант!

Статус
Закрыто для дальнейших ответов.

bre4ck1ng

floppy-диск
Пользователь
Регистрация
29.09.2024
Сообщения
7
Реакции
0
Presentation:

I present a spyware made from scratch and built in "C", apart from being a SpyWare, it can be categorised as a C&C, by default 5 simultaneous connections are allowed.

Functions:

This SpyWare/C&C is full of options, we can do things like this:

  1. Shell mode: Powershell
  2. Exec comands in NO shell mode
  3. Low persistence: No admin required
  4. High Persistence: Admin required (Service based, when persistence runs the connection is from NT AUTHORITY/System)
  5. Download a file (Without size limit and a good looking progress bar)
  6. Upload a file (Without size limit and a good looking progress bar)
  7. Get system information (Not to much, Ram, full disk space, free disk space, PC name, processor, ...)
  8. Check if the file was run as admin
  9. Block peripherals
  10. Unblock peripherals
  11. Dump passwords (Edge/Brave/Chrome, it can be adapted for more browsers, its built from scratch understanding how the browser store the passwords)
  12. Display a message box with a message
  13. Make and download a screenshot (all in one function)
  14. Record "x" seconds of audio from the mic
  15. Scan the network of the victim (give the hosts in it)
  16. Scan a host in the victim network (give the open ports of the host.
  17. Detect Monero installation and steal .keys file.
  18. Detect all installed AVs on the victim
  19. Change crypto wallets if someone is copied into clipboard (Identifies ETH, BTC, XRP and LTC wallets.)
  20. Help commands to show aviable commands (on serves)

Remarcable:

  • We have two main files, the server and the client. The server is modified to be beautiful and easy to use with help messages.
  • The server creates a folder called DATA in the same location where the server is running, where, sectioned by the IP addresses of the sessions, the downloaded files are stored.
  • The malware once executed, as long as the process has not been closed, can close the .exe on the server that the victim will try to connect to again and again, giving a break of 10s.
  • We have commands to manage sessions by displaying the session id and the ip address of the session.
  • Cache memory on session for those command that the output doesn't change. Like: check avs, sysinformation, scan network of the host, ...
  • If the server got crash or stuck u can use [CTRL + C] to close and reopen, the client when notice that the connection has close it tries to connnect another time.
Suggestions can be requested, if you want a customised function just for you the price will be discussed and said in advance.

Basic Plans:

  • Basic 1: Get malware and server in binary format with 5 simultaneous connections and only available (shell, dowload/upload, lowpersistence, password dump) (Changing the IP of attacker)
    • Price: 200€

  • Basic 2: Get malware and server in binary format with 20 simultaneous connections and only available (shell, exec, dowload/upload, lowpersistence, check, check avs, password dump) (Changing the IP of attacker and the crypto wallets)
    • Price: 250€

  • Basic 3: Get malware and server in binary format with 50 simultaneous connections (shell, exec, dowload/upload, sysinformation, persistence, lowpersistence, check, check avs, password dump) (Changing the IP of attacker and the wallets)
    • Price: 300€

Advanced Plans:
  • Advanced 1: Get malware and server in binary format with 100 simultaneous connections with all function available (Changing the IP of attacker and the crypto wallets to change in clipboard)
    • Price: 400€

  • Advanced 2: Get malware and server in binary format with 500 simultaneous connections with all function available (Changing the IP of attacker and the crypto wallets to change in clipboard)
    • Price: 450€

  • Advanced 3: Get malware and server in binary format with 1000 simultaneous connections with all function available (Changing the IP of attacker and the crypto wallets to change in clipboard)
    • Price: 500€

For those who choose an advanced plan, updates will be sent as ‘support’ for the malware.

Master Plan:

Get the complete source code with README.md which explains step by step the following:

  • The installation of the dependencies
  • General information with all the commands and the functions of each of them
  • Preparation on both windows and linux
  • Manual compilation of the source files
  • Brief explanation of how to use NGROK or Linux VPS ass a tunnel for windows.

As an extra we share an ‘autocompile.py’ that allows to compile everything automatically when the dependencies have been installed.
  • Price: 1000€

Contact Method and Payment form:

The payment process can be do it in XMR preferably we can discuss it in PM. For contact methods i have session and qtox.
 
Could you upload photos of your cnc and might i ask why your adding a paywall to the amount of connected devices?

Also i think sales threads are meant to be here: https://xss.pro/forums/104/
Hey, i upload a photo of a test with localhost. btw I have added a paywall to the connections as I think it is a big malware that has taken me a lot of work to program it from scratch without copying other code and I don't think it is necessary for 400€ to limit the functions that the malware has.

Thank you for the clarification of the link, i do not use so much this forum.
 

Вложения

  • sample.png
    sample.png
    22.8 КБ · Просмотры: 67
Пожалуйста, обратите внимание, что пользователь заблокирован
Внесите депозит в размере 1000$
не пишите мне апелляции в личные сообщение
не создавайте новые темы

просто внесите депозит http://xssforum7mmh3n56inuf2h73hvhnzobi7h2ytb3gvklrfqm7ut3xdnyd.onion/deposit
 
Статус
Закрыто для дальнейших ответов.
Верх