• XSS.stack #1 – первый литературный журнал от юзеров форума

PGCrypt - FUD Crypter PE32/64bit EXE/DLL/Driver

В этой теме можно использовать автоматический гарант!

best.krypt

floppy-диск
Пользователь
Регистрация
11.01.2013
Сообщения
1
Реакции
0
PGCrypt - Crypter for serious business
The first and only one crypter support: 64bit PE and Driver

5 crypts will be given to Moderator/Staff of xss.pro/ for verification. Please contact me.

PGCrypt Features

* C/C++ & ASM
* FUD/UD at Runtime and scantime. (always 0 or less than 2, and no major AV detection)
* Stubless and Polymorphic - each and every built file is tolally unique.
* Not an USG
* Supports DLL/EXE and Drivers.
* Compatible with: Zeus, SpyEyes, Andromeda, Pony, SmokeLoader, Carberp, TDL, ZeroAcess, ServU backdoor, any other loaders, RATs, Fake AV / Ransoms / Lockers, ..
* Exetremly high execution rates ~95%-100%, even on Zeus
Ref: from boed: http://trojanforge.com/showthread.php?t=22...ull=1#post18774
Ref: from Stanislav: http://trojanforge.com/showthread.php?t=22...ull=1#post19362
* Supports x86/amd64.
* Support both PE 32bit and PE 64bit files.
* Compatible with 2000/XP/Vista/Win7/Win8
* Supports already packed files (UPX, PECompact, etc,.) with Overlay data
* Support command line
* Size varies from 40 - 900KB depends on polymorphic configuration
* No startup & install, cloner or binder yet.
* Can generate high amount of crypts in short time. No, you don't have to wait.


The different specs of PGCrypt to other crypters available on the market is its strong polymorphic and (should be) metamorphic crypt engine and its supports over PE32 and PE64 files, both EXE/DLL and especially Driver. AFAIK there's no driver crypter available to the public till now. Your kernel mode rootkits should be safe from AV scanners from now on.

Beside that, in my experience, all other crypters only support PE32 x86 files although they describe those have 64bit support. Actually, those crypters only allow PE32 file run on emulator WOW64 platform of 64bit Windows, therefore it is impossible for them to execute/inject themselves inside other real 64bit processes like explorer.exe or IE 64bit. PE64 will be the future, and so are RATs, Adwares. If you have 64bit FormGrabber, Stealer DLL, BHO Adwares and need to inject to IE or any other 64bit browser, then PGCrypt is your perfect solution.

Price
- EXE/DLL
Per crypt: 10$
5 files: 48$
10 files: 92$
20 files: 170$
100 files: 500$

- Driver:
N/A - will be sale on Jan 22 2013

Recrypt on a same file: 1 FREE, 2$ for next time crypt.

Payment
WMZ/LR

Best deal & Offers / Weekly / Monthly / Other Bulk Plans:
-----
Jabber: bestkrypt@rkquery.de
ICQ: 650034693
-----


DEMO:

Random APIs, logics and variable types

2qxb78z.jpg

---
Random arithmethic FPU math op.

bi8g47.jpg

--
One more sample

2ld9cop.jpg


PE64 crypted sample: polymorphic instructions with random logic, variable types and random fake API calls

il9m3l.jpg


2q2iwx1.jpg

----
 


Напишите ответ...
Верх