• XSS.stack #1 – первый литературный журнал от юзеров форума

Gacrux Bot Loader

В этой теме можно использовать автоматический гарант!

txddev

floppy-диск
Пользователь
Регистрация
05.08.2020
Сообщения
7
Реакции
1
Депозит
0.0004
[SALE] GACRUX Bot, resident loader
-Written in C++/C/ASM
-Bin size ~60kb
-No CRT; pure WINAPI.
-Full unicode support, compatibility windows 7+, x32/x64.
-Working in trusted process
-HTTP & HTTPS support (self signed cert work too)
-Communication encrypted
-Support for 5 C&C URLs
-Installation into system
-Hidden startup (Not visible to user, ever, or av products until shutdown)
-Small ring3 rootkit to hide all files of bot (x32/x64)
-Ability to download & execute, run local process, update bot, uninstall
-Tasks for running files support commandline parameters
-Protection of sandboxes, vms, debuggers and other analysis
-Various other measures to harden reversing and analysis
-Additional plugins such as stealer, backconnect.
-Plugins are executed in memory and never touch disk
-Secure C&C Panel with Captcha
-Filters for task execution (By country, location, OS, arch)
-Statistics

Pricing
Bot: 350$
Rebuild binary: 30$

Minor updates are free, major ones are case by case fee.

(Additional plugins available, do not increase bot size
executed in memory; crypting not required)
Stealer: 100$
BackConnect: 50$

Stealer details
-Grabs passwords, cookies, history of browsers
-Chrome, Firefox, Internet Explorer, Microsoft Edge
-Grabs all Chrome based browser 20+
-Grabs all Firefox based browsers 6+
-Desktop screenshot

Panel Screenshots
Login: https://pasteboard.co/JjUGUqG.png
Bots: https://pasteboard.co/JjUH6jx.png
Worldmap: https://pasteboard.co/JjFDI0D.png
Stats: https://pasteboard.co/JjFDZgX.png
Tasks: https://pasteboard.co/JjUHjVo.png
Task execution filters: https://pasteboard.co/JjUHt6Q.png

Runtime scan of bot (with crypt)
-Comodo is sandbox, not detection
-Sophos is static detect, (FROM crypt)
-KIS detection is invalid.

Kaspersky rescan (CLEAN)

I can work with guarantor, at the expense of the buyer.

Contact & support:

txd@exploit.im (OTR)
 
Пожалуйста, обратите внимание, что пользователь заблокирован
Последнее редактирование:
https://dyncheck.com/scan/id/8156d76707b4fddc8ad8f9fa55992c8f
Данный скан фуфло по своей сути ибо софт не отработал.

Чем данный софт лучше триумфа или буера?
What makes you think the software did not work?
This specific binary after crypt was tested multiple times before and after scan to ensure the bot was working correctly, and it was.
 
I have purchased this botnet and can confirm it works 100%.

The seller was very helpful in getting the panel up and running and there are constant improvements that are made.

Seller also helped with getting the file crypted properly so definitely not a scam.
 
Последнее редактирование:
What makes you think the software did not work?
This specific binary after crypt was tested multiple times before and after scan to ensure the bot was working correctly, and it was.
He didn't say that the software did not work. He said, that it is not a legitimate check.
The main reason is because of this: "Internet Connection: block".

Like, you are selling a product that highly relies on a back-connect reply from a machine, but hasn't tested this part of functionality... ?
 
Обязательно используйте гарант. Отзыв от юзера с дневной регой не внушает доверия, мягко говоря.

@txddev make a $500 deposit.
 
Пожалуйста, обратите внимание, что пользователь заблокирован
-Hidden startup (Not visible to user, ever, or av products until shutdown)
Эта что за магия такая нука?
 
Пожалуйста, обратите внимание, что пользователь заблокирован
version 1.4.1.0
-Added deletion of the original file during install.
-Rewrote loading mechanism for increased stability.
-Files that are not executables are now properly launched, this works well with scripts as well.
-Several bugs and memory leaks fixed along with few improvements.
-Added ability to run dll files via rundll32.
 


Напишите ответ...
Верх