• XSS.stack #1 – первый литературный журнал от юзеров форума

x64 PE Cryptor | FUD | Pesieve Bypass | mimikatz demo

В этой теме можно использовать автоматический гарант!

Статус
Закрыто для дальнейших ответов.

NullMe

CD-диск
Пользователь
Регистрация
06.05.2022
Сообщения
16
Реакции
3
couple of days ago i posted that i was looking for a job (malware development in c/asm), in which i stated that i was building a exe cryptor, at that time it was unfinished, and since i didnt get any suitable offers, i decided to finish the cryptor asap and post its features here:

checkzilla (1/19) [the 1 is unkown results] : https://checkzilla.io/scan/ce6b85aa-624a-40a7-a39d-49e3303c4de2
mimikatz Pesieve bypass demo :


mimikatz Pesieve bypass demo (higher resolution) : https://mega.nz/file/m8c0AB7J#Qa6ZgXBhLkZ1vFt2aZ1-tt3cj8c6fShZB0vXERIE1xo



features:
- No Rwx sections
- manual & custom reallocation / iat fixing (from 0)
- syscalls
- no exported functions (the one exported are on purpose)
- handles only x64 exe NATIVE files
- no crt functions
- aes encryption
- so far, its fud
- built with c and asm (visual studio 2017 compiler)
- can add additional features / upgrades, in case of a deal with the customer
- selling with the source code
- selling for 3 customers MAX
- price : 300$ including a builder, and ill set up the environment in case the customer wanted so

contact me via dm or via:
JABBER nullstack@jabb3r.org
TOX: 7122941BC23CBF2F118CD826A1B36F17532E2F5C8D78CAABB5D6EA5C822E39473D1B67B41AC9
 
Последнее редактирование:
update:
- the cryptor is no longer using aes algorithm, we are using a custom compression algorithm that is able to compress your exe to 40% its size
- the total size of the stub is now : 21kb + (40% your exe size)
 
th3tr0ll i dont mind escrow, and i honestly didnt try it with Kaspersky, but if you are looking for loading your c2's agent, i recommend checking out something like this for better runtime evasion, you can dm me for more details, i'll be happy to help
 
Статус
Закрыто для дальнейших ответов.
Верх