• XSS.stack #1 – первый литературный журнал от юзеров форума

Storm FUD exe dropper [PRIVATE]

В этой теме можно использовать автоматический гарант!

V3SP3R

ripper
КИДАЛА
Регистрация
23.07.2021
Сообщения
52
Реакции
5
Гарант сделки
3
Пожалуйста, обратите внимание, что пользователь заблокирован
Providing FUD dropper service to bypass WD, AMSI, & smart screen. Storm dropper will add exclusion path to WD exclusion list then execute your payload inside the excluded path. All SILENT & FUD & fully customizable to your specific desires.
Storm dropper features
✅ Decoy file execution
✅ Each build is custom & handmade with unique file signature & metadata to help your file last long
✅ Bypass WD, AMSI, & smart screen 💯
✅ WD exclusion. All SILENT 💯
✅ Bypass most other AV
✅ Startup persistence
✅ Longtime FUD (if used carefully)
✅ Bypass chrome warning inside zip with no password.
✅ Custom build request is welcome
✅ Storm dropper Persistence
✅ Compatible with any executable (Native/.Net)

Price: $200 first time build & $80 reFUD of same file


Escrow accepted

Tg: @b2kky55
 
i paid 200 here is my review:
It does not bypass smartscreen at all, it will only bypass when put the exe inside zip and opened the zip with winrar
Files are detected by wd and blocked by chrome in few hours even without using them in traffic
overall very bad experience with actor its wastage of money
 
bypass smartscreen
theres no way to bypass smartscreen programatically, idk how people still buying software that contains such a feature, same with chrome alert

question to you, how u accept the escrow deal, if all basic functionallity isn't works at all
 
theres no way to bypass smartscreen programatically, idk how people still buying software that contains such a feature, same with chrome alert

question to you, how u accept the escrow deal, if all basic functionallity isn't works at all
i wont lie but i had purchased a dropper before with +- same price and with spoofed certificate it was bypassing chrome and smartscreen without any issue. This actor also use the spoofed certs but direct exe did not bypass the smartscreen.
 
Signed certs are under investigation and probably most of signed certs that involved to distributing malware has been flagged by Windows team. So there is another methods to bypass smartscreen.
 
Пожалуйста, обратите внимание, что пользователь заблокирован
i paid 200 here is my review:
It does not bypass smartscreen at all, it will only bypass when put the exe inside zip and opened the zip with winrar
Files are detected by wd and blocked by chrome in few hours even without using them in traffic
overall very bad experience with actor its wastage of money
This user is 100% NOOB & a very bad customer. I was polite & patient with him but all he does is insult me when he makes mistakes with the file I sent him. Because of his stupid mistakes I sent him up to 7 different files (which I never do) just to make him happy. But this user keeps making mistakes which is not my fault just that he is a complete noob who knows nothing.

During the test I dealt with him professionally, I even came on his Anydesk to provide assistance for him & he confirmed several times that dropper is perfect & I recorded all these using bandicam. I attached details of our chat here where he confirmed dropper works according to how I posted

This user also kept uploading dropper EXE to AV hosting sites which is against the rules for any exe service (& this cause the main issue like smartscreen detect). So I advised him to use a valid EV cert for the dropper because that is the only way he can use it the way he wants

I have done many successful dropper service to my customers, even with escrow but this noob user was a complete pain in the ass

If admin also wishes to see the video recording as proof, I’m ready to provide it


Video Proof from telegram chat on mobile: hxxps://ufile.io/2x43jmr1

Edit: I forgot to mention that this user first paid $100 after which I gave him the dropper file. Then he paid the remaining $100 when he was satisfied with the results after confirming that all was OK
 

Вложения

  • IMG_7892.jpeg
    IMG_7892.jpeg
    218 КБ · Просмотры: 43
  • IMG_7893.jpeg
    IMG_7893.jpeg
    340.1 КБ · Просмотры: 41
  • IMG_7890.jpeg
    IMG_7890.jpeg
    328.9 КБ · Просмотры: 36
  • IMG_7889.jpeg
    IMG_7889.jpeg
    341 КБ · Просмотры: 35
  • IMG_7888.jpeg
    IMG_7888.jpeg
    334.5 КБ · Просмотры: 35
  • IMG_7914.jpeg
    IMG_7914.jpeg
    321.7 КБ · Просмотры: 43
Последнее редактирование:
Пожалуйста, обратите внимание, что пользователь заблокирован
theres no way to bypass smartscreen programatically, idk how people still buying software that contains such a feature, same with chrome alert

question to you, how u accept the escrow deal, if all basic functionallity isn't works at all
If you check the proof I sent here you see where this noob user confirmed that all is OK. Actually every other thing worked perfectly according to my original post & this user confirmed that all is Ok. But the noob user kept uploading exe to AV hosting sites & I advised him to use valid cert instead of spoofed cert which I attached to dropper.
 
Пожалуйста, обратите внимание, что пользователь заблокирован
i wont lie but i had purchased a dropper before with +- same price and with spoofed certificate it was bypassing chrome and smartscreen without any issue. This actor also use the spoofed certs but direct exe did not bypass the smartscreen.
the certificate spoof is the only option to bypass smartscrean as i Iknow
 
the certificate spoof is the only option to bypass smartscrean as i Iknow
in his product he even added the cert spoof even after that the file was detected with smartscreen )
if someone doubt my words go and pay the actor get his product and you will see the garbage getting exposed ))
 
Пожалуйста, обратите внимание, что пользователь заблокирован
in his product he even added the cert spoof even after that the file was detected with smartscreen )
if someone doubt my words go and pay the actor get his product and you will see the garbage getting exposed ))
after what you said the owner has to provid demo and some people vouch for it !
 
Пожалуйста, обратите внимание, что пользователь заблокирован
All files I sent to the user was working 100%.

XSS Admin has determined that the user’s claim is false here https://xss.pro/threads/93176/#post-646824
 
Пожалуйста, обратите внимание, что пользователь заблокирован
This guy sells poor service and scams. He scammed me 80$.
https://xss.pro/threads/94573/#post-657127
You are a liar bro. I saw the chat with admin you are a foolish liar
 
Stop being scammed. Go learn some stuff before throw money away and complain.

theres no way to bypass smartscreen programatically, idk how people still buying software that contains such a feature, same with chrome alert

The user V1rtualGh0st that commented before already said everything above.

Note : I'm not accusing the thread starter of anything as I didn't use the service or are interested in any of it, just commenting in the discussion.
 
Stop being scammed. Go learn some stuff before throw money away and complain.



The user V1rtualGh0st that commented before already said everything above.

Note : I'm not accusing the thread starter of anything as I didn't use the service or are interested in any of it, just commenting in the discussion.
there are ways, some people still make that happen i bought a loader weeks back from someone else and that guy gave me a non signed exe which was getting bypassed by smartscreen, chrome and wd
 
Пожалуйста, обратите внимание, что пользователь заблокирован
Stop being scammed. Go learn some stuff before throw money away and complain.



The user V1rtualGh0st that commented before already said everything above.

Note : I'm not accusing the thread starter of anything as I didn't use the service or are interested in any of it, just commenting in the discussion.
No one was scammed bro, that user is a worthless liar. I have done many successful transactions. I’ve even done successful escrow transactions with him. The last transaction we had I provided all he requested & he confirmed that all was working fine. I did my best to satisfy him but he decided to lie to the admin so he can cheat me.

All issues sorted out here. Please read carefully to the end I posted all proofs: https://xss.pro/conversations/159167/page-4#convMessage-556455

That user is a worthless animal. Even though he cheated me & his money was returned to him after lying to the admin he still comes here to lie against me.

I attached screenshots of the chat with the worthless liar where he confirmed that all was OK, then he requested 2 files which I agreed to provide.
 

Вложения

  • IMG_8480.jpeg
    IMG_8480.jpeg
    367.7 КБ · Просмотры: 16
  • IMG_8482.jpeg
    IMG_8482.jpeg
    343.2 КБ · Просмотры: 14
  • IMG_8486.jpeg
    IMG_8486.jpeg
    400.5 КБ · Просмотры: 16
Последнее редактирование:
He was denounced in a forum with similar cases; he only manages to deceive those who are uninformed.

1. His first dropper did not trigger a smart screen warning, and I trusted him to continue with the new transaction. However, his this time dropper did trigger a warning. Contrary to his 100% assurance of bypassing the smart screen that he mentioned in the post and told me on Telegram.

HE CLAIMED THAT HIS DROPPER 100% BYPASSES THE SMARTSCREEN AND NOW HIS DROPPER HAS ISSUES WITH THE SMARTSCREEN, WHICH CONTRADICTS HIS CLAIM THAT HIS DROPPER 100% BYPASSES THE SMARTSCREEN

Here are two pieces of evidence about his claim of 100% bypassing the smart screen.
https://transfer.sh/b8rR20sCBO/m.png
https://transfer.sh/qfd3M2Uetc/12345.jpg

2.
He said:

"I worked very hard to bypass the windows security update issue, and me & this user confirmed that all is fixed."

----> I opened AnyDesk for him to check on my Windows 11 computer. When it ran, a smart screen warning popped up. I asked him about it, and he told me to continue running it (he was trying to distract me from the issue).
After it finished running, the WD on Windows 11 did not detect anything. Then, I ran it on Windows 10 and the WD on Windows 10 detected it, alerted on the screen, and blocked my .exe file from functioning.
He was only focused on Windows 11 and tried to distract me from remembering Windows 10 and the smart screen issue.

3:
Here is the evidence of the WD on Windows 10 blocking the file when executing the dropper he sent me.

This is the image of me immediately reporting the WD block issue on Windows 10 to him:
https://transfer.sh/wRr1HGvdow/m.png

These are the images of the WD detection alert:
https://transfer.sh/qtH6H4V9nt/m1.jpg
https://transfer.sh/Ug0ufzSpPy/m2.jpg

HE IS TRYING TO CHANGE THE TOPIC SO THAT ME AND THE ADMIN FORGET THE SMARTSCREEN ISSUE AND THE WD ISSUE ON WINDOWS 10. I REQUEST THAT THE admin PAY ATTENTION TO THESE TWO DETAILS. HE IS TRYING TO DIVERT TO A DIFFERENT TOPIC SO THAT I AND YOU DO NOT PAY ATTENTION TO THESE TWO DETAILS.


I request the ADMIN to ban him from the forum for providing services that are not truthful, as there have been warnings from other forum members about his services. The extremely poor service he provides has wasted a lot of people's time, which I believe is a fraudulent act against those who are uninformed.
 
Stop being scammed. Go learn some stuff before throw money away and complain.



The user V1rtualGh0st that commented before already said everything above.

Note : I'm not accusing the thread starter of anything as I didn't use the service or are interested in any of it, just commenting in the discussion.
He tried to deceive the ADMIN and was detected by the ADMIN. He was warned by the ADMIN for the previous case in which he deceived.
 

Вложения

  • m1.jpg
    m1.jpg
    97.5 КБ · Просмотры: 10
Another member in the forum accused his service of being very poor and fraudulent.

IF HIS SERVICE WAS GOOD, THERE WOULD BE NO COMPLAINTS, SUCH A DESPICABLE FRAUDSTER.

AFTER ALL, HE HAS THE REPUTATION OF A SWINDLER, AND HE MUST PAY FOR THAT.



nebulainstalls

please report him to me
 

Вложения

  • M2.png
    M2.png
    43.1 КБ · Просмотры: 10


Напишите ответ...
Верх