-
question about decrypters
let me see if i can explain myself (english is not my mother language)
i create a server (detected) then i use one decrypter (and he gets undetected)
why i only infect people with no antivirus? (the only pc with antivirus was with bitdefender 8 a very old antivirus)
what the decrypter does? only mask the server?
when the victims click the server the antivirus send alert and stop the action?
why use decrypters if the server gets detected when installed?
thanks in advance
-
Are you saying server gets detected when installed?
I DO NOT THINK SO?
-
I believe you mean ENCrypter [Crypter for short] - not DEcrypter as a decrypter decompiles.
Crypters can mask the server but not always. Anti-virus databases are good at picking through the code to detect it... its why you must find what we call a "FUD" or Fully Un-Detected.
-

Originally Posted by
Ant1-b0dy
I believe you mean ENCrypter [Crypter for short] - not DEcrypter as a decrypter decompiles.
Crypters can mask the server but not always. Anti-virus databases are good at picking through the code to detect it... its why you must find what we call a "
FUD" or Fully Un-Detected.
yes i mean crypter sorry...
my servers are FUD by crypter (tested on novirusthanks)
-

Originally Posted by
Drag
Are you saying server gets detected when installed?
I DO NOT THINK SO?
so how can you explain i only infect victims with no antivirus? (the only 2 pcs i saw with antivirus was bidefender 8 and mcafee enterprise 8 , both are very old antivirus)
and one of my victims say she got a pop up from antivirus 
the server was FUD tested on novirusthanks
-
maybe ur crypter is not runtime.. ? =/
or u dint check the dont distribute option on nvt
or nvt submits to av's...
No. I'm not back to the scene. Quit Sending me stupid requests via PM/mail, I'm not going to respond to them. If you have a problem, post it in the forum.
-
maybe ur crypter is not runtime.. ? =/
or u dint check the dont distribute option on nvt
or nvt submits to av's...
No. I'm not back to the scene. Quit Sending me stupid requests via PM/mail, I'm not going to respond to them. If you have a problem, post it in the forum.
-
the standard encryption for crypters is rc4.
anything encrypted with rc4 with a 40 char+ key cannot be decrypted and is therefore undetected.
The crypter stub contains decryption code and memory execution code.
These are the routines that the antiviruses have tagged.
fud the crypter stub, not the server.
epeius 2.5 still has a good ud rate. 1/23 last time i checked
DelphiBasics - Ultimate Delphi Resource for Beginners
www.delphibasics.info
-
i have many good ones FUD and others with 1/20 (avira is allways on top is this)
i allways check the dont destribute sample on novirusthanks
i dont know...
hi heard av like kaperssky when exute theserver he catchim
-
probably your crypter is only FUD on scantime not RUNTIME
Thread Information
Users Browsing this Thread
There are currently 1 users browsing this thread. (0 members and 1 guests)
Similar Threads
-
By odesa in forum General Programming Help
Replies: 3
Last Post: 06-09-2009, 22:57
-
By matrix-com in forum Malware Discussion and General Help
Replies: 3
Last Post: 18-02-2009, 23:04
-
By acidrain in forum Delphi Help
Replies: 10
Last Post: 22-09-2008, 22:05
-
By darkc0de in forum Visual Basic Help
Replies: 1
Last Post: 17-07-2008, 08:59
-
By acidrain in forum Delphi Help
Replies: 2
Last Post: 10-05-2008, 23:29
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
Forum Rules
All times are GMT +1. The time now is 22:05.
www.opensc.ws
Copyright ©2005 - 2012, OpenSC Forums
Search Engine Friendly URLs by vBSEO 3.6.0 ©2011, Crawlability, Inc.