Remote Administration Tool Research forumRemote Administration Tool Research forum
  Remote Administration Tool Research forum
Register Social Groups Mark Forums Read

Go Back   Remote Administration Tool Research forum > Opensc.ws > Trojan discussion and general help

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 15-02-2010, 14:35
Junior Member
 
Join Date: May 2007
Posts: 12
Xpertvision is on a distinguished road
question about decrypters

let me see if i can explain myself (english is not my mother language)

i create a server (detected) then i use one decrypter (and he gets undetected)

why i only infect people with no antivirus? (the only pc with antivirus was with bitdefender 8 a very old antivirus)

what the decrypter does? only mask the server?

when the victims click the server the antivirus send alert and stop the action?

why use decrypters if the server gets detected when installed?


thanks in advance
Reply With Quote
  #2 (permalink)  
Old 15-02-2010, 15:27
Drag's Avatar
Member
 
Join Date: Aug 2009
Location: the Netherlands
Posts: 49
Drag is on a distinguished road
Are you saying server gets detected when installed?

I DO NOT THINK SO?
__________________
Reply With Quote
  #3 (permalink)  
Old 15-02-2010, 15:49
Ant1-b0dy's Avatar
Senior Member
 
Join Date: Oct 2009
Location: North Carolina, USA
Posts: 238
Ant1-b0dy is on a distinguished road
I believe you mean ENCrypter [Crypter for short] - not DEcrypter as a decrypter decompiles.

Crypters can mask the server but not always. Anti-virus databases are good at picking through the code to detect it... its why you must find what we call a "FUD" or Fully Un-Detected.
__________________
Reply With Quote
  #4 (permalink)  
Old 16-02-2010, 04:30
Junior Member
 
Join Date: May 2007
Posts: 12
Xpertvision is on a distinguished road
Quote:
Originally Posted by Ant1-b0dy View Post
I believe you mean ENCrypter [Crypter for short] - not DEcrypter as a decrypter decompiles.

Crypters can mask the server but not always. Anti-virus databases are good at picking through the code to detect it... its why you must find what we call a "FUD" or Fully Un-Detected.
yes i mean crypter sorry...

my servers are FUD by crypter (tested on novirusthanks)
Reply With Quote
  #5 (permalink)  
Old 16-02-2010, 04:35
Junior Member
 
Join Date: May 2007
Posts: 12
Xpertvision is on a distinguished road
Quote:
Originally Posted by Drag View Post
Are you saying server gets detected when installed?

I DO NOT THINK SO?
so how can you explain i only infect victims with no antivirus? (the only 2 pcs i saw with antivirus was bidefender 8 and mcafee enterprise 8 , both are very old antivirus)

and one of my victims say she got a pop up from antivirus

the server was FUD tested on novirusthanks
Reply With Quote
  #6 (permalink)  
Old 16-02-2010, 04:55
Senior Member
 
Join Date: Jun 2009
Location: 127.0.0.1
Posts: 1,104
~Fleck is on a distinguished road
maybe ur crypter is not runtime.. ? =/
or u dint check the dont distribute option on nvt
or nvt submits to av's...
Reply With Quote
  #7 (permalink)  
Old 16-02-2010, 05:02
Senior Member
 
Join Date: Jun 2009
Location: 127.0.0.1
Posts: 1,104
~Fleck is on a distinguished road
maybe ur crypter is not runtime.. ? =/
or u dint check the dont distribute option on nvt
or nvt submits to av's...
Reply With Quote
  #8 (permalink)  
Old 16-02-2010, 08:36
counterstrikewi's Avatar
Senior Member
 
Join Date: Apr 2009
Location: Opensc.ws
Posts: 828
counterstrikewi is on a distinguished road
the standard encryption for crypters is rc4.
anything encrypted with rc4 with a 40 char+ key cannot be decrypted and is therefore undetected.
The crypter stub contains decryption code and memory execution code.
These are the routines that the antiviruses have tagged.
fud the crypter stub, not the server.
epeius 2.5 still has a good ud rate. 1/23 last time i checked
__________________
|DelphiBasics|
Opensc.ws Village:
εїз ̴̡ı̴̴̡ ̡̡͡|̲̲̲͡͡͡ ̲▫̲͡ ̲̲̲͡͡π̲̲͡͡ ̲̲͡▫̲̲͡͡ | ٩(̾●̮̮̃̾???̃̾)۶ mjrod5 |̲̲̲͡͡͡ ̲▫̲͡ ̲̲̲͡͡π̲̲͡͡ ̲̲͡▫̲̲͡͡ ̲|̡̡̡ ̡ ̴̡ı̴̡̡ ̡͌l̡ ٩(̾̾̾ಠ̮̮̃̾ಠ̃̾)۶ counterstrikewi ̴̡̡̡͡|̲̲̲͡͡͡ ̲▫̲͡ ̲̲̲͡͡π̲̲͡͡ ̲̲͡▫̲̲͡͡ ̲|̡̡̡ ̡
Reply With Quote
  #9 (permalink)  
Old 16-02-2010, 14:33
Junior Member
 
Join Date: May 2007
Posts: 12
Xpertvision is on a distinguished road
i have many good ones FUD and others with 1/20 (avira is allways on top is this)

i allways check the dont destribute sample on novirusthanks

i dont know...

hi heard av like kaperssky when exute theserver he catchim
Reply With Quote
  #10 (permalink)  
Old 17-02-2010, 13:52
Junior Member
 
Join Date: Jan 2010
Posts: 14
Buls is on a distinguished road
probably your crypter is only FUD on scantime not RUNTIME
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
A little question and help! odesa Source Code help 3 06-09-2009 23:57
asking for help ... question in pi 2.3.2 matrix-com Trojan discussion and general help 3 18-02-2009 23:04
a question acidrain Delphi help 10 22-09-2008 23:05
vb question. darkc0de VB help 1 17-07-2008 09:59
a question acidrain Delphi help 2 11-05-2008 00:29


All times are GMT +1. The time now is 05:14.


vBulletin Version is 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.