Crypters - HELP please 01-05-2023, 01:59 AM
#1
Antiviruses are becoming more powerful every day, hence the question arises, do the crypters themselves know how to download updates to infected files over the Internet?
![Stressed Stressed](https://sinister.ly/images/smilies/set/stressed.png)
Crypters - HELP please filter_list | |
(01-05-2023, 04:04 PM)PYA Wrote: Crypters usually depending on if its scantime, and runtime have different methodologies they use for encryption, but generally runtime which is what seems to matter most in terms of longevity use whats called a RunPE alongside the obfuscation of the crypter, this is what you know as the "Stub", when a runPE is detected, or the coding methods used are identified by antivirus vendors as malicious the instructions are added to antivirus database definitions, so when av's scan a file, they have a record of whats "found", its an endless game of cat, and mouse. the best thing for a crypters longevity is finding one thats good at preventing reverse engineering alongside a well coded runpe.Do I understand correctly that just by picking up a good crypter, you can forget about monitoring and it will do everything by itself, including auto-updating?
(01-05-2023, 05:31 PM)schoolme Wrote:(01-05-2023, 04:04 PM)PYA Wrote: Crypters usually depending on if its scantime, and runtime have different methodologies they use for encryption, but generally runtime which is what seems to matter most in terms of longevity use whats called a RunPE alongside the obfuscation of the crypter, this is what you know as the "Stub", when a runPE is detected, or the coding methods used are identified by antivirus vendors as malicious the instructions are added to antivirus database definitions, so when av's scan a file, they have a record of whats "found", its an endless game of cat, and mouse. the best thing for a crypters longevity is finding one thats good at preventing reverse engineering alongside a well coded runpe.Do I understand correctly that just by picking up a good crypter, you can forget about monitoring and it will do everything by itself, including auto-updating?