Sinisterly
REFUD with Hex Editor , Worked ALL RAT,Crypter,Keylogger,Bot - Printable Version

+- Sinisterly (https://sinister.ly)
+-- Forum: Hacking (https://sinister.ly/Forum-Hacking)
+--- Forum: Tutorials (https://sinister.ly/Forum-Tutorials)
+--- Thread: REFUD with Hex Editor , Worked ALL RAT,Crypter,Keylogger,Bot (/Thread-REFUD-with-Hex-Editor-Worked-ALL-RAT-Crypter-Keylogger-Bot)



REFUD with Hex Editor , Worked ALL RAT,Crypter,Keylogger,Bot - darktheatre - 06-05-2012

This is not my method, but i simply optimize the video tutor how to REFUD efficiently.

This technique REFUD is perfect with all file, RAT,Stub,Worm,Keylogger,Bot etc. Dependencies or not ,is not influenced .

Advantages this technique :
+ Support all RAT ( darkcomet , blackshades , cybergate , xtreme RAT , spynet , ProRat ,ect )
+ Support all botnet
+ Support all stealer
+ support all spreader (worm, etc)
+ support all crypter (dependencies or no dependencies)
+ Unique REFUD - different user different byte modification. (longer FUD)
+ May use with different situations (see picture below)
[Image: CbFBc.jpg]


Main Steps REFUD using Hex editor
-) Spread the file offset
-) Scan and take the 1 detection file and previous file (must clean detection)
-) Compare 2 offsets file
-) Change the byte with 1C
-) Scan after changed
-) If clean. change the byte for origanal file server.exe with same location offset
-) Test the file after changed (work or not)
p/s See video tutor with full attention for detail process

Video Tutor REFUD Using Hex Editor
I Make the simple and faster way for you to practice


Test REFUD by Genius Crypter 1.2 -> DOWNLOAD HERE
ALERT: Dont Scan At VIRUS TOTAL, WHY? -> Click Here

SCAN RESULT:
File Info
Report date: 2012-06-02.
Scan Occured: [Image: result_time.php?t=i&w=Mzk1MDg5]
Link to scan: http://metascan.org/result.php?scan=Mzk1MDg5
File name: test.exe
File size: 1125376 bytes
MD5 Hash: c9c3360a392553b9de8c16c7935c1901
SHA1 Hash: aba3228493a92e4be9d17667e192e7812f158692
Detection rate: 10 out of 37
Status: INFECTED

Detections
AVG - Virus found Injector.
Acavir - Clean.
Avast 5 -Clean.
Avast -Clean.
Avira -TR/Dropper.MSIL.Gen.
BitDefender -Gen:Variant.Kazy.62228.
VirusBuster Internet Security -Clean.
Clam Antivirus -Clean.
COMODO Internet Security -Clean.
DrWeb -Trojan.DownLoader5.59917.
eTrust-Vet -Clean.
F-PROT Antivirus -Clean.
F-Secure Internet Security -Gen:Variant.Kazy.62228.
G Data -Gen:Variant.Kazy.62228.
IKARUS Security-Trojan-Dropper.Win32.Injector.
Kaspersky Antivirus -Clean.
McAfee -Clean.
MS Security Essentials -Clean.
ESET NOD32 -Trojan.MSIL/Kryptik.AP.
Norman -Clean.
Norton -Clean.
Panda Security -Clean.
A-Squared Security -Clean.
Quick Heal Antivirus -Clean.
Rising Antivirus -Clean.
Solo Antivirus -Clean.
Sophos -Clean.
Trend Micro Internet Security -Clean.
VBA32 Antivirus -Clean.
Vexira Antivirus -Clean.
Webroot Internet Security -Clean.
Zoner AntiVirus -Clean.
Ad-Aware -Clean.
AhnLab V3 Internet Security -Clean.
Bullguard -virus: Gen:Variant.Kazy.62228.
Imunitet -Gen:Variant.Kazy.62228.
Vipre -Clean.


AFTER REFUD
Report date: 2012-06-04.
Scan Occured: [Image: result_time.php?t=i&w=Mzk2MDcy]
Link to scan: http://metascan.org/result.php?scan=Mzk2MDcy
File name: test2.exe
File size: 1125376 bytes
MD5 Hash: 8ef46d3059e63eaa97dfedfe09b19f87
SHA1 Hash: 864ea518c7c50e8a9f7a6f792429dee17014581b
Detection rate: 3 out of 37
Status: INFECTED

Detections
AVG - Clean.
Acavir - Clean.
Avast 5 -Clean.
Avast -Clean.
Avira -Clean.
BitDefender -Clean.
VirusBuster Internet Security -Clean.
Clam Antivirus -Clean.
COMODO Internet Security -Clean.
DrWeb -Trojan.DownLoader5.60526.
eTrust-Vet -Clean.
F-PROT Antivirus -Clean.
F-Secure Internet Security -Clean.
G Data -Clean.
IKARUS Security-Trojan-Dropper.Win32.Injector.
Kaspersky Antivirus -Clean.
McAfee -Clean.
MS Security Essentials -Clean.
ESET NOD32 -Clean.
Norman -Clean.
Norton -Clean.
Panda Security -Clean.
A-Squared Security -Trojan-Dropper.Win32.Injector!IK.
Quick Heal Antivirus -Clean.
Rising Antivirus -Clean.
Solo Antivirus -Clean.
Sophos -Clean.
Trend Micro Internet Security -Clean.
VBA32 Antivirus -Clean.
Vexira Antivirus -Clean.
Webroot Internet Security -Clean.
Zoner AntiVirus -Clean.
Ad-Aware -Clean.
AhnLab V3 Internet Security -Clean.
Bullguard -Clean.
Imunitet -Clean.
Vipre -Clean.

P/S: After Build please make sure you test your server
Test Your Server On Your Own Computer -> Click Here
Advance Test Your Server Work Properly Without Lose After Victim Reboot PC -> Click Here

RE-FUD Techique -> Please GO Here (RE-FUD Section)


RE: REFUD with Hex Editor , Worked ALL RAT,Crypter,Keylogger,Bot - Manilla Ice - 08-18-2012

Nice share. Thakns for this.


RE: REFUD with Hex Editor , Worked ALL RAT,Crypter,Keylogger,Bot - darktheatre - 11-17-2012

you are welcome, the best i try to give for hackcommunity Smile


RE: REFUD with Hex Editor , Worked ALL RAT,Crypter,Keylogger,Bot - nourdin - 11-24-2012

الله اكبر ما شاء الله عليك


RE: REFUD with Hex Editor , Worked ALL RAT,Crypter,Keylogger,Bot - Desura - 11-28-2012

Thanks man, wil try it soon