Sunday 16 June 2013

Hiding Keyloggers/Rats/Worms/Viruses Using Crypters or Binders......

The main thing you need to focus on after creating keylogger, is to convince your victim to install that keylogger on his PC. Normally free remote keyloggers like Ardamax keylogger or any other cheap, or free keyloggers will create standard .exe installation file without any stealth feature and you can use cracked Keylogger generators too. Also free keyloggers are easily detected by common antiviruses like Kaspersky,Microsoft Security Essentials and more, even the worst (according to me) Avast, the free antivirus detects keyloggers like this instantly. So Eventually your keylogging will end in vain. You might have heard about binders and Crypters before, but do you know what they are used for? and why they are used in keylogging? its simple as their Names stands out what they do. Lets first understand them.

  • Crypter
It is a software that can encrypt executable (.exe) files. crypters are popularly used to encrypt viruses, RAT’s, keyloggers, spywares etc to make them undetectable from antiviruses.
The Crypter takes the original binary code of .exe file and applies many encryption on it and stores at the end of file(EOF). So a new crypted executable file is created. The new exe is not detected by antiviruses because its code is scrambled by the crypter.
  • Binder
Binder is a software used to bind or combine two or more files in one file under one name and extension.
The files to be binded can have any extension or icon. The user has choice to select the name, icon and various attributes of binded file. Now that you are aware of these softwares, do you think antivirus softwares will allow you to run these on your system?Ofcourse not. This is the biggest setback for crypters and binders. With the flourishing use of Crypters and binders to bypass antiviruses, AV became more advanced and started including encryption definitions to even detect crypted or binded strings within code. So, use of crypter to hide Keyloggers became more complicated as nowadays, most of the popular crypters & Binders are easily detected by antiviruses too. So, if you are trying to crypt your keyloggers or viruses with publicly available crypters and binders, they are bound to be detected by antiviruses. This is because most FUD(fully undetectable) crypters remain “FUD” for maximum of one or two weeks, after their public release. When any free FUD crypter/binder becomes popular it also gets the eyes of antivirus companies. The antivirus companies update their software and employ detection mechanism that detect the encryption by the crypter. To obtain FUD crypters, you either need to search for it in hacking forums or make one by yourself. Soon i might post about creating your own crypter.. so be sure to drop back. Meanwhile you can try these latest crypters and binders that are available publicly:

1) Yasar's Crypter v1.0

This Crypter is 100% FUD (Fully Undetectable) and free. It has all features of best crypters taht were ever made and works on all well known RAT's & Keloggers. It has all modern functions like icon changer, binder, Fake Error, EOF, custom stub adder. You can crypt as many files as you want at once. Anti's methods and etc are all here. It might not that much of Noob friendly but only2 or 3 uses will do the trick.
It got its own Stub generator. Well if a Sub is FUD, then the crypter is FUD. You should search Google for what is a stub in crypters for info.

No comments:

Post a Comment