Underc0de

[In]Seguridad Informática => Análisis y desarrollo de malwares => Mensaje iniciado por: Baku en Noviembre 17, 2014, 12:01:28 AM

Título: Baku Crypter v2.0 FUD 0/35 + Binder.
Publicado por: Baku en Noviembre 17, 2014, 12:01:28 AM
Hola amigos, en esta oportunidad les traigo Baku Crypter v2.0, en esta versión se le integro un Binder que permite a la persona que lo use elegir donde dropear el archivo ya sea en TEMP,USERDIR o AppData.


Imagen:

(http://i.imgur.com/qzqpN3P.png)



Scan Stub:

Date and Time: 11/17/2014 02:25:28 UTC
File Name: Baku.exe
File Size: 41.09 KB
MD5: dd0ed7e3310fc4ebf584cc9c3ee844f6
SHA1: 1e964231cf27ae31ce37d96effb024ec1e292ded
Detection: 0 of 35 (0%)
Status: CLEAN

AVG Free - Clean!
Avast - Clean!
AntiVir (Avira) - Clean!
BitDefender - Clean!
Clam Antivirus - Clean!
COMODO Internet Security - Clean!
Dr.Web - Clean!
eTrust-Vet - Clean!
F-PROT Antivirus - Clean!
F-Secure Internet Security - Clean!
G Data - Clean!
IKARUS Security - Clean!
Kaspersky Antivirus - Clean!
McAfee - Clean!
MS Security Essentials - Clean!
ESET NOD32 - Clean!
Norman - Clean!
Norton Antivirus - Clean!
Panda Security - Clean!
A-Squared - Clean!
Quick Heal Antivirus - Clean!
Solo Antivirus - Clean!
Sophos - Clean!
Trend Micro Internet Security - Clean!
VBA32 Antivirus - Clean!
Zoner AntiVirus - Clean!
Ad-Aware - Clean!
BullGuard - Clean!
FortiClient - Clean!
K7 Ultimate - Clean!
NANO Antivirus - Clean!
Panda CommandLine - Clean!
SUPERAntiSpyware - Clean!
Twister Antivirus - Clean!
VIPRE - Clean!

http://www.file2scan.net/report.php?id=hsuc8vhh_MoAsJmDp (http://www.file2scan.net/report.php?id=hsuc8vhh_MoAsJmDp)

Scan Cybergate:

Date and Time: 11/17/2014 02:26:40 UTC
File Name: Cybergate_FUD.exe
File Size: 330.7 KB
MD5: fab9bc6747445aece8386725e1fe0afb
SHA1: e5e61f329cb8174c9f3980f35c7f2cdf9838a6bd
Detection: 0 of 35 (0%)
Status: CLEAN

AVG Free - Clean!
Avast - Clean!
AntiVir (Avira) - Clean!
BitDefender - Clean!
Clam Antivirus - Clean!
COMODO Internet Security - Clean!
Dr.Web - Clean!
eTrust-Vet - Clean!
F-PROT Antivirus - Clean!
F-Secure Internet Security - Clean!
G Data - Clean!
IKARUS Security - Clean!
Kaspersky Antivirus - Clean!
McAfee - Clean!
MS Security Essentials - Clean!
ESET NOD32 - Clean!
Norman - Clean!
Norton Antivirus - Clean!
Panda Security - Clean!
A-Squared - Clean!
Quick Heal Antivirus - Clean!
Solo Antivirus - Clean!
Sophos - Clean!
Trend Micro Internet Security - Clean!
VBA32 Antivirus - Clean!
Zoner AntiVirus - Clean!
Ad-Aware - Clean!
BullGuard - Clean!
FortiClient - Clean!
K7 Ultimate - Clean!
NANO Antivirus - Clean!
Panda CommandLine - Clean!
SUPERAntiSpyware - Clean!
Twister Antivirus - Clean!
VIPRE - Clean!

http://www.file2scan.net/report.php?id=2wgvhhf7_bRbAXfkG (http://www.file2scan.net/report.php?id=2wgvhhf7_bRbAXfkG)

Scan Bozok:

Date and Time: 11/17/2014 02:28:03 UTC
File Name: Bozok1.5_FUD.exe
File Size: 73.68 KB
MD5: 954d81a733244c0a3363580d61896b4c
SHA1: ab0995579779d4b71c6ef73967dd77b01487dfd6
Detection: 0 of 35 (0%)
Status: CLEAN

AVG Free - Clean!
Avast - Clean!
AntiVir (Avira) - Clean!
BitDefender - Clean!
Clam Antivirus - Clean!
COMODO Internet Security - Clean!
Dr.Web - Clean!
eTrust-Vet - Clean!
F-PROT Antivirus - Clean!
F-Secure Internet Security - Clean!
G Data - Clean!
IKARUS Security - Clean!
Kaspersky Antivirus - Clean!
McAfee - Clean!
MS Security Essentials - Clean!
ESET NOD32 - Clean!
Norman - Clean!
Norton Antivirus - Clean!
Panda Security - Clean!
A-Squared - Clean!
Quick Heal Antivirus - Clean!
Solo Antivirus - Clean!
Sophos - Clean!
Trend Micro Internet Security - Clean!
VBA32 Antivirus - Clean!
Zoner AntiVirus - Clean!
Ad-Aware - Clean!
BullGuard - Clean!
FortiClient - Clean!
K7 Ultimate - Clean!
NANO Antivirus - Clean!
Panda CommandLine - Clean!
SUPERAntiSpyware - Clean!
Twister Antivirus - Clean!
VIPRE - Clean!

http://www.file2scan.net/report.php?id=81n3vwog_RSLbSdxF (http://www.file2scan.net/report.php?id=81n3vwog_RSLbSdxF)

Scan Spy-Net:

Date and Time: 11/17/2014 02:28:48 UTC
File Name: SpyNet_FUD.exe
File Size: 324.68 KB
MD5: ce44335b675273b648150057c3d8b43c
SHA1: 9616579d439e3be5c9e3ce1cd03591514aa1f784
Detection: 0 of 35 (0%)
Status: CLEAN

AVG Free - Clean!
Avast - Clean!
AntiVir (Avira) - Clean!
BitDefender - Clean!
Clam Antivirus - Clean!
COMODO Internet Security - Clean!
Dr.Web - Clean!
eTrust-Vet - Clean!
F-PROT Antivirus - Clean!
F-Secure Internet Security - Clean!
G Data - Clean!
IKARUS Security - Clean!
Kaspersky Antivirus - Clean!
McAfee - Clean!
MS Security Essentials - Clean!
ESET NOD32 - Clean!
Norman - Clean!
Norton Antivirus - Clean!
Panda Security - Clean!
A-Squared - Clean!
Quick Heal Antivirus - Clean!
Solo Antivirus - Clean!
Sophos - Clean!
Trend Micro Internet Security - Clean!
VBA32 Antivirus - Clean!
Zoner AntiVirus - Clean!
Ad-Aware - Clean!
BullGuard - Clean!
FortiClient - Clean!
K7 Ultimate - Clean!
NANO Antivirus - Clean!
Panda CommandLine - Clean!
SUPERAntiSpyware - Clean!
Twister Antivirus - Clean!
VIPRE - Clean!

http://www.file2scan.net/report.php?id=fvuyqxiq_YFFRPVFr (http://www.file2scan.net/report.php?id=fvuyqxiq_YFFRPVFr)


Bueno, ahora vamos a usar el troyano y binder a ver que tal sale...

Scan Cybergate + Anotador:

Date and Time: 11/17/2014 02:30:59 UTC
File Name: Cybergate+Anotador_FUD.exe
File Size: 630.7 KB
MD5: 2b18209bdfa1c69dd3b89db8c3ec06a2
SHA1: 5d57d7165924d29b4f921d0dadb1aad8d6013403
Detection: 0 of 35 (0%)
Status: CLEAN

AVG Free - Clean!
Avast - Clean!
AntiVir (Avira) - Clean!
BitDefender - Clean!
Clam Antivirus - Clean!
COMODO Internet Security - Clean!
Dr.Web - Clean!
eTrust-Vet - Clean!
F-PROT Antivirus - Clean!
F-Secure Internet Security - Clean!
G Data - Clean!
IKARUS Security - Clean!
Kaspersky Antivirus - Clean!
McAfee - Clean!
MS Security Essentials - Clean!
ESET NOD32 - Clean!
Norman - Clean!
Norton Antivirus - Clean!
Panda Security - Clean!
A-Squared - Clean!
Quick Heal Antivirus - Clean!
Solo Antivirus - Clean!
Sophos - Clean!
Trend Micro Internet Security - Clean!
VBA32 Antivirus - Clean!
Zoner AntiVirus - Clean!
Ad-Aware - Clean!
BullGuard - Clean!
FortiClient - Clean!
K7 Ultimate - Clean!
NANO Antivirus - Clean!
Panda CommandLine - Clean!
SUPERAntiSpyware - Clean!
Twister Antivirus - Clean!
VIPRE - Clean!

http://www.file2scan.net/report.php?id=5bwb9rx3_fNGvUmKJ (http://www.file2scan.net/report.php?id=5bwb9rx3_fNGvUmKJ)

Scan Spy-Net + Anotador:

Date and Time: 11/17/2014 02:32:15 UTC
File Name: SpyNet+Anotador_FUD.exe
File Size: 624.68 KB
MD5: a5f2efe988743e8eb07c28631b7631b7
SHA1: 4b020ced4d7da165a89320dcc6d7899ea4f620ee
Detection: 0 of 35 (0%)
Status: CLEAN

AVG Free - Clean!
Avast - Clean!
AntiVir (Avira) - Clean!
BitDefender - Clean!
Clam Antivirus - Clean!
COMODO Internet Security - Clean!
Dr.Web - Clean!
eTrust-Vet - Clean!
F-PROT Antivirus - Clean!
F-Secure Internet Security - Clean!
G Data - Clean!
IKARUS Security - Clean!
Kaspersky Antivirus - Clean!
McAfee - Clean!
MS Security Essentials - Clean!
ESET NOD32 - Clean!
Norman - Clean!
Norton Antivirus - Clean!
Panda Security - Clean!
A-Squared - Clean!
Quick Heal Antivirus - Clean!
Solo Antivirus - Clean!
Sophos - Clean!
Trend Micro Internet Security - Clean!
VBA32 Antivirus - Clean!
Zoner AntiVirus - Clean!
Ad-Aware - Clean!
BullGuard - Clean!
FortiClient - Clean!
K7 Ultimate - Clean!
NANO Antivirus - Clean!
Panda CommandLine - Clean!
SUPERAntiSpyware - Clean!
Twister Antivirus - Clean!
VIPRE - Clean!

http://www.file2scan.net/report.php?id=b07udtn5_QYVJDFaC (http://www.file2scan.net/report.php?id=b07udtn5_QYVJDFaC)

Scan Bozok + Anotador:

Date and Time: 11/17/2014 02:33:51 UTC
File Name: Bozok1.5+Anotador_FUD.exe
File Size: 373.68 KB
MD5: f7552d74e3869f94352b6ecf3e133ad6
SHA1: 69e83f7bfee3e2618fc411a1d035d82756f3ca76
Detection: 0 of 35 (0%)
Status: CLEAN

AVG Free - Clean!
Avast - Clean!
AntiVir (Avira) - Clean!
BitDefender - Clean!
Clam Antivirus - Clean!
COMODO Internet Security - Clean!
Dr.Web - Clean!
eTrust-Vet - Clean!
F-PROT Antivirus - Clean!
F-Secure Internet Security - Clean!
G Data - Clean!
IKARUS Security - Clean!
Kaspersky Antivirus - Clean!
McAfee - Clean!
MS Security Essentials - Clean!
ESET NOD32 - Clean!
Norman - Clean!
Norton Antivirus - Clean!
Panda Security - Clean!
A-Squared - Clean!
Quick Heal Antivirus - Clean!
Solo Antivirus - Clean!
Sophos - Clean!
Trend Micro Internet Security - Clean!
VBA32 Antivirus - Clean!
Zoner AntiVirus - Clean!
Ad-Aware - Clean!
BullGuard - Clean!
FortiClient - Clean!
K7 Ultimate - Clean!
NANO Antivirus - Clean!
Panda CommandLine - Clean!
SUPERAntiSpyware - Clean!
Twister Antivirus - Clean!
VIPRE - Clean!

http://www.file2scan.net/report.php?id=8cikl3yw_zViOlAXs (http://www.file2scan.net/report.php?id=8cikl3yw_zViOlAXs)


Ahora voy probar que tal sale juntar 2 troyanos...

Scan Cybergate + Spynet:

Date and Time: 11/17/2014 02:35:07 UTC
File Name: Cybergate+SpyNet_FUD.exe
File Size: 614.2 KB
MD5: 54092448403cde3c6e67439322282db5
SHA1: 976eb38b2ea32c2975325115cc2167b11c0650e9
Detection: 0 of 35 (0%)
Status: CLEAN

AVG Free - Clean!
Avast - Clean!
AntiVir (Avira) - Clean!
BitDefender - Clean!
Clam Antivirus - Clean!
COMODO Internet Security - Clean!
Dr.Web - Clean!
eTrust-Vet - Clean!
F-PROT Antivirus - Clean!
F-Secure Internet Security - Clean!
G Data - Clean!
IKARUS Security - Clean!
Kaspersky Antivirus - Clean!
McAfee - Clean!
MS Security Essentials - Clean!
ESET NOD32 - Clean!
Norman - Clean!
Norton Antivirus - Clean!
Panda Security - Clean!
A-Squared - Clean!
Quick Heal Antivirus - Clean!
Solo Antivirus - Clean!
Sophos - Clean!
Trend Micro Internet Security - Clean!
VBA32 Antivirus - Clean!
Zoner AntiVirus - Clean!
Ad-Aware - Clean!
BullGuard - Clean!
FortiClient - Clean!
K7 Ultimate - Clean!
NANO Antivirus - Clean!
Panda CommandLine - Clean!
SUPERAntiSpyware - Clean!
Twister Antivirus - Clean!
VIPRE - Clean!

http://www.file2scan.net/report.php?id=n9a2c1qz_FVIOfzhC (http://www.file2scan.net/report.php?id=n9a2c1qz_FVIOfzhC)


Creditos:

Agradecimientos a Anto Pixel ::)(Zambito)

Link de descarga: http://www.datafilehost.com/d/71091fc2 (http://www.datafilehost.com/d/71091fc2)

Contraseña:Solo personas que aporten.
Título: Re:Baku Crypter v2.0 FUD 0/35 + Binder.
Publicado por: rollth en Noviembre 17, 2014, 09:12:12 AM
Muy bueno cada dia me sorprendes mas
Título: Re:Baku Crypter v2.0 FUD 0/35 + Binder.
Publicado por: D4RKS0N1K en Noviembre 17, 2014, 01:04:37 PM
Grande Baku¡
Título: Re:Baku Crypter v2.0 FUD 0/35 + Binder.
Publicado por: Shell Shock en Noviembre 17, 2014, 03:25:52 PM
Hey mano, la contraseña no coincide..
por fas man..comparte el archivo y la contraseña adecuada...
Título: Re:Baku Crypter v2.0 FUD 0/35 + Binder.
Publicado por: Baku en Noviembre 17, 2014, 04:06:01 PM
No tienes permitido ver los links. Registrarse o Entrar a mi cuenta
Hey mano, la contraseña no coincide..
por fas man..comparte el archivo y la contraseña adecuada...
Hola! Tecomento que, es SOLO para personas que aporte por lo tanto si no aportas al foro no te gastes en enviar mp porque no te voy a dar la contraseña.
Saludos.
Título: Re:Baku Crypter v2.0 FUD 0/35 + Binder.
Publicado por: Y3K en Noviembre 17, 2014, 04:14:01 PM
No tienes permitido ver los links. Registrarse o Entrar a mi cuenta
Hola! Tecomento que, es SOLO para personas que aporte por lo tanto si no aportas al foro no te gastes en enviar mp porque no te voy a dar la contraseña.
Saludos.

Hahaha, esa estuvo buena :P

Gracias por el aporte Crypter-Man!
Título: Re:Baku Crypter v2.0 FUD 0/35 + Binder.
Publicado por: brampower en Noviembre 20, 2014, 11:29:51 PM
Excelente!! :)