This forum is in archive mode. You will not be able to post new content.

Author Topic: StealthStalker discussion and suggestions  (Read 2732 times)

0 Members and 3 Guests are viewing this topic.

Offline 0poitr

  • Peasant
  • *
  • Posts: 149
  • Cookies: 64
    • View Profile
Re: StealthStalker discussion and suggestions
« Reply #15 on: April 09, 2013, 08:37:51 PM »
An easy way to propagate the binary 'd be to run it on win startup, do checks on pre-determined interval for removable drives. If the drive has FAT32, copy self.
When attached to a machine later, there has to be any kind of misleading (like, say with icon of a folder, unless extensions are shown) so the user clicks to open it and the binary in turn copies itself to that machine and executes. With w7, I guess autorun is a bit more harder than previous versions.

Actually, that's what I did with my spybot in autoit.
Imagination is the first step towards Creation.

Offline Stackprotector

  • Administrator
  • Titan
  • *
  • Posts: 2515
  • Cookies: 205
    • View Profile
Re: StealthStalker discussion and suggestions
« Reply #16 on: April 10, 2013, 08:11:28 AM »
An easy way to propagate the binary 'd be to run it on win startup, do checks on pre-determined interval for removable drives. If the drive has FAT32, copy self.
When attached to a machine later, there has to be any kind of misleading (like, say with icon of a folder, unless extensions are shown) so the user clicks to open it and the binary in turn copies itself to that machine and executes. With w7, I guess autorun is a bit more harder than previous versions.

Actually, that's what I did with my spybot in autoit.

You will get your mall-ware above the radar pretty quickly if you do that. I will always suggest to find your own tricks and do not use existing binders/crypters because av's can find them suspicious because they use known binder and wanna be fud methods and upload them to a av server and when your code is reversed and in the av pattern databases you can wave goodbye to being totally fud.
~Factionwars

Offline kenjoe41

  • Symphorophiliac Programmer
  • Administrator
  • Baron
  • *
  • Posts: 990
  • Cookies: 224
    • View Profile
Re: StealthStalker discussion and suggestions
« Reply #17 on: April 13, 2013, 12:09:48 PM »
For an idea, maybe the malware should also be able to run new own code that its user can insert and change later. This will carter for those wanting it to be a RAT or add anymore capabilities to it rather than the pre-defined rules by its coder.
If you can't explain it to a 6 year old, you don't understand it yourself.
http://upload.alpha.evilzone.org/index.php?page=img&img=GwkGGneGR7Pl222zVGmNTjerkhkYNGtBuiYXkpyNv4ScOAWQu0-Y8[<NgGw/hsq]>EvbQrOrousk[/img]

 



Want to be here? Contact Ande, Factionwars or Kulverstukas on the forum or at IRC.