Saturday, May 7, 2016

Pony (Win32/Fareit)

Pony Stealer leaked (advanced stealers included)


Pony botnet is notorious for banking, bitcoin stealing, and stealing other things..

The Bitcoin theft is in addition to a slew of credentials, over 700,000, that Pony pilfered from September 2013 to January including: 600,000 website login credentials 100,000 email account credentials 16,000 FTP account credentials 900 Secure Shell account credentials 800 Remote Desktop credentials - See more at: http://threatpost.com/latest-instance-of-pony-botnet-pilfers-200k-700k-credentials/104463#sthash.f17KzXK0.dpuf

Pony steals more than 30 concurrency wallets, and is very good at what it does. Some of the botnet is based off the Zeus src source. I personally used this botnet for a year and moved on to more updated malware, but at the time that I used it, it worked fantastically. Most of the panel is in russian, along with the builder, but we were able to translate the russian in the builder.











version : 1.9 , 2.0 ( updated password modules )

 for more details u can contact me @ 

Skype: suriya.cyber




Thursday, March 26, 2015

Exploit for Malware


 Link to Exploit Site


Link to Exploit Site, as it name suggests, refers to the presence of links to malicious websites inside a legitimate website without the knowledge of the administrator. Once users click on the link, they are redirected to a website with malicious code that takes advantage of vulnerabilities in outdated programs or plugins in your device to download and install malware.
Contact : 
ym : cybersuriya73@gmail.com
skype : suriya.cyber




Beta Botnet

Beta Botnet 1.7.0.1 Full Setup 
Contact : cybersuriya73@yahoo.com
skype: suriya.cyber




Version 1.7.0.1

Bot
File search now is more configurable:
  a) Allows folder exclusions (To help prevent useless results/search time)
  b) Allows files with certain strings found in their filename to be uploaded
  c) Maximum search terms increased to 128, maximum filename terms is 64
  d) Parameter "nocache" allows you to have already sent files uploaded again
Botkiller updated once again. New techniques added and existing code revised.
Fixed issue where IE would freeze on load when Avast! was disabled by the AV killer
Injector now more compatible with games/anti-cheat components
Fixed issue with formgrabber sometimes uploading the wrong part of captured form content in Firefox and Chrome
Bot now uploads select header fields with each formgrab capture (when available): User-Agent, Referer, Cookie and Accept-Languages
Fixed DNS Modifier not working with latest versions of Firefox (22+). Another function had to be hooked.
Fixed issue where sometimes UAC prompt would come up even after accepting it because there was a delay in processing messages from the window queue
A couple tweaks to installation code
Misc beneficial changes to bot protection (persistence) code
Fixed a few issues with updater
Windows Defender is now thoroughly disabled instead of just turned off

Panel
Extended the GeoIP information displayed (ASN Name, City information) when available. *
Fixed IE formgrab logs sometimes appearing as "Unknown" browser
Fixed formgrab "view detail" page content sometimes causing table to stretch too far, distorting other table cells.
Fixed issue where searching bots with comments would return zero results
Fixed invalid links for page numbers
Misc fixes to panel HTML code

Notes
The size of the geolite imports is quite large so if users have no use for this, they can simply choose not to import it


Bot - Major
64-bit userkit
POP3 grabber
Chrome grabber / DNS redirection support
File search - Search all files' content for keywords and upload files containing matches to panel
Config editor to edit builds -- Change group names, and modify other minor settings/initial behavior
Block installation of some bootkits (Mainly Rovnix(Carberp) - Can toggle on/off from panel)
Enhanced bot resource protection (persistence) on some systems (around 40%~) (Much harder to remove in some cases)

Bot - Minor
Run DLL/Jar files
File size now less than 140kb
Fetches UAC social engineering translations from panel
ESET AV Killer now works on Vista+, AV Killer updated to include Ahnlab v3 Lite (XP only), BitDefender (on minimal config)
Better support for Avast sandbox. All sandbox prompts are now automatically accepted to increase download/exec rate.
Proactive bypasses updated (Trend Micro/McAfee now fully bypassed, BitDefender bypass finished but not 100% reliable)
PuTTY Live login grabber now works with latest update (0.63). New code locations and improper typecasting previous caused crash in latest version (0.63)
Improved crypter compatibility
Added new detection techniques to botkiller and increased overall efficiency

Panel - Minor
Enhanced search features
TOR Blacklist
Remove bot/other buttons on bot list
Graphs added to statistics page / Panel settings reorganized
Can now delete individual form/login grab entries
Can now add lists of formgrab url masks at a time (Instead of just one at a time)
Modify main bot list view settings (Change display order and maximum number of bots displayed per page)
Main index now displays top 5 countries graph and world map based on bot count
GeoIP updated

Panel - Major
Notes system. Leave notes for single/all user(s)
Task failure tracking
AV Checker (s4y)
Event logs page added in panel settings
Bot grouping via group names
Formgrabber filter management options increased, form search enhanced and other useful changes to formgrab feature
Login grabber can now be toggled on/off


Fixes/Tweaks
Fixed issue where large amounts of page numbers would take up entire webpage
Fixed issue with formgrab filter management not properly handling some SQL queries
Fixed issue with task processing where if bot received more than 3 tasks at once, it would only process first 3, and may sometimes crash while attempting to parse the 4th one
Fixed crash issue related to thread creation in some processes
Fixed rare issue in process injector where an improperly initialized structure could result in fatal crash
Fixed a few memory leak issues
Fixed formgrabber compatibility with Firefox versions >= 22
Fixed issue with hook restorer not restoring system call hook
Fixed formgrabber for Windows 8, however, userkit is still having issues
Tweak: Systems configured to use a proxy for internet access are now supported if bot cannot access directly after cycling through C&C list
Tweak: HTTP Component now handles `302 Found` issues better. However, issue is considered *not* completely resolved.
Tweak: More AVs detected and displayed on panel statistics
Tweak: Grabbed logins exports are now in standard ftp://user:pass@domain.com -OR- type://user:pass@domain.com:port
Tweak: UAC Social engineering trick no longer uses cmd.exe on Windows 7 systems
Tweak: Duplicate bot issue should be *less* of a problem now. However, not completely fixed

Friday, July 4, 2014

SOLAR BOTNET Downloade


hello guys 

          today i am back with new botnet which is called SOLAR BOTNET  and its an latest botnet which it help to hack secure browser like chrome etc..



for more details u can contact me @

SKYPE: suriya.cyber

yahoo: cybersuriya73@yahoo.com






Technical Details
Coded in Lazarus (Pascal)
Code is fully relocatable (Shellcode)
Uses custom CRC32 API loader
Uses BeaEngine Disassembler for x86 and x64
Uses named pipes for inter-process communication
Multpiple layers of encryption and compression
Global Ring 3 rootkit and No own process
Fully Unicode
No dependencies (Only standard system DLLs)
Multiple Anti-Debug methods
Unique Server->Bot traffic encryption
Anti bot installation



Features


Internet Explorer Formgrabber
Mozilla FireFox Formgrabber
Google Chrome Formgrabber
SPDY Grabbing
FTP and POP3 Grabber
SlowLoris DDOS and SlowPost DDOS
GET Flood
UDP DDOS
Update and Download System
MD5 Verified Update and Download System
Reverse Socks 5








Carbon Form Grabber (C++)


Hello Guys, 

                   I am back after long days with new stuff which is call Carbon Form Grabber .Its coded in the language of  C++ .It have lot of cool Features  like




Features


* Startup ( Hidden)
* Userkit(x86 & x64 )
* Injection
* Chrome SSL & HTTP Grabber
* Firefox SSL & HTTP Grabber
* Internet Explorer SSL & HTTP Grabber
* Intuitive PHP Panel
* Escalate to Administrator Privileges.



Features to be Added
    Persistence | Regex patterns | Delete all logs button to





For More Details You Can Contact here



yahoo: cybersuriya73@yahoo.com
skype: suriya.cyber



Sunday, September 29, 2013

8 Ways To Protect Your Website From DDoS Attack




1. Efficiency
DDoS is a war of attrition ? efficient use of resources is a key defence. Applications need to be designed from the ground up with efficiency in mind:

- well architected and designed
- efficient code and algorithms
- proper memory allocation and clean up
- configurable time outs and resource restrictions

====================================

2. Excess Capacity
If your site is running at 90% capacity with normal traffic ? it is a sitting duck for a DDoS attack.

The more excess capacity (throughput) you have the better ? cloud infrastructure that allows you to dynamically add capacity is ideal

====================================

3. Testing and Planning
DDoS attacks can be simulated as part of performance testing. Testing helps you to understand how your application bares the stresses of a DDoS ? so that you can plan a defence

====================================

4. Layer 4 Network Equipment
Switches and routers generally built in defences for layer 4 attacks.

Effective layer 4 defences include bogus IP filtering, traffic shaping, TCP splicing and rate limiting. Work with your ISP or network equipment vendor to understand the features of your network.

====================================

5. Bandwidth Management
Bandwidth management hardware allows you to classify incoming traffic as priority, regular or dangerous. It event of a DDoS attack non-priority requests can be dropped

====================================

6. Intrusion Detection Systems (IDS)
IDS look for attack patterns in incoming traffic and can drop suspicious packets.

====================================

7. Custom Defence
Many layer 7 attacks require a custom on-the-fly defence. Typically, web developers analyse traffic patterns for irregular:

- IPs
- request signatures
- http headers
- form parameters

Once a pattern is determined filters can be implemented on the web server to drop matching requests

====================================

8. Blackholing and Sinkholing
Severe DDoS attacks may require Blackholing ? sending all requests to a non-existent server. This brings the website down but relives the pressure on the server.

Sinkholing sends all requests to a logger that logs some statistics and then drops the requests. Sinkholing can help developers establish attack patterns
====================================

Top Most used Backdoor Programs





Using these programs any noob can remotely access your computer without any Authentication and do whatever he wants. I will tell you some of the features rest of them you need to try it and find out. These Programs :

=> Work as a key logger.
=> Send any Information from Victim?s PC to the Hacker?s PC.
=> Run any program on the Victims PC.
=> Display any Violating Image on victim?s Screen.
=> Open the CD Drive of the Victim?s PC.
=> Open any Web page on the Victims Screen.
=> Disable any Specific Key or whole Keyboard.
=> Shutdown Victim?s PC.
=> Start a Song on the Victim?s PC.etc.etc????..

Back Orifice / Back Orifice 2000

Back Orifice is one of the most common backdoor programs, and one of the most deadly. The name may seem like a joke, but sure, the threat is real. Back Orifice was established in Cult of the Dead Cow group. Back Orifice is an Open Source Program. The main Threat of this software is that by making some changes in the code anybody can make it undetectable to the Anti virus Program running on the Victim?s computer. Apart from the strange title, the program usually gets port 31337, the reference to ?Lit? phenomenon is popular among hackers.

Back Orifice uses a client-server model, while the server and client is the victim attacker. What makes Back Orifice so dangerous that it can install and operate silently. There is not required interaction with the user in, meaning you could its on your computer right now, and do not know.

Companies such as Symantec have taken steps to protect computers against programs that they consider dangerous. But even more attacks using Back Orifice 2000. This is due partly to the fact that it is still evolving, as open source. As stated in the documentation the goal is ultimately the presence of the Back Orifice 2000 unknown even to those who installed it.

Back Orifice 2000, developed for Windows 95, Windows 98, Windows NT, Windows 2000 and Windows XP.

Where can I download Back orifice 2000?

Back Orifice 2000 can be downloaded at the following address: http://sourceforge.net/projects/bo2k/

I infected! How do I remove it?

Removing Back Orifice 2000 may require that you change the registry settings. To remove it at 7 simple steps, refer to the diagram below.

How do I delete Back orifice 2000

1.Click Start> Run, and type ?Regedit?(without the quotes)
2.Follow the path below: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\RunServices ?
3.Now looking in the right box: ?The umgr32 = ?c: \ windows \ system \ umgr32.exe?
4.Right-click on this entry and click Remove. Now restart your computer.
5.After restarting only open Windows Explorer. Make sure you can see all registered extensions. To do so, select ?View Options and configure the appropriate settings.
6.Go to the WINDOWS \ SYSTEM directory, and find ?umgr32.exe? file. 7.Once you find it, delete it.
8.Exit Windows Explorer and reboot again.

NetBus / Netbus 2.0 Pro

NetBus was established around the same time that the Back Orifice was in the late 1990′s. NetBus was originally designed as a program prank friends and family, of course anything too malicious. However, the program was released in 1998, and is widely used as a backdoor to manage computer.

Like the Back Orifice, NetBus allows attackers to do virtually everything in the computer victim. It also works well under Windows 9x systems, as well as Windows XP. Unlike Back Orifice, the latest version of NetBus regarded shareware is not free. NetBus is also implementing less stealthy operations, as a direct result of criticism and complaints of abusive use.

Where can I buy and download NetBus?

NetBus can be purchased and downloaded at the following address: http://www.netbus.org/

Ok, I am infected. Now what?

Fortunately, the latest version of NetBus is a valid program. It can be removed just like any other program. Previous issuance NetBus is a bit more tricky, however. If you are not lucky enough attacked with the latest version, the withdrawal process and in the Back Orifice.

How do I remove NetBus?

1. Click Start> Run, and type ?Regedit ?(without the quotes)
2. Follow the path below: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\RunServices ?
3. Now, in the right box, looking as follows: ?[Name_of_Server].?Exe Of course, you have to find the actual name of this file EXE-. Usually This? Patch.exe ?or? SysEdit.exe ?, but may vary.
3. Reboot and remove all traces of the actual program, which can be left. 4. Additionally, you can set yourself NetBus, and then use its own function disposal.

SubSeven / Sub7

SubSeven or Sub7, has been established for the same purpose was to NetBus pranks. Sub7 actually has more support for pranks, and has more advanced users. Sub7 also widely used by the script kiddies, although that many firewalls and anti-virus software before initialization.

Since Sub7 not supported for several years, the threat is usually very low. Most security programs will not have any problem in ending Sub7 before it has a chance to be started. This shows that the importance to the modernization and security programs is critical, because the money was still there.

Nevertheless, it is widely used by those who have physical access to your firewall, or security programs. If access rights, the tool will work without restrictions.

Where can I buy and download Sub7?

Sub7 not supported more, and hence is not available for download on any legitimate websites. If you were to make a Google search, you would find links to download Sub7. However, this is not the official site, and should be considered dubious and dangerous.

Sounds harmless, How do I remove it?

End of the following processes through the curator: ?editserver.exe, subseven.exe?
Delete the following files: ?editserver.exe, subseven.exe, tutorial.txt.?
Why these programs is absolutely legitimate?

All the basis behind these programs is that they are designed to help people, not harm. While some like NetBus really were originally created for pranks, they switched routes to avoid legal problems.

These programs claim to be the legitimate remote desktop program, although they certainly easily used for malicious use. These programs really should be used to aid or customer support departments. Why all adolescents is to copy these programs goes beyond us, but leave the content of their networks, while computer is a good idea.

The advent of new technology has made these programs in some respects less effective. However, programs such as Back Orifice 2000, yet still evolving, so do not be surprised to learn that he works in the background, waiting for instructions. Since the best defense is a good offense, be sure to save a sharp eye on what is installed on the network computers. After all, an ounce of prevention is worth a pound of cure.