<![CDATA[VX Heavens forum - Virus talks]]> http://vx.netlux.org/forum/index.php Mon, 26 Dec 2011 17:59:24 +0000 PunBB <![CDATA[About Mariposa and ButterFly Bot]]> http://vx.netlux.org/forum/viewtopic.php?id=115&action=new Hi Guys,
Anyone have a sample of "Mariposa" bot or ButterFly Bot sample?
Thanks.

]]>
Mon, 26 Dec 2011 17:59:24 +0000 http://vx.netlux.org/forum/viewtopic.php?id=115&action=new
<![CDATA[HI n i thought VX scene was DEAD :)]]> http://vx.netlux.org/forum/viewtopic.php?id=1902&action=new WOW was checking around the forums and theres seems to be alot of activities! where have i been lol. I don't know what bring me back to here but .... nice.....

]]>
Sat, 24 Dec 2011 03:07:25 +0000 http://vx.netlux.org/forum/viewtopic.php?id=1902&action=new
<![CDATA[VM's safe for testing malware?]]> http://vx.netlux.org/forum/viewtopic.php?id=1424&action=new I'm curious if it's safe to test malware in a VM? I'm pretty sure this is a yes, but need to be sure.

]]>
Sat, 24 Dec 2011 03:04:37 +0000 http://vx.netlux.org/forum/viewtopic.php?id=1424&action=new
<![CDATA[Open source rootkit? (ring0)]]> http://vx.netlux.org/forum/viewtopic.php?id=1925&action=new I'm hoping to find source code for a ring0 rootkit for Windows Xp. Any recommendations for a stable one?

]]>
Sat, 24 Dec 2011 02:23:17 +0000 http://vx.netlux.org/forum/viewtopic.php?id=1925&action=new
<![CDATA[TLINK32 options error]]> http://vx.netlux.org/forum/viewtopic.php?id=1873&action=new I have a problem in TLINK32 linker when use /tpe or -tpe option. I encounter "Invalid Option" error in link time. Also, I use TASM 5.0.
What is the solution of this problem?

]]>
Thu, 15 Dec 2011 17:19:54 +0000 http://vx.netlux.org/forum/viewtopic.php?id=1873&action=new
<![CDATA[H4ck1ngTeam.it Remote Control System?]]> http://vx.netlux.org/forum/viewtopic.php?id=1836&action=new i just saw this tool, i guess its like a Remote Administration Tool or something, anybody got any information about it? maybe what features does it have? screen shots??

here is the link
[Register or log in to view the URL]

don't bother checking the videos, they are useless like TV Ads.

thanks.

]]>
Mon, 12 Dec 2011 00:54:23 +0000 http://vx.netlux.org/forum/viewtopic.php?id=1836&action=new
<![CDATA[Malware Asm Code generator]]> http://vx.netlux.org/forum/viewtopic.php?id=1797&action=new Hi,

I downloaded NGVCK,VCL,G2 and...virus construction kits for produce malware asm code that be compile easly.
But, I can't compile NGVCK or VCL32 virus correctly and I encounter some error in compile time when compile its with TASM32 and link with TLINK32.
NGVCK asm file compiled incorrect and map file is include below error:

Error: Unresolved external 'EXITPROCESS' referenced from module C:\TASM\BIN\NGVCK11.asm

and when I compile VCL32 malware asm file, below error write in map file:

Error: Unresolved external 'SLEEP' referenced from module C:\TASM\BIN\14.ASM
Error: Unresolved external 'EXITPROCESS' referenced from module C:\TASM\BIN\14.ASM

and when I analysis this exe files with anubis sandbox, I received same result for all of compiled files.

what is the reason of this errors and How change asm file to handle this errors?

thanks

]]>
Thu, 08 Dec 2011 21:22:37 +0000 http://vx.netlux.org/forum/viewtopic.php?id=1797&action=new
<![CDATA[Loading and executing elf from memory.]]> http://vx.netlux.org/forum/viewtopic.php?id=1821&action=new Hi everyone. Glad to be registered to this forum.

Please tell me is there a way to execute ELF file from memory?

I wrote a simple code in C, which reads elf-header, loads all segments by mmap into memory and transfers control to start point of executable by asm-command jmp. Everything goes ok with simple asm-programs like hello-world, but I get segfault while executing more complicated C-programs.
I've tried to pack them by UPX first, when load compressed file by my program (there are only two code segments in upx-file, no interpreter), but also got segfalt.

I think there are three problems:
1) I don't know how to correctly load interpreter (like /lib/ld-linux.so.2) and dynamic libraries.
2) I don't know what I should do with .got section, .bss section and others. It isn't enough to place them in memory, is it?
3) I place my code at wrong address (I tried 0x01048000 and 0x09048000).

I thought UPX would solve my problems #1 and #2, but I was wrong because UPX reads itself from file got by /proc/self/exe.
Also, I looked through UPX unpacker code, but it's a bit too complicated for me, so it would take a long time to understand it and implement it in my program.

Any ideas would be helpful, thanks!

]]>
Wed, 07 Dec 2011 12:53:24 +0000 http://vx.netlux.org/forum/viewtopic.php?id=1821&action=new
<![CDATA[Bot Net source codes]]> http://vx.netlux.org/forum/viewtopic.php?id=89&action=new Hi Guys..,

I'm currently looking for source codes for bot nets. Such as Koob Face,Zues, Trojan.Fakeavalert.

Can any one help me on this ?

Thanks.

]]>
Mon, 05 Dec 2011 01:00:58 +0000 http://vx.netlux.org/forum/viewtopic.php?id=89&action=new
<![CDATA[how directx keylogger works...]]> http://vx.netlux.org/forum/viewtopic.php?id=1800&action=new here aklt is firewall leak tester ...it is using one type Directx key logging....plz give me nay kind of info on this m searching lot ...

]]>
Fri, 25 Nov 2011 10:57:11 +0000 http://vx.netlux.org/forum/viewtopic.php?id=1800&action=new
<![CDATA[DLL Injection using AppInit_DLLs on vista and win7 ?]]> http://vx.netlux.org/forum/viewtopic.php?id=1653&action=new DLLs listed under the registry key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\
AppInit_DLLs
will be loaded into every process that links to User32.dll as that DLL attaches itself to the process.

works Fine with windows xp.
but not working on vista and win7

i also took help from bill gates..:)


LoadAppInit_DLLs
(REG_DWORD)   
Value that globally enables or disables AppInit_DLLs.
0x0 – AppInit_DLLs are disabled.
0x1 – AppInit_DLLs are enabled.

AppInit_DLLs
(REG_SZ)    Space -or comma-delimited list of DLLs to load. The complete path to the DLL should be specified by using short file names.
C:\PROGRA~1\Test\Test.dll

RequireSignedAppInit_DLLs
(REG_DWORD)    Require code-signed DLLs.
0x0 – Load any DLLs.
0x1 – Load only code-signed DLLs.

these registry keys need to change for Dll injection on vista and win7
but not success

i build my dll on windows xp 32 bit machine.will that be problem when i use it on vista.

]]>
Fri, 25 Nov 2011 10:44:44 +0000 http://vx.netlux.org/forum/viewtopic.php?id=1653&action=new
<![CDATA[Looking for a tut]]> http://vx.netlux.org/forum/viewtopic.php?id=1782&action=new What is the best introductory tut for the simplest virus (prepender, appender) in c and asm. Something with detailed explanations is what I am looking for. Not very good with asm skills, so its important that details are specific. C skills ok, but good detail and comments still important.

Looking on this site, most explanations require some experience in virus writing, so thats not very introductory. Win32 and Linux ok. assembler does not matter which one. intel at&t syntax both helpful.

This site has alot of magazines also, maybe one of those has something, but it could take forever to find which one is up to date and useful.

So if anyone here can recommend something thanks.

Ps: I have done some research on my question and I can ask very specific questions about coding, if there is someone here that has the time to do a walkthrough with me, pm or email me. Win32 ok, but I would prefer Linux, gcc and linker and as or nasm. But anything that works is ok.

]]>
Fri, 18 Nov 2011 22:40:26 +0000 http://vx.netlux.org/forum/viewtopic.php?id=1782&action=new
<![CDATA[Code Obfuscators]]> http://vx.netlux.org/forum/viewtopic.php?id=1419&action=new Does anyone know of any tell-tale signs that may indicate what kind of code obfuscator may have been used to generate a binary? I'm sure that you could look at what kind of code obfuscation that is being done (e.g. control flow obfuscation, stack built strings, constant obfuscation, etc...), but I wonder if there's any way to signature what particular code obfuscator was used to generate a binary.  I recently looked at something that was full of jumps (which would eventually lead to function calls). Fortunately, it wasn't as annoying as obfuscation used in SpyEyes (for anyone who has ever looked at it), and I was able to use the IDA plugin optimice to clean up the code decently.

I've done some googling and found that [Register or log in to view the URL] has some proprietary software that can be used for software protection. I also found references to some older stuff like the z0mbie mutation engine. Anyone know of any other more mainstream code obfuscators--possibly even free ones? The majority of my googles are just giving me .NET stuff, and I'm more interested in C/C++ code obfuscators.

]]>
Thu, 17 Nov 2011 08:35:58 +0000 http://vx.netlux.org/forum/viewtopic.php?id=1419&action=new
<![CDATA[Best compiler for assembly?]]> http://vx.netlux.org/forum/viewtopic.php?id=1384&action=new Wondering what compiler would be best, i have a x64 system, but either would be fine.

nub question: is x64 diff to x84 when run or when compiled??

]]>
Tue, 15 Nov 2011 04:50:48 +0000 http://vx.netlux.org/forum/viewtopic.php?id=1384&action=new
<![CDATA[Relative path in LNK-exploit]]> http://vx.netlux.org/forum/viewtopic.php?id=1752&action=new Hello VX-world!

I am many researched Windows ShortCut's - flags, locked lnk and others interesting things.
StuxNet has opened me quite new subject. Shortcut on Control panel & DllMain...

So, possible create LNK and prescribe ABSOLUTE network path, and provide mass infection on LAN-network. smile
(\\comp\hidden-shared$\test.dll)

But...how can prescribe relative path in vulnerable lnk?
e.g. ".\test.dll"

]]>
Fri, 11 Nov 2011 22:54:55 +0000 http://vx.netlux.org/forum/viewtopic.php?id=1752&action=new