{"id":1186,"date":"2015-12-22T07:11:16","date_gmt":"2015-12-22T07:11:16","guid":{"rendered":"http:\/\/www.gironsec.com\/blog\/?p=1186"},"modified":"2016-01-27T06:10:24","modified_gmt":"2016-01-27T06:10:24","slug":"joecrypter-finally-released","status":"publish","type":"post","link":"https:\/\/www.gironsec.com\/blog\/2015\/12\/joecrypter-finally-released\/","title":{"rendered":"Joecrypter finally released"},"content":{"rendered":"<p>Finally, I&#8217;m done with this my crypter. I&#8217;ve written the entire thing in a mish mash of C#, C, and assembly. <\/p>\n<p><a href=\"http:\/\/www.gironsec.com\/blog\/wp-content\/uploads\/2015\/12\/joe_crypter.png\" rel=\"attachment wp-att-1187\"><img decoding=\"async\" loading=\"lazy\" src=\"http:\/\/www.gironsec.com\/blog\/wp-content\/uploads\/2015\/12\/joe_crypter.png\" alt=\"joe_crypter\" width=\"503\" height=\"515\" class=\"alignnone size-full wp-image-1187\" \/><\/a><\/p>\n<p>The crypter I made modifies exes, packs them, and adds AV \/ VM \/ Sandbox \/ debugging evasions inside of a wrapper. I&#8217;m employing a basic process hollowing technique for the payload that is only run after all evasions are satisfied. The anti-debug modules include anti-single stepping as well as anti-tracing. I can even detect procmon without checking the process list. <\/p>\n<p>The front end is in C# and that performs the rudimentary exe modifications and packing, however the real meat and potatoes is in the back end. The back-end compiler is <a href=\"http:\/\/www.smorgasbordet.com\/pellesc\/\" target=\"_blank\">Pelles C compiler<\/a> and the evasions are coded in C and assembly. The payload is loaded in as a resource and is encrypted (decrypted at run-time).<\/p>\n<p>I got a theme too as well as music that plays in the background. <\/p>\n<p>So what are you waiting for? <a href=\"http:\/\/www.gironsec.com\/chat\/JoeCrypter_V2(pass_is_infected).7z\" target=\"_blank\">Download it now!<\/a> Btw, the password is &#8216;infected&#8217; without quotes. <\/p>\n<div style=\"width: 600px;\" class=\"wp-video\"><!--[if lt IE 9]><script>document.createElement('video');<\/script><![endif]-->\n<video class=\"wp-video-shortcode\" id=\"video-1186-1\" width=\"600\" height=\"338\" preload=\"metadata\" controls=\"controls\"><source type=\"video\/webm\" src=\"http:\/\/www.gironsec.com\/blog\/wp-content\/uploads\/2015\/12\/devilish.webm?_=1\" \/><a href=\"http:\/\/www.gironsec.com\/blog\/wp-content\/uploads\/2015\/12\/devilish.webm\">http:\/\/www.gironsec.com\/blog\/wp-content\/uploads\/2015\/12\/devilish.webm<\/a><\/video><\/div>\n<p>&#8211;Fixed some bugs that made it not work. Also FF seems to report my code directory as &#8220;malicious \/ unwanted&#8221;. I switched the download dir to \/chat\/ instead to see if VT will leave me be. <\/p>\n","protected":false},"excerpt":{"rendered":"<p>Finally, I&#8217;m done with this my crypter. I&#8217;ve written the entire thing in a mish mash of C#, C, and assembly. The crypter I made modifies exes, packs them, and adds AV \/ VM \/ Sandbox \/ debugging evasions inside of a wrapper. I&#8217;m employing a basic process hollowing technique for the payload that is [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[4,6,7],"tags":[],"_links":{"self":[{"href":"https:\/\/www.gironsec.com\/blog\/wp-json\/wp\/v2\/posts\/1186"}],"collection":[{"href":"https:\/\/www.gironsec.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.gironsec.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.gironsec.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.gironsec.com\/blog\/wp-json\/wp\/v2\/comments?post=1186"}],"version-history":[{"count":6,"href":"https:\/\/www.gironsec.com\/blog\/wp-json\/wp\/v2\/posts\/1186\/revisions"}],"predecessor-version":[{"id":1199,"href":"https:\/\/www.gironsec.com\/blog\/wp-json\/wp\/v2\/posts\/1186\/revisions\/1199"}],"wp:attachment":[{"href":"https:\/\/www.gironsec.com\/blog\/wp-json\/wp\/v2\/media?parent=1186"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.gironsec.com\/blog\/wp-json\/wp\/v2\/categories?post=1186"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.gironsec.com\/blog\/wp-json\/wp\/v2\/tags?post=1186"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}