Malware Corporation
Closed channel
Official Telegram group of Malware Corporation forum Link: @malwarecorp Clearnet: https://malwarecorp.com Donate: https://malwarecorp.ton Our channels: @MalwareLinks Chat: @MalwareForums Price: @MalwareAds admin@malwarecorp.com
Show more7 559
Subscribers
No data24 hours
+427 days
+9330 days
Posts Archive
7 559
NtRemoteLoad
Remote shellcode injector, based on HWSyscalls by ShorSec, leveraging undetectable (currently) indirect native syscalls to inject shellcode into another process, creating a thread and executing it.
https://github.com/florylsk/NtRemoteLoad
Private: @MalwareCloudBot
Магазин вредоносных ПО - @MalwareShopBot
Project @MalwareForum
#shellcode #inject7 559
Repost from Stealer Service
Инструмент для создания вредоносных Zip-файлов, не требующих разархивации
ZipExec - это инструмент для выполнения полезной нагрузки, хранящейся в защищенных паролем zip-файлах, без их извлечения.
Инструмент передает zip-файлы на диск, используя JScript и COM-объекты, для создания zip-файла на диске и последующего их выполнения. Защита zip-файла паролем позволяет обходить EDR и механизмы сканирования антивирусов.
https://github.com/Tylous/ZipExec
Project: @MalwareCorp
Group: @MalwareForums
Private: @MalwareCorpBot
7 559
⏰24/7 - ЛУЧШИЙ ПОКУПАТЕЛЬ FACEBOOK НА РЫНКЕ
ПОКУПКА ЛОГОВ FACEBOOK БЕЗ ЗАМЕН
🔥 У нас 99% валидных методов входа в Facebook🔥
После работы с вашими логами, пожалуйста, не выбрасывайте их, а отправьте нам для проверки FACEBOOK COOKIES, вы получите приятный бонус к выплате:
- Фейсбук логи с биллингом 900$, мы купим за 540$ >720$ (60%-300% от биллинга)
- У кого хороший трафик > 500$, получат бесплатный ПРИВАТНЫЙ шифр
- Выплаты > 100$ + 5%-10% бонус
- Много ежедневных веселых розыгрышей на канале > 50$
- Мы покупаем более 20 типов аккаунтов facebook, которые никто не покупает
- Мы применяем закупочную цену, превышающую лимит расходования средств на счете, что является уникальным на рынке
🗞 Наш канал с ценами и новостями:
https://t.me/+lO6vRu7lNAZmY2Zl
- Работаем практически 24/7, мгновенная выплата при получении результатов
- Мы используем наш приватный чекер или известный FB FAST CHECKER, а также предоставляем отчеты в виде фотографий с результатами!
- Если трафик частный, то условия и цены обсуждаются лично
⁉️ Наши отзывы за 1 год:
https://zelenka.guru/threads/3876311/
https://bhf.im/threads/668568/
https://xss.is/threads/82394/
https://forum.exploit.in/topic/220666
📲 : @VNTRICKER
7 559
Repost from Crypters | Crypt Files | AV Bypass
⛔ @ xzol_drainer scam!! ⛔
Его аккаунты: @facebooktrafficc id: 6378680314
@xavier_drainer id: 5895051693
Его скам проекты: @ MonsterTrafficFB
@ XZOL_DRAINER_BOT
Пытается рекламить у нас в сетке скам проект!
Не ведитесь или строго работайте через гаранта!
7 559
BlackLotus UEFI Windows Bootkit
https://github.com/ldpreload/BlackLotus
Private: @MalwareCloudBot
Магазин вредоносных ПО - @MalwareShopBot
Project @MalwareForum
#blacklotus #bootkit #windows
7 559
Repost from IoT Botnets | DDoS
Mirai Slow Telnet Loader
The fasted and most effective telnet loader
Features/Capabilities:
basic echo response test
/proc/mounts directory parsing for readable and writables and executeable dirs
elf header parsing for /bin/echo for architecture detection
anti honeypot fake wget/curl detection mode (disabled in current version)
to enable set honeycheck to 1
Project: @IoTBotnets
Topic: https://t.me/MalwareForums/289005
Private: @IoTPrivateBot
7 559
Cobalt Strikers Blog
· CobaltStrike original/crack versions
· Artefacts
· Manuals
· Useful materials etc..
t.me/CobaltStrikers
7 559
Cerez is a LD_PRELOAD rootkit, it consists of two parts, a backdoor (written in python) and a loader (written in c). Loader is a SO binary that gets installed into /lib and writes its path into /etc/ld.so.preload, this way every binary on the system preloads it. By overwriting system functions like fopen, readdir, access and unlinkat it makes it nearly impossible to remove/detect the backdoor. I also wrote a simple client that you can use to connect the backdoor.
Features:
✔ Hidden in the process list
✔ Hidden in the file system
✔ Unreadable
✔ Undeleteable
✔ Unwriteable
https://github.com/StayBeautiful-collab/cerez
Private: @MalwareCloudBot
Магазин вредоносных ПО - @MalwareShopBot
Project @MalwareForum
7 559
Repost from IoT Botnets | DDoS
enemy SSH/Telnet IoT botnet
ssh/telnet self replicating "flame" botnet, features:
UDP/TCP/ICMP Flooding methods
mirai syn scanner ran if root
qbot scanner ran if non root
skidripped tor cnc from zbot
custom string encoding (char map lightaidra based)
custom botkiller strings for memory scanning
1s sleep on botkill
custom passlist for ssh
custom tor cnc for onion that broadcasts loader server
EXPLOITS:
liferay
sonicwall
huawei (not working)
SPECIAL METHODS:
blacknurse
DNS request flood (with random dns request id per packet)
Project: @IoTBotnets
Topic: https://t.me/MalwareForums/289005
Private: @IoTPrivateBot
7 559
Repost from IoT Botnets | DDoS
Pyrai - Mirai python variant
This is a working variant of the Mirai IOT botnet, this is fully written in Python3.
In the archive you will find complete installation instructions
Project: @IoTBotnets
Topic: https://t.me/MalwareForums/289005
Private: @IoTPrivateBot
7 559
Malware Reverse Engineering Handbook by Ahmet BALCI, Dan UNGUREANU and Jaromír VONDRUŠKA, NATO, 2023
7 559
Malware Reverse Engineering Handbook by Ahmet BALCI, Dan UNGUREANU and Jaromír VONDRUŠKA, NATO, 2023
There is no novel work presented in this handbook, as it can be considered as the first steps in investigating malware.
The reader will become familiar with the most common open-source toolkits used by investigators around the world when analysing malware. Notes and best practice are also included. By applying the techniques and tools presented here, an analyst can build Yara rules that can help during the investigation to identify other threats or victims.
#malware
7 559
Промокод: Promo20
Процент скидки: 20 %
Активаций промокода: 0 раз
Максимум активаций: 1
Прямая ссылка: https://t.me/MalwareShopBot?start=promoPromo20
7 559
Tired of fighting SmartScreen? Tired of getting few logs? Very low trust in your file?
We can help you!
Balamut Service
Already in stock:
EV Code Signing Certificates
Starting from
$4,000 for pre-order and $5,500 for stock.
EV code signing certificate:
1. Provides instant approval in Microsoft SmartScreen. This ensures that the user does not see an unrecognized publisher warning "Are you sure you want to run this program?".
2. Allows you to remove red and yellow UAC alerts
3. Allows you to sign drivers for Windows
4. Allows you to sign VBA and JavaScript
5. Allows you to bypass some antiviruses that block any files without a signature.
6. By signing a file, users have more trust in the file, because they see the organization that issued the certificate. Accordingly, the offset increases.
7. In SOME cases removes Google Alerts.
Our EV certificates are obtained exclusively for our companies and on our people.
No from logs, no for carding money. We can also go through any verifications in the future, if they are necessary.
When used on white files, it is guaranteed to live its entire service life. We can make a certificate from any certificate authority.
To your token, to our token with further forwarding, to Azure Key Vault and we can also make a certificate with remote access.
Contacts:
Telegram Admin
Telegram Channel
Telegram Chat
Topic on XSS7 559
Shellcode Execution via EnumSystemLocalA
https://blog.securehat.co.uk/process-injection/shellcode-execution-via-enumsystemlocala
Private: @MalwareCloudBot
Магазин вредоносных ПО - @MalwareShopBot
Project @MalwareForum
7 559
Repost from Android Botnets
The Complete Android Ethical Hacking Practical Course
Full Course
Complete Practical, No Bullshit.
Project: @AndroidBotnets
Topic: https://t.me/MalwareForums/286386
Private: @AndroidPrivateBot
7 559
DIY Linux Kernel Rootkit Detection
Хорошая статья для понимания процессов которые влекут за собой руткиты и как их ловить
Ловить будет руткит reveng_rtkit с помощью osquery-defense-kit
Private: @MalwareCloudBot
Магазин вредоносных ПО - @MalwareShopBot
Project @MalwareForum
#rootkit #linux
