Pages

Showing posts with label Malware. Show all posts
Showing posts with label Malware. Show all posts

Wednesday, 5 February 2014

Storm - DDOS Bot


Screens













Videos

https://mega.co.nz/#!5VtWwIiZ!MJYTS0nS4GbFRzfaVfnfKWbkp_E8_w68rcuT3i9_Qp0

https://mega.co.nz/#!gZ1yiLYC!MHK-nTtBlIweJu8Pv8yc8HXOhXEfbRGWcVW8eIh3ERE


Features

====Storm.Bot серверная часть====
Утилита предназначена ИСКЛЮЧИТЕЛЬНО для стресс-тестирования своих собственных сетей. За использования в незаконных целях автор ответсвенности не несет.
- Все модули бота находятся в одном бинарнике.
- Написан на чистом Си.
- Обфусцирован и упакован собственным алгоритмом.
- После запуска бота моментально самоудаляется.
- Хоть это и не windows-бот, все же бот пытается лишний раз не палить себя в системе, прячется под системный процесс, скрываются параметры запуска.
- При каждом запуске очищаются все возможные логи сервера начиная от .bash_history, заканчивая системными. Даже если сервер попадет не в те руки, никто ничего на нем не найдет.
- C&C(админ-панель) автоматически заливает бота при каждой атаке.
- Малый размер - менее 30кб.
- Работает на любой системе *nix(x86,x64).
- Защита по hwid при запуске бота, запускается только со специальным ключом, уникальным для каждого сервера.
- Общение между ботом и C&C зашифровано.

----------------------
*Модуль UDP DNS
----------------------
-Атака DNS-амлификацией.
-Файл с опен-резолверами подгружается в память целиком.
-Атака по рандомным портам.
-Атака по подсети любого размера.
-Возможна атака по любому диапазону(пример 1.1.1.1-1.1.23.2).
-Выжимает максимальную мощность из дедика при низкой загрузке процессора.
-Возможна одновременная амплификация с разных доменов.
-Выбор DNS Query type для атаки(A/TXT/ANY).
-Выбор определенных стран(реализовано на стороне C&C).
-Многопоточность.

----------------------
*Модуль SYN(Syn-Random, Syn-IP-list, Syn-Country, Syn Amplification(Он же SYN Reflection)
----------------------
-Атака "perfect" spoofed-syn-флудом, пробивающим очень многие анти-ддос защиты.
-Syn-пакет !полностью! идентичен пакету Windows 7/8.
-Атака по рандомным портам.
-Выжимает максимальную мощность из дедика при низкой загрузке процессора.
-Автоматическое определение страны атакующего сервера и атака только с ип-адресов той страны где непосредственно находится сервер(Syn-Country флуд).
Данный тип флуда помогает избежать потерь PPS на магистральных провайдерах и на умных маршрутизаторах некоторых датацентров.
-Атака с подменой ип адресов по вашему собственному списку. Сделано для того чтобы все эти ип адреса с большой вероятностью забанились на антиддос провайдере.
-Атака SYN(TCP)-Амплификацией. Возможно поднять мощность PPS в 5 раз(но при этом потеряется немного легальность пакетов, ибо приходить будут SYN-ACK\RST).
-Выбор определенных стран для SYN амплификации(реализовано на стороне C&C).
-Возможность выбора к атакам Syn-Random, Syn-IP-list, Syn-Country параметр ACK.
После каждого SYN будем слать полулегальный ACK. Полулегальный потому что невозможно угадать Seq-number, возможно угадать только Win-окно.
Если комбинировать различные типы атак - то сносит напрочь мозги всяким цискам и джуниперам.
-Многопоточность.

----------------------
*Модуль ABUSE
----------------------
-Атака "Abuse" SYN/ACK флудом по 22/21 портам, с подменой ип адреса жертвы.
Суть заключается в том что мы загружаем большие подсети разных датацентров, и флудим их на 22 и 21 порт, подставляя в обратный ип - адрес жертвы.
И на этот адрес сыпется куча абуз за SCAN/Bruteforce/DDOS 22(ssh) и 21(ftp) портов других датацентров. Большое поле для экспериментов, например залить подсеть US Army или UK Ministry of Defense.

----------------------
*Модуль DNS Scaner
----------------------
-Состоит из двух потоков которые запускаются параллельно, один из них биндится на задданный порт, второй рассылает днс-запросы к потенциальным опен_резолверам.
-Принимает в виде листов как и список ип адресов, так и список подсетей вида 1.1.1.1/24
-В качестве аргумента принимает домен для DNS-запроса и тип query запроса.
-Возможность установить нижний минимальный лимит ответа от DNS опен_резолвера в виде аргумента(например не сохранять опен_резолверы, которые отвечают менее 512 байт)
-Искуственная умная задержка при разных типах сканирования (чтобы не упираться в лимит канала сервера) и всегда собирать ответы от опен_резолверов.

----------------------
*Модуль SYN Scaner
----------------------
-Состоит из двух потоков которые запускаются параллельно, один из них биндится на заданный порт, второй рассылает SYN-запросы на 80 порт.
-Принимает в виде листов как и список ип адресов, так и список подсетей вида 1.1.1.1/24
-Возможность установить нижний минимальный количества ответов от серверов(например не сохранять сервера, которые ответили SYN+ACK менее чем два раза)
-Искусственная умная задержка при разных типах сканирования (чтобы не упираться в лимит канала сервера) и всегда собирать ответы от серверов.
----------------------

Все управление ботом осуществляется через Веб-админку, админка полностью многопоточная, веб2.0, аякс, jquery, все статусы серверов обновляются на аяксе. Все это и прочие штуки работают интуитивно понятно.

Полный комплект всего этого добра стоит 2500 USD.
Оплата в webmoney, либо bitcoin.

Thursday, 20 September 2012

Ulocker Crimeware

Cross posted from Russian Cyber Criminal Forum

English translation @Sherb1n

Seller - xfrzx

Ulocker is EU traffic monetization software. It accepts payments through Ukash and Psc vouchers for €50 or €100.

As of today, it supports AT,CH,CY,DE,ES,FI,FR,GR,IT,NL,PL,PT,RO,SE. You are able to add and modify the number of languages.

Details:

1. Size: ~22KB uncompressed.
2. Kills MSCONFIG.exe, regedit.exe, regedit32.exe, CMD.exe, taskmgr.exe.
3. Accepts Ukash and Psc.
4. Hides Start menu and taskbar.
5. Blocks system keys.
6. Can modify text remotely.
7. Does not turn on if there's no internet connection (optional).
8. Launches on startup.
9. Disables Safe mode (XP)
10. Always on top.
11. Stays up after entry.
12. It's easy to add new languages to work with additional countries (!)

Server component:

Option 1: No panel, writes to file: date || ip || ukash || amount || country. The same for Psc. Responses are written to file.
Option 2: Simple panel, displays vouchers (ukash, psc), displays responses. Requires Php+MySql.
Responses are replies from the infected machines, not necessarily unique ones.

Price:

For the first 3 buyers: $250. 0/3.
The price does not depend on the server component.

The buyer receives:

1. Consultation at the time of purchase.
2. Minor updates for free.
3. You do your own encryption.
4. Help adding new language modules. Not creating, only adding. I'll show you how, it's very simple.
5. Don't have the builder yet (!). Free rebuilds.
6. Vouchers are not checked for validity. Checking services can be added if available.

You're prohibited from:

1. Uploading the build to public AV checkers.
2. Making this software available to others.

Violators will get banned without a refund.

Original

Seller - xfrzx

Ulocker - софт для монетизации евро загрузок.В качестве оплаты принимает Ukash,Psc ваучеры по 50,100 евро.
На данный момент AT,CH,CY,DE,ES,FI,FR,GR,IT,NL,PL,PT,RO,SE . Вы сможете добалять и изменять количество языков.

Детали:

1.Вес ~22кб без сжатия
2.Убивает MSCONFIG.exe, regedit.exe, regedt32.exe, CMD.exe, taskmgr.exe
3.Принимает Ukash,Psc.
4.Скрывает пуск и панель.
5.Блокирует системные клавиши.
6.Возможность удалённо менять текст.
7.Не включается при отключенном интернет(Опционально).
8.Автозагрузка.
9. Отлючение Безопасного режима(хп)
10.Висит поверх всех окон.
11.После ввода не снимается.
12. Возможность быстро и удобно добавлять свои языки для работы с конкретными странами(!)

Серверная часть:

1й вариант - без панели пишет в файл дата || ip || ukash || номинал || страна .C psc аналогично.Пишет отклики в файл.
2й вариант - простенькая панель ,вывод ваучеров(ukash,psc) ,вывод откликов.Необходимо Php+MySql.
Отклик - отстук зараженной машины,не обязательно уникальный.

Цена:

Первым 3 покупателям - 250$ 0/3 .
Цена не зависит от варианта серверной части.

Покупателю:

1. Консультации при покупке.
2. Мелкие апдейты бесплатно.
3. Крипт лежит на вас.
4. Помощь в добавлении языков для работы локера. Не создании,а добавлении.На примере,очень просто.
5. Билдера пока нет(!).Ребилд бесплатно.
6. На валид ваучеры не чекаются.Если есть сервисы для чека,можно добавить.

Запрещено:

1. Сливать билд на паблик чекеры АВ.
2. Выкладывать софт.

При нарушении в бан,без возврата средств.

Upas Rootkit

Cross posted from Russian Cyber Criminal Forum

English translation @Sherb1n

Seller - Auroras

Upas Kit 1.0.0.0

Description:

Upas is a modular http bot created for a single purpose - eliminating your headache. It's an advanced Ring3 rootkit that has something in common with SpyEye and Zeus. As a result, it's installed "silently", without triggering AV. As of today, it works on the following Windows versions: XP, Vista, 7 (Seven), Server 2003, server 2008. It's also "compatible" with all the service packs.

In its current version the rootkit can be injected into any 32-bit process. Written in C++.

By default, the kernel comes with the following modules (additional modules sold separately):

Rootkit
Download/Execute
Update
AntiRuskill
HTTP Panel
Antis

The following modules are sold separately:

USB spreader (lnk/autorun)
Botkiller
Form Grabber (IE, FF, Chrome)
FTP Grabber
Flooders Package - SYN/Slowloris/UDP
DNS Hook
Visit (hidden, show)
Ruskill
Post Spreaders

Prices, as of 6/14/2012:

Kernel $1000
Usb Spreader $200
Form Grabber $1000
Recompile with the same data $10
Recompile with different data (if your DNS is blacklisted or blocked) $50

The prices may seem a bit infated, but if you consider the conversion rate and how effective this kit is, the price is right.

Panel features:

GeoIP (Maxmind)
IP block when the gate receives a response from anything but a bot
IP block when the input data is brute-forced
Add/Remove/Manage users
Installs log
Scan2you scanner for checking files, exploits, IPs, domains, etc. through web requests.
Detailed stats using Google Chart Tools
CAPTCHA at login, to prevent password brute-forcing
Easy way to add/remove jobs with parameters
Pre-populated list of sites for grabbing, ability to modify websites grabbed by Form Grabber
Per-country commands
Simple installer
English and Russian interface

Special features:

Antis file analysis protection
Decent sized stub
Easily cryptable
Unlimited domains. If a domain is unavailable, the bot tries the next one.
Ability to specify subdomains the responses will be sent to.

Disclaimer:

Upas Kit was created for penetration testing of personal and business information systems.
Upas Kit has never been and cannot be used to commit cybercrimes.
By purchasing this software you agree to not break the laws of the Russian Federation and other countries.
By purchasing this product you agree to use it at your own risk. Before installing this software on anyone's computer, you need to ask for that person's permission.


Original

Seller - Auroras

Upas Kit 1.0.0.0

Описание:

Upas - это модульный http бот, который был создан с единственной целью - избавить вас от головной боли. Это продвинутый ring3 руткит, имеющий что-то общее со SpyEye и Zeus. Таким образом установка происходит "тихо" без опознования антивирусами. В данный момент он работает на следующих версиях Windows: XP, Vista, 7 (Seven), Server 2003, Server 2008. Помимо этого "совместим" и со всеми сервис паками.
В текущей версии руткит внедряется во всех 32-х битные процессы. Приложение написано на С++.

По умолчанию ядро поставляется со следующими модулями (дополнительные покупаются отдельно)

Rootkit
Download/Execute
Update
AntiRuskill
HTTP Panel
Antis

Список модулей, которые можно приобрести отдельно:

Usb spreader (lnk/autorun)
Botkiller
Form Grabber (IE,FF,Chrome)
FTP Grabber
Flooders Package - SYN/Slowloris/UDP
DNS Hook
Visit (hidden, show)
Ruskill
Post Spreaders

Цены актуальные 6/14/2012 числа:

Ядро $1000
Usb Spreader $200
FormGrabber $1000
Перекомпиляция на те же данные $10
Перекомпиляция с вводом других данных (если DNS попали в лист, либо заблокировали) $50

Цены могут показатся завышенными, однако, если прикинуть степень монетизация и эффективности данного софта цена становится обоснованной.

Возможности панели:

Geoip от maxmind
Блокировка IP если отстук на гейт пришел не от бота
Блокировка IP в случае брута данных входа
Добавление/Удаление/Управление пользователя
Журнал загрузок
Сканнер Scan2you, использующий веб-запросы для сканирования файлов, эксплойтов, IP, доменов и т.д.
Детальная статистика с использованием Google Chart Tools
Капча при входе в панель для усложнения процесса подбора пароля
Простое и удобнное добавление/удаление задач с параметрами
Готовый список сайтов для грабинга, возможность изменения сайтов сграбленных Форм граббером (Form Grabber)
Отправка команда по странам
Простой установщик
Английский и русский языки

Особенности бота:

Antis защита для предовтращения от анализа вашего файла
Decent sized stub
Easily cryptable
Легко шифруем
Неограниченное число доменов. Отстук идет по доменам, в случае неудачи берется следующий.
Возможность отстука для произвольный поддомен


Отказ от отвественности:

ПО Upas Kit было создано для выявления уязвимостей в информационных системах как частных лиц, так и огранизаций.
Upas Kit никогда не использовался для совершения кибер преступлений и таковым быть не может.
Покупая данный продукт вы соглашаетесь не нарушать законы Российской Федерации и других стран.
Покупая данный продукт вы используете его на свой страх и риск. Перед загрузкой приложения на ПК пользователя вы должны получить его согласие.

Monday, 19 March 2012

Citadel 1.3

Citadel Zeus Bot is under active development and new version 1.3.3 is released by its coder Aquabox.

The author post is directly copied from underground forum and translated to english for your convenience. Thanks to @Sherb1n.


Citadel v1.3.3.0 Spring Edition!

It's springtime, a time when everything changes and functionality goes into full bloom. Pimp out your ride for the summer!

Our product has become quite unique, so we're going to give an overview of all the features you can start using right away to get even more profit out of the new version:

1) Admin control panel has a new section, "Performance and Security", which has been integrated with the scan4you service; now you can run AV detection checks for all of your exe builds with a single click, right from the Citadel control panel. You can also set up automated daily scans, so that if one of your files gets burned by more than 3 AVs, you'll receive an instant Jabber notification and will be able to replace the exe right away. Now that this task is automated, you can feel free to be lazy!

2) Some customers complained that only 40% of their bots were getting updated to the new exe versions, while the rest were failing to update for an unknown reason. Indeed, that turned out to be a bug from the old ZeuS times; we did some research and fixed it. Now config has a new parameter: timer_autoupdate 8, which sets how often (in hours) the bot will download and restart the exe from the server (RC4 key should match). 80% of bots are now successfully updating; go ahead, encrypt and re-upload your exe, with the uptime improved by 37.1%, your bots will have the freshest and cleanest builds.

3) Server reporting system has been rewritten. In previous versions, every report generated a separate POST request to the gate; in the new schema, reports are sent in batches. This reduces the number of open sessions and minimizes the server load, allowing the server to support a larger number of bots online.

4) Video recording format has been changed to .webm (HTML5); an online video player has been built into the Citadel control panel, and now you can watch the videos right in your browser (Opera is recommended). Features: rewind, fast-forward / full-screen / search for videos by BotID, IP address, date.
But that's not all, we didn't stop there: many of you are using AT (and it's about time everyone else started using it to develop this industry collectively), and personal admin servers for your injects/account collections, etc. Wouldn't you like to watch videos of how well your auto-transfers and injections work, right from your admin panel on that server? That's easy! We've created an API system for this: just send your BotID or IP address to the script, and the API will send back an HTML embed code for all the videos uploaded by that bot. You can embed and watch this video wherever you want, even on narod.ru, without having to visit the Citadel server.

5) An improved system command (CMDList) analyzer/parser has been added to the admin panel. Now you can use the new table layout to view the output of system commands like ipconfig, the list of machines on the local network, the list of running processes, etc.

6) Now, upon installation, the bot will automatically send to the server a one-time report with the following information: installed firewalls, installed AV products, installed programs.
This information can be viewed for each bot separately, or for the entire botnet. We've created a new admin panel section where you can see all these stats, visual graphs and calculations. Now you know who you're up against.

7) "Favorite logs" - this new feature allows you to mark any account (or report) of interest when searching for data in admin; the accounts will be highlighted, and you can easily find them later.

8) A new "CardSwipe" module has been developed. It can grab card numbers and dumps out of HTTPS/WinSocket traffic and send them as a separate report.
The module uses LUHN10 algorithm to analyze traffic. Margin of error - 25%.
Price: $250 LR.

9) Injects are now compatible with UTF-8, and can be customized for any language (Japanese, Chinese, etc.)

10) Want to find new clients or business partners in your line of work? Consider placing your banner ad with the Citadel CRM.
Number of ad spaces: only 3 (234x60), two are still available; we only accept ads for relevant vendors and services (installs, encryption, traffic, etc., business partner search). Contact support through Jabber for a price quote.

As always, this update is free for our current clients. Place your requests through Jabber or CRM. (The update kits will be delivered on March 15, at 11:30PM).

New clients will receive a discount when buying the full package!

Citadel V 1.1

http://cyb3rsleuth.blogspot.co.uk/2012/01/citadel-zeus-bot.html

Wednesday, 1 February 2012

Andromeda Bot


English translation by @Sherb1n

Coder - Waahoo - Adv on Private Forum

Description:

This versatile modular bot can be used as the foundation for a botnet with an endless variety of possibilities. The bot’s functionality can be expanded through a system of plugins, any number of which can be added at any time.

Supports unlimited number of reserve domains.

Data exchange protocol between the bot and the admin server is RC4-encrypted.

 You can reconfigure your botnet to your needs at any time, by yourself.

Doesn’t overload the system, doesn’t require admin rights to install, doesn’t trigger a UAC pop-up.

The bot protects itself, so an unskilled user will not be able to remove it from the system.

Bypasses firewalls, doesn’t appear in the list of processes, injects into a trusted process.

Doesn’t produce any DLLs, doesn’t contain TLS, easy to encrypt.

Regardless of how successful the installation is, the original executable is deleted.

Works on WinXP through Win7, including x64 systems.

Very lightweight, written entirely in Assembler.

There are two versions of this bot:

01.* public inject-based, uses QueueUserAPC
02.* bypass-based; this version, unlike the one above, can get through proactive defense.

Written in PHP, bundled with MySQL.
Detects bots behind the NAT.
Keeps botnet stats: # of bots online/offline/dead, breakdown by country, breakdown by platform.
Keeps track of the number of finished/unfinished tasks.
Can set a limit on the number of times the task will be executed.
Can assign tasks to individual bots.
Assign tasks based on the bots’ countries.
Clear all stats/delete all dead bots from the DB.

Admin panel screenshots:










Price list:

01.* - $200
02.* - not for sale at the moment.
Rebuild for a new URL (main URL) - $10
For each additional reserve URL - $10

We accept:

Liberty Reserve (preferred)
Webmoney.

Saturday, 28 January 2012

Citadel Zeus bot

English Translation by @Sherb1n

- New clone of Zeus after ICE IX

Coder- Aquabox - Adv on Underground Forums

Citadel 1.1 - FF/IE/Chrome Grabber + Video Recording & Anti Tracker Protection

We’re offering a great solution for creating and updating your botnet.
We’re not trying to re-invent the wheel or come up with a revolutionary product. We have simply perfected the good old Zeus, making significant functionality improvements, adapting it to the survival conditions of today’s security landscape, and giving it a new name. Originally, we developed it for our own needs; during the development process, we also decided to create a “social circle” of support community, which is described later in this article.

Changes have been made both to the bot itself and to the web components.
We don’t sell “eye candy”. What you are paying for is the new functionality and coders’ motivation to support the product.

New features for the bot:

[+] Fixed VNC bug on Vista/Win7. Internet Explorer is now fully supported (there used to be a rendering problem in IE)

[+] Added support for Mozilla Firefox 7.0 (recent versions have had problems sending the reports; the problem is now fixed)

[+] Crypto-protection (the body is decrypted in memory)

[+] DNS-redirects (not through hosts). Any URL can now be blocked/redirected, undetectable by heuristics. For example, block AV servers or redirect bank pages to a different host.
!BONUS! The list of popular AV server URLs to clock is included.

[+] Software version is included in the report. The report will contain detailed information on the holder’s browser version. This can be used to imitate the holder’s settings.

[+] Extra layer of protection from trackers – Login Key.

[+] Authentication mechanism for config updates (no direct URLs). Adequate protection against established trackers.

[+] Grabber support for Google Chrome. (tested on latest versions 15.x/16.x)

[+] Inject support for Google Chrome. (tested on latest versions 15.x/16.x)

[+] Added function search caching, for faster hook setting in Chrome.

[+] Added feature: bot can run system CMD commands at startup (the CMDList section) and upload the report to server. For example, you can specify that upon installation your bot should upload the output of “ipconfig /all” or the list of all shared drives. This is a good feature to have when analyzing a company’s internal structure. (For example, you can often see bots with names like ACCOUNTANT_PC, POS_SERV, DATABASE…)

[+] Added mechanism to check the integrity of hooks in some Windows.

[+] Environment heuristic analyzer can use a stop-list to terminate undesirable software (significantly improves stealth), all popular AV products are included in the list.

[+] Small bugs have been fixed.

[+] Video grabber gives you a unique opportunity to see how your injects work “through the eyes of the holder”. Just specify the list of URLs and the recording time in seconds in the config file, and the bot will start recording video (in MKV format) as soon as the holder visits one of the URLs. Make sure your server can receive files of 10-60MB.

[+] Removed the “cookie clearing” feature, because it was messing up the machine’s fingerprint.

[+] Added support for HTTP 1.0 and extended headers (for example, the response doesn’t always look like “HTTP/1.1 200 OK”, sometimes it can be “HTTP/1.1 200 follow document”, where code 200 is followed by a couple of words), this is applicable to Firefox & Chrome

[+] Added gate generator (in case you want to place files on an intermediary host for redirect)

[+] All of Zeus’s basic functionality is included. I don’t think it needs to be listed here.

[+] Fully revamped, more user-friendly web-admin interface.


Figure 1. Builder, main screen



Figure 2. Web-panel, main screen



We’re not going to talk about the bot’s uptime, you’ll see it for yourself. Gratitude is accepted in the form of LR tokens.

This is the basic package. Price: $2,399.00

Important:

Our software does not work on Russian-language systems. If a Russian or Ukrainian layout is detected, the bot terminates.

This is done to prevent installs on CIS systems. You may disagree, but that’s taboo for us.

If you want to test the bot or develop your own injects – install an English-language system. We will provide URLs to download the OS image and VMWare to save you some time.

ADDITIONAL MODULES:

List of new features for web-admin panel (individual modules):

[+] Full-featured VNC control panel.
Now you can:
- Collect data on specific companies and accounts of interest into a separate DB and a separate script. It has a nice layout, you can see the list of online bots and details of the collected accounts.
- Create a VNC connection to any bot in 2 mouse clicks.
- View stats on active/dead accounts (or bots).
- Add/edit memos to the collected accounts.
- Receive automated Jabber alerts whenever a new account is added or a bot comes online. For convenience, the alert contains the IP:PORT for VNC connection.
- Sort the bots depending on their online/used/unused status.
- Specify a BotID, and have a VNC connection automatically created whenever the bot comes online.
Price: $495.00

Figure 3. VNC control panel



[+] High-quality SOCKS checker module.
You can specify several DBs of different botnets. The module uses web surfing to check the SOCKS, for a 99.9% accuracy.
Price: $49.00

[+] Executable files auto-encryption module.
Tired of manually encrypting your files or waiting for that encrypter to come back online? Automate the encryption task with this awesome auto-crypt module that will automatically refresh your botnets’ exe files. The script operates through Death’s jabber service called cbot. $15 per encryption.
We are not responsible for the encryption quality. Script is triggered through cron and can encrypt the file as many times as you need.
Price: $395.00

[+] Log parser module.
Many of you have had this problem: lots of bots generate tons of logs, and today’s DB search technologies take up way too much time. We have developed a script that can look across several DBs simultaneously and extract all http/https URLs and related data.
Additional features: caching and memos, for your convenience.
Price: $295.00

Modules can be purchased only if you also buy the basic package; they cannot be sold separately. When buying a module, you get the right to receive updates and support for this module.

CURRENTLY IN DEVELOPMENT:

[*] Advanced file search and upload. Search masks are specified in the config file. For example, “passwords*.txt”

[*] Ability to load the video-grabbing module from a remote host, to reduce the size of the build.


SERVICE & SUPPORT COMMUNITY (SOCIAL CIRCLE)

It’s hardly a secret that any product in this niche is a pile of junk on somebody’s hard drive unless it’s supported by a group of developers. As time goes on, a product must continue to satisfy the needs of the clients, but usually that’s where the problem occurs: there are lots of clients, but only one developer, and your IMs are often ignored. Time is money, that’s why we have created a social network-like platform for our clients.

Citadel CRM Store lets you influence the development of the product, namely:

- Report bugs and errors you discover in our software. All tickets are reviewed by tech support. You will receive a response in a timely manner and will not have to try to catch the developer in ICQ/Jabber.

- Every client has the right to create an unlimited number of requests and suggestions for new module/functionality. These requests can be public or private (visible to you only).

- Every client has the right to vote for ideas submitted by other members and to contribute money towards developing the module/functionality. Based on the voting results, the developers decide which module should be built.

- Every client has the right to comment on requests and talk to other members. Now you can find partners and like-minded people and take an active part in product development discussions.

- You can see all the stages of the development work if the new module is approved by the community. We provide timely updates on the status and completion date.

- If the module is approved, you can start making the initial deposits (50%). As soon as the deposits are made, developers start working on the project: the money is paid directly to the coders, and there will be no delays or procrastination. The process is transparent, every stage of the development work is displayed.

- Convenient notifications via Jabber about new comments or requests.

You will really appreciate this new approach!

When buying the basic package, you agree to make monthly maintenance payments of $125 (payments can be made for several months in advance). What’s included in this cost:

- We’re interested in working with our clients. There are lots of people who promise to “support the product, blah-blah”, but then either their updates come out once every 3 months, or the author just disappears. The problem is, authors need to be motivated. In our case – you support us, and we support you. As simple as that.

- Every month (around the 20th of the month) you get a builder update, including updated AV protection (bot body encryption, heuristic analysis prior to process injection).

- You get access to the CRM: a great opportunity to suggest new features and improvements, vote for others’ projects, and communicate with other members of the Citadel CRM Store.

- You get our support: we answer your questions (via ticketing system), provide installation assistance and usage recommendations. You are prohibited from transferring your personal CRM account to anyone else.

- In the near future, our CRM will start working with web programmers who will be focused exclusively on injects (including auto-transfers). The CRM allows our clients to create tasks, declare completion dates and prices, so that our coders can work on the approved projects. If you can write high-quality injects, let’s talk.

Figure 4. Citadel CRM Store



Demo access upon request (allow up to 24 hours).

Builder is tied to your PC; you can create unlimited number of domains.

We accept LR only. For WM-LR conversions, go to forums like mmgp.ru. We do not accept Webmoney.

To avoid wasting our time (and yours), don’t send us messages like “You there?”, etc. Just give us your request in this format: “Need to buy basic package, plus VNC, Auto-crypt, and SOCKS modules. What’s the total price with the discount?”

Citadel Zeus Bot Version 1.3


http://cyb3rsleuth.blogspot.co.uk/2012/03/citadel-13.html

Sunday, 28 August 2011

Winlock Scareware

English translation by @Sherb1n

Coder - Qunned

Winlock Builder [Private] v1.30:

Special features:

- Pleasant and convenient dark GUI
- Blocks taskmgr.exe, cmd.exe, osk.exe, explorer.exe, etc.
- Blocks hotkeys and hotkey combos (for example, Alt+F4, Ctrl+Alt+Del, Win+E, Win+D, Alt+Tab)
- Disables mouse
- Build size: 38.5KB
- Number randomization (Up to 9 text combinations, each field takes up to 20 characters, and numbers/text are displayed randomly)
- Packed with UPX
- Icon can be changed.
- Background color can be changed.
- Fully-editable text (up to 1,000 chars)
- Monitoring dashboard

Monitoring dashboard allows you to keep track of all your infected users; it displays infection date, IP, and the user’s current status (infected/active).

When using the monitoring function you remain anonymous because the gate is located on our servers, so you don’t have to worry about your anonymity.

- Auto-start.
- Option to use an image (in development)
- Works in safe mode.
- Self-deletion
- Automatic free updates (+cleanup)

Video demo:

http://www.sendspace.com/file/jcscs0

Monitoring demo:

Rules:

1. You are forbidden from re-selling any program components (builder, individual builds, licenses) without an explicit permission from the operators. If you violate this rule, we’ll apply sanctions.
2. You are forbidden from scanning the builds using free AV services that send reports to AV makers; if you violate this rule, the operator reserves the right to revoke your license. (Example: virustotal.com.)
3. At their own discretion, the operators have the right to revoke a customer’s license if the customer forces them to do it. (For example: insults/threats.)
4. Refund is possible only when the customer is not satisfied with the functionality, and he notifies us on the day of purchase.
5. Ignorance of rules does not exempt you from responsibility.

Packages:

Standard, 3 months - 25$
Standard, 6 months - 40$
Standard, 12 months - 75$

Professional, 3 months - 30$
Professional, 6 months - 50$
Professional, 12 months - 80$

Price per build - 10$

Monitoring and Randomization functions are available for Professional packages only!

ICQ:#387***

[+] You can order ad placement in the builder for 40$/month; the ad is displayed when the builder is launched and every 10 minutes.

[+] You can become our partner and help re-sell the builder; more info on ICQ.









--------------------------------------------------------------------------------

Original

Особенности:

- Приятный и удобный темный GUI.
- Блокировка taskmgr.exe, cmd.exe, osk.exe, explorer.exe, и др.
- Блокировка горячих клавиш и их комбинаций. (Пример: Alt+F4, Ctrl+Alt+Del, Win+E, Win+D, Alt+Tab)
- Отключение мыши.
- Размер билда 38,5 кб
- Рандомизация номеров (До 9 текстовых комбинаций, в каждое поле можно ввести до 20 символов, с помощью рандомизации номера/текст отображаются случайно)
- Упаковка UPX'ом.
- Возможность смены иконки.
- Возможность смены цвета фона.
- Полностью редактируемый текст (до 1к символов).
- Мониторинг

• С помощью мониторинга, у Вас появляеться возможность наблюдения за всеми заражеными пользователями, мониторинг отображает дату заражения/ip/ + текущее состояние пользователя (заражен/активен).
• При использовании функции Мониторинга, Вы соблюдаете полную аннонимность, ибо гейт находиться на наших серверах, и поэтому Вы можете небеспокоиться по поводу своей аннонимности.

- Авто-запуск.
- Возможность использовать изображение (Разрабатывается)
- Работает в безопасном режиме.
- Самоудаление
- Автоматические бесплатные обновления (+чистка)

Видеодемонстрация:

http://www.sendspace.com/file/jcscs0

Демонстрация мониторинга:

Правила:

1. Без разрешения операторов, продавать все комплектующие программы (билдер, билды, лицензии) - запрещено. В случае нарушения данного
правила, применяются санкции.
2. Запрещается сканировать билды на бесплатных АВ сервисах которые шлют отчеты, за нарушение данного пункта, оператор имеет право
заблокировать лицензию. (Пример: virustotal.com)
3. На своё усмотрение, операторы имеют полное право лишать клиентов лицензии если они вынуждают их это сделать. (Примеры: оскорбления/угрозы).
4. Возврат денег предусмотрен только в том случае, если клиента не устраивает предоставляемый функционал, и он сообщает об этом в первый
же день покупки.
5. Незнание правил не освобождает от ответственности.

Тарифы:

Стандарт, 3 месяца - 25$
Стандарт, 6 месяцев - 40$
Стандарт, 12 месяцев - 75$

Профессионал, 3 месяца - 30$
Профессионал, 6 месяцев - 50$
Профессионал, 12 месяцев - 80$

Цена за билд - 10$

Функции "Мониторинг" и "Рандомизация" доступны только для

Профессиональных тарифов!

[+] Вы можете заказать рекламу в билдере за 40$ / месяц, реклама

отображается при запуске билдера, а также каждые 10 минут.
[+] Вы можете стать нашим партнером по продаже билдера, более

подробная информация в ICQ.

Thursday, 25 August 2011

Ice IX Bot


 English Translation by Igor @Sherb1n

Coder Ice9 - Released in April 2011

Ice 9 is a new private ZeuS-based bot/form grabber and Zeus’s serious competitor. It’s built on the modified kernel of ZeuS 2.

The kernel has been revised and improved. Firewall- and proactive defense-bypass mechanisms have been perfected.

Injection technology has also been revised, improving injects’ stability.
The main goals were protection against trackers, higher response rate and improved resilience compared to its ancestor. The goals were successfully achieved.

The bot is constantly developed and updated with new functionality.

Main functions:

- Keylogging
- Grabs HTTP and HTTPS forms (IE, FF, Chrome), injects code into IE, IE-based browsers (AOL, Maxthon, etc), and FF
- Grabs cookies, .sol files and saved forms data
- Grabs the following FTP clients: FlashFXP, Total Commander, WsFTP 12, FileZilla 3, FAR Manager 1,2, WinSCP 4.2, FTP Commander, CoreFTP, SmartFTP
- Grabs Windows Mail, Live Mail, Outlook
- SOCKS 5 with back-connect option
- Screenshots in real time, or triggered by specific URLs
- Gets certificates from “MY” storage (certificates marked “non-exportable” are not exported correctly) and clears it. After this any imported certificate will be saved to the server.
- Search for files on the logical drives using wildcards or install a specific file.
- TCP traffic sniffer
- A wide range of commands to control the infected PC

Advantages:

- Protection against trackers. Now you can host your botnet on a regular hosting, not just bulletproof;
- Better response rate and resilience;
- Functionality updates and tech support;
- Custom modules can be created for customers

Price for the current version 1.0.5.

- With hardcoded hosting: $600/LR/WMZ. Bot + builder that generates the config file.
- Unlimited builder license: $1800/LR/WMZ.

------------------------------------------------------

In response to numerous questions on changes and new capabilities we’re happy to present the following information:

Functionality:

- Keylogging
- Grabs HTTP and HTTPS forms (IE, FF, Chrome), injects code into IE, IE-based browsers (AOL, Maxthon, etc), and Mozilla Firefox
- Grabs cookies, .sol files and saved forms data
- Grabs the following FTP clients: FlashFXP, Total Commander, WsFTP 12, FileZilla 3, FAR Manager 1,2, WinSCP 4.2, FTP Commander, CoreFTP, SmartFTP
- Grabs Windows Mail, Live Mail, Outlook
- SOCKS with back-connect option
- Screenshots in real time, or triggered by specific URLs
- Gets certificates from “MY” storage (certificates marked “non-exportable” are not exported correctly) and clears it. After this any imported certificate will be saved to the server.
- Search for files on the logical drives using wildcards or install a specific file.
- TCP traffic sniffer
- A wide range of commands to control the infected PC

Advantages:

- Even an unencrypted bot has a higher response rate than ZeuS – save money on traffic and installs
- Changes to the mutex kernel have improved the bot’s stealth and resilience
- Possibility to use an alternative autostart method – as a service.
- Constant functionality updates and tech support;
- Custom modules can be created for customers

Under development:

- New VNC module with improved stability
- Changes in the encryption algorithm and in the data communication channel “protocol”
- Ability to access ring0 to execute specific tasks at the customer’s request

------------------------------------------------------

New version 1.0.4

Added tracker protection for the config file:
Now, when deploying the config, you have to set the encryption key, to make sure only the bot can access it. Otherwise, it returns a 404 error.

We believe that this important update will provide a great advantage when building large botnets, since trackers have always been ZeuS’s biggest problem.

------------------------------------------------------
Version 1.0.5 released in Aug 2011

ICE9’s config (v. 1.0.5) is protected against download from its URL, which means it’s protected against analysis. It can only be downloaded by the bot, which will be generating a special key to access the config file.






---------------------------------------------------------------------------------

Original

Ice 9 новый приватный бот-формграббер на базе Зевса, являющийся его серьезным моперником. Он построен на модифицированном ядре Зевса 2.
Ядро было переработано и улучшено. Усовершенствован обход проактивных защит и фаерволлов.
Так же переработке подверглась технология инжектирования позволяющая инжектам работать гораздо стабильнее.
Главными задачами ставилось разработка защиты от трекеров, повышение отстука и живучести относительно своего прародителя и данные задачи была успешно выполнена.
Бот постоянно развивается и дополняется.

Основные функции:
-Кейлоггинг
-Граббинг http и https данных форм (IE, FF, Chrome) и инжектирование своего кода в IE и браузеры на его движке (AOL, Maxton, etc.) и FF
-Граббинг cookies .sol файлов а также сохраненных данных форм
-Грабинг FTP клиентов: FlashFXP, Total Commander, WsFTP 12, FileZilla 3, FAR Manager 1,2, WinSCP 4.2, FTP Commander, CoreFTP, SmartFTP
-Граббинг Windows Mail, Live Mail, outlook
-Соксы 5 с возможностью бекконекта
-Скриншоты в реальном времени а так же возможность задания срабатывания при просмотре определенного URL
-Получение сертификатов из хранилища "MY" (сертификаты с пометкой "Не экспортируемый" не экспортируются корректно) и его очистка.
После этого любой импортируемый сертификат будет сохранен на сервер.
-Поиск на логических дисках файлов по маске или загрузка конкретного файла.
-Снифер трафика для протокола TCP
-Широкий набор команд для управления зараженным ПК

Преимущества:
- Защита от трекеров.
Теперь Вы можете размещать ботнет на обычном хостинге, а не только на абузоустойчивом;
- Выше отстук и дольше живучесть;
- Обновление функционала и тех. поддержка;
- Возможность дописки дополнительных модулей по желанию заказчика

Цена лицензии за текущую версию 1.0.5.
- С привязкой к хостингу: $600/LR/WMZ . Бот + билдер который генерит конфиг.
- Лицензия на билдер без ограничений: $1800/LR/WMZ/

-----------------------------------------------------

В связи с многочисленными вопросами об изменениях и новых возможностях мы рады предоставить нижеследующую информацию:

Функционал:

-Кейлоггинг
-Граббинг http и https данных форм и инжектирование своего кода в Internet Explorer и браузеры на его движке (AOL, Maxton, etc.), Mozilla FireFox
-Граббинг cookies .sol файлов а также сохраненных данных форм
-Грабинг FTP клиентов: FlashFXP, Total Commander, WsFTP 12, FileZilla 3, FAR Manager 1,2, WinSCP 4.2, FTP Commander, CoreFTP, SmartFTP
-Граббинг Windows Mail, Live Mail, outlook
-Соксы с возможностью бекконекта
-Скриншоты в реальном времени а так же возможность задания срабатывания при просмотре определенного URL
-Получение сертификатов из хранилища "MY" (сертификаты с пометкой "Не экспортируемый" не экспортируются корректно) и его очистка.
После этого любой импортируемый сертификат будет сохранен на сервер.
-Поиск на логических дисках файлов по маске или загрузка конкретного файла.
-Снифер трафика для протокола TCP
-Широкий набор комманд для управления зараженным ПК

Приемущества:

-Отстук даже некриптованного бота, выше чем у ZeuS - экономия на траффике/загрузках
-За счет изменения ядра работы с мьютексами повышена скрытность и живучесть бота
-Возможность альтернативного метода прописки в автозапуск-сервисом.
-Постоянное обновление функционала и тех. поддержка
-Возможность дописки дополнительных модулей по желанию заказчика

В разработке:

-Новый VNC модуль обладающий повышенной стабильностью
-Смена алгоритма шифрования и "протокола" канала обмена данных
-Возможность выхода в ring0 для выполнения специфических задач по требованиям заказчика

----------------------------------------------------------------------

Новая версия 1.0.4

Добавлена защита конфига от трекеров:
теперь при размещении конфига нужно также задать ключ шифрования для того, чтобы конфиг отдавался только по запросу бота иначе возвращается 404 ошибка

Думаем это важное обновление дает большое преимущество при построении больших ботнетов. Так как основная проблема для зевса - это как раз трекеры.

----------------------------------------------------------------

Конфиг ICE9 версии 1.0.5 защищен от скачивания по его урлу а значит и защищен от анализа. Его может скачать только бот, который генерирует спец ключ для доступа к конфигу. 

Wednesday, 3 August 2011

Botnet Sale

Vendor - Geed

Сервис по продаже ботнетов только для вас!

Мы сделаем SpyEye ботнет под ваш заказ. SpyEye самая последняя версия. Только от нас вы получите 15% скидку на антиабузные серверы от Jaguarc, 10% скидку на связку BlackHole (аренда или продажа) и 10% скидку на заказ от mallorca.

Ботнет под UK - 700$ + цена за сервер. В комплекте вы получите EXE + config, полный доступ в сервер. Предлагаем anti-rapport, CC grabber, SOCKS backconnect server, FTP backconnect server, следующие инжекты: santander/abbey, hsbc, lloyds tsb, natwest, rbs, first direct, halifax. Formgabber работает под браузеры IE + FF.

Ботнет под ES - 700$ + цена за сервер. В комплекте вы получите EXE + config, полный доступ в сервер. Предлагаем anti-rapport, CC grabber, SOCKS backconnect server, FTP backconnect server, следующие инжекты: bancodevalencia, bancogallego, bancomediolanum, bancopastor, banesto, bankinter, barclays, bbva, caixacatalunya, caixagalicia, caixagirona, caixalaietana, caixamanlleu, caixapenedes, caixatarragona, cajaduero, cajaespana, caja-granada, cajamadridempresas, cajamurcia, cajasoldirecto, cajastur, cajasur, cajavital, cam, ccm, deutsche-bank, e-pueyo, gruposantander, halifax, ingdirect, iparkutxa, kutxa, lacaixa, ruralvia, sanostra, uno-e. Formgabber работает под браузеры IE + FF.

Ботнет под DE - 700$ + цена за сервер. В комплекте вы получите EXE + config, полный доступ в сервер. Предлагаем anti-rapport, CC grabber, SOCKS backconnect server, FTP backconnect server, следующие инжекты: comdirect, commerzbanking, deutsche-bank, dkb, postbank, targobank. Formgabber работает под браузеры IE + FF.

Ботнет под PT - 700$ + цена за сервер. В комплекте вы получите EXE + config, полный доступ в сервер. Предлагаем anti-rapport, CC grabber, SOCKS backconnect server, FTP backconnect server, следующие инжекты: santandertotta, cgd. Formgabber работает под браузеры IE + FF.

Ботнет под USA - 700$ + цена за сервер. В комплекте вы получите EXE + config, полный доступ в сервер. Предлагаем anti-rapport, CC grabber, SOCKS backconnect server, FTP backconnect server, следующие инжекты: MNOGO INJEKTOV. Formgabber работает под браузеры IE + FF.

Ботнет с вашими инжектами - 600$ + цена за сервер. В комплекте вы получите EXE + config, полный доступ в сервер. Предлагаем anti-rapport, CC grabber, SOCKS backconnect server, FTP backconnect server.

Обновление config (для смены IP/domain, добовления injektov) - 50$

Monday, 4 July 2011

Web Injects Zeus/Spyeye

Coder - mynetthebest

We sell already made webinjects for Zeus/Spyeye. We can develope webinjects to your needs if you provide logins for testing it. Injects can be made on for any country and any language if you provide details for it.

All injects are tested on accounts before selling. We can do injects in different languages, depending on your needs (you have to provide the text for fields)

Injects are sold encrypted and you can`t modify them.

Now we have the following working injects ready for sale:

UK

1) Barclays (phone banking + full cc) ,
2) Co-operative banking (acc+full cc) , inject inpage
3) Smile bank(full cc) , inject inpage
4) Halifax (all banking info + full cc) ,
5) Hsbc (sec key + phone+ email) ,
6) Lloyds (banking info +pin) ,
7) Santander (full cc),
8) O2(full cc)
9) Paddy Power (full cc) ,
10) Southern-electric (full cc) ,
11) T-mobile(full cc) ,
12) Vodafone(full cc),
13) William hill(full cc),
14) Tfl (full cc),
15) Coral (acc + full CC),
16) Hmrc (acc+full cc)
17) eBay UK (full cc)
18) Paypal UK(full cc)
19) NationWide Bank (full cc) inject inpage
20) Capital One Banking (full cc) inject inpage
21) FirstDirect Bank (banking info)
22) Amex UK (full cc)
23) Egg Banking (full cc)
24) Natwest Bank
25) Rbs Bank


Canada

1) RBC (Full cc) french language
2) Scotia Bank (banking info + cc)
3) Amex (full cc)

USA

1) eBay (full cc)
2) Paypal (full cc)
3) NC SECredit Union (full cc)
4) VerizonWireless (full cc)
5) Greatsouthernbank (full cc)
6) Valley National Bank (full cc ) Inject inpage
7) Bank Of America (full banking info + full cc - price 100 wmz/lr)
8) Bank of America (small inject )
9) Chase (banking info )
10) Amex (full cc)
11) Wellsfargo Bank (full cc)
12) Suntrust
13) Usbank
14) Wachovia
15) 53
16) Fidelity
17) Usaa
18) Accountonline
19) Citibank
20) Discovercard
21) Key
22) Mandtbank
23) Regions

DE

1) Sparkasse bank (full cc + vbv)
2) Postbank (full cc + vbv)
3) Paypal (full cc+ vbv)

FR

1) Paypal (full cc)
2) BNP (full cc)

INT

Western union (full cc + vbv/mcsec pass)
Moneybookers (full cc + vbv/mcsec pass)

Price for one inject is now 60 WMZ/LR

Price for UK injects pack 800 WMZ/LR
Price for US injects pack 740 WMZ/LR

Updated/modify of injects 20 lr each.

Webinjects have card verification with Luhn algorithm and field verification for non-sense characters like !@#$%^&*()/\\';][{}|":><?\|)

ESCROW WELCOMED. (YOU PAY ESCROW CHARGES).

READ THIS BEFORE YOU BUY:

1.) PLEASE DONT ASK US ABOUT BOTNET SALE - WE ARE NOT SELLERS OF BOTNET SERVICE , WE ONLY DEVELOPE INJECTS !! IF YOU NEED BOTNET PLEASE CONTACT BOTNET AUTHORS TO BUY!!!

2.) DONT ASK US TO CUSTOMIZE INJECT (MAKE IT 50 FIELDS BIG WITH ALL LIFE HISTORY OF THE USER) AND THEN COME BACK TO US AND SAY "I DONT GET RESULTS WITH YOUR INJECTS" (..ALL OUR INJECTS WORK ON METHOD "POST" AND ARE ALREADY TESTED ..)

3.) IF YOU DONT HAVE ANTI-TRUSTEER GO AND BUY ONE FROM YOUR BOTNET AUTHOR , REMEMBER ABOUT AV/FIREWALL/ AND OTHER THIRD PART PROGRAMS THAT CAN STOP YOUR BOT CONNECTION.

4.) LEARN TO USE A BOTNET BEFORE YOU USE INJECTS , LEARN HOW BOT WORKS , HOW INJECTING IS MADE

5.) WE KEEP LOGS OF EVERY BUYER - (all buyers that will contact us with any problem not directly implicated on injects work will be ignored) SO PLEASE TEST THEM BEFORE YOU CONTACT US.

6.) RESELL/SHARE IS NOT ALLOWED

WE DONT SELL INJECTS TO ZEUS/SPYEYE BIN SELLERS SO TRY NOT TO CONTACT ABOUT !!

Thanks for understanding !

Screen of in page inject http://www.sendspace.com/file/eseubo

live screen WU http://www.sendspace.com/file/ueulg4

live screen BOA  http://www.sendspace.com/file/klcl3r      pass: carder.pro

Monday, 13 June 2011

CarberP Banking Bot

English translation by Igor @Sherb1n 

Carberp (http://www.google.com/search?q=carberp) is a 

multifunctional banking bot

Response rate: 60-90%

Works even on limited accounts in XP/Vista/7

-------------------------------

- Loader
- FTP grabber (31 clients)
- Password grabber
- Form grabber (IE, FF, Opera*)
- FTP sniffer
- Grabber of basic-authorization in IE
- Deletes cookies and sol in IE and FF
- DDoS
- Backconnect (the server is able to maintain around 500 connections)
- Injects for IE and FF (syntax is exactly like that in ZeuS)
- Ability to take screenshots directly from JS
- %user_id% inserts the bot’s uid into the HTML code
- Inject editor/debugger has a nice GUI
- Config for injects
- Traffic encryption
- Builder
- Modular system allows to load additional plugins and control their online status (on demand)
- Pimped out multifunctional admin panel, access to form grabber and password grabber logs
- Hidden browser (similar to VNC, works even on limited accounts in XP/Vista/7)

Full description of the bot: http://www.sendspace.com/file/7a6z8u (skRyyuJg)

Admin panel video: http://www.sendspace.com/file/rkchnh (fMNxtm5p)

Hidden browser video: http://www.sendspace.com/file/jablft (RGj4Ycnp)

Inject debugger: http://www.sendspace.com/file/gr0zew (EQtcGCgS)

*Support for the latest version of Opera is not guaranteed, since they are constantly changing stuff.

-------------------------------
Updates

Bug fixes for current modules and small functionality enhancements are free
New modules and major functionality upgrades are reasonably priced
Any other features can be ordered as well

-------------------------------

Prices and conditions

Loader + grabbers + all the major functions (except for the below) – 1K wmz

All of the above + Backconnect + Injects – 2.5K wmz

All of the above + Hidden browser – 5K wmz

Those who have money can test it out

Escrows welcome

Contact us on Jabber: qru****@jabber.org


---------------------------------------------------------------
Original

Carberp (http://www.google.com/search?q=carberp) - многофункциональный банкбот

Отстук 60-90%

Работает даже на ограниченных учетках XP/Vista/7

------------------------------- 

- Лоадер
- ФТП граббер (31 клиент)
- Пассворд граббер
- Форм граббер (IE, FF, Opera*)
- ФТП сниффер
- Граббер basic-авторизации в IE
- Удаление cookie и sol в IE и FF
- DDOS
- Бекконнект (сервер способен держать около 500 соединений)
- Инжекты IE+FF (синтаксис 1в1 как у зевса)
- Возможность делать скриншоты прямо из js
- %user_id% вставляет в html-код uid бота
- Программа для написания и отладки инжектов с удобным GUI
- Конфиг для инжектов
- Шифрование траффика
- Билдер
- Плагинная система с подгрузкой модулей и контроля онлайна этих плагинов (по запросу)
- Навороченная многофункциональная админка лоадера, работа с логами форм граббера и пассворд граббера
- Скрытый браузер (аналог VNC, работает даже на ограниченных учетках XP/Vista/7)

Полное описание бота: http://www.sendspace.com/file/7a6z8u (skRyyuJg)

Видео админки: http://www.sendspace.com/file/rkchnh (fMNxtm5p)

Видео Скрытого Браузера: http://www.sendspace.com/file/jablft (RGj4Ycnp)

Программа-отладчик инжектов: http://www.sendspace.com/file/gr0zew (EQtcGCgS)

*Поддержка самой последней версии оперы не гарантируется, т.к. они постоянно там что-то меняют.

------------------------------- 

Обновления

Багфиксы в текущих модулях и мелкие дополнения к функционалу бесплатны
Новые модули и серьезные дополнения к текущим за умеренную плату
Так же возможны любые доработки по желанию

------------------------------- 

Прайс и правила покупки

Лоадер + грабберы + весь основной функционал (кроме того что ниже) - 1к wmz
Все что выше + Бекконнект + Инжекты - 2.5к wmz
Все что выше + Скрытый браузер (аналог VNC) - 5к wmz

Билдер - 1к wmz

Тест возможен людям с деньгами
Гарант велком

Связь по жаберу: qru****@jabber.org