Theattacker-Crypter
Tool to evade Antivirus With Different Techniques
DO NOT UPLOAD TO VIRUSTOTAL!!!
VirusTotal cooperates with many antiviruses and shares its up-to-date database.
In order for this crypter to work for a longer time, you must follow this simple rule.
Screenshot
Updates
- Added AMSI Bypass
- Added RUNPE
- Added support for 32 bit injection
- Added support for 64 bit injection
- Ability to clone Assembly
- Ability to execute your own Encoded Powershell Commands
- Ability to Disable Amsi even if you are not injecting .Net Paylaod
- Ability to choose Payload type if it Native or .Net
- Added New injection Paths
- Notify When stub Executed on Macihne 2 Methods Impelmented
- using Telegrem
- using Socket TCP/IP server
- Fixed SomeBugs
- New Ui
- Mutex to prevent the process from running Multiple times
- Simple .Net Obfuscator
- Melt Function for the exe to Delete it self after injecting the payload
- File Pumper
- Anti VM Payload won t execute in Vms
- current last version
poc
AntiVmExample
Usage
- Download Crypter from Releases
- choose File and Generate Encryption Key
- Upload Loader.txt in raw url Ex(pasteBin)
- put the url in the build Section and Build
Detection rate
I don t know how much This will stay FUD but will be updating it always and adding New Injection and new Attacks to it
HINT
Simple Note to avoid Detection Completely Use .NET obfuscator like Smart Assembly
YT-VID
https://www.youtube.com/watch?v=caev1GH8PzE
TODO