UnamSanctam / SilentXMRMiner

A Silent (Hidden) Monero (XMR) Miner Builder
MIT License
560 stars 162 forks source link

did you mondark crypto through confuserex? #167

Closed Toxenskiy closed 3 years ago

Toxenskiy commented 3 years ago

sihost64.exe detected new detect image

UnamSanctam commented 3 years ago

Yes I obfuscated Mandark although not through ConfuserEx

UnamSanctam commented 3 years ago

And you can obfuscate the Watchdog as I said before if you want to decrease the detection

Toxenskiy commented 3 years ago

This is the obfuscated version. You can throw off the original Mondark, I myself want it crypting

UnamSanctam commented 3 years ago

This is the unobfuscated Mandark but the detection you sent doesn't have anything to do with that. Mandark.zip

Toxenskiy commented 3 years ago

i know

Toxenskiy commented 3 years ago

obfuscated miner image

UnamSanctam commented 3 years ago

Is that from Windows Defender when you run the miner?

Toxenskiy commented 3 years ago

+

Toxenskiy commented 3 years ago

yea

UnamSanctam commented 3 years ago

Interesting

Toxenskiy commented 3 years ago

I think obfuscation is not enough, we still need to impose something

UnamSanctam commented 3 years ago

Can you try building a miner with this version (it's using the old injector) and see if you get the same detection? Silent XMR Miner Builder.zip

Toxenskiy commented 3 years ago

try. but first I want to try to impose a different defense

UnamSanctam commented 3 years ago

What kind of defense?

Toxenskiy commented 3 years ago

helped image

UnamSanctam commented 3 years ago

Did you do that on the Mandark?

Toxenskiy commented 3 years ago

not on the whole miner, Mondark I encrypted in order to make it unique, otherwise it’s not a fact that yours will not be killed

UnamSanctam commented 3 years ago

Yes obfuscating the miner should always be done but if you try building a miner with the latest file I sent does it still get detected as CoinMiner when you start it? Or when did it detect it as CoinMiner?

Toxenskiy commented 3 years ago

obfuscation works for 10 minutes, after 10 minutes it writes detection

Toxenskiy commented 3 years ago

the only thing that smartscreen complains about every launch

UnamSanctam commented 3 years ago

Yes that will always happen unless you get it certified from Microsoft which you can't really do https://docs.microsoft.com/en-us/windows/win32/win_cert/windows-certification-portal?redirectedfrom=MSDN

Toxenskiy commented 3 years ago

But it never happened before

UnamSanctam commented 3 years ago

That only happens on computers that have it on, I don't get any messages like that and most others don't either

UnamSanctam commented 3 years ago

Do you get the same message if you use Silent XMR Miner Builder.zip?

Toxenskiy commented 3 years ago

ok try

Toxenskiy commented 3 years ago

to impose obfuscation? If so, at what level

UnamSanctam commented 3 years ago

Use any, I just want to see if you experience any difference when using the old injector (that builder has the old one).

Toxenskiy commented 3 years ago

well, it seems like there are no complaints from the antivirus, but this is only after launch

Toxenskiy commented 3 years ago

and how do injectors differ?

UnamSanctam commented 3 years ago

The code is a bit different, I wanted to upgrade it since I was worried that the injector was a bit unstable but maybe it works fine with the old one. So now I have to decide whether to use the old one or revert to the old one.

Toxenskiy commented 3 years ago

It would be cool if you did 2 versions, one uploaded in telegram and the other here.

Toxenskiy commented 3 years ago

So that there are not many detections straight.

UnamSanctam commented 3 years ago

Well the code will still be the same so the detections wouldn't differ too much since I don't have the time to change the entire code signature.

Toxenskiy commented 3 years ago

old injector detected

Toxenskiy commented 3 years ago

sihost64 detected last version obfuscated maximum image

UnamSanctam commented 3 years ago

Yeah, that's not the sihost64 getting detected but the obfuscator being detected

UnamSanctam commented 3 years ago

Some protections do get detected sometimes

Toxenskiy commented 3 years ago

I can't find a normal obfuscator in any way

Toxenskiy commented 3 years ago

Eziriz detected, confuserex detected

UnamSanctam commented 3 years ago

Yeah, obfuscators get detected after a while, sometimes it works by using less protections

Toxenskiy commented 3 years ago

you thought to make a config, just every time it takes a very long time to enter everything

UnamSanctam commented 3 years ago

Yeah, it's just that making a config will be a lot of code so I haven't had time yet.