Zum Inhalt wechseln

Als Gast hast du nur eingeschränkten Zugriff!


Anmelden 

Benutzerkonto erstellen

Du bist nicht angemeldet und hast somit nur einen sehr eingeschränkten Zugriff auf die Features unserer Community.
Um vollen Zugriff zu erlangen musst du dir einen Account erstellen. Der Vorgang sollte nicht länger als 1 Minute dauern.

  • Antworte auf Themen oder erstelle deine eigenen.
  • Schalte dir alle Downloads mit Highspeed & ohne Wartezeit frei.
  • Erhalte Zugriff auf alle Bereiche und entdecke interessante Inhalte.
  • Tausche dich mich anderen Usern in der Shoutbox oder via PN aus.
 

   

Foto

PEunion (Binder, Crypter & Downloader)

- - - - -

  • Bitte melde dich an um zu Antworten
Keine Antworten in diesem Thema

#1
Exynos

Exynos

    Lehrling

  • Premium Member
  • Likes
    147
  • 92 Beiträge
  • 514 Bedankt
  • Android, Android [root]
  • Windows, Linux

PEunion bundles multiple executables (or any other file type) into a single file. Each file can be configured individually to be compressed, encrypted, etc. In addition, an URL can be provided for a download to be executed.

The resulting binary is compiled from dynamically generated C# code. No resources are exposed that can be harvested using tools like Resource Hacker. PEunion does not use managed resources either. Files are stored in byte[] code definitions and when encryption and compression is applied, files become as obscure as they can get. 

And on top of that, obfuscation is applied to a maximal extent! Variable names are obfuscated using barely distinguishable Unicode characters. String literals for both strings that you provide, as well as constant string literals are encrypted. 

PEunion can be either used as a binder for multiple files, as a crypter for a single file, or as a downloader. 

 

Each file can be configured individually. Default settings already include obfuscation, compression and encryption. Relevant settings are primarily: Where to drop the file, using what name and whether or not to execute it and so on...

The project can be saved into a .peu file, which includes all project information. Paths to your files are relative if they are located in the same directory or a sub directory.

001.png

 

PEunion can also be used as a downloader. Simply specify a URL and provide drop & execution parameters. Of course, bundled files and URL downloads can be mixed in any constellation.

002.png

 

For the C# code that is generated, compiler settings can be configured here. Usually, you will be looking to change the icon and assembly info:

003.png

 

The next two pages include settings for obfuscation and startup parameters. Default obfuscation settings are at maximum, however they can be changed, if required.

003.png004.png

 

Finally, the project is compiled into a single executable file. In addition, generating just the code will compile the .cs file, but not the binary.

006.png

 

Right to Left Override

A lesser-known bug feature: Right to left override. By using the U+202e unicode character, file name strings can be reversed, yielding additional obscurity. 

Example: Colorful A[U+202E]gpj.scr will be displayed as Colorful Arcs.jpg in File Explorer. Since "scr" (for screensaver) easily goes unseen, it may be superior over "exe". With the matching icon applied, the file may look just like an image or document file:

008.png

 

Behind the scenes - Obfuscation!

Starting here, an array with all the files is declared. This is the definition of all files, what to do with them and the byte[] literal contains the encrypted and compressed file:

code1.png

 

Symbol names for variables, methods and classes are obfuscated using barely readable characters. This is the difference:

code2.gif

 

Quelle: 

Please Login HERE or Register HERE to see this link!

  & 

Please Login HERE or Register HERE to see this link!

Download: 

Please Login HERE or Register HERE to see this link!

Denke VT / HA Link ist an der Stelle geschenkt.

Ist übrigens echt klasse in Verbindung mit Born2Hack seinem Crypter. An der Stelle noch einmal Danke an B2H für seine klasse Arbeit!


  • Avni, Born2Hack, nibble nibble und 2 anderen gefällt das

Thanked by 4 Members:
1x1 , m0nk3y , Avni , psner


  Thema Forum Themenstarter Statistik Letzter Beitrag

Besucher die dieses Thema lesen:

Mitglieder: , Gäste: , unsichtbare Mitglieder:


This topic has been visited by 62 user(s)


    1x1, 3eyes, Alsuna, Avni, Bananajoe, BlackZetsu, Bloodman, BloodSw0rd, Boneau, Born2Hack, butchy, C4shin0ut, Cent0S, cubik, daredevil_hellfire207, daten, Dean36, DeepWater, desmond, dvalar, ERBOX, Exynos, fl4shx, fothermucker, FrogPussyGreen, halymaly, hlaus777, JimBeam, kiwitone, Leak, m0nk3y, m0rph75, m0rtifer, mettbrot, Mini Rick, N4dja, nibble nibble, nninja, notfound, o0o, Onek, PadX18, papillon121, psner, Psykoon303, Rico1980, rockito, Rogerlopensio, rsneumann, siddis, silvercow79, snoppy0066, starz, Terrafaux, twixeis, Volle29, w0tan, webpanel0815, x1rk2, xVirtu, z91, Zerobyte
Die besten Hacking Tools zum downloaden : Released, Leaked, Cracked. Größte deutschsprachige Hacker Sammlung.