Author Topic: Some Tools I've Collected  (Read 728 times)

0 Members and 1 Guest are viewing this topic.

Offline Riv3r

  • Devotee
  • **
  • Posts: 168
    • View Profile
Some Tools I've Collected
« on: October 09, 2014, 07:05:03 pm »
None of this is anything that I've written, this is just some of the tools that were given to me or I've managed to acquire. Some work well, some don't. I have more and will continue adding to the list when I've organized better. This is for educational purposes only, to see how it works and runs. Whatever you do with this is none of my business. I also can't be bothered to tell you how to use them. Use these on machines that YOU own.

Enjoy.

https://www.dropbox.com/sh/svixk15dmp8faxd/AAB1sE46OG4DrCM0GkrQRkkOa?dl=0

Offline Rook

  • Arch Disciple
  • ***
  • Posts: 590
    • View Profile
Re: Some Tools I've Collected
« Reply #1 on: October 15, 2014, 05:05:38 am »
anyone confirm these arent loaded?
The woods are lovely, dark and deep. But I have promises to keep, and miles to go before I sleep.
-Robert Frost

Offline aldra

  • Arch Disciple
  • ***
  • Posts: 623
  • albrecht drais
    • View Profile
Re: Some Tools I've Collected
« Reply #2 on: October 15, 2014, 05:10:20 am »
doubt riv3r would, but nobody's going to tell you anyway. anyone who's not borderline-retarded can evade antivirus scanners, but considering what those files are they'll probably get picked up on general principle - the only way to be sure is to run and trace the file yourself. or just set up a vm and test; most of the trojans/botnets/etc in there are old enough to be unlikely to contain any sort of virtualisation detection

Offline mmmmmmmQuestions

  • Arch Disciple
  • ***
  • Posts: 597
    • View Profile
Re: Some Tools I've Collected
« Reply #3 on: October 15, 2014, 05:13:10 am »
anyone confirm these arent loaded?


can anyone confirm you're not loaded?

Offline Rook

  • Arch Disciple
  • ***
  • Posts: 590
    • View Profile
Re: Some Tools I've Collected
« Reply #4 on: October 15, 2014, 05:24:54 am »
 It's not that I suspect Riv3r of doing such a thing, just one can never be too careful. I only say this because up until recently I felt pretty confident in my network security, until I sniffed out a fishy program that had been remotely installed a few weeks back.. I appreciate the upload nonetheless.. Just never hurts to check for reviews.
The woods are lovely, dark and deep. But I have promises to keep, and miles to go before I sleep.
-Robert Frost

Offline Riv3r

  • Devotee
  • **
  • Posts: 168
    • View Profile
Re: Some Tools I've Collected
« Reply #5 on: October 20, 2014, 08:08:17 am »
anyone confirm these arent loaded?

This is one of those things where my words won't mean much so I understand where you're coming from. I've been there and we all have, if you're out actively trying to get these programs. The ones that I know for certain that are clean are ragebot* and darkcometfinal. DarkComet is a RAT that is well known by many in the infosec community. I downloaded that from the company before they were shut down. They have/had a great reputation.

*ragebot is not there. I thought it was. I'll up it when I find it. It's not on the computer that I thought it was.

Also, aldra is right. FUDcrypters, polymorphic code and obfuscation have rendered AV useless. You can't tell. This is one of those "at your own risk" type things. I recommend a virtual box or a burner computer. Technically, they are loaded. When you or whoever else downloads this (not installs), most antivirus will pick it up and delete it.
« Last Edit: October 20, 2014, 08:14:15 am by Riv3r »

Offline Rook

  • Arch Disciple
  • ***
  • Posts: 590
    • View Profile
Re: Some Tools I've Collected
« Reply #6 on: October 23, 2014, 07:05:32 am »
anyone confirm these arent loaded?

This is one of those things where my words won't mean much so I understand where you're coming from. I've been there and we all have, if you're out actively trying to get these programs. The ones that I know for certain that are clean are ragebot* and darkcometfinal. DarkComet is a RAT that is well known by many in the infosec community. I downloaded that from the company before they were shut down. They have/had a great reputation.

*ragebot is not there. I thought it was. I'll up it when I find it. It's not on the computer that I thought it was.

Also, aldra is right. FUDcrypters, polymorphic code and obfuscation have rendered AV useless. You can't tell. This is one of those "at your own risk" type things. I recommend a virtual box or a burner computer. Technically, they are loaded. When you or whoever else downloads this (not installs), most antivirus will pick it up and delete it.

 I know all about Darkcomet, and had used it in the past. There are few applications I was planning to use it for, and already tested a few of those downloads on a.. err.. public network. Better than my comps.. heh, but I really do appreciate those uploads. And I'm glad you understood, paranoia is often safe.
The woods are lovely, dark and deep. But I have promises to keep, and miles to go before I sleep.
-Robert Frost