CoolOutdatedSuper Nanny Injector v3.6 (Stable Manual Map + Thead Hijack)

Posts 1–14 of 14 · Page 1 of 1
Super Nanny Injector v3.6 (Stable Manual Map + Thead Hijack)
Super Nanny Injector v3.6



New release of Super Nanny Injector, last version with exclusive support for x86 . Before start using it, check the past release for more instructions.

Different from past release, this one have no experimental features. All code have ben tested over and over again, to meet a working and stable version. All strings (excluding ones from shared libraries and QT5) have ben obfuscated with a mutate algorithm, reducing easy spots for signature matching.

What's new:
  • Code: More stable and reliable, new UI scheme to handle more options . Pre tab for options used before injection, and Post after it.
  • Manual Map: Stable and working, supports TLS, forward imports, etc. . Unless you use SEH exceptions or code compression (as UPX), it will work.
  • NtCreateThreadEx: Now it hides thread from debugger on remote process. Used by default for create a remote thread by Manual Map.
  • Pre Injection Delay: Just wait before starts injection.
  • UnDLLNotification: Bypass a NT internal API that notify DLL loading (this includes dependencies, e.g. even if A.dll uses stealth injection, when using msvcrt.dll, NT internal delivery a notification for "msvcrt.dll load").
  • Thread Hijack stub: Uses Thread Hijack to write and start code for Manual Map (doesn't use *API for create a remote thread).
  • Hide Dll: Hides dll from PeB entry into remote process, so it can't list/find (user mode!) the injected DLL. This option in combination with Thread Hijack + Wipe Dll Header, can achieve a similar lvl of stealth of Manual Map, although it's more aggressive.
  • WDelay: Wipe delay shared between Wipe Dll Header and Wipe Load_stub.
  • Process name: Now it's possible to select injectable processes already ran from a listbox



A/V:
https://www.virustotal.com/pt/file/b...is/1476053180/
https://virusscan.jotti.org/en-US/fi...job/423zmy0rkz
SuperNanny3_mpgh.net.zip5.1 MB · 1,917 downloads 2/56 malicious
Approved
Use at your OWN risk.
looks amazing dude, glad you're doing this for the community would you have a set of recommended settings for this?
Quote Originally Posted by Dank_snake View Post
looks amazing dude, glad you're doing this for the community would you have a set of recommended settings for this?
Well, obfuscation then manual map + thread hijack + wipe dll seems great :P
Too much functions xD
after I choose obfuscation app crashes any solutions ?
Quote Originally Posted by heman38 View Post
after I choose obfuscation app crashes any solutions ?
I answered u on the other thread :P ... Basically what's ur windows version and language?
Does this avoid being VACed?
Sorry for the extreme delay ahaha ... RL issues.

Well, I don't know if this particular injector is ben tracked by any A.V team. My guess is that it (injector process) have good chances to be detected, as any other injector, by signature scanning.
Now, about userland injection, using all it's features still save. I don't have any news about it's algorithm/mechanism been flagged or detected anywhere....

But again, cheating is about chances and odds :}

I'm working in a 64 bits versions, I didn't released it yet because of RL . Soon or later a better version with support to 32-64 bits will appear here, watch out
This version became outdated . New version here.
can i get Vac Detected if i use this?
@Gaar @Raple , can you please change this thread to Outdated? New version here.
Thanks
Closed as outdated.
Posts 1–14 of 14 · Page 1 of 1
This thread is closed for replies.

Similar Threads

Tags for this Thread

Need help?