tehe

Posts 1–15 of 15 · Page 1 of 1
tehe
Soo, Extreme Injector v1.2 -> All PE Hiding, All Dll Scrambling, Manual Map = No Detect ?

Sure ?

Injected .DLL whit Makecert -> Using these Method's -> Xtrap Error v8000 Abnormal Acess Memory, Tool Name: blank.

This method is already catched, our guys doing something wrong.
Quote Originally Posted by sobasoba13 View Post
What ? xD ...
Quote Originally Posted by XarutoUsoCrack View Post
your words are not clear xD
manual map inject -> xtrap
everything is xtrap today.
Quote Originally Posted by XarutoUsoCrack View Post
manual map inject -> xtrap
everything is xtrap today.
manual map is working fine with me
try to make your own injector cuz Extreme Injector is buggy a little
Still Working For Me , NA/CF
well, anyway, if i create a _beginthreadex it geet's unhooked for some reason, and CreateThread is my only solution, but it gives this xtrap message, soo...
Quote Originally Posted by XarutoUsoCrack View Post
well, anyway, if i create a _beginthreadex it geet's unhooked for some reason, and CreateThread is my only solution, but it gives this xtrap message, soo...
I use createthread and it works !!!
use it with a cert and manual mapping injector ,, it should works !!
Code:
#include <Windows.h>

DWORD WINAPI InfinityLoop ( LPVOID )
{
	while( true )
	{

	}
	return false;
}

DWORD WINAPI DllMain ( HMODULE hDll, DWORD dwReason, LPVOID ipvReason )
{
	switch( dwReason )
	{
	case 1:
		DisableThreadLibraryCalls( hDll );
		CreateThread( 0, 0, InfinityLoop, 0, 0, 0 );
		break;
	}

	return 1;
}
Xtrap v8000 Detection No Tool Name, using PE Hiding, Scrambling and Manual Map & Makecert, injector: Extreme Injector v1.2
Quote Originally Posted by XarutoUsoCrack View Post
Code:
#include <Windows.h>

DWORD WINAPI InfinityLoop ( LPVOID )
{
	while( true )
	{

	}
	return false;
}

DWORD WINAPI DllMain ( HMODULE hDll, DWORD dwReason, LPVOID ipvReason )
{
	switch( dwReason )
	{
	case 1:
		DisableThreadLibraryCalls( hDll );
		CreateThread( 0, 0, InfinityLoop, 0, 0, 0 );
		break;
	}

	return 1;
}
Xtrap v8000 Detection No Tool Name, using PE Hiding, Scrambling and Manual Map & Makecert, injector: Extreme Injector v1.2
Don't Use PE Hiding Nor Scrambling
Code:
BOOL WINAPI DllMain ( HINSTANCE hinstDLL, DWORD dwReason, LPVOID lpReserved )
{
	switch(dwReason) {
     case DLL_PROCESS_ATTACH: 
		DisableThreadLibraryCalls(hinstDLL);
		 CreateThread(NULL, NULL, (LPTHREAD_START_ROUTINE)Thread, hinstDLL, NULL, NULL); 
		break;
		  case DLL_PROCESS_DETACH: break;
                  case DLL_THREAD_ATTACH:  break;
		  case DLL_THREAD_DETACH:  break;
	}
	return TRUE;
}
this is what i am using
try it
That's what happens when I tell someone how I get my hack not being detected by XTrap..
Code:
typedef UINT(__stdcall *threadFunc_t)(void*);
HANDLE createStealthThread(threadFunc_t pThreadFunc, void *pArgument)
{
   BYTE *pK32     = (BYTE*)GetModuleHandleA("kernel32");
   BYTE *pPopRet  = nullptr;
   DWORD oldProt;

   auto rva2va = [&](DWORD dwVA)
   { 
      return (void*)((uintptr_t)pK32 + dwVA);
   };

   // Find propper location to place our shellcode
   void *pWriteTarget = nullptr;

   auto pMz          = (IMAGE_DOS_HEADER*    )pK32;
   auto pNt          = (IMAGE_NT_HEADERS32*  )rva2va(pMz->e_lfanew);
   auto pCurSection  = (IMAGE_SECTION_HEADER*)((uintptr_t)pNt
                     + sizeof(IMAGE_NT_HEADERS32));

   for (int i = 0; i < pNt->FileHeader.NumberOfSections; ++i)
   {
      if (memcmp(".text", pCurSection->Name, 5) == 0)
      {
         pWriteTarget = (void*)((uintptr_t)rva2va(pCurSection->VirtualAddress) 
                                + pCurSection->Misc.VirtualSize - 6);
         break;
      }
      ++pCurSection;
   }

   if (!pWriteTarget)
      return NULL;

   // Prepare and write shellcode to K32
   uint8_t shellcode[] = "\x68\x00\x00\x00\x00\xC2";
   *(threadFunc_t*)(shellcode + 1) = pThreadFunc;
   
   VirtualProtect(pWriteTarget, 6, PAGE_EXECUTE_READWRITE, &oldProt);
   memcpy(pWriteTarget, shellcode, 6);
   VirtualProtect(pWriteTarget, 6, oldProt, &oldProt);

   // Create thread
   return CreateThread(nullptr, 
                       0, 
                       (LPTHREAD_START_ROUTINE)pWriteTarget,
                       pArgument,
                       NULL,
                       nullptr);
} // ==> createStealthThread
Requires MSVC10+ or a compiler with at least equivalent C++11 support. We used that when debugging our hack in the beginning of 2013. Should still work (didn't test it, though).
That munual map also doesnt work for me... I suggest that everybody writes his OS info here so we can see...

I am Win 7 Ultimate x64
Posts 1–15 of 15 · Page 1 of 1
This thread is closed for replies.

Similar Threads

Tags for this Thread

None

Talk with us