
Originally Posted by
The Czar
Alright time to give you skids a fucking lesson on AV Detections as I own a crypter as well.
VARIANT DETECTIONS = SUSPECIOUS ASSEMBLY / FILE NAME
TROJAN = MY LOADER IS A INJECTOR OFC IT WILL GET DETECTED AS THAT
AND
Retards spread my cheat on youtube with their RATs so my file gets falsely detected
Uhm, "non-skid," your file won't get higher detection rates because other people throw RAT's inside of it.
The complete hash string with change because of this, the amount of bytes, the assembly information, etc.
It will be scanned as a new file. I can actually prove this to you.
Also, binding things with known RATs like DarkComet, VaNtoM RAT, njRAT, Blackshades, etc without further encryption will show up as Spyware with a name appropiate for the used RATing software.
If the file is encrypted, it will still show up as either crypted, obfuscated, etc after the methods are outdated, or as Spyware with a name appropiate for the used RATing software.
TL;DR: People throwing RAT's into existing files, will not change the detection rates of the main, unmodified file as the complete hash string with change because of this, the amount of bytes, the assembly information, etc.. will not match anymore.