Sinisterly
Tutorial how to code a rat in c++ - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Hacking (https://sinister.li/Forum-Hacking)
+--- Forum: Remote Administration & Stress Testing (https://sinister.li/Forum-Remote-Administration-Stress-Testing)
+--- Thread: Tutorial how to code a rat in c++ (/Thread-Tutorial-how-to-code-a-rat-in-c)

Pages: 1 2


RE: how to code a rat in c++ - darkninja1980 - 04-21-2019

(04-21-2019, 07:12 AM)IsBadWritePtr Wrote: Its not about if you know the language, it is about knowing the subsystem and how it will behave, example on windows if you use too many CPUID instructions the antivirus might flag your program as potential thread, starting svchost.exe, same if you open too many processes with PRCOESS_ALL_ACCESS

about the syntax for what you use like for an example. like arrays or loops.


RE: how to code a rat in c++ - IsBadWritePtr - 04-21-2019

(04-21-2019, 07:22 PM)darkninja1980 Wrote:
(04-21-2019, 07:12 AM)IsBadWritePtr Wrote: Its not about if you know the language, it is about knowing the subsystem and how it will behave, example on windows if you use too many CPUID instructions the antivirus might flag your program as potential thread, starting svchost.exe, same if you open too many processes with PRCOESS_ALL_ACCESS

about the syntax for what you use like for an example. like arrays or loops.

What syntax ? CPUID can be used to detect hyper-visor and if the CPU information is altered and there might be more tricks that makes it taboo to spam CPUID in a loop for some antivirus sandboxes, svchost and explorer is where almost all malware is injected, NtOpenProcess is filtered by the antivirus and using PROCESS_ALL_RIGHT might be no no for the antivirus


RE: how to code a rat in c++ - darkninja1980 - 04-21-2019

(04-21-2019, 08:07 PM)IsBadWritePtr Wrote:
(04-21-2019, 07:22 PM)darkninja1980 Wrote:
(04-21-2019, 07:12 AM)IsBadWritePtr Wrote: Its not about if you know the language, it is about knowing the subsystem and how it will behave, example on windows if you use too many CPUID instructions the antivirus might flag your program as potential thread, starting svchost.exe, same if you open too many processes with PRCOESS_ALL_ACCESS

about the syntax for what you use like for an example. like arrays or loops.

What syntax  ? CPUID can be used to detect hyper-visor and if the CPU information is altered and there might be more tricks that makes it taboo to spam CPUID in a loop for some antivirus sandboxes, svchost and explorer is where almost all malware is injected, NtOpenProcess is filtered by the antivirus and using PROCESS_ALL_RIGHT might be no no for the antivirus

like for making tools such as for rats, malware and etc? I know like task kill or delete files.