how can be sure RAT haven't backdoor inside ?
by - Thursday, January 1, 1970 at 12:00 AM
(November 16, 2022, 03:58 AM)x1z1 Wrote:
(November 15, 2022, 09:52 PM)section777 Wrote:
(November 15, 2022, 09:11 PM)x1z1 Wrote: either creat your own RAT or you`ll have to fully check the code or maybe full analyse it on a test machine


check full the code is it posible for fews hours ? i ask about standard rat ,small size.


well if its a short one , the a static check should be ur base start

Thanks
Reply
(November 16, 2022, 05:02 PM)section777 Wrote:
(November 16, 2022, 03:58 AM)x1z1 Wrote:
(November 15, 2022, 09:52 PM)section777 Wrote:
(November 15, 2022, 09:11 PM)x1z1 Wrote: either creat your own RAT or you`ll have to fully check the code or maybe full analyse it on a test machine


check full the code is it posible for fews hours ? i ask about standard rat ,small size.


well if its a short one , the a static check should be ur base start

Thanks

You're welcome buddy
Reply

if post,the fud will be dead before to be born.

Is it any trusted member here or any coder somwhere else who read/check the source as service ? as pay for checking ? it can be good idea but also the "checker" can put somthing inside...that's the problem. 😕 
regards



Use a local installation of cuckoo sandbox on both the installer and payload made. Make sure no connections are made from the builder and the payload only connects to your c2.
  :pomsleep: i am in your walls
Reply
(November 16, 2022, 06:01 PM)tty Wrote:

if post,the fud will be dead before to be born.

Is it any trusted member here or any coder somwhere else who read/check the source as service ? as pay for checking ? it can be good idea but also the "checker" can put somthing inside...that's the problem. 😕 
regards



Use a local installation of cuckoo sandbox on both the installer and payload made. Make sure no connections are made from the builder and the payload only connects to your c2.


yes nice way but how to sure no connection betwen both ? with port scanning ?
regards;
Reply
(November 19, 2022, 04:56 PM)section777 Wrote:
(November 16, 2022, 06:01 PM)tty Wrote:

if post,the fud will be dead before to be born.

Is it any trusted member here or any coder somwhere else who read/check the source as service ? as pay for checking ? it can be good idea but also the "checker" can put somthing inside...that's the problem. 😕 
regards



Use a local installation of cuckoo sandbox on both the installer and payload made. Make sure no connections are made from the builder and the payload only connects to your c2.


yes nice way but how to sure no connection betwen both ? with port scanning ?
regards;


Cuckoo sandbox will show you all network connections made
  :pomsleep: i am in your walls
Reply
(November 19, 2022, 05:48 PM)tty Wrote:
(November 19, 2022, 04:56 PM)section777 Wrote:
(November 16, 2022, 06:01 PM)tty Wrote:

if post,the fud will be dead before to be born.

Is it any trusted member here or any coder somwhere else who read/check the source as service ? as pay for checking ? it can be good idea but also the "checker" can put somthing inside...that's the problem. 😕 
regards



Use a local installation of cuckoo sandbox on both the installer and payload made. Make sure no connections are made from the builder and the payload only connects to your c2.


yes nice way but how to sure no connection betwen both ? with port scanning ?
regards;


Cuckoo sandbox will show you all network connections made

amazing answer.thanks for your help,that exactly ppl like you who is needed over forum.hard to find now....
Reply


 Users viewing this thread: how can be sure RAT haven't backdoor inside ?: No users currently viewing.