Welcome to The Forum

Register now to gain access to all of our features. Once registered and logged in, you will be able to create topics, post replies to

existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile

and so much more. This message will be removed once you have signed in.

Active Hackers

The best community of active hackers. This community has been working in hacking for more than 10 years.

 

Hacker Forum

Hacker from all countries join this community to share their knowledge and their hacking tools

    Hacking Tools

    You can find thousands of tools shared by hackers. RAT's, Bot's, Crypters FUD, Stealers, Binders, Ransomware, Mallware, Virus, Cracked Accounts, Configs, Guides, Videos and many other things.

      PRIV8

      Become a Priv8 user and access all parts of the forum without restrictions and without limit of download. It only costs 100 dollars, and it will last you for a lifetime.

      Read Rules

      In this community we follow and respect rules, and they are the same for everyone, regardless of the user's rank. Read the rules well not to be prohibited.

      All Activity

      This stream auto-updates     

      1. Past hour
      2. [Hidden Content] This is 1000% tested working even our student carded by this method.
      3. [Hidden Content]
      4. Level23HackTool

        american-pornstar.com x1

        [Hidden Content]
      5. dEEpEst

        QVC.com TUT

        [Hidden Content]
      6. [Hidden Content]
      7. Level23HackTool

        Sendspace.com x1

        [Hidden Content]
      8. dEEpEst

        Evil Clippy

        This tool was released during our BlackHat Asia talk (March 28, 2019). A video recording will be online in 90 days. Evil Clippy A cross-platform assistant for creating malicious MS Office documents. Can hide VBA macros, stomp VBA code (via P-Code) and confuse macro analysis tools. Runs on Linux, OSX and Windows. If you're new to this tool, you might want to start by reading our blog post on Evil Clippy:[Hidden Content] Current features Hide VBA macros from the GUI editor VBA stomping (P-code abuse) Fool analyst tools Serve VBA stomped templates via HTTP Set/Remove VBA Project Locked/Unviewable Protection If you have no idea what all of this is, check out the following resources first: Our MS Office Magic Show presentation at Derbycon 2018 VBA stomping resources by the Walmart security team Pcodedmp by Dr. Bontchev How effective is this? At the time of writing, this tool is capable of getting a default Cobalt Strike macro to bypass all major antivirus products and most maldoc analysis tools (by using VBA stomping in combination with random module names). Technology Evil Clippy uses the OpenMCDF library to manipulate MS Office Compound File Binary Format (CFBF) files, and hereto abuses MS-OVBA specifications and features. It reuses code from Kavod.VBA.Compression to implement the compression algorithm that is used in dir and module streams (see MS-OVBA for relevant specifications). Evil Clippy compiles perfectly fine with the Mono C# compiler and has been tested on Linux, OSX and Windows. Compilation A cross-platform compiled binary can be found under "releases". OSX and Linux Make sure you have Mono installed. Then execute the following command from the command line: mcs /reference:OpenMcdf.dll,System.IO.Compression.FileSystem.dll /out:EvilClippy.exe *.cs Now run Evil Clippy from the command line: mono EvilClippy.exe -h Windows Make sure you have Visual Studio installed. Then execute the following command from a Visual Studio developer command prompt: csc /reference:OpenMcdf.dll,System.IO.Compression.FileSystem.dll /out:EvilClippy.exe *.cs Now run Evil Clippy from the command line: EvilClippy.exe -h Usage examples Print help EvilClippy.exe -h Hide/Unhide macros from GUI Hide all macro modules (except the default "ThisDocument" module) from the VBA GUI editor. This is achieved by removing module lines from the project stream [MS-OVBA 2.3.1]. EvilClippy.exe -g macrofile.doc Undo the changes done by the hide option (-g) so that we can debug the macro in the VBA IDE. EvilClippy.exe -gg macrofile.doc Stomp VBA (abuse P-code) Put fake VBA code from text file fakecode.vba in all modules, while leaving P-code intact. This abuses an undocumented feature of module streams [MS-OVBA 2.3.4.3]. Note that the VBA project version must match the host program in order for the P-code to be executed (see next example for version matching). EvilClippy.exe -s fakecode.vba macrofile.doc Note: VBA Stomping does not work for files saved in the Excel 97-2003 Workbook (.xls) format Set target Office version for VBA stomping Same as the above, but now explicitly targeting Word 2016 on x86. This means that Word 2016 on x86 will execute the P-code, while other versions of Word wil execute the code from fakecode.vba instead. Achieved by setting the appropriate version bytes in the _VBA_PROJECT stream [MS-OVBA 2.3.4.1]. EvilClippy.exe -s fakecode.vba -t 2016x86 macrofile.doc Set/reset random module names (fool analyst tools) Set random ASCII module names in the dir stream [MS-OVBA 2.3.4.2]. This abuses ambiguity in the MODULESTREAMNAME records [MS-OVBA 2.3.4.2.3.2.3] - most analyst tools use the ASCII module names specified here, while MS Office used the Unicode variant. By setting a random ASCII module name most P-code and VBA analysis tools crash, while the actual P-code and VBA still runs fine in Word and Excel. EvilClippy.exe -r macrofile.doc Note: this is known to be effective in tricking pcodedmp and VirusTotal Set ASCII module names in the dir stream to match their Unicode counterparts. This reverses the changes made using the (-r) optoin of EvilClippy EvilClippy.exe -rr macrofile.doc Serve a VBA stomped template via HTTP Service macrofile.dot via HTTP port 8080 after performing VBA stomping. If this file is retrieved, it automatically matches the target's Office version (using its HTTP headers and then setting the _VBA_PROJECT bytes accordingly). EvilClippy.exe -s fakecode.vba -w 8080 macrofile.dot Note: The file you are serving must be a template (.dot instead of .doc). You can set a template via a URL (.dot extension is not required!) from the developer toolbar in Word. Also, fakecode.vba must have a VB_Base attribute set for a macro from a template (this means that your facecode.vba must start with a line such as Attribute VB_Base = "0{00020906-0000-0000-C000-000000000046}"). Set/Remove VBA Project Locked/Unviewable Protection To set the Locked/Unviewable attributes use the '-u' option: EvilClippy.exe -u macrofile.doc To remove the Locked/Unviewable attributes use the '-uu' option: EvilClippy.exe -uu macrofile.doc Note: You can remove the Locked/Unviewable attributes on files that were not locked with EvilClippy as well. Limitations Developed for Microsoft Word and Excel document manipulation. As noted above, VBA stomping is not effective against Excel 97-2003 Workbook (.xls) format. [Hidden Content]
      9. [HIDE][Hidden Content]]
      10. Level23HackTool

        HULU And HBO x15

        [Hidden Content]
      11. dEEpEst

        Xerosploit

        Xerosploit Xerosploit is a penetration testing toolkit whose goal is to perform man in the middle attacks for testing purposes. It brings various modules that allow to realise efficient attacks, and also allows to carry out denial of service attacks and port scanning. Powered by bettercap and nmap. Dependencies nmap hping3 build-essential ruby-dev libpcap-dev libgmp3-dev tabulate terminaltables Instalation Dependencies will be automatically installed. git clone [Hidden Content] cd xerosploit && sudo python install.py sudo xerosploit Tested on Operative system Version Ubuntu 16.04 / 15.10 Kali linux Rolling / Sana Parrot OS 3.1 features Port scanning Network mapping Dos attack Html code injection Javascript code injection Download intercaption and replacement Sniffing Dns spoofing Background audio reproduction Images replacement Drifnet Webpage defacement and more ... Demonstration [Hidden Content]
      12. Level23HackTool

        Wtfpass x1

        [Hidden Content]
      13. dEEpEst

        Clone phishing

        [Hidden Content]
      14. dEEpEst

        CRYPTOJACKING

        [Hidden Content]
      15. dEEpEst

        Spyware

        [Hidden Content]
      16. dEEpEst

        COLD BOOT ATTACKS 

        [Hidden Content]
      17. dEEpEst

        Mosca

        Mosca ===== Manual analysis tool to find bugs like a grep unix command, Version 0.05 because is not dynamic... uses static code to search... don't confuse with academic views hahaha don't have graph here or CFG... is a simple "grep" *egg modules is a config to find to vulnerabilities *you can use at C, PHP, javascript, ruby etc *Save results at XML file *create your own modules etc... *why static ? [Hidden Content]
      18. dEEpEst

        NodeCrypt - Linux Ransomware

        What is nodeCrypto? Install server Install and run Screenshot What is nodeCrypto? nodeCrypt is a linux Ransomware written in NodeJs that encrypt predefined files. This project was created for educational purposes, you are the sole responsible for the use of nodeCrypto. Install server Upload all file of server/ folder on your webserver. Create a sql database and import sql/nodeCrypto.sql Edit server/libs/db.php and add your SQL ID. Install and run git clone [Hidden Content] cd nodeCrypto && npm install You must edit first variable in index.js Once your configuration is complete, you can start the ransomware. node index.js The files at the root of the web server will encrypt and send to the server. Screenshot To Do Client (victim) Encrypt webserver Use private key for encryption Adapt SSL Server Recover data (user + encrypted file) Format the database Make GUI for webserver Make an executable to decrypt the files (Only on request! Contact me) [Hidden Content]
      19. Level23HackTool

        Naughtyamerica.com

        [Hidden Content]
      20. Today
      21. dEEpEst

        How To Make Combos

        [Hidden Content]
      22. Level23HackTool

        Deezer.com Premium x2

        [Hidden Content]
      23. Level23HackTool

        NordVPN Premium x5

        [Hidden Content]
      24. itsMe

        x1 Netflix

        [Hidden Content]
      1. Load more activity