HNHacker News
TopNewBestAskShowJobs

AdvDebug

41 karma · joined July 6, 2023

submissionscomments
AdvDebug··on [dead]
AntiCrack-DotNet is a project containing advanced techniques to prevent various malicious actions in your C# software, which is becoming more useful as AOT is being developed more and more.

anti-debug techniques (with syscall support to avoid anti anti-debuggers like scyllahide):

- NtUserGetForegroundWindow (looks for bad active window names to check if it's a known debugger)

- Debugger.IsAttached

- Hide Threads From Debugger

- IsDebuggerPresent

- PEB.BeingDebugged

- PEB.NtGlobalFlag

- NtSetDebugFilterState

- Page Guard Breakpoints Detection

- NtQueryInformationProcess: ProcessDebugFlags, ProcessDebugPort, ProcessDebugObjectHandle

- NtClose: Invalid Handle, Protected Handle

- Parent Process Checking (Checks if parent are explorer.exe or cmd.exe)

- Detection of Hardware Breakpoints

- FindWindow (looks for bad window names)

- GetTickCount

- OutputDebugString

- Crashing Non-Managed Debuggers with a Debugger Breakpoint

- OllyDbg Format String Exploit

- Patching DbgUiRemoteBreakin and DbgBreakPoint (Anti-Debugger Attaching)

Anti-Virtualization:

- Detecting Any.run

- Detecting Triage

- Detecting Qemu.

- Detecting Parallels.

- Detecting Sandboxie

- Detecting Comodo Container

- Detecting Qihoo360 Sandbox

- Detecting Cuckoo Sandbox

- Detecting VirtualBox and VMware

- Detecting HyperV

- Detecting Emulation

- Checking For Blacklisted Usernames

- Detecting KVM

- Detecting Wine

- Checking For Known Bad VM File Locations

- Checking For Known Bad Process Names

- Checking For Ports on the system (useful if the VM or the sandbox have no ports connected)

- Checking for devices created by VMs or Sandboxes

- Checking if AVX x64/x86 instructions are properly implemented to see if we are in an emulator.

- Checking for RDRAND x64/x86 instruction to see if it's properly implemented which could indicate an emulator.

- Checking for flags manipulation (for x64 and x86) checks to see if it's correctly handled.

Anti Injection:

- Taking Advantage of Binary Image Signature Mitigation Policy to prevent injecting Non-Microsoft Binaries.

- Checking if any injected libraries are present (simple dlls path whitelist check)

- Thread Injection Detection

- Using PEB to change the main module info of the program which is main module name and module base address at runtime.

- Detecting process hollowing in our program by checking suspicious image base address.

Other Detections:

- Detecting if Unsigned Drivers are Allowed to Load

- Detecting if Test-Signed Drivers are Allowed to Load

- Detecting if Kernel Debugging are Enabled on the System

- Detecting if Secure Boot are Enabled on the System

- Detecting if Virtualization-Based Security is Enabled.

- Detecting if Memory Integrity Protection is Enabled.

- Detecting if the current assembly has been invoked.

Hooks Detection:

- Detecting Most Anti Anti-Debugging Hooking Methods on Common Anti-Debugging Functions by checking for Bad Instructions on Functions Addresses and it detects user-mode anti anti-debuggers like scyllahide, and it can also detect some sandboxes which uses hooking to monitor application behaviour/activity (like Sandboxie/Sandboxie Plus, Hybrid analysis, Cuckoo Sandbox, and a lot of other online malware analysis websites/applications).

- Basic detection for stealthy page guard hooking.

- Detecting CLR Functions Hooking (like harmony hooks).

AdvDebug··on Elrouby Decrypted Desktop: The Best safe place for your files
ElroubyDecryptedDesktop is a project made in csharp that encrypts the user files and securely stores them.

- it uses Rijandel-256 (CBC Mode) - it have a nice UI.

i hope it can be useful to someone :)

AdvDebug··on [dead]
BehavEye is an advanced malware analysis tool that monitors malware behavior and give a comprehensive log about everything that happened.

Features:

- Monitoring Connections

-Monitors Process Actions (Impersonating Tokens, Creating Spoofed Parent, opening a process handle, creating a new process, setting process information, getting system information, process memory writing/reading, etc)

- Monitors Registry Actions

- Monitors the User API (for example if the process tried to find a window with a specific name, getting clipboard data, getting the last time the user was active, hooking mouse or keyboard which could be used for keylogging, etc)

- Monitor Driver Actions (monitoring driver/service creation, monitoring if the process tried to commuincate with a service/kernel driver, etc)

- Misc Monitoring (monitoring if the process tried to crash the system, shutdown the system, etc)

and much more.

AdvDebug··on [dead]
De4py v1.0.4 update has been released and includes an advanced feature that can be used for analysis of python files by monitoring it's behavior.

in this update a major feature have taken place, memory analyzing (WinAPI hooking). Monitoring Files:

Monitoring File Handles Creation

Monitoring Processes:

Monitoring Process handle

Monitoring if the process tried to write/read to a process

Monitoring Termination of other processes

Monitoring Connections:

Monitoring Socket creation

Monitoring sending/receiving of data with the size of data sent/recieved.

more to come soon.

AdvDebug··on [dead]
De4py is a simple python reverse engineering toolkit that contains deobfuscators for some popular obfuscators and some additional functionality that can help in reverse engineering.
AdvDebug··on NoMoreCookies: Protection Against Accounts Stealing
This Project protects against Accounts Stealing by malicious malware developers/script kiddies that makes a malicious executable file to try to steal cookies/passwords from browsers, in addition to warning the user about the program by making a notification that the stealing have been blocked and here's the program name.
AdvDebug··on AntiCrack-DotNet:C# Project that contains some advanced anti-cracking techniques
C# Project that contains some advanced techniques in C# to prevent dll injection, detecting winapi hooking (including detecting scyllahide, hybrid analysis, and similar software/sandboxing websites that hooks some winapis), detecting debuggers, VMs, etc.
AdvDebug··on Unshackle: A tool to bypass Windows and Linux password logins
Unshackle is a simple tool that deletes windows password logins (Linux support coming soon) using a bootable USB Drive, and makes you enter the system without any passwords, based on Alpine Linux.
AdvDebug··on NoMoreCookies: Protection against browser stealers/rats
there's no way to completely prevent stealers in the first place unless i had a kernel-driver, i'm not planning to eradicate/completely prevent stealers from stealing browser data. it's the same as if you had an antivirus, it doesn't protect you from every malware in existence, and their goal is to minimize your chances of getting infected. also most of the people who make stealers are just copy-pasting code so it will take a lot of time until they adapt to this, also i will implement some other stuff that prevents/make it harder for the program from removing the protection from itself.
AdvDebug··on NoMoreCookies: Protection against browser stealers/rats
i made a new github project called NoMoreCookies that protects users from the new stealers that are being released in the wild. it support protection for various browsers like: Firefox, MS Edge, Brave, Yandex, Chrome, Opera. and it's are being actively updated to mitigate any kind of bypass that attackers may try to implement if the tool got more popular. i thought of releasing such a tool cause a lot of stealers are being made and people channels are getting stolen and i thought that this is the time i make something that would prevent/slowing down the development of new stealers significantly and also making old ones obsolete.

you can find NoMoreCookies here: https://github.com/AdvDebug/NoMoreCookies

any feedback or suggestions are appreciated.