• Earn real money by being active: Hello Guest, earn real money by simply being active on the forum — post quality content, get reactions, and help the community. Once you reach the minimum credit amount, you’ll be able to withdraw your balance directly. Learn how it works.

Crypter Crybat (previously known as Jlaive)

Status
Not open for further replies.

dEEpEst

☣☣ In The Depths ☣☣
Staff member
Administrator
Super Moderator
Hacker
Specter
Crawler
Shadow
Joined
Mar 29, 2018
Messages
13,860
Solutions
4
Reputation
27
Reaction score
45,546
Points
1,813
Credits
55,090
‎7 Years of Service‎
 
56%
Crybat (previously known as Jlaive) is an antivirus evasion tool that can convert executables to undetectable batch files .NET assemblies are not guaranteed to work.


Features


  • .NET/Native (x64) support
  • AES/XOR encryption
  • Compression
  • Anti Debug
  • Anti VM
  • Melt file (self delete)
  • Bind files
  • AMSI bypass
  • ETW bypass


Screenshots


This link is hidden for visitors. Please Log in or register now.
 
This link is hidden for visitors. Please Log in or register now.


✓ Download:
To see this hidden content, you must like this content.
 
example1.PNG


Get-UnJlaive is tool which is able to reconstruct Jlaive (.NET Antivirus Evasion Tool (Exe2Bat)) to original Assembly and stub Assembly.
It should defeat even the obfuscated form.

✓Video Tutorial:

To see this hidden content, you must like this content.
✓Original Source:

To see this hidden content, you must like this content.
 
+Info 👇

Sergio de los Santos 

Última moda en ofuscación. Un fichero BAT (de 14MB) totalmente ofuscado, que corre un powershell que descifra (con AES) y ejecuta un .NET. Este por dentro también está ofuscado. Como es de esperar, cero detecciones en estático desde hace semanas. Además juega bien con los sets +¬

20230506-123405.jpg


To see this hidden content, you must like this content.
 
Last edited by a moderator:
Status
Not open for further replies.
Back
Top