Many of you might have tried many stealers and remote monitoring application to get records of your client.
You might have authorized on various FTP, PHP websites or even messages to analyze and get records of your clients.
Well, if you are not getting records that does not mean Stealer or Key logger is not excellent or web host website is bad.
There are various factors why individuals never get records many periods.
I will talk about some of the factors, which I know. If you know more than these, please you can Comment
Reason 1:
You might have joined incorrect FTP, PHP information and facts. This is because many individuals never know how to put right PHP or FTP information and facts into Stealer or Key logger.
Reason 2:
May be your application is preventing entry to your information file.
If your client has highly effective application (like ZoneAlarm, Outpost etc…), then it WILL suspicious some dubious conduct and pop-up Also benefit. If your client is sensible enough, then he/she may avoid entry to your information file.
Reason 3:
You never know who is installing your information file (EXE). If the person is able enough to ollydbg your information file, he may quickly get your FTP information and facts (if information file is not hardly crypted). If the person is sensible enough, he may VMWare or Sand box ur information file and may remove ur information file after seeing such exterior accessibility information and facts.
Reason 4:
Many Stealers or Keyloggers use UDP relationship instead of TCP, for example Stealer2600.
UDP is very much not reliable as when in comparison to TCP. So, UDP does not offer mistake checksum or resending of information. If ur Stealer or Key logger is using TCP relationship, then its much better.
Reason 5:
Sometimes it may occur that FTP or PHP coordinator is down for some factors (like copy or upgradation etc…). Then, ur stealer will deliver information and facts to the coordinator, but as the coordinator is down, u will not get records.
Reason 6:
If your Stealer or Key logger is FUD, say nowadays on 10 Goal. It may become recognized on 14 or 14 of Goal. You may never know. So, it will not be FUD any longer and AV’s will remove it or may be Firewall program will avoid entry to your information file.
Reason 7:
If your client has highly effective AV’s like Kaspersky, Avast, Nod etc…, they have Heutistic checking. This may also avoid information file from starting.
If ur exe is anti-Kaspersky or such like that, then well and excellent.
Reason 8:
Make sure your EXE is FUD and with many Anti-methods like anti-anubis, anti-sandbox, anti-VMWare, anti-debugger, anti-emulator, anti-sunbelt etc… (There are terrible lot of anti-methods, i just described a few)…
If ur exe is not quit with any of the above techniques, then it may get recognized, even by a n00b symbol razz 20 Reasons Why Individuals do not Receive Wood logs via Stealer or Keylogger
Reason 9:
Sometimes, while stealer is submitting records to ur FTP or PHP, some packages may missing while visiting ur coordinator. This is because of many factors, like program traffic jam or bottleneck issues, etc…
Reason 10:
Sometimes, your coordinator gets too fast paced and might come under very much demand. So, it may quit performing and may not gather records.
Reason 11:
Once you have spread ur EXE and if ur using FTP acc to get records, and then if modify complete of ur FTP acc, then also ur exe will not deliver records.
This is coz, think say, ur ftp sign in information and facts is username: “hello” and code is: “123456″. This is information and facts is saved in ur exe and u spread that. While posting, ur exe will use the above information and facts to publish records to ur FTP.
If u modify the code to “456789″, then u know that u hv modified the code of ur FTP acc, but ur EXE does not know this. It will use the code as “123456″. So, in this situation also you will not get records.
Reasons 12:
Your Stealer or keylogger is a man-made application. It also needs servicing and upgradation. Over some time interval, its may efficiency may reduce. This is also the purpose of not getting records. But this happens very hardly ever, only if ur sticked to the same stealer for 2 decades or more.
Reason 13:
Next purpose is may be your crypter/binder/packer. If ur crypter does not assistance the stealer or keylogger which ur using, then it may infected ur exe.
So, select the stealer and crypter collaboration correctly.
Reason 14:
Another purpose is an os. Assume say, ur stealer or keylogger is designed to run on XP SP1, SP2, SP3, NT, 2k and Windows vista.
If ur clients is using Windows 7, then obviously ur exe will not run on his PC as it can not comprehend how to perform.
Reason 15:
Another purpose cud be 32-bit and 64-bit. If stealer or keylogger is designed to run only on 32-bit models, then on 64-bit models, it may not perform, even if ur using XP and stealer is appropriate with XP.
Reason 16:
If you dun have excellent crypter and if ur FUDing ur information file personally via Hexing, then create sure that u know appropriate hexing. Do not just go on the search engines or on some boards and discover hexing remedy on FUDing ur information file. You WILL infected ur EXE if ur dun comprehend balanced out and other terms…
Using guide on hexing is the best option but dun utilize ur own sense with that hex tut if u never hexing.
Also, dun incorporate one hex guide with another hex guide.
This will definitely infected ur information file.
Reason 17:
If ur client does not have saved account details in his visitor, then also stealer will not deliver records or it will deliver clear records.
Reason 18:
Say, ur client is using Google firefox and saving account details in it. If ur stealer is not designed to grab account details from firefox, then also u will not get records.
So, select a stealer which have excellent collaboration of visitor (FF, IE, etc…)
Reason 19:
Suppose ur EXE is FUD and is less than 20MB and if ur clients tests ur EXE under virustotal, or jotti, then ur EXE will get recognized by many AV’s and within few periods, it will get recognized quickly and AV’ will remove it.
Reason 20:
Even if ur EXE is 0/24 (FUD) on NVT, but if ur clients tests ur exe under Anubis, then mostly Anubis will present all the information and facts after undertaking ur exe. This may notify ur client and he may remove ur information file.
You might have authorized on various FTP, PHP websites or even messages to analyze and get records of your clients.
Well, if you are not getting records that does not mean Stealer or Key logger is not excellent or web host website is bad.
There are various factors why individuals never get records many periods.
I will talk about some of the factors, which I know. If you know more than these, please you can Comment
Reason 1:
You might have joined incorrect FTP, PHP information and facts. This is because many individuals never know how to put right PHP or FTP information and facts into Stealer or Key logger.
Reason 2:
May be your application is preventing entry to your information file.
If your client has highly effective application (like ZoneAlarm, Outpost etc…), then it WILL suspicious some dubious conduct and pop-up Also benefit. If your client is sensible enough, then he/she may avoid entry to your information file.
Reason 3:
You never know who is installing your information file (EXE). If the person is able enough to ollydbg your information file, he may quickly get your FTP information and facts (if information file is not hardly crypted). If the person is sensible enough, he may VMWare or Sand box ur information file and may remove ur information file after seeing such exterior accessibility information and facts.
Reason 4:
Many Stealers or Keyloggers use UDP relationship instead of TCP, for example Stealer2600.
UDP is very much not reliable as when in comparison to TCP. So, UDP does not offer mistake checksum or resending of information. If ur Stealer or Key logger is using TCP relationship, then its much better.
Reason 5:
Sometimes it may occur that FTP or PHP coordinator is down for some factors (like copy or upgradation etc…). Then, ur stealer will deliver information and facts to the coordinator, but as the coordinator is down, u will not get records.
Reason 6:
If your Stealer or Key logger is FUD, say nowadays on 10 Goal. It may become recognized on 14 or 14 of Goal. You may never know. So, it will not be FUD any longer and AV’s will remove it or may be Firewall program will avoid entry to your information file.
Reason 7:
If your client has highly effective AV’s like Kaspersky, Avast, Nod etc…, they have Heutistic checking. This may also avoid information file from starting.
If ur exe is anti-Kaspersky or such like that, then well and excellent.
Reason 8:
Make sure your EXE is FUD and with many Anti-methods like anti-anubis, anti-sandbox, anti-VMWare, anti-debugger, anti-emulator, anti-sunbelt etc… (There are terrible lot of anti-methods, i just described a few)…
If ur exe is not quit with any of the above techniques, then it may get recognized, even by a n00b symbol razz 20 Reasons Why Individuals do not Receive Wood logs via Stealer or Keylogger
Reason 9:
Sometimes, while stealer is submitting records to ur FTP or PHP, some packages may missing while visiting ur coordinator. This is because of many factors, like program traffic jam or bottleneck issues, etc…
Reason 10:
Sometimes, your coordinator gets too fast paced and might come under very much demand. So, it may quit performing and may not gather records.
Reason 11:
Once you have spread ur EXE and if ur using FTP acc to get records, and then if modify complete of ur FTP acc, then also ur exe will not deliver records.
This is coz, think say, ur ftp sign in information and facts is username: “hello” and code is: “123456″. This is information and facts is saved in ur exe and u spread that. While posting, ur exe will use the above information and facts to publish records to ur FTP.
If u modify the code to “456789″, then u know that u hv modified the code of ur FTP acc, but ur EXE does not know this. It will use the code as “123456″. So, in this situation also you will not get records.
Reasons 12:
Your Stealer or keylogger is a man-made application. It also needs servicing and upgradation. Over some time interval, its may efficiency may reduce. This is also the purpose of not getting records. But this happens very hardly ever, only if ur sticked to the same stealer for 2 decades or more.
Reason 13:
Next purpose is may be your crypter/binder/packer. If ur crypter does not assistance the stealer or keylogger which ur using, then it may infected ur exe.
So, select the stealer and crypter collaboration correctly.
Reason 14:
Another purpose is an os. Assume say, ur stealer or keylogger is designed to run on XP SP1, SP2, SP3, NT, 2k and Windows vista.
If ur clients is using Windows 7, then obviously ur exe will not run on his PC as it can not comprehend how to perform.
Reason 15:
Another purpose cud be 32-bit and 64-bit. If stealer or keylogger is designed to run only on 32-bit models, then on 64-bit models, it may not perform, even if ur using XP and stealer is appropriate with XP.
Reason 16:
If you dun have excellent crypter and if ur FUDing ur information file personally via Hexing, then create sure that u know appropriate hexing. Do not just go on the search engines or on some boards and discover hexing remedy on FUDing ur information file. You WILL infected ur EXE if ur dun comprehend balanced out and other terms…
Using guide on hexing is the best option but dun utilize ur own sense with that hex tut if u never hexing.
Also, dun incorporate one hex guide with another hex guide.
This will definitely infected ur information file.
Reason 17:
If ur client does not have saved account details in his visitor, then also stealer will not deliver records or it will deliver clear records.
Reason 18:
Say, ur client is using Google firefox and saving account details in it. If ur stealer is not designed to grab account details from firefox, then also u will not get records.
So, select a stealer which have excellent collaboration of visitor (FF, IE, etc…)
Reason 19:
Suppose ur EXE is FUD and is less than 20MB and if ur clients tests ur EXE under virustotal, or jotti, then ur EXE will get recognized by many AV’s and within few periods, it will get recognized quickly and AV’ will remove it.
Reason 20:
Even if ur EXE is 0/24 (FUD) on NVT, but if ur clients tests ur exe under Anubis, then mostly Anubis will present all the information and facts after undertaking ur exe. This may notify ur client and he may remove ur information file.
1 comments:
I found few of website but this website very unique and so many interesting information in here. I have come to know lots from this blog. Looking forward for more.
Post a Comment