Thread Rating:
  • 2 Vote(s) - 5 Average
  • 1
  • 2
  • 3
  • 4
  • 5
How to decrypt phishers
#1
Hello mates today I'm going to show you how to decrypt phisher to get out their information and stop them for good. This process is called Reverse Engineering.

Now first you need to download a good disassembler like:


Also need to download Sandboxie from here

After you done downloading the disassembler let's get start it Smile.


First you need to find a phisher of course, here is an example of a video I found in youtube it talks about how this program can change "stats" from the game runescape.:
[Image: Tutorial.jpg]

Now that we have our phisher lets run it sandboxie to see if is a real phisher or maybe a keylogger o_0.

[Image: Tutorial1.jpg]

So in this image nothing unusual just a simple phisher an ftp function in the program, or mailsystem.

Now we use String Stealer to break down the program


It should be something like this.
[Image: tutorial3.jpg]

Now to open the file in String Stealer go to:
Menu> Load Assambler> phisher.exe{This should be the phisher}
Now it should look something like this:
[Image: tutorial2.jpg]

Now most likely that you will find the email and password should be in
Form1> Button1_Click:
[Image: tutorial4-1-1.jpg]

Bingo we hit the jackpot we found the email and password of the phiser's owner. After you do this I will recommend to delete everything/change password/or even delete the email of the phisher's owner because he deserves it.
==============================================================================================================
Tools you need (an optional)

  • Red Gate's Reflector:
    This is a good Decompiler it can show you the code of the classes and methods, and how everything relates (optional):
    News about the .NET Reflector here

  • String Stealer:
    Basic dissassembler will be using during this tutorial

  • Sandboxie
    Really important you will use this to test the phishers

  • BinText:
    Optional (thanks to Elektrisk)

==============================================================================================================

Feedbacks opinions are accepted


==============================================================================================================
Credits


I wrote this tutorial, but I also give some credits to Qkyrie who taught me how to do this.
[Image: mynewsig.jpg]

Want to know how to stop offline Phisher for good, well click here
Reply


Messages In This Thread
How to decrypt phishers - by Acekidd01 - 10-09-2009, 01:09 PM
RE: How to decrypt phishers - by Michael - 10-09-2009, 01:15 PM
RE: How to decrypt phishers - by Acekidd01 - 10-09-2009, 01:17 PM
RE: How to decrypt phishers - by juan9087 - 10-09-2009, 01:35 PM
RE: How to decrypt phishers - by Acekidd01 - 10-09-2009, 01:37 PM
RE: How to decrypt phishers - by Acekidd01 - 10-09-2009, 01:42 PM
RE: How to decrypt phishers - by brett7 - 10-09-2009, 03:23 PM
RE: How to decrypt phishers - by Lazydude2000 - 10-09-2009, 03:25 PM
RE: How to decrypt phishers - by Monoxide - 10-09-2009, 03:26 PM
RE: How to decrypt phishers - by Elektrisk - 10-09-2009, 03:37 PM
RE: How to decrypt phishers - by rajvid9 - 10-10-2009, 07:28 AM
RE: How to decrypt phishers - by 5C4RF4C3 - 10-09-2009, 03:39 PM
RE: How to decrypt phishers - by Acekidd01 - 10-09-2009, 03:40 PM
RE: How to decrypt phishers - by MYPE - 10-09-2009, 09:19 PM
RE: How to decrypt phishers - by Elektrisk - 10-09-2009, 09:27 PM
RE: How to decrypt phishers - by Acekidd01 - 10-09-2009, 10:21 PM
RE: How to decrypt phishers - by Acekidd01 - 10-10-2009, 06:40 PM
RE: How to decrypt phishers - by Bit - 10-10-2009, 06:40 PM
RE: How to decrypt phishers - by Dingo_Dog - 10-10-2009, 08:05 PM
RE: How to decrypt phishers - by Viciousness - 10-10-2009, 08:06 PM
RE: How to decrypt phishers - by Dingo_Dog - 10-10-2009, 08:12 PM
RE: How to decrypt phishers - by HuNt3R - 10-10-2009, 08:32 PM
RE: How to decrypt phishers - by Acekidd01 - 10-11-2009, 12:27 AM
RE: How to decrypt phishers - by Reece - 10-11-2009, 12:31 AM
RE: How to decrypt phishers - by Acekidd01 - 10-11-2009, 12:34 AM
RE: How to decrypt phishers - by BlizzStaff - 10-11-2009, 06:54 PM
RE: How to decrypt phishers - by Viciousness - 10-11-2009, 06:56 PM
RE: How to decrypt phishers - by Elektrisk - 10-11-2009, 07:54 PM
RE: How to decrypt phishers - by Acekidd01 - 10-12-2009, 01:09 PM
RE: How to decrypt phishers - by Extasey - 11-03-2009, 04:10 AM
RE: How to decrypt phishers - by Acekidd01 - 11-03-2009, 07:48 AM
RE: How to decrypt phishers - by ßeowulf - 11-07-2009, 03:38 PM
RE: How to decrypt phishers - by Jake - 11-07-2009, 11:05 PM
RE: How to decrypt phishers - by Acekidd01 - 11-08-2009, 01:25 AM
RE: How to decrypt phishers - by Socrates - 11-09-2009, 07:18 AM
RE: How to decrypt phishers - by Acekidd01 - 11-12-2009, 08:26 PM
RE: How to decrypt phishers - by Trojan - 11-17-2009, 04:20 PM
RE: How to decrypt phishers - by Guerreiro - 11-20-2009, 07:03 AM
RE: How to decrypt phishers - by Sagittarius - 12-14-2009, 06:07 AM
RE: How to decrypt phishers - by p1g 0wnz - 12-30-2009, 05:13 AM
RE: How to decrypt phishers - by --([-S7N-])-- - 04-11-2010, 08:53 AM
RE: How to decrypt phishers - by HCrew - 04-06-2011, 06:41 AM
RE: How to decrypt phishers - by Š Λ☨∀И - 04-06-2011, 11:01 AM
RE: How to decrypt phishers - by Scalise - 04-06-2011, 11:31 AM
RE: How to decrypt phishers - by prince of persia - 04-11-2011, 03:10 PM
RE: How to decrypt phishers - by Acekidd01 - 04-16-2011, 01:35 AM
RE: How to decrypt phishers - by Resistance - 04-16-2011, 08:38 AM
RE: How to decrypt phishers - by Mammoth - 04-18-2011, 07:45 AM
RE: How to decrypt phishers - by Griffin - 04-18-2011, 08:55 PM
RE: How to decrypt phishers - by aggouras - 04-19-2011, 12:41 PM
RE: How to decrypt phishers - by ReactioNz - 04-24-2011, 02:16 PM
RE: How to decrypt phishers - by harris21 - 04-25-2011, 08:34 AM
RE: How to decrypt phishers - by Xenomorph - 04-26-2011, 05:39 PM
RE: How to decrypt phishers - by rootkit - 04-27-2011, 11:08 AM
RE: How to decrypt phishers - by Quintus - 04-29-2011, 03:53 AM
RE: How to decrypt phishers - by Extornia - 04-30-2011, 06:53 PM
RE: How to decrypt phishers - by tomamaer - 05-31-2011, 11:59 PM
RE: How to decrypt phishers - by shopping - 06-01-2011, 04:40 AM
RE: How to decrypt phishers - by !LoL - 06-01-2011, 04:40 AM
RE: How to decrypt phishers - by Filefinder - 06-01-2011, 04:52 PM
RE: How to decrypt phishers - by Black Demon - 06-07-2011, 01:03 AM
RE: How to decrypt phishers - by Zumog - 06-08-2011, 02:07 PM
RE: How to decrypt phishers - by -Dreams - 06-13-2011, 11:53 PM
RE: How to decrypt phishers - by ๖ۣۜDunsparth - 06-14-2011, 12:15 AM
RE: How to decrypt phishers - by -Dreams - 06-14-2011, 01:40 AM
RE: How to decrypt phishers - by sockatobi - 06-22-2011, 12:01 PM
RE: How to decrypt phishers - by etcBro - 06-22-2011, 04:12 PM
RE: How to decrypt phishers - by Scream - 08-13-2011, 08:24 AM
RE: How to decrypt phishers - by SuperBass - 09-30-2011, 09:30 PM
RE: How to decrypt phishers - by Digital-Punk - 10-12-2011, 07:13 PM
RE: How to decrypt phishers - by New Jersey - 11-27-2011, 09:25 AM
RE: How to decrypt phishers - by iMoney - 11-27-2011, 10:55 AM

Possibly Related Threads…
Thread Author Replies Views Last Post
  Guide: Be Aware From Phishers Liberty 0 937 10-08-2009, 07:11 PM
Last Post: Liberty

Forum Jump:


Users browsing this thread: 1 Guest(s)