45.88.3.236 - Hcrypt Service

Introduction: Crypters are tools used by skids / scammers for make their program undetectable. The crypters can encrypt, obfuscate, and manipulate malware. The Crypter-as-a-Service (COS) is used to deploy RATS (Revenge RAT, Agent Tesla, AsyncRAT, and NetWire RAT) payloads on compromised systems.

[color=#FF00]Link (Dangerous): [/color] http://45.88.3.236
image

Virustotal Samples:
https://www.virustotal.com/gui/file/6f35ab9d6aed8b8df1754149da79be5cdadae7b5366e8f2be46d9370f7e920c0/relations
https://www.virustotal.com/gui/file/1aae4a0ee3da930c656e21a78157065ee57337828611b33ee39ca924e8c8ccfe

Example Crypter Obfuscation Message:


Now Source of COS (45.88.3.236):


Server.txt

Random.vbs

PS1.txt

HHA.HTA

1 Like

AsyncRAT:


Understable Text: (Simple Deobfuscation)

1 Like

Nice post, thanks :slight_smile: