UNDERCODE COMMUNITY
2.67K subscribers
1.23K photos
31 videos
2.65K files
79.4K links
πŸ¦‘ Undercode Cyber World!
@UndercodeCommunity


1️⃣ World first platform which Collect & Analyzes every New hacking method.
+ AI Pratice
@Undercode_Testing

2️⃣ Cyber & Tech NEWS:
@Undercode_News

3️⃣ CVE @Daily_CVE

✨ Web & Services:
β†’ Undercode.help
Download Telegram
▁ β–‚ β–„ ο½•π•Ÿπ”»β’Ίπ«Δ†π”¬π““β“” β–„ β–‚ ▁

πŸ¦‘Online #Scanners and #Sandboxes topic

Web-based multi-AV scanners, and malware sandboxes for automated analysis.


[anlyz.io](https://sandbox.anlyz.io/) - Online sandbox.

any.run - Online interactive sandbox.

[AndroTotal](https://andrototal.org/) - Free online analysis of APKs
against multiple mobile antivirus apps.

AVCaesar - Malware.lu online scanner and
malware repository.

[BoomBox](https://github.com/nbeede/BoomBox) - Automatic deployment of Cuckoo
Sandbox malware lab using Packer and Vagrant.

Cryptam - Analyze suspicious office documents.

[Cuckoo Sandbox](https://cuckoosandbox.org/) - Open source, self hosted
sandbox and automated analysis system.

cuckoo-modified - Modified
version of Cuckoo Sandbox released under the GPL. Not merged upstream due to
legal concerns by the author.

[cuckoo-modified-api](https://github.com/keithjjones/cuckoo-modified-api) - A
Python API used to control a cuckoo-modified sandbox.

DeepViz - Multi-format file analyzer with
machine-learning classification.

[detux](https://github.com/detuxsandbox/detux/) - A sandbox developed to do
traffic analysis of Linux malwares and capturing IOCs.

DRAKVUF - Dynamic malware analysis

ENJOY β€οΈπŸ‘πŸ»
βœ…2020 GIT SOURCES
@UndercodeTesting
@UndercodeSecurity
@UndercodeHacking
▁ β–‚ β–„ ο½•π•Ÿπ”»β’Ίπ«Δ†π”¬π““β“” β–„ β–‚ ▁
▁ β–‚ β–„ ο½•π•Ÿπ”»β’Ίπ«Δ†π”¬π““β“” β–„ β–‚ ▁

πŸ¦‘#Domain Analysis Topic resources 2020

Inspect domains and IP addresses.


[AbuseIPDB](https://www.abuseipdb.com/) - AbuseIPDB is a project dedicated to helping combat the spread of hackers, spammers, and abusive activity on the internet.

badips.com - Community based IP blacklist service.

[boomerang](https://github.com/EmersonElectricCo/boomerang) - A tool designed for consistent and safe capture of off network web resources.

Cymon - Threat intelligence tracker, with IP/domain/hash search.

[Desenmascara.me](http://desenmascara.me) - One click tool to retrieve as much metadata as possible for a website and to assess its good standing.

Dig - Free online dig and other
network tools.

[dnstwist](https://github.com/elceef/dnstwist) - Domain name permutation
engine for detecting typo squatting, phishing and corporate espionage.

IPinfo - Gather information
about an IP or domain by searching online resources.


[mailchecker](https://github.com/FGRibreau/mailchecker) - Cross-language
temporary email detection library.

MaltegoVT - Maltego transform
for the VirusTotal API. Allows domain/IP research, and searching for file
hashes and scan reports.

[Multi rbl](http://multirbl.valli.org/) - Multiple DNS blacklist and forward
confirmed reverse DNS lookup over more than 300 RBLs.

NormShield Services - Free API Services
for detecting possible phishing domains, blacklisted ip addresses and breached
accounts.

[PhishStats](https://phishstats.info/) - Phishing Statistics with search for
IP, domain and website title

Spyse - subdomains, whois, realted domains, DNS, hosts AS, SSL/TLS info,

[SecurityTrails](https://securitytrails.com/) - Historical and current WHOIS,
historical and current DNS records, similar domains, certificate information
and other domain and IP related API and tools.

SpamCop - IP based spam block list.

[SpamHaus](https://www.spamhaus.org/lookup/) - Block list based on
domains and IPs.

Sucuri SiteCheck - Free Website Malware
and Security Scanner.

ENJOY β€οΈπŸ‘πŸ»
@UndercodeTesting
@UndercodeSecurity
@UndercodeHacking
▁ β–‚ β–„ ο½•π•Ÿπ”»β’Ίπ«Δ†π”¬π““β“” β–„ β–‚ ▁
▁ β–‚ β–„ ο½•π•Ÿπ”»β’Ίπ«Δ†π”¬π““β“” β–„ β–‚ ▁

πŸ¦‘File #Carving #Mlawares

 extracting files from inside disk and memory images.

[bulk_extractor](https://github.com/simsong/bulk_extractor) - Fast file
carving tool.

EVTXtract - Carve Windows
Event Log files from raw binary data.

[Foremost](http://foremost.sourceforge.net/) - File carving tool designed
by the US Air Force.

hachoir3 - Hachoir is a Python library
to view and edit a binary stream field by field.

[Scalpel](https://github.com/sleuthkit/scalpel) - Another data carving
tool.

SFlock - Nested archive
extraction/unpacking (used in Cuckoo Sandbox).

ENJOY β€οΈπŸ‘πŸ»
βœ…2020 GIT SOURCES
@UndercodeTesting
@UndercodeSecurity
@UndercodeHacking
▁ β–‚ β–„ ο½•π•Ÿπ”»β’Ίπ«Δ†π”¬π““β“” β–„ β–‚ ▁
▁ β–‚ β–„ ο½•π•Ÿπ”»β’Ίπ«Δ†π”¬π““β“” β–„ β–‚ ▁

πŸ¦‘WHEN SANDBOX BECOME A MALWARE ?
#FastTip

Nearly every malware analysis sandbox looks at the system call interface or the Windows API when monitoring the behavior of a user mode process. ...

> In other words, a sandbox may see a malware read from a script, but it can not tell how the malware actually handles the data.

@UndercodeSecurity
@UndercodeHacking
▁ β–‚ β–„ ο½•π•Ÿπ”»β’Ίπ«Δ†π”¬π““β“” β–„ β–‚ ▁
▁ β–‚ β–„ ο½•π•Ÿπ”»β’Ίπ«Δ†π”¬π““β“” β–„ β–‚ ▁

πŸ¦‘Essential malware analysis reading material #resources
#Malware/

[Learning Malware Analysis](
https://www.packtpub.com/networking-and-servers/learning-malware-analysis) - Learning Malware Analysis: Explore the concepts, tools, and techniques to analuze and investigate Windows malware

Mastering Malware Analysis - Mastering Malware Analysis: The complete malware analyst's guide to combating malicious software, APT, cybercime, and IoT attacks

[Mastering Reverse Engineering](https://www.packtpub.com/networking-and-servers/mastering-reverse-engineering) - Mastering Reverse Engineering: Re-engineer your ethical hacking skills

Practical Malware Analysis - The Hands-On
Guide to Dissecting Malicious Software.

[Practical Reverse Engineering](https://www.amzn.com/dp/1118787315/) -
Intermediate Reverse Engineering.

Real Digital Forensics - Computer
Security and Incident Response.

[Rootkits and Bootkits](https://www.amazon.com/dp/1593277164) - Rootkits and Bootkits: Reversing Modern Malware and Next Generation Threats

The Art of Memory Forensics - Detecting
Malware and Threats in Windows, Linux, and Mac Memory.

[The IDA Pro Book](https://amzn.com/dp/1593272898) - The Unofficial Guide
to the World's Most Popular Disassembler.

The Rootkit Arsenal - The Rootkit Arsenal:
Escape and Evasion in the Dark Corners of the System




ENJOY β€οΈπŸ‘πŸ»
βœ…2020 GIT SOURCES
@UndercodeTesting
@UndercodeSecurity
@UndercodeHacking
▁ β–‚ β–„ ο½•π•Ÿπ”»β’Ίπ«Δ†π”¬π““β“” β–„ β–‚ ▁
▁ β–‚ β–„ ο½•π•Ÿπ”»β’Ίπ«Δ†π”¬π““β“” β–„ β–‚ ▁

πŸ¦‘ #Awesome repo Lists new :


[Android Security](https://github.com/ashishb/android-security-awesome)

AppSec

[CTFs](https://github.com/apsdehal/awesome-ctf)

Forensics

["Hacking"](https://github.com/carpedm20/awesome-hacking)

Honeypots

[Industrial Control System Security](https://github.com/hslatman/
awesome-industrial-control-system-security)

Incident-Response

[Infosec](https://github.com/onlurking/awesome-infosec)

PCAP Tools

[Pentesting](https://github.com/enaqx/awesome-pentest)

Security

[Threat Intelligence](https://github.com/hslatman/awesome-threat-
intelligence)

YARA

ENJOY β€οΈπŸ‘πŸ»
βœ…2020 GIT SOURCES
@UndercodeTesting
@UndercodeSecurity
@UndercodeHacking
▁ β–‚ β–„ ο½•π•Ÿπ”»β’Ίπ«Δ†π”¬π““β“” β–„ β–‚ ▁
πŸ¦‘Bin For Spotify 3 Months Premium + ATRESplayer Premium

BIN: 5183024500xxxxxx
DATE: Rnd
CVV: Rnd
IP: USA πŸ‡ΊπŸ‡Έ

βœ…Spotify
βœ…AteresPlayer

How use bin https://t.me/UnderCodeTesting/3768
Written pdfs tutorials
▁ β–‚ β–„ ο½•π•Ÿπ”»β’Ίπ«Δ†π”¬π““β“” β–„ β–‚ ▁

πŸ¦‘MALWARE RESOURCES :


* [SMRT](https://github.com/pidydx/SMRT) - Sublime Malware Research Tool, a
plugin for Sublime 3 to aid with malware analyis.

* [strace](https://sourceforge.net/projects/strace/) - Dynamic analysis for

* [StringSifter](https://github.com/fireeye/stringsifter) - A machine learning tool
that automatically ranks strings based on their relevance for malware analysis.

* [Triton](https://triton.quarkslab.com/) - A dynamic binary analysis (DBA) framework.

* [Udis86](https://github.com/vmt/udis86) - Disassembler library and tool
for x86 and x86_64.

* [Vivisect](https://github.com/vivisect/vivisect) - Python tool for
malware analysis.

* [WinDbg](https://developer.microsoft.com/en-us/windows/hardware/download-windbg) - multipurpose debugger for the Microsoft Windows computer operating system, used to debug user mode applications, device drivers, and the kernel-mode memory dumps.

* [X64dbg](https://github.com/x64dbg/) - An open-source x64/x32 debugger for windows.

* [iocextract](https://github.com/InQuest/python-iocextract) - Advanced Indicator
of Compromise (IOC) extractor, Python library and command-line tool.

βœ…2020 GIT SOURCES
@UndercodeTesting
@UndercodeSecurity
@UndercodeHacking
▁ β–‚ β–„ ο½•π•Ÿπ”»β’Ίπ«Δ†π”¬π““β“” β–„ β–‚ ▁
▁ β–‚ β–„ ο½•π•Ÿπ”»β’Ίπ«Δ†π”¬π““β“” β–„ β–‚ ▁

πŸ¦‘helpfull termux tool :

FEATURES :

>Grabb email passwords NEW!
>Check passwords leaked.
>Check hash code leaked.
>Check email leaked!

πŸ„ΈπŸ„½πŸ…‚πŸ…ƒπŸ„°πŸ„»πŸ„»πŸ„ΈπŸ…‚πŸ„°πŸ…ƒπŸ„ΈπŸ„ΎπŸ„½ & πŸ…πŸ…„πŸ„½ :

1️⃣sudo apt update && sudo apt install python3 python3-pip

2️⃣git clone https://github.com/GitHackTools/Leaked

3️⃣cd Leaked

4️⃣bash install_update.sh

5️⃣python3 leaked.py

6️⃣CHOOSE OPTIONS VIA NUMBER SIMPLY

@UndercodeTesting
@UndercodeSecurity
@UndercodeHacking
▁ β–‚ β–„ ο½•π•Ÿπ”»β’Ίπ«Δ†π”¬π““β“” β–„ β–‚ ▁
Russian CARDING -ENGLISH COMPLET- pdf
Enjoy β€οΈπŸ‘πŸ»
▁ β–‚ β–„ ο½•π•Ÿπ”»β’Ίπ«Δ†π”¬π““β“” β–„ β–‚ ▁

πŸ¦‘Apache Log Modules
Apache has several modules that are responsible for weblogs:

1️⃣mod_log_config . Keeps a log of requests made to the server. This is the main module, which is enabled by default, and it is he who saves information about requests. Basically, here we will consider this particular module and its settings. Provides access log operation .

2️⃣mod_log_debug . Additional custom debug logs. Enables Additional configurable debug logging. It has an experimental status.

3️⃣mod_log_forensic . Forensic registration of server requests. Provides Forensic (forensic logs).

4️⃣mod_logio . Registration of input and output bytes of each request. This module must be included in the Apache configuration if you want to log information about the amount of data transferred and / or received. Provides some of the features of the Access Log format (access log).

5️⃣Apache Core Features - The main Apache HTTP Server features that are always available. It also provides the operation of Error Log and Per-module logging .

6️⃣mod_cgi and mod_cgid . Provides the work of the CGI Script Execution Log.

Written by Undercode
▁ β–‚ β–„ ο½•π•Ÿπ”»β’Ίπ«Δ†π”¬π““β“” β–„ β–‚ ▁
▁ β–‚ β–„ ο½•π•Ÿπ”»β’Ίπ«Δ†π”¬π““β“” β–„ β–‚ ▁

πŸ¦‘2020 BRUTEFORCE RDP BEST METHODE USING
HYDRA THE FAMOUS TOOL- RUSSIAN CODE
Script for automatic scanning of the address list for the presence of open 3389 ports, and then selecting the method and starting busting pair login / password.

πŸ„ΈπŸ„½πŸ…‚πŸ…ƒπŸ„°πŸ„»πŸ„»πŸ„ΈπŸ…‚πŸ„°πŸ…ƒπŸ„ΈπŸ„ΎπŸ„½ & πŸ…πŸ…„πŸ„½ :

1️⃣git clone https://github.com/getdrive/Lazy-RDP

2️⃣cd Lazy-RDP && chmod +x hydra/configure hydra/hydra src/rdp_brute.sh patator.py start INSTALL

3️⃣Installing dependencies

  ./INSTALL

4️⃣Running the script

./start

πŸ¦‘Tested On :

-Kali

-Parrot

-Debian 10/9

- work's for ubuntu Systems

πŸ¦‘VIDEO TUTORIAL (BRUTEFORCE RDP)

https://www.youtube.com/watch?v=Kpl8l6YQq48&feature=youtu.be


ENJOY β€οΈπŸ‘πŸ»

βœ…2020 GIT SOURCES
@UndercodeTesting
@UndercodeSecurity
@UndercodeHacking
▁ β–‚ β–„ ο½•π•Ÿπ”»β’Ίπ«Δ†π”¬π““β“” β–„ β–‚ ▁
▁ β–‚ β–„ ο½•π•Ÿπ”»β’Ίπ«Δ†π”¬π““β“” β–„ β–‚ ▁

πŸ¦‘How to change x11vnc options without restarting the service ??


> The x11vnc service can be controlled remotely, for example, terminate its work or change options on the fly. To do this, use the same command that runs the VNC server, that is, x11vnc with the -remote option . This option has two aliases: -R and -r

The list of supported commands is large, let's consider only a few examples:

To install an already running VNC server, use any of the following commands:

1️⃣x11vnc -remote stop<font></font>
x11vnc -R stop

2️⃣To enable shared connections:

x11vnc -R shared

3️⃣The following command will scale the desktop:

x11vnc -R scale:3/4

πŸ¦‘The command to allow connections if the VNC server was started with the -deny_all option :


1️⃣ x11vnc -remote nodeny
To run a sequence of commands, use something like this:

2️⃣x11vnc -R 'script:
To read commands from a file, use:


x11vnc -R script:file...

3️⃣A file can consist of several lines and use the ' # ' symbol for commenting. In any case, you need to use split ' ; 'to separate each team.

written by Undercode
▁ β–‚ β–„ ο½•π•Ÿπ”»β’Ίπ«Δ†π”¬π““β“” β–„ β–‚ ▁