ROUSH - DROPPER IN MEMORY | FUD WD | NATIVE x86 x64 | SCAN 0/26 RUN 0-2/18

roush

Member
Messages
2
Reaction score
0
Points
1
Support:
┏ Native .exe [x64 / x86 (x32)]
┣ Output extensions .exe/.msi
┣ Weight without pump (clean stub dropper): 40 KB – 500 KB
┗ Full compatibility with Windows 10–11 (x86 / x64) (not tested on 8 and below, test+adaptation possible on demand)

Operating principle:
Loading and running exclusively in memory (no drop to disk) (single thread)
Each build is completely unique, exclusively privately for the customer
┣ Standard package "AntiVM and AntiDebug"
┣ Possibility of gluing with legitimate applications, or a suit installer
No PE crypto required, quick replacement of payload without replacing the dropper

Works with dll sideload (bypass smartscreen)

Additional options are possible. Parameters/modifications (for example: self-delete, post/get requests to your API, additional stream, etc.)

Cost from $ 250 - varies depending on your technical tasks. Available depending on the subscription format.
WD FUD guarantee - 24 hours from the moment of receiving the file, if during this time WD began to detect - a free replacement or refund.
Average order fulfillment time is 60 minutes.

Each issued file is run through a live, up-to-date Windows Defender 10/11 + avsense before sending.
Mandatory check for knocking (no risk of leakage).

Permanent anti-RU module: Protection against knocking on RU regions.
+ Forum Escrow

Loyalty system for regular customers:

Permanent discount on all service products 10% / 20% when buying 10 / 20 files.
And also, a permanent promotion 1 + 1 = 3 - buy two identical tariffs, you get the third one for free!

Terms of Service: By submitting a service request, you agree to the terms of service. The product provided must be tested by the customer before use. Untested use voids the warranty. Distribution of the product to platforms such as Virus Total and others will result in blocking within the service and denial of refunds. The file provided must not contain any third-party modifications or cryptography, and must be verified for functionality. Failure to comply with these terms will result in a refund or replacement being denied.

Current contact on Telegram: @roush_file
 
Top