/DotNET_XorCryptor

A new simple and powerfull packer for malware

Primary LanguageVisual Basic .NETMIT LicenseMIT

DotNET XorCryptor

This is a .NET executable packer with payload encryption. Use for educational purposes only.

How to use?

  • --file {path} - specify file name
  • --flood - add junk classes to file
  • --proxy - move original entry point to from Main()

For example:

xor-pack.exe --file "stub.exe" --proxy --flood

For enhanced effectiveness, it is strongly recommended to heavily obfuscate the assembly before applying the encryption process.