-
Notifications
You must be signed in to change notification settings - Fork 56
Home
Welcome to the UnamDownloader wiki!
Here I will write explanations for all the features and give examples on how to use them. I will also strive to answer the most frequently asked questions so that there is fast and easy access to information otherwise usually gained by experience.
I will write everything on a single page instead of multiple pages for a more portable navigation experience. As always you can utilize tools such as CTRL+F or the sidebar navigation menu to quickly try and find the information you're looking for.
Navigation Menu |
---|
Downloader Features |
FAQ |
This is where all the files it will download and execute (if chosen to do so) are listed. You can add new ones, edit the ones already there or remove them as well.
The type of file it should build, there are currently two available: Native (coded in C) or Managed (coded in .NET C#).
Native: Compiled directly into machine code, meaning antiviruses will have a harder time detecting it since they cannot read the code itself. Compiling it as native will also make it runnable on nearly all computers.
Managed: Compiled as a managed program meaning that the program itself is run by the .NET Framework, antiviruses can technically read the code directly (though it can be made more difficulty by obfuscators) so there will always be more detections. Running the program will require at least .NET Framework 4.0 (which comes preinstalled with Windows). Building it as native does not support adding an icon or assembly directly in the builder, though you can probably use resource hackers online to add them if you want that.
Will display a fake error with the text that you enter when the file is started. Only supports ASCII (Latin1/ISO 8859-1) characters.
Will pause the file for the amount of seconds chosen before downloading and executing (if chosen) the files, can bypass Windows Defender sandboxing among others.
Whether the program should be compiled to be run with administrator privileges, this is required for the "Add Windows Defender exclusions" option.
Will add exclusions to the following locations: %UserProfile%, %AppData%, %Temp% and %SystemRoot% before any files are downloaded. This means that if this option is enabled then any files downloaded should not be detected by Windows Defender.
The filename that the file will be dropped with, should include the extension the file should have, like .exe, .txt, .jpg or whatever type of file it is.
The URL it should download the file from, this URL should be a direct download link, meaning a link that when you visit it then it will instantly try to download it (on browsers it usually asks for where to save it).
The location it should drop the downloaded file in.
Whether it should execute the downloaded file after it's been dropped to it's location.
These options can be used when building the file as a managed file. These are pretty self explanatory and won't require much explanation, the "Icon" option is the icon that the file will have and the "Assembly" option is the assembly information that will be used by Windows when displaying the program in different places and can also be seen when right-clicking the file and checking its properties.
If you built it as native file then you should be able to use any crypter, though currently it should be undetected without using any crypters. If you have experience with C then you can probably also change the around the Program.c file to reduce detections.
If you built it as a managed file then you can use an obfuscator or crypter that supports .NET files, you can find a list for obfuscators here: https://github.com/NotPrab/.NET-Obfuscator.