CFS - CRYPT FILE SERVICE x DSAS by INJECT [Labs]
Open in Telegram
No data
Subscribers
-524 hours
+47 days
+6530 days
Data loading in progress...
Similar Channels
Tags Cloud
Incoming and Outgoing Mentions
---
---
---
---
---
---
Attracting Subscribers
April '25
April '25
+1 290
in 0 channels
March '25
+123
in 0 channels
Get PRO
February '25
+44
in 0 channels
Get PRO
January '25
+58
in 0 channels
Get PRO
December '24
+51
in 1 channels
Get PRO
November '24
+61
in 1 channels
Get PRO
October '24
+44
in 1 channels
Get PRO
September '24
+154
in 2 channels
Get PRO
August '24
+182
in 1 channels
| Date | Subscriber Growth | Mentions | Channels | |
| 14 April | 0 | |||
| 13 April | 0 | |||
| 12 April | +1 271 | |||
| 11 April | +1 | |||
| 10 April | 0 | |||
| 09 April | +2 | |||
| 08 April | +6 | |||
| 07 April | +4 | |||
| 06 April | +1 | |||
| 05 April | +2 | |||
| 04 April | +1 | |||
| 03 April | +1 | |||
| 02 April | +1 | |||
| 01 April | 0 |
Channel Posts
We are pleased to present a new section «Dungeon» on our Discord channel!
▪️Now you can access our top courses, such as "Kill AV/EDR", a detailed guide to circumventing antivirus systems and end device protection (EDR), as well as "OPSEC", a complete course on operational security, where we understand how to protect your actions and remain invisible in the digital world.. In addition to these flagship programs, we have added other useful materials to help you deepen your knowledge and skills.
➖All this is available with a monthly subscription to the channel! You will receive content in two formats: detailed text instructions for those who like to delve into details, and dynamic video tutorials for visual mastering of the material.
| 2 | Dropper + Kill any AV - EDR's from USER PRIVILAGE ! Crowdstrike, SentinelOne + LSSAS Exploit | 195 |
| 3 | Fix high entropy
We are correcting the high entropy that gives additional static detectors of AV, your packaged software, using C++20 metaprogramming.
#include <stdio.h>
// We dilute the .data section with zeros
template<unsigned int N, typename T, T value>
struct E {
constexpr E() : array() {
for (unsigned int i = 0; i < N; i++) {
array[i] = (T)value;
}
}
T array[N];
};
#pragma code_seg(".text")
__declspec(allocate(".text"))
constexpr auto e = E<2500, long long, 1>();
#pragma code_seg(".data")
__declspec(allocate(".data"))
constexpr auto e2 = E<2500, long long, 1>();
int main() {
int total = 0;
for (auto x : e.array)
total += x;
for (auto x : e2.array)
total += x;
return total;
} | 210 |
| 4 | DarwinOps - Already available on CFS platform. [Not sale, as a service]
DarwinOps help RedTeams targeting Mac OS platforms. DarwinOps is a Mac OS equivalent to MacroPack Pro and also includes post exploitation options.
➖Turnkey Scenarios
▪️Command execution
▪️Run shellcode from a binary
▪️Download and execute payload
▪️Download and load JXA
▪️Drop and run embedded payload
▪️Target enumeration
➖Supported Payloads
▪️Malicious App
▪️JavaScript file
▪️Shell script
▪️Visual Studio Code extension
▪️Package File
▪️Dynamic Library
▪️Mach-O Binary
▪️Disk Images, ISO volume, zip, 7zip, etc.
▪️HTML smuggling
➖Security Bypass
▪️EDR Bypass Profiles
▪️Several Code Obfuscation
▪️Run payloads from memory
▪️GateKeeper Bypass Tips
▪️Social Engineering tricks
▪️Anti sandbox and anti reverse engineering
▪️Private Evasion Methods
▪️Privilege Elevation
▪️Persistence Methodes | 178 |
| 5 | MacroPack Pro - Already available on CFS platform. [Not sale, as a service]
MacroPack Pro is a Swiss-army knife for initial vector generation. It helps Red Teams automate, weaponize and deliver payloads while offering robust defense bypass techniques.
MacroPack Pro supports the latest trend in payload generation such as LNK, URL, ClickOnce, HTML smuggling. It can be used to generate or trojan classic Office formats (Word, Excel, PowerPoint, Publisher, OneNote, Visio, MS Project). If you are looking at Office alternatives, use MacroPack to generate scripts such as HTA, WSF, SCT, VBS, MSI, etc.
➖Turnkey Templates
▪️Command execution
▪️Run shellcode from current process (including stageless shellcodes)
▪️Inject shellcode in process
▪️Download and execute exe, dll, or script
▪️Download and load XSL
▪️Drop and run embedded exe, dll, or script
▪️Target enumeration
▪️Empire/PowerShell stager
▪️DotNET weaponization/Obfuscation
➖Supported Payloads
▪️Popular: LNK, Clickonce,
▪️Scripts: BAT, VBS, HTA, SCT, WSF, XSL
▪️Office: Word, Excel, PowerPoint, ▪️Publisher, OneNote
▪️MS Project & Visio
▪️MSI Installers
▪️Compiled help files (CHM)
▪️Visual Studio Project
▪️Misc: URL, INF, IQY, SLK, Excel 4.0 , etc.
▪️Containers such as ISO volume, zip, 7zip, etc.
▪️HTML smuggling
➖Security Bypass
▪️AV/EDR Bypass tested during real operations
▪️VBA, VBS, and command line obfuscation
▪️Self decode in memory
▪️Run payloads from memory
▪️Multiple AMSI bypass
▪️Social Engineering tricks
▪️Anti sandbox and anti reverse engineering
▪️ASR bypass
▪️Multiple UAC bypass
▪️XLM injection | 157 |
| 6 | Another smartass. Check our contacts on the website or channel! Before you write to us. | 162 |
| 7 | We would also like to tell you what software you can purchase in our service.
- CORE IMPACT v21.6 - 3800💵
- METASPLOIT PRO - 2200💵
- SHELLTER PRO v10 - 5400💵
- EXPLOIT PACK PRO v18.04 - 3000💵
- NIGHTHAWK v0.3 - 16000💵
- BRUTE RATEL v2.1.2 - 4500💵
- NESSUS (Expert/Professional) - 3000💵
- CHECKMARX [CxCodebashing / CxIAST / CxOSA] - 1500💵
- COBALT-STRIKE 4.9.1 [ modify ARSENAL KIT + Bypass AV/EDR BOX ] - 4000💵
- COBALT-STRIKE 4.11 (LATEST) + Arsenal Kit
( Available
Self-Written Cobalt Strike Artifacts.
- x86/64,
- .exe/dll,
- Custom syscall gate, asm stabs,
- Inject.
4500💵
When used correctly - FUD for more than six months without cleaning )
🙎🏻♂️ Contacts:
▫️Telegram: https://t.me/Evi1Grey5
Telegram channel: https://t.me/injectcrypt
▪️Website: injectexp.dev
▪️Forum: pro.injectexp.dev
▪️Email: injectexpdev@proton.me
▫️Tox: 340EF1DCEEC5B395B9B45963F945C00238ADDEAC87C117F64F46206911474C61981D96420B72
▫️Session: 0581af1f006c3eb8d735046e515c9a9ffd3a1caf37eae5852f8184e6c439bada31 | 185 |
| 8 | 🆕 Added for Cobalt-Strike;
▪️.NET Runtime for BOFS (beacon object files)
▪️ Bloated Exe > LNK (AV/EDR does not transfer such a large file to the cloud for further scanning and does not scan it)
▪️Persistence Kit (cna || exe)
▪️Azure C2 Redirector
▪️Official Kit + Self-written
▪️Mutator Kit
▪️Updated the Dockerfile to use alpine version 3.19, which is the latest version supporting LLVM and CLANG version 14.
▪️Updated mutator scripts to reference the current release (4.10) of the sleepmask source code.
▪️Fixed an issue when running with WSL on Windows when the pathname has a space character.
▪️User Defined Reflective Loader for Visual Studio (UDRL-VS) Kit
▪️Added the extc2-loader example to go along with this Cobalt Strike blog post.
▪️Sleep Mask Kit
▪️Added the -fno-jump-tables to the sleepmask build.sh script to fix bug when compiling the sleepmask with certain versions of mingw
➖Profiles
▪️Google API Profile (1300+ lines)
▪️Memory Evasion Profile (500+ lines)
▪️Other Things Included / Misc
▪️Headless Script
▪️Modify The beacon in runtime
request implementation | 308 |
| 9 | Price until the end of the month 2000💵For Cobalt Strike Artifacts + update. | 332 |
| 10 | Using C# Tools as If Defender Doesn't Exist CFS | 323 |
| 11 | Mimikatz Bypasses Windows Defender Easily CSF | 319 |
| 12 | Update CFS
▪️Added Bypass New Killer - Chinees AV Guanjia
▪️Added Bypass New Killer - Chinees AV 360 Total Security
▪️Added Bypass New Killer - Chinese AV Cynet
▪️Added Bypass New Killer- Chinese AV F-Secure | 303 |
| 13 | Cobalt Strike Beacon Bypasses SentinelOneEDR smoothly - Make your beacon like a Ninja (Note: Connection took a bit because of sleep) | 309 |
| 14 | Commercial Penetration Testing Tool - Immunity CANVAS (Latest - Cracked)
▫️Features:
▪️Extensive Exploit Library: it includes over 800 different exploits targeting a wide array of vulnerabilities.
▪️Automated Exploitation: Streamlines the testing and attack simulation process.
▪️Dynamic Shellcode Generator (Mosdef): Enables shellcode (built-in) modifications.
▪️Cross-Platform: Works on Linux, Windows, and MacOS environments.
▪️Red Team Collaboration: Supports coordinated attack simulations for team operations.
▪️Diverse-Exploits: Exploits on Windows or Linux, and to some extent - even Android, MacoOS and SCADA Systems
1250💵
Cracked! you don't have to worry about time or number of machines
NOTE: DOCUMENTATION IS PROVIDED! | 291 |
| 15 | Until the end of this month we will provide a 15% discount on AVAILABLE SOFTWARE
We would also like to tell you what software you can purchase in our service.
- CORE IMPACT v21.6 - 3800💵
- METASPLOIT PRO - 2200💵
- SHELLTER PRO v10 - 5400💵
- EXPLOIT PACK PRO v18.04 - 3000💵
- NIGHTHAWK v0.3 - 16000💵
- BRUTE RATEL v2.1.2 - 4500💵
- NESSUS (Expert/Professional) - 3000💵
- CHECKMARX [CxCodebashing / CxIAST / CxOSA] - 1500💵
- COBALT-STRIKE 4.9.1 [ modify ARSENAL KIT + Bypass AV/EDR BOX ] - 4000💵
- COBALT-STRIKE 4.11 (LATEST) + Arsenal Kit
( Available
Self-Written Cobalt Strike Artifacts.
- x86/64,
- .exe/dll,
- Custom syscall gate, asm stabs,
- Inject.
5000💵
When used correctly - FUD for more than six months without cleaning )
- Commercial Penetration Testing Tool - Immunity CANVAS (Latest - Cracked) 1250💵
🙎🏻♂️ Contacts:
▫️Telegram: https://t.me/Evi1Grey5
Telegram channel: https://t.me/injectcrypt
▪️Website: injectexp.dev
▪️Forum: pro.injectexp.dev
▪️Email: injectexpdev@proton.me
▫️Tox: 340EF1DCEEC5B395B9B45963F945C00238ADDEAC87C117F64F46206911474C61981D96420B72
▫️Session: 0581af1f006c3eb8d735046e515c9a9ffd3a1caf37eae5852f8184e6c439bada31 | 246 |
| 16 | Available for sale - License 3 months / 6 months / 1 year
https://telegra.ph/CFS---CRYPTER-03-23
🙎🏻♂️ Contacts:
▫️Telegram: https://t.me/Evi1Grey5
Telegram channel: https://t.me/injectcrypt
▪️Website: injectexp.dev
▪️Forum: pro.injectexp.dev
▪️Email: injectexpdev@proton.me
▫️Tox: 340EF1DCEEC5B395B9B45963F945C00238ADDEAC87C117F64F46206911474C61981D96420B72
▫️Session: 0581af1f006c3eb8d735046e515c9a9ffd3a1caf37eae5852f8184e6c439bada31 | 299 |
| 17 | Until the end of this month we will provide a 15% discount on AVAILABLE SOFTWARE. | 267 |
| 18 | +1 RCE MS Office.rar | 368 |
| 19 | # Detection, description of vulnerability FILE/HTML: * Office uses the IE browser engine by default, and for the sake of security, MS disabled everything possible: JS, IFRAME, Rederiks, plugins, etc. i.e. nothing can be done on the browser side, and nothing is executed, leaving pure HTML and displaying pictures. Oops... :-(
* Then we need to go beyond the work of the office in order to achieve our goal, but what will happen if when the office contacts our server, we perform manipulation on the server side? when opening a document, a request is made to the server, JS on the HTML page does not process, we will not be able to send the payload through the JNLP protocol in a way that JS does not redirect, redirection does not work with HTML either, because redirects are disabled on the browser side.
* Raising Node.js is not suitable either, then it comes to mind to raise a web server with ngnx+apache+php, create a php page, and write header in it ('location: path_to file'); but JS and IFRAME will still not be executed on it, so we get a simple redirection, because when there is a call to the php page, the server immediately redirected the browser/office to another page we need
* But if we specify that the redirect should be to an HTML page, then the JS will still not work and we will not be able to open the JNLP protocol to receive our payload.
* I understand Windows, go to “Options -> Select standard applications for file types”, look at file types, and find such an interesting file type as .htmed, not a single program is associated with it, this file type is present on windows 7/8.1/ 10/11 and server Windows
* I go to the web server, create saint_1869.htmed, open it for editing, write in it the code that makes up a standard HTML page, add “DriveUpdateWord” comments to this .htmed file, a total of 76 lines and comment and HTML tags, the total file size is 10 kb, total number of characters in file 101
* I am writing code in JS so that I can run my JNLP protocol: and always with https://domain.name/path_to_payload, I save the file that created .htmed
* I open the bitcoin.php file on the server, write in it the php code for redirecting to the saint_1869.htmed page, save it!
* I launch my created Word document .docx and the office browser redirection worked, redirected to the page saint_1869.htmed, the HTML and JS code was executed
* The Java Oracle JNLP protocol was launched, the payload was received, which was previously signed by me with a certificate, and Java Oracle executed it, the powershell code that was specified in the payload was executed, this code contained a powershell command to download the file from my server and run it on the computer | 304 |
| 20 | Forbidden
- Use in the former CIS countries is not allowed!
- Illegal use is your responsibility! At your own conscience, at your own risk. I am not responsible for this!!!
- For legal pentest!
Information
- The command is executed [cmd | powershell]
- Tested on stands with windows 7/8/10/11 update
- Office 2010, 2013, 2016, 2019, Office 365 without update and with update
- Triggering: will work by opening it in Word, there is also no need to open the file in Word, just go to the file and look at it in the preview panel. The preview pane will activate the external HTML payload and RCE will launch on your computer without any mouse clicks.
- For the payload to run, the “victim” must have Oracle Java JRE installed - >= 8
- For the payload and Powershell, the Office team contacts the web server, receives the payload via the JNLP: protocol, and then executes it; after executing the payload, it receives a file with your PS commands and will successfully execute them on the “victim” computer.
- After the payload has been successfully assembled on the web server, you will have a file in the form of a JAR, which needs to be signed with a certificate!
* To sign a file, you need to purchase a certificate or contact the services and get a subscription from them, a certificate is needed to sign applications and code!!! CodeSigning certificates such as Sectigo/Comodo Code Signing SSL, Sectigo/Comodo EV Code Signing SSL, etc. are suitable for this
- The “victim” must be allowed to execute powershell scripts, it can also be executed via cmd, it depends on what command you write in the payload.
- How to deliver a document: spam, websites, landing pages, and more at your discretion...
Equipment
- Python sources to generate the document, .htmed file to receive the payload, the required version of Java to install on the web server to collect the payload.
- java sources, + the required java version to install on your web server to generate jars
- a Powershell file that will be placed on your web server in which commands are written to be executed on the “victim” computer.
- Installation, configuration and assembly manual with commands to run everything.
Affected versions
| Operating system | Office | HTML Templates | Target | Delivery Method | Execution Method | Working |
|-------------------|-----------------------|-------------------------|-----------------|------------------|-----------------|
| Windows 11 |2010,2013,2016,2019,365| HTMED | WORD | DOCX |JS+JNLP+JAR+PS+cmd| YES |
| Windows 10 |2010,2013,2016,2019,365| HTMED | WORD | DOCX |JS+JNLP+JAR+PS+cmd| YES |
| Windows 8.1 |2010,2013,2016,2019,365| HTMED | WORD | DOCX |JS+JNLP+JAR+PS+cmd| YES |
| Windows 7 |2010,2013,2016,2019,365| HTMED | WORD | DOCX |JS+JNLP+JAR+PS+cmd| YES |
| | | | | | | |
| | | | | | | |
Prepare the document
- We create two identical types of .docx document, for this we wrote a program in Python, the 1st document to make a request to our server, for this we will use OLEobject, in it we will indicate to our link where the request will be executed?/!/ so that antiviruses do not They burned our document.
- The second one was created by hand, it uses AFCchunk in this document, we connect the first document that we generated, we get a document within a document, after such manipulations, one common document sends a request, and it can be viewed in the preview panel without even clicking on the mouse . | 228 |
