84 Commits
Author SHA1 Message Date
Kurosh Dabbagh Escalante e238146cf7 Version 2.0.0 (#6)
* Setup script and other small changes

* Changes to make the setup.ps1 script work properly

* Update README.md

* Update README.md

* Update README.md

* Some code improvements

* Update README.md

* C&C features removed; ETW patch and DInvoke added.

In the C&C Python console the options execute, downexec and copy have been removed.
In the C# agent, ETW is now patched before setting up the reverse connection and the DInvoke technique (check out SharpSploit!) is being used to replace some PInvoke calls.
DInvoke removes IAT Win32 API entries and also avoids EDR API hooking by  manually loading and mapping the required modules.

* Some minor changes

* PInvoke removed.

* DInvoke implemented and some other minor changes

* Processess listing improved

* Strings encoded using base64

* AMSI patching added.

* LdrLoadDll hooking added to deny undesired DLLs (like EDR's) in our process.

This will protect our malware from some EDR dll injections. Since the hooking is using DInvoke and manual module mapping its a bit slow, which may give enough time to the EDRs to load their Dlls in our process in some cases.

* Update Controller.cs

* LdrLoadDll hooking removed temporally. Great fixes on GetSystem and EnablePrivileges.

* Basic sandbox detection added.

* RWX memory protection removed from direct syscalls shellcode allocating. and others

* Update README.md

* Update README.md

* update images

* Update README.md
2020-08-25 18:09:50 +02:00
Kurosh Dabbagh Escalante 2ec3eb728d Pinvoke removed. DInvoke added to evade all usermode API hooks in those cases where direct syscalls weren't possible. ETW and AMSI patching added. (#5)
* Setup script and other small changes

* Changes to make the setup.ps1 script work properly

* Update README.md

* Update README.md

* Update README.md

* Some code improvements

* Update README.md

* C&C features removed; ETW patch and DInvoke added.

In the C&C Python console the options execute, downexec and copy have been removed.
In the C# agent, ETW is now patched before setting up the reverse connection and the DInvoke technique (check out SharpSploit!) is being used to replace some PInvoke calls.
DInvoke removes IAT Win32 API entries and also avoids EDR API hooking by  manually loading and mapping the required modules.

* Some minor changes

* PInvoke removed.

* DInvoke implemented and some other minor changes

* Processess listing improved

* Strings encoded using base64

* AMSI patching added.
2020-08-12 17:04:14 +02:00
Kurosh Dabbagh Escalante 066963c61e Setup script ready and some other minor changes (#3)
* Setup script and other small changes

* Changes to make the setup.ps1 script work properly

* Update README.md

* Update README.md

* Update README.md

* Some code improvements

* Update README.md
2020-07-12 13:53:00 +02:00
Kurosh Dabbagh Escalante feb99e1e4b Update README.md 2020-03-15 23:50:18 +01:00
Kurosh Dabbagh Escalante 1921e13193 Delete BITSReference4_0.dll 2020-03-14 15:27:57 +01:00
Kurosh Dabbagh Escalante c196ca3b07 Fixing dependencies to make the tool work in old Windows OS versions. 2020-03-14 15:27:41 +01:00
Kurosh Dabbagh Escalante e37e188238 Fixing dependencies to make the tool work in old Windows OS versions. 2020-03-14 15:27:12 +01:00
Kurosh Dabbagh Escalante 9a21f8920c Fixing dependencies to make the tool work in old Windows OS versions.
BITS 4.0 has been replaced with BITS 2.5 version in order to ensure compatibility with old Windows operative system builds.
2020-03-14 15:26:36 +01:00
Kurosh Dabbagh Escalante 74bfea9fdd Update README.md 2020-02-22 21:37:52 +01:00
Kurosh Dabbagh Escalante d96b663da5 GetSystem improved to avoid AV detection
Since named pipes impersonation is one of the Meterpreter's default getsystem methods, a lot of AV systems are aware of this technique and they tag it as malicious as soon as you try to use it. In order to avoid AV detection, the GetSystem functionality will try to impersonate a System process's access token and only if that fails it will use the old named pipes impersonation method.
2020-02-22 21:37:18 +01:00
Kurosh Dabbagh Escalante 1b11866244 Add files via upload 2020-02-22 21:34:12 +01:00
Kurosh Dabbagh Escalante 9b98f74a3d Add files via upload 2020-02-22 21:33:52 +01:00
Kurosh Dabbagh Escalante 30435a17ea Update README.md 2020-02-10 21:26:37 +01:00
Kurosh Dabbagh Escalante b9629a93b5 Update LauncherPE.cs 2020-02-08 14:41:11 +01:00
Kurosh Dabbagh Escalante 969b981ca7 Reflective .exe injection added. 2020-02-08 13:20:56 +01:00
Kurosh Dabbagh Escalante ca3d69edd4 Reflective .exe injection added. 2020-02-08 13:13:35 +01:00
Kurosh Dabbagh Escalante 77e6f3a170 Reflective .exe injection added.
Now the inject functionaly also allows to reflectively inject .NET assemblies in exe format.
The .NET assemblies injection functionality has been improved to support different scenarios.
2020-02-08 13:11:26 +01:00
Kurosh Dabbagh Escalante 4fb3db91f3 Reflective .exe injection added.
Now the inject functionaly also allows to reflectively inject .NET assemblies in exe format.
The .NET assemblies injection functionality has been improved to support different scenarios.
2020-02-08 13:06:56 +01:00
Kurosh Dabbagh Escalante 5b7a48adb5 Reflective .exe injection added. 2020-02-08 13:04:56 +01:00
Kurosh Dabbagh Escalante dd50798e8c Fixing missing dependencies. 2020-02-02 23:29:15 +01:00
Kurosh Dabbagh Escalante 056d25c554 Fixing missing dependencies. 2020-02-02 23:28:19 +01:00
Kurosh Dabbagh Escalante 9c1a9106fd Added syscall for OpenProcess 2020-02-02 20:03:48 +01:00
Kurosh Dabbagh Escalante 4c81e9c401 Added syscall for OpenProcess 2020-02-02 20:02:54 +01:00
Kurosh Dabbagh Escalante 41e8fbabae Delete Utils.cs 2020-02-02 20:02:28 +01:00
Kurosh Dabbagh Escalante fb36037bb7 Delete SysCallManager.cs 2020-02-02 20:02:21 +01:00
Kurosh Dabbagh Escalante 5c6b482dbb Delete TokenManager.cs 2020-02-02 20:02:09 +01:00
Kurosh Dabbagh Escalante 5a8c241b74 Delete StreamString.cs 2020-02-02 20:02:03 +01:00
Kurosh Dabbagh Escalante d3a2b4f7e8 Delete Response.cs 2020-02-02 20:01:46 +01:00
Kurosh Dabbagh Escalante 9bcdb381d1 Delete PowerCat.cs 2020-02-02 20:01:39 +01:00
Kurosh Dabbagh Escalante 3c63a13658 Delete LauncherShellCode.cs 2020-02-02 20:01:34 +01:00
Kurosh Dabbagh Escalante 4ed3f3c9b5 Delete LauncherPowershell.cs 2020-02-02 20:01:29 +01:00
Kurosh Dabbagh Escalante eb7de48f56 Delete LauncherDll.cs 2020-02-02 20:01:24 +01:00
Kurosh Dabbagh Escalante 871396d97d Delete Controller.cs 2020-02-02 20:01:18 +01:00
Kurosh Dabbagh Escalante 10ae2d40f0 Delete Content.cs 2020-02-02 20:01:12 +01:00
Kurosh Dabbagh Escalante 04b517d80b Added syscall for OpenProcess 2020-02-02 19:51:25 +01:00
Kurosh Dabbagh Escalante 3b4ce49595 Some bugs fixed. 2020-01-26 17:43:24 +01:00
Kurosh Dabbagh Escalante 4e1147a9f5 Some bugs fixed. 2020-01-26 17:28:53 +01:00
Kurosh Dabbagh Escalante cf4ff38ef7 Delete SyscallManager.cs 2020-01-26 17:28:35 +01:00
Kurosh Dabbagh Escalante d4848bec34 Some bugs fixed. 2020-01-26 17:22:35 +01:00
Kurosh Dabbagh Escalante 5083ea23ef Some bugs fixed. 2020-01-26 17:22:17 +01:00
Kurosh Dabbagh Escalante a9d968b79e Bug on psh option fixed.
Due to a bad output parsing the psh option wasnt working properly after impersonating other user.
2020-01-21 23:40:15 +01:00
Kurosh Dabbagh Escalante 99a66e2595 Bug on CreateProcess* functions fixed. 2020-01-21 23:23:12 +01:00
Kurosh Dabbagh Escalante 413c49da0f Merge pull request #1 from TheAnachronism/master
Basic refactoring of the C# solution and fixed some project-file bugs :: Pull request made by @TheAnachronism.
2020-01-21 23:18:19 +01:00
Kurosh Dabbagh Escalante 9371d3868e Added NtOpenProcessToken syscall and some restructuring. 2020-01-19 16:14:56 +01:00
Kurosh Dabbagh Escalante bd54fc62e3 Update README.md 2020-01-16 18:21:52 +01:00
Kurosh Dabbagh Escalante e24442ed12 Update SyscallManager.cs 2020-01-12 21:37:15 +01:00
Kurosh Dabbagh Escalante 559133f295 Update README.md 2020-01-12 19:57:40 +01:00
Kurosh Dabbagh Escalante b039aa10d3 Added feature to shellcode remote process injection.
With this changes, the injection of shellcode can be executed both in the own shell process or in another process as well.
The shellcode injection is executed using directly syscalls, avoiding user mode API calls to evade EDR API hooking.
In the future, more Win32 API calls will be replaced with their corresponding syscalls.
2020-01-12 19:54:03 +01:00
Kurosh Dabbagh Escalante 442c97f95c Added feature to shellcode remote process injection. 2020-01-12 19:50:27 +01:00
Kurosh Dabbagh Escalante 74e4ea0c10 Delete Controler.cs 2020-01-08 20:20:35 +01:00
Kurosh Dabbagh Escalante b4bb3d100d Add files via upload 2020-01-08 20:19:33 +01:00
Kurosh Dabbagh Escalante 6c50e18cf2 Small changes to add the referenced BITS dll.
Migrated to "PackageReference" project.
2020-01-07 20:32:49 +01:00
Kurosh Dabbagh Escalante 05a7fc603d Update lawlbin.py 2020-01-07 20:01:19 +01:00
Kurosh Dabbagh Escalante 2b5e593806 Add files via upload 2020-01-05 02:36:40 +01:00
Kurosh Dabbagh Escalante 68d2d84af2 Update README.md 2020-01-05 02:35:41 +01:00
Kurosh Dabbagh Escalante a2cbc08cde Add files via upload 2020-01-05 02:34:37 +01:00
Kurosh Dabbagh Escalante de6fdaa9f9 Update README.md 2020-01-05 02:31:33 +01:00
Kurosh Dabbagh Escalante 2768144e42 Update README.md 2020-01-05 02:29:05 +01:00
Kurosh Dabbagh Escalante c4805050af Update README.md 2020-01-05 02:28:46 +01:00
Kurosh Dabbagh Escalante a183b922c5 Update README.md 2020-01-05 01:27:08 +01:00
Kurosh Dabbagh Escalante 27ff47a624 Update README.md 2020-01-05 01:26:23 +01:00
Kurosh Dabbagh Escalante 42db58c7d8 Update README.md 2020-01-05 01:23:20 +01:00
Kurosh Dabbagh Escalante d1f879540c Update README.md 2020-01-05 01:23:00 +01:00
Kurosh Dabbagh Escalante 52f15cb25d Update README.md 2020-01-05 01:21:54 +01:00
Kurosh Dabbagh Escalante df9529bd5c Update README.md 2020-01-05 01:20:54 +01:00
Kurosh Dabbagh Escalante fc974baa24 Update README.md 2020-01-05 01:20:18 +01:00
Kurosh Dabbagh Escalante 356591f9d0 Update README.md 2020-01-05 01:19:47 +01:00
Kurosh Dabbagh Escalante 2ecfaf1335 Update README.md 2020-01-05 00:46:35 +01:00
Kurosh Dabbagh Escalante 1205209ba1 Update README.md 2020-01-05 00:45:17 +01:00
Kurosh Dabbagh Escalante cd2f7efdd9 Update README.md 2020-01-05 00:44:39 +01:00
Kurosh Dabbagh Escalante a5256bccc5 Update README.md 2020-01-05 00:42:21 +01:00
Kurosh Dabbagh Escalante c19ba51bff Add files via upload 2020-01-05 00:07:06 +01:00
Kurosh Dabbagh Escalante 277d3fafac Add files via upload 2020-01-04 23:33:24 +01:00
Kurosh Dabbagh Escalante a330983d9a Add files via upload 2020-01-04 23:13:02 +01:00
Kurosh Dabbagh Escalante a652b92a85 Add files via upload 2020-01-04 23:05:17 +01:00
Kurosh Dabbagh Escalante 7baa73827e Update myapp.py 2020-01-04 22:14:28 +01:00
Kurosh Dabbagh Escalante 146212e4ca Add files via upload 2020-01-04 18:39:47 +01:00
Kurosh Dabbagh Escalante 3aa9049613 Add files via upload 2020-01-04 18:39:10 +01:00
Kurosh Dabbagh Escalante 466291bbfc Add files via upload 2020-01-04 18:39:03 +01:00
Kurosh Dabbagh Escalante 2b00164111 Delete Controler.cs 2020-01-04 18:38:42 +01:00
Kurosh Dabbagh Escalante e5194b6f62 Add files via upload 2020-01-04 18:38:15 +01:00
Kurosh Dabbagh Escalante 1bd342e50a Update Program.cs 2020-01-04 17:33:05 +01:00
Kurosh Dabbagh Escalante 4ce6959db3 Initial upload 2020-01-04 17:29:26 +01:00
Kurosh Dabbagh Escalante f6aececf33 Initial commit 2020-01-04 17:27:03 +01:00