.doc
, .docm
, .dotm
, .dot
, .rtf
, .mht
.xls
, .xlsm
, .xltm
, .xlt
, .xlsb
, .xla
, .xlam
.pptm
, .ppsm
, .potm
.mdb
, .accde
.vdw
, .vsd
, .vsdm
, .vss
, .vssm
, .vstm
, .vst
.mpp
, .mpt
.pub
.otm
(used in Outlook persistence scenarios).vba
.vbs
: VBscript.vbe
: VBScript encoded.js
: JScript / JXA.jse
: Jscript encoded.msc
: Microsoft Management Console Snap-in.hta
: HTML Application containing VBscript/JScript.xsl
: XML containing VBScript/JScript.wsf
: XML containing VBScript/JScript.wsc
: COM Scriptlet containing VBScript/JScript.zip
: can contain hidden files.7zip
.rar
.iso
: can contain hidden files.img
: ISO-renamed, can contain hidden files.gz
, .tar.gz
, .tar.bz2
, .tar
, .tar.xz
, .tar.zst
, .tzst
, .tbz2
, .tgz
, .txz
: various tarballs, bzip2 and other linux archives.sz
/ .szdd
/ .kwaj
- MSCOMPRESS legacy archive format.cab
.wim
.vhd
.vhdx
.cpio
: archive format supported by Apple's Archiver Utility, dubbed as Regular Archive.cpgz
: archive format supported by Apple's Archiver Utility, dubbed as Compressed Archive.pdf
: files embedded into PDF.lnk
: LNK with appended file/ZIP, uses Powershell to unpack itself.rdp
: idea to conceal payloads within RDP files, as described here .application
, .manifest
, .appref-ms
: ClickOnce deployment files.bat
, .cmd
: Classic cmd.exe batch files.ps1
: Powershell scripts.html
, .svg
: HTML Smuggling, SVG Smuggling.lnk
: Windows shortcut.url
: a shortcut that can launch direct victim onto URL in default browser or launch locally available file through file:///path/to/file.exe
URI-handler.chm
: can run system commands, useful in complex infection scenarios.msi
: malicious MSI installer or backdoored MSI.mst
: Installation transform file.msp
: Installation patch file, backdoors legitimate MSI.msg
: BadAppointment attack, implements malicious appointment to coerce NetNTLM authentication.diagcab
: path-traversal enabled CAB file exploiting Dogwalk exploit, generated with exploiter.exe.inf
: INF installation file invoking SCT, in an INF-SCT weaponization scenarioFile Dropper
is considered one)Wscript.Shell
considered one)InkPicture1_Painted
).JS
JXA scriptsBatteries Included »
Batteries Included »
Batteries Included »
Batteries Included »
MST
transform files or MSP
patch filesBatteries Included »
Batteries Included »
.appref-ms
deployment filesBatteries Included »
exe, hta, vbs, msi, dll, cpl, macro-enabled Office documents, ClickOnce manifest
) & digitally signs it with provided certificateBatteries Included »
Batteries Included »
Batteries Included »
Apfell.js
? Why not Apfell-obf.js
. Out-of-the-box complex apfell code obfuscation ready when you are!Batteries Included »
packager.exe malware.exe Report.lnk,Financial.zip,index.html
Batteries Included »
Batteries Included »
Batteries Included »
Batteries Included »
Batteries Included »
Batteries Included »
Batteries Included »
Batteries Included »
steal.NetNTLM
steal.NetNTLM2
ddeauto.execute
link.com
exfil.file
Batteries Included »
Batteries Included »
Batteries Included »
Batteries Included »
Sounds interesting? »
Type | Price |
---|---|
1 year New license for 5 seats | 3500 EUR |
1 year License renewal | 2200 EUR |
Premium package - including RMF, custom shellcode loader with source code and bunch of additional tooling | Request a quote |
Copyright © 2022 binary-offensive.com | designed by www.ombre.tech