.doc
, .docm
, .dotm
, .dot
, .rtf
, .mht
.xls
, .xlsm
, .xltm
, .xlt
, .xlsb
, .xla
, .xlam
.pptm
, .ppsm
, .potm
.mdb
, .accde
.vdw
, .vsd
, .vsdm
, .vss
, .vssm
, .vstm
, .vst
.mpp
, .mpt
.pub
.otm
(used in Outlook persistence scenarios).msc
: Microsoft Management Console Snap-in.xsl
: XML containing VBScript/JScript.wsc
: COM Scriptlet containing VBScript/JScript.wsf
: XML containing VBScript/JScript.vbs
: VBscript.js
: JScript / JXA.hta
: HTML Application containing VBscript/JScript.zip
: can contain hidden files.7zip
.rar
.iso
: can contain hidden files.cab
.vhd
.vhdx
.pdf
: files embedded into PDF.lnk
: LNK with appended file/ZIP, uses Powershell to unpack itself.application
, .manifest
: ClickOnce deployment files.bat
, .cmd
: Classic cmd.exe batch files.ps1
: Powershell scripts.html
, .svg
: HTML Smuggling, SVG Smuggling.lnk
: Windows shortcut.url
: a shortcut that can launch direct victim onto URL in default browser or launch locally available file through file:///path/to/file.exe
URI-handler.chm
: can run system commands, useful in complex infection scenarios.msi
: malicious MSI installer or backdoored MSI.mst
: Installation transform file.msg
: BadAppointment attack, implements malicious appointment to coerce NetNTLM authentication.diagcab
: path-traversal enabled CAB file exploiting Dogwalk exploit, generated with exploiter.exe.inf
: INF installation file invoking SCT, in an INF-SCT weaponization scenarioBatteries Included »
Batteries Included »
Batteries Included »
Batteries Included »
MST
transform files or MSP
patch filesBatteries Included »
Batteries Included »
.appref-ms
deployment filesBatteries Included »
exe, hta, vbs, msi, dll, cpl, macro-enabled Office documents, ClickOnce manifest
) & digitally signs it with provided certificateBatteries Included »
Batteries Included »
Batteries Included »
Apfell.js
? Why not Apfell-obf.js
. Out-of-the-box complex apfell code obfuscation ready when you are!Batteries Included »
packager.exe malware.exe Report.lnk,Financial.zip,index.html
Batteries Included »
Batteries Included »
Batteries Included »
Batteries Included »
Batteries Included »
Batteries Included »
Batteries Included »
Batteries Included »
steal.NetNTLM
steal.NetNTLM2
ddeauto.execute
link.com
exfil.file
Batteries Included »
Sounds interesting? »
Type | Price |
---|---|
1 year Company/Team license (5 seats) | Contact us |
Copyright © 2022 binary-offensive.com | designed by www.ombre.tech