.Lnk exploit Builder - Spoof ANY extension AND icon - FUD - N-day exploit - Bypass Smartscreen - UAC Bypass & More

В этой теме можно использовать автоматический гарант!

QuantumSoftware

RAM
Забанен
Регистрация
13.05.2022
Сообщения
105
Реакции
14
Гарант сделки
3
Пожалуйста, обратите внимание, что пользователь заблокирован
Welcome everyone,
QuantumBuilder will make your payload look like any file format (.png, .mp4, .doc, ...), you can even disguise them as a folder.

Macros are for the most part dead, this is the best method to deliver malicious code (apart from expensive 0-days)
There are countless articles about this very tool online, here are the major ones:
-> https://www.bleepingcomputer[.]com/...k-attacks-made-easy-with-new-quantum-builder/
-> https://blog.cyble.com/2022/06/22/quantum-software-lnk-file-based-builders-growing-in-popularity/
-> https://cn-sec.com/archives/1080507.html
Looking up "lnk quantum" is enough to see some more articles:
-> https://duckduckgo.com/?q=lnk+quantum+builder

Features:
  • Spoof ANY extension
  • 300+ different icons available (Microsoft Office ones included)
  • UAC Bypass (VIP license and above only)
  • Implementation of the dogwalk n-day exploit, more info below (Private license only)
  • Bypass Windows Smartscreen, EV certs are a thing of the past
  • Decoy (upon opening your .lnk a file of your choosing will be displayed on your victim's pc)
  • Multiple payloads per .lnk file. Even if one gets detected the rest will still run
  • Supported payload formats: .exe/.js/.vbs/.bat/.ps1/.msi
  • Dll payloads (VIP license and above only)
  • 99% FUD, even if you spread your stub. Every build is unique
  • Choose the .lnk file size (VIP license and above only)
  • WD exclusion wrapper
  • Execute your exes with admin privileges by prompting UAC with a Microsoft signed binary (powershell.exe)
  • Run your payload at startup, with a delay or when the victim's computer is idle
  • Hide your payloads after executing them
  • Melt .lnk after execution
  • Replace the .lnk with the decoy file once executed. (Private license only)
  • Choose where your payload is dropped on your victim's computer
  • Display a message when the lnk gets run
  • Compress your shortcut in a .iso/.img/.cab
Demo:

The actual .lnk extension is always hidden in windows:
demo.PNG


Implementation of the dogwalk n-day exploit:
This exploit will allow you to send shortcuts over email without actually attaching any file.
Demo:


Prices:

[PUBLIC]
1 month > 189 EUR
2 months > 378 355 EUR
6 months > 1134 899 EUR
Lifetime > 1500 EUR

[VIP]
1 month > 389 EUR
2 months > 778 555 EUR
6 months > 2334 1099 EUR
Lifetime > 1700 EUR

[PRIVATE]
1 month > 800 EUR
Lifetime > 2000 EUR

[URL Edition]
1 month > 1900 EUR
2 months > 3400 EUR
Lifetime > 5000 EUR

PUBLIC license characteristics:
  • public stub updated every few days
VIP license advantages:
  • Semi-shared UAC bypass (updated every few days)
  • WD exclusion wrapper
  • UAC disabler
  • Choose the .lnk file size
  • .dll support
  • 100% FUD payload (Semi-shared)
PRIVATE license advantages:
  • All VIP features
  • Replace the .lnk with the decoy file once executed.
  • Dogwalk n-day exploit
  • Completely unique payload
  • Completely unique and FUD UAC bypass
URL edition license advantages:
Please check out this thread:
https://xss.pro/threads/76877/

Contacts:
Telegram > @QuantumBuilderSupport (https://t.me/QuantumBuilderSupport)
This is the @ of a user, not a channel. Some scammers are trying to impersonate us so be careful.
Tox > FD378852532E37DB2DC7B945E581F2C5D49AB2E89F4715AC136E89F04F960A06EA08061D4DD4

Reviews and vouches:
You can find us on ExploitIn

TOS:
  • Uploading samples to virus total and similar scanners is prohibited.
  • All support is provided via private chat, not in this thread.
  • If you are given some instructions and you refuse to follow them, for example disabling windows defender's sample submission, your license might be banned.
  • We do not offer any kind of compensation if your payload gets detected while the files produced by this builder are clean.
  • All sales are final.
 
Последнее редактирование:
Пожалуйста, обратите внимание, что пользователь заблокирован
Update
  • Added UAC disabler (VIP stub only)
  • Improved dll support (VIP stub only)
If you need a custom feature feel free to contact me about it.
 
Последнее редактирование:
Пожалуйста, обратите внимание, что пользователь заблокирован
How to deliver .lnk file? must be compresed in .zip or .rar right?
Yeah, or you can also compress it in a .img/.iso (you can do that in the builder).
 
Пожалуйста, обратите внимание, что пользователь заблокирован
must have all 3 files in 1 place ?

You need to host 2 files (your payload and the .hta) and send only 1 (the shortcut) to the victim.
 
Пожалуйста, обратите внимание, что пользователь заблокирован
Update:

(vip stub only)
  • added UAC disabler
  • fixed some UAC bypass detections
  • added a second layer of in-memory decryption for some kind of payloads
  • merged dll and non-dll builder
  • fixed some bugs
  • added .msi payload compatibility
  • improved the documentation present in the builder
 
Последнее редактирование:
Пожалуйста, обратите внимание, что пользователь заблокирован
i wish i can get putty file, i open the lnk file and putty comes up. i will so love
 
Пожалуйста, обратите внимание, что пользователь заблокирован
i wish i can get putty file, i open the lnk file and putty comes up. i will so love
Yeah thats exactly what happens, you only need to send your victim the .lnk, all the other files just need to be hosted somewhere.
 
Пожалуйста, обратите внимание, что пользователь заблокирован
Update (private license only)
  • Added WD exclusion wrapper. This feature adds your payload/s to WinDef exclusions before downloading them, so now non-crypted payloads will get executed too.
 
Пожалуйста, обратите внимание, что пользователь заблокирован
Пожалуйста, обратите внимание, что пользователь заблокирован
Good product. Works as described. Worth way more money that he is selling it for.
+1 to this guy
Thanks for the positive review :)
 


Напишите ответ...
Верх