Is .LNK the best exploit right now?yes i sell this stuff, but if your malware is detected then after download malware WD will detect (only malware not LNK)
Is .LNK the best exploit right now?yes i sell this stuff, but if your malware is detected then after download malware WD will detect (only malware not LNK)
if you know how to spread then maybe yes, i am not that much good at spreading but iso + lnk seems to be a good combo, you are also trying to spam then we can work togetherIs .LNK the best exploit right now?
Yeah sure we can do but .lnk doesn't seem so good to me as it can't be sent via email. Do you have .Xll exploit? If possible 0day .Xll exploit if signed by a trusted EV Publisher. That's why i'm looking for an EV Publisher. The .xll opens the .exe in one click, FUDif you know how to spread then maybe yes, i am not that much good at spreading but iso + lnk seems to be a good combo, you are also trying to spam then we can work together![]()
yah you cannot attach iso and lnk in emails but you can give a direct download linkYeah sure we can do but .lnk doesn't seem so good to me as it can't be sent via email. Do you have .Xll exploit? If possible 0day .Xll exploit if signed by a trusted EV Publisher. That's why i'm looking for an EV Publisher. The .xll opens the .exe in one click, FUD
Of coursethis works undetected brother?
Try it first!!this will detect
How much per one?yes i sell this stuff, but if your malware is detected then after download malware WD will detect (only malware not LNK)
10$ maybeHow much per one?
This execution chain has been combined with password-protected .zip files(Just place the iso/lnk inside the zip achieve) which can't get scanned.yah you cannot attach iso and lnk in emails but you can give a direct download link, i am also looking for xll exploit (
yah but opening zip and then lnk seems too clickyThis execution chain has been combined with password-protected .zip files(Just place the iso/lnk inside the zip achieve) which can't get scanned.
You attach the .zip file and put the password within the mail-content.
Well, even Excel macros need the victims to enable them... at some point all those execution chains require that the victim is stupid enough and performs specific actions.yah but opening zip and then lnk seems too clicky
yah you are correct, and it is easy to convince people to enable macros XD , i just think it is lil bit hard to understand victims how to extract an runWell, even Excel macros need the victims to enable them... at some point all those execution chains require that the victim is stupid enough and performs specific actions.
its easyyah you are correct, and it is easy to convince people to enable macros XD , i just think it is lil bit hard to understand victims how to extract an run
and i ll get connection brrr ratatataaits easy
When somone will try to open your lnk, winrar will ask for password. When password is correct, your lnk will run.
so .lnk does infact work? i was having issues with getting virus detected on download in chrome, i used a tutorial here to make the lnk file but i assume maybe thats why?This execution chain has been combined with password-protected .zip files(Just place the iso/lnk inside the zip achieve) which can't get scanned.
You attach the .zip file and put the password within the mail-content.
the best on your own hostingso .lnk does infact work? i was having issues with getting virus detected on download in chrome, i used a tutorial here to make the lnk file but i assume maybe thats why?
thanks for the responses, ive been trying to get this to work for ages now.
can anyone recommend where to host exe?
in the above poc i hosted all the stagers on discordso .lnk does infact work? i was having issues with getting virus detected on download in chrome, i used a tutorial here to make the lnk file but i assume maybe thats why?
thanks for the responses, ive been trying to get this to work for ages now.
can anyone recommend where to host exe?
thats smartWhat a drama.
You can host your final payload anywhere,your own server or third-party services,specially legitimate ones,to host your final payload or the initial delivery(zip/iso) for example if you are not attaching to the email.
The guys above said almost everything already. In my case I use zipped password protected archive with DLL Search Order hijacking besides the .lnk and office macros. For those who don't know this technique,basically you use a legitimate vulnerable .exe file to load a malicious DLL on the same directory,or sideload. Choose a .exe with icon that helps with the social engineering in your campaign and that don't show any gui on the execution.
And about this taking too much steps to achieve execution,remember that is all about social engineering,people are dumb.
i hear mixed reviews on discord but ill give it a shot thanksin the above poc i hosted all the stagers on discordand still FUD
my file is over 300mbin the above poc i hosted all the stagers on discordand still FUD