Login Register






Delivering A Payload Using A PDF file filter_list
Author
Message
Delivering A Payload Using A PDF file #1
Have anyone got ideas how to deliver a payload using a pdf file or how to conceal a payload in a pdf ?

Reply

RE: Delivering A Payload Using A PDF file #2
It's totally possible. I've no idea how to inject a virus directly into an already made PDF. But I do know there are converters out there that can convert an EXE to a PDF. Unfortunately, most of them are hundreds of dollars.

For something affordable or more viable you'll have to wait for another reply.

Reply

RE: Delivering A Payload Using A PDF file #3
Why not simply bind the executable file to the PDF?

Of course, If the binder Is not FUD, you'll need to crypt It.
[Image: AD83g1A.png]

Reply

RE: Delivering A Payload Using A PDF file #4
(05-08-2020, 05:19 AM)mothered Wrote: Why not simply bind the executable file to the PDF?

Of course, If the binder Is not FUD, you'll need to crypt It.
1. I have mfilebinder, and UST tool, so does it mean they can be crypted ? Cos they do raise detection each time i use them...
2. After binding an exe file with let's say a pdf file, the output is always gonna be an exe file which obviously isn't useful

(05-08-2020, 02:26 AM)Drako Wrote: It's totally possible. I've no idea how to inject a virus directly into an already made PDF. But I do know there are converters out there that can convert an EXE to a PDF. Unfortunately, most of them are hundreds of dollars.

For something affordable or more viable you'll have to wait for another reply.
ok i only know about free softwares out there that can convert an exe to doc file, but i don't know how that is achieved but i know doc files often work with macros and when turned on can activate a hidden shell script, so my question now is how an exe file can be converted to a shell, (i only know bat files can be converted to shell script) , i don't know if you got ideas about what am talking about...
(This post was last modified: 05-08-2020, 01:50 PM by xdlwilliamz.)

Reply

RE: Delivering A Payload Using A PDF file #5
(05-08-2020, 01:23 PM)xdlwilliamz Wrote: 1. I have mfilebinder, and UST tool, so does it mean they can be crypted ? Cos they do raise detection each time i use them...
Yes, use an FUD crypter.


(05-08-2020, 01:23 PM)xdlwilliamz Wrote: 2. After binding an exe file with let's say a pdf file, the output is always gonna be an exe file which obviously isn't useful
That's not right at all, opt for another binder.

Binders allow you to select the output file, that will ultimately be the one that's viewed by your victim- In this case, the PDF. The executable will run In the background, without any knowledge of Its existence.
[Image: AD83g1A.png]

Reply

RE: Delivering A Payload Using A PDF file #6
(05-08-2020, 04:46 PM)mothered Wrote:
(05-08-2020, 01:23 PM)xdlwilliamz Wrote: 1. I have mfilebinder, and UST tool, so does it mean they can be crypted ? Cos they do raise detection each time i use them...
Yes, use an FUD crypter.


(05-08-2020, 01:23 PM)xdlwilliamz Wrote: 2. After binding an exe file with let's say a pdf file, the output is always gonna be an exe file which obviously isn't useful
That's not right at all, opt for another binder.

Binders allow you to select the output file, that will ultimately be the one that's viewed by your victim- In this case, the PDF. The executable will run In the background, without any knowledge of Its existence.
that sounds nice, can you give suggestion of one of those binders ?
Crypting them ain't gonna be a problem.

Reply

RE: Delivering A Payload Using A PDF file #7
(05-08-2020, 11:33 PM)xdlwilliamz Wrote:
(05-08-2020, 04:46 PM)mothered Wrote:
(05-08-2020, 01:23 PM)xdlwilliamz Wrote: 1. I have mfilebinder, and UST tool, so does it mean they can be crypted ? Cos they do raise detection each time i use them...
Yes, use an FUD crypter.


(05-08-2020, 01:23 PM)xdlwilliamz Wrote: 2. After binding an exe file with let's say a pdf file, the output is always gonna be an exe file which obviously isn't useful
That's not right at all, opt for another binder.

Binders allow you to select the output file, that will ultimately be the one that's viewed by your victim- In this case, the PDF. The executable will run In the background, without any knowledge of Its existence.
that sounds nice, can you give suggestion of one of those binders ?
Crypting them ain't gonna be a problem.

Shockwave's File Binder v1.0 Is pretty old, but nonetheless, does the job well.

It gives you the option to run either the first or second file hidden. In your case, It's obviously the executable that will be hidden.
Spoiler:
[Image: cAW7LKw.png]
[Image: AD83g1A.png]

Reply

RE: Delivering A Payload Using A PDF file #8
(05-09-2020, 04:41 AM)mothered Wrote:
(05-08-2020, 11:33 PM)xdlwilliamz Wrote:
(05-08-2020, 04:46 PM)mothered Wrote: Yes, use an FUD crypter.


That's not right at all, opt for another binder.

Binders allow you to select the output file, that will ultimately be the one that's viewed by your victim- In this case, the PDF. The executable will run In the background, without any knowledge of Its existence.
that sounds nice, can you give suggestion of one of those binders ?
Crypting them ain't gonna be a problem.

Shockwave's File Binder v1.0 Is pretty old, but nonetheless, does the job well.

It gives you the option to run either the first or second file hidden. In your case, It's obviously the executable that will be hidden.
Spoiler:
[Image: cAW7LKw.png]
ook, am gonna try it out asap

Reply

RE: Delivering A Payload Using A PDF file #9
(05-09-2020, 07:34 AM)xdlwilliamz Wrote:
(05-09-2020, 04:41 AM)mothered Wrote:
(05-08-2020, 11:33 PM)xdlwilliamz Wrote: that sounds nice, can you give suggestion of one of those binders ?
Crypting them ain't gonna be a problem.

Shockwave's File Binder v1.0 Is pretty old, but nonetheless, does the job well.

It gives you the option to run either the first or second file hidden. In your case, It's obviously the executable that will be hidden.
Spoiler:
[Image: cAW7LKw.png]
ook, am gonna try it out asap

Good to read.

I tested It quite a few years ago, and It served Its purpose well. I don't believe anything has changed since then.
[Image: AD83g1A.png]

Reply