Sinisterly
DKMC ~ {Don't Kill My Cat} - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Hacking (https://sinister.li/Forum-Hacking)
+--- Forum: Hacking Tools (https://sinister.li/Forum-Hacking-Tools)
+--- Thread: DKMC ~ {Don't Kill My Cat} (/Thread-DKMC-Don-t-Kill-My-Cat)



DKMC ~ {Don't Kill My Cat} - S3xySmurf - 11-02-2017

Don't Kill My Cat (DKMC)

Don't kill my cat is a tool that generates obfuscated shellcode that is stored inside of polyglot images. The image is 100% valid and also 100% valid shellcode. The idea is to avoid sandbox analysis since it's a simple "legit" image. For now the tool rely on PowerShell the execute the final shellcode payload.

Why it's called don't kill my cat? Since I suck at finding names for tools, I decided to rely on the fact that the default BMP image is a cat to name the tool.

Presentation on how it works internally can be found here: https://github.com/Mr-Un1k0d3r/DKMC/blob/master/DKMC%20presentation%202017.pdf

Basic Flow:
  • Generate shellcode (meterpreter / Beacon)
  • Embed the obfuscated shellcode inside the image
  • PowerShell download the image and execute the image as shellcode
  • Get your shell



https://github.com/Mr-Un1k0d3r/DKMC


RE: DKMC ~ {Don't Kill My Cat} - Synthx - 11-02-2017

Okay, this is extremely interesting. I have done somewhat similar things using Automator for mac, and using Unicode characters. I can almost 100% guarantee that I will use this tool sometime. Thanks for the HQ share, and all of your recent one's as well!


RE: DKMC ~ {Don't Kill My Cat} - S3xySmurf - 11-08-2017

This makes infecting someone very interesting a few lines of code could turn any application into a special little dropper and could easily bypass most AV's using this method


RE: DKMC ~ {Don't Kill My Cat} - Bish0pQ - 11-08-2017

Nice! I have actually been thinking of a embedding it into an image. Looks like you beat me to it. I will try this out, but looks very decent. Thank you for this!