![]() |
|
DKMC ~ {Don't Kill My Cat} - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Hacking (https://sinister.li/Forum-Hacking) +--- Forum: Hacking Tools (https://sinister.li/Forum-Hacking-Tools) +--- Thread: DKMC ~ {Don't Kill My Cat} (/Thread-DKMC-Don-t-Kill-My-Cat) |
DKMC ~ {Don't Kill My Cat} - S3xySmurf - 11-02-2017 Don't Kill My Cat (DKMC) Don't kill my cat is a tool that generates obfuscated shellcode that is stored inside of polyglot images. The image is 100% valid and also 100% valid shellcode. The idea is to avoid sandbox analysis since it's a simple "legit" image. For now the tool rely on PowerShell the execute the final shellcode payload. Why it's called don't kill my cat? Since I suck at finding names for tools, I decided to rely on the fact that the default BMP image is a cat to name the tool. Presentation on how it works internally can be found here: https://github.com/Mr-Un1k0d3r/DKMC/blob/master/DKMC%20presentation%202017.pdf Basic Flow:
https://github.com/Mr-Un1k0d3r/DKMC RE: DKMC ~ {Don't Kill My Cat} - Synthx - 11-02-2017 Okay, this is extremely interesting. I have done somewhat similar things using Automator for mac, and using Unicode characters. I can almost 100% guarantee that I will use this tool sometime. Thanks for the HQ share, and all of your recent one's as well! RE: DKMC ~ {Don't Kill My Cat} - S3xySmurf - 11-08-2017 This makes infecting someone very interesting a few lines of code could turn any application into a special little dropper and could easily bypass most AV's using this method RE: DKMC ~ {Don't Kill My Cat} - Bish0pQ - 11-08-2017 Nice! I have actually been thinking of a embedding it into an image. Looks like you beat me to it. I will try this out, but looks very decent. Thank you for this! |