What's new
Runion

This is a sample guest message. Register a free account today to become a member! Once signed in, you'll be able to participate on this site by adding your own topics and posts, as well as connect with other members through your own private inbox!

email spreading

sallynice45

Midle Weight
Депозит
$0
can someone tell me an effective way to spread a link over email? it seems i try gg short url and it just doesnt work? am i missing something? trying to spread my lnk direct download link.

thanks
 
Most email providers will block for spam. Have you tried container files like ISOs, image files, or MSI?
 
nek_0 сказал(а):
Most email providers will block for spam. Have you tried container files like ISOs, image files, or MSI?
Пожалуйста, обратите внимание, что пользователь заблокирован

MSI is bad for this.
 
Пожалуйста, обратите внимание, что пользователь заблокирован
try html smuggling combined with xor encryption or smuggle the file by spoofing google drive URL for attachments
 
Anunnaki сказал(а):
try html smuggling combined with xor encryption or smuggle the file by spoofing google drive URL for attachments
Пожалуйста, обратите внимание, что пользователь заблокирован

HTML with xor encryption? Can you explain more?
 
nek_0 сказал(а):
Most email providers will block for spam. Have you tried container files like ISOs, image files, or MSI?

was kinda hoping to skip all the testing cause ive done too much already and hoping someone can just tell me what is actually working at the moment lol.
like HOW are people spreading exe in an email?? this is what im after. i know to zip, and put a password.. but still having difficulties.
 
nek_0 сказал(а):
it can be done but you are correct, not ideal.
Пожалуйста, обратите внимание, что пользователь заблокирован

MSIs are very detected.
Lnks are better, even under password is zip/rar.
 
Aster сказал(а):
MSIs are very detected.
Lnks are better, even under password is zip/rar.

how are you getting lnk to work, seems its detected for me all the time? or wont execute my exe
 
sallynice45 сказал(а):
how are you getting lnk to work, seems its detected for me all the time? or wont execute my exe
Пожалуйста, обратите внимание, что пользователь заблокирован

Well, if you are using public lnk builder then good luck
Malware is hard without investment.
 
sallynice45 сказал(а):
how are you getting lnk to work, seems its detected for me all the time? or wont execute my exe

umm i think INK detections depends on how you calling powershell and downloading and executing bad stuff, try to download and run your stub in multiple stages
 
DanteXDark сказал(а):

obfuscate the javascript host the html on server and put direct link in html templet.
Пожалуйста, обратите внимание, что пользователь заблокирован


There are varieties to this method. This quotes link source doesn't include xor encryption/decryption. Also look into using MS-office URI protocols to directly execute from URL which can be embedded into emails or invoked via some crafty OOXML vector in email attachment . This can be combined with earlier method for more novelty.

As an additional sidenote, DNS tunneling works wonders still
Последнее редактирование: 07.09.2022
 
Anunnaki сказал(а):
There are varieties to this method. This quotes link source doesn't include xor encryption/decryption. Also look into using MS-office URI protocols to directly execute from URL which can be embedded into emails or invoked via some crafty OOXML vector in email attachment . This can be combined with earlier method for more novelty.

As an additional sidenote, DNS tunneling works wonders still

humm looks good can you share some resources (blogs or anything )
Последнее редактирование: 07.09.2022
 
There are a lot of ways to execute your payload using lnk, avoid powershell.exe for example. There are others LOLBINS to achieve the same thing.
 
marauda18 сказал(а):
There are a lot of ways to execute your payload using lnk, avoid powershell.exe for example. There are others LOLBINS to achieve the same thing.
Пожалуйста, обратите внимание, что пользователь заблокирован

Exactly.
 
Top