Hacking Articles Tips Tricks Videos Tutorials
471 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Nimcrypt2 is yet another PE packer/loader designed to bypass AV/EDR. It is an improvement on my original Nimcrypt (https://github.com/icyguider/nimcrypt) project, with the main improvements being the use of direct syscalls (https://www.kitploit.com/search/label/Syscalls) and the ability to load regular PE files as well as raw shellcode. Before going any further, I must acknowledge those who did the VAST majority of work and research (https://www.kitploit.com/search/label/Research) that this project depends on. Firstly, I must thank @byt3bl33d3r (https://twitter.com/byt3bl33d3r) for his Offensive Nim repo (https://github.com/byt3bl33d3r/OffensiveNim), and @ShitSecure (https://twitter.com/ShitSecure) for all of the code snippets he's publicly released. That is what the original version of this tool was created from, and the current version is no different. Particularly, the new PE loading functionality used in this tool is just an implementation of ShitSecure's recently released Nim-RunPE (https://github.com/S3cur3Th1sSh1t/Nim-RunPE) code. I highly encourage sponsoring him for access to his own Nim PE Packer (https://twitter.com/ShitSecure/status/1482428360500383755), which is no doubt a much better and more featureful version of this.
Additionally, I would like to thank @ajpc500 (https://twitter.com/ajpc500) for his NimlineWhispers2 (https://github.com/ajpc500/NimlineWhispers2) project that this tool uses for direct syscalls. I cannot stress enough how this project is simply an amalgamation of the public work of those previously mentioned, so all credit must go to them. ] [-p ] [-n] [-u] [-s] [-v] nimcrypt (-h | --help) Options: -h --help Show this screen. --version Show version. -f --file filename File to load -t --type filetype Type of file (csharp, raw, or pe) -p --process process Name of process for shellcode injection -o --output filename Filename for compiled exe -u --unhook Unhook ntdll.dll -v --verbose Enable verbose messages during execution -n --no-randomization Disable syscall name randomization -s --no-sandbox Disable sandbox checks"> ___
.-' `'.
/ \
| ;
| | ___.--,
_.._ |0) ~ (0) | _.---'`__.-( (_.
__.--'`_.. '.__.\ '--. \_.-' ,.--'` `""`
( ,.--'` ',__ /./; ;, '.__.'` __
_`) ) .---.__.' / | |\ \__..--"" ""'--.,_
`---' .'.''-._.-'`_./ /\ '. \ _.-~~~````~~~-._`-.__.'
| | .' _.-' | | \ \ '. `~---`
\ \/ .' \ \ '. '-._)
\/ / \ \ `=.__`~-. Nimcrypt v2
jgs / /\ `) ) / / `"".`\
, _.-'.'\ \ / / ( ( / / 3-in-1 C#, PE, & Raw Shellcode Loader
`--~` ) ) .-'.' '.'. | (
(/` ( (` ) ) '-;
` '-; (-'

Nimcrypt v 2.0

Usage:
nimcrypt -f file_to_load -t csharp/raw/pe [-o ] [-p ] [-n] [-u] [-s] [-v]
nimcrypt (-h | --help)

Options:
-h --help Show this screen.
--version Show version.
-f --file filename File to load
-t --type filetype Type of file (csharp, raw, or pe)
-p --process process Name of process for shellcode injection
-o --output filename Filename for compiled exe
-u --unhook Unhook ntdll.dll

___________________________
@hacking_Attack
@Hacking_Video
-v --verbose Enable verbose messages during execution< br/> -n --no-randomization Disable syscall name randomization
-s --no-sandbox Disable sandbox checks
Features: NtQueueApcThread Shellcode Execution w/ PPID Spoofing (https://www.kitploit.com/search/label/Spoofing) & 3rd Party DLL Blocking Syscall Name Randomization Ability to load .NET and Regular PE Files AES Encryption (https://www.kitploit.com/search/label/Encryption) with Dynamic Key Generation Sandbox Evasion Tested and Confirmed Working on: Windows 11 (10.0.22000) Windows 10 21H2 (10.0.19044) Windows 10 21H1 (10.0.19043) Windows 10 20H2 (10.0.19042) Windows 10 19H2 (10.0.18363) Windows Server 2019 (10.0.17763) Installation/Dependencies: Nimcrypt2 is designed to be used on Linux systems with Nim installed. Before installing Nim, you must ensure that you have the following packages installed via your package manager: sudo apt install gcc mingw-w64 xz-utils git
To install Nim, I prefer to use choosenim (https://github.com/dom96/choosenim) as follows: > ~/.bashrc export PATH=$HOME/.nimble/bin:$PATH'>curl https://nim-lang.org/choosenim/init.sh -sSf | sh
echo "export PATH=$HOME/.nimble/bin:$PATH" >> ~/.bashrc
export PATH=$HOME/.nimble/bin:$PATH
Nimcrypt2 also depends on a few packages that can be installed via Nimble. This can be done like so: nimble install winim nimcrypto docopt ptr_math
With all the dependencies now installed, Nimcrypt2 can be compiled like so: nim c -d=release --cc:gcc --embedsrc=on --hints=on --app=console --cpu=amd64 --out=nimcrypt nimcrypt.nim
Known Bugs: As described (https://github.com/S3cur3Th1sSh1t/Nim-RunPE/blob/a117ecec635824703047c1d850607bdf2cfa628b/README.md?plain=1#L13) by ShitSecure, if the release version of mimikatz is loaded via the PE loader, it will not accept commands for some unknown reason. Using a version of mimikatz that was compiled from source fixes this issue. Greetz & Credit: @byt3bl33d3r (https://twitter.com/byt3bl33d3r) for their Offensive Nim project: https://github.com/byt3bl33d3r/OffensiveNim @ShitSecure (https://twitter.com/ShitSecure) for their Nim-RunPE project: https://github.com/S3cur3Th1sSh1t/Nim-RunPE @ajpc500 (https://twitter.com/ajpc500) for their NimlineWhispers2 project: https://github.com/ajpc500/NimlineWhispers2 @Snovvcrash (https://twitter.com/snovvcrash) for their NimHollow (https://www.kitploit.com/search/label/NimHollow) project: https://github.com/snovvcrash/NimHollow

Download Nimcrypt2 (https://github.com/icyguider/Nimcrypt2)

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
GIF
KitPloit - PenTest Tools!
Nimcrypt2 - .NET, PE, And Raw Shellcode Packer/Loader Written In Nim

https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiys8OACKfgsKDYuW4hT-_z5NTOO8ekXeyUFxQTWxoYBek7r30sH8IyKMdq7hmzWcM9ydEFvzQaVXo3HjVq6cWm62EWEpdVSZvJLGNusxMmqzW0LV4wj3yLtNO3NbZFDQP0zdhZdmurNBOvH7u51gsjrXuane1J9gqVhnBTHTV1TgiYoKCQ69WAC-Vl/w640-h256/nimcrypt.gif Nimcrypt2 is yet another PE packer/loader designed to bypass AV/EDR. It is an improvement on my original Nimcrypt project, with the main improvements being the use of direct syscalls and the ability to load regular PE files as well as raw shellcode.

Before going any further, I must acknowledge those who did the VAST majority of work and research that this project depends on. Firstly, I must thank @byt3bl33d3r for his Offensive Nim repo, and @ShitSecure for all of the code snippets he's publicly released. That is what the original version of this tool was created from, and the current version is no different. Particularly, the new PE loading functionality used in this tool is just an implementation of ShitSecure's recently released Nim-RunPE code. I highly encourage sponsoring him for access to his own Nim PE Packer, which is no doubt a much better and more featureful version of this.
Additionally, I would like to thank @ajpc500 for his NimlineWhispers2 project that this tool uses for direct syscalls. I cannot stress enough how this project is simply an amalgamation of the public work of those previously mentioned, so all credit must go to them.
] [-p ___
.-' `'.
/ \
| ;
| | ___.--,
_.._ |0) ~ (0) | _.---'`__.-( (_.
__.--'`_.. '.__.\ '--. \_.-' ,.--'` `""`
( ,.--'` ',__ /./; ;, '.__.'` __
_`) ) .---.__.' / | |\ \__..--"" ""'--.,_
`---' .'.''-._.-'`_./ /\ '. \ _.-~~~````~~~-._`-.__.'
| | .' _.-' | | \ \ '. `~---`
\ \/ .' \ \ '. '-._)
\/ / \ \ `=.__`~-. Nimcrypt v2
jgs / /\ `) ) / / `"".`\
, _.-'.'\ \ / / ( ( / / 3-in-1 C#, PE, & Raw Shellcode Loader
`--~` ) ) .-'.' '.'. | (
(/` ( (` ) ) '-;
` '-; (-'

Nimcrypt v 2.0

Usage:
nimcrypt -f file_to_load -t csharp/raw/pe [-o ] [-p -n --no-randomization Disable syscall name randomization
-s --no-sandbox Disable sandbox checks
Features:* NtQueueApcThread Shellcode Execution w/ PPID Spoofing & 3rd Party DLL Blocking
* Syscall Name Randomization
* Ability to load .NET and Regular PE Files
* AES Encryption with Dynamic Key Generation
* Sandbox Evasion Tested and Confirmed Working on:* Windows 11 (10.0.22000)
* Windows 10 21H2 (10.0.19044)
* Windows 10 21H1 (10.0.19043)
* Windows 10 20H2 (10.0.19042)
* Windows 10 19H2 (10.0.18363)
* Windows Server 2019 (10.0.17763) Installation/Dependencies:Nimcrypt2 is designed to[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
KitPloit - PenTest Tools! Nimcrypt2 - .NET, PE, And Raw Shellcode Packer/Loader Written In Nim https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiys8OACKfgsKDYuW4hT-_z5NTOO8ekXeyUFxQTWxoYBek7r30sH8IyKMdq7hmzWcM9ydEFvzQaVXo3HjVq6cWm62EWEpdVSZvJLG…
be used on Linux systems with Nim installed. Before installing Nim, you must ensure that you have the following packages installed via your package manager: sudo apt install gcc mingw-w64 xz-utils git To install Nim, I prefer to use choosenim as follows:

> ~/.bashrc export PATH=$HOME/.nimble/bin:$PATH">curl https://nim-lang.org/choosenim/init.sh -sSf | sh
echo "export PATH=$HOME/.nimble/bin:$PATH" >> ~/.bashrc
export PATH=$HOME/.nimble/bin:$PATH


Nimcrypt2 also depends on a few packages that can be installed via Nimble. This can be done like so: nimble install winim nimcrypto docopt ptr_math With all the dependencies now installed, Nimcrypt2 can be compiled like so: nim c -d=release --cc:gcc --embedsrc=on --hints=on --app=console --cpu=amd64 --out=nimcrypt nimcrypt.nim Known Bugs:* As described by ShitSecure, if the release version of mimikatz is loaded via the PE loader, it will not accept commands for some unknown reason. Using a version of mimikatz that was compiled from source fixes this issue. Greetz & Credit:* @byt3bl33d3r for their Offensive Nim project: https://github.com/byt3bl33d3r/OffensiveNim
* @ShitSecure for their Nim-RunPE project: https://github.com/S3cur3Th1sSh1t/Nim-RunPE
* @ajpc500 for their NimlineWhispers2 project: https://github.com/ajpc500/NimlineWhispers2
* @Snovvcrash for their NimHollow project: https://github.com/snovvcrash/NimHollow Download Nimcrypt2

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Clipboard malware on my computer

Apparently, there was some malware on my Windows 10 pc that changes any bitcoin address to this one:

"bc1qn0r06gtwlamffet49fph9jnm9u2e2ylx5ns7qc".

I sold a Google Play card on a legit website for bitcoin and didn't even notice that i put the wrong address. I was confused as it said that the transaction was complete and there were no bitcoins on my electrum wallet (this is my first bitcoin transaction btw). After some time of being confused i realised that the address is wrong and then i tried coping the right one and it was pasting the one noted above! I was still confused, thought at first that the c on the keyboard doesn't function properly or that windows automaticaly doesn't copy as it thinks it's the same text or smth. But then i realised that this may is a malware... I googled about it and there exist malware like this one... Then googled about the address and it has a complete history of transactions and others have reported it for scamming and issues like this one.

Funny thing is that i don't even know how long i had this malware on my computer and was focused on not getting scammed selling my gift card haha. Thankfully, the amound was only 25$ but im still surprised.

I am now scanning my computer to find the malware, it might take some hours, and then will try to analyze it. I don't think any other password is hacked as i don't believe there is data being send from it but you never know... After this i am ofcourse removing windows from my computer forever and changing every single password i have.

submitted by /u/JuicyNatural
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video