From 6b2ddb5bc905487e8bb676ccc0a781d7f5ac931e Mon Sep 17 00:00:00 2001 From: CodeXTF2 Date: Mon, 24 Oct 2022 02:39:54 +0800 Subject: [PATCH] credits --- README.md | 3 ++- bin/screenshotBOF.zip | Bin 4856 -> 4677 bytes 2 files changed, 2 insertions(+), 1 deletion(-) diff --git a/README.md b/README.md index e8cadfc..48d8d90 100644 --- a/README.md +++ b/README.md @@ -37,4 +37,5 @@ beacon> download screenshot.bmp Cobalt Strike uses a technique known as fork & run for many of its post-ex capabilities, including the screenshot command. While this behaviour provides stability, it is now well known and heavily monitored for. This BOF is meant to provide a more OPSEC safe version of the screenshot capability. ## Credits -- Made using https://github.com/securifybv/Visual-Studio-BOF-template \ No newline at end of file +- Made using https://github.com/securifybv/Visual-Studio-BOF-template +- Save BMP to file from https://stackoverflow.com/a/60667564 \ No newline at end of file diff --git a/bin/screenshotBOF.zip b/bin/screenshotBOF.zip index 27609d19e74936ec615d7461811cd3118b331420..5f6b83918689def59337fbbfdb520d62b04aab8d 100644 GIT binary patch delta 3982 zcmZXXS5y-WlZF#&00HT}_f9~%ksd&LZvxVbG^Hsm(wj6x4T1sbp-PdCNdS@Fln#mz z0#Zdk2qLWC?)fivcjn?fGiPSb+&wcFLc@YBlR%m{ke#)<5`t=!8~_MsfUg31VYX5J zj<#&-i`l}D)ZCcwPkx?VJ?KpIl6UU+3KT`~EbfIxtlPEDdpXK|$X*>;NXv|wkF0I6 zNfS7Od3gEow(=#7ozu<62CX+podpKi9EkC65!2C6RK(iud^%A{A+^( zn;uYFjU^4-+^5xpKY5~@KT%n++;wN6FeBS5q`0Ao^P`ZwK)1UAICs2~;dDD#4vZi; z%;0<*$``bMt6Dv-wK^Kbij5|2TWsm7I85vT3Ig zryEQ@O*Y6KI}W?uxyf2bh`=;R{pkwxHF%USsI7=`bLh3_$ux6B400afUFO!gA!L?c z+*jbfI`fYUOj<(I6MHp(Q>v%UjJJyv1_z9?itKIKeAYL3O*fhGy7fsHRb*M!Jl~_O z-D!~h(QG5?sk%B%=jf`Y(X;12@C%1U`(*WwHHyub3X(7xDNyrPf1Zf7H03=LDq0MT z5{(%KN`jha(XeFPNznEiRL%_(z~(0YghM~7jJR1jB(BG9xJk6n<9#PkhT|k1=zynF8M)9R%Nm+)V zf(%M%1!h+lM%LVVz8H*BzuI%it~#MK*_Fv~z_yY#7w6F&ODo)U-gEh~-S7q(2GyN0mM-Z+7<0$)ONF>f{fn=2P|n0el3ge41f9PW&B1C>2tQ z1hzir+i^(Lo{wxMS}`=cH8V-V^*Idw3Kztl^BSq5;lhiTL^@JjG9UxvHx|aZ!)M#_ z$g60#j#nr8DHK1jQx%m3BX7jx3!Nk7ej*K@hcmPTeP}gbO(#XKDGmkf z&iq5<&(Y7lFn*}x_{eb-+UKKsJVvIoxJJhPd@=K`D&`N1ASipHl!OqPsCUU7e|0eN z9jX?Z_}eoFnE+>rz21dgg+B}p`n~t-4Wt(_w>QSMGkEp*Y-&TK`Klwboe(Gs3xgrf zZn~cQX>}RIIe)H5V?@b!XmtNvQ|epG_WsE>%*mB_P7w^G@T+Rs!@-rv$GY0YyG`er= zVUt=BOr>c0Nx0X0^bqGnWrE7#L+%LKY2_kn^0S@%_NT z0W1m@(46eVi8uWQ-Zsh%A?Noh^D!?7xILjWZ}PL#Hj!j!CAX)D;cr!Ku&Gemb)EYZ z2mcfo>(j7TNp~5s$FE5DtVV|6q*&Icsf`Ouj`GvQ-iF&gg&re$v4T)8IhaiP5#!o0DhwF)l@8k&`PlvA#xbcl}%+&*xe0RM1Z^ zvWHXss$l9;2S*C>xf@nFjM`S@-|tvj7PQR}IUJA^&slIyiPhib^RsTXgXTw9T^SDt z&Q+Lb=_#l#sw+Bz`CFEgzlQt08`;v5+h_)}3D#FL)FW9>G1y)mNos(3G5*ER&utAX&;I zecJ?b+ZOqRS$HivyB1ylylB(Z5~prvNKC>A002OM#J|WFZ<;E6Lk0jy(gFZ%f3sSq zP#H`2C!U^xA@Bnr2&Swk9pvV>{`VBHv}RRziepk-!i& zVKL7&y!KYqKKBN49dfY=!hIDin&sKSZVN-|Cv;jEqao^wk0aRfhk~l#WaaIHhuHky z4w0UJ7`-~`?tk~LU+DVS{zzr;_iyf9waq^!)5Y3ttb58qNLa9#RyKbtTfDjOdoB-) zW*?F=io8z+ObOicbNz#BQs&=IqH8}|37EGI-=@A)fgv~&Yt&>Mr}f#Dt5YP7@p)aV z4vE}xHIgn*8NLbRguLdP`OJ-4=3m|aT0G}@sXeYy$jjYk9_H1I{np~xnI9IB5}zDg zTXoPBTDpAHvIv_ER|@#Yj-xZ5&>)>Xeb~Cp5fdKqCa7>7N?0=)^J{Lils>nF9*7-& zNm(KUtOxafxnOb~YGi66) z_U%$Y3|23zgp{#IIbQ@G6wW$h z)_i!s8!b*!hKQ)XJt0(gx?yh++eW~A3QdSUUGPgqu|_ju?yA<{VcpwWtIP$hTAt-7GwjF0E5@x`y;>m4XbDva9A9SQEx)1G zsA3^2c;(Qc)e~e*)QZ;0K)dZl^G8ozM}rRcJ<*@rbD! z!%EX>gHlaR23Q7jn<46QHKcw3N=kZ~q=jSA&q}S#zK7p1HF@L5l2=#d*GKmTB5=pq z%lzFBxBA^v=Oxl<#uC{>s?P)$s$U6eDidSuMO$N6CaS0=i3xk9fT5`nq5nzP z=izJHw4zP8kV|CYsWX__Y^~jlnjCJz*Cg}Jc);;C9?$%Uy4XOnV&uxw{hu;#w;5Qe~iXI zN;CsP3%8eJpAXy?aOLpFlqE{FaE2JzA7>rN@L*)nK1|3k)<$xx^jzv38i5q(+Zgg0 zix(T@p)ybr;Cjkz&I{@BGFvRg0QZ{+;Cl8fg$9T0rMRgwiu7kpSzdyH2JOS2EJ(Q* zHW}eTR#dJV^|R4;>J>S+_4^j` zJ@BALo8de4Ma1H`u5^Od@B?%3AgV}B+^bZ$q|OFx!ZhFHMlX(o-+{YH*B5b!L)qtA ztcDlri%P|lEx|!3SP_u*1^do<4-xiWvH3<5%eVV8Zw|saB%=q+^a`iF(JXhOGyL+E zPq`mBPX`}qgR}OKY|`wML!(lDq$LWIpH~kw9Nx6-vP$^tsHM<1CDKT!G8 z!kT67IX8TPEyunPw2A6m<|_xk-46slQ^T_Hd8U2;f+*GYq1JOVN*I)9oe~>fZlp?L z3u#J=(ABO`%xjRVIJ|eYnUI|Z6)=Cf77!SW2%sME9)XSX6{W7b;~iFdzW!Vz?C;ycixcfj2xpzaF!haTJ#(994>!~^&r2>zeH zSD0Q!#|e)M`M3N(I??*PbZ_T>xBY*13jU?%zs3s!05BBrO&}Azi=JM3Wxp-r-(mmJ cMqUU{*MILo`WL$Z0Lfp60|9_nxBrd)3mPhk_W%F@ delta 4134 zcmV+>5ZUj=B={w;%>fd9g;!NSo!Ud~!H8p3bFH@uB{i znQ|#uDHr-blpc!j)|WM zIXsOw*yScP&hy@sGZVp8% zO@#QAn14;j9zqXqKg8yw#&NmC7G$YdtFmg1RqExc+9=j#xynk_65EhwWz3h#jpLf% zhj$!evsfll8J3i=rchR=B_$XPQXTcun5wD4!n9&3r@03?$j#yo{h1sW5YD8zF5&ch z&w)E(aXt1Le)T3v+iCbvc!uY4?Tj^>ZI4*9&42c&HG6U%3e2au=8jk9mmxn1`7Gp5 zYWWGh4goS#0$8TZ{9zu{6Z1K4(qT{pAQem=*2y{UETortF3O@S2-gC-2(BH{kT8$E z0~){{A!T_eJedr4!mnH0fR|I2cGEAZtL-uJ^y}y%VbQP0@l{ghn_8OYly_FrgWxPl z&3`snVUC*uslh86Jbeid&&4Z_hljCa)6lFwb0k~uMYOgK;MQjaz12b*vQaIb_FAJw z;f~O{6uEe1g-0;lK6ntO$osUXvxue>S~{tvhe@cHXfFLzwab-_31dh zILEyPne!~Ea)ApldUy~%?&<*?z#R8GIyrtsbNFZG-`61j0syW4IqpSBdtTzXD9)Ut zE|#z>3NM(jW5P=&ykf#vaLQ=z<`+oyqzhV|O|9$KpKSeUmG>9R?|XZmr@`Qbq<<}} z2`|XzVJJH=?60-smj2eK<^oBr%Wjc2R+vAD*WlmVxYhr7rrl#J{4`Em7f6cKLF>X5 zV0iJ2e%d~Ag0`M46q$*5F$;@4GjJJ}Cej2`czz9Nvvh$pOY<6F>|R?J=*&`g#YpF4 zjiVYH%yEJdtX?Ce15l<5Qr3g?DSvt%{~qHG>SL@OqzEvJl$$fF!kxe3qsUS`Lx=pV z)*{^R(4ekCZHJo#+c(IP!m7s&^n|8wbp|2#lok;ARZK6!>W?jvxxZ-c4T=_pO@_C{ zNwP;+CH8T3Pg4O}*Bj^r5cM!A<(5DF63FuCO1_7-h=zd0zDha5Ypgf=; z!srN~wFFfS-DyUzcY&cNGaq^q&_;ru0rY8t{spLuAjYGYJ?5cjG9OX^Z6fF^9(?8_ zUJUdTkM6k#PKS39bRAGX^?wZLZh|)Y=$X%lB0jyZL_nKq^nkVy^aDU!3Hr5Ry=GY7 z_UY00!jH@jg1!yt9)dasy6UI0K;1mTeh5fm`cZQ4oJOU4|ZoqxS(gMn~Q4iU8P z(7Erw`Oly27~9_Y;qrq$cQu6*mAlJtzwyTF(tr5%Z#~w$5y~9MGJU7MJA2~5v%h*# zk0x5IO)J52>7_6DnVUDUr|1z`QiGuote#VpvEC$b1HH^Laz55ugokLZxiyv>gqLVu z)+~Sazq^GZPTaqD_kZ5VeTIfG;n40#pM%*m$U2$(CY(&xH2B$LVJIWGn4>P{YcA${F6Nwz`HhRY;bPV>PG+l% z+2>+J7gKRDUv@Fyaxp)3F;`v8J1)lSaWWfSOvJ^ExR_%uW`EAbe8<7SiN?kJ7LpEQ z9rwTC{mi2?TzVvIoi(=@Ooy>ByLKbJ6lSb9VLzFN8#Eu!K0fqEGlmV?F5;)N*K#ku zg_Pp7+wkqn`&wqHtzL_Upj}?NYx@mm+)IBKOij~E_j6P8V=w*Pp&ILLdljiYf}GD= zP$Hi%Pb>L2xqq*b%hVB#qPJphzpRRnG*o#yBdhgtvEj1v360v%r+`V+VRw=fuxUwZ zxlobqW|uim?rb)RC|6)N8!a4zugw73cty1bFsjJaM5U}0YEr#qHzlVP^^p&;iLz=~ zcsxorYobzX$cEh(0}sKeW}~zMW57xcleTJCXb9~DK7SFjvA8eg*>X`%NJ_(LpWOl-#2u|6jx1z?H1eZr z(bOL)(cOHkfHc1!r_BEVP)h>@6aWAK2mpbFS5;t$mgM#Z0021<000>PlkgE6f8AGG zY#T)s9mi>twke5thVtkV5}J}?+@u7zfLK2^jltVEeo!6?W^HeXx0~45o2so88ZaNV zmLQNS9ui1=fItX|e$b|cpM(~Icu1ub5u|`3luD^;gb@+sBT(+lc-QOQApRN4GiT4a zbLY;T8Sgk?TZ7L19Z5viA+#OQf8t1H#e}k7EI*=Y_|73yS>FV9Vtn+;*04s+!uJhZ zwHb?=JdSKqP=pFM3E$Bgvz?Q5DB=O7b$CSMuB}CAn;juf9e$$mF(~+iBQdlu*S$mU z+YaAt>#F^s^-TZ7aFFx*d;DA|e4o?gDVh_rU7clLMqzg{wJHylmyejpzJPC! zo9DtU4Empz_O=`&C`?;&>n;YM^FW)^B_BY@=MM)1?nlsLw+}E8A-7LVGI3Ezq(>Mf z&1ABv5ha(%isA?(j3k+yf3RP~d@_~W2Rnu;E~JVWUk1n%es%k2d#NH9D*Bq|zz)c|;SV#-39&&2~9-LhNLSdxG4y<*iYS3R^{e^D?xxoJ-}H#z}d2GMI{>}_Bh_qb@XL} z)}ltJn+Vzj^_2v*>By<0dvx?L)K?LNU$$2hbO`Eee+W|XJCLB`P+v#T6x7WGeFpXQ z1f7F=6G8aQ-aycgP;VgUf*#ecP&W{?g5UCF#9ElhM#44NG`pK@blkOQ3!obb>H>5V zLH7Z=nV=+~dV*xV?{Pru2>KY%W`e%3;rBL)Pe+To=N)hpxP_oeKrIBF0dy-tbAVb2 z`lUw8e-(l|K^s9E0o_JWC!j3^_3CO!S0A@)(H{cTLC`mVwh?quN59+YZDK9@3(!`A z>fp%VPSCvrC*Jvf>3B!O56j;*9_{JO&A<2b!3$`xTi)`=PpzK^P`R*)^l-+JN=`nt z#&-EK4woGi1;ycXzJ$;?X6#jWEWDTOwrON8f5!V&4Y8TE+8FLuc49MGRyKdi%v01F z-o3N)ZkJ29p^U3@XS0d9>u$!(xFTj|=K&Mb?L4A0#yeasiRao{dUKm-J^Dr^?pnhf zYEbOSv_WAIy&N`I+2FF%!t|LKgr2f6uUeQ7EzFk|=AwnEx0#u(7N*z2JYiuDS(ukC zf6Orp^RMslkg)Hr%CZ`~~_;e$Cv9OgwOn@Z%^9aaOMx5DoB z`GNFi;p~cDIMRZWip%1ETX@JdlHJ}}e{B{PWjOMEaS3YHWzax_E*@E7yShyg^<~5n zubj%n(?T|BiI*GBCrtNJs!8&B-R$=6Y6WLq+@DH_ULliXT^5o0a~tycAQ#%h1+XfoNq0)s43NRT(v@Byt6y($)QIoBneSTQY9NYPC0YyjTs*p@_5B%p? zMI>w0D~u%NRaKJRo|G)QR~vY5Hbqso(~0hnk-t(gF`G?iS@sckZ_w@Qbw0p8itZ1? zU!Pu&Kf=3%ku>Q*^=O%l#aK4z1o46CKa-pgMg_uyz&XQ{=MZ8BUwE3)yXKQm5f%=8 zg;!NF9*a641&X>F9*a6J3fSu{(*a1*W0RkTY6aWAK z2mpbFS5;t$mgM#Z0021<000>PBme*a00000AP4{eA_|l65hpHA(Nvnd=GXyF(Nvnd k=GXzPAUz+r=GXyHO9ci10000400aP&0RR9`5dZ)H08xtkJpcdz