ALERT!
Click here to register with a few steps and explore all our cool stuff we have to offer!

Jump to content



Photo

CVE 2017-8570 to CVE 2017-11882 RE-BRANDED


  • Please log in to reply
CVE 2017-8570 to CVE 2017-11882 RE-BRANDED

#81

kr0vshenk0
kr0vshenk0
    Offline
    0
    Rep
    4
    Likes

    Member

  • PipPipPip
Posts: 60
Threads: 3
Joined: Jan 19, 2019
Credits: 0
Five years registered
#81

hs anyone review it? As op says it does take a lot of error and trial to undetect.


  • 0

#82

smithhats
smithhats
    Offline
    0
    Rep
    1
    Likes

    Advanced Member

  • PipPipPipPip
Posts: 108
Threads: 0
Joined: Apr 01, 2019
Credits: 0
Five years registered
#82

I shared my experience days ago about my team and i working to REFUD custom CVE some cluelessly said all manners of rubbish.

This is link to my thread https://www.nulled.t...loit-by-my-team

 

Now am going to show you a sample of a custom CVE

 

 

This is a file given to my group which is 21/32

 

Now after playing around we could clean it up to 6/32

 

 

Also some people said 2017-11882 is patched

Answer is "YES" but 11882 executes when the memory allocated is corrupted then it has 4.523 secs to execute command line.

But when you drop it from another RTF it has 8.193 secs to execute. Since microsoft words opens a WBK file. We just rename extension to plugin.wbk as seen below.

 

 

Here comes the trick to bypass Microsoft Patch. This was sold on the dark web for 4000 AED.

Everyone is now unto CVE 2018-0802, CVE 2018-8414, CVE 2018-8714 but the secret is that non works as much as CVE 11882. All you have to do is embed into CVE 2017-8570

 

CVE 2017-8570 is fully silent and FUD/UD in some cases. All attachable via any mail server, any email client and any chat forum.

CVE 2017-8570 

This link above proves that it works on an updated PC as of 09/14/2018

app.any.run PC are always updated and patch installed.

 

Now i will explain deeper. CVE 2017-8570 downloads CVE 2017-11882 as plugins.wbk and executes a HTA command which is asked to download a crypted LOKI bot and executed silently. 

 

 

This technique got me closely 200 bots in 2 days via email spreading

My Bot Chart: 

My Total Bots in 2days: 

 

So please for those saying exploits sellers are all SCAMS and FAKE. This is prove that FUD/UD exploits still exists. Just do the right research

 

 

My team is looking forward to more customers from nulled. 

 

Got an issue with SMTP? Get my PMTA guide here

 

https://www.nulled.t...0-inbox-rate/  Unlimited SMTP until the VPS is shutdown by its administrator.

ok thanks for share!!!


  • 0

#83

magiquenet213
magiquenet213
    Offline
    2
    Rep
    14
    Likes

    Advanced Member

Posts: 92
Threads: 7
Joined: Jul 08, 2015
Credits: 0
Eight years registered
#83

nice share thanks so ....... m


  • 0

Contact me via Telegram

https://t.me/tesseract0x


#84

I3lalHat
I3lalHat
    Offline
    0
    Rep
    1
    Likes

    New Member

Posts: 14
Threads: 0
Joined: Dec 29, 2018
Credits: 0
Five years registered
#84
Let me check. Thank you!!

  • 0

#85

yunmak
yunmak
    Offline
    0
    Rep
    0
    Likes

    Member

Posts: 33
Threads: 1
Joined: Feb 27, 2018
Credits: 0
Six years registered
#85

GREAT job!!! tyvm


  • 0

#86

Gam0ra
Gam0ra
    Offline
    2
    Rep
    7
    Likes

    Member

Posts: 45
Threads: 6
Joined: Mar 24, 2019
Credits: 0
Five years registered
#86

WOTTT


  • 0

#87

kassettebrahim
kassettebrahim
    Offline
    0
    Rep
    1
    Likes

    I am confused by suicide or the killing of all my people

Posts: 46
Threads: 0
Joined: Aug 16, 2018
Credits: 0
Five years registered
#87

ok


  • 0

#88

Eboy
Eboy
    Offline
    -1
    Rep
    1
    Likes

    Addicted

  • PipPipPipPipPip
Posts: 182
Threads: 1
Joined: Apr 18, 2019
Credits: 0

Five years registered
#88
Soo interesting

  • 0

#89

cccp666
cccp666
    Offline
    0
    Rep
    0
    Likes

    Lurker

Posts: 5
Threads: 0
Joined: Aug 28, 2019
Credits: 0
Four years registered
#89

Thanks man


  • 0

#90

mojetwoje
mojetwoje
    Offline
    0
    Rep
    0
    Likes

    Lurker

Posts: 5
Threads: 0
Joined: Aug 28, 2019
Credits: 0
Four years registered
#90

Thanks for the info


  • 0


 Users browsing this thread: