shadowbrokers-exploits/windows/Resources/Pc/Payloads/winnt/payload_level4_x64.xml
2017-04-14 11:45:07 +02:00

130 lines
4.4 KiB
XML

<Payloads>
<Payload>
<Description>Standard TCP</Description>
<Name>PeddleCheap</Name>
<ShortName>Pc</ShortName>
<Arch>x64</Arch>
<Os>winnt</Os>
<BinType>sharedlib</BinType>
<Type>Level4</Type>
<BaseFile>Level4/x64-winnt/release/PC_Level4_dll</BaseFile>
<Persistence>Generic</Persistence>
<Extra name="Comms">Winsock</Extra>
<Extra name="CommsType">TCP</Extra>
<Extra name="Fc_Name">Level 4 TCP DLL</Extra>
<Extra name="Fc_OsFamily">Windows NT</Extra>
<Extra name="Fc_Architecture">x64</Extra>
</Payload>
<Payload>
<Description>HTTP Proxy</Description>
<Name>PeddleCheap</Name>
<ShortName>Pc</ShortName>
<Arch>x64</Arch>
<Os>winnt</Os>
<BinType>sharedlib</BinType>
<Type>Level4</Type>
<BaseFile>Level4/x64-winnt/release/PC_Level4_http_dll</BaseFile>
<Persistence>Generic</Persistence>
<Extra name="Comms">Winsock</Extra>
<Extra name="CommsType">HTTP</Extra>
<Extra name="Fc_Name">Level 4 HTTP DLL</Extra>
<Extra name="Fc_OsFamily">Windows NT</Extra>
<Extra name="Fc_Architecture">x64</Extra>
</Payload>
<Payload>
<Description>Standard TCP AppCompat-enabled</Description>
<Name>PeddleCheap</Name>
<ShortName>Pc</ShortName>
<Arch>x64</Arch>
<Os>winnt</Os>
<BinType>sharedlib</BinType>
<Type>Level4</Type>
<BaseFile>Level4/x64-winnt/release/PC_Level4_FRPA_dll</BaseFile>
<Persistence>AppCompat</Persistence>
<Extra name="Comms">Winsock</Extra>
<Extra name="CommsType">TCP</Extra>
<Extra name="Fc_Name">Level 4 TCP AppCompat DLL</Extra>
<Extra name="Fc_OsFamily">Windows NT</Extra>
<Extra name="Fc_Architecture">x64</Extra>
</Payload>
<Payload>
<Description>HTTP Proxy AppCompat-enabled</Description>
<Name>PeddleCheap</Name>
<ShortName>Pc</ShortName>
<Arch>x64</Arch>
<Os>winnt</Os>
<BinType>sharedlib</BinType>
<Type>Level4</Type>
<BaseFile>Level4/x64-winnt/release/PC_Level4_http_FRPA_dll</BaseFile>
<Persistence>AppCompat</Persistence>
<Extra name="Comms">Winsock</Extra>
<Extra name="CommsType">HTTP</Extra>
<Extra name="Fc_Name">Level 4 HTTP AppCompat DLL</Extra>
<Extra name="Fc_OsFamily">Windows NT</Extra>
<Extra name="Fc_Architecture">x64</Extra>
</Payload>
<Payload>
<Description>Standard TCP WinsockHelperApi-enabled</Description>
<Name>PeddleCheap</Name>
<ShortName>Pc</ShortName>
<Arch>x64</Arch>
<Os>winnt</Os>
<BinType>sharedlib</BinType>
<Type>Level4</Type>
<BaseFile>Level4/x64-winnt/release/PC_Level4_WSHA_dll</BaseFile>
<Persistence>WinsockHelperApi</Persistence>
<Extra name="Comms">Winsock</Extra>
<Extra name="CommsType">TCP</Extra>
<Extra name="Fc_Name">Level 4 TCP Winsock DLL</Extra>
<Extra name="Fc_OsFamily">Windows NT</Extra>
<Extra name="Fc_Architecture">x64</Extra>
</Payload>
<Payload>
<Description>HTTP Proxy WinsockHelperApi-enabled</Description>
<Name>PeddleCheap</Name>
<ShortName>Pc</ShortName>
<Arch>x64</Arch>
<Os>winnt</Os>
<BinType>sharedlib</BinType>
<Type>Level4</Type>
<BaseFile>Level4/x64-winnt/release/PC_Level4_http_WSHA_dll</BaseFile>
<Persistence>WinsockHelperApi</Persistence>
<Extra name="Comms">Winsock</Extra>
<Extra name="CommsType">HTTP</Extra>
<Extra name="Fc_Name">Level 4 HTTP Winsock DLL</Extra>
<Extra name="Fc_OsFamily">Windows NT</Extra>
<Extra name="Fc_Architecture">x64</Extra>
</Payload>
<Payload>
<Description>Standard TCP</Description>
<Name>PeddleCheap</Name>
<ShortName>Pc</ShortName>
<Arch>x64</Arch>
<Os>winnt</Os>
<BinType>exe</BinType>
<Type>Level4</Type>
<BaseFile>Level4/x64-winnt/release/PC_Level4_exe</BaseFile>
<Persistence>Generic</Persistence>
<Extra name="Comms">Winsock</Extra>
<Extra name="CommsType">TCP</Extra>
<Extra name="Fc_Name">Level 4 TCP EXE</Extra>
<Extra name="Fc_OsFamily">Windows NT</Extra>
<Extra name="Fc_Architecture">x64</Extra>
</Payload>
<Payload>
<Description>HTTP Proxy</Description>
<Name>PeddleCheap</Name>
<ShortName>Pc</ShortName>
<Arch>x64</Arch>
<Os>winnt</Os>
<BinType>exe</BinType>
<Type>Level4</Type>
<BaseFile>Level4/x64-winnt/release/PC_Level4_http_exe</BaseFile>
<Persistence>Generic</Persistence>
<Extra name="Comms">Winsock</Extra>
<Extra name="CommsType">HTTP</Extra>
<Extra name="Fc_Name">Level 4 HTTP EXE</Extra>
<Extra name="Fc_OsFamily">Windows NT</Extra>
<Extra name="Fc_Architecture">x64</Extra>
</Payload>
</Payloads>