Poshc2 Payloads CyberChef Recipes:
-------------------------------- .BAT & .HTA --------------------------------
-------------------------------- .XML --------------------------------
-------------------------------- .CS --------------------------------
Sharp_posh_Stager.cs
-------------------------------- .B64 --------------------------------
Sharp_v4_x86_Shellcode.b64 & Sharp_v4_x64_Shellcode.b64 https://gchq.github.io/CyberChef/#recipe=From_Base64('A-Za-z0-9%2B/%3D',true)Remove_null_bytes()Regular_expression('User%20defined','%5Ba-z0-9/%5C%5C%2B%3D%5D%7B400,%7D',true,true,false,false,false,false,'List%20matches')From_Base64('A-Za-z0-9%2B/%3D',true)Remove_null_bytes()Regular_expression('User%20defined','Host.*%5C%5Cs(.*)',true,true,false,false,false,false,'List%20matches')
Posh_v4_x86_Shellcode.b64 & Posh_v4_x64_Shellcode.b64 & Posh_v2_x86_Shellcode.b64 & Posh_v2_x64_Shellcode.b64 https://gchq.github.io/CyberChef/#recipe=Regular_expression('User%20defined','%5Ba-z0-9/%5C%5C%5C%5C%2B%3D%5D%7B300,%7D',true,true,false,false,false,false,'List%20matches')From_Base64('A-Za-z0-9%2B/%3D',true)Remove_null_bytes()Regular_expression('User%20defined','%5Ba-z0-9/%5C%5C%5C%5C%2B%3D%5D%7B300,%7D',true,true,false,false,false,false,'List%20matches')From_Base64('A-Za-z0-9%2B/%3D',true)Remove_null_bytes()Regular_expression('User%20defined','%5Ba-z0-9/%5C%5C%5C%5C%2B%3D%5D%7B300,%7D',true,true,false,false,false,false,'List%20matches')From_Base64('A-Za-z0-9%2B/%3D',true)Gunzip()
-------------------------------- .BIN --------------------------------
Posh_v4_x86_Shellcode.bin & Posh_v4_x64_Shellcode.bin & Posh_v2_x86_Shellcode.bin & Posh_v2_x64_Shellcode.bin https://gchq.github.io/CyberChef/#recipe=Remove_null_bytes()Regular_expression('User%20defined','%5Ba-z0-9/%5C%5C%2B%3D%5D%7B400,%7D',true,true,false,false,false,false,'List%20matches')From_Base64('A-Za-z0-9%2B/%3D',true)Remove_null_bytes()Regular_expression('User%20defined','%5Ba-z0-9/%5C%5C%2B%3D%5D%7B400,%7D',true,true,false,false,false,false,'List%20matches')From_Base64('A-Za-z0-9%2B/%3D',true)Gunzip()
-------------------------------- .SH & .PY --------------------------------
py_dropper.sh & py_dropper.py https://gchq.github.io/CyberChef/#recipe=Regular_expression('User%20defined','%5Ba-z0-9/%5C%5C%5C%5C%5C%5C%5C%5C%2B%3D%5D%7B300,%7D',true,true,false,false,false,false,'List%20matches')From_Base64('A-Za-z0-9%2B/%3D',true)
-------------------------------- .DLL -------------------------------- Sharp_v4_x86.dll & Sharp_v4_x64.dll https://gchq.github.io/CyberChef/#recipe=Remove_null_bytes()Regular_expression('User%20defined','%5Ba-z0-9/%5C%5C%2B%3D%5D%7B400,%7D',true,true,false,false,false,false,'List%20matches')From_Base64('A-Za-z0-9%2B/%3D',true)Remove_null_bytes()Regular_expression('User%20defined','Host.*%5C%5Cs*(.*)',true,true,false,false,false,false,'List%20matches')
Posh_v4_x86.dll & Posh_v4_x64.dll & Posh_v2_x86.dll & Posh_v2_x64.dll https://gchq.github.io/CyberChef/#recipe=Remove_null_bytes()Regular_expression('User%20defined','%5Ba-z0-9/%5C%5C%2B%3D%5D%7B400,%7D',true,true,false,false,false,false,'List%20matches')From_Base64('A-Za-z0-9%2B/%3D',true)Remove_null_bytes()Regular_expression('User%20defined','%5Ba-z0-9/%5C%5C%2B%3D%5D%7B400,%7D',true,true,false,false,false,false,'List%20matches')From_Base64('A-Za-z0-9%2B/%3D',true)Gunzip()
-------------------------------- .JS --------------------------------
-------------------------------- .C --------------------------------
-------------------------------- MACRO -------------------------------- Macro.txt https://gchq.github.io/CyberChef/#recipe=Regular_expression('User%20defined','%22(.*?)%22',true,true,false,false,false,false,'List%20capture%20groups')Remove_whitespace(true,true,true,true,true,false)From_Base64('A-Za-z0-9%2B/%3D',true)Remove_null_bytes()Regular_expression('User%20defined','%5Ba-z0-9/%5C%5C%5C%5C%2B%3D%5D%7B300,%7D',true,true,false,false,false,false,'List%20matches')From_Base64('A-Za-z0-9%2B/%3D',true)Gunzip()
-------------------------------- .EXE --------------------------------
Posh32.exe & Posh32_migrate.exe & Posh64.exe & Posh64_migrate.exe https://gchq.github.io/CyberChef/#recipe=Remove_null_bytes()Regular_expression('User%20defined','%5Ba-z0-9/%5C%5C%2B%3D%5D%7B400,%7D',true,true,false,false,false,false,'List%20matches')From_Base64('A-Za-z0-9%2B/%3D',true)Remove_null_bytes()Regular_expression('User%20defined','%5Ba-z0-9/%5C%5C%2B%3D%5D%7B400,%7D',true,true,false,false,false,false,'List%20matches')From_Base64('A-Za-z0-9%2B/%3D',true)Gunzip()