@@ -221142,6 +221142,40 @@
221142221142 "stage_refname": "windows/x64/custom",
221143221143 "stager_refname": "windows/x64/reverse_winhttps"
221144221144 },
221145+ "payload_cmd/windows/http/x64/download_exec": {
221146+ "name": "HTTP Fetch",
221147+ "fullname": "payload/cmd/windows/http/x64/download_exec",
221148+ "aliases": [],
221149+ "rank": 300,
221150+ "disclosure_date": null,
221151+ "type": "payload",
221152+ "author": [
221153+ "Brendan Watters",
221154+ "Muzaffer Umut ŞAHİN <
[email protected] >"
221155+ ],
221156+ "description": "Fetch and execute an x64 payload from an HTTP server.",
221157+ "references": [],
221158+ "platform": "Windows",
221159+ "arch": "cmd",
221160+ "rport": null,
221161+ "autofilter_ports": null,
221162+ "autofilter_services": null,
221163+ "targets": null,
221164+ "mod_time": "2024-01-03 14:46:15 +0000",
221165+ "path": "/modules/payloads/adapters/cmd/windows/http/x64.rb",
221166+ "is_install_path": true,
221167+ "ref_name": "cmd/windows/http/x64/download_exec",
221168+ "check": false,
221169+ "post_auth": false,
221170+ "default_credential": false,
221171+ "notes": {},
221172+ "session_types": false,
221173+ "needs_cleanup": false,
221174+ "payload_type": 8,
221175+ "adapter_refname": "cmd/windows/http/x64",
221176+ "adapted_refname": "windows/x64/download_exec",
221177+ "staged": false
221178+ },
221145221179 "payload_cmd/windows/http/x64/encrypted_shell/reverse_tcp": {
221146221180 "name": "HTTP Fetch, Windows Command Shell, Encrypted Reverse TCP Stager",
221147221181 "fullname": "payload/cmd/windows/http/x64/encrypted_shell/reverse_tcp",
@@ -224149,6 +224183,40 @@
224149224183 "stage_refname": "windows/x64/custom",
224150224184 "stager_refname": "windows/x64/reverse_winhttps"
224151224185 },
224186+ "payload_cmd/windows/https/x64/download_exec": {
224187+ "name": "HTTPS Fetch",
224188+ "fullname": "payload/cmd/windows/https/x64/download_exec",
224189+ "aliases": [],
224190+ "rank": 300,
224191+ "disclosure_date": null,
224192+ "type": "payload",
224193+ "author": [
224194+ "Brendan Watters",
224195+ "Muzaffer Umut ŞAHİN <
[email protected] >"
224196+ ],
224197+ "description": "Fetch and execute an x64 payload from an HTTPS server.",
224198+ "references": [],
224199+ "platform": "Windows",
224200+ "arch": "cmd",
224201+ "rport": null,
224202+ "autofilter_ports": null,
224203+ "autofilter_services": null,
224204+ "targets": null,
224205+ "mod_time": "2024-01-03 14:46:15 +0000",
224206+ "path": "/modules/payloads/adapters/cmd/windows/https/x64.rb",
224207+ "is_install_path": true,
224208+ "ref_name": "cmd/windows/https/x64/download_exec",
224209+ "check": false,
224210+ "post_auth": false,
224211+ "default_credential": false,
224212+ "notes": {},
224213+ "session_types": false,
224214+ "needs_cleanup": false,
224215+ "payload_type": 8,
224216+ "adapter_refname": "cmd/windows/https/x64",
224217+ "adapted_refname": "windows/x64/download_exec",
224218+ "staged": false
224219+ },
224152224220 "payload_cmd/windows/https/x64/encrypted_shell/reverse_tcp": {
224153224221 "name": "HTTPS Fetch, Windows Command Shell, Encrypted Reverse TCP Stager",
224154224222 "fullname": "payload/cmd/windows/https/x64/encrypted_shell/reverse_tcp",
@@ -235709,6 +235777,40 @@
235709235777 "stage_refname": "windows/x64/custom",
235710235778 "stager_refname": "windows/x64/reverse_winhttps"
235711235779 },
235780+ "payload_cmd/windows/powershell/x64/download_exec": {
235781+ "name": "Powershell Exec",
235782+ "fullname": "payload/cmd/windows/powershell/x64/download_exec",
235783+ "aliases": [],
235784+ "rank": 300,
235785+ "disclosure_date": null,
235786+ "type": "payload",
235787+ "author": [
235788+ "Spencer McIntyre",
235789+ "Muzaffer Umut ŞAHİN <
[email protected] >"
235790+ ],
235791+ "description": "Execute an x64 payload from a command via PowerShell",
235792+ "references": [],
235793+ "platform": "Windows",
235794+ "arch": "cmd",
235795+ "rport": null,
235796+ "autofilter_ports": null,
235797+ "autofilter_services": null,
235798+ "targets": null,
235799+ "mod_time": "2022-05-27 16:41:25 +0000",
235800+ "path": "/modules/payloads/adapters/cmd/windows/powershell/x64.rb",
235801+ "is_install_path": true,
235802+ "ref_name": "cmd/windows/powershell/x64/download_exec",
235803+ "check": false,
235804+ "post_auth": false,
235805+ "default_credential": false,
235806+ "notes": {},
235807+ "session_types": false,
235808+ "needs_cleanup": false,
235809+ "payload_type": 8,
235810+ "adapter_refname": "cmd/windows/powershell/x64",
235811+ "adapted_refname": "windows/x64/download_exec",
235812+ "staged": false
235813+ },
235712235814 "payload_cmd/windows/powershell/x64/encrypted_shell/reverse_tcp": {
235713235815 "name": "Powershell Exec, Windows Command Shell, Encrypted Reverse TCP Stager",
235714235816 "fullname": "payload/cmd/windows/powershell/x64/encrypted_shell/reverse_tcp",
@@ -239334,6 +239436,40 @@
239334239436 "stage_refname": "windows/x64/custom",
239335239437 "stager_refname": "windows/x64/reverse_winhttps"
239336239438 },
239439+ "payload_cmd/windows/smb/x64/download_exec": {
239440+ "name": "SMB Fetch",
239441+ "fullname": "payload/cmd/windows/smb/x64/download_exec",
239442+ "aliases": [],
239443+ "rank": 300,
239444+ "disclosure_date": null,
239445+ "type": "payload",
239446+ "author": [
239447+ "Spencer McIntyre",
239448+ "Muzaffer Umut ŞAHİN <
[email protected] >"
239449+ ],
239450+ "description": "Fetch and execute an x64 payload from an SMB server.",
239451+ "references": [],
239452+ "platform": "Windows",
239453+ "arch": "cmd",
239454+ "rport": null,
239455+ "autofilter_ports": null,
239456+ "autofilter_services": null,
239457+ "targets": null,
239458+ "mod_time": "2025-02-07 15:59:31 +0000",
239459+ "path": "/modules/payloads/adapters/cmd/windows/smb/x64.rb",
239460+ "is_install_path": true,
239461+ "ref_name": "cmd/windows/smb/x64/download_exec",
239462+ "check": false,
239463+ "post_auth": false,
239464+ "default_credential": false,
239465+ "notes": {},
239466+ "session_types": false,
239467+ "needs_cleanup": false,
239468+ "payload_type": 8,
239469+ "adapter_refname": "cmd/windows/smb/x64",
239470+ "adapted_refname": "windows/x64/download_exec",
239471+ "staged": false
239472+ },
239337239473 "payload_cmd/windows/smb/x64/encrypted_shell/reverse_tcp": {
239338239474 "name": "SMB Fetch, Windows Command Shell, Encrypted Reverse TCP Stager",
239339239475 "fullname": "payload/cmd/windows/smb/x64/encrypted_shell/reverse_tcp",
@@ -242341,6 +242477,40 @@
242341242477 "stage_refname": "windows/x64/custom",
242342242478 "stager_refname": "windows/x64/reverse_winhttps"
242343242479 },
242480+ "payload_cmd/windows/tftp/x64/download_exec": {
242481+ "name": "TFTP Fetch",
242482+ "fullname": "payload/cmd/windows/tftp/x64/download_exec",
242483+ "aliases": [],
242484+ "rank": 300,
242485+ "disclosure_date": null,
242486+ "type": "payload",
242487+ "author": [
242488+ "Brendan Watters",
242489+ "Muzaffer Umut ŞAHİN <
[email protected] >"
242490+ ],
242491+ "description": "Fetch and execute an x64 payload from a TFTP server.",
242492+ "references": [],
242493+ "platform": "Windows",
242494+ "arch": "cmd",
242495+ "rport": null,
242496+ "autofilter_ports": null,
242497+ "autofilter_services": null,
242498+ "targets": null,
242499+ "mod_time": "2024-01-03 14:46:15 +0000",
242500+ "path": "/modules/payloads/adapters/cmd/windows/tftp/x64.rb",
242501+ "is_install_path": true,
242502+ "ref_name": "cmd/windows/tftp/x64/download_exec",
242503+ "check": false,
242504+ "post_auth": false,
242505+ "default_credential": false,
242506+ "notes": {},
242507+ "session_types": false,
242508+ "needs_cleanup": false,
242509+ "payload_type": 8,
242510+ "adapter_refname": "cmd/windows/tftp/x64",
242511+ "adapted_refname": "windows/x64/download_exec",
242512+ "staged": false
242513+ },
242344242514 "payload_cmd/windows/tftp/x64/encrypted_shell/reverse_tcp": {
242345242515 "name": "TFTP Fetch, Windows Command Shell, Encrypted Reverse TCP Stager",
242346242516 "fullname": "payload/cmd/windows/tftp/x64/encrypted_shell/reverse_tcp",
@@ -262902,6 +263072,37 @@
262902263072 "stage_refname": "windows/x64/custom",
262903263073 "stager_refname": "windows/x64/reverse_winhttps"
262904263074 },
263075+ "payload_windows/x64/download_exec": {
263076+ "name": "Windows Download Execute",
263077+ "fullname": "payload/windows/x64/download_exec",
263078+ "aliases": [],
263079+ "rank": 300,
263080+ "disclosure_date": null,
263081+ "type": "payload",
263082+ "author": [
263083+ "Muzaffer Umut ŞAHİN <
[email protected] >"
263084+ ],
263085+ "description": "Downloads and executes the file from the specified url.",
263086+ "references": [],
263087+ "platform": "Windows",
263088+ "arch": "x64",
263089+ "rport": null,
263090+ "autofilter_ports": null,
263091+ "autofilter_services": null,
263092+ "targets": null,
263093+ "mod_time": "2025-08-12 11:39:44 +0000",
263094+ "path": "/modules/payloads/singles/windows/x64/download_exec.rb",
263095+ "is_install_path": true,
263096+ "ref_name": "windows/x64/download_exec",
263097+ "check": false,
263098+ "post_auth": false,
263099+ "default_credential": false,
263100+ "notes": {},
263101+ "session_types": false,
263102+ "needs_cleanup": false,
263103+ "payload_type": 1,
263104+ "staged": false
263105+ },
262905263106 "payload_windows/x64/encrypted_shell/reverse_tcp": {
262906263107 "name": "Windows Command Shell, Encrypted Reverse TCP Stager",
262907263108 "fullname": "payload/windows/x64/encrypted_shell/reverse_tcp",
0 commit comments