@@ -221142,6 +221142,40 @@
221142
221142
"stage_refname": "windows/x64/custom",
221143
221143
"stager_refname": "windows/x64/reverse_winhttps"
221144
221144
},
221145
+ "payload_cmd/windows/http/x64/download_exec": {
221146
+ "name": "HTTP Fetch",
221147
+ "fullname": "payload/cmd/windows/http/x64/download_exec",
221148
+ "aliases": [],
221149
+ "rank": 300,
221150
+ "disclosure_date": null,
221151
+ "type": "payload",
221152
+ "author": [
221153
+ "Brendan Watters",
221154
+ "Muzaffer Umut ŞAHİN <
[email protected] >"
221155
+ ],
221156
+ "description": "Fetch and execute an x64 payload from an HTTP server.",
221157
+ "references": [],
221158
+ "platform": "Windows",
221159
+ "arch": "cmd",
221160
+ "rport": null,
221161
+ "autofilter_ports": null,
221162
+ "autofilter_services": null,
221163
+ "targets": null,
221164
+ "mod_time": "2024-01-03 14:46:15 +0000",
221165
+ "path": "/modules/payloads/adapters/cmd/windows/http/x64.rb",
221166
+ "is_install_path": true,
221167
+ "ref_name": "cmd/windows/http/x64/download_exec",
221168
+ "check": false,
221169
+ "post_auth": false,
221170
+ "default_credential": false,
221171
+ "notes": {},
221172
+ "session_types": false,
221173
+ "needs_cleanup": false,
221174
+ "payload_type": 8,
221175
+ "adapter_refname": "cmd/windows/http/x64",
221176
+ "adapted_refname": "windows/x64/download_exec",
221177
+ "staged": false
221178
+ },
221145
221179
"payload_cmd/windows/http/x64/encrypted_shell/reverse_tcp": {
221146
221180
"name": "HTTP Fetch, Windows Command Shell, Encrypted Reverse TCP Stager",
221147
221181
"fullname": "payload/cmd/windows/http/x64/encrypted_shell/reverse_tcp",
@@ -224149,6 +224183,40 @@
224149
224183
"stage_refname": "windows/x64/custom",
224150
224184
"stager_refname": "windows/x64/reverse_winhttps"
224151
224185
},
224186
+ "payload_cmd/windows/https/x64/download_exec": {
224187
+ "name": "HTTPS Fetch",
224188
+ "fullname": "payload/cmd/windows/https/x64/download_exec",
224189
+ "aliases": [],
224190
+ "rank": 300,
224191
+ "disclosure_date": null,
224192
+ "type": "payload",
224193
+ "author": [
224194
+ "Brendan Watters",
224195
+ "Muzaffer Umut ŞAHİN <
[email protected] >"
224196
+ ],
224197
+ "description": "Fetch and execute an x64 payload from an HTTPS server.",
224198
+ "references": [],
224199
+ "platform": "Windows",
224200
+ "arch": "cmd",
224201
+ "rport": null,
224202
+ "autofilter_ports": null,
224203
+ "autofilter_services": null,
224204
+ "targets": null,
224205
+ "mod_time": "2024-01-03 14:46:15 +0000",
224206
+ "path": "/modules/payloads/adapters/cmd/windows/https/x64.rb",
224207
+ "is_install_path": true,
224208
+ "ref_name": "cmd/windows/https/x64/download_exec",
224209
+ "check": false,
224210
+ "post_auth": false,
224211
+ "default_credential": false,
224212
+ "notes": {},
224213
+ "session_types": false,
224214
+ "needs_cleanup": false,
224215
+ "payload_type": 8,
224216
+ "adapter_refname": "cmd/windows/https/x64",
224217
+ "adapted_refname": "windows/x64/download_exec",
224218
+ "staged": false
224219
+ },
224152
224220
"payload_cmd/windows/https/x64/encrypted_shell/reverse_tcp": {
224153
224221
"name": "HTTPS Fetch, Windows Command Shell, Encrypted Reverse TCP Stager",
224154
224222
"fullname": "payload/cmd/windows/https/x64/encrypted_shell/reverse_tcp",
@@ -235709,6 +235777,40 @@
235709
235777
"stage_refname": "windows/x64/custom",
235710
235778
"stager_refname": "windows/x64/reverse_winhttps"
235711
235779
},
235780
+ "payload_cmd/windows/powershell/x64/download_exec": {
235781
+ "name": "Powershell Exec",
235782
+ "fullname": "payload/cmd/windows/powershell/x64/download_exec",
235783
+ "aliases": [],
235784
+ "rank": 300,
235785
+ "disclosure_date": null,
235786
+ "type": "payload",
235787
+ "author": [
235788
+ "Spencer McIntyre",
235789
+ "Muzaffer Umut ŞAHİN <
[email protected] >"
235790
+ ],
235791
+ "description": "Execute an x64 payload from a command via PowerShell",
235792
+ "references": [],
235793
+ "platform": "Windows",
235794
+ "arch": "cmd",
235795
+ "rport": null,
235796
+ "autofilter_ports": null,
235797
+ "autofilter_services": null,
235798
+ "targets": null,
235799
+ "mod_time": "2022-05-27 16:41:25 +0000",
235800
+ "path": "/modules/payloads/adapters/cmd/windows/powershell/x64.rb",
235801
+ "is_install_path": true,
235802
+ "ref_name": "cmd/windows/powershell/x64/download_exec",
235803
+ "check": false,
235804
+ "post_auth": false,
235805
+ "default_credential": false,
235806
+ "notes": {},
235807
+ "session_types": false,
235808
+ "needs_cleanup": false,
235809
+ "payload_type": 8,
235810
+ "adapter_refname": "cmd/windows/powershell/x64",
235811
+ "adapted_refname": "windows/x64/download_exec",
235812
+ "staged": false
235813
+ },
235712
235814
"payload_cmd/windows/powershell/x64/encrypted_shell/reverse_tcp": {
235713
235815
"name": "Powershell Exec, Windows Command Shell, Encrypted Reverse TCP Stager",
235714
235816
"fullname": "payload/cmd/windows/powershell/x64/encrypted_shell/reverse_tcp",
@@ -239334,6 +239436,40 @@
239334
239436
"stage_refname": "windows/x64/custom",
239335
239437
"stager_refname": "windows/x64/reverse_winhttps"
239336
239438
},
239439
+ "payload_cmd/windows/smb/x64/download_exec": {
239440
+ "name": "SMB Fetch",
239441
+ "fullname": "payload/cmd/windows/smb/x64/download_exec",
239442
+ "aliases": [],
239443
+ "rank": 300,
239444
+ "disclosure_date": null,
239445
+ "type": "payload",
239446
+ "author": [
239447
+ "Spencer McIntyre",
239448
+ "Muzaffer Umut ŞAHİN <
[email protected] >"
239449
+ ],
239450
+ "description": "Fetch and execute an x64 payload from an SMB server.",
239451
+ "references": [],
239452
+ "platform": "Windows",
239453
+ "arch": "cmd",
239454
+ "rport": null,
239455
+ "autofilter_ports": null,
239456
+ "autofilter_services": null,
239457
+ "targets": null,
239458
+ "mod_time": "2025-02-07 15:59:31 +0000",
239459
+ "path": "/modules/payloads/adapters/cmd/windows/smb/x64.rb",
239460
+ "is_install_path": true,
239461
+ "ref_name": "cmd/windows/smb/x64/download_exec",
239462
+ "check": false,
239463
+ "post_auth": false,
239464
+ "default_credential": false,
239465
+ "notes": {},
239466
+ "session_types": false,
239467
+ "needs_cleanup": false,
239468
+ "payload_type": 8,
239469
+ "adapter_refname": "cmd/windows/smb/x64",
239470
+ "adapted_refname": "windows/x64/download_exec",
239471
+ "staged": false
239472
+ },
239337
239473
"payload_cmd/windows/smb/x64/encrypted_shell/reverse_tcp": {
239338
239474
"name": "SMB Fetch, Windows Command Shell, Encrypted Reverse TCP Stager",
239339
239475
"fullname": "payload/cmd/windows/smb/x64/encrypted_shell/reverse_tcp",
@@ -242341,6 +242477,40 @@
242341
242477
"stage_refname": "windows/x64/custom",
242342
242478
"stager_refname": "windows/x64/reverse_winhttps"
242343
242479
},
242480
+ "payload_cmd/windows/tftp/x64/download_exec": {
242481
+ "name": "TFTP Fetch",
242482
+ "fullname": "payload/cmd/windows/tftp/x64/download_exec",
242483
+ "aliases": [],
242484
+ "rank": 300,
242485
+ "disclosure_date": null,
242486
+ "type": "payload",
242487
+ "author": [
242488
+ "Brendan Watters",
242489
+ "Muzaffer Umut ŞAHİN <
[email protected] >"
242490
+ ],
242491
+ "description": "Fetch and execute an x64 payload from a TFTP server.",
242492
+ "references": [],
242493
+ "platform": "Windows",
242494
+ "arch": "cmd",
242495
+ "rport": null,
242496
+ "autofilter_ports": null,
242497
+ "autofilter_services": null,
242498
+ "targets": null,
242499
+ "mod_time": "2024-01-03 14:46:15 +0000",
242500
+ "path": "/modules/payloads/adapters/cmd/windows/tftp/x64.rb",
242501
+ "is_install_path": true,
242502
+ "ref_name": "cmd/windows/tftp/x64/download_exec",
242503
+ "check": false,
242504
+ "post_auth": false,
242505
+ "default_credential": false,
242506
+ "notes": {},
242507
+ "session_types": false,
242508
+ "needs_cleanup": false,
242509
+ "payload_type": 8,
242510
+ "adapter_refname": "cmd/windows/tftp/x64",
242511
+ "adapted_refname": "windows/x64/download_exec",
242512
+ "staged": false
242513
+ },
242344
242514
"payload_cmd/windows/tftp/x64/encrypted_shell/reverse_tcp": {
242345
242515
"name": "TFTP Fetch, Windows Command Shell, Encrypted Reverse TCP Stager",
242346
242516
"fullname": "payload/cmd/windows/tftp/x64/encrypted_shell/reverse_tcp",
@@ -262902,6 +263072,37 @@
262902
263072
"stage_refname": "windows/x64/custom",
262903
263073
"stager_refname": "windows/x64/reverse_winhttps"
262904
263074
},
263075
+ "payload_windows/x64/download_exec": {
263076
+ "name": "Windows Download Execute",
263077
+ "fullname": "payload/windows/x64/download_exec",
263078
+ "aliases": [],
263079
+ "rank": 300,
263080
+ "disclosure_date": null,
263081
+ "type": "payload",
263082
+ "author": [
263083
+ "Muzaffer Umut ŞAHİN <
[email protected] >"
263084
+ ],
263085
+ "description": "Downloads and executes the file from the specified url.",
263086
+ "references": [],
263087
+ "platform": "Windows",
263088
+ "arch": "x64",
263089
+ "rport": null,
263090
+ "autofilter_ports": null,
263091
+ "autofilter_services": null,
263092
+ "targets": null,
263093
+ "mod_time": "2025-08-12 11:39:44 +0000",
263094
+ "path": "/modules/payloads/singles/windows/x64/download_exec.rb",
263095
+ "is_install_path": true,
263096
+ "ref_name": "windows/x64/download_exec",
263097
+ "check": false,
263098
+ "post_auth": false,
263099
+ "default_credential": false,
263100
+ "notes": {},
263101
+ "session_types": false,
263102
+ "needs_cleanup": false,
263103
+ "payload_type": 1,
263104
+ "staged": false
263105
+ },
262905
263106
"payload_windows/x64/encrypted_shell/reverse_tcp": {
262906
263107
"name": "Windows Command Shell, Encrypted Reverse TCP Stager",
262907
263108
"fullname": "payload/windows/x64/encrypted_shell/reverse_tcp",
0 commit comments