Ironsquirrel project aims at delivering browser exploits to the victim browser in an encrypted fashion. Ellyptic-curve Diffie-Hellman (secp256k1) is used for key agreement and AES is used for encryption.
By delivering the exploit code (and shellcode) to the victim in an encrypted way, the attack can not be replayed. Meanwhile the HTML/JS source is encrypted thus reverse engineering the exploit is significantly harder.
+ nokogiri and gibberish gems
+ Ebowla https://github.com/Genetic-Malware/Ebowla
git clone https://github.com/MRGEffitas/Ironsquirrel && cd Ironsquirrel
sudo cp *.* /var/www/html/
ruby IRONSQUIRREL.rb --exploit full_path_to_exploit