morphHTA - morphing Cobalt Strike PowerShell Evil HTA.

morphHTA – morphing Cobalt Strike PowerShell Evil HTA.

Disclaimer:
As usual, this code and tool should not be used for malicious purposes.

morphHTA is a morphing Cobalt Strike PowerShell Evil HTA generator.
Dependencies:
+ Python 2.7.x

Payload generator:
+ Max variable name length and randomly generated string length reduced to reduce overall size of HTA output:
python morph-hta.py –maxstrlen 4 –maxvarlen 4

+ Max split in chr() obfuscation, this reduces the number of additions we do to reduce length:
python morph-hta.py –maxnumsplit 4

morphHTA – Morphing Cobalt Strike’s evil.HTA

How to use:

Source: https://github.com/vysec