Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
cobaltstrike4.5_cdf-1 — cobaltstrike4.5版本破/解、去除checksum8特征、bypass BeaconEye、修复错误路径泄漏stage、增加totp双因子验证、修复CVE-2022-39197等 | Kitploit
Tools/GitHubGitHub/zeoday/cobaltstrike4.5_cdf-1
Penetration Testing FrameworksExploit FrameworksVulnerability AnalysisIDS/IPS EvasionReverse EngineeringCryptographyCommand and ControlBinary AnalysisAuthenticationRed TeamingPayload Development
1224 years agoNot yet reviewed
GitHubzeoday/cobaltstrike4.5_cdf-1

cobaltstrike4.5_cdf-1

cobaltstrike4.5版本破/解、去除checksum8特征、bypass BeaconEye、修复错误路径泄漏stage、增加totp双因子验证、修复CVE-2022-39197等

View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

cobaltstrike4.5_cdf

Crack cobaltstrike4.5, remove checksum8 feature, bypass BeaconEye, fix stage leakage via wrong path, add TOTP two-factor authentication, add encrypted username display, fix foreign spawn bug in 4.5, rename client configuration file, etc.

cobalt strike4.5 crack

cobaltstrike4.5 crack

[TOC]

Disclaimer / Agreement

This tool and article content are for security research only. Users assume all legal and related responsibilities arising from the use of this tool and article content! The author assumes no legal responsibility! If you engage in any illegal activities while using this tool or article content, you shall bear the corresponding consequences yourself. We will not assume any legal or joint liability. Otherwise, please do not install or use this tool. Your use of this tool or any other express or implied acceptance of this agreement shall be deemed as your having read and agreed to be bound by this agreement. When using this tool for security research, you should ensure that the behavior complies with laws and regulations and that sufficient authorization has been obtained. Do not use it against unauthorized targets.

Yes, I'm back, continuing the original cobaltstrike4.4_cdf: https://github.com/lovechoudoufu/about_cobaltstrike4.4_cdf This time it's version 4.5. The previous 4.4 was deleted by GitHub, and it's estimated that this project will also be deleted soon.

It is recommended to join the Telegram group. Subsequent updates and deleted projects can be downloaded from the group:

image-20220802163532221

Before use, please carefully verify the corresponding version's jar file hash.

CS Crack

Versions before 4.5

Certificate authentication process (using 4.3 as an example): slightly modified in version 4.5.

Official decryption keys for each version:

4.0 1be5be52c6255c33558e8a1cb667cb06
4.1 80e32a742060b884419ba0c171c9aa76
4.2 b20d487addd4713418f2d5a3ae02a7a0
4.3 3a4425490f389aeec312bdd758ad2b99
4.4 5e98194a01c6b48fa582a6a9fcbb92d6

cobaltstrike.auth authentication key file, RSA encrypted. Decrypted content:

4.3

-54, -2, -64, -45,	// file header
0, 77,	// subsequent length 
1, -55, -61, 127, 	// certificate time limit 29999999 (perpetual)
0, 0, 0, 1, 	// watermark
43, 	// version
16, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 
16, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 
16, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 
16, 58, 68, 37, 73, 15, 56, -102, -18, -61, 18, -67, -41, 88, -83, 43, -103

With each version update, the corresponding length increases by 17, and the key increases by 17 bytes.

In aggressor/Aggressor.class, License.checkLicenseGUI(new Authorization()); starts the license authentication:

image-20211101142121856

License.checkLicenseGUI uses isValid, isPerpetual, isExpired, isAlmostExpired to determine if the license is valid or expired:

image-20211101142738431

The Authorization class handles the cobaltstrike.auth file, reads the file content, and calls AuthCrypto().decrypt to process it:

image-20211101143829398

In the AuthCrypto() constructor, load() is called, which performs an MD5 check on resources/authkey.pub and then retrieves the RSA public key:

image-20211101144809625

In decrypt(), _decrypt is called to RSA-decrypt the content of the cobaltstrike.auth file using the public key, assigns the result to array var2, then converts it using DataParser to var3. readInt() retrieves the first four bytes of var3 for file header verification (-889274181 for 3.x; -889274157 for 4.x). Then readShort() gets two bytes as the length, assigned to var5, and var6 = var3.readBytes(var5) retrieves that length of content and returns it:

image-20211101145153818

In the Authorization class, the obtained arrayOfByte2 is the content after removing the first six bytes. It continues processing arrayOfByte2: first retrieves four bytes assigned to i, then four bytes assigned to watermark, then one byte assigned to b1. It checks if b1 < 43, if i == 29999999. In common/ListenerConfig, when watermark is 0, an antivirus detection watermark is added:

image-20211101152338045

image-20211101152000407

After removing the first six bytes, then removing the nine bytes for i, watermark, b1, the remaining content is the keys from 4.0 to 4.3, structured as: 16, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20:

            byte b2 = dataParser.readByte();	// get 1 byte, i.e., 16
            byte[] arrayOfByte3 = dataParser.readBytes(b2);		// get 16 bytes, which is the key for 4.0
            byte b3 = dataParser.readByte();	// get 1 byte, i.e., 16
            byte[] arrayOfByte4 = dataParser.readBytes(b3);		// get 16 bytes, which is the key for 4.1
            byte b4 = dataParser.readByte();	// get 1 byte, i.e., 16
            byte[] arrayOfByte5 = dataParser.readBytes(b4);		// get 16 bytes, which is the key for 4.2
            byte b5 = dataParser.readByte();	// get 1 byte, i.e., 16
            byte[] arrayOfByte6 = dataParser.readBytes(b5);		// get 16 bytes, which is the key for 4.3, assigned to arrayOfByte6

In the Authorization class, SleevedResource.Setup is called to process arrayOfByte6. In SleevedResource, the key is set as the decryption key for AES and HmacSHA256. In _readResource, this.data.decrypt(arrayOfByte1); is called for decryption, and the decrypted content is the dll files in /sleeve/:

image-20211101153935202

In SleeveSecurity, the key for AES and HmacSHA256 decryption is set. It uses the passed value to compute a 256-bit digest, then takes bytes 0-16 as the AES key and bytes 16-32 as the HmacSHA256 key:

image-20211101154127243

If the corresponding key is not obtained, the dll in the sleeve folder cannot be decrypted, and when connecting to the server, the error message "[Sleeve] Bad HMAC" will appear:

image-20211101160942103

For the HMAC decryption part, refer to: Cobaltstrike 4 crack: I issue a license to myself

Therefore, the key to a successful crack is the corresponding CS version key.

New Validation in Version 4.5

According to the official description, version 4.5 adds license security, which is indeed the case:

image-20220802145353409

Download Tool