Coder Social home page Coder Social logo

dn9uy3n / cve-2024-21412_water-hydra Goto Github PK

View Code? Open in Web Editor NEW

This project forked from lsr00ter/cve-2024-21412_water-hydra

0.0 0.0 0.0 4 KB

according to trendmicro's research

Home Page: https://www.trendmicro.com/en_us/research/24/b/cve202421412-water-hydra-targets-traders-with-windows-defender-s.html

HTML 66.89% Batchfile 33.11%

cve-2024-21412_water-hydra's Introduction

CVE-2024-21412_Water-Hydra

通过 CVE-2024-21412 传递恶意软件

usage

依次启动服务,并访问 web server

webserver

在文件夹内启动 web server: python -m http.server

  • Initial Access: 使用 Windows 高级查询语法(AQS)链接回 WebDAV 共享的 JPEG 木马。
  • Initial Access:使用 search: 协议来自定义 Windows 资源管理器窗口
    • 它使用 search: 应用协议搜索来执行照片搜索
    • 它使用 crumb 参数来限制搜索范围到恶意的 WebDAV 共享。
    • 它使用 DisplayName 元素来欺骗用户,使他们认为这是本地的下载文件夹。

samba-compose

在文件夹内执行 docker compose up

  • 使用 crazymax/samba docker 的 samba 服务器

loader

编写 a2.cmd 并压缩为 a2.zip 文件,放在 samba-compose/pictures 文件夹内

  • Execution: 利用 CVE-2024-21412 (ZDI-CAN-23100) 绕过 Microsoft Defender SmartScreen

CVE-2024-21412 围绕互联网快捷方式。这些.url 文件是简单的 INI 配置文件,它们采用“URL=”参数指向一个 URL。虽然.url 文件格式没有官方文档,但 URL 参数是这种文件类型所必需的唯一参数。

cve-2024-21412_water-hydra's People

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.