File Transfers
- You got RCE on an IIS server via an upload and opened a reverse shell.
- PowerShell was blocked by AppLocker/WDAC, so scripts couldn’t be used.
- You found SeImpersonatePrivilege — lets a process impersonate higher-privilege accounts.( same as setuid binaries in linux systems???????)
- Web downloads (GitHub, Dropbox) and FTP were blocked, but outbound SMB (TCP 445) was allowed.
- You used an SMB file transfer to put a compiled binary (PrintSpoofer) on the machine, ran it, and escalated to admin.
Windows File Transfer Methods
Introduction
-
Fileless attacks: This kind of attack is where attackers use legitimate built in tools in windows to execute an attack; a malware is loaded into memory using these built in tools, and it wouldn’t be present in disk, there is a file transfer though. This kind of attack gave birth to a lot more like astaroth attacks; The Astaroth attack generally followed these steps: A malicious link in a spear-phishing email led to an LNK file. When double-clicked, the LNK file caused the execution of the WMIC tool with the "/Format" parameter, which allowed the download and execution of malicious JavaScript code. The JavaScript code, in turn, downloads payloads by abusing the Bitsadmin tool. All the payloads were base64-encoded and decoded using the Certutil tool resulting in a few DLL files. The regsvr32 tool was then used to load one of the decoded DLLs, which decrypted and loaded other files until the final payload, Astaroth, was injected into the Userinit process. Below is a graphical depiction of the attack.
Download Operations
Powershell base64 encode & decode
Confirming the MD5 Hashes Match
Powershell Web Downloads
- Powershell DownloadFile method
-
Powershell DownloadString - Fileless method
Powershell
SMB Downloads
FTP Downloads
Upload Operations
Powershell Web Uploads
SMB Uploads
Configuring WebDav Server
Installing WebDav Python modules
Using the WebDav Python module
Connecting to the Webdav Share
Linux File Transfer Methods
Download Operation
Base64 Encoding/ Decoding
Web Downloads
Fileless attacks in Linux
Downloads with Bash : /dev/tcp
SSH Downloads
Miscellaneous (Alternative) File Transfer Methods
Netcat in File Transfers
1) Listener on the compromised machine (receive)
2) Sender on the attack host (send)
Reverse direction (listen on attacker, victim connects)
If Netcat/Ncat aren't available: /dev/tcp (Bash)
In the next part we will talk about the alternatives in Windows
PowerShell Remoting (WinRM) — reliable Windows copy
RDP drive/clipboard redirection
- When connecting via RDP (mstsc, xfreerdp, rdesktop) enable drive sharing or clipboard.
- Linux example (xfreerdp) — expose local folder as \\tsclient\share:


