SOFTWARE
SOFTWARE
A-B
C-D
E-F
G-H
I-J
K-L
M-N
O-P
Q-R
S-T
U-V
W-X
Invoke-PSImage
Invoke-PSImage takes a PowerShell script and embeds the bytes of the script into the pixels of a PNG image. It generates a one liner for executing either from a file of from the web. Example of usage is embedding the PowerShell code from the Invoke-Mimikatz module and embed it into an image file. By calling the image file from a macro for example, the macro will download the picture and execute the PowerShell code, which in this case will dump the passwords. [1]
ID: S0231
Type: TOOL
Platforms: Windows
Contributors: Christiaan Beek, @ChristiaanBeek
Version: 1.0
Created: 18 April 2018
Last Modified: 17 October 2018
Techniques Used
Domain | ID | Name | Use | |
---|---|---|---|---|
Enterprise | T1027 | Obfuscated Files or Information |
Invoke-PSImage can be used to embed a PowerShell script within the pixels of a PNG file.[1] |
References
×