Malware Note
⌘Ctrlk
Malware Note
  • 恶意软件学习笔记
    • 服务
    • 启动项
    • 用户账户
    • DLL劫持
    • COM劫持
    • 映像劫持
    • 计划任务
    • WMI
    • Office
    • BITS Jobs
    • Rootkit
    • 未分类
    • LOLBin
    • Take a Test
    • createdump.exe
    • sihclient.exe
    • change.exe
    • ftp.exe
    • tpmtool.exe
    • tar.exe
    • curl.exe
    • IMEWDBLD.exe
    • Privileges
    • UAC Bypass
    • 漏洞
    • 错误配置
    • WMI
    • RPC
    • DCOM
    • HASH
    • Kerberos tickets
    • Office
    • LNK
    • PE
    • CHM
    • 注入
    • 反虚拟机/沙盒
    • SMB
    • 注入mstsc.exe
    • Mimikatz
    • NPLogonNotify
    • Tickets
    • 启动进程
    • 关闭WD
    • 绕过AMSI
    • MiniDumpWriteDump
    • Shellcode
    • SilentProcessExit
    • procdump
    • Task Manager/Process Explorer
    • Sqldumper
    • comsvcs.dll
    • WinPmem
    • ProcessDump.exe
    • Dumpert
    • BSOD
    • PPLdump
    • Hibernation
    • Stealer
    • Hidden Remote
    • Untitled
    • 鬼知道有什么用的小知识
由 GitBook 提供支持
For the complete documentation index, see llms.txt. This page is also available as Markdown.
  1. 1.0.0
  2. 获取用户密码或hash

SMB

使用恶意主题来窃取密码

LogoWindows 10 themes can be abused to steal Windows passwordsBleepingComputer

利用恶意pdf文件来窃取密码

LogoNTLM Credentials Theft via PDF Files - Check Point ResearchCheck Point Research

一个多种利用方法的工具

LogoGitHub - Greenwolf/ntlm_theft: A tool for generating multiple types of NTLMv2 hash theft files by Jacob Wilkin (Greenwolf)GitHub

上一页反虚拟机/沙盒下一页注入mstsc.exe

最后更新于 5年前