1. Create a listener on covenant

    Untitled

  2. create a PowerShell payload in covenant

    Untitled

    Untitled

    Untitled

  3. using this script on windows

    https://github.com/samratashok/nishang/blob/master/Client/Out-Word.ps1

    Untitled

  4. go again to the listener but this time to the created one before

    Untitled

    Untitled

    Untitled

  5. now you can create a fishing email and hyperlink the doc file to be downloaded