Path: blob/master/payloads/library/remote_access/win_smb-backdoor/README.md
3018 views
"Microsoft Windows" SMB Backdoor
Title: "Microsoft Windows" SMB Backdoor
Author: TW-D
Version: 1.0
Target: Microsoft Windows
Category: Remote Access
Description
Adds a user account (RD_User:RD_P@ssW0rD).
Adds this local user to local administrator group.
Shares "C:" directory (RD_SHARE).
Adds a rule to the firewall.
Sets a value to "LocalAccountTokenFilterPolicy" to access the "C:" with a local account.
Hides this user account.
Exploitation
The connection identifiers will be those defined by the values : RD_User and RD_P@ssW0rD.
The connection identifiers and the share name will be those defined by the values : RD_SHARE, RD_User and RD_P@ssW0rD.