Afrikaans
Akan
Albanian
Amharic
Arabic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
English
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Krio (Sierra Leone)
Kurdish
Kurdish (Soranรฎ)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Polish
Portuguese (Brazil)
Portuguese (Portugal)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
Okay, now that we have TheFatRat loaded, let's see how we can use it to generate an undetectable backdoor.
Now you can see the tool can be used to do many more things, like it creates an a backdoor for Android
and combining a backdoor with another file but we're not going to be talking about that now.
We're gonna go over that later on in the course.
But for now we're interested into creating an undetectable backdoor.
And the one I'm gonna use is Creating one with PwnWinds which actually uses PowerShell.
So this is number '06' right here, so all I have to do is just enter '06' or '6'
and that will take me to PwnWinds, which gives me even even more options to generate the backdoor.
Now the backdoor generated with this uses PowerShell
and PowerShell is basically, a framework made by Windows,
which a kind of expands on to the basic DOS commands.
So it basically, gives you more Shell commands that can be used to automate tasks
and run things on Windows Operating Systems.
Powershell comes in pre-installed with all Windows machines after Windows 7.
So you can guarantee that it's going to work on all Windows computers,
if they're running Windows 7 and up.
I'm gonna 'Create a bat', which is an executable type
and that's gonna use PowerShell to inject the backdoor and give us the Reverse Shell.
The other options will still use PowerShell but we'll create a slightly different backdoor.
For example, you can see this one will attempt to embed the backdoor with a PDF
but it won't work against all systems.
You'll see that this one will use 'C', this one will use 'Apache',
this one will use 'C#' but for our one, we're just going to use a basic BAT file with PowerShell
and it should be able to bypass antivirus programs.
So I'm gonna go with number '1' which uses a bat file with PowerShell
and the reason why I'm going with it because I've actually already tested the others
and they get detected by at least an antivirus programs, so I'm gonna go with number '1'.
And then you can see that the tool is really nice because it already tells us
our local IP, our real IP and our Hostname, now we'll talk about the real IP and all of that later on.
For now all that, we're interested in is our local IP and when we were using Veil,
we had to run 'ifconfig' to see what's our local IP.
So remember we had to split the screen and do 'ifconfig'
and then we can see that our local IP is '10.20.14.213'.
But in here it's actually given a start already, so we can just give it straight away
and we don't have to do set, so remember with Veil,
we had to say set something equals something and all that.
For now we can just give it the IP straight away.
So it's asking for the 'LHOST', which is my local IP and that's '10.20.14.213'
and then it's asking me for the Port to be used for the reverse connection
and I'm going to set that to 8080
and then it's asking me what do I want to call the file and I'm just gonna call it 'rev_https_8080_'
and I'm gonna put 'fr' at the end for FatRat so we know that this was generated using TheFatRat.
So I'm gonna hit 'Enter'
and then it's gonna ask me what type of Payload do I want to use.
So if you look at these, you'll see that they're actually kind of similar to the Payloads in Veil-Evasion.
Especially, the last parts, so you can see that we have 'Meterpreter payloads'
and you can see that we have a 'reverse_tcp' and we have a 'reverse_http' and if we scroll down,
we have the 'meterpreterreverse_https', which is the same payload that we used with Veil-Evasion.
So again, essentially, we're generating the exact same payload which is gonna give us
the exact same access to the computer.
The only difference is the way that this payload is going to be delivered
and executed on the target computer.
So I'm gonna click on 'OK' and again just like Veil-Evasion,
TheFatRat will actually use 'Metasploit' framework to generate the payload.
And now it's telling me that the payload is saved to the output folder and that's it it's telling me do I want to 'Exit'
and I'm gonna say 'Yes' I'm done with you thank you.
And that's it, we're out of TheFatRat.
Now what I wanna do is I wanna just check
and make sure that this backdoor is not detected by any antivirus programs.
So I'm gonna go down and I'm gonna go on my browser.
I'm gonna upload a file
and the file is going to be stored in the output of TheFatRat.
So as you remember, TheFatRat was stored in 'opt', so I'm actually just clicking here on the pen in here.
And then I'm gonna give the full access to the full path where the backdoor is stored
and it start in the same location, where we create-- Where we installed TheFatRat.
So that was in '/opt/TheFatRat', if you remember
and you can see that we have all the files of TheFatRat right here.
Now if we go to 'output', there should be a file called 'output' and that's it right here.
And in it, we have our backdoor, which is called the 'rev_https_8080_fr.bat'
I'm gonna 'Open' this file and 'Scan' it
and as you can see the scan is done and it's only being detected by one antivirus program.
So it's bypassing actually, pretty much all the famous antivirus programs, it's bypassing McAfee,
it's bypassing Kaspersky, it's bypassing AVG, it's bypassing Norton right here.
It's pretty much bypassing everything, the only one that's detecting it, is IKARUS security.
So out of all the antivirus programs, we'll be able to bypass them all,
except for this particular antivirus program, which is a really, really good result.
So I'm gonna go back and we're gonna test the backdoor exactly the same way we tested our Veil backdoor.
So the first thing we're gonna do is we're gonna listen for incoming connections using 'msfconsole'
and we're gonna use the multi handler exactly the same way that we used it before.
Keep in mind that doesn't matter how we created the payload both of these payloads use
a 'Meterpreter_reverse_http' connection.
Therefore, when we want to listen for incoming connections, we're gonna use the same module
and the same payload.
So I'm gonna do this a bit quickly because we have done it and explained it before.
So the first thing I'm gonna do is 'use exploit/multi/handler'.
Then I'm gonna set the payload
and I have to set this exactly to the same payload that I created that I want to receive connections from.
And we created a 'meterpreter_reverse_http payload'.
So that's what we're gonna do to 'windows/meterpreter/reverse_https'
and then we're gonna set the 'LHOST' to the IP address of my machine.
Again, the same 'LHOST' that we set when we created the backdoor.
And we're gonna set the 'LPORT' to the part that we want to receive the connection from
and again the same 'LPORT' that we used when we created the backdoor, so it's 8080.
And now all is done, I'm just gonna do 'show options' and just to make sure everything is okay
and we can see that we were using a 'windows/meterpreter/reverse_https'.
We have the right IP and we have the right port, so everything is perfect.
Now I'm actually just gonna run one command before I run this exploit.
I'm gonna do 'save' and what this will do is it's gonna save all this config automatically,
so that the next time, I run 'msfconsole', I'll have the multi headler, Handler loaded already
and it will have all these options pre configured automatically so I won't have to do it again.
and now I'm just gonna do 'exploit' to run this module and wait for incoming connections on 8080.
The last step to do now is to just run the backdoor on my Windows machine
and I'm gonna deliver it using our very basic delivery method
and that's basically by placing our backdoor in our Web server
and then we're going to download it from the Windows machine.
So my backdoor is right here, I'm gonna 'copy' it and I'm gonna click on the address bar again,
put forward slash and then put var/www/html/' and we created a directory called 'evil-files'
that we stored our previous backdoor in and I'm gonna paste this backdoor in it
and that's it, we're good to go.
So we're just going to download it from the Windows machine, like we did in the previous video.
And before I can download it, I need to start the Apache server, the web server in Kali
and we're gonna do that using the command service.
Apache to start.
So I'm gonna go to my Windows machine
and I'm gonna navigate to my website, which is '10.20.14.213' the same IP as the Kali IP
and we're gonna go to the directory that contains the evil files which is called 'evil-files'.
And we can see our two backdoors, we see the one that we used before
and we have our new backdoor here which is called 'rev_https_8080_fr',
I'm going to click that, 'Download' it and then I'm gonna run it
and again, Windows is just telling, telling me be careful this is an executable,
so be careful when you're on files like this, it's not telling me that it's a virus
and it's not telling me that it contains malware, so I'm gonna run it anyway.
And if we come back here,
you'll see that we got a 'Meterpreter Shell'
and the connection came back again from the target computer, which is at '10.20.14. 206',
came back to us on Port 8080.
Now, like I said before, now, I basically, hacked the Windows machine, I can do anything I want to do on it.
So if I just do 'sysinfo' to confirm,
you can see we can get the information about that machine
and we can basically do anything that the target person can do on their computer.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.