All language subtitles for 7. Generating An Undetectable Backdoor Using TheFatRat (1)

af Afrikaans
ak Akan
sq Albanian
am Amharic
ar Arabic
hy Armenian
az Azerbaijani
eu Basque
be Belarusian
bem Bemba
bn Bengali
bh Bihari
bs Bosnian
br Breton
bg Bulgarian
km Cambodian
ca Catalan
ceb Cebuano
chr Cherokee
ny Chichewa
zh-CN Chinese (Simplified)
zh-TW Chinese (Traditional)
co Corsican
hr Croatian
cs Czech
da Danish
nl Dutch
en English
eo Esperanto
et Estonian
ee Ewe
fo Faroese
tl Filipino
fi Finnish
fr French
fy Frisian
gaa Ga
gl Galician
ka Georgian
de German
el Greek
gn Guarani
gu Gujarati
ht Haitian Creole
ha Hausa
haw Hawaiian
iw Hebrew
hi Hindi
hmn Hmong
hu Hungarian
is Icelandic
ig Igbo
id Indonesian
ia Interlingua
ga Irish
it Italian
ja Japanese
jw Javanese
kn Kannada
kk Kazakh
rw Kinyarwanda
rn Kirundi
kg Kongo
kri Krio (Sierra Leone)
ku Kurdish
ckb Kurdish (Soranรฎ)
ky Kyrgyz
lo Laothian
la Latin
lv Latvian
ln Lingala
lt Lithuanian
loz Lozi
lg Luganda
ach Luo
lb Luxembourgish
mk Macedonian
mg Malagasy
ms Malay
ml Malayalam
mt Maltese
mi Maori
mr Marathi
mfe Mauritian Creole
mo Moldavian
mn Mongolian
my Myanmar (Burmese)
sr-ME Montenegrin
ne Nepali
pcm Nigerian Pidgin
nso Northern Sotho
no Norwegian
nn Norwegian (Nynorsk)
oc Occitan
or Oriya
om Oromo
ps Pashto
pl Polish
pt-BR Portuguese (Brazil)
pt Portuguese (Portugal)
pa Punjabi
qu Quechua
ro Romanian
rm Romansh
nyn Runyakitara
ru Russian
sm Samoan
gd Scots Gaelic
sr Serbian
sh Serbo-Croatian
st Sesotho
tn Setswana
crs Seychellois Creole
sn Shona
sd Sindhi
si Sinhalese
sk Slovak
sl Slovenian
so Somali
es Spanish
es-419 Spanish (Latin American)
su Sundanese
sw Swahili
sv Swedish
tg Tajik
ta Tamil
tt Tatar
te Telugu
th Thai
ti Tigrinya
to Tonga
lua Tshiluba
tum Tumbuka
tr Turkish
tk Turkmen
tw Twi
ug Uighur
uk Ukrainian
ur Urdu
uz Uzbek
vi Vietnamese
cy Welsh
wo Wolof
xh Xhosa
yi Yiddish
yo Yoruba
zu Zulu

Original subtitles

Okay, now that we have TheFatRat loaded, let's see how we can use it to generate an undetectable backdoor.

Now you can see the tool can be used to do many more things, like it creates an a backdoor for Android

and combining a backdoor with another file but we're not going to be talking about that now.

We're gonna go over that later on in the course.

But for now we're interested into creating an undetectable backdoor.

And the one I'm gonna use is Creating one with PwnWinds which actually uses PowerShell.

So this is number '06' right here, so all I have to do is just enter '06' or '6'

and that will take me to PwnWinds, which gives me even even more options to generate the backdoor.

Now the backdoor generated with this uses PowerShell

and PowerShell is basically, a framework made by Windows,

which a kind of expands on to the basic DOS commands.

So it basically, gives you more Shell commands that can be used to automate tasks

and run things on Windows Operating Systems.

Powershell comes in pre-installed with all Windows machines after Windows 7.

So you can guarantee that it's going to work on all Windows computers,

if they're running Windows 7 and up.

I'm gonna 'Create a bat', which is an executable type

and that's gonna use PowerShell to inject the backdoor and give us the Reverse Shell.

The other options will still use PowerShell but we'll create a slightly different backdoor.

For example, you can see this one will attempt to embed the backdoor with a PDF

but it won't work against all systems.

You'll see that this one will use 'C', this one will use 'Apache',

this one will use 'C#' but for our one, we're just going to use a basic BAT file with PowerShell

and it should be able to bypass antivirus programs.

So I'm gonna go with number '1' which uses a bat file with PowerShell

and the reason why I'm going with it because I've actually already tested the others

and they get detected by at least an antivirus programs, so I'm gonna go with number '1'.

And then you can see that the tool is really nice because it already tells us

our local IP, our real IP and our Hostname, now we'll talk about the real IP and all of that later on.

For now all that, we're interested in is our local IP and when we were using Veil,

we had to run 'ifconfig' to see what's our local IP.

So remember we had to split the screen and do 'ifconfig'

and then we can see that our local IP is '10.20.14.213'.

But in here it's actually given a start already, so we can just give it straight away

and we don't have to do set, so remember with Veil,

we had to say set something equals something and all that.

For now we can just give it the IP straight away.

So it's asking for the 'LHOST', which is my local IP and that's '10.20.14.213'

and then it's asking me for the Port to be used for the reverse connection

and I'm going to set that to 8080

and then it's asking me what do I want to call the file and I'm just gonna call it 'rev_https_8080_'

and I'm gonna put 'fr' at the end for FatRat so we know that this was generated using TheFatRat.

So I'm gonna hit 'Enter'

and then it's gonna ask me what type of Payload do I want to use.

So if you look at these, you'll see that they're actually kind of similar to the Payloads in Veil-Evasion.

Especially, the last parts, so you can see that we have 'Meterpreter payloads'

and you can see that we have a 'reverse_tcp' and we have a 'reverse_http' and if we scroll down,

we have the 'meterpreterreverse_https', which is the same payload that we used with Veil-Evasion.

So again, essentially, we're generating the exact same payload which is gonna give us

the exact same access to the computer.

The only difference is the way that this payload is going to be delivered

and executed on the target computer.

So I'm gonna click on 'OK' and again just like Veil-Evasion,

TheFatRat will actually use 'Metasploit' framework to generate the payload.

And now it's telling me that the payload is saved to the output folder and that's it it's telling me do I want to 'Exit'

and I'm gonna say 'Yes' I'm done with you thank you.

And that's it, we're out of TheFatRat.

Now what I wanna do is I wanna just check

and make sure that this backdoor is not detected by any antivirus programs.

So I'm gonna go down and I'm gonna go on my browser.

I'm gonna upload a file

and the file is going to be stored in the output of TheFatRat.

So as you remember, TheFatRat was stored in 'opt', so I'm actually just clicking here on the pen in here.

And then I'm gonna give the full access to the full path where the backdoor is stored

and it start in the same location, where we create-- Where we installed TheFatRat.

So that was in '/opt/TheFatRat', if you remember

and you can see that we have all the files of TheFatRat right here.

Now if we go to 'output', there should be a file called 'output' and that's it right here.

And in it, we have our backdoor, which is called the 'rev_https_8080_fr.bat'

I'm gonna 'Open' this file and 'Scan' it

and as you can see the scan is done and it's only being detected by one antivirus program.

So it's bypassing actually, pretty much all the famous antivirus programs, it's bypassing McAfee,

it's bypassing Kaspersky, it's bypassing AVG, it's bypassing Norton right here.

It's pretty much bypassing everything, the only one that's detecting it, is IKARUS security.

So out of all the antivirus programs, we'll be able to bypass them all,

except for this particular antivirus program, which is a really, really good result.

So I'm gonna go back and we're gonna test the backdoor exactly the same way we tested our Veil backdoor.

So the first thing we're gonna do is we're gonna listen for incoming connections using 'msfconsole'

and we're gonna use the multi handler exactly the same way that we used it before.

Keep in mind that doesn't matter how we created the payload both of these payloads use

a 'Meterpreter_reverse_http' connection.

Therefore, when we want to listen for incoming connections, we're gonna use the same module

and the same payload.

So I'm gonna do this a bit quickly because we have done it and explained it before.

So the first thing I'm gonna do is 'use exploit/multi/handler'.

Then I'm gonna set the payload

and I have to set this exactly to the same payload that I created that I want to receive connections from.

And we created a 'meterpreter_reverse_http payload'.

So that's what we're gonna do to 'windows/meterpreter/reverse_https'

and then we're gonna set the 'LHOST' to the IP address of my machine.

Again, the same 'LHOST' that we set when we created the backdoor.

And we're gonna set the 'LPORT' to the part that we want to receive the connection from

and again the same 'LPORT' that we used when we created the backdoor, so it's 8080.

And now all is done, I'm just gonna do 'show options' and just to make sure everything is okay

and we can see that we were using a 'windows/meterpreter/reverse_https'.

We have the right IP and we have the right port, so everything is perfect.

Now I'm actually just gonna run one command before I run this exploit.

I'm gonna do 'save' and what this will do is it's gonna save all this config automatically,

so that the next time, I run 'msfconsole', I'll have the multi headler, Handler loaded already

and it will have all these options pre configured automatically so I won't have to do it again.

and now I'm just gonna do 'exploit' to run this module and wait for incoming connections on 8080.

The last step to do now is to just run the backdoor on my Windows machine

and I'm gonna deliver it using our very basic delivery method

and that's basically by placing our backdoor in our Web server

and then we're going to download it from the Windows machine.

So my backdoor is right here, I'm gonna 'copy' it and I'm gonna click on the address bar again,

put forward slash and then put var/www/html/' and we created a directory called 'evil-files'

that we stored our previous backdoor in and I'm gonna paste this backdoor in it

and that's it, we're good to go.

So we're just going to download it from the Windows machine, like we did in the previous video.

And before I can download it, I need to start the Apache server, the web server in Kali

and we're gonna do that using the command service.

Apache to start.

So I'm gonna go to my Windows machine

and I'm gonna navigate to my website, which is '10.20.14.213' the same IP as the Kali IP

and we're gonna go to the directory that contains the evil files which is called 'evil-files'.

And we can see our two backdoors, we see the one that we used before

and we have our new backdoor here which is called 'rev_https_8080_fr',

I'm going to click that, 'Download' it and then I'm gonna run it

and again, Windows is just telling, telling me be careful this is an executable,

so be careful when you're on files like this, it's not telling me that it's a virus

and it's not telling me that it contains malware, so I'm gonna run it anyway.

And if we come back here,

you'll see that we got a 'Meterpreter Shell'

and the connection came back again from the target computer, which is at '10.20.14. 206',

came back to us on Port 8080.

Now, like I said before, now, I basically, hacked the Windows machine, I can do anything I want to do on it.

So if I just do 'sysinfo' to confirm,

you can see we can get the information about that machine

and we can basically do anything that the target person can do on their computer.

Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.