Skip to content

Commit

Permalink
add a few strings + tweak process injection options.
Browse files Browse the repository at this point in the history
  • Loading branch information
rsmudge committed May 23, 2017
1 parent dd6fb85 commit 085153a
Showing 1 changed file with 5 additions and 0 deletions.
5 changes: 5 additions & 0 deletions APT/meterpreter.profile
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,9 @@ set sleeptime "100";
set spawnto_x86 "%windir%\\syswow64\\notepad.exe";
set spawnto_x64 "%windir%\\sysnative\\notepad.exe";

# process injection tweak
set hijack_remote_thread "false";

# propagate user-agent to all transactions
set useragent "Mozilla/5.0 (Windows NT 6.1; Trident/7.0; rv:11.0) like Gecko";

Expand All @@ -24,10 +27,12 @@ stage {

transform-x86 {
strrep "beacon.dll" "metsrv.dll";
append "stdapi_sys_process_getpid";
}

transform-x64 {
strrep "beacon.x64.dll" "metsrv.dll";
append "stdapi_sys_process_getpid";
}
}

Expand Down

0 comments on commit 085153a

Please sign in to comment.