Executing ps
on the Markup machine doesn’t reveal any process resembling ‘wevtutil’. Because of this, as I reason, the script doesn’t execute and make to call to my attacking machine listening on port XXXX. Below is the full output of ps
on Markup.
Handles NPM(K) PM(K) WS(K) CPU(s) Id SI ProcessName
------- ------ ----- ----- ------ -- -- -----------
74 5 2444 4140 628 1 cmd
74 5 3300 4188 2776 1 cmd
72 5 2240 3676 3192 1 cmd
228 12 7424 8456 3808 1 cmd
77 5 2344 3932 0.00 4952 0 cmd
155 10 6312 12868 3184 1 conhost
155 11 6364 4180 3232 1 conhost
116 6 1204 4904 0.75 3796 0 conhost
156 10 7036 5744 3920 1 conhost
157 11 6352 12152 4368 1 conhost
155 10 6908 2884 0.39 4484 1 conhost
392 16 2260 5276 376 0 csrss
304 15 2136 5248 488 1 csrss
255 13 3936 13432 2732 0 dllhost
49 6 1520 4932 784 1 fontdrvhost
49 6 1264 4176 792 0 fontdrvhost
179 28 9504 3452 0.53 4640 1 httpd
499 49 18720 4180 1.30 4700 1 httpd
0 0 56 8 0 0 Idle
829 20 4684 12424 640 0 lsass
223 13 3104 10508 3048 0 msdtc
585 72 164864 140060 1864 0 MsMpEng
147 15 209940 41616 1676 0 mysqld
74 6 876 3180 4996 1 PING
753 34 73176 91492 2.73 3344 0 powershell
0 9 3832 6840 88 0 Registry
409 10 3700 7712 620 0 services
53 3 492 1220 288 0 smss
123 22 1948 7268 1588 0 sshd
129 9 2480 7804 2708 0 sshd
139 9 2480 7700 0.48 4948 0 sshd
184 9 1760 7596 328 0 svchost
427 9 2712 8896 340 0 svchost
217 11 1968 9544 344 0 svchost
85 5 876 3844 736 0 svchost
278 12 2892 9476 756 0 svchost
165 11 1736 7992 772 0 svchost
532 16 3312 9556 868 0 svchost
231 10 1692 6912 908 0 svchost
115 7 1228 5348 992 0 svchost
424 13 23684 27956 1004 0 svchost
325 17 3964 13224 1028 0 svchost
123 15 3164 7164 1052 0 svchost
234 13 2832 8212 1084 0 svchost
216 9 1960 7440 1092 0 svchost
384 31 5840 13884 1196 0 svchost
186 11 1844 7788 1288 0 svchost
115 7 1164 5756 1340 0 svchost
186 10 1772 8700 1416 0 svchost
454 17 3072 10888 1480 0 svchost
396 17 9032 21196 1500 0 svchost
242 25 3416 12288 1508 0 svchost
171 9 1956 7032 1516 0 svchost
136 8 1424 6204 1544 0 svchost
334 14 3856 10988 1564 0 svchost
118 7 1164 5516 1608 0 svchost
207 11 2260 8416 1660 0 svchost
207 12 1800 7484 1756 0 svchost
391 16 11448 20468 1764 0 svchost
227 13 2916 10840 1892 0 svchost
269 10 2228 8172 2200 0 svchost
163 10 2100 7696 2316 0 svchost
251 14 7276 11236 2756 0 svchost
107 7 2476 5552 3064 0 svchost
310 17 14104 26832 3648 0 svchost
131 8 2932 9436 4064 0 svchost
312 20 9328 14232 4144 0 svchost
124 7 1212 5632 4256 0 svchost
1206 0 192 144 4 0 System
210 12 1944 9692 3748 1 taskhostw
167 11 2896 10924 1668 0 VGAuthService
141 8 1684 6940 1652 0 vm3dservice
138 10 2292 8040 1972 1 vm3dservice
361 22 9440 21444 1692 0 vmtoolsd
201 16 4712 13664 3320 1 vmtoolsd
170 11 1472 6952 480 0 wininit
259 12 2528 11432 544 1 winlogon
311 15 7192 15848 2992 0 WmiPrvSE
I did try executing job.bat myself, but obviously this didn’t work since I don’t have admin privileges.
In addition, below is the output of schtasks
:
Folder: \
TaskName Next Run Time Status
======================================== ====================== ===============
INFO: There are no scheduled tasks presently available at your access level.
Folder: \Microsoft
TaskName Next Run Time Status
======================================== ====================== ===============
INFO: There are no scheduled tasks presently available at your access level.
Folder: \Microsoft\Windows
TaskName Next Run Time Status
======================================== ====================== ===============
INFO: There are no scheduled tasks presently available at your access level.
Folder: \Microsoft\Windows\.NET Framework
TaskName Next Run Time Status
======================================== ====================== ===============
.NET Framework NGEN v4.0.30319 N/A Ready
.NET Framework NGEN v4.0.30319 64 N/A Ready
.NET Framework NGEN v4.0.30319 64 Critic N/A Disabled
.NET Framework NGEN v4.0.30319 Critical N/A Disabled
Folder: \Microsoft\Windows\Active Directory Rights Management Services Client
TaskName Next Run Time Status
======================================== ====================== ===============
AD RMS Rights Policy Template Management N/A Disabled
AD RMS Rights Policy Template Management N/A Ready
Folder: \Microsoft\Windows\AppID
TaskName Next Run Time Status
======================================== ====================== ===============
PolicyConverter N/A Disabled
VerifiedPublisherCertStoreCheck N/A Disabled
Folder: \Microsoft\Windows\Application Experience
TaskName Next Run Time Status
======================================== ====================== ===============
Microsoft Compatibility Appraiser 12/4/2023 3:56:05 AM Ready
Folder: \Microsoft\Windows\Chkdsk
TaskName Next Run Time Status
======================================== ====================== ===============
ProactiveScan N/A Ready
SyspartRepair N/A Ready
Folder: \Microsoft\Windows\Customer Experience Improvement Program
TaskName Next Run Time Status
======================================== ====================== ===============
Consolidator 12/3/2023 12:00:00 PM Ready
Folder: \Microsoft\Windows\Data Integrity Scan
TaskName Next Run Time Status
======================================== ====================== ===============
Data Integrity Scan 12/23/2023 1:24:14 AM Ready
Data Integrity Scan for Crash Recovery N/A Ready
Folder: \Microsoft\Windows\Defrag
TaskName Next Run Time Status
======================================== ====================== ===============
ScheduledDefrag N/A Ready
Folder: \Microsoft\Windows\Device Information
TaskName Next Run Time Status
======================================== ====================== ===============
Device 12/4/2023 3:36:19 AM Ready
Folder: \Microsoft\Windows\Flighting
TaskName Next Run Time Status
======================================== ====================== ===============
INFO: There are no scheduled tasks presently available at your access level.
Folder: \Microsoft\Windows\Flighting\OneSettings
TaskName Next Run Time Status
======================================== ====================== ===============
RefreshCache 12/3/2023 4:03:05 PM Ready
Folder: \Microsoft\Windows\MUI
TaskName Next Run Time Status
======================================== ====================== ===============
LPRemove N/A Ready
Folder: \Microsoft\Windows\NetTrace
TaskName Next Run Time Status
======================================== ====================== ===============
GatherNetworkInfo N/A Ready
Folder: \Microsoft\Windows\PLA
TaskName Next Run Time Status
======================================== ====================== ===============
Server Manager Performance Monitor N/A Disabled
Folder: \Microsoft\Windows\Plug and Play
TaskName Next Run Time Status
======================================== ====================== ===============
Device Install Group Policy N/A Ready
Device Install Reboot Required N/A Ready
Sysprep Generalize Drivers N/A Ready
Folder: \Microsoft\Windows\PowerShell
TaskName Next Run Time Status
======================================== ====================== ===============
INFO: There are no scheduled tasks presently available at your access level.
Folder: \Microsoft\Windows\Server Manager
TaskName Next Run Time Status
======================================== ====================== ===============
CleanupOldPerfLogs N/A Ready
Folder: \Microsoft\Windows\Servicing
TaskName Next Run Time Status
======================================== ====================== ===============
StartComponentCleanup N/A Ready
Folder: \Microsoft\Windows\Shell
TaskName Next Run Time Status
======================================== ====================== ===============
CreateObjectTask N/A Ready
Folder: \Microsoft\Windows\Software Inventory Logging
TaskName Next Run Time Status
======================================== ====================== ===============
Collection N/A Disabled
Configuration N/A Ready
Folder: \Microsoft\Windows\SpacePort
TaskName Next Run Time Status
======================================== ====================== ===============
SpaceAgentTask N/A Ready
SpaceManagerTask N/A Ready
Folder: \Microsoft\Windows\Storage Tiers Management
TaskName Next Run Time Status
======================================== ====================== ===============
Storage Tiers Management Initialization N/A Ready
Storage Tiers Optimization N/A Disabled
Folder: \Microsoft\Windows\TextServicesFramework
TaskName Next Run Time Status
======================================== ====================== ===============
MsCtfMonitor N/A Running
Folder: \Microsoft\Windows\Time Synchronization
TaskName Next Run Time Status
======================================== ====================== ===============
SynchronizeTime N/A Ready
Folder: \Microsoft\Windows\Time Zone
TaskName Next Run Time Status
======================================== ====================== ===============
SynchronizeTimeZone N/A Ready
Folder: \Microsoft\Windows\Windows Defender
TaskName Next Run Time Status
======================================== ====================== ===============
Windows Defender Cache Maintenance N/A Ready
Windows Defender Cleanup N/A Ready
Windows Defender Scheduled Scan 12/4/2023 2:00:36 AM Ready
Windows Defender Verification N/A Ready
Folder: \Microsoft\Windows\Windows Error Reporting
TaskName Next Run Time Status
======================================== ====================== ===============
QueueReporting 12/3/2023 11:23:48 AM Ready
Folder: \Microsoft\Windows\Windows Filtering Platform
TaskName Next Run Time Status
======================================== ====================== ===============
BfeOnServiceStartTypeChange N/A Ready
Folder: \Microsoft\Windows\WindowsUpdate
TaskName Next Run Time Status
======================================== ====================== ===============
Scheduled Start 12/4/2023 10:11:30 AM Ready
Folder: \Microsoft\Windows\Wininet
TaskName Next Run Time Status
======================================== ====================== ===============
CacheTask N/A Running
Please advise or point me in the right direction.Thank you.