One day , i’ve made two scripts client.py or malware script and the server script
so what i do is that i let my pc have a static ip 192.168.100.XX and i port forward it in my router on port 4444 in order to receive and send packets from nubip.ddns.net on port 4444 , so that i make a malware that works for external wifi of the victime , Actually i didn’t send the malware to anyone yet because it was just for educational and ethical hacking , but one day , suddenly I’ve made a weird connection from some one called frank , i typed whoami in his shell and found this => >desktop-d019gdmfrank then the connection gone ! after some days the same thing happen’s but with another one called george i really don’t know anyone of them and i didn’t give the malware to anyone , how ever the connection with this one called george was for about 10 seconds which give opportunity to type some commands her’s what happend on my server python script =>
################################## 4444 port is opened on 192.168.100.50 ! ######################################## Listening for packets… ######################################## (‘34.141.245.25’, 49727) has connected to the server! Shell started… ######################################## > > >whoami >desktop-b0t93d6george >dir > Volume in drive C has no label. Volume Serial Number is 68C4-4A0E Directory of C:UsersgeorgeDesktop 05/11/2024 04:17 PM . 05/11/2024 04:17 PM .. 06/09/2024 07:55 PM 5,594,012 App.exe 05/11/2024 04:17 PM 1,026 BNAGMGSPLO.mp3 05/11/2024 04:17 PM CZQKSDDMWR 05/11/2024 04:17 PM EEGWXUHVUG 05/11/2024 04:17 PM EFOYFBOLXA 05/11/2024 04:17 PM 1,026 EFOYFBOLXA.png 05/11/2024 04:17 PM 1,026 EOWRVPQCCS.png 05/11/2024 04:17 PM 1,026 GAOBCVIQIJ.mp3 05/11/2024 04:17 PM 1,026 GAOBCVIQIJ.pdf 05/11/2024 04:17 PM GIGIYTFFYT 05/11/2024 04:17 PM 1,026 GIGIYTFFYT.mp3 05/11/2024 04:17 PM 1,026 GRXZDKKVDB.jpg 05/11/2024 04:17 PM IPKGELNTQY 05/11/2024 04:17 PM 1,026 IPKGELNTQY.docx 05/11/2024 04:17 PM 1,026 IPKGELNTQY.xlsx 05/11/2024 04:17 PM LSBIHQFDVT 05/11/2024 04:17 PM 1,026 LSBIHQFDVT.docx 05/11/2024 04:17 PM 1,026 LSBIHQFDVT.jpg 05/11/2024 04:17 PM 1,026 LSBIHQFDVT.xlsx 05/11/2024 04:17 PM 1,026 NEBFQQYWPS.pdf 05/11/2024 04:17 PM 1,026 PALRGUCVEH.mp3 05/1 1/2024 04:17 PM 1,026 PWCCAWLGRE.xlsx 05/11/2024 04:17 PM QCFWYSKMHA 05/11/2024 04:17 PM 1,026 QCFWYSKMHA.jpg 05/11/2024 04:17 PM QCOILOQIKC 05/11/2024 04:17 PM QNCYCDFIJJ 05/11/2024 04:17 PM 1,026 QNCYCDFIJJ.xlsx 05/11/2024 04:17 PM SFPUSAFIOL 05/11/2024 04:17 PM 1,026 SFPUSAFIOL.docx 05/11/2024 04:17 PM 1,026 SQSJKEBWDT.jpg 05/11/2024 04:17 PM 1,026 SQSJKEBWDT.pdf 05/11/2024 04:17 PM 1,026 SUAVTZKNFL.pdf 05/11/2024 04:17 PM 1,026 SUAVTZKNFL.png 05/11/2024 04:17 PM ZGGKNSUKOP 05/11/2024 04:17 PM ZQIXMVQGAH 05/11/2024 04:17 PM 1,026 ZQIXMVQGAH.docx 05/11/2024 04:17 PM 1,026 ZQIXMVQGAH.png 25 File(s) 5,618,636 bytes 14 Dir(s) 180,925,497,344 bytes free >net user > User accounts for DESKTOP-B0T93D6 ——————————————————————————- Administrator DefaultAccount george Guest WDAGUtilityAccount The command completed successfully. >ipconfig > > > >whoami > > >An error occurred while receiving data: [WinError 10054] Une connexion existante a dû être fermée par l’hôte distant > >whoami Connection lost. Listening for new connections…
###########################
the weirdest thing also is that he was having a lots of files maked in same date and hour and minute and in the night of the day , also he was using a vpn => 34.141.245.25 so he isn’t a normal user , but how he was able to run the malware if i didn’t give him to it , he is dumb or what ? does he spy on me ? plz help me ! i’m so scared ! i downloaded malwarebyte and avast but nothing was detected ! plz help and explain to me what happen !!
Mohamed Lhachimi is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.