[DE] Aigner Immobilien

#1
[AI PRELUDE]
Aigner Immobilien is a leading real estate brokerage company based in Munich, Germany, with over 30 years of experience in the market. They offer services for buying, selling, and renting properties, providing personalized support throughout the entire process. 
[/AI PRELUDE]


We land in env via CVE-2024-7399 (most likely ran now but you never know ? ) 

We hit WIN11 ENV so mimi is out of play (LSASS wise) but we can always dump locally (SAM) or query AD and hope for big mistake? --> https://ibb.co/QF3vDQqV
 
Whoever from the administration created this account left the password in desc as "remember me" most likely so big win for us, big loss for company here. After IA we already have somewhat mapping of the WIN network:
Code:
SMB                      192.168.100.19  445    AIG-X2WS-18      [*] Windows Server 2022 Build 20348 (name:AIG-X2WS-18) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.31  445    AIG-X3WS-18      [*] Windows Server 2022 Build 20348 (name:AIG-X3WS-18) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.91  445    AIG-X3WS-08      [*] Windows Server 2022 Build 20348 (name:AIG-X3WS-08) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.23  445    AIG-X3WS-23      [*] Windows Server 2022 Build 20348 (name:AIG-X3WS-23) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.127 445    AIG-X2WS-55      [*] Windows Server 2022 Build 20348 (name:AIG-X2WS-55) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.5   445    AIG-X1WS-12      [*] Windows Server 2022 Build 20348 (name:AIG-X1WS-12) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.184 445    AIG-XD2022-09    [*] Windows Server 2022 Build 20348 (name:AIG-XD2022-09) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.1   445    AIG-X3WS-13      [*] Windows Server 2022 Build 20348 (name:AIG-X3WS-13) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.25  445    AIG-X1WS-26      [*] Windows Server 2022 Build 20348 (name:AIG-X1WS-26) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.7   445    AIG-X2WS-30      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X2WS-30) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.9   445    AIG-X2WS-03      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X2WS-03) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.97  445    AIG-X1WS-46      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X1WS-46) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.4   445    AIG-X1WS-23      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X1WS-23) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.22  445    AIG-X1WS-15      [*] Windows Server 2022 Build 20348 (name:AIG-X1WS-15) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.18  445    AIG-X2WS-27      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X2WS-27) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.6   445    AIG-X1WS-09      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X1WS-09) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.11  445    AIG-X3WS-16      [*] Windows Server 2022 Build 20348 (name:AIG-X3WS-16) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.174 445    AIG-XDWS-32      [*] Windows Server 2022 Build 20348 (name:AIG-XDWS-32) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.113 445    AIG-X3WS-17      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X3WS-17) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.187 445    AIG-X1WS-58      [*] Windows Server 2022 Build 20348 (name:AIG-X1WS-58) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.10  445    AIG-X2WS-16      [*] Windows Server 2022 Build 20348 (name:AIG-X2WS-16) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.204 445    AIG-SRV-FFTEST2  [*] Windows 10 / Server 2016 Build 14393 (name:AIG-SRV-FFTEST2) (domain:aig24.local) (signing:False) (SMBv1:True)
SMB                      192.168.100.143 445    AIG-X5WS-03      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X5WS-03) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.185 445    AIG-XD2022-10    [*] Windows Server 2022 Build 20348 x64 (name:AIG-XD2022-10) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.93  445    AIG-X2WS-13      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X2WS-13) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.177 445    AIG-FFONB-10     [*] Windows Server 2022 Build 20348 x64 (name:AIG-FFONB-10) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.109 445    AIG-DATEV-N2     [*] Windows 10 / Server 2019 Build 17763 (name:AIG-DATEV-N2) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.148 445    AIG-X5WS-18      [*] Windows Server 2022 Build 20348 (name:AIG-X5WS-18) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.154 445    AIG-FFONB-03     [*] Windows Server 2022 Build 20348 (name:AIG-FFONB-03) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.112 445    AIG-XD2022-13    [*] Windows Server 2022 Build 20348 (name:AIG-XD2022-13) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.121 445    AIG-X5WS-26      [*] Windows Server 2022 Build 20348 (name:AIG-X5WS-26) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.24  445    AIG-X3WS-25      [*] Windows Server 2022 Build 20348 (name:AIG-X3WS-25) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.94  445    AIG-X3WS-28      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X3WS-28) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.65  445    AIG-X3WS-51      [*] Windows Server 2022 Build 20348 (name:AIG-X3WS-51) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.49  445    AIG-X3WS-26      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X3WS-26) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.80  445    AIG-X2WS-53      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X2WS-53) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.210 445    AIG-SRV-DDC01    [*] Windows 8.1 / Server 2012 R2 Build 9600 x64 (name:AIG-SRV-DDC01) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.37  445    AIG-X1WS-20      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X1WS-20) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.140 445    AIG-X3WS-22      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X3WS-22) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.54  445    AIG-X1WS-14      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X1WS-14) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.217 445    AIG-X5WS-38      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X5WS-38) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.200 445    AIG-SRV-DC01     [*] Windows Server 2022 Build 20348 x64 (name:AIG-SRV-DC01) (domain:aig24.local) (signing:True) (SMBv1:False)
SMB                      192.168.100.71  445    AIG-SRV-KORTUS   [*] Windows Server 2022 Build 20348 x64 (name:AIG-SRV-KORTUS) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.64  445    AIG-X3WS-48      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X3WS-48) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.170 445    AIG-XDWS-35      [*] Windows Server 2022 Build 20348 x64 (name:AIG-XDWS-35) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.141 445    AIG-X2WS-19      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X2WS-19) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.130 445    AIG-X1WS-03      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X1WS-03) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.131 445    AIG-X2WS-04      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X2WS-04) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.128 445    AIG-X1WS-10      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X1WS-10) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.190 445    AIG-X5WS-39      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X5WS-39) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.138 445    AIG-X1WS-02      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X1WS-02) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.35  445    AIG-X3WS-21      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X3WS-21) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.12  445    AIG-X3WS-10      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X3WS-10) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.38  445    AIG-X1WS-13      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X1WS-13) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.26  445    AIG-X2WS-25      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X2WS-25) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.158 445    AIG-FFONB-01     [*] Windows Server 2022 Build 20348 x64 (name:AIG-FFONB-01) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.139 445    AIG-X3WS-06      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X3WS-06) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.32  445    AIG-X3WS-27      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X3WS-27) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.52  445    AIG-X3WS-07      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X3WS-07) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.21  445    AIG-X2WS-24      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X2WS-24) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.135 445    AIG-X5WS-27      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X5WS-27) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.103 445    AIG-X1WS-57      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X1WS-57) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.3   445    AIG-X1WS-25      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X1WS-25) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.118 445    AIG-X2WS-05      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X2WS-05) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.180 445    AIG-X5WS-12      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X5WS-12) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.125 445    AIG-X1WS-52      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X1WS-52) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.14  445    AIG-X1WS-21      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X1WS-21) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.86  445    AIG-X3WS-55      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X3WS-55) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.46  445    AIG-X1WS-19      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X1WS-19) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.137 445    AIG-X1WS-11      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X1WS-11) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.167 445    AIG-FFONB-09     [*] Windows Server 2022 Build 20348 x64 (name:AIG-FFONB-09) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.134 445    AIG-X3WS-29      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X3WS-29) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.106 445    AIG-X3WS-46      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X3WS-46) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.59  445    AIG-X2WS-52      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X2WS-52) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.211 445    AIG-SRV-DDC02    [*] Windows 8.1 / Server 2012 R2 Build 9600 x64 (name:AIG-SRV-DDC02) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.62  445    AIG-X3WS-50      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X3WS-50) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.176 445    AIG-XDWS-36      [*] Windows Server 2022 Build 20348 x64 (name:AIG-XDWS-36) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.120 445    AIG-X2WS-56      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X2WS-56) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.163 445    AIG-X5WS-04      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X5WS-04) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.116 445    AIG-X2WS-02      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X2WS-02) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.17  445    AIG-X2WS-06      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X2WS-06) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.159 445    AIG-FFONB-07     [*] Windows Server 2022 Build 20348 x64 (name:AIG-FFONB-07) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.72  445    AIG-X2WS-28      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X2WS-28) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.117 445    AIG-X2WS-08      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X2WS-08) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.191 445    AIG-XD2022-07    [*] Windows Server 2022 Build 20348 x64 (name:AIG-XD2022-07) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.88  445    AIG-X1WS-29      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X1WS-29) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.63  445    AIG-X3WS-52      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X3WS-52) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.90  445    AIG-X3WS-11      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X3WS-11) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.150 445    AIG-X5WS-29      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X5WS-29) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.152 445    AIG-X5WS-01      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X5WS-01) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.53  445    AIG-X2WS-21      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X2WS-21) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.107 445    AIG-X2WS-01      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X2WS-01) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.188 445    AIG-X5WS-20      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X5WS-20) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.85  445    AIG-X3WS-53      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X3WS-53) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.164 445    AIG-XD2022-02    [*] Windows Server 2022 Build 20348 x64 (name:AIG-XD2022-02) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.98  445    AIG-X3WS-57      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X3WS-57) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.45  445    AIG-X2WS-17      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X2WS-17) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.87  445    AIG-X1WS-07      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X1WS-07) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.39  445    AIG-X3WS-05      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X3WS-05) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.108 445    AIG-X1WS-28      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X1WS-28) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.33  445    AIG-X1WS-01      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X1WS-01) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.47  445    AIG-X1WS-05      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X1WS-05) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.175 445    AIG-XDWS-34      [*] Windows Server 2022 Build 20348 x64 (name:AIG-XDWS-34) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.169 445    AIG-XDWS-33      [*] Windows Server 2022 Build 20348 x64 (name:AIG-XDWS-33) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.142 445    AIG-X5WS-02      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X5WS-02) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.66  445    AIG-X1WS-04      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X1WS-04) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.151 445    AIG-X5WS-17      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X5WS-17) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.165 445    AIG-X5WS-16      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X5WS-16) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.145 445    AIG-X5WS-08      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X5WS-08) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.48  445    AIG-X1WS-17      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X1WS-17) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.102 445    AIG-X1WS-48      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X1WS-48) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.41  445    AIG-X1WS-08      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X1WS-08) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.171 445    AIG-FFONB-08     [*] Windows Server 2022 Build 20348 x64 (name:AIG-FFONB-08) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.44  445    AIG-X5WS-25      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X5WS-25) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.160 445    AIG-FFONB-06     [*] Windows Server 2022 Build 20348 x64 (name:AIG-FFONB-06) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.96  445    AIG-X3WS-04      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X3WS-04) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.50  445    AIG-X3WS-01      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X3WS-01) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.13  445    AIG-X1WS-24      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X1WS-24) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.100 445    AIG-X2WS-50      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X2WS-50) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.82  445    AIG-X3WS-47      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X3WS-47) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.42  445    AIG-X5WS-23      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X5WS-23) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.75  445    AIG-X3WS-19      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X3WS-19) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.74  445    AIG-X1WS-16      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X1WS-16) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.84  445    AIG-X3WS-56      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X3WS-56) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.77  445    AIG-X1WS-49      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X1WS-49) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.126 445    AIG-X1WS-55      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X1WS-55) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.73  445    AIG-X2WS-22      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X2WS-22) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.214 445    AIG-X5WS-40      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X5WS-40) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.56  445    AIG-X1WS-53      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X1WS-53) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.92  445    AIG-X2WS-29      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X2WS-29) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.79  445    AIG-X1WS-56      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X1WS-56) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.172 445    AIG-XDWS-31      [*] Windows Server 2022 Build 20348 x64 (name:AIG-XDWS-31) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.115 445    AIG-X3WS-24      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X3WS-24) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.60  445    AIG-X2WS-57      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X2WS-57) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.221 445    AIG-SRV-DATEV2   [*] Windows Server 2022 Build 20348 x64 (name:AIG-SRV-DATEV2) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.89  445    AIG-X2WS-07      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X2WS-07) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.76  445    AIG-X2WS-14      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X2WS-14) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.83  445    AIG-X3WS-54      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X3WS-54) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.199 445    AIG-X5WS-31      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X5WS-31) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.202 445    AIG-SRV-FF01     [*] Windows 10 / Server 2016 Build 14393 (name:AIG-SRV-FF01) (domain:aig24.local) (signing:False) (SMBv1:True)
SMB                      192.168.100.144 445    AIG-X1WS-59      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X1WS-59) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.218 445    AIG-X5WS-45      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X5WS-45) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.78  445    AIG-X1WS-47      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X1WS-47) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.58  445    AIG-X2WS-51      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X2WS-51) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.81  445    AIG-X2WS-48      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X2WS-48) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.124 445    AIG-X1WS-50      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X1WS-50) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.95  445    AIG-X3WS-20      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X3WS-20) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.29  445    AIG-X3WS-14      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X3WS-14) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.67  445    AIG-X1WS-27      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X1WS-27) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.30  445    AIG-X2WS-11      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X2WS-11) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.203 445    AIG-SRV-FFUPDAT  [*] Windows 10 / Server 2019 Build 17763 x64 (name:AIG-SRV-FFUPDAT) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.157 445    AIG-X5WS-32      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X5WS-32) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.201 445    AIG-SRV-FS02     [*] Windows Server 2022 Build 20348 x64 (name:AIG-SRV-FS02) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.223 445    AIG-SRV-SERVICE  [*] Windows 8.1 / Server 2012 R2 Build 9600 x64 (name:AIG-SRV-SERVICE) (domain:aig24.local) (signing:False) (SMBv1:True)
SMB                      192.168.100.136 445    AIG-X3WS-30      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X3WS-30) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.226 445    AIG-SRV-MGMT     [*] Windows 8.1 / Server 2012 R2 Build 9600 x64 (name:AIG-SRV-MGMT) (domain:aig24.local) (signing:False) (SMBv1:True)
SMB                      192.168.100.220 445    AIG-SRV-DC02     [*] Windows Server 2022 Build 20348 x64 (name:AIG-SRV-DC02) (domain:aig24.local) (signing:True) (SMBv1:False)
SMB                      192.168.100.110 445    AIG-X1WS-22      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X1WS-22) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.206 445    AIG-SRV-FFAPP    [*] Windows 8.1 / Server 2012 R2 Build 9600 x64 (name:AIG-SRV-FFAPP) (domain:aig24.local) (signing:False) (SMBv1:True)
SMB                      192.168.100.34  445    AIG-X2WS-23      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X2WS-23) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.215 445    AIG-SRV-DDC05    [*] Windows 10 / Server 2019 Build 17763 x64 (name:AIG-SRV-DDC05) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.101 445    AIG-X2WS-46      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X2WS-46) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.57  445    AIG-X1WS-54      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X1WS-54) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.68  445    AIG-X2WS-26      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X2WS-26) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.205 445    AIG-X1WS-06      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X1WS-06) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.28  445    AIG-X2WS-12      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X2WS-12) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.99  445    AIG-X2WS-54      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X2WS-54) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.51  445    AIG-FFONB-02     [*] Windows Server 2022 Build 20348 x64 (name:AIG-FFONB-02) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.61  445    AIG-X3WS-49      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X3WS-49) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.192 445    AIG-X5WS-42      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X5WS-42) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.119 445    AIG-X2WS-10      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X2WS-10) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.224 445    AIG-SRV-SRVC2    [*] Windows 10 / Server 2019 Build 17763 x64 (name:AIG-SRV-SRVC2) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.69  445    AIG-X1WS-18      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X1WS-18) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.16  445    AIG-X1WS-30      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X1WS-30) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.2   445    AIG-X3WS-09      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X3WS-09) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.15  445    AIG-X3WS-15      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X3WS-15) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.104 445    AIG-X1WS-51      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X1WS-51) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.70  445    AIG-X3WS-12      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X3WS-12) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.55  445    AIG-X3WS-02      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X3WS-02) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.213 445    AIG-X5WS-36      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X5WS-36) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.36  445    AIG-X2WS-20      [*] Windows Server 2022 Build 20348 x64 (name:AIG-X2WS-20) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.222 445    AIG-SRV-PRTG     [*] Windows 8.1 / Server 2012 R2 Build 9600 (name:AIG-SRV-PRTG) (domain:aig24.local) (signing:False) (SMBv1:True)
SMB                      192.168.100.105 445    AIG-X2WS-47      [*] Windows Server 2022 Build 20348 (name:AIG-X2WS-47) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.196 445    AIG-X5WS-33      [*] Windows Server 2022 Build 20348 (name:AIG-X5WS-33) (domain:aig24.local) (signing:False) (SMBv1:False)
SMB                      192.168.100.122 445    AIG-X2WS-49      [*] Windows Server 2022 Build 20348 (name:AIG-X2WS-49) (domain:aig24.local) (signing:False) (SMBv1:False)
Running nxc against 256 targets ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 100% 0:00:00

We scan again and look for high interest targets / ports (MSSQL here, afterall windows network) and we find the backend server. At this point we land in SQL server and all is almost done but we cant login, what now? We have ADMINISTRATOR/SYSTEM access here via backup user so we can add our own user to MSSQL without even knowing the original super user password (Excercise for reader =), simple )
With our new user we dump (or backup) whatever we want and get results.

https://www.swisstransfer.com/d/79959f60...ba71ee300f

(It is a little malformed, we tried export with unicode, UTF8 and local system language and with all these we still get extra spacing etc. But with educated guess here is about 200-300k customers.

SAMPLE:
Code:
DSN,KENNUNG,IDX_FIRMA,IDX_NAME,ANGELEGT,TOUCH,FIRMA,ANREDE,ANREDEKURZ,NAME,STRAßE,LAND_PLZ,LAND,ORT,ORTSTEIL,PF_PLZ,POSTFACH,BRIEFANREDE,TELEFON,FAX,STICHWORT,STICHWORT2,EXTRA,FARCHIV,ÄN_BEN_DSN,NEU_BEN_DSN,BLZ,KONTONR,BANK,NOTIZ,Gruppe,AD_DSN,SUCHNAME,CONTROLS,STATEMENT,EMAIL,INTERNET,ACHTUNG,ACL,WEITEMAIL,stamp,LCID,IBAN,BIC,IDX_NAME2,Supplementary,Creator_DSN,BIRTHDAY,MandateID,LP_BIRTHDAY,Position
{469E694A-D9F3-4F70-9C57-A6ACB917750E},  20452260,,Abokwidir,2025-09-10 17:41:30,2025-09-10 17:42:44,,Frau,Frau,Deemah Abokwidir,Saportastr. 10,80637,,München,Neuhausen-Nymphenburg,,,Sehr geehrte Frau Abokwidir,,        
        
+49(176)    61182866    ,,,,,0,{223905B9-72BA-44D6-8B45-075CE9DB377A},{223905B9-72BA-44D6-8B45-075CE9DB377A},,,,,,,,,,Dima_ak@hotmail.com,,0,,,00000001835DD69C,1031,,,,,{223905B9-72BA-44D6-8B45-075CE9DB377A},,,,
{659EC445-54F2-4289-8F86-92913E165BE2},  20452261,,Cuzic,2025-09-10 17:42:42,2025-09-10 17:43:39,,Frau,Frau,Hela Cuzic,Dorfstr. 28b,85591,,Vaterstetten,,,,Sehr geehrte Frau Cuzic,,        
        
+49(155)    66082553    ,,,,,0,{223905B9-72BA-44D6-8B45-075CE9DB377A},{223905B9-72BA-44D6-8B45-075CE9DB377A},,,,10.09.2025 17:42-Albulena Berisha: Guten Tag,
mein Name ist Hela Cuzic (28), und ich suche gemeinsam mit meinem Bruder Mihovil Cuzic (30) nach einer Wohnung. Wir arbeiten beide an Forschungsinstituten, dem Fraunhofer Institut und TUM, mit einem gemeinsamen Nettoeinkommen von ca. 6.000,,,,,,hela.cuzic@gmail.com,,0,,hela.cuzic@googlemail.com
,00000001835DD90C,1031,,,,,{223905B9-72BA-44D6-8B45-075CE9DB377A},,,,
{FE1B6DE7-4D30-481D-BD5E-C7B9AE0EB304},  20452262,,Holl,2025-09-10 17:45:12,2025-09-10 17:46:40,,Frau,Frau,Julia Holl,Christoph-Rapparini-Bogen 9,80639,,München,Laim,,,Sehr geehrte Frau Holl,,        
        
+49(176)    62259218    ,,,,,0,{223905B9-72BA-44D6-8B45-075CE9DB377A},{223905B9-72BA-44D6-8B45-075CE9DB377A},,,,,,,,,,julia.holl@gmx.net,,0,,,00000001835DDF71,1031,,,,,{223905B9-72BA-44D6-8B45-075CE9DB377A},,,,
{7B7ED5F5-B080-4BBE-BCF7-4CB1585A2420},  20452273,,Zehelein,2025-09-11 09:23:28,2025-10-29 09:13:01,,Frau,Frau,Gertrud Zehelein,Gernotstr. 6,,80804,,München,Schwabing-West,,,Sehr geehrte Frau Zehelein,,        
        
        
+49(89)    3086607    ,,,,,0,{9C8F9E1E-00FE-4BDA-8087-015D5FF985C5},{7C748F39-FEDD-4944-B4F3-120E81B2F419},,,,11.09.2025 09:24-Dingana Ganyonga: Eigentümerin der Wohnung in der Gartenstr. 7, München - Die Dame ist ca. 90 Jahre alt.

AUFTRAG von der HIS real Estate erhalten.

Mieterin Frau Flemmig unterverknüft,,{4F7C45E9-E87F-4489-9ECF-96BACBFD69FE},,,,,,0,,,00000001963A62AD,1031,,,,,{7C748F39-FEDD-4944-B4F3-120E81B2F419},,,,
{852D7CC7-2025-49CC-97D7-DFBE6433780C},  20452283,ELVA Hausverwaltung OHG,Pavlu,2025-09-11 10:04:18,2025-09-11 10:04:49,ELVA Hausverwaltung OHG,Frau,Frau,Tereza Pavlu,Truderinger Str. 302,,81825,,München,Trudering-Riem,,,Sehr geehrte Frau Pavlu,,+49(89)    413273460    
        
+49(178)    5794155    ,,,,,0,{081BFE6D-AFED-4898-B9C3-688D80EA2D42},{081BFE6D-AFED-4898-B9C3-688D80EA2D42},,,,,,{32B47EEE-8163-4FB2-8432-7A045FE2431E},,,,info@elva-hv.de,,0,,,0000000183854ACE,1031,,,,,{081BFE6D-AFED-4898-B9C3-688D80EA2D42},,,,
{73FC6202-FD27-4C32-AB32-A507BE98E2EF},  20452288,,Schwaiger-Milosevic,2025-09-11 10:29:13,2025-11-18 09:21:29,,Frau und Herrn,Frau + Herr,Marija Schwaiger-Milosevic
Tobias Schwaiger,Waldstr. 32a,82538,,Geretsried,,,,Sehr geehrte Frau Schwaiger-Milosevic,
sehr geehrter Herr Schwaiger,,        
        
+49(176)    32634001    ,,,,,0,{CFF13152-0375-4320-A1C6-ED57DCBAAC05},{C3FE2459-B36A-4582-A92B-2EC9807943A0},,,,,,,,,,marija.tobias@gmx.de,,0,,,000000019E1698D6,1031,,,Schwaiger,,{C3FE2459-B36A-4582-A92B-2EC9807943A0},,,,
{750D424F-745E-4D2A-B84F-4BA5EB957103},  20452291,,Dominik,2025-09-11 10:41:58,2025-09-11 10:54:55,,Frau und Herrn,Frau + Herr,Marleen Dominik
Dr. Philipp Dominik,Philipp-Loewenfeld-Str. 19,80339,,München,Ludwigsvorstadt-Isarvorstadt,,,Sehr geehrte Frau Dominik,
sehr geehrter Herr Dr. Dominik,,        
        
+49(151)    11147323    ,,,,,0,{F3DDA7F2-0A6B-4342-8CCC-D1049C3B0B19},{F3DDA7F2-0A6B-4342-8CCC-D1049C3B0B19},,,,11.09.2025 10:50-Ines Tyria: Besitzen beide Eigentum, allerdings nicht in DE. Wohnen hier zur Miete.

11.09.2025 10:43-Ines Tyria: Philipp ist selbständig in der Medizinbranche tätig und ich bin verbeamtete Regierungsrätin im Bayerischen Staatsministerium für Wirtschaft, Landesentwicklung und Energie.,,,,,,marleen.dominik@outlook.com,,0,,,00000001838CEAB5,1031,,,Dominik,,{F3DDA7F2-0A6B-4342-8CCC-D1049C3B0B19},,,,
{45DF63FF-73BB-4E56-836B-DF6AF2130EB3},  20452279,,Stadler,2025-09-11 09:52:07,2025-09-11 10:14:03,,Herrn,Herr,Christoph Stadler,Willstätterstr. 41,80999,,München,Allach-Untermenzing,,,Sehr geehrter Herr Stadler,,        
        
+49(176)    43895875    ,,,,,0,{C3FE2459-B36A-4582-A92B-2EC9807943A0},{C3FE2459-B36A-4582-A92B-2EC9807943A0},,,,11.09.2025 10:13-Matea Ravnjak: wird sks online hinterlegen,,,,,,christophstadler01@gmail.com,,0,,christophstadler01@googlemail.com
,00000001838C53B1,1031,,,,,{C3FE2459-B36A-4582-A92B-2EC9807943A0},,,,
{F64C009D-AF3B-4587-9557-3DBD2292DE9F},  20452294,,Diaz,2025-09-11 10:57:42,2025-11-07 11:53:55,,Frau,Frau,Doris Diaz,Egerlandstr. 16,85540,,Haar,,,,Sehr geehrte Frau Diaz,,        
        
+34()    611271036

Now after dumping big mistake of thinking maybe they wont see this and continue tomorrow? Unlucky, they see this and kill access completely (even from multiple srv) but we have what we want.
Reply
#2
Hello, the download link has been updated as of this post.
This account is currently banned.
Ban Length: Permanent
Ban Reason: Self-ban | https://spear.cx/Forum-Ban-Appeals if you feel this is incorrect.
Reply



Recently Browsing 1 Guest(s)