[ Topic ] BadUSB - Payload Under SYSTEM
by 0x27 - Saturday July 8, 2023 at 12:47 AM
#1
[Image: 2pdXomC.png]



So you've got a badusb or cheaper equivalent (malduino / digispark) that performs HID attacks. Well, lets see what we can do with that. I've created a malicious powershell command that downloads your malware / shellcode and executes it on the victims machine and attempts to elevate your malicious process to run under the SYSTEM context. Below is the script and a more detailed explanation as what takes place. Enjoy.

Hidden Content
You must register or login to view this content.


This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Scamming | https://doxbin.com/upload/0x27Doxxed | https://ibb.co/nqtc4prn
Reply
#2
More powerful when using with hoaxshell
Reply
#3
you can use any C2 or Rat as you'd like Smile

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Scamming | https://doxbin.com/upload/0x27Doxxed | https://ibb.co/nqtc4prn
Reply
#4
(Jul 08, 2023, 12:55 AM)0x27 Wrote: you can use any C2 or Rat as you'd like Smile

Thanks for this
Reply
#5
This code is definitely as valuable for spreading malware as it is for saturating a computer.

nice information!

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Scraping | Contact us via https://breachforums.rs/misc.php?action=help&hid=27 if you feel this is incorrect.
Reply
#6
(Jul 13, 2023, 06:48 PM)B3ulah1 Wrote: This code is definitely as valuable for spreading malware as it is for saturating a computer.

nice information!

my pleasure

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Scamming | https://doxbin.com/upload/0x27Doxxed | https://ibb.co/nqtc4prn
Reply
#7
Thanks for share
Reply
#8
Great tutorial man! Cool
Reply
#9
(Jul 08, 2023, 12:54 AM)bytemafia Wrote: More powerful when using with hoaxshell

how do you combine or use it please?

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Attempting to sell credit card information
Reply
#10
this is awesome thanks you
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [ LIST ] 5 FREE STEALERS WITH PROS/CONS elix 398 16,323 38 minutes ago
Last Post: obito07
  [Sektor7] Full Recent Course Spearr 36 1,248 1 hour ago
Last Post: Netr0
  PowerShell AMSI Bypass via VEH Loki 43 4,224 2 hours ago
Last Post: NUKEx
  Xordium stealer for Pulsar v2.4.5 nullvex 30 1,370 2 hours ago
Last Post: NUKEx
  Bypass Cookies Encryption | Working FrancisMDouble 10 1,296 Yesterday, 05:28 PM
Last Post: zxACASD

Forum Jump:


 Users browsing this forum: 1 Guest(s)