Book a Demo!
CoCalc Logo Icon
StoreFeaturesDocsShareSupportNewsAboutPoliciesSign UpSign In
hak5
GitHub Repository: hak5/usbrubberducky-payloads
Path: blob/master/payloads/library/incident_response/GoodUSB/payload.txt
2968 views
1
GUI r
2
DELAY 1000
3
STRING notepad.exe
4
ENTER
5
DELAY 1000
6
STRING Greetings!
7
ENTER
8
STRING You've just launched GoodUSB!
9
ENTER
10
ENTER
11
STRING This script will take the following actions:
12
ENTER
13
STRING 1) Download ClamAV
14
ENTER
15
STRING 2) Update ClamAV to the latest malware definitions.
16
ENTER
17
STRING 3) Scan your system memory for any malicious processes.
18
ENTER
19
STRING 4) If any are found, TERMINATE THEM!
20
ENTER
21
ENTER
22
STRING This process may take a very long time, about 30 minutes to an hour.
23
ENTER
24
STRING You can abort now by unplugging this device.
25
ENTER
26
STRING Otherwise, the process will begin in 5...
27
DELAY 3000
28
STRING 4...
29
DELAY 3000
30
STRING 3...
31
DELAY 3000
32
STRING 2...
33
DELAY 3000
34
STRING 1...
35
DELAY 3000
36
STRING 0
37
ENTER
38
STRING Away we go!
39
DELAY 2000
40
ALT F4
41
DELAY 1000
42
ALT N
43
GUI r
44
DELAY 1000
45
STRING powershell.exe
46
ENTER
47
DELAY 1000
48
STRING Start-Process powershell -Verb runAs ; exit
49
ENTER
50
DELAY 4000
51
LEFT
52
ENTER
53
DELAY 4000
54
STRING mkdir $env:USERPROFILE\AppData\Local\Temp ; cd $env:USERPROFILE\AppData\Local\Temp ; Invoke-WebRequest -Uri https://www.clamav.net/downloads/production/clamav-1.3.0.win.x64.zip -OutFile clam.zip ; Expand-Archive -Force clam.zip ; del clam.zip ; cd clam\* ; mv .\conf_examples\freshclam.conf.sample freshclam.conf ; mv .\conf_examples\clamd.conf.sample clamd.conf ; Set-Content -Path "freshclam.conf" -Value (get-content -Path "freshclam.conf" | Select-String -Pattern 'Example' -NotMatch) ; Set-Content -Path "clamd.conf" -Value (get-content -Path "clamd.conf" | Select-String -Pattern 'Example' -NotMatch) ; Start-Process -Wait .\freshclam.exe ; Start-Process -NoNewWindow -Wait .\clamscan.exe "--memory --kill" ; cd $env:USERPROFILE\AppData\Local\Temp ; rmdir -R clam
55
ENTER
56
57