[ Topic ] BadUSB - Payload Under SYSTEM
by 0x27 - Saturday July 8, 2023 at 12:47 AM
#21
wondering if anything good or just the same recycled payloads
Reply
#22
[quote="0x27" pid='48007' dateline='1688777263']
[Image: 2pdXomC.png]



Então você tem um badusb ou equivalente mais barato (malduino /digispark) que executa ataques HID. Bem, vamos ver o que podemos fazer com isso. Eu criei um comando malicioso powershell que baixa seu malware /shellcode e executa-o na máquina das vítimas e tenta elevar seu processo malicioso para ser executado sob o contexto SYSTEM. Abaixo está o roteiro e uma explicação mais detalhada como o que acontece. Desfrutar.


[/citação]

Smile
Reply
#23
sounds fun, want to see
This forum account is currently banned. Ban Length: (Permanent)
Ban Reason: Leeching | http://breached26tezcofqla4adzyn22notfqw...an-Appeals if you feel this is incorrect.
Reply
#24
knowledge is important
Reply
#25
Great tutorial man! Cool
Reply
#26
Thanks for share Smile
Reply
#27
thanks for your work
Reply
#28
(07-08-2023, 12:47 AM)0x27 Wrote:
[Image: 2pdXomC.png]



So you've got a badusb or cheaper equivalent (malduino / digispark) that performs HID attacks. Well, lets see what we can do with that. I've created a malicious powershell command that downloads your malware / shellcode and executes it on the victims machine and attempts to elevate your malicious process to run under the SYSTEM context. Below is the script and a more detailed explanation as what takes place. Enjoy.

Ho Ho Ho I'm going to .........

Ho Ho Ho I'm going to .........
Reply
#29
Thanks bro! This looks intresting too see thank you for sharing Big Grin
This forum account is currently banned. Ban Length: (Permanent)
Ban Reason: Leeching | https://breachforums.hn/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#30
Thanks fror this
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [ Topic ] Malware Evasion - What is Code Signing? 0x27 40 7,692 04-04-2025, 07:55 PM
Last Post: NX000
  [ Topic ] Malware Evasion - Persistent Malware WatchDog DLL 0x27 10 6,249 02-06-2025, 05:02 PM
Last Post: exynos01
  Embed Payload In Png Aanya 4 649 10-30-2024, 05:03 AM
Last Post: Aanya
  [ Topic ] ChatGPT - Progression of Malware [Part II] 0x27 6 3,764 01-12-2024, 04:18 AM
Last Post: 0x27
  [ TOPIC ] We need to see more activity here. 0x27 5 2,405 01-11-2024, 10:09 PM
Last Post: GrassCrab

Forum Jump:


 Users browsing this thread: 5 Guest(s)