A.S.E - Advanced_System_Exfiltration #226
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This slow, and steady staged payload takes it's time and gleans detailed system information using powershell, Ducky script and notepad. First hidden powershells are opened in stages, and payloads are deployed to collect the target computers system information, Then a notepad.txt file named loot is created with all the gleaned information, and hidden in the Public Users folder C:\Users\Public\loot.txt The loot is then exfiltrated using a Discord webhook. In the final stage of the payload the loot.txt file, the recycling bin contents, the temp folder contents and powershell history are all deleted.