Credz-Plz

Credz-Plz
Download Copy
Title: Credz-Plz
Author: I am Jakoby

A script used to prompt the target to enter their creds to later be exfiltrated with dropbox. A pop up box will let the target know "Unusual sign-in. Please authenticate your Microsoft Account" This will be followed by a fake authentication ui prompt. If the target tried to "X" out, hit "CANCEL" or while the password box is empty hit "OK" the prompt will continuously re pop up Once the target enters their credentials their information will be uploaded to your dropbox for collection.

🏆   Recognized with a Payload Award in September 2023

 

Credential harvesting is the method of obtaining credentials — think usernames and passwords. Many techniques are used to obtain credentials, from keylogging to credential dumping. With a set of credentials in hand, red teamers may access systems and make lateral movement across the network, as well as creating their own credentials which may be difficult to detect in a breach. See all credential payloads.

This payload is for the USB Rubber Ducky — a "flash drive" that types keystroke injection payloads into unsuspecting computers at incredible speeds. It's no wonder this little quacker has made appearances on Mr. Robot, FBI, Blacklist, National Geography and more!

Submit your own payload, or browse more featured USB Rubber Ducky Payloads.

 

 

Related Payloads

Doppelganger
Doppelganger
Spoof your targets hostname and MAC address to appear less suspicious to the target network.
Read More
Jelly Sentinel
Jelly Sentinel
Jelly Sentinel is a native network security assessment tool built for the WiFi Pineapple Pager. Drop it on a network,
Read More
FuzzFinder
FuzzFinder
Scans for Axon devices and alerts user if they're present.
Read More