"Microsoft Windows 10" Fake Logon Screen

Download Copy
Title: "Microsoft Windows 10" Fake Logon Screen
Author: TW-D

Change "monitor-timeout (AC and DC)" at NEVER with "powercfg" utility. Change "standby-timeout (AC and DC)" at NEVER with "powercfg" utility. Retrieve the current username. Full-screen opening of the phishing HTML page using the default web browser with a random wallpaper. The "Bash Bunny" can be removed because the files are cached in the web browser. The password will be sent by HTTP POST to the URL specified in the "DROP_URL" constant.

 

🏆   Recognized with a Payload Award in September 2023

 

 

 

Phishing is a popular technique for gaining access to a target. Generally, phishing is a digitally delivered social engineering method. Phishing techniques may use a wide net, or specifically target one role or individual — known as spearphishing. Many phishing campaigns involve tricking a target into divulging confidential information, such as by mimicking a known-trusted source — be it a website or person. See all phishing payloads.

This payload is for the Bash Bunny. Simultaneously mimic multiple trusted devices to trick targets into divulging sensitive information without triggering defenses. The Bash Bunny is truly the world's most advanced USB attack platform.

Submit your own payload, or browse more featured Bash Bunny Payloads.

 

 

Related Payloads

A.S.E - Advanced System Exfiltration
A.S.E - Advanced System Exfiltration
This slow, and steady staged payload takes it's time and gleans detailed system information using Powershell, Ducky scri
Read More
run command as root without sudo password
run command as root without sudo password
A payload that allows for executing any bash command on the targets computer as root, without knowing their sudo passwor
Read More
Windows Screenshot Exfil
Windows Screenshot Exfil
This payload captures screenshots from a Windows machine every 10 seconds and uploads them to a specified server using t
Read More