SharkDOS

SharkDOS

🏆   by drapl0n June 09, 2022

Execution Shark Jack

SharkDOS payload intelligently scan target's network for open http (configurable for https) ports and DOS it.
My Pictures 2 Ascii Art

My Pictures 2 Ascii Art

🏆   by Cribbit June 09, 2022

Bash Bunny Prank

Converts Jpeg, Png & BMP's in the My Pictures to ascii art versions.

FollinaBunny

FollinaBunny

🏆   by PanicAcid June 01, 2022

Bash Bunny Execution

Executes code leveraging CVE-2022-30190 aka Follina using a malicious html file hosted on the Bunny itself. Whilst this exploit can be called via a malicious...
ScreenSaver_FuNNN_b-b

ScreenSaver_FuNNN_b-b

🏆   by LulzAnarchyAnon June 01, 2022

Bash Bunny Prank

The webcam is opened, and 15 pictures are taken and saved to the camera roll folder. The wallpaper settings are then changed so the Photos/Camera Roll folder...

Blue_Harvester

Blue_Harvester

🏆   by LulzAnarchyAnon May 29, 2022

Execution OMG

This is a Three stage payload that begins by opening bluetooth file transfer on the target device. Next the attackers bluetooth adapter name is selected for...
Chrome Exfil

Chrome Exfil

🏆   by thisismyrobot May 29, 2022

Exfiltration USB Rubber Ducky

A script to exfiltrate Chrome browser credentials from a target. Entered interactively to bypass a lot of PowerShell-related AV triggers. The Chrome GET requ...

Credz-Plz

Credz-Plz

🏆   by I am Jakoby May 19, 2022

Credentials USB Rubber Ducky

A script used to prompt the target to enter their creds to later be exfiltrated with dropbox. A pop up box will let the target know "Unusual sign-in. Please ...
ReverseBunnySSL

ReverseBunnySSL

🏆   by 0i41E May 12, 2022

Bash Bunny Remote Access

ReverseBunnySSL gets you remote access to your target in seconds. Unlike ReverseBunny, ReverseBunnySSL offers encrypted traffic via OpenSSL.

Fake sudo

Fake sudo

🏆   by TW-D May 12, 2022

Bash Bunny Phishing

1. Copies the "sudo" command spoofing program to the user's home directory. 2. Defines a new persistent "sudo" alias with the file "~/.bash_aliases". 3. When...
ADV-Recon

ADV-Recon

🏆   by I am Jakoby May 10, 2022

OMG Recon

A script used to do an advanced level of Recon on the targets computer. This program enumerates a target PC to include Operating System, RAM Capacity, Public...

ADV-Recon

ADV-Recon

🏆   by I am Jakoby May 10, 2022

Bash Bunny Recon

A script used to do an advanced level of Recon on the targets computer. This program enumerates a target PC to include Operating System, RAM Capacity, Public...
BLE_EXFIL_DEMO

BLE_EXFIL_DEMO

🏆   by drapl0n May 02, 2022

Bash Bunny Exfiltration

Demonstration of BLE_EXFIL extension.

Physical_Rick_Roll

Physical_Rick_Roll

🏆   by the-jcksn April 29, 2022

Bash Bunny Prank

Adds a physical copy of 'The Best of Rick Astley' CD to the target's Amazon shopping basket/cart. Requires the target to be logged onto amazon with 'remember...
KeyManager Backup

KeyManager Backup

🏆   by Cribbit April 20, 2022

Bash Bunny Exfiltration

Create a backup of the key manager which stores log-on credentials for servers, websites and programs. Config: set the password for the backup by setting th...

"Microsoft Windows" WinRM Backdoor

🏆   by TW-D April 20, 2022

Remote Access USB Rubber Ducky

Adds a user account (RD_User:RD_P@ssW0rD). Adds this local user to local administrator group. Enables "Windows Remote Management" with default settings. Adds...
AUTOinCORRECT

AUTOinCORRECT

🏆   by the-jcksn April 17, 2022

Prank USB Rubber Ducky

Creates a custom Microsoft Word Autocorrect rule, default sets rule to change "the" to "teh". Can be changed to any words you wish.

FodCableII - UAC Bypass

FodCableII - UAC Bypass

🏆   by 0i41E April 08, 2022

Execution OMG

Use your O.MG Cable / Plug to bypass UAC using one of the Fodhelper.exe methods. This POC will get you an elevated powershell instance and won't trigger AV a...
OMG Acid Burn

OMG Acid Burn

🏆   by I am Jakoby April 08, 2022

OMG Prank

A script I put together to torment Call Center Scammers but can be used on your friends as well.. or Foes.