Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Sample: dd7639c87f4dfa99b08601cbead7848d9614d84ff0efa685936b881fa27d7331
- hexlified string "72720C767474730E750C74070A0F737A0205757200740A757B01047E0B017B72"
- >>> key = "DCA4B6A09190288"
- >>> key = bytearray(key)
- test = bytearray(binascii.unhexlify('72720C767474730E750C74070A0F737A0205757200740A757B01047E0B017B72'))
- for i in range(len(test)):
- test[i] ^= key[(i+1)%len(key)]
- Environment
- OpenProcess
- Software\Microsoft\Windows\CurrentVersion\Run
- odbcconf.exe
- comspec
- UserInitMprLogonScript
- RegSetValueExW
- advapi32.dll
- GetModuleFileNameW
- ExpandEnvironmentStringsW
- CreateToolhelp32Snapshot
- Notepad
- /c del
- /s /n /u /i:
- kernel32.dll
- CryptGenRandom
- Software\Microsoft
- .txt
- RegQueryValueExW
- >> NUL
- TerminateProcess
- GetEnvironmentVariableW
- 38B45FE13299B3B8
- regsvr32.exe
- E99B80FBD917FB6EC240177A529C2C15
- 1384B5C7D5D52779C17DAD3DB16F3E83
- Software\Microsoft\Notepad
- RegCreateKeyExW
- AVP.EXE
- 7463
- RegCloseKey
- %APPDATA%\
- Process32NextW
- CryptAcquireContextW
- CreateProcessW
- %username%
- RegOpenKeyExW
- CryptReleaseContext
- scrobj.dll
Advertisement
Add Comment
Please, Sign In to add comment