Advertisement
PepperPotts

46bc86cff88521671e70edbbadbc17590305c8f91169f777635e8f529ac2

Feb 14th, 2019
308
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.47 KB | None | 0 0
  1. *Urls and contents:
  2. -------------------
  3.  
  4. • http://66.117.6.174/test.html:
  5.  
  6. http://66.117.6.174/ups.rar C:\windows\system\cab.exe 1
  7.  
  8. • http://66.117.6.174/1.txt:
  9.  
  10. 20180807
  11.  
  12. • http://66.117.6.174/update.txt:
  13.  
  14. http://66.117.6.174/wpd.jpg c:\windows\system\msinfo.exe
  15. http://66.117.6.174/my1.html c:\windows\system\my1.bat
  16.  
  17. • http://223.25.247.240/ok/ups.html
  18.  
  19. 66.117.6.174
  20.  
  21. • http://66.117.6.174/dll/packet.dll
  22. • http://66.117.6.174/dll/64npf.sys
  23. • http://66.117.6.174/dll/npf.sys
  24. • http://66.117.6.174/dll/wpcap.dll
  25.  
  26.  
  27. *Behavior:
  28. ----------
  29.  
  30. • HKLM\\System\\CurrentControlSet\\services\\Tcpip\\Parameters\\Interfaces\\NameServer = 223.5.5.5,8.8.8.8
  31. • "C:\\Windows\\system32\\cmd.exe" /c sc start xWinWpdSrv&ping; 127.0.0.1 -n 10 && del <mainexe> >> NUL
  32. • sc start xWinWpdSrv
  33.  
  34.  
  35. *Strings (unpacked):
  36. --------------------
  37.  
  38. • c:\\windows\\system\\upslist.txt
  39. • get wpcap.dll failed
  40. • c:\\windows\\system\\msinfo.exe
  41. • get packet.dll failed
  42. • get npptools.dll failed
  43. • http://%s/update.txt
  44. • config xWinWpdSrv binpath= "c:\\windows\\system\\msinfo.exe -s -syn 1000"
  45. • /c sc start xWinWpdSrv&ping; 127.0.0.1 -n 10 && del
  46. • http://%s/dll/64npf.sys
  47. • http://223.25.247.240/ok/ups.html
  48. • Content-Type: application/x-www-form-url
  49. • GET %s HTTP/1.1
  50. • \\npptools.dll
  51. • /delete /f /tn msinfo
  52. • Accept: text/html,application/xhtml+xml;application/xml;q=0.9,*/*;q=0.8
  53. • \\StringFileInfo\\%04x%04x\\ProductVersion
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement